background image

Juniper Networks, Inc.

1194 North Mathilda Avenue

Sunnyvale, CA 94089

USA

408-745-2000

www.juniper.net

Published: 2010-11-09

JunosE

 Software

for E Series

 Broadband Services Routers

Release Notes

Release 11.0.2

Summary of Contents for JUNOSE 11.0.2 RELEASE NOTES

Page 1: ...iper Networks Inc 1194 North Mathilda Avenue Sunnyvale CA 94089 USA 408 745 2000 www juniper net Published 2010 11 09 JunosE Software for E Series Broadband Services Routers Release Notes Release 11 0...

Page 2: ...ed outside the Americas such applicable entity being referred to herein as Juniper and ii the person or organization that originally purchased from Juniper or an authorized Juniper reseller the applic...

Page 3: ...WILL BE FREE OF VULNERABILITY TO INTRUSION OR ATTACK In no event shall Juniper s or its suppliers or licensors liability to Customer whether in contract tort including negligence breach of warranty or...

Page 4: ...nd supersedes all prior and contemporaneous agreements relating to the Software whether oral or written including any inconsistent terms contained in a purchase order except that the terms of a separa...

Page 5: ...Release Overview 5 Before You Start 5 Release Highlights 7 IPv6 7 Early Field Trial Features 8 ANCP 8 IPv6 8 System Maximums 9 Unsupported Features 9 E120 Router and E320 Router 9 Policy Management 9...

Page 6: ...Software 35 SSH 35 Stateful SRP Switchover High Availability 35 Subscriber Interfaces 36 System 37 System Logging 38 Tunneling 38 Known Problems and Limitations 38 ANCP 38 ATM 38 BFD 40 CLI 40 DHCP 40...

Page 7: ...F 58 Policy Management 59 QoS 59 Service Manager 59 SRP 59 System 59 Errata 60 Appendix A System Maximums 69 ERX310 ERX7xx and ERX14xx System Maximums 70 General System Maximums 70 Physical and Logica...

Page 8: ...viii Table of Contents JunosE 11 0 2 Release Notes...

Page 9: ...restore the earlier software version Upgrading to Release 5 3 0 or a Higher Numbered Release When you upgrade from a lower numbered release to Release 5 3 0 or a higher numbered release the higher re...

Page 10: ...cuments JunosE System Basics Configuration Guide Chapter 6 Managing Modules Upgrading NVS Cards on SRP Modules in ERX Hardware Guide Chapter 8 Maintaining ERX Routers Upgrading NVS Cards on SRP Module...

Page 11: ...protocols and applications supported by ERX router modules are in ERX Module Guide Appendix A Module Protocol Support Compatibility of E120 router and E320 router modules with software releases is in...

Page 12: ...notes http www juniper net customers csc software Search technical bulletins for relevant hardware and software notifications https www juniper net alerts Join and participate in the Juniper Networks...

Page 13: ...69 If the information in these Release Notes differs from the information found in the published documentation set follow these Release Notes Before You Start These Release Notes include information a...

Page 14: ...ndancy stateful SRP switchover unified ISSU VRRP and interchassis redundancy ICR JunosE Service Availability Configuration Guide Configure IP IPv6 and Neighbor Discovery and interior gateway protocols...

Page 15: ...ents In addition to configuring Neighbor Discovery through the CLI you can also use IPv6 profiles and RADIUS to configure Neighbor Discovery route advertisements for dynamically configured interfaces...

Page 16: ...n be used to send messages to establish adjacency To learn the partition ID the NAS has to wait until it receives the first GSMP_SYN message from an access node The following command has been added to...

Page 17: ...r targeted configuration The following features are present but unsupported in this release E120 Router and E320 Router The ES2 10G LM and ES2 10G Uplink LM do not support layer 2 statistics for VLANs...

Page 18: ...the configuration guides Core Routing Stack Internet Protocol IP version 4 and version 6 Transmission Control Protocol TCP for IPv4 User Datagram Protocol UDP for IPv4 and IPv6 Layer 2 Protocols Async...

Page 19: ...ocol IGMP Intermediate System to Intermediate System IS IS Layer 2 Virtual Private Networks L2VPNs Mobile IP Open Shortest Path First OSPF version 2 and version 3 Protocol Independent Multicast Protoc...

Page 20: ...ugh you can use the max sessions command to configure a maximum of 32 000 outstanding authentication authorization requests to a RADIUS server AAA internal limits prevent the actual number of outstand...

Page 21: ...icating the burst size is invalid and it does not create the VC Defect ID 58357 Work around Configure a CBR or a UBR plus PCR to create the circuit with the same parameters depending on the desired pr...

Page 22: ...environment we recommend that you increase the hold timers for the following protocols to appropriate values based on the level of complexity of the network and scaling settings so as to enable grace...

Page 23: ...mode the table specifies any modes for which it is still available Deprecated Command Command Mode Preferred Command aaa accounting interval Global Configuration aaa service accounting interval and a...

Page 24: ...cp relay with the strings docsis and pktc in the server string mapping specification no ip inspect strict Global Configuration Use stateful firewall commands ip inspect keyword ip mirror Global Config...

Page 25: ...next hop Policy List Configuration forward next hop in Classifier Group Configuration mode no next interface Policy List Configuration forward interface in Classifier Group Configuration mode nrzi enc...

Page 26: ...rivileged Exec show ipsec identity show ike policy rule User Exec Privileged Exec show ipsec ike policy rule show ike sa User Exec Privileged Exec show ipsec ike sa show ip dhcp external binding Privi...

Page 27: ...scriber interface extends its IP address lease by restarting the DHCP discovery process on its primary IP interface instead of by initiating the DHCP renewal process on its dynamic subscriber interfac...

Page 28: ...igure the client facing and server facing interfaces for DHCP external server and either DHCP relay or relay proxy on the same ES2 10G LM instead of the same ES2 4G LM Configure the client facing and...

Page 29: ...full bandwidth is delivered only on a maximum of 16 ports those in slots 2 and 4 When the GE 2 line module or the GE HDE line module is installed in either the ERX1440 router or the ERX310 router and...

Page 30: ...esets due to an out of memory condition However the ERX310 router still supports 1 GB of memory in the SRP SE10 module Work around Upgrade your SRP module memory to 2 GB for all ERX7xx and ERX14xx rou...

Page 31: ...ple if you have issued the shutdown command for the interface before you try to delete the interface issue the no shutdown command then delete the interface IP The ip tcp adjust mss command which modi...

Page 32: ...78 host1 config ip vrf 123 host1 config vrf description longdescription Work around Before you upgrade from an affected release to JunosE Release 9 2 0p1 0 or higher numbered releases ensure that you...

Page 33: ...tgoing IP interface to the IP destinations of IPSec tunnels the tunnels remain in the up state rather than transitioning to down As a consequence all IP routes that use these tunnels as next hops also...

Page 34: ...mselves as the DIS for the same network segment and the configuration fails Defect ID 72367 Work around To ensure proper election of the DIS when you configure IS IS over bridged Ethernet for back to...

Page 35: ...cy On E120 routers and E320 routers redundant IOAs have a temperature sensor and the show environment all command lists the temperature of IOAs in their associated slots On ERX routers redundant I O m...

Page 36: ...ting Control word is not preferred by default Because control words are required for these MPLS shim interfaces these circuits should instead be signaled with the setting Control word is preferred by...

Page 37: ...MAC address of the analyzer device and gets a response over the new link Policy Management In JunosE Release 11 0 0 and higher numbered releases you must specify at least one option by which the route...

Page 38: ...numbered lower than Release 5 2 0 If multiple forward or filter rules were configured to reference the same classifier list in a single policy then all rules except the first rule configured were mar...

Page 39: ...es not support dynamic IP interfaces over static PPP interfaces when the PPPoE subinterface is also static The OC3 STM1 GE FE line module does not support dynamic IP interfaces over static PPP interfa...

Page 40: ...ore Release 7 2 0 you could not configure scheduler nodes as active constituents of the simple shared shaper except for the best effort node To recover the default behavior available before Release 7...

Page 41: ...tput is sent to the CLI the first time you enter Global Configuration mode or issue the show subscribers command after viewing the VLAN subinterface over which a subscriber is connected Defect ID 8450...

Page 42: ...correct enterprise OID value Work around Use the OIDs that the SNMP agent sends When you configure the router with an address pool that has two IP address ranges only the range that you configured fi...

Page 43: ...10 minutes following the successful reloading of the SM This amount of time allows for IP tunnel relocation and for the tunnels to become operational again on the SM If an SRP switchover occurs while...

Page 44: ...o set the hold time We recommend the following hold times for each protocol based on the number of interfaces When you issue show commands as soon as the CLI is available after a stateful SRP switchov...

Page 45: ...either The I O module is not present The primary line module is fully booted and ready to resume operation In this case the standby is currently providing services E120 routers and E320 routers report...

Page 46: ...is limited to 0 5 Gbps per module In releases numbered lower than Release 7 3 0 a dynamic tunnel server port was located on port 8 of the GE HDE line module and GE 8 I O module In Release 7 3 0 and hi...

Page 47: ...mand displays only 4096 entries when the line module is configured with more than 4096 NBMA ARP entries Defect ID 68849 The baseline interface atm command fails for a VCD assigned by the router to F4...

Page 48: ...Work around Try using the dhcp delete binding all command If this does not clear the subscribers you may want to reload the line module to avoid further issues DHCP DHCP packets are not forwarded to...

Page 49: ...indings are not created in the DHCP external server when DHCP clients on an ATM bulk configuration interface stack and dynamic VLAN over Ethernet stack sends a renew message Defect ID 87087 DoS Protec...

Page 50: ...Defect ID 174784 Specifying S VLAN ranges that partially overlap does not work Defect ID 81918 For example the following configuration fails because S VLAN 22 falls within the previously specified S V...

Page 51: ...hat configure subinterfaces for ICR partitions before the commands used for VLAN based or S VLAN based grouping of subscribers When you configure ICR settings using a CLI macro ICR commands are run in...

Page 52: ...APS I O module boot from NVS and issue the slot erase command before booting has completed the line module resets Defect ID 64104 Work around To recover from the error issue the slot reload command an...

Page 53: ...e modules reset again Work around Configure the IPSec tunnels to use ISASKMP IKE to negotiate SA and establish keys Defect ID 178304 IPSec tunnels created over Fast Ethernet interfaces fail to come up...

Page 54: ...ting reassembled packet Defect ID 50111 The initial fragment of a packet must either contain the entire MLPPP packet or be greater than 128 bytes The fragment size of the peer must not be lower than 1...

Page 55: ...e hops when LSPs are autoroute announced to IGPs When the IPv4 explicit null label appears anywhere other than at the bottom of the label stack TTL expiration for this label is not handled correctly A...

Page 56: ...actual value minus 65 536 For example an MD Port Number of 65 540 is displayed in the mirrored packet as 4 Defect ID 84712 If you have removed the last rule in a policy list the router generates a war...

Page 57: ...cent option into a console or Telnet session from show configuration output because the output displays the sign rather than the percent keyword that was submitted with the command and the percent sig...

Page 58: ...shared shaping rate to a scheduler profile configured with legacy shaping rate Defect ID 183291 Work around To avoid this problem apply shared shaping on the best effort queue instead of on the best e...

Page 59: ...ion information based on the session owner instead of the show service management subscriber session subscriberName interface interfaceType command to display details on subscriber sessions SONET You...

Page 60: ...SRP switchover is performed the first time an identical packet loss occurs In this case too no packet loss occurs during subsequent switchovers E120 router or E320 router When you use the ping command...

Page 61: ...ound Use the no interface ip ipAddress command to remove the dynamic subscriber interfaces Although you can use the dhcp delete binding command to remove the DHCP binding and the dynamic subscriber in...

Page 62: ...ization process also ends properly Although the standby SRP module reloads for the second time when it is synchronized with the upgraded release normal router operations such as handling of subscriber...

Page 63: ...e in a large bridged Ethernet configuration Defect ID 178798 Under certain conditions a unified ISSU from JunosE Release 9 2 0p1 0 to the current release fails and causes the SRP module and the ES2 4G...

Page 64: ...en performing SNMP set operation file ethernet cc line 2687 task scheduler Defect ID 90708 DHCP DHCP external server does not update the lease time when the client sends a renew request Defect ID 9068...

Page 65: ...wn Defect ID 90606 LM10A crash SRA 2048 file ic1Detector cc line 1013 message Ic1Detector requestRecovery executed forced IC crashes Defect ID 90704 LM10 Memory leak on luCodeBranch code branch repres...

Page 66: ...EgressDirectNextHopLabel Defect ID 90732 LDP and OSPF flap when an unconfigured LM10 is reloaded with 75k MPLS next hops Defect ID 90471 Multicast The following commands which appear in IPv6 PIM Data...

Page 67: ...not cleaned up Defect ID 90559 Service Manager Service manager incorrectly deactivates an existing service after an attempt to activate a second service Defect ID 90705 SRP standby SRP reset type pan...

Page 68: ...om a new NVS card This restriction is not applicable if you upgrade your software remotely through Telnet or FTP The imprecise information appears in the following JunosE documents The Upgrading to Ju...

Page 69: ...2 I O modules OCx STMx ATM line modules with 4xDS3 ATM I O modules CT3 T3 FO line modules with CT3 T3 12 I O modules ERX Module Guide Appendix C Module Name Cross Reference Information fails to includ...

Page 70: ...ual mode is enabled In JunosE IP IPv6 and IGP Configuration Guide Chapter 2 Configuring IPv6 the Before You Configure IPv6 section fails to list all the modules that support IPv6 You can find complete...

Page 71: ...ered PIM sparse mode interface Use the same address as the loopback interface Lp in the parent router PE2 host1 config virtual router PE2 CE2 host1 PE2 CE2 config interface loopback 0 host1 PE2 CE2 co...

Page 72: ...restart capability is also disabled both globally and for specified peers or peer groups The bgp graceful restart command section incorrectly mentions that you can use the default keyword to restore...

Page 73: ...ccess fails to mention that the router uses the backoff algorithm only for subscriber AAA accounting messages except Acct On messages The IP Hinting section in JunosE Broadband Access Configuration Gu...

Page 74: ...w radius servers RADIUS Authentication Configuration Monitoring RADIUS Server Information 1 Udp Retry Maximum Dead IP Address Port Count Timeout Sessions Time Secret Status RADIUS Accounting Configura...

Page 75: ...p graceful restart command in the JunosE Command Reference A to M incorrectly states that graceful restart is enabled by default It also erroneously states that using the default keyword with the bgp...

Page 76: ...support mode and is not user configurable In the JunosE System Event Logging Reference Guide for the radiusClient event category the Error field incorrectly includes the following errors Internal allo...

Page 77: ...aximums for ERX310 ERX7xx and ERX14xx Section General router values General System Maximums on page 70 Physical layer values Physical and Logical Density Maximums on page 71 Link layer values Link Lay...

Page 78: ...ble 1 General System Maximums Feature ERX310 ERX705 and ERX710 ERX1410 ERX1440 Fabric size 10 Gbps 5 or 10 Gbps 10 Gbps 40 Gbps Chassis per 7 foot rack 14 6 3 3 NTP clients 1000 1000 1000 1000 NTP ser...

Page 79: ...E Physical Layer Configuration Guide Chapter 5 Configuring Ethernet Interfaces 3 When you pair the GE HDE line module with the GE 8 I O module on the ERX1440 router you can terminate up to 96 Gigabit...

Page 80: ...ports per chassis OC12 STM4 I O modules 2 4 5 8 12 12 OC12 STM 4 POS ports per chassis OC12 STM4 I O modules 2 4 5 4 12 12 OC48 STM16 POS ports per chassis OC48 FRAME I O modules ERX1440 router only 2...

Page 81: ...000 500 per OC3 STM1 Logical fractional T1s DS0 per CT3 T3 F0 line module 1992 166 per T3 1992 166 per T3 1992 166 per T3 1992 166 per T3 Logical fractional T3s DS3 per COCX F3 line module 12 12 12 12...

Page 82: ...atic The JunosE Software supports up to 10 000 PPP interfaces with EAP authentication negotiation configured Performance and scalability is unchanged when EAP is not configured 2 The total maximum num...

Page 83: ...chassis 100 100 100 100 ATM VP VC addresses per line module OCx STMx DS3 ATM 20 bit 20 bit 20 bit 20 bit OC3 STM1 GE FE 20 bit 20 bit 20 bit 20 bit ATM VP tunnels per port all supported modules 256 25...

Page 84: ...16 384 OC3 2 GE APS I O 4096 4096 4096 4096 Ethernet VLAN bulk configuration VLAN ranges per chassis 300 300 300 300 Ethernet VLAN bulk configuration VLAN ranges per line module 300 300 300 300 Ethern...

Page 85: ...interface columns MLPPP bundles per chassis 12 000 12 000 12 000 12 000 MLPPP bundles per line module The maximum number of MLPPP bundles supported per line module is the lesser of the maximum number...

Page 86: ...8000 Subinterfaces per GE 2 line module 8000 8000 Subinterfaces per GE HDE line module 8000 8000 Subinterfaces per OCx STMx DS 3 ATM line module 8000 8000 8000 8000 Subinterfaces per OC3 STM 1 GE FE l...

Page 87: ...a maximum of 16 000 IP network interfaces For all these models the interfaces can be any combination of dynamic or static 3 These values are subject to limitations on available SRP module memory whic...

Page 88: ...RX1440 BFD Sessions per line module 50 50 50 50 ECMP maximum paths to a destination BGP IS IS MPLS OSPF RIP 16 16 16 16 IPv4 forwarding table entries See Note 1 on page 79 Chassis with only ASIC modul...

Page 89: ...ircuits per chassis See Note 7 on page 79 16 000 16 000 16 000 32 767 External Martini circuits per chassis 16 000 16 000 16 000 32 767 Internal Martini circuits local cross connects per chassis 16 00...

Page 90: ...82 ERX310 ERX7xx and ERX14xx System Maximums VRRP VRIDs per line module ASIC See Ethernet VRRP VRIDs per line module ASIC on page 76 Table 4 Routing Protocol Maximums continued Feature ERX310 ERX705...

Page 91: ...most configurations each classifier entry in a policy consumes one CAM entry However a policy that has only the default classifier consumes no CAM resources Policies that use CAM hardware classifiers...

Page 92: ...Combined IP and IPv6 interface attachments on all other line modules 16 000 16 000 16 000 16 000 Combined ATM Frame Relay GRE L2TP LNS only MPLS and VLAN interface attachments 8191 8191 8191 8191 Rat...

Page 93: ...rview Table 6 Tunneling Maximums Feature ERX310 ERX705 and ERX710 ERX1410 ERX1440 DVMRP IP in IP tunnels per chassis 4000 4000 4000 4000 DVMRP IP in IP tunnels per line module See Note 1 on page 85 GE...

Page 94: ...nnel server ports provisioned 8000 8000 IPSec Service Module ISM L2TP IPSec sessions 5000 5000 5000 5000 Service Module SM 16 000 16 000 16 000 16 000 L2TP tunnels per chassis 8000 8000 8000 8000 L2TP...

Page 95: ...f 32 000 static major interfaces Although the ERX1440 router supports a maximum of 48 000 static major interfaces for PPPoE the PPPoE static limit is enforced at the subinterface level which has a lim...

Page 96: ...thentication server Local user databases per chassis 100 100 100 100 Users per local user database 100 100 100 100 Users for all local user databases 100 100 100 100 RADIUS requests Concurrent RADIUS...

Page 97: ...ces per chassis 16 000 32 000 32 000 48 000 Dynamic subscriber interfaces per line module 8000 8000 8000 8000 Static subscriber interfaces per chassis 16 000 32 000 32 000 48 000 Static subscriber int...

Page 98: ...and VRF instance is running a routing protocol 2 The maximum of 3000 VRs and VRFs can be achieved only with the SRP 120 and SRP 320 modules which have 4 GB of memory The limits cannot be achieved with...

Page 99: ...lled in slot 2 or slot 4 you cannot install another line module in slot 3 or slot 5 In this case you can only install the ES2 4G LM in slots 0 1 and 6 11 therefore the maximum number of ports and the...

Page 100: ...1 OC12 2 STM4 POS IOAs 24 48 OC48 STM16 ports per chassis ES2 S1 OC48 STM16 POS IOAs 6 12 Logical density per chassis Logical OC3 STM1 per chassis 96 192 Logical OC12 STM4 per chassis 24 48 Logical OC...

Page 101: ...cation negotiation configured Performance and scalability is unchanged when EAP is not configured 4 The E120 router supports a maximum of 64 000 Ethernet subinterfaces that can be active at any one ti...

Page 102: ...00 128 000 ATM bulk configuration VC ranges per chassis 300 1025 ATM bulk configuration VC ranges per line module 300 1025 ATM bulk configuration total VCs per chassis 192 000 384 000 ATM bulk configu...

Page 103: ...tion Links per LAG bundle 8 8 LAGs bundles per chassis 64 64 Ethernet S VLANs per chassis See Notes 2 4 and 5 on page 93 64 000 96 000 Ethernet S VLANs per IOA See Note 6 on page 93 ES2 S1 GE 4 IOA wi...

Page 104: ...0G Uplink LM See Note 5 on page 93 4096 4096 ES2 S3 GE 20 IOA with ES2 10G LM 16 384 16 384 ES2 S3 GE 20 IOA with ES2 10G ADV LM 32 768 32 768 Ethernet VLAN major interfaces over Bridged Ethernet Inte...

Page 105: ...the line module For more information see the JunosE Link Layer Configuration Guide PPP major interfaces per chassis See Notes 2 and 3 on page 93 64 000 96 000 PPP major interfaces per line module ign...

Page 106: ...terfaces per line module ES2 4G LM 16 000 16 000 ES2 10G LM 16 000 16 000 ES2 10G ADV LM 32 000 32 000 Transparent bridging and VPLS Bridge groups or VPLS instances per chassis 1024 1024 Bridge interf...

Page 107: ...tions on available SRP module memory which varies according to your router configuration 4 Depending on your configuration the router may support more routing table entries or fewer routing table entr...

Page 108: ...0 000 1 500 000 IP next hops egress FECs used to represent the IP addresses of next hop routers on Ethernet interfaces 1 000 000 1 000 000 MPLS next hops egress FECs when graceful restart is not enabl...

Page 109: ...32 767 Internal Martini circuits local cross connects per chassis 16 000 32 767 Mobile IP bindings per chassis 96 000 Multicast routes IPv4 and IPv6 Forwarding entries S G pairs per chassis See Note 7...

Page 110: ...policy The line modules support policy attachments based on the following considerations IPv4 Up to 2 ingress policy attachments and 1 egress policy attachment Secure policy Up to 1 ingress policy at...

Page 111: ...nts 16 383 16 383 ES2 10G ADV LM IP interface attachments 32 000 32 000 ES2 10G ADV LM VLAN interface attachments 32 000 32 000 ES2 10G Uplink LM IP interface attachments 16 383 16 383 ES2 10G Uplink...

Page 112: ...10G Uplink LM 64 000 64 000 Policy statistics blocks egress per line module ES2 4G LM 256 000 256 000 ES2 10G LM 256 000 256 000 ES2 10G ADV LM 512 000 512 000 ES2 10G Uplink LM 256 000 256 000 Policy...

Page 113: ...ent groups only 8191 8191 ES2 10G Uplink LM internal parent groups only 8191 8191 Software lookup blocks per line module ES2 4G LM 16 383 16 383 ES2 10G LM 16 383 16 383 ES2 10G ADV LM 32 000 32 000 E...

Page 114: ...120 E320 DVMRP IP in IP tunnels per chassis 4000 4000 DVMRP IP in IP tunnels per line module with shared tunnel server ports provisioned 4000 4000 DVMRP IP in IP tunnels per ES2 S1 Service IOA See Not...

Page 115: ...aximums L2TP tunnels per line module with shared tunnel server ports provisioned See Note 2 on page 106 8000 8000 L2TP tunnels per ES2 S1 Service IOA See Note 1 and Note 2 on page 106 16 000 16 000 Ta...

Page 116: ...stored for all DHCP relay and DHCP relay proxy instances that is for all virtual routers 2 On the E120 router the SRP 120 and the SRP 320 support a maximum of 64 000 interfaces On the E320 router the...

Page 117: ...e Manager Service definitions 2048 2048 Service sessions active 131 072 196 608 EFT 131 072 262 144 EFT Active subscriber sessions 49 152 64 000 EFT 49 152 96 000 EFT SRC Software and SDX Software COP...

Page 118: ...JunosE 11 0 2 Release Notes 110 E120 and E320 System Maximums...

Reviews: