EasyManua.ls Logo

Juniper JUNOS OS 10.4 - RELEASE NOTES - Intrusion Detection and Prevention (IDP)

Juniper JUNOS OS 10.4 - RELEASE NOTES
197 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
set class-of-service interfaces at-5/0/0 unit 0 shaping-rate 62400 ADD IFL SHAPER
On SRX210, SRX220, and SRX240 devices, 1-port Gigabit Ethernet SFP mini-PIM does
not support switching in Junos OS Release 10.4.
On SRX1400, SRX3400, SRX3600, SRX5600, and SRX5800 devices, the Link
Aggregation Control Protocol (LACP) is not supported on Layer 2 interfaces.
On SRX650 devices, MAC pause frame and FCS error frame countersare not supported
for the interfaces ge-0/0/0 through ge-0/0/3.
On SRX240 and SRX650 devices, the VLAN range from 3967 to 4094 falls under the
reserved VLAN address range, and the user is not allowed any configured VLANs from
this range.
On SRX650 devices, the last 4 ports of a 24-Gigabit Ethernet switch GPIM can be used
either as RJ-45 or SFP ports. If both are present and providing power, the SFP media
is preferred. If the SFP media is removed or the link is brought down, then the interface
will switch to the RJ-45 medium. This can take up to 15 seconds, during which the LED
for the RJ-45 port might go up and down intermittently. Similarly when the RJ-45
medium is active and an SFP link is brought up, the interface will transition to the SFP
medium, and this transition could also take a few seconds.
On SRX210 devices, the USB modem interface can handle bidirectional traffic of up
to 19 Kbps. On oversubscription of this amount (that is, bidirectional traffic of 20 Kbps
or above), keepalives do not get exchanged, and the interface goes down.
On SRX3400 and SRX3600 devices, BGP based VPLS over aggregated ethernet (ae)
interfaces does not work because it is not supported. It works on child ports and physical
interfaces.
On SRX100, SRX210, SRX240 and SRX650 devices, on the Level 3 ae interface, the
following features are not supported:
Encapsulations (such as CCC, VLAN CCC, VPLS, and PPPOE) on Level 3 ae interfaces
J-Web
Level 3 ae for 10-Gigabit Ethernet
Intrusion Detection and Prevention (IDP)
If SRX series device that are configured for IDP and are upgraded to Junos OS Release
10.4, administrators must install the new security database as old IDP detector might
not be compatible.
Administrators must update the detector by using the request security idp
security-package download full-update command followed by request security idp
security-package install command.
IDP does not allow header checks for nonpacket contexts.
Copyright © 2010, Juniper Networks, Inc.138
JUNOS OS 10.4 Release Notes

Table of Contents

Related product manuals