What's Changed
Learn about what changed in this release for NFX Series devices.
VNF
-
Operational Access for Non-Root Users (NFX150, NFX250, NFX350)—New permissions enable non-root users to access VNFs through SSH, Telnet, and console connections. This enhancement enables more flexible and secure user management, allowing users other than root to perform necessary operational tasks on VNFs.
-
On the NFX and SRX series platforms, a peer device behind a NAT device may experience communication failure over the IPsec tunnel. This occurs if the NAT port number or IP address changes and the DPD 'always-send' is configured, causing the next DPD or rekey process to fail to update the port number in the existing tunnel NAT-T flow session. As a workaround, use the CLI, set security ike gateway gateway-name dead-peer-detection optimized.
-
Optimized dead peer detection for NAT-T (SRX Series Firewall and NFX Series)-When the NAT-T remote port changes, incoming Dead Peer Detection (DPD) from the peer device may create a new session, leading to session mismatches and traffic interruptions. To prevent this, you can enable optimized dead peer detection. Use the command set security ike gateway gateway-name dead-peer-detection optimized to ensure that any new session created during incoming DPD expires, and the existing tunnel NAT-T session is updated with the new port number, allowing traffic to resume. [See Understanding NAT-T.] <https://www.juniper.net/documentation/us/en/software/junos/vpn-ipsec/topics/topic-map/security-route-based-and-policy-based-vpns-with-nat-t.html>