Intrusion Detection And Prevention (Idp) - Juniper JUNOS OS 10.4 - RELEASE NOTES Release Note

Table of Contents

Advertisement

JUNOS OS 10.4 Release Notes
138
set class-of-service interfaces at-5/0/0 unit 0 shaping-rate 62400 ADD IFL SHAPER
On SRX210, SRX220, and SRX240 devices, 1-port Gigabit Ethernet SFP mini-PIM does
not support switching in Junos OS Release 10.4.
On SRX1400, SRX3400, SRX3600, SRX5600, and SRX5800 devices, the Link
Aggregation Control Protocol (LACP) is not supported on Layer 2 interfaces.
On SRX650 devices, MAC pause frame and FCS error frame counters are not supported
for the interfaces
ge-0/0/0
On SRX240 and SRX650 devices, the VLAN range from 3967 to 4094 falls under the
reserved VLAN address range, and the user is not allowed any configured VLANs from
this range.
On SRX650 devices, the last 4 ports of a 24-Gigabit Ethernet switch GPIM can be used
either as RJ-45 or SFP ports. If both are present and providing power, the SFP media
is preferred. If the SFP media is removed or the link is brought down, then the interface
will switch to the RJ-45 medium. This can take up to 15 seconds, during which the LED
for the RJ-45 port might go up and down intermittently. Similarly when the RJ-45
medium is active and an SFP link is brought up, the interface will transition to the SFP
medium, and this transition could also take a few seconds.
On SRX210 devices, the USB modem interface can handle bidirectional traffic of up
to 19 Kbps. On oversubscription of this amount (that is, bidirectional traffic of 20 Kbps
or above),
do not get exchanged, and the interface goes down.
keepalives
On SRX3400 and SRX3600 devices, BGP based VPLS over aggregated ethernet (
interfaces does not work because it is not supported. It works on child ports and physical
interfaces.
On SRX100, SRX210, SRX240 and SRX650 devices, on the Level 3
following features are not supported:
Encapsulations (such as CCC, VLAN CCC, VPLS, and PPPOE) on Level 3
J-Web
Level 3
for 10-Gigabit Ethernet
ae

Intrusion Detection and Prevention (IDP)

If SRX series device that are configured for IDP and are upgraded to Junos OS Release
10.4, administrators must install the new security database as old IDP detector might
not be compatible.
Administrators must update the detector by using the
security-package download full-update
security-package install
IDP does not allow header checks for nonpacket contexts.
through
.
ge-0/0/3
command followed by
command.
interface, the
ae
ae
interfaces
request security idp
request security idp
Copyright © 2010, Juniper Networks, Inc.
)
ae

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents