What's Changed
Learn about what changed in this release for MX Series routers.
EVPN
-
Flow-label configuration status for EVPN ELAN services-The output for the
show evpn instance extensivecommand now displays the flow-label and flow-label-static operational status for a device and not for the routing instances. A device withflow-labelenabled supports flow-aware transport (FAT) flow labels and advertises its support to its neighbors. A device withflow-label-staticenabled supports FAT flow labels but does not advertise its capabilities. -
Updated output for show route table—The output for
show route table bgp.evpn.0now displays L2 service TLV type. Previously, the output displayed the L3 service TLV. -
New enhancement "udp source port" introduced in Junos OS Release 22.4R1 for overlay ping and traceroute—In Junos OS releases prior to 22.4R1, you could not configure the udp source port in a ping overlay or traceroute overlay operation. You may now configure this value in an EVPN-VXLAN environment using
hash. The configuration optionhashwill override any other hash-* options that may be used to determine the source port value.PR1705726
General Routing
-
Enhanced bandwidth and burst policer value (MX Series and EX9200 Series)]--We've updated the default bandwidth value from 20000 to 100 pps and burst policer value from 20000 to 100 packets. This enhancement avoids the CPU usage of
eventdandsnmpdreaching more than 100%. Earlier to this release, when the system receives a violated traffic for SNMP along with other protocols traffic, the CPU usage ofeventdandsnmpdwas reaching more than 100% with an error. -
The Ethernet link fault management process (lfmd) runs only when the link-fault-management protocol is configured.PR1698132
-
PTP configuration might not function correctly on an MX10008 Router with JNP10K-LC2101 Line card: - when Hypermode is enabled. Hypermode can be enabled by default when MX10008 Router has Switch Fabric Board 2 (SFB2), or by using the command
set forwarding-optionshyper mode. Hence, such PTP interfaces (slave, master, stateful) are unsupported. if an aggregated Ethernet (AE) interface is configured and either the primary or secondary links on the AE do not support PTP with Hypermode, then the whole AE is marked as unsupported. -
Prior to this change when route sharding is configured the output of CLI
show routecommands included information about sharding. After the change the use must add the "rib-sharding all" argument to CLIshow routecommands to display sharding information. -
The traffic rate could display incorrect values in the "show services inline ip-reassembly statistics fpc x pfe-slot y" output.
-
Qualification check for "ordered-by-user" -- Review to check and confirm if hierarchies qualify for "ordered-by-user" list type. Once
show policy-options prefix-listis initiated by the user, the hierarchies appear in the order updated by the user. This enhancement organizes the hierarchies in ascending order. -
In order to monitor vmhost storage usage: A new minor alarm, VMHost RE 0 Disk 1 inode usage breached threshold is introduced. The existing minor alarm, VMHost RE 0 Disk 1 Usage is above threshold is changed to VMHost RE 0 Disk 1 Size usage breached threshold.
-
Support for DDoS protocol (MX10008)-We've enabled the DDoS protocol support at the [
edit system ddos-protection] hierarchy level for MX10008 devices. In earlier releases, the MX10008 devices did not support these DDoS protocol statements.Filter-actionVirtual-chassisTtlRedirectRe-servicesRe-services-v6Rejectv6L2ptSyslogVxlan
[See protocols (DDoS).]
-
Instance type change is not permitted from default to L3VRF in open configuration (ACX Series, EX Series, MX Series, QFX Series, SRX Series, vMX, and vSRX)--DEFAULT_INSTANCE is the primary instance that runs when there is no specific instance type configured in the route
set routing-options?. Any instance you explicitly configure is translated intoset routing-instance r1 routing-options?. The issue appears in translation, when you change instance type DEFAULT_INSTANCE (any instance to DEFAULT_INSTANCE) to L3VRF or L3VRF to DEFAULT_INSTANCE. As a result, such changes are not permitted. Additionally, DEFAULT_INSTANCE can only be named DEFAULT, and DEFAULT is reserved for DEFAULT_INSTANCE, therefore allowing no such changes. -
Instance type change is not permitted from default to L3VRF in open configuration (ACX Series, EX Series, MX Series, QFX Series, SRX Series, vMX, and vSRX)—DEFAULT_INSTANCE is the primary instance that runs when there is no specific instance type configured in the route
set routing-options?. Any instance you explicitly configure is translated intoset routing-instance r1 routing-options?. The issue appears in translation, when you change instance type DEFAULT_INSTANCE (any instance to DEFAULT_INSTANCE) to L3VRF or L3VRF to DEFAULT_INSTANCE. As a result, such changes are not permitted. Additionally, DEFAULT_INSTANCE can only be named DEFAULT, and DEFAULT is reserved for DEFAULT_INSTANCE, therefore allowing no such changes. -
Router advertisement module status on backup Routing Engine (MX Series)—The router advertisement module does not function in the backup Routing Engine as the Routing Engine does not send an acknowledgment message after receiving the packets. Starting in this Junos OS Release, you can view the router advertisement module information using the
show ipv6 router-advertisementoperational command. -
For Access Gateway Function (AGF) statistics, consistency changes are implemented for specific leaf values in telemetry data to match field values in Junos CLI operational mode commands. AGF NG Application Protocol (NGAP) data streamed to a collector and viewable from the Junos CLI now displays "ngap-amf-stats-init-ctx-setup-failure" and Access and Mobility Function (AMF) overload state now displays "On, Off".
-
Multicast debug information added in EVPN options to request system information command (MX Series, QFX Series)—The output from CLI command
request support information evpn-vxlannow includes additional information to help debug EVPN multicast issues.[See request support information.]
-
Modified show ancp subscriber details output fields (MX Series)--As the access loop encapsulation is transport independent it can be either passive optical network (PON) or DSL TLV. Hence, the
show ancp subscriber detailsoutput field should not tag the details as a DSL TLV. Therefore, we've modified the existingDSL Line Data Link,DSL Line Encapsulation, andDSL Line Encapsulation Payloadoutput fields to the following respectively:Access Loop Encapsulation Data LinkAccess Loop Encapsulation Encapsulation1Access Loop Encapsulation Encapsulation2
-
[See show ancp subscriber.]
-
Earlier, if the system failed to install an interface or hierarchical policer, the PFE crashed due to an assert. Now, the system installs a firewall discard and logs a DFW_HALP_ERR_MSG_POLICER_ADD_FAILED error message. This error message provides the name of the affected policer and the corresponding error code. Relevant policers appear under the interface > unit > family > policer input/output (or) interface > unit > family > input-hierarchical-policer stanzas.PR1701676
-
An optics configuration mismatch alarm may be triggered when there is a discrepancy between the configured speed of an interface and the supported speed of the optic. This alarm indicates that the optic installed in the specified FPC is incompatible with the speed configured on the interface.PR1703957
-
Change the output of the show arp command to display IP addresses and hostnames (MX Series routers)—You can force the show arp command output to display the IP address next to the hostname of each device. To do this, enable the force-show-arp-resolve statement at the [edit system services subscriber-management overrides] hierarchy level. This makes it easier to manage subscriber access if your subscriber configuration relies on the IP addresses of the devices.
[See overrides (Enhanced Subscriber Management) and Configuring Junos OS Enhanced Subscriber Management.]PR1708347
-
Increased maximum limit for TTP TLVs (MX Series)—The Junos Kernel now accommodates an increased number of TTP TLVs (TNP Tunneling Protocol: type, length, and value messages) to help avoid dropped packets.
-
The connectivity fault management process (cfmd) runs only when the ethernet connectivity-fault-management protocol is configured.PR1712419
-
In the past inet6flow.0 was not allowed to be a primary rib in a rib-group. Starting with Junos OS release 22.3 this is now allowed.PR1716840
-
The shared-tunnels statement is not supported on EX9204, EX9208, EX9214, EX9251, EX9253, MX304, MX10001, MX10002, MX960, MX480, MX240, MX2020, MX2010, MX2008, and vMX devices.PR1716955
-
The packet rate and byte rate fields for LSP sensors on AFT (with the legacy path) have been renamed as jnx-packet-rate and jnx-byte-rate and is in parity with the UKERN behavior. Previously, these rate fields were named as packetRate and byteRate.PR1725641
Junos XML API and Scripting
-
Ability to commit
extension-service fileconfiguration when application file is unavailable—When you set theoptionaloption at theedit system extension extension-service application file file-namehierarchy level, the operating system can commit the configuration even if the file is not available at the /var/db/scripts/jet file path.[See file (JET).]
-
Ability to restart restart daemonized applications—Use the
request extension-service restart-daemonize-app application-namecommand to restart a daemonized application running on a Junos device. Restarting the application can assist you with debugging and troubleshooting.[See request extension-service restart-daemonize-app.]PR1725063
MPLS
-
Change in display of affinity constraints to hexadecimal values (MX10004, ACX7100-32C, ACX7100-48L, ACX7509, ACX7024, PTX10001-36MR, PTX10004, PTX10008, and PTX10016)-Starting in Junos OS release 22.4R1 and Junos Evolved Release 22.4R1, in the output of the <codeph>show ted spring-te-policy extensive</codeph> operational command, the affinity constraints will be displayed in hexadecimal format instead of decimal.
-
Display flexible algorithm information for SRv6 locators in TED database]--Use the
show ted database extensivecommand to view the metric, flags, and flexible algorithm information associated with a SRv6 locator. Prior to this release, this information was not included in the TED database.[See show ted database.]
Network Management and Monitoring
-
Junos YANG modules for RPCs include the
junos:commandextension statement (ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series, vMX, and vSRX)--The Junos YANG modules that define RPCs for operational mode commands include the <codeph>junos:command</codeph> extension statement in schemas emitted with extensions. The statement defines the CLI command for the corresponding RPC. The Juniper YANG GitHub repository stores the RPC schemas with extensions in therpc-with-extensionsdirectory for the given release and device family. Additionally, when you configure theemit-extensionsstatement at the[edit system services netconf yang-modules]hierarchy level and generate the YANG schemas on the local device, the YANG modules for RPCs include thejunos:commandextension statement. -
Enhancement to the jnxRmonAlarmState (ACX Series, EX Series, MX Series, NFX Series, PTX Series, QFX Series, SRX Series)—You can now view the following additional values for the jnxRmonAlarmState when you use the show snmp mib walk jnxRmonAlarmTable: fallingThreshold (6) - If the value is less than or equal to falling-threshold risingThreshold (5) - If the value is greater than or equal to rising-threshold getFailure (7)- If the value is any value other than noError for the current internal 'get' request In earlier releases, you could view only the following status for the jnxRmonAlarmState: unknown (1), underCreation (2), or active (3).
-
operatorlogin class is restricted from viewing NETCONF trace files that areno-world-readable(ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series, vMX, and vSRX)—When you configure NETCONF tracing options at the[edit system services netconf traceoptions]hierarchy level and you restrict file access to the file owner by setting or omitting theno-world-readablestatement (the default), users assigned to theoperatorlogin class do not have permissions to view the trace file.
Platform and Infrastructure
-
The
ping host | display xml validatecommand validates XML without error (ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series, and vMX)—In Junos OS and Junos OS Evolved releases prior to 22.4R2, theping host | display xml validatecommand results in CRITICAL ERROR: Root tag name mismatch. Expected 'ping-results', got 'run-command'. The command now validates the XML successfully without error. -
Prior to this change, devices by default responded only to ARP requests originating from the same subnet. Configure the new CLI option,
respond-out-of-subnetat the[edit system arp]hierarchy level to allow ARP reply to a request that originates from a different subnet. PR1710699
Software Installation and Upgrade
-
New options for the
request system snapshotcommand (ACX Series, EX Series, MX Series, PTX Series, QFX Series, and SRX Series)—Therequest system snapshotcommand includes new options for non-recovery snapshots. You can include thenameoption to specify a user-defined name for the snapshot, and you can include theconfigurationorno-configurationoption to include or exclude configuration files in the snapshot. By default, the snapshot saves the configuration files, which include the contents of the /config and /var directories and certain SSH files.[See request system snapshot (Junos OS with Upgraded FreeBSD).]
Routing Protocols
-
BGP Multipath route calculation—When configuring multipath in the routing-instance, BGP routes that are inactive due to cluster-list length are also considered as eligible for multipath calculations. This enhances route selection by including more potential paths in your multipath configuration.
-
Prior to this change the output of the
show isis spring flex-algorithm | display xmlcommand was invalidly formatted when multiple flex algorithm instances were configured. With the change, the XML output is properly structured showing flex algorithm information for each instance. A new XML tag "isis-spring-flex-algorithm" is added to bundle information for each instance.PR1722352
User Interface and Configuration
-
Persistent CLI timestamps—To have a persistent CLI timestamp for the user currently logged in, enable the
set cli timestampoperational command. This ensures the timestamp shows persistently for each new line of each SSH session for the user or class until the configuration is removed.To enable timestamp for a particular class with permissions and format for different users, configure the following statements:
set system login class class name permissions permissions,set system login class class name cli timestamp, andset system login user username class class name authentication plain-text-password.Note:The default timestamp format is %b %d %T. You can modify the format per your requirements. For example, you can configure the following statement:
set system login class class name cli timestamp format "%T %b %dTo enable timestamp for a particular user with default class permissions and format, configure the following statements:set system login user username class class name authentication plain-text-password set system login user username cli timestamp. -
Port Mirroring Configuration Update—Interface ranges are no longer supported as part of configuration groups for creating analysers. If you attempt to use an interface-range in a config group, you will encounter an error indicating an invalid interface type. Additionally, interface ranges or interface lists cannot be configured under this setting. This change ensures precise and error-free configuration by requiring the specification of individual interfaces rather than ranges, thus improving the accuracy and reliability of port mirroring setups.PR1728883