The Juniper Session Smart™ Router takes software-defined routing and SD-WAN
to a new level. It creates an application-aware network fabric that
meets the most stringent enterprise performance, security, and
availability requirements.
The router overcomes inherent inefficiencies and cost constraints of
conventional solutions with breakthrough economics and simplicity.
Deploy it as software on customer premises equipment (CPE), on data center network servers, and in the cloud. An appliance version for branch sites offers multiple WAN link options, including 4G/LTE and 5G. The Session Smart Router is centrally manageable using the AI-driven Juniper Mist Cloud or the Juniper Session Smart Conductor platform.
Key Features
Application-aware routing
Fail-safe service delivery
Orchestration and automation
Zero trust security
Centralized management using the Juniper Mist Cloud or Session Smart Conductor
Features + Benefits
Optimized for User Experience
The
only product in the industry with a network routing fabric expressly
designed to connect users with unparalleled experiences, not just
connect devices.
Breakthrough Economics
Tunnel-less
architecture enables up to 75 percent reduction in headend
infrastructure costs and 30 to 50 percent reduction in bandwidth costs.
Visibility and Insights
Delivers richer and more granular services and sessions than packet-based router solutions.
Zero Trust Security
The
session-aware fabric integrates secure vector routing with zero trust
access control, directionality, and segmentation policy.
Scale and Speed
Routing
fabric rapidly scales to thousands of sites while accelerating service
deployment through centralized orchestration of global policies.
Agility
Session-smart
fabric maintains session, tenant, and dynamic workload context end to
end, making the network more responsive to underlay conditions.
Application-Based Control
Supports load balancing and traffic steering based on session policies and network status.
Centralized Cloud Management
Simplifies deployment with easy claim-code zero-touch provisioning (ZTP), operated from the Mist AI Cloud.
The Juniper vSRX Virtual Firewall offers the same features as physical SRX Series firewalls,
including core and next-gen firewall capabilities, networking, and
automated lifecycle management, all in a virtualized form factor. It
delivers security services scalable to match network demand and operates
at speeds up to 100 Gbps.
The vSRX supports Juniper Contrail
software-defined networking (SDN) and third-party SDN solutions. It
also integrates with cloud orchestration tools such as OpenStack. Junos
Space Security Director with Policy Enforcer
automates policy enforcement and provides centralized visibility and
management of physical and virtual assets through a common interface.
The Junos Space SDK delivers on the
programmability promise of software-defined networking (SDN) by making
it easy to create custom analytic and management applications that run
on the Junos Space Network Management Platform. The connections and
intelligence embedded in the network can be leveraged to create
customized management solutions that meet specific needs and to create
new revenue streams.
The Junos Space SDK also makes it simple to safely extract data from
your network to add intelligence to existing applications and new
solutions you create. In this way, you can enable automated responses to
application and network conditions that improve the user experience.
Key Features
Real-time policy management
Energy usage tracking
Custom workflows
Network insight for business intelligence
Correlation of user subscribed services
Policy and QoS management
Features + Benefits
Flexible Applications Based on Behavior
Create better user experiences with networks and applications that make real-time changes based on behavior.
Enhanced Network Visibility and Control
Gain visibility into network activity and control outcomes using apps tailored for your specific analytic and management needs.
Better Access to Network Information
Access
network data through the Application-Layer Traffic Optimization (ALTO)
protocol, BGP-TE, GenApp interface, and other tools.
Enhanced End-User Experience
Deliver better quality of service and experiences to your customers.
Advanced Orchestration
Improve cost-effectiveness, resource optimization, and personalization of services.
New Revenue Opportunities
Discover
new offerings likely to appeal to subscribers based on the data you
collect about their habits, buying history, and preferences.
Juniper provides this document as a means to help customers and
Juniper manufacturing select a Junos software version that aligns with
their deployment needs. The releases listed below have performed well
for the general population, but note that due to the uniqueness of our
customer network deployments to include areas such as design, traffic
patterns/flows, and specific usage of features and functionality,
Juniper recommends that all customers A) read the associated Release
Notes to understand how features,
functionality, fixes, and any known outstanding issues may apply to
your specific network and applications, and B) test and certify the
suggested code version(s) to ensure they will perform as expected in
your network.
This article applies to the following devices:
ACX Series
EX Series
MX Series
NFX Series
PTX Series
QFX Series
SRX Series
For other Junos devices, refer to the Release Notes and the Alerts column on the Download Software pages.
Notes:
The software versions included in this article are selected by
utilizing input from Juniper Engineering, customers, and analysis of
field usage data.
To be automatically notified of updates to
this document, use the Subscribe link. If you do not see the Subscribe
link, log in with your user account.
Juniper Networks offers
optional fee-based services to further aide customers in selecting and
testing software releases. If interested in more information, please
contact your Juniper Sales Representative to discuss offering details
and pricing.
For use by customers and Juniper manufacturing planning an upgrade or initial installation.
Exceptions for evaluating these suggested software versions include:
A Juniper engineer has recommended that a customer use a specific
version of Junos software that is different from what is listed here in
this article.
You require specific features ( Feature Explorer
) that are available only in another version of Junos software. In that
case, be sure to download the latest maintenance release.
Your current installed version of Junos is meeting your requirements as is.
To see features supported per specific Junos versions, please go to the Juniper Pathfinder page and navigate to "Feature Explorer"
To download Junos Software, go to the Software Download site and find your product.
Suggested Junos Software Versions for your consideration and evaluation are listed in the tables below.
NOTE: To locate a Junos release containing an 'S' (i.e. Junos 17.3R3- S 3), on the Software Download product page change the OS drop-down from Junos to Junos SR
It is highly recommended to refer to the
Release Notes, Technical Documentation, and KB articles for any
outstanding and resolved issues before making the upgrade decision.
Contact JTAC if there are any queries.
Please refer to TSB16758 for minimum software requirements for newer revision EX8200 line cards.
This includes subscriber management deployments that incorporate services such as CGNAT, etc.
See KB33938 for detailed information and directly downloadable links to software for M/MX/PTX/T-Series JUNOS Software
Recently
released hardware may require a software version newer than listed
above. Please use the latest Service Release for the required JUNOS
software version
Due to feature parity recommended from Product Line Management
TSB17655
- On the SRX5000 series with SRX5k RE-13-20 a software upgrade to
Junos release 12.3X48-D80, D85, or D90 may fail the pre-check due to
insufficient space available on the compact flash.
For Junos OS upgrade paths instructions for SRX platforms, please see KB36620 .
Notes for upgrading from Junos 15.1X49 releases to 19.4R3 or 19.4R3 based Service Releases:
Junos OS upgrade from 15.1X49 directly to 19.4R3 or 19.4R3 based
Service Releases is supported for all SRX platforms (ISSU is not
supported). Note: PR1572963 - Junos OS upgrade from 15.1X49 directly to 19.4R3-S2 fails on SRX5400 / SRX5600 / SRX5800.
In case you would need to roll back or downgrade from 19.4 to the
15.1X49 release on SRX1500, SRX4100/4200, SRX5k, or vSRX, all files on
the device may be lost. Hence it is important to back up the relevant
files (configuration, license-keys, etc) before the upgrade and have
console access during the upgrade and during a potential rollback if
required.
For vSRX the following limitations apply when upgrading from 15.1X49 directly to 19.4R3 or 19.4R3 based Service Releases:
The file system mounted on /var usage must be below 14% of capacity. Check this with root@vsrx> show system storage | match " /var$" /dev/vtbd1s1f 2.7G 82M 2.4G 3% /var Note: The CLI command ‘request system storage cleanup’ may help reach that percentage if needed
The Junos upgrade image must be placed in the directory /var/host-mnt/var/tmp/ request system software add /var/host-mnt/var/tmp/
It is recommended to deploy a new vSRX VM instead of performing a
Junos upgrade. That also gives the option to move from vSRX to the newer
and more recommended vSRX 3.0.
ISSU is not supported when upgrading from Junos 15.1X49 to any higher versions.
KB34945
- When Junos Space Security Director is used for managing the SRX
configuration and the AppFW, IDP, or UTM features are used, then when
upgrading to Junos 18.2R1 or higher, the SRX configuration needs to be
migrated to the new Unified Policies style and Security Director version
19.3 or higher is required.
Starting with Junos OS Release 17.3, when you upgrade from Junos OS
Release 15.1X49 to Junos OS Release 17.3 or higher, or downgrade from
Junos OS Release 17.3 or higher to Junos OS Release 15.1X49, you must
update the IPS signature package by downloading and installing the IPS
signature package update.
2022-07-26: Update MX and PTX to be the latest 20.4R3-Sx from 20.4R3
2022-06-02: Added Latest 21.2R3-Sx as Suggested Release for all applicable EX/QFX platforms.
2022-05-27 : Added ERB and QFX5130/QFX5220/QFX5700 Suggestion to Latest 21.2R3-Sx
2022-02-22: Added EX2300-MP
2022-01-28: Added QFX5130/QFX5220/QFX5700 EVO Suggestion to 21.2R2-S1 and EVPN ERB updated to have 21.2R2-S1
2022-01-22: Removing EOE software from MX and PTX Suggested Release
2022-01-20: Added MX Series EVPN MPLS/VXLAN with latest 20.4R3-Sx
2021-12-23: Updated for SRX platforms
2021-11-19: Updated ACX7100 to 21.2R1-S2-EVO
2021-10-18: Updated ACX platforms and MX services. Removing M-Series and T-Series since the software has reached EOS
2021-10-08: Updated SRX platforms and updated note 3 with a KB link for Junos OS upgrade paths information.
2021-09-30:
Update all MX, PTX both Junos, and Junos EVO to add 20.4R3. Removed
17.3/4R3-Sx as it has reached EOE in August 2021. Adding a link to Juno
EVO Date & Milestones page.
Updated vBNG and BNG Releases
2021-08-23: Added EX4400 - 21.1R2
2021-08-19: Added QFX5200 (Nautilus) - EVO suggestion to 18.3R1-EVO
2021-08-10: Update PTX3000 and PTX5000 adding 19.3R3-S3, moving to 18.2R3-S8
2021-06-08: Update NFX150, NFX250-NG, NFX350 to 20.2R2
2021-06-01: Update MX204, MX10000s
2021-05-11: Update PTX Junos Evolve software to 20.4R2-EVO for all PTX Evo platforms
2021-05-04: Update SRX5k to 19.4R3 due to PR 1501752
2021-04-26: Updating SRX1500 to 20.2R3, due to cosmetic fan alarm issue PR1546132 leading to unnecessary RMA's. Also updated SRX380 from 20.2R2 to 20.2R3.
2021-04-13: Updated SRX notes due to upgrade issue from 15.1X49 to 19.4R3-S2 (PR1572963)
2021-04-09: Update Junos-EVO suggestion from 20.4R1-EVO to 20.4R1-S1-EVO
2021-04-02: Removed Note #2 for MX section as MS-DPC is EOL.
2021-04-01: Update MX with 20.2R2-S2 to 20.2R2-S3
2021-03-09: Added a note regarding SRX upgrade from 15.1X49 to later releases.
2021-02-24: Added 20.2R2-S2 for MPC10
2021-02-19: Removed 19.3 from MPC10 Suggested Software, moving to 19.4R3-S1
2021-01-26: Added PTX10001. Update PTX running Junos Evolved to add "Deployment" vs. "Qualify" Software Version (see KB33938 for detail)
2021-01-07: Added PTX10004. Update PTX running Junos Evolved to be 20.4R1-EVO
2020-11-13: Update most of MX series - update to latest SR, added 19.4R3 for most platforms
2020-11-03:
Fixing typo for PTX from 19.2R2-S4 (no such version) to 19.1R2-S4.
Consolidate MX2008/2010/2020 to be the MX2000 series.
2020-10-16:
Updated for SRX platforms the 12.3X48 release to D105, which is the
final release for the 12.3X48 version. Also added an additional note.
2020-10-02: Updated the MS-SPC3/MS-MPC releases. Fixed typo in MX240/480/950 with SCBE3 to MX240/480/960 with SCBE3.
2020-08-24: Consolidate PTX series to simplify the display. Create pointer to KB33938 for detail information
2020-07-29:
Updated SRX4600 from 18.4R3-S4 to 18.4R3-S3 due to an issue which may
occur during installation of 18.4R3-S4 (PR1528203)
2020-07-16: Updated SRX, PTX10003 platforms
2020-07-09: MX Subscriber Management and vBNG recommendations modified to 19.1R3-S1 and 19.4R1-S2
2020-07-07: Updated SRX Note 4 about direct upgrade from Junos 15.1X49 to 18.4R3. Added the exception for SRX5k due to PR1505864
2020-06-26: Updated ACX5448
2020-06-16: Updated SRX Note 4 about direct upgrade from Junos 15.1X49 to 18.4R3
2020-06-05: Updated SRX5k platform with RE3 / SCB4 / IOC4 and added a note.
2020-06-01: Update MX2000s with MPC11E to be 20.1R1 - reason - MACSEC support and feature parities
2020-05-15: Update PTX10003 to be 19.4R2-S1-EVO
2020-05-12: Adding MPC10E - previously missing from the list
2020-05-11: Added NFX Series section, and NFX platforms
2020-04-24: Updated SRX platforms
2020-04-21: Update MX, PTX software. Adding PTX10003, PTX10008 with LC1201-36CD and JNP10008-SF3
2020-03-30: Updated SRX Note3 for more precise listing of unsupported features in current JRR 18.2 versions.
2020-03-30: Added SRX380 platform
2020-03-02: Updated the SRX platforms which support up to Junos 12.3X48 releases
2020-01-29: Remove 16.1 from M-Series since their last version is 15.1
2020-01-22: Updated ACX5448
2020-01-13: SRX platforms updated; Deleted row for SRX Branch devices with 1G RAM due to EOS reached (see TSB17084 and the Junos Dates & Milestones page for details)
2020-01-13: MX, PTX platforms updated: Removing 15.1R7 due to reaching EOS
2019-12-30: Adding MX-SPC3 with 19.3R2 as the minimum required software
2019-12-26: updated PTX10008/16 with AC2, DC2, FAN2 recommends 19.2R1-2
2019-12-13: non-technical format changes.
2019-12-13: updated MX10008 to 19.2R1-S2
2019-12-12: updated MX204, MX10003 from 17.4R2-S8 to 18.2R3-S1
2019-12-04:
Add MX2000s with MPC11 and SFB3 2019-10-23: Corrected the download
links for Junos 18.2R3 images at the SRX300 series and SRX550HM.
2019-10-21: Changed MSMPC/MSDPC recommendation from S5 to S3 due to
session affinity changes in S4 that cause instability.
2019-10-15: Updated SRX300 series and SRX550HM to 18.2R3 from 18.2R3-S1 due to DHCP server issue PR1464267 affecting 18.2R3-S1 but not affecting 18.2R3.
2019-10-11:
Cleanup for SRX table. Combined SRX100/200 platforms which have the
same recommended release in a row. Removed notes for EOL releases.
Updated note 2 to link to TSB17655.
2019-10-11: Updated MX Subscriber to release 18.2R3-S1
2019-09-30:
Updated SRX4600, SRX5k-SPC3, SRX200, 300, 550(M), 650 series, and
SRX1k/3k, added new entries for the vSRX 3.0 and SRX5k RE3/IOC4/SCB4
2019-07-25: Updated MX Subscriber and MX Services information
2019-07-21: Adding "Important Software Upgrade Notification" at the beginning
2019-06-25: Add a link to KB33938 for details of M-Series, MX-Series, PTX-Series, and T-Series
2019-04-25: Corrected SRX download links
2019-04-16: Updated SRX releases
2019-04-10: Fixed QFabric and EX6200 links.
2019-03-19: Removing EOL released from M-series, and T-series
2019-03-01: Added note on how to locate Junos release versions containing an 's'
2019-02-28: Updated for several SRX platforms; added a link to Feature Explorer.
2019-01-30: Fixed broken links for MX and vMX.
2018-12-19: Updated JRR for SRX5k with SPC3
2018-10-15: Updated SRX JRR versions and removed SRX210B and SRX210H platforms due to EOS reached.
2018-10-05: SRX: Move direct link to JRR version to the middle column that references JRR version
2018-10-03: SRX: Added direct link to JRR version per platform
2018-09-26: Removed J-Series platforms, due to EOS reached.
2018-06-25: Updated releases for ACX, MX, and vMX platforms.
2018-05-17: Corrected link to SRX4600's software download page.
2018-05-15: Updated the recommended release for ACX5048 / ACX5096
2017-11-16: Updated VRR to 16.2
2017-04-18: Added jump links for quick access to platform series sections
The Juniper Networks Security Incident Response Team has
an email alias that makes it easy for customers and others to report
potential security vulnerabilities.
Please report any potential or real instances of security
vulnerabilities with any Juniper Networks product to the Juniper
Networks Security Incident Response Team at sirt@juniper.net. For immediate assistance, JTAC is available 24 hours a day by calling 888-314-JTAC FREE (North America) or +1-408-745-9500.
Please report any security vulnerabilities found on the Juniper
Networks external website to the IT Computer Incident Response Team at IT-CIRT@juniper.net.
First you need the network connect client software from Juniper
Networks.
If the Java plugin from Sun Microsystems is installed on your system
and you use a 32-bit Linux (sun-java6-plugin works for me on Debian/Ubuntu
32-bit), then just connect once using the standard user interface via web
browser (Firefox is supported by Juniper Networks, Opera worked for me, too).
You are asked for the root password because the setuid bit of the ncsvc binary
must be set. If you don't have a root password (e. g. because you use
Ubuntu) just press CTRL+D to abort. Nevertheless the software will be
downloaded to the directory ~/.juniper_networks/network_connect. Just
make sure the binaries have the required permissions:
If the Sun Java doesn't work on your system with Juniper (64-bit Linux)
or you don't want to use Java, just login on the web site of your Juniper
SSL/VPN and change the URL as follows: If the site's URL is
https://vpn.kit.edu enter
https://vpn.kit.edu/dana-cached/nc/ncLinuxApp.jar and download the
file ncLinuxApp.jar.
Then execute the following commands:
Download jnc, copy it to an appropriate directory (e. g.
/usr/local/bin) and make it executable:
$ chmod a+x jnc
In addition to perl openssl must be installed to use it. If you want to use
the GUI, Java from Sun Microsystems must be available, too, of course.
If you use a 64-bit Linux the Network Connect Java GUI will not work. So
remember to start jnc with option --nox (or -n), see below. Also install the
32-bit versions of the required libraries.
On Debian/Ubuntu: # apt-get install libc6-i386 lib32z1 lib32nss-mdns
On RH 6 and higher: # yum install glibc.i686 zlib.i686 nss.i686
and create a configuration file in this directory. It must be named
somename.conf.
Example config file
(Karlsruhe Institute of Technology (KIT) users: click here)
host=foo.bar.com
user=username
password=secret
realm=very long realm with spaces
cafile=/etc/ssl/bar-chain.pem
certfile=
password and realm are optional.
cafile: ca chain to verify the host certificate
certfile: host certificate in DER format
cafile or certfile must be configured.
For cafile/certfile you have to use the full path.
You must not use ~, it won't be expanded.
If you don't know about any realm there's possibly only one, so you
can omit this configuration option. You can also find out your realm
by viewing the page source of your sign-in page: just search for the
word realm in it.
Start network connect with
$ jnc somename
or
$ jnc --nox somename
for use without GUI. To stop the client, just (click Sign Out in
the Java GUI or) execute
$ jnc stop
For more options see
$ jnc --help
Updating the client: if your Juniper SSL/VPN site was
upgraded to a new firmware version there could be also a new network
connect client version available. To get it, just repeat step one
in this howto. You don't have to remove any files before.
The Junos Space SDK provides a means for developing end-user
specific applications that accesses the capabilities and
resources provided by the Junos Space Platform environment.
Implementation exposes Junos Space Platform resources through a
Web-based (HTTP) interface using Representational State Transfer
(REST) APIs. Developers can browse the existing REST Web
services using a customized HTTP-enabled client application.
Under this environment, a Web browser client application or a
standalone client application can make HTTP requests to access
related information, which is available to the Junos Space
Platform.
The Junos Space SDK also provides a mechanism for application
developers to expose their own Web services as RESTful APIs.
REST Design
The Junos Space SDK development system implements the REST
architectural style to accomplish its goals:
Representational State Transfer (REST) is a concept
that employs the Web's stateless client-server model. It
represents REST Web services as resources identified by
URLs.
Resources can be added, modified, or deleted using the CRUD
APIs. Resources can also expose their own method links,
which, when accessed, perform a certain action on the
resource. (Source: RESTful
Web Services.)
In REST, requests and responses are built around the
transfer of "representations" of "resources". A resource can
be any object that can be addressed. A representation of a
resource is typically an XML or JSON document that captures
the current or intended state of a resource. (Source:
http://en.wikipedia.org/wiki/Representational_State_Transfer.)
Hypermedia As The Engine Of Application State
(HATEOAS) is a constraint on REST that says that a client of a
REST application must only know a single fixed URL to access
it. Any and all resources should be discoverable dynamically
from that URL, through hyperlinks included in the
representations of returned resources.
SDK Elements
The Junos Space SDKToolkit helps in the
development of Junos Space applications. These
applications can then be deployed on the Junos Space
Platform. The SDK Toolkit comes pre-loaded with the Junos
Space Virtual Appliance (JSVA), which can be used to
emulate the Junos Space Platform for functional
verification of the developed application.
Note: All applications must be signed with a certificate
(issued by Juniper Networks) to be deployed into production
environments, but they do not require a certificate when deployed on
the JSVA.
The Junos Space SDK development system consists of these components:
Development Tools
The Junos Space Eclipse plug-in installed on an Eclipse IDE.
The Junos Space Eclipse plug-in allows wizard-based
creation of different types of Junos Space applications,
automated build, and deployment of applications for test
and debug purposes, control of device simulations on a
device simulator, and other features.
REST Web Services interfaces
Interfaces to the core capabilities of the Junos Space
platform. These REST Web Service interfaces are a part of
the Junos Space network application platform.
Device and environment simulators
The development environment includes the Junos Space
Virtual Appliance that provides access to:
A fully functional instance of the Junos Space network
application for use in deploying and testing
applications developed using the Junos Space SDK.
Device and element simulators providing the ability to
test applications against virtual Juniper Network
devices.
Performance, Analytics, Security, and Profiling tools
While the Junos Space SDK does not ship performance,
analytics, security, or profiling tools, it is compatible
with the most popular tools available today, such as
VisualVM, JBoss Tools, and so on.
Reference Apps
Reference applications, including annotated source code.
These applications provide examples for developers to
learn from and use.
Documentation and Online Resources
The SDK install package includes complete documentation
for using the SDK, including an Installation Guide, an API
Reference, and an Application Developer Guide. The
latter two are provided in the Eclipse plug-in as online
help. Finally, the SDK includes reference applications
demonstrating how to use the many SDK features.
From the SDK user's perspective, the SDK Web development
environment looks like the following: