Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

What's Changed

Learn about what changed in this release for ACX Series routers.

Authentication and Access Control

  • ChaCha20-Poly1305 algorithm deprecation for SSH cipher option— The ChaCha20-Poly1305 authenticated encryption algorithm is deprecated for SSH cipher option. Configure aes-128-gcm and aes-256-gcm as the encryption algorithm for SSH Cipher option. [See ssh (System Services).]

EVPN

  • OISM SBD bit in EVPN Type 3 route multicast flags extended community—In EVPN Type 3 Inclusive Multicast Ethernet Tag (IMET) route advertisements for interfaces associated with the supplemental bridge domain (SBD) in an EVPN optimized intersubnet multicast (OISM) network, we now set the SBD bit in the multicast flags extended community. We set this bit for interoperability with other vendors, and to comply with the IETF draft standard for OISM, draft-ietf-bess-evpn-irb-mcast .

    [See the description of the show route table bgp.evpn.0 ? extensive command in CLI Commands to Verify the OISM configuration.]

  • Default behavior changes and new options for the easy EVPN LAG configuration (EZ-LAG) feature—The easy EVPN LAG configuration feature now uses some new default or derived values, as follows:
    • Peer PE device peer-id value can only be 1 or 2.

    • You are required to configure the loopback subnet addresses for each peer PE device using the new loopback peer1-subnet and loopback peer2-subnet options at the edit services evpn device-attribute hierarchy level. The commit script uses these values for each peer PE device's loopback subnet instead of deriving those values on each PE device. These replace the loopback-subnet option at the edit services evpn device-attribute hierarchy level, which has been deprecated.

    • If you configure the no-policy-and-routing-options-config option, you must configure a policy statement called EXPORT-LO0 that the default underlay configuration requires, or configure the new no-underlay-config option and include your own underlay configuration.

    • The commit script generates "notice" messages instead of "error" messages for configuration errors so you can better handle edit services evpn configuration issues.

    • The commit script includes the element names you configure (such as IRB instance names and server names) in description statements in the generated configuration.

    • This feature also now includes a few new options so you have more flexibility to customize the generated configuration:

    • no-underlay-config at the edit services evpn hierarchy level—To provide your own underlay peering configuration.

    • mtu overlay-mtu and mtu underlay-mtu options at the edit services evpn global-parameters hierarchy level—To change the default assigned MTU size for underlay or overlay packets.

    [See Easy EVPN LAG Configuration.]

    .

  • Limit on number of IP address associations per MAC address per bridge domain in EVPN MAC-IP database—By default, devices can associate a maximum of 200 IP addresses with a single MAC address per bridge domain. We provide a new CLI statement to customize this limit, mac-ip-limit statement at the edit protocols evpn hierarchy level. In most use cases, you don?t need to change the default limit. If you want to change the default limit, we recommend that you don?t set this limit to more than 300 IP addresses per MAC address per bridge domain. Otherwise, you might see very high CPU usage on the device, which can degrade system performance.

    [See mac-ip-limit.]

Flow-based and Packet-based Processing

  • The subscription path for the flow sensor is changed from /junos/security/spu/flow/usage to /junos/security/spu/flow/statistics. This change maintains a uniform path in request and response data.

General Routing

  • New commit check for MAC-VRF routing instances with the encapsulate-inner-vlan statement configured—We introduced a new commit check that prevents you from configuring an IRB interface and the encapsulate-inner-vlan statement together in a MAC-VRF routing instance. Please correct or remove these configurations prior to upgrading to 23.2R2 or newer to avoid a configuration validation failure during the upgrade.

    [See encapsulate-inner-vlan.]

  • Starting in Junos OS Release 24.2R1, when you run the run show lldp local-information interface <interface-name> | display xml command, the output is displayed under the lldp-local-info root tag and in the lldp-local-interface-info container tag. When you run the run show lldp local-information interface | display xml command, the lldp-tlv-filter and lldp-tlv-select information are displayed under the lldp-local-interface-info container tag in the output.

  • Non-revertive switchover for sender based MoFRR— In earlier Junos releases, source-based MoFRR ensured that the traffic reverted to the primary path from the backup path, when the primary path or session was restored. This reversion could result in traffic loss. Starting in Junos OS 22.4R3-S1, source-based MoFRR will not revert to the primary path, i.e. traffic will continue to flow through the backup path as long as the traffic flow rate on the backup path does not go below the configured threshold set under the protocols mvpn hot-root-standby min-rate command.

