Juniper JUNOS OS 10.4 - RELEASE NOTES REV 6 Release Note page 184

Hide thumbs Also See for JUNOS OS 10.4 - RELEASE NOTES REV 6:
Table of Contents

Advertisement

JUNOS OS 10.4 Release Notes
184
The Junos OS Security Configuration Guide states that the following aggressive aging
statements are supported on all SRX Series devices when in fact they are not supported
on SRX3400, SRX3600, SRX5600, and SRX5800 devices:
[edit security flow aging early-ageout]
[edit security flow aging high-watermark]
[edit security flow aging low-watermark
The Junos OS Security Configuration Guide states that the maximum acceptable timeout
range for an IDP policy is 0 through 65,535 seconds, whereas the
range has been modified to 0 through 64,800 seconds.
The Junos OS Security Configuration Guide is missing information about the new CLI
option
download-timeout
, which has been introduced to
automatic download-timeout < value >
The default value for
download-timeout
the download times out, the signature is automatically updated after the download.
If the download takes longer than the configured period, the auto signature update is
aborted.
user@host# set security idp security-package automatic download-timeout ?
Possible completions:
Maximum time for download to complete (1 - 60 minutes)
[edit]
set security idp security-package automatic download-timeout
user@host#
Range: 1
60 seconds
Default: 1 second
The Junos OS Security Configuration Guide states the following limitations in the
"Limitations of IDP" section:
On SRX Series and J Series devices, IP actions do not work when you select a timeout
value greater than 65,535 in the IDP policy.
This issue has been fixed and is no longer a limitation.
The Junos OS Security Configuration Guide incorrectly states the following limitations
in the "Limtations of IDP" section:
On SRX210, SRX240, and SRX650 devices, the maximum number of IDP sessions
supported is 16,000.
The correct information is as follows:
The maximum number of IDP sessions supported is 1600 on SRX210 devices, 32,000
on SRX240 devices, and 128,000 on SRX650 devices.
When specifying a forwarding target after authentication on a captive portal, use the
?target=
option followed by either the
variable forwards authenticated users to the protected resource they
%dest-url%
originally specified. A URL forwards authenticated users to a specific site.
set security idp security-package
to configure the download timeout in minutes.
is one minute. If download is completed before
< download-timeout >
%dest-url%
variable or a specific URL. The
Copyright © 2011, Juniper Networks, Inc.
timeout
ipaction

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents