Tuesday, 28 November 2017

16.2R2-S3: Software Release Notification for Junos Software Service Release version 16.2R2-S3

Alert Type:

SRN - Software Release Notification
Product Affected:
ACX, MX, T, TX, PTX, VMX, VRR
Alert Description:
Junos Software Service Release version 16.2R2-S3 is now available for download from the Junos software download site
Download Junos Software Service Release:
  1. Go to Junos Platforms - Download Software page
  2. Select your product
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts
 
Solution:
Junos Software service Release version 16.2R2-S3 is now available.
The following are incremental changes in 16.2R2-S3.
 
PR Number Synopsis Description
1275149 ACX500 IPSec license activation error - license not valid for this product In some rare scenarios, ACX500 IPSec will have license activation error with message license not valid for this product. The license cannot be re-added after the deletion. This issue is related to incorrect Product information index in the license feature structure.
1298262 rpd core at aspath_migrate_and_prepend(), rt_ribgroup_migrate_domain(), rt_change_ribgroup_import() when configures routing-instance with static routes The routing protocol process (rpd) may restart unexpectedly when configuring rib-groups and routing-instances with static routes in a certain order.
1302504 The rpd might crash when toggling vrf-propagate-ttl and no-vrf-propagate-ttl knob With Protocol-Independent Load Balancing for Layer 3 VPNs enabled (i.e. configure 'routing-instances routing-options multipath') in virtual routing and forwarding (VRF) routing instance, when toggling TTL action knob (i.e. vrf-propagate-ttl/no-vrf-propagate-ttl) for this VRF routing instance, if BGP receives a VPN route update for the VRF during the processing of the reconfiguration, the rpd might crash. This is a timing issue due to the race condition.

Friday, 3 November 2017

End of Life Announcement: J-series subscription licenses

OVERVIEW:
This document announces the End of Life of the J-series licenses listed in the table below. This announcement is effective immediately with a last order date (LOD) of November 30, 2017. On the last order date, the SKUs are removed from the price list and are no longer orderable.

AFFECTED PRODUCTS:
EOL Model Number Description Last Software Version
J2320-IDP One year subscription for IDP updates on J2320 12.1X46
J2320-K-AV One year subscription for Juniper-Kaspersky AV updates on J2320 12.1X46
J2320-S2-AS One year subscription for Juniper-Sophos Anti-Spam for J2320 12.1X46
J2320-SMB2-CS One year security subscription for Enterprise - includes Kaspersky AV, WF, Sophos AS and IDP - on J2320 12.1X46
J2320-W-WF One year subscription for Juniper-Websense Integrated Web Filtering for J2320 12.1X46
J2350-IDP One year subscription for IDP updates on J2350 12.1X46
J2350-K-AV One year subscription for Juniper-Kaspersky AV updates on J2350 12.1X46
J2350-S2-AS One year subscription for Juniper-Sophos Anti-Spam for J2350 12.1X46
J2350-SMB2-CS One year security subscription for Enterprise - includes Kaspersky AV, WF, Sophos AS and IDP - on J2350 12.1X46
J2350-W-WF One year subscription for Juniper-Websense Integrated Web Filtering for J2350 12.1X46
J4350-IDP One year subscription for IDP updates on J4350 12.1X46
J4350-K-AV One year subscription for Juniper-Kaspersky AV updates on J4350 12.1X46
J4350-S2-AS One year subscription for Juniper-Sophos Anti-Spam for J4350 12.1X46
J4350-SMB2-CS One year security subscription for Enterprise-includes Kaspersky AV,WF,Sophos AS and IDP-on J4350 12.1X46
J4350-W-WF One year subscription for Juniper-Websense Integrated Web Filtering for J4350 12.1X46
J6350-IDP One year subscription for IDP updates on J6350 12.1X46
J6350-K-AV One year subscription for Juniper-Kaspersky AV updates on J6350 12.1X46
J6350-S2-AS One year subscription for Juniper-Sophos Anti-Spam for J6350 12.1X46
J6350-SMB2-CS One year security subscription for Enterprise - includes Kaspersky AV, WF, Sophos AS and IDP - on J6350 12.1X46
J6350-W-WF One year subscription for Juniper-Websense Integrated Web Filtering for J6350 12.1X46


REPLACEMENT PRODUCTS:
Model Number Product Description Min Software Version
NA NA NA