  • Show active forwarding session for sender based MoFRR— The show multicast route extensive command will show the active forwarding session in the case of source-based MoFRR. The field Session Status: Up & Forwarding will indicate that the particular session is currently forwarding traffic.

  • Change in options and generated configuration for the EZ-LAG configuration IRB subnet-address statement—With the EZ-LAG subnet-address inet or subnet-address inet6 options at the edit services evpn evpn-vxlan irb irb-instance hierarchy, you can now specify multiple IRB subnet addresses in a single statement using the list syntax addr1 addr2 ... . Also, in the generated configuration for IRB interfaces, the commit script now includes default router-advertisement statements at the edit protocols hierarchy level for that IRB interface.

    [See subnet-address (Easy EVPN LAG Configuration).]

  • Three new VSA's have been added to code repository for 802.1x authentication on RADIUS server under Vendor ID: 2636: - 53: Event-Type - 54: Sub-Event-Type - 55: Juniper-Generic-Message

    [See Radius Attributes and VSA list supported by 802.1X.]

  • Change to the commit process—In prior Junos OS and Junos OS Evolved releases, if you use the commit prepare command and modify the configuration before activating the configuration using the commit activate command, the prepared commit cache becomes invalid due to the interim configuration change. As a result, you cannot perform a regular commit operation using the commit command. The CLI shows an error message: 'error: Commit activation is pending, either activate or clear commit prepare'. If you now try running the commit activate command, the CLI shows an error message: 'error: Prepared commit cache invalid, failed to activate'. You then must clear the prepared configuration using the clear system commit prepared command before performing a regular commit operation. From this Junos and Junos OS Evolved release, when you modify a device configuration after 'commit prepare' and then issue a 'commit', the OS detects that the prepared cache is invalid and automatically clears the prepared cache before proceeding with regular 'commit' operation.

    [See Commit Preparation and Activation Overview.]

  • Media Access Control Security (MACsec) session remains stable when changing exclude-protocol configuration—When you change the protocols excluded from MACsec using the exclude-protocol protocol-name option at the edit security macsec connectivity-association connectivity-association-name, the MACsec session remains stable.

    [See exclude-protocol.]

  • New CLIs introduced to collect Layer 2 bridging and Layer 2 protocols for smart debugging.PR1791299

  • Disable the integrity check value (ICV) indicator type, length, and value (TLV) on the MKA protocol to enable MACsec sessions—By default, the ICV indicator is enabled. In most networks, when MACsec is configured, devices ignore the ICV TLV and establish a MACsec session instead. In networks that do not establish a MACsec session when the ICV TLV is enabled, use the disable-icv-indicator option at the [edit security macsec connectivity-association ca-name mka] hierarchy level to disable the ICV TLV and allow the network to establish the MACsec session. To confirm the ICV TLV is disabled, use the show security mka sessions detail command. PR1743300

    Disable the integrity check value
  • New LSP state for show spring-traffic-engineering—We have introduced a new state Initializing in the output of show spring-traffic-engineering, which indicates that the tunnel configuration has been queued up and is awaiting processing. The LSP is in this state only during initial application of the tunnel configuration. Any subsequent changes or updates to the tunnel configuration do not trigger this state again.

    [See show spring-traffic-engineering.]PR1762424

  • Change in use of RSA signatures with SHA-1 hash algorithm—Starting in Junos OS Release 24.2R1, there is a behavioural change by OpenSSH 8.8/8.8p1. OpenSSH 8.8/8.8p1 disables the use of RSA signatures with SHA-1 hash algorithm by default. You can use RSA signatures with SHA-256 or SHA-512 hash algorithm. PR1782818

Infrastructure

  • Option to disable path MTU discovery—Path MTU discovery is enabled by default. To disable it for IPv4 traffic, you can configure the no-path-mtu-discovery statement at the edit system internet-options hierarchy level. To reenable it, use the path-mtu-discovery statement.

    [See Path MTU Discovery.]

Network Management and Monitoring

  • With this release, the CLI does not allow you to delete the management-instance configuration from the edit system hierarchy level if you have configured syslog messages for remote hosts with the mgmt_junos instance as routing instance at the edit system syslog hierarchy level and at the edit system hierarchy level. If you try to delete the management-instance configuration at the edit system hierarchy level without deleting it from the edit system syslog hierarchy level, the CLI shows a commit error.PR1785475

Routing Protocols

  • Commands for Viewing Transport-Class and Resolution Scheme Information—We've introduced the show route transport-class command to view transport-class information and show route resolution scheme command to view custom resolution schemes for route next-hop resolution.

    [See show route transport-class and show route resolution scheme.]PR1757468

  • BGP Neighbor Telemetry Statistics (Junos OS and Junos OS Evolved)—BGP neighbor statistics reported through telemetry are now always aggregated, regardless of whether rib-sharding is enabled. Previously, when sharding was active, statistics were streamed per shard. With the current behavior, sensors are installed appropriately, and statistics are aggregated in the main thread before being streamed. The controllers and collectors now receive a single, unified view of BGP neighbor statistics.PR1765189

  • Micro-SID Locator Configuration Validation—We have introduced a validation rule to prevent the configuration of micro-SID locators where the Node Code is 0x00. You might encounter a commit error if you attempt to configure a micro-SID locator that results in a Node Code of 0x00. This change ensures that the SID 0x0000, reserved for End of Container (EOC), is not utilized in configurations, preventing potential routing issues.PR1782293

  • iBGP RR Update for Link Bandwidth Aggregation—In iBGP Route Reflector (RR) deployments, aggregation policies may advertise BGP Link Bandwidth (LBW) values that differ from the arithmetic sum of LBWs that multiple Provider Edges (PEs) provide. The update clarifies and enforces correct LBW calculation on RRs because the RRs recompute bandwidth locally instead of summing it cumulatively. Users might observe changes in the LBW values that RRs advertise, which can influence traffic-engineering behavior.PR1806864

User Interface and Configuration

  • Configuration database maximum size increased (ACX Series, EX Series, MX Series, QFX Series, SRX Series, and vSRX)—We've enhanced the extend-size statement at the [edit system configuration-database] hierarchy level to increase the maximum database size. On devices with a default configuration database size of ~400 MB, extend-size increases the maximum database size to ~2 GB. On devices with a default configuration database size of ~660 MB, extend-size increases the maximum database size to ~2.2 GB.

    [See configuration-database.]

  • Viewing files with the file compare files command requires users to have maintenance permission—The file compare files command in Junos OS and Junos OS Evolved requires a user to have a login class with maintenance permission.

    [See Login Classes Overview.]PR1759073

  • Displaying RPC Details Despite Command Invalidity—The system now allows displaying RPC details even when executing the show pfe filter hw | display xml rpc command on unsupported platforms. This change provides essential debugging information without requiring the command to pass product checks, thus improving diagnostic capabilities.PR1765385

  • Message Redirection for Syslog Messages—When you have configured syslog message redirection using the following CLI: [edit system syslog] user <user_name> { any info; } and need to disable the redirection of syslog messages to the interactive terminal, issue the set cli syslog-output disable command. To enable the redirection of syslog messages, issue the syslog-output enable command. We've introduced this command to reduce clutter in the terminal output caused by redirection messages. For more flexibility, the root user or any other user can configure allow-syslog-output or no-allow-syslog-output configuration statements at the [edit system login user <user_name> cli ] hierarchy level to allow or disallow the users from getting the syslog message redirection to the interactive terminal.

  • Configuration History Persistence—This update ensures that the configuration history, including commits and rollback data, is preserved when restarting Docker with a new container ID. By persisting the /config directory in a Docker/Podman volume, the show system commits data is now retained. This enhancement ensures full traceability of configuration changes and assists users in debugging and monitoring their configurations more efficiently. PR1787729

VPNs

  • Increase in revert-delay timer range—The revert-delay timer range is increased to 600 seconds from 20 seconds.

    [See min-rate.]

  • Configure min-rate for IPMSI traffic explicitly— In a source-based MoFRR scenario, you can set a min-rate threshold for IPMSI traffic explicitly by configuring ipmsi-min-rate under set routing-instances protocols mvpn hot-root-standby min-rate. If not configured, the existing min-rate will be applicable to both IPMSI and SPMSI traffic.

    [See min-rate.]

  • Hot Root Standby with Inactive Route Support—Hot Root Standby (HRS) now supports querying inactive routes from shards. This enables MVPN to access and utilize inactive route data for required features. MVPN processes involving inactive routes are now handled asynchronously, ensuring smoother and more efficient operations. With this change, HRS is supported with sharding enabled.

    [See hot-root-standby.]PR1763724