What's Changed
Learn about what changed in this release for EX Series switches.
General Routing
-
SSH key options for user account credentials—You can configure
key-options key-optionsoption at the[edit system login user user authentication ssh-rsa|ssh-ecdsa|ssh-ed25519 ssh key]hierarchy level.[See login.]
-
Option
allow-transientsis set by default for the EZ-LAG commit script—The EZ-LAG feature simplifies setting up EVPN multihoming configurations using a set of configuration statements and a commit script. The commit script applies transient configuration changes, which requires theallow-transientssystem commit scripts option to be set. Now the default system configuration sets theallow-transientsoption at the EZ-LAG commit script file level, removing the need to set this option manually. In earlier releases where this option isn't set by default, you must still configure the option explicitly either globally or only for the EZ-LAG commit script. -
Deprecation of jnxLEDTable—The jnxLEDTable table is no longer supported. PR1848057
-
A new counter "Sessions hit due to high rate" is added to
show services service-sets screen-session-limit-counterscommand for all subscriber traffic. This counter tracks the sessions that come up on the screen irrespective of thealarm-without-dropconfiguration. Whenalarm-without-dropoption is disabled, all the counters display updated statistics. Whenalarm-without-dropis enabled, then, the screen-drop counters onshow services service-sets statistic screen-dropcommand do not increase. The "sessions hit due to high rate" value is displayed.[See alarm-without-drop (IDS Screen Next Gen Services), show services service-sets statistic screen-drops (Next Gen Services), and show services service-sets statistic screen-session-limit-counters (Next Gen Services).]PR1849594
-
Changes to request system recover command syntax (EX Series)—Options
all-members | local | member member-idhave been added to therequest system recovercommand to specify the members for which the system needs to recover data.[See request system recover.]
-
Support for 4x10G uplink module—You can use the 4x10G uplink module to support both 10G and 1G transceivers and interfaces. The device automatically detects the presence of a 10G or 1G transceiver and creates a physical interface of the corresponding speed.
-
Validation of /vm-primary mount during JDM installation or upgrade (Junos Node Slicing External Server Deployment)—During installation or upgrade of the Juniper Device Manager (JDM) on external servers running Junos Node Slicing Release 25.2 or later, an issue occurred with the validation of the /vm-primary mount that stores the GNF images. When /vm-primary was mounted using logical volumes (LVM), JDM would fail to detect that the underlying storage was an SSD. This issue is now fixed. However, the fix introduces a new dependency on the LVM2 package in the host OS. This package is included by default in standard installations of both RHEL and Ubuntu external servers. However, it is advised that you check if the
LVM2package is already installed on the host before installing or upgrading JDM.PR1877593 -
On the MPC7E-10G line card, when you configure the 10-Gigabit Ethernet ports to operate as 1-Gigabit Ethernet ports, use the speed statement at both the
[edit interfaces interface name gigether-options]and[edit interfaces interface name]hierarchy levels.PR1879198
Network Management and Monitoring
-
Deprecation of shell option—The
shelloption no longer requires a separate configuration and is now the default behavior. Deprecating the shell option enhances efficiency and simplifies management tasks. -
Shell Command Logging Enhancement—All shell commands executed on the device and root sessions are now logged by default. This enhancement ensures enhanced security and auditability by capturing all commands entered in any shell environment, preventing bypassing audit logging.PR1867216
Routing Protocols
-
SNMP Trap Behavior Honors Logical-System Hierarchy (All Platforms)—The
snmp-options backward-traps-only-from-establishedconfiguration now correctly applies when set under a logical system. In earlier releases, the setting needed acommit fullor a corresponding global configuration to take effect. Logical-system-specific values are activated with a standardcommitand don't depend on global scope.PR1837269 -
RTC Route Display Fixed—The latest update corrects the display issue for RTC routes associated with transport targets in BGP
showcommand output. Earlier versions failed to format (pretty-print) those routes correctly in theshow routeandshow route table bgp.rtarget.0 protocol rtargetoutputs, leading to readability problems. This enhancement now presents RTC routes in a clear format, making routing table inspections and troubleshooting more efficient.PR1839269 -
Extension of traceoptions support for VLANs in IGMP/MLD snooping— The
traceoptionsoption is supported under the[edit routing-instance protocols igmp-snooping vlan]and[edit routing-instance protocols mld-snooping vlan]hierarchy.traceoptionscan be enabled for both specific and all vlans.[See vlan (IGMP Snooping) and vlan (MLD Snooping).]
-
Multipath Prioritization Feature Now Visible (All Platforms)—The multipath-prioritization capability, previously hidden within the configuration hierarchy, is now exposed for direct use. This direct access enables operators to manage path-selection behavior and optimize traffic flow across multiple routes. The newly exposed feature also improves operational clarity for multipath routing deployments.
[See multipath (Protocols BGP) and prioritization.]PR1847793
-
Holddown Route definition—A holddown route is redefined as a Route that is in pending delete state because a protocol has an existing interest bit set on it.
[See show route.]PR1853954
-
Modification of SRTE Advertisement Policy Name Display—BGP will now not generate and not display the "Advertised Policy Name" field for BGP-SRTE routes in show command output when the "Name TLV" is not received in the tunnel encapsulation attribute with the BGP-SRTE NLRI. The field will only be displayed when the "Name TLV" is received. This update eliminates ambiguity by ensuring multiple NLRIs do not display the same policy name, providing clearer and more accurate route information in command outputs.PR1853958
-
BGP Task Progress Monitoring—The
show task jobs extensivecommand now displays progress for BGP-specific jobs including BGP init policy walk, BGP group join, BGP Peer Reconfig, New policy flash update, and BGP RIB reconfig. This provides network administrators with detailed visibility into BGP task completion status, improving operational transparency and diagnostics.PR1857368
Subscriber Access Management
-
Addition of
message-authenticatorandno-message-authenticatorattributes underaccess radius-server,access profile radius-server, andsystem radius-serverhierarchies—Setmessage-authenticatorif you require the RADIUS server to include the Message Authenticator attribute in replies to Access-Request messages. Setno-message-authenticatorto not require that attribute.PR1871147
User Interface and Configuration
-
Access privileges for request support information command (ACX Series, EX Series, MX Series, QFX Series, SRX Series Firewalls, and vSRX Virtual Firewall)—The
request support informationcommand is designed to generate system information for troubleshooting and debugging purposes. Users with the specific access privileges maintenance, view, and view-configuration can executerequest support informationcommand. -
Updated Annotate Command Behavior—The
annotatecommand now correctly handles multi-line comments that start with `#`. This change ensures that all lines of a multi-line comment remain comments, preventing unauthorized configuration changes when the configuration is committed, reloaded, or rollbacked. These improvements enhance security by mitigating potential privilege escalation attacks from users with limited configuration editing permissions.PR1868636 -
Changes to the
show system storagecommand output (ACX Series, EX Series, MX Series, QFX Series, and SRX Series)—We've updated theshow system storagecommand output to include only true (physical) storage and exclude any host/hypervisor level storage. In earlier releases, the output also includes a container/jail storage, which does not have a separate storage of its own.[See show system storage.]
-
Option to view combined disk space usage statistics for all configuration databases (ACX Series, EX Series, MX Series, QFX Series, SRX Series, and vSRX)—The
show system configuration database usagecommand provides themergeoption. When you include themergeoption, the command output displays combined disk space usage statistics for all configuration databases, including the static configuration database and all ephemeral configuration database instances. -
Enhanced Permission Checks for Rename/Copy Operations—New permission checks have been introduced for rename and copy operations within the configuration hierarchy. These checks parse the hierarchy being modified to ensure the user has the required permissions for the hierarchy and its sub-hierarchies. If permissions are insufficient, the operation will fail and a "Permission denied" error will be displayed. This enhancement ensures that configuration modifications are performed only by authorised users, improving security and preventing unintended changes to critical system settings.PR1882303
-
Stale ui-state.db data in persistent NETCONF sessions post-mgd restart—Existing NETCONF sessions might fetch stale data from ui-state.db after mgd -N restart. New sessions correctly map the refreshed database. Scripts must establish new sessions post-restart to access updated values. Functional configuration remains unaffected.
Script failures monitoring "local-host" NETCONF sessions—Scripts might fail when including "local-host" NETCONF sessions in monitoring operations. Internal sessions are now excluded from tracking. Scripts must filter out "local-host" sessions. No impact to internal application functionality.PR1888557