Thursday, 1 September 2022

Junos Space SDK

 

The Junos Space SDK delivers on the programmability promise of software-defined networking (SDN) by making it easy to create custom analytic and management applications that run on the Junos Space Network Management Platform. The connections and intelligence embedded in the network can be leveraged to create customized management solutions that meet specific needs and to create new revenue streams.

The Junos Space SDK also makes it simple to safely extract data from your network to add intelligence to existing applications and new solutions you create. In this way, you can enable automated responses to application and network conditions that improve the user experience.

Key Features


  • Real-time policy management 
  • Energy usage tracking 
  • Custom workflows 
  • Network insight for business intelligence 
  • Correlation of user subscribed services
  • Policy and QoS management

Features + Benefits

Flexible Applications Based on Behavior

Create better user experiences with networks and applications that make real-time changes based on behavior.

Enhanced Network Visibility and Control

Gain visibility into network activity and control outcomes using apps tailored for your specific analytic and management needs.

Better Access to Network Information

Access network data through the Application-Layer Traffic Optimization (ALTO) protocol, BGP-TE, GenApp interface, and other tools.

Enhanced End-User Experience

Deliver better quality of service and experiences to your customers.

Advanced Orchestration

Improve cost-effectiveness, resource optimization, and personalization of services.

New Revenue Opportunities

Discover new offerings likely to appeal to subscribers based on the data you collect about their habits, buying history, and preferences.

Monday, 1 August 2022

Junos Software Versions - Suggested Releases to Consider and Evaluate

 Juniper provides this document as a means to help customers and Juniper manufacturing select a Junos software version that aligns with their deployment needs. The releases listed below have performed well for the general population, but note that due to the uniqueness of our customer network deployments to include areas such as design, traffic patterns/flows, and specific usage of features and functionality, Juniper recommends that all customers A) read the associated Release Notes to understand how features, functionality, fixes, and any known outstanding issues may apply to your specific network and applications, and B) test and certify the suggested code version(s) to ensure they will perform as expected in your network.

This article applies to the following devices:

  • ACX Series
  • EX Series
  • MX Series
  • NFX Series
  • PTX Series
  • QFX Series
  • SRX Series

For other Junos devices, refer to the Release Notes and the Alerts column on the Download Software pages.

Notes:

  1. The software versions included in this article are selected by utilizing input from Juniper Engineering, customers, and analysis of field usage data.
  2. To be automatically notified of updates to this document, use the Subscribe link. If you do not see the Subscribe link, log in with your user account.
  3. ​Juniper Networks offers optional fee-based services to further aide customers in selecting and testing software releases. If interested in more information, please contact your Juniper Sales Representative to discuss offering details and pricing.

For use by customers and Juniper manufacturing planning an upgrade or initial installation.

Exceptions for evaluating these suggested software versions include:

  • A Juniper engineer has recommended that a customer use a specific version of Junos software that is different from what is listed here in this article.

  • You require specific features ( Feature Explorer ) that are available only in another version of Junos software. In that case, be sure to download the latest maintenance release.

  • Your current installed version of Junos is meeting your requirements as is.

  • If you use NSM, refer to the NSM & Junos Compatibility Matrix to make sure the suggested Junos software version can be managed by NSM.


To see the list​ of End of Engineering (EOE) and EOS (End of Support) dates for specific Junos versions, please go to the Junos Dates & Milestones page or the Junos OS Evolved Dates & Milestones page

To see features supported per specific Junos versions, please go to the Juniper Pathfinder page and navigate to "Feature Explorer"


To download Junos Software, go to the Software Download  site and find your product.

Suggested Junos Software Versions for your consideration and evaluation are listed in the tables below. 

NOTE: To locate a Junos release containing an 'S' (i.e. Junos 17.3R3- S 3), on the Software Download product page change the OS drop-down from Junos to Junos SR
 

Select to jump to a platform series:

 

EX Series Ethernet Switches

PlatformJunos Software by PlatformLast
Updated
EX2200  (See Note 3)Latest Junos 12.3R12-Sx1 Feb 2022
EX2200-C  ( See Note 3)Latest Junos 12.3R12-Sx1 Feb 2022
EX2300 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EX2300-C Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EX2300-MP Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EX3200 Latest Junos 12.3R12-Sx1 Feb 2022
EX3300  ( See Note 4)Latest Junos 12.3R12-Sx1 Feb 2022
EX3400 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EX4200  Latest Junos 12.3R12-Sx / 15.1R7-Sx     1 Feb 2022
EX4300 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EX4300-MP Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EX4400 Latest Junos 21.2R3-Sx2 Jun 2022
EX4500  Latest Junos 12.3R12-Sx / 15.1R7-Sx1 Feb 2022
EX4550  Latest Junos 12.3R12-Sx / 15.1R7-Sx1 Feb 2022
EX4600 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EX4650 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EX6200 Latest Junos 12.3R12-Sx / 15.1R7-Sx1 Feb 2022
EX8200 (See Note 2)Latest Junos 12.3R12-Sx / 15.1R7-Sx1 Feb 2022
EX8200-VC (XRE200) (See Note 2 )Latest Junos 12.3R12-Sx / 15.1R7-Sx1 Feb 2022
EX9200  Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EX9251 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EX9253 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
Junos Fusion Enterprise (JFE) Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
 

Notes:

  1. It is highly recommended to refer to the Release Notes, Technical Documentation, and KB articles for any outstanding and resolved issues before making the upgrade decision. Contact JTAC if there are any queries.
  2. Please refer to  TSB16758  for minimum software requirements for newer revision EX8200 line cards.
  3. Please refer to  TSB17138 for more details.
  4. Please refer to  TSB17329 .
( back to the top )


ACX Series Service Routers

PlatformJunos Software by PlatformLast
Updated
ACX500 Latest Junos 20.2R3-Sx
Latest Junos 20.4 (LSV Outdoor)      
Latest Junos 21.2 (LSV Indoor)
2 Nov 2021
ACX710 Latest Junos 20.4R3-Sx18 Oct 2021
ACX1000 Latest Junos 20.4R3-Sx
Latest Junos 21.2 (LSV)
18 Oct 2021
ACX1100 Latest Junos 20.4R3-Sx
Latest Junos 21.2 (LSV)
18 Oct 2021
ACX2000 Latest Junos 20.4R3-Sx
Latest Junos 21.2 (LSV)
18 Oct 2021
ACX2100 Latest Junos 20.4R3-Sx
Latest Junos 21.2 (LSV)
18 Oct 2021
ACX2200 Latest Junos 20.4R3-Sx
Latest Junos 21.2 (LSV)
18 Oct 2021
ACX4000 Latest Junos 20.4R3-Sx
Latest Junos 21.2 (LSV)
18 Oct 2021
ACX5448 Latest Junos 20.4R3-Sx18 Oct 2021
ACX5048 / ACX5096 Latest Junos 20.4R3-Sx18 Oct 2021
ACX7100 Junos Evolved 21.2R2-S1-EVO  20 Jan 2022

( back to the top )

MX and PTX Series Routers

PlatformJunos Software by PlatformLast
Updated
PTX Series (See KB33938 for detail)
    (Except ones listing below)
Latest Junos 19.4R3-Sx
Latest Junos 20.4R3-Sx
26 July 2022
PTX10001-36MRLatest Junos Evolved 20.4R3-Sx-EVO26 Jul 2022
PTX10003Latest Junos Evolved 20.4R3-Sx-EVO26 Jul 2022
PTX10004Latest Junos Evolved 20.4R3-Sx-EVO26 Jul 2022
PTX10008/16 with FAN2/AC2/DC2 Components
    (Do not use if deploy - JNP10008-SF3)
Latest Junos 19.4R3-Sx
Latest Junos 20.2R3-Sx
Latest Junos 20.4R3-Sx
26 Jul 2022
PTX10008 with PTX10K-LC1201-36CD and JNP100008-SF3
JNP10K-RE1-E
Latest Junos Evolved 20.4R3-Sx-EVO26 Jul 2022
PTX10008 with PTX10K-LC1202 and JNP100008-SF3
JNP10K-RE1-E
Latest Junos Evolved 20.4R3-SxEVO26 Jul 2022
MX SeriesLatest Junos 19.4R3-Sx
Latest Junos 20.2R3-Sx
Latest Junos 20.4R3-Sx
26 Jul 2022
MX Series with MX-SPC3 Latest Junos 21.2R2-Sx 10 Jan 2022
MX 2008/2010/2020 See MX Series 
MX240/480/960 with SCBE3Latest Junos 19.4R3-Sx
Latest Junos 20.2R3-Sx
Latest Junos 20.4R3-Sx
26 Jul 2022
MX240/480/960 with MPC10E Latest Junos 20.2R3-Sx
Latest Junos 20.4R3-Sx
26 July 2022
MX5, MX10, MX40, MX80, MX104 SeriesSee MX Series 
MX150, MX204, MX10003 SeriesSee MX Series 
MX10008/16 SeriesLatest Junos 19.4R3-Sx
Latest Junos 20.2R3-Sx
LatestJunos 20.4R3-Sx
26 July 2022
MX Series with EVPN MPLS/VXLANLatest Junos 20.4R3-Sx20 Jan 2022
MX Subscriber Management (*1) Latest Junos 20.4R3-Sx30 Sept 2021
MX Services on MS-MPC/MIC (*3) Latest Junos 21.2R2-Sx10 Jan 2022
vMX / vBNG (*2) Latest Junos 20.4R3-Sx30 Sept 2021
 

Notes:

  1. This includes subscriber management deployments that incorporate services such as CGNAT, etc.
  2. See KB33938 for detailed information and directly downloadable links to software for M/MX/PTX/T-Series JUNOS Software
  3. Recently released hardware may require a software version newer than listed above. Please use the latest Service Release for the required JUNOS software version
  4. Due to feature parity recommended from Product Line Management
  5. MPC11 is not supported in Junos 19.4
  ( back to the top )


NFX Series Network Services Platform

PlatformJunos ReleaseSoftware ArchitectureRelease TypeLast
Updated
NFX150 Junos 20.2R2nfx-3Service08 Jun 2021
NFX250 Junos 18.4R3nfx-2Standard11 May 2020
NFX250-NG Junos 20.2R2nfx-3Standard08 Jun 2021
NFX350 Junos 20.2R2nfx-3Standard08 Jun 2021

( back to the top )

QFX Series

PlatformJunos Software by PlatformLast
Updated
QFX5220/QFX5130/QFX5700 Latest Junos Evolved 21.2R3-Sx27 May 2022
QFX5100  Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
QFX5200 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
QFX5110 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
QFX5120-32C Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
QFX5120 -48Y Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
QFX5120-48T Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
QFX5210 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
QFX10002 / QFX10008 / QFX10016 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
QFX10002-60C Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EVPN-VXLAN Fabric CRB (Centrally Routed Bridging) Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
EVPN-VXLAN Fabric ERB ( Edge Routed Bridging)  Latest Junos 20.4R3-Sx / 21.2R3-Sx   27 May 2022
IP-Fabric ( QFX10K and QFX5K) Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
VCF-QFX5110 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
VCF-QFX5100 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
VC-QFX5100 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
VC-QFX5110 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
VC-QFX5120 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
VC-QFX5120-32C Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
VC-QFX5200 Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
MC-LAG (QFX5K) Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
MC-LAG (QFX10K) Latest 20.4R3-Sx/21.2R3-Sx2 Jun 2022
Qfabric (See Note 1)Junos 14.1X53-D13030 Jul 2019

 

Note:

  1. Qfabric NSSU upgrade from Junos 12.2X50 to later releases is NOT recommended. Please see TSB16842 for more details.

( back to the top )


SRX Series Services Gateways

PlatformJunos Software by PlatformRelease TypeLast
Updated
vSRXJunos 20.4R3-S1 Service23 Dec 2021
vSRX 3.0Junos 20.4R3-S1 Service23 Dec 2021
SRX100H2 / SRX110H2 / SRX210HE2 / SRX220H2 / SRX240H2Junos 12.3X48-D105 Standard16 Oct 2020
SRX300 / SRX320 / SRX340 / SRX345Junos 20.2R3-S2 Service08 Oct 2021
SRX380Junos 20.4R3-S1 Service23 Dec 2021
SRX550Junos 12.3X48-D105 Standard16 Oct 2020
SRX550HMJunos 20.2R3-S2 Service08 Oct 2021
SRX650Junos 12.3X48-D105 Standard16 Oct 2020
SRX1400Junos 12.3X48-D105 Standard16 Oct 2020
SRX1500Junos 20.4R3-S1 Service23 Dec 2021
SRX3400 / SRX3600Junos 12.3X48-D105 Standard16 Oct 2020
SRX4100 / SRX4200Junos 20.4R3-S1 Service23 Dec 2021
SRX4600Junos 20.4R3-S1 Service23 Dec 2021
SRX5400 / SRX5600 / SRX5800
with SRX5K-RE3-128G (*1)
Junos 20.4R3-S1 Service23 Dec 2021
SRX5400 / SRX5600 / SRX5800
with RE-1800X4 (*1)
Junos 20.4R3-S1 Service23 Dec 2021
SRX5400 / SRX5600 / SRX5800
with SRX5K-RE-13-20 (*1)
Junos 12.3X48-D105 (*2) Standard16 Oct 2020
 

Notes:

  1. KB30446 - SRX Junos SRX5K Hardware / Software compatibility matrix.

  2. TSB17655  - On the SRX5000 series with SRX5k RE-13-20 a software upgrade to Junos release 12.3X48-D80, D85, or D90 may fail the pre-check due to insufficient space available on the compact flash.

  3. For Junos OS upgrade paths instructions for SRX platforms, please see  KB36620 .

  4. Notes for upgrading from Junos 15.1X49 releases to 19.4R3 or 19.4R3 based Service Releases:

    • Junos OS upgrade from 15.1X49 directly to 19.4R3 or 19.4R3 based Service Releases is supported for all SRX platforms (ISSU is not supported). Note: PR1572963 - Junos OS upgrade from 15.1X49 directly to 19.4R3-S2 fails on SRX5400 / SRX5600 / SRX5800.

    • In case you would need to roll back or downgrade from 19.4 to the 15.1X49 release on SRX1500, SRX4100/4200, SRX5k, or vSRX, all files on the device may be lost. Hence it is important to back up the relevant files (configuration, license-keys, etc) before the upgrade and have console access during the upgrade and during a potential rollback if required.

    • For vSRX the following limitations apply when upgrading from 15.1X49 directly to 19.4R3 or 19.4R3 based Service Releases:

      • The file system mounted on /var usage must be below 14% of capacity.
        Check this with
        root@vsrx> show system storage | match " /var$"
        /dev/vtbd1s1f 2.7G 82M 2.4G 3% /var

        Note: The CLI command ‘request system storage cleanup’ may help reach that percentage if needed

      • The Junos upgrade image must be placed in the directory /var/host-mnt/var/tmp/
        request system software add /var/host-mnt/var/tmp/

      • It is recommended to deploy a new vSRX VM instead of performing a Junos upgrade. That also gives the option to move from vSRX to the newer and more recommended vSRX 3.0.
         

    • ISSU is not supported when upgrading from Junos 15.1X49 to any higher versions.

    • KB34945 - When Junos Space Security Director is used for managing the SRX configuration and the AppFW, IDP, or UTM features are used, then when upgrading to Junos 18.2R1 or higher, the SRX configuration needs to be migrated to the new Unified Policies style and Security Director version 19.3 or higher is required.

    • Starting with Junos OS Release 17.3, when you upgrade from Junos OS Release 15.1X49 to Junos OS Release 17.3 or higher, or downgrade from Junos OS Release 17.3 or higher to Junos OS Release 15.1X49, you must update the IPS signature package by downloading and installing the IPS signature package update.

( back to the top )

 

  • 2022-07-26: Update MX and PTX to be the latest 20.4R3-Sx from 20.4R3
  • 2022-06-02: Added Latest 21.2R3-Sx as Suggested Release for all applicable EX/QFX platforms.
  • 2022-05-27 : Added ERB and QFX5130/QFX5220/QFX5700 Suggestion to Latest 21.2R3-Sx
  • 2022-02-22: Added EX2300-MP
  • 2022-01-28: Added QFX5130/QFX5220/QFX5700 EVO Suggestion to 21.2R2-S1 and EVPN ERB updated to have 21.2R2-S1
  • 2022-01-22: Removing EOE software from MX and PTX Suggested Release
  • 2022-01-20: Added MX Series EVPN MPLS/VXLAN with latest 20.4R3-Sx
  • 2021-12-23: Updated for SRX platforms
  • 2021-11-19: Updated ACX7100 to 21.2R1-S2-EVO
  • 2021-10-18: Updated ACX platforms and MX services. Removing M-Series and T-Series since the software has reached EOS
  • 2021-10-08: Updated SRX platforms and updated note 3 with a KB link for Junos OS upgrade paths information.
  • 2021-09-30: Update all MX, PTX both Junos, and Junos EVO to add 20.4R3. Removed 17.3/4R3-Sx as it has reached EOE in August 2021. Adding a link to Juno EVO Date & Milestones page.
  • Updated vBNG and BNG Releases
  • 2021-08-23: Added EX4400 - 21.1R2
  • 2021-08-19: Added QFX5200 (Nautilus) - EVO suggestion to 18.3R1-EVO
  • 2021-08-10: Update PTX3000 and PTX5000 adding 19.3R3-S3, moving to 18.2R3-S8 
  • 2021-06-08: Update NFX150, NFX250-NG, NFX350 to 20.2R2
  • 2021-06-01: Update MX204, MX10000s
  • 2021-05-11: Update PTX Junos Evolve software to 20.4R2-EVO for all PTX Evo platforms
  • 2021-05-04: Update SRX5k to 19.4R3 due to PR 1501752
  • 2021-04-26: Updating SRX1500 to 20.2R3, due to cosmetic fan alarm issue PR1546132 leading to unnecessary RMA's. Also updated SRX380 from 20.2R2 to 20.2R3.
  • 2021-04-13: Updated SRX notes due to upgrade issue from 15.1X49 to 19.4R3-S2 (PR1572963)
  • 2021-04-09: Update Junos-EVO suggestion from 20.4R1-EVO to 20.4R1-S1-EVO
  • 2021-04-02: Removed Note #2 for MX section as MS-DPC is EOL.
  • 2021-04-01: Update MX with 20.2R2-S2 to 20.2R2-S3
  • 2021-03-09: Added a note regarding SRX upgrade from 15.1X49 to later releases.
  • 2021-02-24: Added 20.2R2-S2 for MPC10
  • 2021-02-19: Removed 19.3 from MPC10 Suggested Software, moving to 19.4R3-S1
  • 2021-01-26: Added PTX10001. Update PTX running Junos Evolved to add "Deployment" vs. "Qualify" Software Version (see KB33938  for detail)
  • 2021-01-07: Added PTX10004. Update PTX running Junos Evolved to be 20.4R1-EVO
  • 2021-01-06: Updated for SRX platforms
  • 2020-11-17: Added QFX Architecture( VCF, VC, MC-LAG, IP-Fabric) 
  • 2020-11-13: Update most of MX series - update to latest SR, added 19.4R3 for most platforms
  • 2020-11-03: Fixing typo for PTX from 19.2R2-S4 (no such version) to 19.1R2-S4. Consolidate MX2008/2010/2020 to be the MX2000 series.
  • 2020-10-16: Updated for SRX platforms the 12.3X48 release to D105, which is the final release for the 12.3X48 version. Also added an additional note.
  • 2020-10-02: Updated the MS-SPC3/MS-MPC releases. Fixed typo in MX240/480/950 with SCBE3 to MX240/480/960 with SCBE3.
  • 2020-08-24: Consolidate PTX series to simplify the display. Create pointer to KB33938 for detail information
  • ​2020-07-29: Updated SRX4600 from 18.4R3-S4 to 18.4R3-S3 due to an issue which may occur during installation of 18.4R3-S4 (PR1528203)
  • 2020-07-16: Updated SRX, PTX10003 platforms
  • 2020-07-09: MX Subscriber Management and vBNG recommendations modified to 19.1R3-S1 and 19.4R1-S2
  • 2020-07-07: Updated SRX Note 4 about direct upgrade from Junos 15.1X49 to 18.4R3. Added the exception for SRX5k due to PR1505864
  • 2020-06-26: Updated ACX5448
  • 2020-06-16: Updated SRX Note 4 about direct upgrade from Junos 15.1X49 to 18.4R3
  • 2020-06-05: Updated SRX5k platform with RE3 / SCB4 / IOC4 and added a note.
  • 2020-06-01: Update MX2000s with MPC11E to be 20.1R1 - reason - MACSEC support and feature parities
  • 2020-05-15: Update PTX10003 to be 19.4R2-S1-EVO
  • 2020-05-12: Adding MPC10E - previously missing from the list
  • 2020-05-11: Added NFX Series section, and NFX platforms
  • 2020-04-24: Updated SRX platforms
  • 2020-04-21: Update MX, PTX software. Adding PTX10003, PTX10008 with LC1201-36CD and JNP10008-SF3
  • 2020-03-30: Updated SRX Note3 for more precise listing of unsupported features in current JRR 18.2 versions.
  • 2020-03-30: Added SRX380 platform
  • 2020-03-02: Updated the SRX platforms which support up to Junos 12.3X48 releases
  • 2020-01-29: Remove 16.1 from M-Series since their last version is 15.1
  • 2020-01-22: Updated ACX5448
  • 2020-01-13: SRX platforms updated; Deleted row for SRX Branch devices with 1G RAM due to EOS reached (see TSB17084 and the Junos Dates & Milestones page for details)
  • 2020-01-13: MX, PTX platforms updated: Removing 15.1R7 due to reaching EOS
  • 2019-12-30: Adding MX-SPC3 with 19.3R2 as the minimum required software
  • 2019-12-26: updated PTX10008/16 with AC2, DC2, FAN2 recommends 19.2R1-2
  • 2019-12-13: non-technical format changes.
  • 2019-12-13: updated MX10008 to 19.2R1-S2
  • 2019-12-12: updated MX204, MX10003 from 17.4R2-S8 to 18.2R3-S1
  • 2019-12-04: Add MX2000s with MPC11 and SFB3 2019-10-23: Corrected the download links for Junos 18.2R3 images at the SRX300 series and SRX550HM. 2019-10-21: Changed MSMPC/MSDPC recommendation from S5 to S3 due to session affinity changes in S4 that cause instability.
  • 2019-10-15: Updated SRX300 series and SRX550HM to 18.2R3 from 18.2R3-S1 due to DHCP server issue  PR1464267  affecting 18.2R3-S1 but not affecting 18.2R3.
  • 2019-10-11: Cleanup for SRX table. Combined SRX100/200 platforms which have the same recommended release in a row. Removed notes for EOL releases. Updated note 2 to link to TSB17655.
  • 2019-10-11: Updated MX Subscriber to release 18.2R3-S1
  • 2019-09-30: Updated SRX4600, SRX5k-SPC3, SRX200, 300, 550(M), 650 series, and SRX1k/3k, added new entries for the vSRX 3.0 and SRX5k RE3/IOC4/SCB4
  • 2019-07-25: Updated MX Subscriber and MX Services information
  • 2019-07-21: Adding "Important Software Upgrade Notification" at the beginning
  • 2019-06-25: Add a link to KB33938 for details of M-Series, MX-Series, PTX-Series, and T-Series
  • 2019-04-25: Corrected SRX download links
  • 2019-04-16: Updated SRX releases
  • 2019-04-10: Fixed QFabric and EX6200 links. 
  • 2019-03-19: Removing EOL released from M-series, and T-series
  • 2019-03-01: Added note on how to locate Junos release versions containing an 's'
  • 2019-02-28: Updated for several SRX platforms; added a link to Feature Explorer.
  • 2019-01-30: Fixed broken links for MX and vMX.
  • 2018-12-19: Updated JRR for SRX5k with SPC3
  • 2018-10-15: Updated SRX JRR versions and removed SRX210B and SRX210H platforms due to EOS reached.
  • 2018-10-05: SRX: Move direct link to JRR version to the middle column that references JRR version
  • 2018-10-03: SRX: Added direct link to JRR version per platform
  • 2018-09-26: Removed J-Series platforms, due to EOS reached.
  • 2018-06-25: Updated releases for ACX, MX, and vMX platforms.
  • 2018-05-17: Corrected link to SRX4600's software download page.
  • 2018-05-15: Updated the recommended release for ACX5048 / ACX5096
  • 2017-11-16: Updated VRR to 16.2
  • 2017-04-18: Added jump links for quick access to platform series sections


Friday, 1 July 2022

Junos : Report a Security Vulnerability

 

The Juniper Networks Security Incident Response Team has an email alias that makes it easy for customers and others to report potential security vulnerabilities.

Please report any potential or real instances of security vulnerabilities with any Juniper Networks product to the Juniper Networks Security Incident Response Team at sirt@juniper.net. For immediate assistance, JTAC is available 24 hours a day by calling 888-314-JTAC FREE (North America) or +1-408-745-9500.

Please report any security vulnerabilities found on the Juniper Networks external website to the IT Computer Incident Response Team at IT-CIRT@juniper.net.

Wednesday, 1 June 2022

Juniper SSL/VPN for Linux Users

 

Howto

  1. First you need the network connect client software from Juniper Networks.
    • If the Java plugin from Sun Microsystems is installed on your system and you use a 32-bit Linux (sun-java6-plugin works for me on Debian/Ubuntu 32-bit), then just connect once using the standard user interface via web browser (Firefox is supported by Juniper Networks, Opera worked for me, too). You are asked for the root password because the setuid bit of the ncsvc binary must be set. If you don't have a root password (e. g. because you use Ubuntu) just press CTRL+D to abort. Nevertheless the software will be downloaded to the directory ~/.juniper_networks/network_connect. Just make sure the binaries have the required permissions:

      $ sudo chown root:root ~/.juniper_networks/network_connect/ncsvc
      $ sudo chmod 6711 ~/.juniper_networks/network_connect/ncsvc
      $ chmod 744 ~/.juniper_networks/network_connect/ncdiag

    • If the Sun Java doesn't work on your system with Juniper (64-bit Linux) or you don't want to use Java, just login on the web site of your Juniper SSL/VPN and change the URL as follows:
      If the site's URL is https://vpn.kit.edu enter https://vpn.kit.edu/dana-cached/nc/ncLinuxApp.jar and download the file ncLinuxApp.jar.
      Then execute the following commands:

      $ mkdir -p ~/.juniper_networks/network_connect/
      $ unzip ncLinuxApp.jar -d ~/.juniper_networks/network_connect/
      $ sudo chown root:root ~/.juniper_networks/network_connect/ncsvc
      $ sudo chmod 6711 ~/.juniper_networks/network_connect/ncsvc
      $ chmod 744 ~/.juniper_networks/network_connect/ncdiag

  2. Download jnc, copy it to an appropriate directory (e. g. /usr/local/bin) and make it executable:

    $ chmod a+x jnc

    In addition to perl openssl must be installed to use it. If you want to use the GUI, Java from Sun Microsystems must be available, too, of course.

    If you use a 64-bit Linux the Network Connect Java GUI will not work. So remember to start jnc with option --nox (or -n), see below. Also install the 32-bit versions of the required libraries.

    On Debian/Ubuntu:
    # apt-get install libc6-i386 lib32z1 lib32nss-mdns

    On RH 6 and higher:
    # yum install glibc.i686 zlib.i686 nss.i686

  3. Create the directory for the configuration files

    $ mkdir -p ~/.juniper_networks/network_connect/config

    and create a configuration file in this directory. It must be named somename.conf.

    Example config file
    (Karlsruhe Institute of Technology (KIT) users: click here)

    host=foo.bar.com
    user=username
    password=secret
    realm=very long realm with spaces
    cafile=/etc/ssl/bar-chain.pem
    certfile=
    

    password and realm are optional.
    cafile: ca chain to verify the host certificate
    certfile: host certificate in DER format
    cafile or certfile must be configured.

    For cafile/certfile you have to use the full path. You must not use ~, it won't be expanded.

    If you don't know about any realm there's possibly only one, so you can omit this configuration option. You can also find out your realm by viewing the page source of your sign-in page: just search for the word realm in it.

  4. Start network connect with

    $ jnc somename

    or

    $ jnc --nox somename

    for use without GUI. To stop the client, just (click Sign Out in the Java GUI or) execute

    $ jnc stop

    For more options see

    $ jnc --help

  5. Updating the client: if your Juniper SSL/VPN site was upgraded to a new firmware version there could be also a new network connect client version available. To get it, just repeat step one in this howto. You don't have to remove any files before.

Sunday, 1 May 2022

Understanding the Junos Space SDK

 

The Junos Space SDK provides a means for developing end-user specific applications that accesses the capabilities and resources provided by the Junos Space Platform environment. Implementation exposes Junos Space Platform resources through a Web-based (HTTP) interface using Representational State Transfer (REST) APIs. Developers can browse the existing REST Web services using a customized HTTP-enabled client application. Under this environment, a Web browser client application or a standalone client application can make HTTP requests to access related information, which is available to the Junos Space Platform.

The Junos Space SDK also provides a mechanism for application developers to expose their own Web services as RESTful APIs.

REST Design

The Junos Space SDK development system implements the REST architectural style to accomplish its goals:

  • Representational State Transfer (REST) is a concept that employs the Web's stateless client-server model. It represents REST Web services as resources identified by URLs.

    Resources can be added, modified, or deleted using the CRUD APIs. Resources can also expose their own method links, which, when accessed, perform a certain action on the resource. (Source: RESTful Web Services.)

    In REST, requests and responses are built around the transfer of "representations" of "resources". A resource can be any object that can be addressed. A representation of a resource is typically an XML or JSON document that captures the current or intended state of a resource. (Source: http://en.wikipedia.org/wiki/Representational_State_Transfer.)

  • Hypermedia As The Engine Of Application State (HATEOAS) is a constraint on REST that says that a client of a REST application must only know a single fixed URL to access it. Any and all resources should be discoverable dynamically from that URL, through hyperlinks included in the representations of returned resources.

SDK Elements

The Junos Space SDK Toolkit helps in the development of Junos Space applications. These applications can then be deployed on the Junos Space Platform. The SDK Toolkit comes pre-loaded with the Junos Space Virtual Appliance (JSVA), which can be used to emulate the Junos Space Platform for functional verification of the developed application.

Note: All applications must be signed with a certificate (issued by Juniper Networks) to be deployed into production environments, but they do not require a certificate when deployed on the JSVA.

The Junos Space SDK development system consists of these components:

  1. Development Tools

    • The Junos Space Eclipse plug-in installed on an Eclipse IDE.

    • The Junos Space Eclipse plug-in allows wizard-based creation of different types of Junos Space applications, automated build, and deployment of applications for test and debug purposes, control of device simulations on a device simulator, and other features.

  2. REST Web Services interfaces
    • Interfaces to the core capabilities of the Junos Space platform. These REST Web Service interfaces are a part of the Junos Space network application platform.

  3. Device and environment simulators

    • The development environment includes the Junos Space Virtual Appliance that provides access to:

      • A fully functional instance of the Junos Space network application for use in deploying and testing applications developed using the Junos Space SDK.

      • Device and element simulators providing the ability to test applications against virtual Juniper Network devices.

  4. Performance, Analytics, Security, and Profiling tools

    • While the Junos Space SDK does not ship performance, analytics, security, or profiling tools, it is compatible with the most popular tools available today, such as VisualVM, JBoss Tools, and so on.

  5. Reference Apps

    • Reference applications, including annotated source code. These applications provide examples for developers to learn from and use.

  6. Documentation and Online Resources

    • The SDK install package includes complete documentation for using the SDK, including an Installation Guide, an API Reference, and an Application Developer Guide. The latter two are provided in the Eclipse plug-in as online help. Finally, the SDK includes reference applications demonstrating how to use the many SDK features.

From the SDK user's perspective, the SDK Web development environment looks like the following:

Wednesday, 13 April 2022

Junos Space SDK

 

The Junos Space SDK delivers on the programmability promise of software-defined networking (SDN) by making it easy to create custom analytic and management applications that run on the Junos Space Network Management Platform. The connections and intelligence embedded in the network can be leveraged to create customized management solutions that meet specific needs and to create new revenue streams.

The Junos Space SDK also makes it simple to safely extract data from your network to add intelligence to existing applications and new solutions you create. In this way, you can enable automated responses to application and network conditions that improve the user experience.

Key Features


  • Real-time policy management 
  • Energy usage tracking 
  • Custom workflows 
  • Network insight for business intelligence 
  • Correlation of user subscribed services
  • Policy and QoS management

Features + Benefits

Flexible Applications Based on Behavior

Create better user experiences with networks and applications that make real-time changes based on behavior.

Enhanced Network Visibility and Control

Gain visibility into network activity and control outcomes using apps tailored for your specific analytic and management needs.

Better Access to Network Information

Access network data through the Application-Layer Traffic Optimization (ALTO) protocol, BGP-TE, GenApp interface, and other tools.

Enhanced End-User Experience

Deliver better quality of service and experiences to your customers.

Advanced Orchestration

Improve cost-effectiveness, resource optimization, and personalization of services.

New Revenue Opportunities

Discover new offerings likely to appeal to subscribers based on the data you collect about their habits, buying history, and preferences.

Wednesday, 23 March 2022

Reimagining Data Center Operations with Intent-Based Networking: The Latest Step in an Innovative Apstra Journey

 

New Apstra product enhancements make it easier than ever to experience the benefits of a Juniper experience-first data center

It’s been a little over a year since Juniper Networks took the bold step of acquiring Apstra, the creator of the only vendor-agnostic intent-based networking software for data center operations. In that time, much has happened both externally and internally at Juniper, all of which has enabled the company’s data center business to continue its growth. Many factors contributed to this tremendous success, including continued investment in the Juniper Apstra product, development of Apstra partners and significant Apstra customer momentum across both the enterprise and service provider segments.

Today, we’re excited to announce the latest series of Apstra product enhancements that will enable Juniper to continue its strong data center momentum into 2022 and beyond. Not only have we expanded all the benefits of our intent-based networking solution to more data center environments, but it’s even easier to deploy and operate with more robust security capabilities.

To the Edge and Beyond

No one could have predicted the surge in workload distribution that a pandemic would generate – including data volume and demand for faster, more reliable service. To support increasing business digitization and reduce latency, many organizations have turned to edge computing to bring data processing closer to the end user.

Now, in addition to using Apstra in centralized or hyperscale data centers, customers can use our powerful software in edge locations – or at any remote site that doesn’t require the full scale of a multistage switching network. With Apstra, networking teams can centrally design, deploy and operate a network consisting of an EVPN-VXLAN overlay with an IP fabric underlay in a configuration made up of only two leaf switches. Additionally, teams can scale and add access switches to the fabric whenever needed. Apstra will automatically register the new devices and apply the pre-validated configurations.

Zero Trust for a More Secure Data Center

Apstra’s single source of truth is a key foundation for Zero Trust security, enabling network operators and security experts to view the exact state of the network, its configuration and the intended outcome. Apstra’s enhanced policy assurance introduces new segmentation capabilities. By allowing organizations to apply all their security policies from a single point and to specify enforcement at the most granular level, Apstra ensures that the network is continuously compliant, consistent and reliable.

Apstra also provides:

  • Role-Based Access Control (RBAC) to limit who can see which data
  • Continuous validation against intent to identify configuration drift in real time
  • Policy assurance to confirm that security policies are being enforced as intended
  • Live audits to track the origin of changes

Improvements in RBAC, audit and security policy granularity have all been made to meet the requirements of customers using Apstra in multi-tenant environments.

Hassle-Free Deployments and Migrations

With IT requirements evolving at an unprecedented rate, constant data center deployments and migrations are inevitable. In addition, the number of data centers in use frequently changes, either increasing due to natural IT growth or acquisitions, or decreasing when older data centers are decommissioned or businesses divest themselves of certain IT requirements or applications. These deployments and migrations can be challenging, expensive and resource intensive. But they don’t have to be.

Juniper’s new Apstra Deployment and Migration services leverage Apstra’s intent-based networking architecture and in-house tools to help organizations significantly reduce the time, cost and risk associated with deployments. Our experts perform real-time preconditioned validations based on the exact blueprint, network models and operating systems. This enables customers to migrate to the latest architectures and automate everyday operations with minimal downtime and an unprecedented level of assurance, while also reducing the CapEx and OpEx associated with physical and virtual testing during deployment. Customers can also take advantage of best-practice design methodologies and in-house automation tools to accelerate deployments for increased business agility.

New Data Center Learning

Both experienced and new data center networkers will have the ability to advance their careers with Juniper’s revised curriculum that includes new and updated training and certifications.

  • Introduction to Juniper Data Center Networking: This foundational course provides introductory instruction on data center switching using Juniper products and covers the baseline knowledge necessary to understand a data center that’s built upon an IP fabric with an EVPN/VXLAN overlay. This is the recommended preparation for the new Juniper Networks Certified Associate, Data Center (JNCIA-DC) certification, which launches in May 2022.
  • Data Center Automation using Juniper Apstra: This expanded course provides the necessary knowledge required to manage data center networks with Apstra and now covers how to add a spine, leaf and generic system to a running blueprint (IP fabric), VMware integration and data center interconnect. It’s recommended as preparation for the new Juniper Networks Certified Specialist, Data Center (JNCIS-DC) certification, also launching in May 2022.
  • Data Center Fabric with EVPN and VXLAN: This recently updated course now includes coverage of enhanced loop protection, MAC-VRF, ERB, collapsed fabric configuration, super spine configuration, EVPN multicast-assisted replication, filter-based forwarding in the data center and seamless EVPN-VXL. This course is recommended training for the updated Juniper Networks Certified Professional, Data Center (JNCIP-DC)

A Year of Integration, Innovation and Achievements

Now that we’ve described the latest enhancements, let’s look back at how far Juniper has come with Apstra since the acquisition last year.

  • Apstra was integrated with more Juniper products. It takes time to fully integrate a newly acquired company, but Juniper hit the ground running this past year! We’ve added Apstra support for more Juniper switches and routers, as well as for all current versions of our Junos® operating system, including Junos Evolved in spine, super-spine and non-EVPN-VXLAN leafs.
  • Apstra adoption grew by leaps and bounds. Since the acquisition, Apstra logos have increased over 400 percent. Additionally, pre-acquisition customers renewed their Apstra licenses. For example, one Fortune 5 customer not only renewed, but also deployed Apstra to a second data center and introduced Apstra to a major managed services provider.
    • Juniper expanded Apstra’s multivendor support. Apstra is the only intent-based networking software that eliminates vendor lock-in, and Juniper proved that it was committed to keeping this unique feature. For example, in last year’s Apstra 4.0 release, we provided validated qualification for Cisco Systems, Arista Networks, Dell Technologies and added VMware NSX-T 3.0 and Enterprise SONiC integrations. Although we believe that customers benefit most by combining Apstra with our own QFX Series switches and other proprietary hardware and software, our primary goal is to give customers the tools they need to reduce operational complexity and assure reliability – regardless of which vendor environment they have.
    loading...