Datasheet
6
High Availability (continued)
• LAG load sharing algorithm—Bridged Multicast Trac:
- IP: S/D MAC, S/D IP
- TCP/UDP: S/D MAC, S/D IP, S/D port
- Non-IP: S/D MAC
• LAG sharing algorithm—Routed Multicast Trac:
- IP: S/D IP
- TCP/UDP: S/D IP, S/D port
• Tagged ports support in LAG
• Uplink Failure Detection (UFD)
Multicast
• Internet Group Management Protocol (IGMP) snooping
entries: 1,000
• IGMP: v1, v2, v3
• IGMP snooping
• Protocol Independent Multicast-Sparse Mode (PIM-SM), PIM
Source-Specific Multicast (PIM-SSM), PIM Dense Mode (PIM-DM)
Quality of Service (QoS)
• Layer 2 QoS
• Layer 3 QoS
• Ingress policing: 1 rate 2 color
• Hardware queues per port: 8
• Scheduling methods (egress): Strict Priority (SP), shaped deficit
weighted round-robin (SDWRR)
• 802.1p: DSCP /IP precedence trust and marking
• L2-L4 classification criteria: Interface, MAC address, Ethertype,
802.1p, VLAN, IP address, DSCP/IP precedence, TCP/UDP port
numbers
• Congestion avoidance capabilities: Tail drop
Security
• MAC limiting
• Allowed MAC addresses—configurable per port
• Sticky MAC (persistent MAC address learning)
• Dynamic ARP inspection (DAI)
• Proxy ARP
• Static ARP support
• DHCP snooping
• IP source guard
• 802.1X port-based
• 802.1X multiple supplicants
• 802.1X with VLAN assignment
• 802.1X with authentication bypass access (based on host MAC
address)
• 802.1X with VoIP VLAN support
• 802.1X dynamic access control list (ACL) based on RADIUS
attributes
• 802.1X Supported EAP types: Message Digest 5 (MD5), Transport
Layer Security (TLS), Tunneled Transport Layer Security (TTLS),
Protected Extensible Authentication Protocol (PEAP)
• Captive Portal
• Static MAC authentication
• MAC-RADIUS
• Fallback Authentication
• Trusted Network Connect (TNC) certified
• Control plane DoS protection
Access Control Lists (ACLs) (Junos OS firewall filters)
• Port-based ACL (PACL)—ingress
• VLAN-based ACL (VACL)—ingress and egress
• Router-based ACL (RACL)—ingress and egress
• ACL entries (ACE) in hardware per system: 1,500
• ACL counter for denied packets
• ACL counter for permitted packets
• Ability to add/remove/change ACL entries in middle of
list (ACL editing)
• L2-L4 ACL
Services and Manageability
• Junos OS command-line interface (CLI)
• Web interface: Junos Web (planned for future release)
• Out-of-band management: Serial, 10/100BASE-T Ethernet
• ASCII configuration
• Rescue configuration
• Configuration rollback
• Image rollback
• Element management tools: Juniper Networks Junos Space
Network Management Platform
• Real-Time Performance Monitoring (RPM)
• SNMP: v1, v2c, v3
• Remote monitoring (RMON) (RFC 2819) Groups 1, 2, 3, 9
• Network Time Protocol (NTP)
• DHCP server
• DHCP client and DHCP proxy
• DHCP relay and helper
• RADIUS authentication
• SSHv2
• Secure copy
• HTTP/HTTPs
• DNS resolver
• System logging
• Temperature sensor
• Configuration backup via FTP/secure cop
• Real-time performance monitoring (RPM)
• Interface range
Supported MIBs
4
• RFC1155 Structure of Management Information (SMI)
• RFC 1157 SNMPv1
• RFC 1905 RFC 1907 SNMP v2c, SMIv2, and revised MIB-II RFC
2570-2575 SNMPv3, user-based security, encryption, and
authentication
• RFC 2576 Coexistence between SNMP V1, V2, and V3
• RFC 1212, RFC 1213, RFC 1215 MIB-II, Ethernet-like MIB, and SNMP
TRAPs
• RFC 2578 SNMP Structure of Management Information MIB
• RFC 2579 SNMP Textual Conventions for SMIv2
• RFC 2925 Ping/traceroute MIB
• RFC 2665 Ethernet-like interface MIB
• RFC 1643 Ethernet MIB
• RFC 1493 Bridge MIB
• RFC 2096 IPv4 Forwarding Table MIB
• RFC 2011 SNMPv2 for IP using SMIv2
• RFC 2012 SNMPv2 for transmission control protocol using SMIv2
• RFC 2013 SNMPv2 for user datagram protocol using SMIv2
Specifications (continued)