END OF LIFE TIMETABLE:
EOL Timetable Milestone Definition of Action Effective Date
End-of-life Notification Product Support Notification released that announces end of life of a product. 10/30/2017
Last Order Date Last day to buy product, order a new service contract, or add product to an existing support contract. Thereafter, products and services are removed from price lists. 11/30/2017
End-of-warranty service conversion Last date to convert warranty coverage for products purchased prior to EOL to a support contract. NA
First service step-down The available services offerings for the product will be capped at Next-day and Next-day Onsite support.
Same-day and Same-day onsite support will be discontinued.
NA
Second service step-down The available J-Care services offerings for the product will be capped at Core and CorePlus support. The available JNSAC service offerings will be capped at Basic, RTF and AR-5.
Next-day and Next Day Onsite support will be discontinued.
NA
End-of-service contract renewal date Last date to renew or extend existing support contracts.  Support cannot extend beyond the end-of-support date.
 
NA
End of Software Engineering support date EOSE is the date after which Juniper is no longer committed to furnish Software Engineering level support for the operating system software licensed for the affected hardware. This means that no further Releases (e.g. service or maintenance releases or patches) will be created for the support of the affected hardware product. JTAC support will generally be limited to investigation and troubleshooting in an attempt to provide solutions, configuration guidelines and workarounds. 07/31/2018
 
End of Hardware Engineering support date After EOHE Juniper has no commitment to perform hardware engineering level support (including hardware modifications and hardware failure analysis) for hardware defects. NA
 
End-of-service date Last date to receive contracted service (including hardware and software bug fixes, and logistics replacement or repair services) for the product.  Limited support will be offered on a per-incident, non-contracted basis only, at the discretion of Juniper Networks. 07/31/2018

Tuesday, 17 October 2017

Out-of-Cycle Security Bulletin: Multiple Products: Multiple vulnerabilities in Wi-Fi Protected Access (WPA1/WPA2) protocols (aka KRACK attack).

Product Affected:
This issue affects Junos OS 12.1X46. Affected platforms: SRX 210, 240, 650 series firewalls with AX411 Wireless Access Points. This issue affects ScreenOS 6.3. Affected platforms: ScreenOS SSG-5 and SSG-20 devices with embedded Wireless Access Points radios. This issue affects WLAN 9.2, 9.6. Affected platforms: MSS.
 
Problem:
A series of Wi-Fi Protected Access (WPA/WPA1) and Wi-Fi Protected Access II (WPA2) security protocols used in Juniper’s SRX 210, 240, 650 series firewalls which support the AX411 Access Points, ScreenOS SSG-5 and SSG-20 firewalls with integrated WiFi radios, and lastly, the WLAN product line have one or more vulnerabilities present when these Wi-Fi radios are enabled.
This is a series of protocol level vulnerabilities and not specific to any Juniper products. WPA and WPA2 security protocols are present in nearly all modern Wi-Fi products.
Successful exploitation of these vulnerabilities could allow unauthenticated attackers to perform packet replay, decrypt wireless packets, and to potentially forge or inject packets into a wireless network.
The following CVE IDs have been issued for each of the possible vulnerabilities:
CVE-2017-13077 reinstallation of the pairwise key in the Four-way handshake
CVE-2017-13078 reinstallation of the group key in the Four-way handshake
CVE-2017-13079 reinstallation of the integrity group key in the Four-way handshake
CVE-2017-13080 reinstallation of the group key in the Group Key handshake
CVE-2017-13081 reinstallation of the integrity group key in the Group Key handshake
Juniper's products do not support Fast BSS Transition Reassociation so are Not Vulnerable to CVE-2017-13082.
The following CVE IDs are still under investigation:
CVE-2017-13084 reinstallation of the STK key in the PeerKey handshake
CVE-2017-13086 reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake
CVE-2017-13087 reinstallation of the group key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame
CVE-2017-13088 reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame
The research paper referenced in the related links section below can be reviewed for details.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was discovered by an external security researcher.

No other Juniper Networks products or platforms are affected by this issue.


Solution:
WLAN
MSS 9.2.1, 9.6.5, and all subsequent releases.

This issue is being tracked as PR 1297300 and is visible on the Customer Support website.
Workaround:
There are no viable workarounds for these issues.
The following methods may be used to reduce the possibility of exploitation:
SRX 210, 240, 650 series firewalls with AX411 Wireless Access Points:
Disabling all Wi-Fi configurations and setting all ports with AX411 Access Points administratively down will protect the SRX device from exploitation.
Customers may also physically disconnect the AX411 Wi-Fi Access Points from their network.
ScreenOS devices with embedded Wireless Access Points:
Disable all Wi-Fi configurations.
WLAN:
Disable all Wi-Fi Access Points until such time that the MSS can be upgraded.
 
Implementation:
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/.
 
Modification History:
Modification History: 2017-10-16: Initial publication
 
CVSS Score:
7.9 (CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
 
Risk Level:
High
 
Risk Assessment:
Information for how Juniper Networks uses CVSS can be found at KB 16446 "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."
 
Acknowledgements:
Juniper SIRT would like to acknowledge and thank

   * researchers Mathy Vanhoef and Frank Piessens of DistriNet (Distributed Systems and Computer Networks) at the Computer Science department of the Katholieke Universiteit Leuven, Belgium for responsibly disclosing these vulnerabilities.
   * John A. Van Boxtel with Cyprus Semiconductor for finding that wpa_supplicant v2.6 is also vulnerable to CVE-2017-13077.

Friday, 13 October 2017

User Interface update on JUNOS Software Download page - providing a URL for on device download

The user interface of the JUNOS Software Download page - https://www.juniper.net/support/downloads/group/?f=junos - has been updated. The last step in downloading software has been modified. The change will be in production on 2017-10-13T19:30:00-07:00
Solution:
The user interface of the JUNOS Software Download page - https://www.juniper.net/support/downloads/group/?f=junos - has been updated. The last step in downloading software has been modified to
  1. Enhance automation by providing a URL of the image that can be used with command line tools such as "curl", "wget", or "cli> file copy ..." on a JUNOS device
  2. The software image download no longer starts automatically via a user's browser. A user can choose to either click to download, or copy the image's URL to use on another device
The change will be in production on 2017-10-13T19:30:00-07:00
Implementation:

The user interface of the JUNOS Software Download page - https://www.juniper.net/support/downloads/group/?f=junos - has been updated as follow:
After a user selects a JUNOS image, the software download displays the "End User License Agreement" (EULA). The user reviews the EULA and can either agree or disagree with the EULA. If a user agrees, the image is downloaded using the user's browser within a couple of seconds.

Figure 1: Current software download step - after a user accepts the EULA, they are transferred to this page. The image downloads automatically after a few seconds delay to the browser download directory.


We received feedback from users that downloading a large image via a browser to use the image in the field is not optimal. Many users prefer to get the URL of the image. They can then use the URL on their devices to copy the image to local storage directly. To illustrate this scenario, a user has to:
  1. Interrupt the download - one usually interrupts the automatic download since the browser starts downloading the image to the desktop within a couple of seconds
  2. Copy the image's URL - usually by righ-click on the "Click to Download" link to get the URL
  3. Delete the partially downloaded image on the browser download folder


The last step in downloading software has been modified to
  1. Enhance automation by providing a URL of the image that can be used with command line tools such as "curl", "wget", or "cli> file copy ..." on a JUNOS device
  2. The software image download is no longer starts automatically via a user's browser. A user can choose to either click to download, or copy the image's URL to use on another device
Figure 2: The new user interface to the last step of JUNOS software download procedure. The interface provides a URL to the image, or the ability to download the image via the browser

Monday, 18 September 2017

Chef for Junos OS

Chef software automates the provisioning and management of compute, networking, and storage resources.

Chef for Junos OS provides support for Chef on selected Juniper Networks devices running Junos OS, allowing you to automate common switching network configurations, such as physical and logical Ethernet link properties and VLANs.

Tuesday, 5 September 2017

Software Release Notification for Junos Software Service Release version 16.1R3-S5

Alert Description:

Junos Software Service Release version 16.1R3-S5 is now available for download from the Junos software download site
Download Junos Software Service Release:
  1. Go to Junos Platforms - Download Software page
  2. Select your product
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts
Solution:
Junos Software service Release version 16.1R3-S5 is now available.

The following are incremental changes in 16.1R3-S5.​
 
PR Number Synopsis Description
1209308
tcp_timer_keep: Dropping socket connection when remote VPLS PE comes up
In some rare scenarios remote VPLS PE coming up might cause TCP keepalive timeouts on the local sockets between the master RE and the FPCs (e.g. ppmd <-> PPManager connection): kernel: tcp_timer_keep: Dropping socket connection due to keepalive timer expiration Local(0x80000001:6011) Foreign(0x80000015:36678) kernel: tcp_timer_keep: Dropping socket connection due to keepalive
1231167 MPC2E-NG/MPC3E-NG core-dump with specific MIC due to tight loop of PCIe critical exceptions On MX platform with MPC2E-3D-NG/MPC2E-3D-NG-Q/MPC3E-3D-NG/MPC3E-3D-NG-Q line card, if the FPC-MIC link failure happens, the bridge may keep sending register messages in an infinite loop, which would cause continuous PCI exceptions, the MPC might crash and traffic forwarding might be affected. This is a rare issue, it is hard to reproduce.
1241801 The rpd might crash on backup RE when changing l2circuit neighbor in NSR scenario With NSR enabled and a Layer 2 circuit configured, an rpd crash might be observed on the backup Routing Engine when you change the Layer 2 circuit neighbor and then commit the changes. The issue does not exist if NSR is not enabled.
1251556 KRT queue stuck on RE causing RIB and FIB to go out of sync​ From Junos 16.1R1 and later, there is a rpd problem sending route update messages to the kernel. The KRT queue used to send the messages can get into a state where no more messages can be sent to the kernel. This causes the RIB and FIB to get out of
1256736 IRP interrupt "INTR: throttle 3630sec PECHIP[2]:pe.irp.intr.status:ap0_trap(0): (Count:3434)" would be observed for every hour under certain conditions. While processing lookup results, IRP block would raise an interrupt upon detecting an error condition. The interrupt would be active until the trapcode error is read. Under certain conditions, software is not reading this trapcode error upon IRP interrupt. This issue causes the following syslog message to be generated: fpc5
1258472 The rpd might crash during the next-hop change if unicast reverse-path- forwarding (uRPF) is used In a very rare cases, if the unicast reverse path forwarding (uRPF) is used, the rpd might crash and the core file might be generated during the next-hop change.
1259579 Rpd memory leak is observed in NG-MVPN environment Rpd memory leak is seen when NG-MVPN type 6 and type 7 route adds/deletes/changes. The leak is 36 byte block size on Junos versions prior to 15.1, and 44 byte block size on Junos versions 15.1 or higher.
1276748 RPD core: Assertion failed rpd[6255]: file src/junos/usr.sbin/rpd/rsvp/rsvp_enh_lp.c", line 4928: "rsvp_enh_lp_supported_psb_type(psb) RPD core: Assertion failed rpd[6255]: file src/junos/usr.sbin/rpd/rsvp/rsvp_enh_lp.c", line 4928: "rsvp_enh_lp_supported_psb_type(psb)
1280809 RPD core generation when a memory is allocated twice Under a rare circumstance show task command of any type might cause a double free of a data structure resulting in a rpd coredump.
1282672 Rpd might crash due to a certain chain of events in BGP-LU protection scenario In BGP-LU protection scenario with the statement per-prefix-label configured, rpd might crash due to a certain chain of events that if receiving a BGP route with the indirect next-hop firstly and later receiving another BGP route with the direct next-hop (which has the same prefix with the route received early)
1290789 The rpd crashes due to LDP defect during NSR-enabled RE switchover The rpd will generate core file, if it involves an Label Distribution Protocol (LDP) egress route, which is stitched to a Border Gateway Protocol (BGP) route via the "ldp egress-policy" configuration.

Friday, 25 August 2017

Software Release Notification: Junos OS 16.1R5

Alert Description:

Junos OS 16.1R5 for the ACX Series, EX Series, MX Series, PTX Series, QFX Series, T Series and Junos Fusion is now available.
Solution:

Consult Release Notes:
For new and changed features, changes in behavior, known behavior and issues, resolved issues, and more, refer to:

Release Notes for Junos OS 16.1R5 for the ACX Series, EX Series, MX Series, PTX Series, QFX Series, T Series and Junos Fusion.
HTML

Download Junos OS Software:
1. Go to Junos Platforms - Download Software page.
2. Select your product.
3. Under 'Type / OS', select 'Junos'.
​4. Under 'Version', select '16.1'.
4. Click the "Software" tab.
5. Select the Install Package Release needed, and follow the prompts.
loading...