Juniper Mist Government Cloud (GovCloud) operates within the AWS GovCloud (US) Regions. These regions are designed to host sensitive data and regulated workloads, ensuring compliance with stringent U.S. government security and compliance requirements. By leveraging AWS Government Cloud (US), Juniper Mist provides a secure and compliant environment tailored for U.S. government agencies, contractors, educational institutions, and other organizations handling sensitive workloads in the cloud. Currently, this environment is “Authorized” on FedRAMP and GovRAMP (previously known as StateRAMP) marketplace for Impact level “Moderate”.

This page lists the Juniper Mist updates released on US GovCloud in September 2026.

Simplified Operations

Monitor and troubleshoot live Zoom meetings

You can now monitor and troubleshoot live Zoom meetings directly from the Mist portal using the Live Debug feature. Live Debug is a real‑time monitoring and diagnostic tool that enables network administrators and support teams to observe ongoing Zoom meetings, analyze participant Quality of Service (QoS) metrics (such as latency, jitter, and packet loss), and correlate issues with client and site conditions. You can use it to investigate ongoing quality problems, proactively monitor critical meetings, and perform post‑incident analysis to confirm root causes and validate fixes.

The Live Debug feature is available in the Meeting Insights section on the Monitor > Service Levels page. To start a live debug capture, identify the meeting that needs troubleshooting and click the Process button.

image-20260330-065245.png

The captured debug data includes the key information such as meeting ID, number of participating devices, client MAC addresses, and per-client QoS metrics.

image-20260330-070211.png

For more information, refer to Monitor and Troubleshoot Live Zoom Meetings.

Critical Infrastructure Alert template- enabled by default for new organizations

When you create a new organization in Mist, the default alert template automatically includes all critical alerts recommended by Mist, with e-mail notifications to the organization administrator enabled by default. This ensures that every newly created organization has all critical alerts enabled, without requiring any manual configuration.

Similarly, when you create a new alert template within an organization, all critical alerts—along with e-mail notifications to the organization administrator—are enabled by default. The template also includes an Enable Mist Recommended Alerts button. This button remains disabled as long as all critical alerts are already selected. If you deselect one or more critical alerts, the button becomes active, allowing you to re-enable all critical alerts with a single click. You can use this button to quickly apply critical alert settings to existing templates.

image-20260527-054428.png

Unified upgrade orchestration for APs, WAN Edges, and Mist Edges

Unified firmware upgrade management through the Firmware Upgrades page (Organization > Firmware Upgrades) is now available for APs, WAN Edges (SSR and SRX devices), and Mist Edges.

image-20260707-060817.png

Below are the key features of the new organization-level Firmware Upgrades page:

  • Centralized scheduled upgrades—Schedule firmware upgrades from one place. Select target sites, firmware versions, rollout strategy, and schedule timing.

  • Auto-upgrade settings—Configure auto-upgrade policies for switches and WAN Edges at the org level, with the option to override at the site level.

  • Upgrade status tracking—Get real-time visibility into upgrade progress across device types.

  • Edit and cancel upgrades—Modify scheduled upgrades or cancel them.

  • Upcoming upgrade notifications—Device list views and site configuration pages alert administrators to pending upgrades.

As part of this enhancement, we have removed the Firmware Upgrade section from the Organization > Settings page.

Marvis

Enhancements to the Marvis Minis SLE page

We have introduced the following enhancements to enhance usability and provide clearer actionable insights:

  • Additional filtering options—Users can now filter the Marvis Minis SLE data by applications and VLANs. This enhancement allows for more focused analysis, enabling users to focus on specific network segments or applications most relevant to their needs.

    87938833-41dd-432d-af27-f565f7c4c566.png

For added granularity, users can also filter the data for a specific classifier.

  • Checkerboard chart visualization—The Marvis Minis SLE page now features a checkerboard chart that provides a quick visual summary of hourly validation test outcomes at the site level. Users can view the chart for a selected timeline, classifier, and delve into the specifics of each individual test for more detailed insights. You can also view the chart for a specific application or VLAN.

    image-20260327-061314.png

    Every cell on the checkerboard chart represents data from an hourly validation. By clicking on a cell, users can view the details of the tests executed, including its results.

    image-20260327-061508.png
  • Visibility into issue detection source—The Distribution and Affected Items tabs feature a new Source column, which indicates whether the issue detection occurred during a wireless or wired test.

    image-20260327-061658.png
  • Option to provide feedback on latency and packet loss data—We have provided an option to submit feedback about latency and packet loss detected by Marvis Minis at a site level for applications. You can report issues you encounter, undetected problems, or incorrect information.
    To access the feedback option, select a site and an application from the drop-down lists on the top of the Marvis Minis SLE page. You will find the feedback link available below the latency and packet loss graphs.

    image-20260402-061425.png

If your feedback pertains to a specific time range, simply select the relevant area on the graph. This action will open the feedback dialog box where you can enter your comments and observations.

Option to submit feedback on potential anomalies detected by Marvis

We are looking for feedback about potential anomalies detected by Marvis to enable ongoing enhancements to user experience. You can submit details about issues you encounter, as well as report undetected problems or incorrect information.

To submit feedback, use the feedback option located on the Potential Anomalies and Optimizations tab on the Insights page.

image-20260327-065007.png

New Marvis Action - DFS Optimization

We are excited to introduce DFS Optimization, a new self‑driving Marvis Action designed to bring greater visibility and intelligence to how the Mist Radio Resource Management (RRM) system handles Dynamic Frequency Selection (DFS) radar events and their effect on Wi‑Fi channel assignments.

DFS Optimization gives customers clear insight into how radar‑impacted channels are evaluated over the last seven days and how that activity influences channel selection. Channels are classified as follows:

  • Normal—Assigned as usual.

  • Limited use—Restricted due to recent radar activity.

  • Restricted—Avoided because of heavy radar activity to reduce service disruption.

  • Limited capacity—Used when high AP density and limited available spectrum require it, helping to reduce co‑channel interference and contention even under challenging DFS conditions.

DFS Optimization eliminates guesswork by showing which channels are impacted, why they are classified that way, and how RRM is adapting its channel decisions. In addition, the Radio Management page, accessible from the left navigation under the site options, displays the number of radios assigned to each channel in the 5 GHz spectrum. This provides at‑a‑glance visibility into channel utilization and helps you better understand how the network distributes load across the available channels. When you open the DFS Optimization action (under the Wireless category in Marvis Actions), you will see a detailed table that includes site, last DFS event, and current channel classification (Normal, Limited use, Restricted, or Limited capacity). Selecting View more reveals DFS audit details such as radar event history over the past 7 days across the impacted channels and the categorization applied to each channel.

New Marvis Action - Dynamic Capacity Optimization

The Dynamic Capacity Optimization is a self-driving Marvis Action added to the Wireless category. When self-driving is enabled for this Marvis Action, it automatically adjusts the AP radio band and bandwidth settings to improve the overall Wi-Fi performance. In collaboration with RRM, the Dynamic Capacity Optimization Marvis Action focuses on band selection and channel bandwidth optimization to mitigate issues such as capacity constraints, high channel utilization, high client usage, and cochannel interference.

The Dynamic Capacity Optimization Marvis action is triggered when Marvis detects either a significant number of APs with insufficient capacity or a single AP that is consistently overloaded. To address these issues, the Dynamic Capacity Optimization action can enable dual band operation on APs so they can serve clients on dual 5 GHz or dual 6 GHz with 2.4 GHz auto-cancellation to increase capacity. It can also increase channel width (for example, from 20 MHz to 40 MHz) where conditions allow to provide more throughput per radio.

image-20260402-093742.png

New Marvis Action - Rogue DHCP Server Detected

We have added a new self-driving Marvis Action called Rogue DHCP Server Detected under the Wired category. This action highlights unauthorized DHCP servers detected on EX Series access switches that have DHCP snooping enabled.

Marvis generates the Rogue DHCP Server Detected action after repeatedly observing DHCP offers from an unknown server and mapping the activity to a specific switch, port, VLAN, or site to confirm that it is an ongoing issue. When you enable the self-driving capability for this action, Marvis automatically disables the switch port used by the rogue DHCP server. Note that this only applies to access ports.

If self-driving is not enabled, you have the option to manually disable the port from the Marvis Actions page.  

image-20260402-095532.png

New Marvis Action - Mist Edge Anomaly

We have added a new Marvis Action called Mist Edge Anomaly under the Wireless category to highlight unusual traffic or tunnel behavior on a Mist Edge. Marvis leverages the telemetry data from the Mist Edges to detect and surface potential issues such as:

  • Abnormally low or huge spike in Tx/Rx traffic, which could indicate that traffic is not passing through the Mist Edge or a potential loop in the network.

  • Port/link errors potentially impacting connectivity and network performance.

  • Sudden drop in the number of AP tunnels terminating on the Mist Edge, suggesting that a large number of APs are unable to reach the Mist Edge.

image-20260403-111122.png

Enhancements to the Missing VLAN Marvis Action

The scope of Marvis Minis validations has been expanded to cover detection of missing VLANs. When Marvis identifies a potential missing VLAN issue in the network, it now automatically initiates Marvis Minis validations (provided Marvis Minis is enabled for your organization). Marvis Minis tests and validates connectivity along the suspected VLAN path to confirm if the VLAN is missing and highlights issues with supporting evidence. The View More link provides details from the Marvis Minis validations. 

image-20260403-053014.png

Potential Anomalies Metric for APs, Switches, and WAN Edges

We have expanded the potential anomaly visibility down to the device-level pages by introducing a new metric, Potential Anomalies, on the AP, Switch, and WAN Edge pages. Derived from the Marvis-detected potential anomalies, this metric represents the percentage of devices with no anomalies detected, providing visibility into both actionable and early-warning signals of issues.

To calculate this metric, Marvis evaluates the number of potential anomalies per device type:

  • If none of the devices have potential anomalies, the score is 100%.

  • If the devices have potential anomalies, the score decreases in proportion to how many devices are affected. For example, if a site has 10 APs and 2 of them have anomalies, the score is 80%.

Devices with potential anomalies are listed with a Troubleshoot button. Clicking the Troubleshoot button launches the conversational assistant with a pre-filled prompt such as “Troubleshoot <device> for last 7 days”, enabling you to view the detected anomalies without having to manually initiate troubleshooting.

image-20260402-090933.png

Detect Layer 2 loops from VLAN overlaps in campus fabric

Mist now automatically detects potential Layer 2 loops caused by VLAN ID overlaps between the EVPN overlay and the campus underlay on non‑core switches, especially when AP traffic is tunneled into Mist Edge.

image-20260402-060924.png

A VLAN ID overlap occurs when the same VLAN ID is used both as an EVPN overlay VLAN and as an underlay/access VLAN on non‑core switches (for example, on AP trunk ports). Such overlaps might cause the network to unintentionally create a parallel Layer‑2 forwarding path - one in the overlay and one in the underlay. This condition leads to bridging loops, broadcast storms, and service degradation. When Mist detects this issue at a site, it generates a site‑level event called Fabric Loop Detected. This event includes rich context so operators can quickly understand and fix the misconfiguration before it impacts user traffic.

New webhooks topics for Marvis Minis

Mist has introduced two new webhook topics for Marvis Minis - Minis Network and Minis Application. These topics are available under site‑level and organization‑level webhook settings. These webhook endpoints allow external monitoring systems to consume network‑focused and application‑focused Marvis Minis insights separately, enabling cleaner, more efficient monitoring.

image-20260402-061119.png

You will need a Marvis subscription (SUB-VNA) to subscribe to this webhook.

You can configure these webhook topics from the following pages:

  • Organization > Settings (organization-level settings)

  • Organization > Site Configuration > Site Name page (site-level settings)

Marvis Minis for wired networks

We are extending Marvis Minis validations to wired networks. By simulating a physically connected client, Marvis Minis assesses whether RADIUS, DHCP, ARP, and DNS services are operational. This eliminates the need to connect a physical client to a switch to troubleshoot VLAN reachability—a process that can be both time-consuming and labor intensive when numerous VLANs are involved.

The validations for wired networks are supported on Juniper EX switches running Junos OS version 25.4R2 and later. Marvis Minis runs hourly validations on every switch within a site. These validations focus on up to 16 VLANs, prioritizing those with the highest levels of client activity. To avoid overlaps, VLANs tested as part of the wireless network validations are excluded from the wired network validations. Management VLANs are not included in the validations. The validations can be triggered by events such as VLAN updates, WLAN template updates, and new switch onboarding.

Enhancements to the DFS Optimization Marvis Action

Marvis now classifies DFS optimization based on both radar activity and site capacity constraints, rather than radar events alone. This enhanced classification helps you understand how RRM performs optimization based on the site capacity. If a site has sufficient capacity, RRM deprioritizes the use of channels with repeated DFS radar detections.

The new classifications are as follows:

  • No DFS Optimization/High Capacity Constraint—RRM detects DFS radar activity, but does not perform optimization because the site is severely capacity-constrained. If a site does not have sufficient spare capacity, RRM has limited options to optimize channel assignments effectively as moving radios off DFS channels would impact performance. Thus, DFS channels remain in the overall site channel plan despite radar exposure. In such cases, optimization can be implemented only after additional capacity, such as 6 GHz is added.

  • Low DFS Optimization/Medium Capacity Constraint—RRM detects significant DFS radar activity, but moderate site capacity constraints limit how far the RRM can reduce DFS channel usage. RRM avoids the most affected DFS channels while keeping others in service to meet capacity needs. Additional capacity, such as 6 GHz, gives RRM more flexibility to move away from DFS-affected channels.

  • Medium DFS Optimization/Low Capacity Constraint—RRM detects significant DFS radar activity, and site capacity constraints are low. RRM moves most radios away from the affected DFS channels while retaining a limited number of DFS channels where necessary to support capacity.

  • Medium DFS Optimization/No Capacity Constraint—RRM detects moderate DFS radar activity, and the site has no capacity constraints. It can move radios from the affected DFS channels to more stable alternatives without affecting performance.

  • High DFS Optimization/No Capacity Constraint—RRM detects significant DFS radar activity, and the site has no capacity constraints. It moves radios from DFS-affected channels to stable non-DFS channels.

image-20260603-101357.png

The View More page now shows additional DFS optimization details.

image-20260603-101505.png

Marvis LEM experience correlation

The Marvis Large Experience Model (LEM) is an AI-driven model that predicts bad user experiences and ranks their root causes for collaboration applications such as Microsoft Teams and Zoom across the network. LEM is now available for all organizations even when Microsoft Teams or Zoom is not integrated as a labeled data source. Using a Shapley-based data science model, Marvis LEM processes all available data—such as channel utilization, RSSI, latency to cloud, and more—to highlight feature-level root cause contributions and identify bad user experiences. LEM requires a Marvis for Wireless subscription.

image-20260603-100008.png

Updates to Marvis Minis SLEs

We have updated the Application (now called Application Services) SLE classifiers to improve issue classification and provide more granular visibility across the application, LAN, and WAN domains. The following primary classifiers are now available, each with additional sub-classifiers to help pinpoint the exact nature of an issue:

  • Application—Indicates that the issue is isolated to a specific application or service, while the network path to the destination remains healthy. This classifier helps distinguish application-level problems from broader network connectivity issues.

  • LAN—Indicates that the issue is on the local network, specifically between the user’s device and the local gateway. This classifier covers problems related to local connectivity
     or switching within the LAN environment.

  • WAN—Indicates that the issue lies outside of the local network, specifically between the local gateway and the destination. This classifier includes problems related to external connectivity, ISP links, routing across wide-area networks, or upstream network disruptions.

    The LAN and WAN classifiers are classified only for APs running firmware version 0.15x and later.

image-20260527-102304.png

We have also added the following DNS sub-classifiers under the Network Services SLE:

  • Unresponsive

  • Lookup Failed

  • Latency

Latency insights for pre-connect network services

We have introduced a latency graph for the Network Services SLE on the Marvis Minis SLE page. This graph provides time-series visibility into the latency for the four pre-connect network services: DHCP, ARP, DNS, and RADIUS.

Marvis Minis already validates user connectivity by simulating pre-connect steps on active VLANs. With this enhancement, the latency data for each of the pre-connect steps is displayed as a time-series graph, enabling you to monitor network services performance over time.

image-20260527-101736.png

Marvis Minis goes global

The Marvis Minis application is now live. Marvis Minis running on devices validates application reachability and performance against a globally hosted Minis cloud application, served through a CDN. This enables Minis to measure network metrics as close as possible to your client VLAN's Internet gateways. Ensure that *.mist.com addresses are allowed and reachable through your firewall.

image-20260602-163404.png

Enhancements to Marvis Minis SLE checkerboard chart

We have made several usability improvements to the checkerboard chart on the Marvis Minis SLE page to make it easier to read, navigate, and understand test results:

  • Test outcome visibility—Hovering over a cell on the checkerboard chart now displays a tooltip with the exact count of successful and failed tests for that hour, providing quick visibility into test outcomes.

    image-20260713-084459.png
  • Clear visual states—Selected and hovered cells are now more visually distinct, with improved contrast for better readability and accessibility. It’s easier to identify the cell currently in focus.

  • Improved navigation experience—Clicking a cell now opens the detailed view with the selected hour clearly highlighted. You can seamlessly move to the previous or next hour directly from the detailed view, making it easier to analyze trends over time without having to return to the checkerboard chart for each selection.

    image-20260713-084413.png

Organization-Level application experience correlation (without Zoom or Teams integration)

Organization-level experience correlation is now available for organizations that have not enabled Microsoft Teams or Zoom integration. This view lists up to 100 worst-performing sites in the organization, ranked by total bad minutes in descending order (highest at the top), and excludes any sites with zero bad minutes. The page shows the total user minutes, the time impacted by poor user experience, and categorizes bad minutes by source, enabling you to determine whether issues are related to the WAN, wireless network, or client devices.

In the Mist portal, navigate to Monitor > Service Levels > Application and select Entire Org to access this view.

image-20260720-055308.png

You can also click each site to see how the bad minutes are distributed across APs and clients. This helps you to quickly identify which APs or clients are experiencing more issues.

image-20260720-055603.png

Intra-AP Roam visibility in Shapley Feature Ranking

The Shapley Feature Ranking graph for Zoom and Microsoft Teams application experience now includes Intra AP Roam as a wireless feature. An intra-AP roam occurs when a wireless client switches between radios on the same AP—for example, moving from the 2.4 GHz band to the 5 GHz band or moving between dual 5 GHz bands on the same AP.

Intra-AP Roam provides visibility into how these intra-AP roaming events contribute to bad user minutes during Zoom and Teams calls. This helps you to assess whether the radio power or channel width on each radio band of an AP is causing intra AP roaming and impacting call quality.

You can view this on the Monitor > Application page under the Experience Correlation tab.

image-20260721-165251.png

Wireless Assurance

GPS‑based geolocation visibility for Wi‑Fi 6E and Wi-Fi 7 APs

Juniper Mist now provides GPS‑based geolocation visibility for supported access points equipped with built‑in GNSS/GPS radios. When GPS data is available, Mist automatically displays APs' latitude and longitude coordinates across the AP List page, AP Details page, AP Insights, and the Location Live View. This enhancement provides administrators with location information determined by APs using GPS signals at their location.

image-20260408-035945.png

Configurable antenna beam pattern for AP66D

For AP66D access points (APs), you can now select an antenna beam pattern in the Mist dashboard RF Templates (Organization > RF Templates) for the 5 GHz and 6 GHz bands. With the improved signal control, you can better align the RF signal to the shape of your physical environment. The beam patterns are: Wide (90° × 90°), Medium (30° × 90°), and Narrow (30° × 30°). The Wide beam pattern is useful in open areas, while Medium directs coverage along one dimension, such as a row, and Narrow concentrates RF coverage into a specific zone.

image-20260414-024910.png

For more information, refer to RF Template Configuration.

Configurable antenna modes for AP36M

For AP36M access points (APs), you can now select the antenna modes you want, Internal or External, in the Mist dashboard RF Templates (Organization > RF Templates). Internal antennas are best in deployments where omni-coverage from the AP’s mounting location is sufficient and installation simplicity is a priority, such as offices, classrooms, and open areas. External antennas provide more options in challenging deployments, such as long corridors, high-ceiling venues, and areas that require directional or specialized antennas.

Note: Changing the antenna mode on AP36M requires an AP reboot, so you should plan to do your changes during a maintenance window.

image-20260414-024700.png

For more information, refer to RF Template Configuration.

AP45E, AP66, and AP66D support 6 GHz Standard Power via AFC

To help enterprises extend high-performance Wi-Fi to 6 GHz without causing interference to existing spectrum users, we have introduced Automated Frequency Coordination (AFC) support for Mist access points (APs) with external antennas and outdoor APs that can operate in 6 GHz band. With AFC integration, Mist APs can operate in the 6 GHz band as per standard power transmission regulations where allowed, ensuring stronger and faster Wi-Fi connections—particularly in outdoor and mixed-use environments.

The following Mist APs now support 6 GHz Standard Power operations in the US Region:

  • AP45E

  • AP66

  • AP66D

When Standard Power is enabled, these APs and associated clients can communicate at higher allowed power levels on the 6 GHz band for enterprise deployments, improving coverage and performance. For this feature to work, APs must be able to determine their location either natively (built-in GPS) or through neighboring peers with GPS capability. AFC enables dynamic frequency and power allocation based on APs' real-time location. Firmware version 0.15 or later is recommended for optimal performance and full feature support.

In Mist, you can view the geolocation or latitude and longitude data for the AFC-enabled APs on the following pages AP list page, AP details page, AP Insights, and Location live view.

Note that the AP64 and AP47E already support 6 GHz operation.

Channel utilization insights per radio

A new Channel Utilization visualization is now available on the AP Insights page and Marvis Query Language (MQL) screens, providing a detailed per-channel, per-radio breakdown of how airtime is being used. This gives network administrators granular visibility into the sources of channel utilization across 2.4 GHz, 5 GHz, and 6 GHz bands, enabling faster identification of interference issues and capacity constraints.

On the AP Insights page, each channel's total utilization is shown as a color-coded bar. Click any channel bar to expand an inline breakdown showing the utilization distribution by source such as upload, download, Wi-Fi interference, and Non-Wi-Fi interference.

image-20260602-164151.png

You can also use the Marvis query UTILIZATIONOF <AP MAC> DURING <Time Duration> to get channel utilization insights across the following three tabs:

  • Total—Aggregated utilization over time for all bands (2.4 GHz, 5 GHz, 6 GHz).

  • Channels—Per-channel utilization for each band.

  • Breakdown—Detailed source-level breakdown per channel (upload, download, Wi-Fi interference, and Non-Wi-Fi interference).

image-20260602-164050.png

ASSA ABLOY Vingcard door lock integration with Mist

You can now connect ASSA ABLOY Visionline wireless locks directly to Mist AP36 access points and Mist Edge over Zigbee, eliminating the need for dedicated Zigbee gateway hardware. Mist AP36 acts as the native Zigbee gateway, while Mist Edge provides secure on-premises backhaul. Visionline remains the system of record for lock management, credentials, and access control policies.

Using Mist's AI-driven cloud platform and existing wireless infrastructure, the integration provides centralized monitoring, real-time lock telemetry (status, RSSI), dashboards and alerts without changing existing Visionline workflows. All data plane traffic remains on-premises with end-to-end encryption and secure Zigbee pairing.

The solution scales to 32 locks per AP and approximately 2,000 locks per site, delivering secure, enterprise-grade connectivity and simplified deployment. This is currently supported on AP36 only.

image-20260812-123743.png

Wired Assurance

Zero Trust Inline Segmentation

Mist now supports Zero Trust Inline Segmentation (ZTIS) which allows microsegmentation even in simple branch deployments without requiring an EVPN fabric.

Traditionally, micro segmentation has been exercised in the campus fabric IP Clos deployments. ZTIS simplifies micro segmentation by enforcing security policies inline at the access layer in branch deployments, eliminating the requirement for L3 gateways at the access layer. It enables consistent, identity‑based segmentation across wired clients without the complexity of private VLANs, VXLAN group‑based policies, or EVPN fabric designs. It improves lateral threat protection by allowing granular control of traffic between clients and toward external networks.

ZTIS leverages a Group‑Based Policy (GBP) tag that uses IP, port, or protocol as match conditions. Policies are enforced using a source GBP tag and destination-based GBP tags within the same VLAN. ZTIS extends microsegmentation to traffic leaving the client VLAN by enforcing policies at the L2 access switches using source GBP tags with destination IP prefix and L4 port matching. You must apply ZTIS via switch templates (Organization > Switch Templates) for consistent and synchronized configuration across switches within a site.

image-20260504-141315.png

Notes:

  • ZTIS enforcement is supported on EX4400,EX4100,EX4650 and QFX5120 switches running Junos OS 25.4R1‑S1 or later (or 24.4R2‑S3).

  • Virtual switches VMs , including vJunos‑Switch, do not support ZTIS enforcement.

For more information, refer to ZTIS Configuration and Testing Examples.

Visibility into top DDoS packet sources for faster troubleshooting

For EX4100, EX4400, EX4000, and EX4100‑H switches running Junos OS 25.4R1 or later, Mist now offers enhanced visibility into DDoS protocol‑violation events. The Switch Events section on the Switch Insights page now displays the top packet sources contributing to each DDoS protocol violation, enabling faster analysis and more effective troubleshooting. The packet source information includes:

  • Protocol—The protocol associated with the violation.

  • MAC Address—The MAC address of the packet source that triggered the event. You can click the MAC address to navigate to the affected client.

  • IP Address—The packet source’s IP address, when available.

  • Count—The number of packets observed from that source.

image-20260331-061358.png

DDoS protocol‑violation events are triggered when host‑bound traffic for a specific protocol exceeds its configured bandwidth threshold. With the current enhancement, operators receive a clear, actionable list of top packet sources, along with one‑click navigation to affected clients, significantly improving the DDoS troubleshooting experience.

Switch policy enhancements for easier policy management and troubleshooting

We have enhanced the switch policy configuration with the following options:

  • Clone—Lets you use the parameters (source and destination) of an existing policy to quickly create a new policy with a single click.

  • Clear Policy Counters—Lets you reset the policy hit count and start from a clean slate when diagnosing issues. After making configuration changes, you can reset the counters and observe only the new policy hits, making it easier to confirm whether a rule is still being triggered.
    Note: This option is available only at the switch level (switch details).

  • Move Up/Move Down—Lets you reorder switch policies.

  • Enable or Disable—Lets you disable a policy without deleting it and re-enable it when needed.

image-20260416-095319.png

For more information on how to use these options, refer to Manage Switch Policies.

New switch metrics

We have added the following new switch metrics to the Switches page:

  • Switchport Usage—This metric helps you quickly assess the availability of switch ports. This metric displays the percentage of ports that are currently in use. You can hover over the metric icon to view a breakdown of total, active, and inactive port counts. If the switch port usage is at 90 percent or higher, the metric icon turns red to indicate that the number of ports available for use is low. This metric is available in both the site-level and organization-level view of the Switches page.

  • Config Success—This metric shows the percentage of switches that are currently in a configuration success state, providing quick visibility into overall network health. If the success rate is below 100 percent, you can click the metric to view the switches that are in a configuration failed state, enabling faster troubleshooting. A switch is marked as configuration failed when its most recent configuration event (within the past 7 days) has failed. This metric is already available at the site level, and we are now adding it to the organization-level view.

  • Potential Anomalies—Shows percentage of devices with no anomalies detected, providing visibility into both actionable and early-warning signals of issues. If none of the devices have potential anomalies, the score is 100%. If the switches have potential anomalies, the value decreases in proportion to how many are affected. If the percentage is less than 100%, you can click the metric to view the switches with anomalies.

image-20260407-053537.png

For more information, refer to Switch Metrics.

Switch time zone management

You can now configure a switch’s time zone using switch templates (at the organization or site level) or directly on an individual switch (at the switch level). This configuration is available under the Management section on the Switch Details page as well as within templates. This enhancement introduces the Use Site Timezone option, which allows you to configure a switch to automatically align its time zone with the site’s configured time zone.

image-20260417-045751.png

When this option is enabled and saved, the effective time zone is displayed on both the site and switch detail pages and is pushed to the device. If Use Site Timezone is disabled, the switch defaults to UTC. Note that the switch time zone configured via the additional CLI commands takes precedence over the time zone configured using the Use Site Timezone option.

Improvements to site variable configuration

To provide a more intuitive experience when working with site variable configuration, we have introduced the following enhancements:

  • VAR label next to supported fields—A VAR label now appears beside fields that support site variable configuration, making them easier to identify.

  • Autocomplete—When you begin typing a site variable value, the field now displays autocomplete suggestions in a drop‑down list.

  • Resolved values—For any field configured using site variables, the resolved value is displayed directly beneath it.

  • Warning about unresolved fields: If a site variable cannot resolve the configuration value, a warning message is displayed at the top of the configuration page.

image-20260326-104837.png

These fields already include help text that explains the site variable configuration format. With these new enhancements, configuring site variables is now simpler and more user‑friendly.

Improvements to Port List and Wired Clients views

We have enhanced the switch Port List view to deliver a more informative viewing experience and deeper operational insights. The improvements include new columns in the Port List and Wired Clients views, refined table controls, and usability enhancements.

  • Updates to columns and table settings—The switch Port List view (in Switch Insights and Switch Details), as well as the Wired Clients view, now support additional configurable columns. You can enable or disable these columns using Table Settings:

    • VoIP Network—Shows the VoIP VLAN configured on the port profile bound to the port.
      Note that this column is not applicable to the Wired Clients view.

    • VLAN (Assigned By RADIUS)—Shows the VLAN ID that the RADIUS server dynamically returned during the client authentication.

    • RADIUS Returned VoIP VLAN—Shows the VoIP VLAN that the RADIUS server dynamically returned for a wired client or port during authentication.

    • Dynamic Filter—Shows the name of a firewall filter (ACL) dynamically applied to the switch port during authentication. This filter is typically returned by the RADIUS server.

    • Auth Domain—Shows the authentication domain used for the client or port.

      image-20260406-070732.png

      We have also removed the option to enable or disable the Port column from the table settings of the Port list view, as the Port is essential information in this view.

  • Locked header row and Port column—The column headers and the Port column in Port List now remain in place as you scroll up, down, or side to side, making it easier to interpret port data without losing context.

    image-20260406-074608.png
  • Larger viewing window—The Port List view now has a larger window than it did previously. This allows you to view a fuller list, while reducing the overall amount you may have to scroll.

  • Filter option—A new Filter field in the Port List. You can use this search field to find any information regarding your switch ports, including information that is available in the additional columns in the Table Settings.

filter-search-field-switch-port-list--20260403-153921.png

Configure bridge priority at the organization level

You can now configure bridge priority at the switch template (organization) level. This configuration can be overridden at both the site and device levels, providing additional flexibility.

To configure bridge priority at the switch template level, navigate to Organization > Switch Templates > Template Name, and scroll down to the Select Switches Configuration section. From there, open an existing rule or click Add Rule to create new rule. Then, go to the STP Bridge Priority tab, and select the desired Bridge Priority value.

image-20260403-061905.png

Note: Bridge priority that was configured using Additional CLI commands takes precedence over the value selected in the UI.

Switch-level configuration conflict detection

When multiple administrators edit the same switch configuration simultaneously, the system now detects conflicts and prevents one user from inadvertently overwriting another’s changes. If you attempt to save a switch configuration that has been modified by another administrator since you loaded the page, a Configuration Conflict pop-up window appears. This alert informs you that the configuration has changed. You can then refresh the page to load the latest configuration and reapply your changes, ensuring that no work is silently lost.

This feature applies to all configuration fields on the Switch Detail page, including port configuration, network settings, port profiles, static routes, NTP, DNS, routing policies, and more. It works across all administrator roles and browser sessions.

image-20260527-063447.png

Push port descriptions from port profiles to devices

You can now push port descriptions defined in port profiles directly to your switches using the Use Port Description From Port Profile toggle in switch settings. Enable the Use Port Description From Port Profile toggle in the Management section of the switch details page or a switch template to apply the port profile description to the device configuration—making it visible in CLI outputs such as show interfaces descriptions. Previously, port profile descriptions were used only for display purposes in the Mist portal. If a port-level description is also configured for an individual port, it takes precedence over the port profile description.

image-20260527-071706.png

Ping test utility enhancements — IPv6 and VRF support

The ping test utility under Switch Testing Tools now supports IPv6 addresses and VRF (Virtual Routing and Forwarding) input, giving network administrators more flexibility when troubleshooting connectivity from managed switches. You can find Switch Testing tools under Utilities > Testing Tools on the switch details page.

image-20260528-044315.png

Aggregate route configuration for switches

You can now configure aggregate routes on individual switches and within campus fabrics. Aggregate routes summarize multiple specific routes into a single, broader route prefix, reducing the number of routes advertised to upstream devices. At the switch level, you can configure aggregate routes from the new Aggregate Route tile in the Routing section of the switch details page (Switches > Switch Name). You can configure the destination prefix, routing metric, route preference, and discard behavior for each aggregate route.

image-20260706-084542.png

To advertise aggregate routes to external peers (for example, via BGP), configure a routing policy with aggregate as the matching protocol and the aggregate prefix as the route filter.

In campus fabric deployments (IPCLOS, ERB, and CRB), aggregate routes are used to summarize internal fabric routes for advertisement to external peers like firewalls or WAN routers. The VRF tile on the Network Settings tab of the campus fabric page (Organization > Wired > Campus Fabric) now has a Loopback Per-VRF IPv4/IPv6 field. When you define a Loopback Per-VRF IPv4/IPv6 Subnet for a VRF, Mist automatically creates a matching aggregate route for that entire subnet. You can also manually include additional aggregate routes per VRF.

image-20260723-165343.png

Mist automatically pushes aggregate routes only to devices designated as border nodes or to core nodes (if the fabric has no border node), ensuring that route summarization occurs only at the fabric's external edge. Aggregate routes configured at the campus fabric level appear as read-only on individual switches that are part of the fabric and cannot be modified from the switch details page.

