What's Changed in 24.4R2-S2
Learn about what changed in this release for SRX Series.
Chassis Clustering
-
MNHA Upgrade Requirement for IPv6-Based ICL Encryption [SRX4600, SRX4200, SRX4300, SRX4700]—In Multinode High Availability (MNHA) deployments that use IPv6 addresses for Interchassis Link (ICL) (HA link) encryption, upgrading from an earlier Junos OS release to a release that supports IPv6-based ICL encryption requires following the isolated node upgrade procedure to ensure a successful transition. This is a one-time requirement when moving to the first supported release; subsequent upgrades do not require the isolated node upgrade procedure.
[See Isolated node upgrade procedure and Software Upgrade in Multinode High Availability].
-
Configuration validation for HA link encryption (SRX Series)—New validation checks have been introduced to restrict the configuration of tunnel MTU for HA link encryption tunnels in a Multinode High Availability setup. The validation check ensures that the end-to-end MTU for HA links using IPv6 encryption meets the minimum requirement of 2000 bytes, helping maintain optimal performance and reliability during high availability operations. For example, if your configuration includes the following stanza where tunnel-mtu is less than 2000, you'll receive a commit check error:
user@host# set security ipsec vpn L3HA_IPSEC_VPN tunnel-mtu.Note: In an MNHA setup, for IPv6 HA link encryption, ensure to maintain a minimum end-to-end MTU of 2000 bytes.