Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

What's Changed

Learn about what changed in this release for ACX Series routers.

General Routing

  • SSH key options for user account credentials. You can configure key-options <key-options> option at the set system login user user authentication [ssh-rsa|ssh-ecdsa|ssh-ed25519 <ssh key> hierarchy level.

    [See login.]

  • Option allow-transients is set by default for the EZ-LAG commit script—The EZ-LAG feature simplifies setting up EVPN multihoming configurations using a set of configuration statements and a commit script. The commit script applies transient configuration changes, which requires the allow-transients system commit scripts option to be set. Now the default system configuration sets the allow-transients option at the EZ-LAG commit script file level, removing the need to set this option manually. In earlier releases where this option isn't set by default, you must still configure the option explicitly either globally or only for the EZ-LAG commit script.

    [See Easy EVPN LAG Configuration Overview.]

  • Process generates a live core when its related process generates a core (ACX Series, PTX Series, and QFX Series)—For related processes, when one process stops responding and generates a core file, by default, the system also generates a live core for the related process. By generating a live core for the related process, the system provides more complete diagnostic data at the time of the failure, which enables you to perform a more thorough root cause analysis and resolve issues faster. You can disable this feature for an individual process or for all processes by configuring the no-livecore-dump-on-crash statement at the [edit system processes process-name] or [edit system processes all-processes] hierarchy level, respectively. The process pairs that support this feature are:

    • bfdd and bfddagent

    • cfmd and cfmd-agent

    • dot1xd and dot1xd-agent

    • l2ald and l2ald-agent

    • l2cpd and l2cpd-agent

    • mcsnoopd and mcsnoopd-agent

    • ppmd and ppmdagent

    • routing and rpdagent

    [See processes.]PR1829890

  • A new counter Sessions hit due to high rate is added to show services service-sets screen-session-limit-counters command for all subscriber traffic. This counter tracks the sessions that come up on the screen irrespective of the alarm-without-drop configuration. When alarm-without-drop option is disabled, all the counters display updated statistics. When alarm-without-drop is enabled, then:

    • The screen-drop counters on show services service-sets screen-session-limit-counters command do not increase.

    • The Sessions hit due to high rate value is displayed.

    [See alarm-without-drop-edit-services-screen-ids-options-usf, show-services-service-sets-statistic-screen-drop, and show-services-service-sets-statistic-screen-session-limit-counters.]PR1849594

  • Validation of /vm-primary mount during JDM installation or upgrade (Junos Node Slicing External Server Deployment)—During installation or upgrade of the Juniper Device Manager (JDM) on external servers running Junos Node Slicing Release 25.2 or later, an issue occurred with the validation of the /vm-primary mount that stores the GNF images. When /vm-primary was mounted using logical volumes (LVM), JDM would fail to detect that the underlying storage was an SSD. This issue is now fixed. However, the fix introduces a new dependency on the LVM2 package in the host OS. This package is included by default in standard installations of both RHEL and Ubuntu external servers. However, it is advised that you check if the LVM2 package is already installed on the host before installing or upgrading JDM. PR1877593

  • Core files generated for related processes are bundled into a compressed TAR file (ACX Series, PTX Series, and QFX Series)—When a process generates a core file and the system generates a live core for its related process, the system bundles the core files into a compressed TAR file. In earlier releases, the system does not bundle the files. The process pairs that support this feature are: bfdd and bfddagent; cfmd and cfmd-agent; dot1xd and dot1xd-agent; l2ald and l2ald-agent; l2cpd and l2cpd-agent; mcsnoopd and mcsnoopd-agent; ppmd and ppmdagent; routing and rpdagent.PR1889091

Network Management and Monitoring

  • Deprecation of shell option—The shell option no longer requires a separate configuration and is now the default behavior. Deprecating the shell option enhances efficiency and simplifies management tasks.