Switch reboot scheduling now available without firmware upgrades

You can now schedule reboot-only operations for switches through the Firmware Upgrades page (Organization > Firmware Upgrades), without requiring a firmware upgrade. This enables you to orchestrate planned switch reboots—for example, to apply configuration changes that require a reboot or to perform routine maintenance—during a scheduled maintenance window.

image-20260708-051027.png

You can either reboot switches immediately or schedule a reboot for a future date and time. You can target specific switch models for the reboot, and you can use match criteria (switch name, switch role, or campus fabric role) to further narrow the scope.

You can also cancel scheduled reboots or edit the reboot date from the Reboot Only section of the Firmware Upgrades page.

For more information, refer to Create Reboot-Only Schedules for Switches.

Device-level variables for switch configuration

Mist now supports switch-level configuration variables. These variables allow you to apply unique configuration values per switch, even when multiple switches are associated with the same template.

Device variables are similar to site variables, except that they are scoped to a specific switch rather than a site. You can define them as key-value pairs and reference them in configuration fields using the {{variable_name}} syntax.

A new Device Variables tile is available in the Management section of the switch details page (Switches > Switch Name). You can add, delete, and import device variables from this block.

image-20260723-164913.png

When you type {{ in a supported configuration field, an autocomplete drop-down displays both device variables and site variables. If a device variable has the same name as a site variable, the device variable takes precedence.

You can also import device variables in bulk using a CSV file, following the same format as site variable imports. For more information, refer to Configure Switch-Level Variables.

Additional client properties on the wired client Insights page

The wired client Insights page now displays additional client properties, providing enhanced visibility into wired client details without leaving the Insights view. Previously, these details were available only as optional columns on the Wired Clients list page.

The following new properties are now shown in the Client Properties section on the wired client Insights page (Monitor > Service Levels > Insights > Wired Client): Username, VLAN, Manufacturer, Authentication State, Authentication Method, Auth Domain, DHCP Hostname, DHCP Vendor Class Identifier, DHCP FQDN, DHCP Client Identifier, Dynamic Filter, and RADIUS Returned VoIP VLAN.

image-20260706-083318.png

The DHCP-related fields require DHCP snooping to be enabled on the switch and are supported on devices running Junos version 23.2 or later. The authentication-related fields are populated for clients that authenticate through 802.1X or MAC-RADIUS.

Additionally, the switch name shown under the Connection Status section under Client Properties is now a clickable link that navigates directly to the switch detail page.

Wired client Insights data for disconnected clients

The wired client Insights page now displays historical time-series charts, switch events, wired client events, and the last known port or ports for clients that are disconnected from the switch. Previously, these sections appeared empty when a wired client went offline, even though the underlying data was available.

When you open the Insights page for a disconnected wired client (Monitor > Service Levels > Insights > Wired Client), the page now uses the client's last known switch and port information to load the data. Note that for clients that were connected through aggregated Ethernet (LAG), the port selector on the client Insights page lists all the trunk ports.

image-20260710-060416.png

Expanded AE Index range for improved scalability

We have expanded the supported AE (aggregated Ethernet) index range from 0–255 to 0–4091 for non–campus fabric switches, providing network administrators with greater flexibility when configuring link aggregation groups.

The AE index input field now accepts values from 0 to 4091 across switch, site, and organization levels. You can find the AE Index field in the Port section of the switch details page or on the Port Config tab under Select Switches Configuration of a switch template (organization or site level).

The AE index is a numeric identifier used to designate an aggregated Ethernet interface on switches and similar platforms. Expanding the AE index range ensures that administrators do not encounter index limitations. Note that campus fabric switches continue to use the existing 0–255 AE index range.

image-20260527-092305.png

MAC-VRF Architecture for New Campus Fabrics

Juniper Mist Campus Fabrics now default to MAC-VRF routing instances for all new fabrics created after this update. This change updates only the configuration pushed from the cloud to the devices, ensuring advanced multi-tenancy and unified EVPN services without changing the cloud UI experience. Existing fabrics are unaffected, and all older deployments will continue to operate as usual with no operational impact. The Mist cloud uses the vlan-aware instance type for MAC-VRF configuration. For more details, see MAC-VRF Routing Instance Type Overview | Junos OS | Juniper Networks.

WAN Assurance

WAN Topology Builder - Support for Hub and Spoke topology

The WAN Topology Builder now supports hub and spoke topologies. This enhancement provides a single place to see all the configured Overlay Paths as well as customize Overlay Setting when required. A hub and spoke WAN topology is a design where hub sites act as the central aggregation points, while spoke sites connect primarily to the hub (rather than building tunnels to every other site).

The hub and spoke topology is created as a standardized OrgOverlay. Only one hub and spoke topology can exist per organization. If a hub and spoke topology already exists, such as for existing customers, Mist does not allow the creation of an additional one. To ensure consistency across site deployments, the topology name (OrgOverlay) is system-generated and cannot be customized. Within the topology, you can configure the following overlay parameters: Overlay IP subnet (SSR only), BGP AS, and IPv6 enablement (SSR only).

image-20260413-165528.png

The BGP AS should be customized only when the default AS conflicts with your existing environment, or when additional considerations, such as overlapping AS numbers, require a different configuration.

Enhancements to WAN path statistics

We have enhanced the statistics view on the WAN Edge Insights page to make it easier to view and assess probe statistics. This update introduces a renaming of the section from Peer Path Stats to Probe Stats.

We have also added a new WAN Probes tab, where the jitter, loss, and latency data are presented in a time series format. This new tab features a dropdown menu, where you can select an interface to see probe stats for. The WAN Probes tab is now the default view of the Probe Stats section, making it easier to assess WAN probe health.

This update also introduces new naming to the pre-existing tabs:

  • Worst 3 Peer Paths tab has been renamed Worst 3 Overlay Paths.

  • Peer Paths tab has been renamed Overlay Paths.

These tabs still display the same data as they did previously, and you can drag your mouse across any of the graphs to get detailed data as before.

For information on how to configure real-time performance monitoring (RPM) probes for monitoring WAN link health, see Customizable IPv4 and IPv6 RPM probe configuration and WAN Settings.

New VPN tunnel up alert

You can now configure Mist to alert users to an SRX or SSR IPsec VPN tunnel up event. You can configure the Tunnel Up alert from the Monitor > Alerts page. This alert gives operators a clear, time‑stamped confirmation that connectivity has been restored. Previously, the Alerts page only reported Tunnel Down conditions, while Tunnel Up was visible only as an event under Insights. This enhancement aligns outage and recovery visibility, improving troubleshooting, post‑incident verification, and operational auditing.

image-20260414-162457.png

View resolved values for site variables

On the WAN Edge device details page, you can see the resolved value for fields configured with site variables by hovering over the field.

image-20260511-105707.png

For more information on site variables, refer to Use Site Variables to Streamline Configuration.

Support for SRX4120

Juniper Mist WAN Assurance now supports the SRX4120 as a WAN Edge device.

WAN Assurance simplifies all aspects of WAN Edge device management that include device onboarding, configuration at scale, and monitoring and troubleshooting. With WAN Assurance, you can monitor your WAN in real time and gain full visibility into its health and performance. You can see how your WAN Edge devices are doing, check out service level expectations (SLE) metrics, and even get insights into the end user experiences, among other things.

SFP transceiver visibility for WAN Edge devices

You can now view details of the SFP transceiver connected to your WAN Edge device interfaces directly in the device details page, including the SFP model, part number, and serial number. This information is displayed alongside other interface-level data, eliminating the need to SSH into devices and run CLI commands to identify installed optics. To view SFP transceiver details, navigate to the WAN Edge device details page (WAN Edges > WAN Edges > WAN Edge name) and hover over the port to which the SFP is connected. This feature improves operational efficiency by providing quick access to optics information directly from the Mist portal, reducing troubleshooting time and dependency on CLI access.

image-20260522-053359.png

Suggested firmware versions for SSR WAN Edge devices

The firmware upgrade page in Mist now highlights Mist-suggested firmware versions for Session Smart Router (SSR) WAN Edge devices, bringing feature parity with the upgrade experience available for SRX gateways and EX switches. These firmware versions have been validated and are considered optimal for production deployments. They are grouped under a Suggested category, which appears at the top of the version selector drop-down list on the upgrade page.

image-20260525-052935.png

Configure ATP cloud region in Secure WAN Edge Integration

Mist now supports selecting the ATP cloud region as part of Secure WAN Edge integration. You can configure the cloud region using the Cloud Name field on the ATP Cloud integration page
(Org Settings > Secure WAN Edge Integration > Add Credentials > ATP Cloud).

image-20260514-051231.png

Unified upgrade orchestration for WAN Edges

For more information, refer to Unified upgrade orchestration for switches and WAN Edges.

Extended application support, customizable app list, and introduction of show custom apps toggle for SRX SLEs

All curated applications that were previously available only on SSR are now fully supported for Application SLEs on SRX, providing feature parity between SSR and SRX for application-level SLE monitoring.

To configure this, go to Monitor > Service Levels, select the WAN tab, and click Settings. In the Settings pop-up, select the Application tab. You’ll see an expanded list of supported applications and an Add Application option that lets you add or customize the applications being tracked.

This enhancement gives you greater flexibility to select and monitor application-level SLE metrics for SRX devices.

Support for SRX400

Mist WAN Assurance now supports adopting the SRX4XX Series Firewall as a WAN Edge device at the branch, deployed in a standalone non-HA topology. The SRX400 is a next-generation firewall that includes security, switching, routing, and WAN connectivity in a single device. It also provides scalability, easy management, security, and advanced threat mitigation. Unlike traditional branch deployments that require multiple hardware components and manual provisioning, the SRX400 provides provisioning via the Mist cloud for accelerated setup.

The SRX400 Series Firewall includes the SRX400, SRX440, and SRX440-2AC models.

SRX400-for-rns.png

For more information, refer to the SRX400 Firewall Series for Branch Datasheet.

To onboard an SRX4XX Series Firewall into Mist, you must use the adoption workflow.

HTTP-based probes for WAN path viability monitoring (SRX)

Mist WAN Assurance now supports HTTP-based probes for WAN path viability monitoring on Mist-managed SRX devices. You can configure HTTP to determine whether a WAN breakout path is up. Because upstream providers may rate-limit or drop ICMP traffic even when HTTP-based applications remain reachable, HTTP probes provide a more accurate measure of actual application reachability.

In addition, you can now use hostnames as ICMP probe targets, giving you greater flexibility beyond IPv4 and IPv6 addresses alone.

To configure HTTP-based probes, add or edit the WAN interface configuration for a WAN Edge device or WAN Edge template, and configure the following:

  • URLs—Enter one or more HTTP URLs to probe. The system sends HTTP requests to the specified URLs to assess path reachability.

  • Probe Profile—Select Broadband (default) or LTE to control inherited probe timing behavior (interval, count, test interval). This setting applies to both ICMP and HTTP probes.

image-20260715-062130.png

Note that you can configure ICMP probes, HTTP probes, or both simultaneously. When both ICMP and HTTP probes are configured, the WAN path remains up as long as at least one configured probe type reports success. The path is marked down only when all configured probes fail.

Structured tabular output for SRX Testing Tools (BGP, OSPF, FIB)

The Testing Tools for SRX WAN Edge devices now provide diagnostic results in a structured tabular format, not as raw CLI text output. This improvement applies to the following tools: BGP, OSPF, and FIB.

Previously, running a diagnostic command such as BGP Summary or Show FIB returned unformatted, shell-style text that was difficult to scan and interpret—especially for large result sets. With this enhancement, results are automatically displayed in tabular format with clear headings. This change improves readability and makes it faster to identify issues such as peers in a non-established state, missing prefixes, or unexpected routing entries. The following image shows a sample output returned by the BGP tool.

image-20260715-072955.png

Application rate limiting (SSR)

You can now apply per-application bandwidth rate limiting on Mist-managed WAN Edge (SSR) devices. This feature lets you cap the upload and download bandwidth that specific applications can consume across your WAN, preventing bandwidth-hungry apps from causing congestion or excessive costs.

With this release, you can define service-level rate limits per application, and the settings are automatically translated into the appropriate SSR rate-limit-policy configuration and pushed to your WAN Edge devices.

You can configure rate limit from the Advanced Settings section on the Organization > WAN > Applications page. You can specify the maximum upload limit (Rate Limit Up) or download limit (Rate Limit Down) for an application, in kilobits per second (kbps). Rate limit must be a value between 64 and 10,485,760.

image-20260715-080027.png

IPv6 packet capture support for WAN Edge devices (SSR)

The WAN Edge Packet Capture (PCAP) tool now supports IPv6 traffic capture on Session Smart Router (SSR) WAN Edge devices. Previously, packet capture filtering was limited to IPv4 traffic. With this enhancement, you can build capture filters that target IPv6 traffic directly from the Mist portal.

The following IPv6 options are now available in the PCAP expression builder on the Site > WAN > WAN Edge Packet Captures page for sites with SSR devices:

  • ICMPv6 protocol filter—The Add Port Filter section now includes ICMPv6 as a selectable protocol, allowing you to capture ICMPv6 traffic.

  • IPv6 Multicast filter—A new IPv6 checkbox in the Multicast section of the expression builder. When selected, the system generates the ip6 multicast filter expression to capture IPv6 multicast traffic. This option works alongside the existing Ethernet and IPv4 multicast filters.

image-20260715-100616.png

Note: IPv6 packet capture is supported only on SSR WAN Edge devices. For SRX WAN Edge devices, packet capture remains IPv4 only.

Dynamic PCAP for Intrusion Detection and Prevention events (SRX)

When an SRX detects an Intrusion Detection And Prevention (IDP) attack, Mist automatically retrieves the associated packet capture from the device and makes it available on the Security Events page for download. You can click the download icon (a paperclip image) in the Dynamic PCAP column to immediately download the PCAP file associated with an IDP event. Each Dynamic PCAP captures up to five packets before and five packets after the attack signature match, providing context around the security event for faster root-cause analysis. Dynamic PCAP for IDP events is supported on SRX WAN Edge devices running Junos version 23.1R1 or later.

To access the Dynamic PCAP downloads, navigate to Site > WAN > Security Events and look for the Dynamic PCAP column on IDP attack events. When a PCAP is available, a download icon appears in the column. Click the icon to download the PCAP file.

image-20260715-110202.png

Spaces no longer allowed in hub profile and WAN Edge template names

Mist now validates hub profile and WAN Edge template names to prevent spaces. Previously, a hub profile name containing a space (for example, "My Hub") could cause overlay endpoint failures, resulting in peer paths not coming up between hub and spoke devices.

If you have an existing hub profile with a space in the name, Mist will display a warning: "Hub Profile name cannot contain spaces." To resolve this, clone the affected profile using a name without spaces, reassign your devices to the new profile, and delete the old one. For existing WAN Edge templates with spaces in their names, you can edit the names to remove the spaces.

Mist Edge

New Mist Edge OS version and upgrade enhancements

We have made several improvements to the Mist Edge upgrade experience in the Mist portal to provide clearer naming, more accurate upgrade notifications, and better model-specific handling.

A new base OS version is now available for Mist Edge devices (except for the ME‑X5, ME-X5M, and ME‑X10 models). As a result, most customers will begin seeing an ‘OS upgrade recommended’ notification for applicable Mist Edge devices. This notification replaces the previous ‘Firmware upgrade available’ notification.

We have also enhanced the Mist Edge upgrade experience by separating the tunnel service upgrade from the base OS upgrade. This gives customers more flexibility: you may choose to remain on the current base OS and upgrade only the tunnel service (if an update is available), or you can upgrade both the base OS and the tunnel service together. The Upgrade Mist Edge window now includes a drop‑down menu that allows you to select one of the following options:

  • Upgrade Service—Upgrades only the tunnel service.

  • Upgrade Service and OS—Upgrades both the base OS and the tunnel service.

image-20260327-103803.png

The Mist Edge upgrades are incremental. If your Mist Edge device has not been upgraded in the past two years, you may need to perform the upgrade sequence more than once.

Note: For a Mist Edge device that is functioning only as a proxy and doesn’t have an active tunnel service to upgrade, the option 'Upgrade Service and OS' is chosen by default; you cannot choose the upgrade type.

  • The Mist Edge OS version labels have been updated to the user-friendly MEOS10, MEOS11, MEOS12 format.

  • The upgrade notification on the Mist Edge list has been refined to better distinguish between service-only and OS-level upgrades:

    • The ‘Firmware upgrade available’ message is rephrased to ‘OS upgrade recommended’, and it is displayed when a newer Mist Edge OS version is available, indicating that the upgrade includes a base OS and Mist Edge services update.

      image-20260529-042644.png
    • A triangle icon is shown when only a Mist Edge tunnel service (firmware) upgrade is available and no OS upgrade is required.

      image-20260529-042615.png
  • The ME-X5,ME-X5M and ME-X10 models are excluded from OS upgrade prompts.

When a user selects ‘Upgrade Service and OS,’ the ‘Confirm & Upgrade’ button is disabled, and the following message is displayed: "Contact Mist Support for upgrading the Mist Edge OS." Users who need an OS upgrade should reach out to Mist Support for assisted upgrades. 

Mist Edge device details page redesign

We have redesigned the Mist Edge device details page to improve usability and better align it with Mist Edge hardware models. Below are the key updates:

  • Model-aware chassis front panel—A new interactive chassis front panel provides a visual representation of your Mist Edge hardware, including the OOBM port and data ports. The layout automatically adapts to the specific Mist Edge model, accurately reflecting port count and physical arrangement. Health gauges for CPU, memory, temperature, PSUs, and fans are displayed alongside the chassis view.

  • Reorganized layout—The device details page is now structured into clear, collapsible sections—Properties, Device, Tunnel Management, and Advanced—making it easier to locate and manage configuration settings.

  • Port selection—Ports on the chassis panel are now interactive. Clicking a port displays associated details such as LLDP, LACP, and port statistics, along with options to start packet capture and bounce ports. For disconnected devices, placeholder ports are shown based on the model definition.

  • Device photos—Upload and manage up to three photos per Mist Edge appliance.

image-20260730-022306.png

Site variable support for Mist Edge tunnel selection in custom forwarding

We have simplified Mist Edge tunnel configuration in WLANs with the following two enhancements to site variables:

  • Support for Mist Edge tunnels in site variables. This enhancement enables template-based deployments that automatically map to the correct tunnel at each site.

  • The Site Variables section on the Organization > Site Configuration page includes two new fields: an optional Note field for adding descriptions and a new Variable Type option, Mxtunnel, which allows administrators to select a Mist Edge tunnel by name instead of manually entering a tunnel ID.

When creating a site variable in the Site Variables section on the Organization > Site Configuration page, you can set the variable type to Mxtunnel, define a variable, and select a tunnel from the available Mist Edge tunnels to associate with it. After creating an Mxtunnel site variable, you can easily reference it in the Custom Forwarding section of the WLAN configuration.

image-20260515-070051.png

This feature streamlines Mist Edge tunnel configuration in multi-site deployments. By referencing tunnels through named site variables, network administrators can create reusable WLAN templates that automatically resolve to the appropriate tunnel at each site—reducing configuration effort and minimizing errors.

Location Services

View battery percentage for Aruba asset tags

The Mist dashboard now displays the battery percentage of HPE Aruba BLE asset tags. You can view battery percentage information for Aruba asset tags on the MFG Data tab of the BLE Clients page (Clients > BLE Clients > Named Assets).

image-20260513-163003.png

This visibility enables customers to proactively monitor battery levels and plan replacements before tags go offline, helping reduce gaps in asset‑tracking coverage.

This feature applies only to named Aruba asset tags with Vendor ID 0x11B and subtype 0x06.

Network Observability and Business Intelligence

Premium Analytics access for site‑only roles

Premium Analytics is now available to users restricted to specific sites or site groups. When these users open Premium Analytics dashboards on the Mist portal, only their allowed site list is passed to the analytics backend so that dashboards display data solely for sites they are permitted to view.

This improves consistency with existing role‑based access controls:

  • Org‑level users (Super User, Org Admin, Super Observer, Network Admin with Org Read) see analytics for all sites.

  • Site‑restricted roles (Network Admin without Org Read, Observer, Helpdesk) now see analytics limited to their assigned sites; If a user’s site assignment is "All sites", dashboards show org‑level analytics.

PMA enforces these restrictions across dashboard displays, data downloads, and scheduled reports.
Note: Site‑based access supports roughly up to 100 sites per user. For users needing access to more than 100 sites, you must grant org‑level access.

Feature Deprecation

Mist Edge: Tunnel stats API uptime field replaced with start_time

The tunnel stats API response now returns a start_time epoch timestamp instead of a rolling uptime value. If you consume the tunnel stats API directly, calculate uptime as current time - start time.

Customers or integrations reading uptime directly from the API must now use start_time and compute uptime themselves (current time - start time).