Specifications
•
The following information is missing from the passive-mode-tunneling configuration
statement and the “Example: Configuring Junos VPN Site Secure on MS MIC and
MS-MPC” topic:
Passive module tunneling is not supported on MS-MICs and MS-MPCs.
•
The open-timeout configuration statement topic and the “Configuring Default Timeout
Settings for Services Interfaces” topic incorrectly state that the default value of the
timeout period for TCP session establishment is 30 seconds. The correct default value
is 5 seconds.
•
The Supported Platforms section of theset chassis display message command topic
erroneously states that this command is supported on MX Series routers. This command
is not available on MX Series routers.
•
The following information regarding the restriction on prefix lengths that can be
configured in NAT pools on MS-MPCs and MS-MICs applies to the "Configuring Source
and Destination Addresses Network Address Translation Overview " section of the
"Network Address Translation Rules Overiew" topic:
On MX Series routers with MS-MPCs and MS-MICs, if you configure a NAT address
pool with a prefix length that is equal to or greater than /16, the PIC does not contain
sufficient memory to provision the configured pool. Also, memory utilization problems
might occur if you attempt to configure many pools whose combined total IP addresses
exceed /16. In such circumstances, a system logging message is generated stating that
the NAT pool name is failed to be created and that the service set is not activated. On
MS-MPCs and MS-MICs, you must not configure NAT pools with prefix lengths greater
than /16.
•
The following procedure applies to the “Provisioning Flow-Tap to a Linux Mediation
Device” topic:
The following example shows the syntax to invoke the Perl script from a Linux device
for deleting a previously configured Flow-Tap session:
1. Invoke the Perl script:
[root@blr-e flowtap]# ./dfcclient.pl
2. Use the following line to push the parameter file del_lea1_tcp.flowtap to the router.
In this example, 10.209.75.199 is the IP address of the router, and verint verint123 is
the username and password that has permission to implement flow-tap-operation.
Any firewall that is between the mediation device and the routing device should
allow ssh and port 32001.
[root@blr-e flowtap]# ./dfcclient.pl 10.209.75.199 verint verint123 del_lea1_tcp.flowtap
The following settings are contained in the del_lea1_tcp.flowtap DTCP parameter
file. DTCP DELETE can use either Criteria- ID to delete only that criteria or Cdest-ID
to delete everything with cdest-ID that you previously created.
DELETE DTCP/0.7
Csource-ID: dtcp
Cdest-ID: LEA1
Flags: STATIC
Copyright © 2015, Juniper Networks, Inc.148
Release Notes: Junos OS Release 13.3R6 for the EX Series, M Series, MX Series, PTX Series, and T Series