What's Changed
Learn about what changed in this release for MX Series routers.
General Routing
-
Changes to default behavior under forwarding-table (MX Series)—The
ecmp-fast-rerouteandindirect-next-hop-change-acknowledgementscommands are enabled by default under the[edit routing-options forwarding-table]hierarchy. You can verify these defaults by running theshow configuration routing-options forwarding-tablecommand in the operational mode.[See ecmp-fast-reroute .]
-
SSH key options for user account credentials. You can configure key-options key-options option at the
[edit system login user user authentication [ssh-rsa|ssh-ecdsa|ssh-ed25519] ssh key] hierarchy level.[See login.]
-
Transceiver name required for configuring temperature thresholds (MX304)—You must use the transceiver name instead of the interface name when configuring temperature threshold values on devices with optic modules. This change applies to the output of several show commands, including those for chassis alarms, environment, and temperature thresholds. It ensures accurate identification and configuration of temperature-related settings for optical transceivers.
[See temperature-sensor,show chassis temperature-thresholds, show chassis environment, show chassis alarms, and request interface optics reset.]PR1840314
-
Licensing (MX Series)—The PWHT for Layer 3 VPNs or BNG feature moved from Premium tier to Advanced tier.PR1843429
-
Deprecation of jnxLEDTable—The jnxLEDTable table is no longer supportedPR1848057
-
A new counter "Sessions hit due to high rate" is added to
show services service-sets screen-session-limit-counterscommand for all subscriber traffic. This counter tracks the sessions that come up on the screen irrespective of the "alarm-without-drop" configuration. When "alarm-without-drop" option is disabled, all the counters display updated statistics. When "alarm-without-drop" is enabled, then, the screen-drop counters onshow services service-sets statistic screen-dropcommand do not increase. The "sessions hit due to high rate" value is displayed.[See alarm-without-drop (IDS Screen Next Gen Services), show services service-sets statistic screen-drops (Next Gen Services), and show services service-sets statistic screen-session-limit-counters (Next Gen Services).]PR1849594
-
The
show subscribers extensive client-type dhcp | display xml validatecommand has now been updated to display correct output instead of theDuplicate data elementerror message. -
SFP Optics LOS alarms (MX Series)—SFP Optics don't support Tx laser disabled alarm, Tx loss of signal functionality alarm, and Rx loss of signal alarm as diagnostics output.
-
G.8275.1 profile configuration with PTP, SyncE, and hybrid mode (Junos)]—On all Junos OS platforms, when configuring the G.8275.1 profile, it is mandatory to configure Precision Time Protocol (PTP), Synchronous Ethernet (SyncE), and hybrid mode. Earlier, the system would not raise a commit error even if the required hybrid and SyncE configurations were missing while configuring G.8275.1 profile. However, going forward you will not be able to configure the G.8275.1 profile without configuring PTP, SyncE and hybrid mode to be compliant with the ITU-T standards.
[See G.8275.1 Telecom Profile.]
-
Extension of traceoptions support for VLANs in IGMP/MLD snooping—The
traceoptionsoption is supported under the[edit routing-instance protocols igmp-snooping vlan]and[edit routing-instance protocols mld-snooping vlan]hierarchy.traceoptionscan be enabled for both specific and all vlans.[See vlan (IGMP Snooping) and vlan (MLD Snooping).]
-
Validation of /vm-primary mount during JDM installation or upgrade (Junos Node Slicing External Server Deployment)—During installation or upgrade of the Juniper Device Manager (JDM) on external servers running Junos Node Slicing Release 25.2 or later, an issue occurred with the validation of the /vm-primary mount that stores the GNF images. When /vm-primary was mounted using logical volumes (LVM), JDM would fail to detect that the underlying storage was an SSD. This issue is now fixed. However, the fix introduces a new dependency on the LVM2 package in the host OS. This package is included by default in standard installations of both RHEL and Ubuntu external servers. However, it is advised that you check if the
LVM2package is already installed on the host before installing or upgrading JDM.PR1877593 -
You can monitor chassis temperature on MX Series devices at Flexible PIC Concentrator (FPC) level as well using the
show chassis alarmscommand, which displays a minor, major or critical alarm, "Temperature Warm" when the FPC exceeds the configured warm threshold temperature. PR1877621 -
On the MPC7E-10G line card, when you configure the 10-Gigabit Ethernet ports to operate as 1-Gigabit Ethernet ports, use the speed statement at both the
[edit interfaces interface name gigether-options]and[edit interfaces interface name]hierarchy levels.PR1879198 -
log-tag functionality—The log-tag functionality is introduced in
set services service-set.PR1885614
Network Management and Monitoring
-
Deprecation of shell option—The
shelloption no longer requires a separate configuration and is now the default behavior. Deprecating the shell option enhances efficiency and simplifies management tasks. -
Shell Command Logging Enhancement—All shell commands executed on the device and root sessions are now logged by default. This enhancement ensures enhanced security and auditability by capturing all commands entered in any shell environment, preventing bypassing audit logging.PR1867216
Routing Protocols
-
SNMP Trap Behavior Honors Logical-System Hierarchy (All Platforms)—The
snmp-options backward-traps-only-from-establishedconfiguration now correctly applies when set under a logical system. In earlier releases, the setting needed acommit fullor a corresponding global configuration to take effect. Logical-system-specific values are activated with a standardcommitand don't depend on global scope.PR1837269 -
RTC Route Display Fixed (Junos OS and Junos OS Evolved)—The latest update corrects the display issue for RTC routes associated with transport targets in BGP
showcommand output. Earlier versions failed to format (pretty-print) those routes correctly in theshow routeandshow route table bgp.rtarget.0 protocol rtargetoutputs, leading to readability problems. This enhancement now presents RTC routes in a clear format, making routing table inspections and troubleshooting more efficient.PR1839269 -
Multipath Prioritization Feature Now Visible (All Platforms)—The multipath-prioritization capability, previously hidden within the configuration hierarchy, is now exposed for direct use. This direct access enables operators to manage path-selection behavior and optimize traffic flow across multiple routes. The newly exposed feature also improves operational clarity for multipath routing deployments.
[See multipath (Protocols BGP) and prioritization.]PR1847793
-
Peer Auto-Discovery Configuration Validation—A new commit-time validation check has been introduced for BGP peer auto-discovery configurations. This check ensures that required address parameters remain correctly configured when modifying BGP groups that use peer auto-discovery, preventing invalid configurations that could lead to unexpected behavior. Specifically, when peer auto-discovery is enabled, either extended-nexthop or local-ipv4-address must be configured to ensure correct next-hop advertisement in BGP updates carrying IPv4 prefixes sent by dynamically discovered peers. The validation prevents the removal of the extended-nexthop statement unless local-ipv4-address is explicitly configured. If neither option is present, the commit is rejected. This enhancement improves the robustness of BGP auto-discovery peering setups by detecting invalid configurations at commit time, reducing the risk of operational issues and improving overall system stability during configuration changes.PR1850469
-
Holddown Route definition—A holddown route is redefined as a Route that is in pending delete state because a protocol has an existing interest bit set on it.
[See show route.]PR1853954
-
Modification of SRTE Advertisement Policy Name Display—BGP will now not generate and not display the "Advertised Policy Name" field for BGP-SRTE routes in show command output when the "Name TLV" is not received in the tunnel encapsulation attribute with the BGP-SRTE NLRI. The field will only be displayed when the "Name TLV" is received. This update eliminates ambiguity by ensuring multiple NLRIs do not display the same policy name, providing clearer and more accurate route information in command outputs.PR1853958
-
BGP Task Progress Monitoring—The
show task jobs extensivecommand now displays progress for BGP-specific jobs including BGP init policy walk, BGP group join, BGP Peer Reconfig, New policy flash update, and BGP RIB reconfig. This provides network administrators with detailed visibility into BGP task completion status, improving operational transparency and diagnostics.PR1857368 -
Behavior change for multihop eBGP sessions (MX960)—When a multihop eBGP session with a directly connected peer goes into IDLE state due to no local interface being present, the system now does a hard reset instead of handling it as a configuration change. This change ensures that the session and associated routes are reset promptly, improving the timeliness and accuracy of routing updates. This adjustment is important for maintaining the stability and efficiency of your network routing, especially in scenarios involving interface deactivation or removal.PR1869927
Subscriber Access Management
-
You can configure VLAN termination cause codes to specify RADIUS attribute values for different termination scenarios on Junos OS MX platforms supporting the Layer-2 Bitstream Access (L2BSA) feature. You can diagnose and manage network issues effectively by understanding the specific reasons for VLAN termination. Ensure that the correct termination cause codes are sent by validating configuration and testing scenarios to correctly interpret network events. When a subscriber logs out, the system occasionally sends an incorrect termination cause value to RADIUS. The subscriber VLAN "Account-Terminate-Cause" in "Acct-Stop" message for different L2BSA subscriber logout error scenarios is modified to display correct reasons for termination.
[See VLAN Termination Causes and Code Values and show network-access aaa terminate-code.]
-
Addition of
message-authenticatorandno-message-authenticatorattributes underaccess radius-server,access profile radius-server, andsystem radius-serverhierarchies—Setmessage-authenticatorif you require the RADIUS server to include the Message Authenticator attribute in replies to Access-Request messages. Setno-message-authenticatorto not require that attribute.PR1871147
User Interface and Configuration
-
Access privileges for request support information command (ACX Series, EX Series, MX Series, QFX Series, SRX Series Firewalls, and vSRX Virtual Firewall)—The
request support informationcommand is designed to generate system information for troubleshooting and debugging purposes. Users with the specific access privilegesmaintenance,viewandview-configurationcan execute request support information command. -
Updated Annotate Command Behavior—The
annotatecommand now correctly handles multi-line comments that start with `#`. This change ensures that all lines of a multi-line comment remain comments, preventing unauthorized configuration changes when the configuration is committed, reloaded, or rollbacked. These improvements enhance security by mitigating potential privilege escalation attacks from users with limited configuration editing permissions.PR1868636 -
Changes to the
show system storagecommand output (ACX Series, EX Series, MX Series, QFX Series, and SRX Series)—We've updated theshow system storagecommand output to include only true (physical) storage and exclude any host/hypervisor level storage. In earlier releases, the output also includes a container/jail storage, which does not have a separate storage of its own.[See show system storage.]
-
Option to view combined disk space usage statistics for all configuration databases (ACX Series, EX Series, MX Series, QFX Series, SRX Series, and vSRX)—The
show system configuration database usagecommand provides themergeoption. When you include themergeoption, the command output displays combined disk space usage statistics for all configuration databases, including the static configuration database and all ephemeral configuration database instances. -
Enhanced Permission Checks for Rename/Copy Operations—New permission checks have been introduced for rename and copy operations within the configuration hierarchy. These checks parse the hierarchy being modified to ensure the user has the required permissions for the hierarchy and its sub-hierarchies. If permissions are insufficient, the operation will fail and a "Permission denied" error will be displayed. This enhancement ensures that configuration modifications are performed only by authorised users, improving security and preventing unintended changes to critical system settings.PR1882303
-
Stale ui-state.db data in persistent NETCONF sessions post-mgd restart—Existing NETCONF sessions might fetch stale data from ui-state.db after mgd -N restart. New sessions correctly map the refreshed database. Scripts must establish new sessions post-restart to access updated values. Functional configuration remains unaffected.
Script failures monitoring "local-host" NETCONF sessions—Scripts might fail when including "local-host" NETCONF sessions in monitoring operations. Internal sessions are now excluded from tracking. Scripts must filter out "local-host" sessions. No impact to internal application functionality.PR1888557