■
Default idle timeout value for UDP- and TCP-based applications
—Upon
identification by AppID, the default idle timeout value is set to 30 seconds for
UDP-based applications and 1 hour for TCP-based applications. These settings
can be overridden by including the
idle timeout
statement at the
[edit services
application-identification application
application
]
hierarchy level.
[
Services Interfaces
]
■
New statement to bypass traffic on exceeding flow limit
—If the flow in the
service-set crosses the maximum limit set by the
max-flow
statement, the
bypass-traffic-on-exceeding-flow-limits allows the packets to bypass without
creating a new session. Following are the required privilege levels:
■
interface—To view the statement in the configuration
■
interface-control—To add the statement to the configuration
[
Services Interfaces
]
■
Diffie-Hellman group5 added to group1 and group2
—The group5 designation
specifies that IKE should use the 1536-bit Diffie-Hellman prime modulus group
when performing the new Diffie-Hellman exchange. To configure the
Diffie-Hellman group for an IKE proposal, include the
dh-group
statement at the
[edit services ipsec-vpn ike proposal
proposal-name
]
hierarchy level:
[edit services ipsec-vpn ike proposal proposal-name]
dh-group (group1 | group2| group5);
[
Services Interfaces
]
■
Permanent limitation for session-timeout on APPID
—If session-timeout is
configured for an APPID application, a session for that application will be cleared
once the session-timeout expires. Once the same session is re-created as a new
session, it will not be identified by APPID.
[
Services Interfaces
]
■
Integrated Multi-Services Gateway (IMSG)
—The
clear services
border-signaling-gateway
gateway-name
statistics
command no longer clears the
active calls counter.
[
System Basics and Services Command Reference
]
■
New configuration statements for assigning policies
—The following
configuration statements at the
[edit services border-signaling-gateway
gateway-name
service-point
service-point-name
service-policies]
hierarchy level have been
deprecated and replaced by new statements:
■
new-call-usage-policies [
policy-and-policy-set-names
]
■
new-transaction-policies [
policy-and-policy-set-names
]
Each statement applied policies to calls or transactions entering at the service
point. Each is replaced by statements that explicitly apply policies to transactions
or policies entering the service point or exiting from the service point. The new
statements are:
■
new-call-usage-input-policies [
policy-and-policy-set-names
]
■
new-call-usage-output-policies [
policy-and-policy-set-names
]
Changes in Default Behavior and Syntax in JUNOS Release 10.1 for M Series, MX Series, and T Series Routers
■
49
Changes in Default Behavior and Syntax in JUNOS Release 10.1 for M Series, MX Series, and T Series Routers