What's Changed in 22.4R3

Learn about what changed in this release for MX Series routers.

Class of Service (CoS)

  • You cannot apply a classifier to a physical interface on MX Series routers. On MX Series routers, you must apply the classifier to a logical interface.

General Routing

  • Introduction of extensive option for IPsec security associations (MX Series, SRX Series and vSRX 3.0)-We've introduced the extensive option for the show security ipsec security-associations command. Use this option to display IPsec security associations with all the tunnel events. Use the existing detail option to display upto ten events in reverse chronological order.

    [See show security ipsec security-associations.]

  • In older Junos Releases, Data Definition Language (DDL) lists were ordered by the sequence in which the user configured the list items, for example a series of static routes. With this change, the list order is determined by the system with items displayed in numerical sequence rather than by the order in which the items were configured. There is no functional impact to this change.

  • The max-db-size is an optional configuration command on routers having >=32 GB DRAM, for example, on MX960 platform. To enable subscriber-management, use the command set chassis network-services enhanced-ip and set system services subscriber-management enable. The router reboots and comes-up with subscriber-management enabled without max-db-size (optional) configuration and requires only 1 reboot.

  • Multicast debug information added in EVPN options to request system information command (MX Series, QFX Series)—The output from CLI command request support information evpn-vxlan now includes additional information to help debug EVPN multicast issues.

    [See request support information.]

  • Increased maximum limit for TTP TLVs (MX Series)—The Junos Kernel now accommodates an increased number of TTP TLVs (TNP Tunneling Protocol: type, length, and value messages) to help avoid dropped packets.

    [See show system statistics]

  • Two new alarms are added and can be seen with MPC11E when 400G-ZR optics are used—High Power Optics Too Warm: warning of the increase in chassis ambient temperature with no functional action taken on the optics Temperature too high for optics power on: New inserted optics when the chassis ambient temperature is elevated beyond the threshold will not be powered on and would need to be reinserted when the ambient temperature is within the acceptable range.

  • The packet rate and byte rate fields for LSP sensors on AFT (with the legacy path) have been renamed as jnx-packet-rate and jnx-byte-rate and is in parity with the UKERN behavior. Previously, these rate fields were named as packetRate and byteRate.

  • Write cache disabled alarms no longer raised—The "Disk 2 Write Cache disabled" alarms were reported in the chassis alarms due to a missing SSD model in Junos OS supported device table. The support is now added, and alarms are no longer reported. PR1956899

Interfaces and Chassis

Changes to the RPC response for
  • When all the members of the AE have the same speed (x) and no mixed speed configured. If you change the speed value of any member of the AE to a value other than x, the commit succeeded in earlier releases. From this release, the commit fails. When there are et interfaces with different speeds and you want them to be part of an AE interface. If you change the speed of all the members of the interfaces to be the same speed (x), configure the AE interface, and commit, the commit failed in earlier releases. From this release, such commits succeed.PR1745893

Junos XML API and Scripting

  • Ability to commit extension-service file configuration when application file is unavailable—When you set the optional option at the edit system extension extension-service application file file-name hierarchy level, the operating system can commit the configuration even if the file is not available at the /var/db/scripts/jet file path.

    [See file (JET).]

  • Ability to restart restart daemonized applications--Use the request extension-service restart-daemonize-app <varname>application-name</varname> command to restart a daemonized application running on a Junos device. Restarting the application can assist you with debugging and troubleshooting.

    [See request extension-service restart-daemonize-app.]

  • Changes to XML output for MACsec operational commands—We have changed the XML output for the following MACsec operational commands (and the corresponding RPCs) so that they emit valid XML. show security mka sessions brief ? A new "session-common" element encloses each set of information for each session. show security mka sessions detail ? A new "session-live" element encloses the state of the interface. show security mka sessions summary ? A new "mka-session-terse" tag encloses the set of tags for each session. show security macsec connections ? A new "macsec-interface-common-information" element encloses the set of tags for each connection. show security mka statistics ? A new "mka-interface-statistics" element encloses each interface?s protocol statistics.

    [See show security mka sessions{https://www.juniper.net/documentation/us/en/software/junos/cli-reference/topics/ref/command/show-security-mka-sessions.html }, show security macsec connections{https://www.juniper.net/documentation/us/en/software/junos/cli-reference/topics/ref/command/show-security-macsec-connections.html }, and show security mka statistics ..]PR1744564

Network Management and Monitoring

  • Changes to the NETCONF server's <rpc-error> element when the operation="delete" operation deletes a nonexistent configuration object (ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series, vMX, and vSRX )—We've changed the <rpc-error> response that the NETCONF server returns when the <edit-config> operation uses operation="delete" to delete a configuration element that is absent in the target configuration. The error severity is error instead of warning, and the <rpc-error> element includes the <error-tag>data-missing</error-tag> and <error-type>application</error-type> elements.

  • Changes to the RPC response for <validate> operations in RFC-compliant NETCONF sessions (ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series, vMX, and vSRX )—When you configure the rfc-compliant statement at the [edit system services netconf] hierarchy level, the NETCONF server emits only an <ok/> or <rpc-error> element in response to <validate> operations. In earlier releases, the RPC reply also includes the <commit-results> element.

Platform and Infrastructure

  • DDoS syslog messages enhancement (MX Series devices with MPC10, MPC11, LC4800, or LC9600? line cards)--We've enhanced the severity of the DDoS module syslog messages ddos_get_vbf_ifl_from_flow_id and ddos_get_vbf_ifl_name in a subscriber management environment. In earlier releases, these syslog messages displayed incorrect messages in a subscriber management environment when you enable SCFD (suspicious control flow detection).

    [See Control Plane DDoS Protection Flow Detection Overview.]

  • Previously, shaping of Layer 2 pseudowires did not work on logical tunnel interfaces. This has been fixed for all platforms except QX chip-based MICs and MPCs.

Routing Protocols

  • TI-LFA and Legacy LFA Configuration Commit Validation Update (Junos OS and Junos OS Evolved)—You can now enable TI-LFA and legacy FRR (node-link-protection) in separate OSPF instances. The system generates a commit error only if you enable both TI-LFA and legacy FRR under the same OSPF instance. In that case, the commit fails and triggers the following message: "error: commit failed: (statements constraint check failed)".

    [See Topology-Independent Loop-Free Alternate with Segment Routing for IS-IS and OSPF.]PR1718886

  • BGP Multipath route calculation—When configuring multipath in the routing-instance, BGP routes that are inactive due to cluster-list length are also considered as eligible for multipath calculations. This enhances route selection by including more potential paths in your multipath configuration.

    [See Understanding BGP Path Selection.]PR1719797

  • Prior to this change the output of the "show isis spring flex-algorithm | display xml" command was invalidly formatted when multiple flex algorithm instances were configured. With the change, the XML output is properly structured showing flex algorithm information for each instance. A new XML tag "isis-spring-flex-algorithm" is added to bundle information for each instance.

  • Correction in show bgp neighbor Output (Junos OS and Junos OS Evolved)—We corrected a typo in the show bgp neighbor command output where configrued was displayed instead of configured. We've also added the existing option AcceptedPrefixLimit to the output so it displays when configured. This improvement ensures accurate display of the configuration settings and provides additional information for monitoring and managing BGP neighbor configurations.

    [See show bgp neighbor.]PR1740982

  • BGP Neighbor Telemetry Statistics (Junos OS and Junos OS Evolved)—BGP neighbor statistics reported through telemetry are now always aggregated, regardless of whether rib-sharding is enabled. Previously, when sharding was active, statistics were streamed per shard. With the current behavior, sensors are installed appropriately, and statistics are aggregated in the main thread before being streamed. The controllers and collectors now receive a single, unified view of BGP neighbor statistics. PR1765189

User Interface and Configuration

  • Port Mirroring Configuration Update—Interface ranges are no longer supported as part of configuration groups for creating analysers. If you attempt to use an interface-range in a config group, you will encounter an error indicating an invalid interface type. Additionally, interface ranges or interface lists cannot be configured under this setting. This change ensures precise and error-free configuration by requiring the specification of individual interfaces rather than ranges, thus improving the accuracy and reliability of port mirroring setups. PR1728883

  • Viewing files with the file compare files command requires users to have maintenance permission] -- The file compare files command in Junos OS and Junos OS Evolved requires a user to have a login class with maintenance permission.

    [See Login Classes Overview.]

VPNs

  • Enhancement to MVPN Sender Site Configuration—Multicast Virtual Private Network (MVPN) sender sites configured with an Ingress Replication (IR) tunnel send Type 1 routes with label 0. This means that remote PEs do not add the Type 1 route as a leaf of the tunnel but will still add the sender site PE as MVPN neighbor. This ensures that traffic from the sender site PE is not dropped by the remote PEs due to unknown MVPN neighbor. But since the sender site PE sends the label as 0, remote PEs will not add the sender site PE as a leaf and traffic from the remote PE will not be replicated to this PE ensuring sender site functionality.PR1711769