What's Changed
Learn about what changed in this release for EX Series switches.
EVPN
-
Flow-label configuration status for EVPN ELAN services The output for the
show evpn instance extensivecommand now displays the flow-label and flow-label-static operational status for a device and not for the routing instances. A device with flow-label enabled supports flow-aware transport (FAT) flow labels and advertises its support to its neighbors. A device with flow-label-static enabled supports FAT flow labels but does not advertise its capabilities. -
Updated output for
show route table—The output for show route table bgp.evpn.0 now displays L2 service TLV type. Previously, the output displayed the L3 service TLV. -
New enhancement "udp source port" for overlay ping and traceroute— In Junos OS releases prior to 22.4R1, you could not configure the udp source port in a ping overlay or traceroute overlay operation. You may now configure this value in an EVPN-VXLAN environment using hash. The configuration option hashwill override any other hash-* options that may be used to determine the source port value.
General Routing
-
New options for the
request system snapshotcommand (ACX Series, EX Series, MX Series, PTX Series, QFX Series, and SRX Series)—The request system snapshot command includes new options for non-recovery snapshots. You can include the name option to specify a user-defined name for the snapshot, and you can include the configuration or no-configuration option to include or exclude configuration files in the snapshot. By default, the snapshot saves the configuration files, which include the contents of the /config and /var directories and certain SSH files. -
When subscribing to the resource path /junos/system/linecard/environment, the prefix for the streamed path at the collector side was displaying as /junos/linecard/environment. This issue is resolved in Junos OS 23.1R1 and Junos OS Evolved 23.1R1 and the subscription path and the streamed path match to display /junos/system/linecard/environment.
-
The Ethernet link fault management process (lfmd) runs only when the link-fault-management protocol is configured.
-
XML tag in the get-system-yang-packages RPC reply changed (ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series, vMX, and vSRX)—The get-system-yang-packages RPC reply replaces the xmlproxy-yang-modules tag with the proxy-xml-yang-modules tag in the XML output.
-
Prior to this change the output of a show task replication | display xml validate returned an error of the form "ERROR: Duplicate data element (task-protocol-replication-name). With this change the XML output is properly structured with no validation errors. PR1711008
- Prior to this change the output of a
show task replication | display xml validatereturned an error of the form "ERROR: Duplicate data element . With this change the XML output is properly structured with no validation errors. Before this change the output of ashow task replication logical-system all | display xml validatecommand reported an error. After the change the output is correctly formatted with a "logical-system" root tag and no validation error occurs. The connectivity fault management process (cfmd) runs only when the Ethernet connectivity-fault-management protocol is configured. -
Advertise inactive local RIB paths in BMP—We have introduced a new configuration statement
bmp-loc-rib-add-pathat the[edit routing-options bmp]hierarchy level. -
Previously, if the system failed to install an interface or hierarchical policer, the PFE crashed due to an assert. Now, the system installs a firewall discard and logs a DFW_HALP_ERR_MSG_POLICER_ADD_FAILED error message. This error message provides the name of the affected policer and the corresponding error code. Relevant policers appear under the interface > unit > family > policer input/output (or) interface > unit > family > input-hierarchical-policer stanzas.PR1701676
-
In the past inet6flow.0 was not allowed to be a primary rib in a rib-group. Starting with Release 22.3 this is now allowed.PR1716840
Network Management and Monitoring
-
Changes to Aggregate Level Policer at FPC (EX9208)—The summation of newly added sub-policers HELLO and UNCLS for DDOS protocols OSPF, OSPFv3, and RSVP result in the correct reporting of counters at the FPC level, for example, packet drops. Earlier, you could configure the OSPF, OSPFv3, and RSVP aggregate policer at the FPC level directly. You can use the following CLI statements to configure the burst and bandwidth values for OSPF, OSPFv3, and RSVP.
-
operatorlogin class is restricted from viewing NETCONF trace files that areno-world-readable(ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series, vMX, and vSRX)—When you configure NETCONF tracing options at the[edit system services netconf traceoptions]hierarchy level and you restrict file access to the file owner by setting or omitting theno-world-readablestatement (the default), users assigned to theoperatorlogin class do not have permissions to view the trace file.PR1707820 -
set system ddos-protection protocols ospf ospf-hello burst size bandwidth packets-per-second
-
set system ddos-protection protocols ospf ospf-uncls burst 10000 bandwidth 10000
-
set system ddos-protection protocols ospfv3v6 ospfv3v6-hello burst 10000 bandwidth 10000
-
set system ddos-protection protocols ospfv3v6 ospfv3v6-uncls burst 10000 bandwidth 10000
-
set system ddos-protection protocols rsvp rsvp-hello burst 10000 bandwidth 10000
-
set system ddos-protection protocols rsvp rsvp-uncls burst 10000 bandwidth 10000
[See Protocols (DDOS).]
-
operatorlogin class is restricted from viewing NETCONF trace files that areno-world-readable(ACX Series, EX Series, MX Series, QFX Series, SRX Series, vMX, and vSRX)—When you configure NETCONF tracing options at the[edit system services netconf traceoptions]hierarchy level and you restrict file access to the file owner by setting or omitting theno-world-readablestatement (the default), users assigned to theoperatorlogin class do not have permissions to view the trace file. -
Support for the
junos:cli-featureYANG extension (ACX Series, EX Series, MX Series, QFX Series, SRX Series, vMX, and vSRX)—Thecli-featureYANG extension identifies certain CLI properties associated with some command options and configuration statements. The Junos YANG modules that define the configuration or RPCs include thecli-featureextension statement, where appropriate, in schemas emitted with extensions. This extension is beneficial when a client consumes YANG data models, but for certain workflows, the client needs to generate CLI-based tools. -
XML tag in the
get-system-yang-packagesRPC reply changed (ACX Series, EX Series, MX Series, QFX Series, SRX Series, vMX, and vSRX)—Theget-system-yang-packagesRPC reply replaces thexmlproxy-yang-modulestag with theproxy-xml-yang-modulestag in the XML output. -
Support for the
junos:cli-featureYANG extension (ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series, vMX, and vSRX)—Thecli-featureYANG extension identifies certain CLI properties associated with some command options and configuration statements. The Junos YANG modules that define the configuration or RPCs include thecli-featureextension statement, where appropriate, in schemas emitted with extensions. This extension is beneficial when a client consumes YANG data models, but for certain workflows, the client needs to generate CLI-based tools.[See Understanding the Junos DDL Extensions YANG Module.]PR1713424
-
Changes to the NETCONF server's
rpc-errorelement when theoperation="delete"operation deletes a nonexistent configuration object (ACX Series, EX Series, MX Series, QFX Series, SRX Series, vMX, and vSRX)—We've changed therpc-errorresponse that the NETCONF server returns when the[edit-config]orload-configurationoperation usesoperation="delete"to delete a configuration element that is absent in the target configuration. The error severity is error instead of warning, and therpc-errorelement includes thedata-missingandapplicationelements. -
Changes to the NETCONF server's
rpc-errorelement when theoperation="delete"operation deletes a nonexistent configuration object (ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series, vMX, and vSRX)—We've changed therpc-errorresponse that the NETCONF server returns when the[edit config]orload-configurationoperation usesoperation="delete"to delete a configuration element that is absent in the target configuration. The error severity is error instead of warning, and therpc-errorelement includes theerror-tag data-missing error-taganderror-type application error-typeelements.PR1722578
Platform and Infrastructure
-
The
ping host | display xml validatecommand validates XML without error (ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series, and vMX)—In Junos OS and Junos OS Evolved releases prior to 22.4R2, theping host | display xml validatecommand results in CRITICAL ERROR: Root tag name mismatch. Expected 'ping-results', got 'run-command'. The command now validates the XML successfully without error.[See ping.]
-
Prior to this change, devices by default responded only to ARP requests originating from the same subnet. Configure the new CLI option,
respond-out-of-subnetat the[edit system arp]hierarchy level to allow ARP reply to a request that originates from a different subnet.
Routing Protocols
-
Addition of
nexthop-resolution no-resolutionoption for Route Target constrains (RTC) family—Thenexthop-resolution no-resolutionconfiguration option has been added to thefamily route-targetin BGP configurations. This addition allows users to disable nexthop-resolution for RTC family (AFI 1, SAFI 132) routes, and consider them usable for filtering of VPN-routes without depending on the RTC route's nexthop reachability.[See family route-target].PR1690014
-
Prior to this change the output of the
show isis statistics interface interface_name | display xmlcommand used the XML tag "interface-name", which generated an error. With the change the XML output uses the tag "isis-interface-name".PR1712358 -
BGP Multipath route calculation—When configuring multipath in the routing-instance, BGP routes that are inactive due to cluster-list length are also considered as eligible for multipath calculations. This enhances route selection by including more potential paths in your multipath configuration.