  • Shell Command Logging Enhancement—All shell commands executed on the device and root sessions are now logged by default. This enhancement ensures enhanced security and auditability by capturing all commands entered in any shell environment, preventing bypassing audit logging. PR1867216

Routing Protocols

  • SNMP Trap Behavior Honors Logical-System Hierarchy (All Platforms)—The snmp-options backward-traps-only-from-established configuration now correctly applies when set under a logical system. In earlier releases, the setting needed a commit full or a corresponding global configuration to take effect. Logical-system-specific values are activated with a standard commit and don't depend on global scope.PR1837269

  • RTC Route Display Fixed (Junos OS and Junos OS Evolved)—The latest update corrects the display issue for RTC routes associated with transport targets in BGP show command output. Earlier versions failed to format (pretty-print) those routes correctly in the show route and show route table bgp.rtarget.0 protocol rtarget outputs, leading to readability problems. This enhancement now presents RTC routes in a clear format, making routing table inspections and troubleshooting more efficient.PR1839269

  • Extension of traceoptions support for VLANs in IGMP/MLD snooping—The traceoptions option is supported under the [edit routing-instance protocols igmp-snooping vlan] and [edit routing-instance protocols mld-snooping vlan] hierarchy. traceoptions can be enabled for both specific and all vlans.

    [See vlan (IGMP Snooping) and vlan (MLD Snooping).]PR1845242

  • Multipath Prioritization Feature Now Visible (All Platforms)—The multipath-prioritization capability, previously hidden within the configuration hierarchy, is now exposed for direct use. This direct access enables operators to manage path-selection behavior and optimize traffic flow across multiple routes. The newly exposed feature also improves operational clarity for multipath routing deployments.

    [See multipath (Protocols BGP) and prioritization.]PR1847793

  • Holddown Route definition—A holddown route is redefined as a Route that is in pending delete state because a protocol has an existing interest bit set on it.

    [See show route.]PR1853954

  • Modification of SRTE Advertisement Policy Name Display—BGP will now not generate and not display the "Advertised Policy Name" field for BGP-SRTE routes in show command output when the "Name TLV" is not received in the tunnel encapsulation attribute with the BGP-SRTE NLRI. The field will only be displayed when the "Name TLV" is received. This update eliminates ambiguity by ensuring multiple NLRIs do not display the same policy name, providing clearer and more accurate route information in command outputs.PR1853958

  • BGP Task Progress Monitoring—The show task jobs extensive command now displays progress for BGP-specific jobs including BGP init policy walk, BGP group join, BGP Peer Reconfig, New policy flash update, and BGP RIB reconfig. This provides network administrators with detailed visibility into BGP task completion status, improving operational transparency and diagnostics.PR1857368

Subscriber Access Management

  • Addition of message-authenticator and no-message-authenticator attributes under access radius-server, access profile radius-server, and system radius-server hierarchies—Set message-authenticator if you require the RADIUS server to include the Message Authenticator attribute in replies to Access-Request messages. Set no-message-authenticator to not require that attribute.PR1871147

User Interface and Configuration

  • Access privileges for request support information command (ACX Series, EX Series, MX Series,QFX Series, SRX Series Firewalls, and vSRX Virtual Firewall)—The request support information command is designed to generate system information for troubleshooting and debugging purposes. Users with the specific access privileges maintenance, view, and view-configuration can execute request support information command.

  • Changes to the show system storage command output (ACX Series, EX Series, MX Series, QFX Series, and SRX Series)—We've updated the show system storage command output to include only true (physical) storage and exclude any host/hypervisor level storage. In earlier releases, the output also includes a container/jail storage, which does not have a separate storage of its own.

    [See show system storage.]

  • Option to view combined disk space usage statistics for all configuration databases (ACX Series, EX Series, MX Series, QFX Series, SRX Series, and vSRX)—The show system configuration database usage command provides the merge option. When you include the merge option, the command output displays combined disk space usage statistics for all configuration databases, including the static configuration database and all ephemeral configuration database instances.

    [See show system configuration database usage.]

  • Updated Annotate Command Behavior—The annotate command now correctly handles multi-line comments that start with `#`. This change ensures that all lines of a multi-line comment remain comments, preventing unauthorized configuration changes when the configuration is committed, reloaded, or rollbacked. These improvements enhance security by mitigating potential privilege escalation attacks from users with limited configuration editing permissions.PR1868636

  • Enhanced Permission Checks for Rename/Copy Operations—New permission checks have been introduced for rename and copy operations within the configuration hierarchy. These checks parse the hierarchy being modified to ensure the user has the required permissions for the hierarchy and its sub-hierarchies. If permissions are insufficient, the operation will fail and a "Permission denied" error will be displayed. This enhancement ensures that configuration modifications are performed only by authorised users, improving security and preventing unintended changes to critical system settings.PR1882303