Juniper JUNOS OS 10.4 - RELEASE NOTES REV 5 Release Note page 96

Hide thumbs Also See for JUNOS OS 10.4 - RELEASE NOTES REV 5:
Table of Contents

Advertisement

JUNOS OS 10.4 Release Notes
96
IPv4 IPIP
IPv4 GRE
IPv4 IPsec
Dual-stack lite
[Junos OS Security Configuration Guide]
DNS ALG for routing, NAT, and NAT-PT—This feature is supported on all SRX Series
and J Series devices.
Domain Name System (DNS) is the part of the ALG that handles DNS traffic. The DNS
ALG module has been working as expected for IPv4. In Junos OS Release 10.4, this
feature implements IPv6 support on DNS ALG for routing, NAT, and NAT-PT.
When the DNS ALG receives a DNS query from the DNS client, a security check is done
on the DNS packet. When the DNS ALG receives a DNS reply from the DNS server, a
similar security check is done, and then the session for the DNS traffic closes.
When the DNS traffic works in NAT mode, the DNS ALG translates the public address
in a DNS reply to a private address when the DNS client is on a private network, and
similarly translates a private address to a public address when the DNS client is on a
public network. When DNS traffic works in NAT-PT mode, the DNS ALG translates the
IP address in a DNS reply packet between the IPv4 address and the IPv6 address when
the DNS client is in an IPv6 network and the server is in an IPv4 network, and vice versa.
To support NAT-PT mode in a DNS ALG, the NAT module should support NAT-PT.
[Junos OS Security Configuration Guide]
Dual-stack lite—This feature is supported on SRX650, SRX3400, SRX3600, SRX5600,
and SRX5800 devices.
IPv6 dual-stack lite (DS Lite) is a technology for maintaining connectivity between
legacy IPv4 devices and networks despite a depleted IPv4 address pool and as a service
provider networks transition to IPv6-only deployments.
DS Lite allows IPv4 customers to continue accessing IPv4 internet content with
minimum disruption to their home networks, while enabling IPv6 customers to access
IPv6 content.
The DS Lite deployment model consists of the following components:
Softwire Initiator (SI) in the DS Lite home router (SI is not available in Junos release
10.4)
Softwire Concentrator (SC) in the DS Lite carrier-grade Network Address Translation
(NAT)
A softwire is a tunnel-over-IPv6 network. The SI finds the SC address, encapsulates
an IPv4 packet, and transmits it across the softwire. The SC receives an IPv4 packet
in the IPv6 softwire packet and decapsulates the IPv6 software packet to retrieve the
inner IPv4 packet. Multiple SIs can have the same SC as the endpoint of the softwires.
Copyright © 2011, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents