the commit process is complete. This behavior occurs whether you have a list
or regular expressions (for example, regular-expression [sip:88824.* sip:88821.*
sip:88822.sip:88823.*]), or you group regular expressions using the | symbol
(for example, "sip:88821.*|sip:88822.*|sip:88823.*|sip:88824.*").
The time taken for the software to apply the configuration changes increases
exponentially with the number of regular expressions in your configuration.
[PR/448474]
■
Under some failure scenarios, a switchover of the active BSG from a master to
a backup MS-PIC/MS-DPC may take more than two seconds. [PR/467837]
■
A performance-related issue may occur when the IDP plug-in is enabled. The
connection per second for HTTP (64 bytes) with AACL, AI, and IDP (with
Recommended Attacks group) plug-ins has been downgraded to 7.6K through
7.9K per second. [PR/476162]
■
When a standard application is specified under the
[edit security idp idp-policy
policy-name
rulebase-ips rule
rule-name
match application]
hierarchy level, the IDP
does not detect the attack on the non-standard port (for example, junos:ftp on
port 85). [PR/477748]
■
In the export version of the JUNOS Software, the signature download does not
work for AppID and IDP features in the Dynamic Application Awareness (DAA)
suite. In order to resolve this, install the Crypto software suite. [PR/499395]
■
When a backup gateway is configured in any term under an IPsec stanza, for
any subsequent terms where this backup gateway is now configured as the
primary, IPsec tunnel establishment will fail. [PR/510608]
■
The IPv6 gateway may have a NULL value when the destination address points
to an aggregated next hop. [PR/516058]
Subscriber Access Management
■
The
revert-interval
value configured in the
[edit access profile]
hierarchy level is
ignored. [PR/454040]
■
The RADIUS accounting stop messages do not include the Acct-Terminate-Cause
attribute (type 49). [PR/458034]
■
For a dynamic PPPoE interface in which the subscriber is assigned to a
non-default routing-instance (via the LSRI-Name or redirect-LSRI-Name RADIUS
VSAs), the IP address assigned to the subscriber must be specified via the
framed-ip-address RADIUS attribute. An IP address can not be allocated from a
local pool defined in the assigned routing-instance, either when RADIUS returns
no address attributes or when the RADIUS framed-pool attribute is returned.
[PR/471677]
User Interface and Configuration
■
Deletion of configuration groups cannot be prevented with the allow-configuration
and deny-configuration statements. [PR/59187]
■
On M20 routers, after a Routing Engine mastership switchover, it might not be
possible to enter CLI configuration mode on the new master Routing Engine.
Issues in JUNOS Release 10.1 for M Series, MX Series, and T Series Routers
■
63
Issues in JUNOS Release 10.1 for M Series, MX Series, and T Series Routers