Specifications

For an IPv6 address prefix, the length is 16 and the value displayed is 15.
For a subnet mask of an IPv6 address prefix, the length is 32 and the value displayed
is 31.
For a range of IPv6 address prefixes, the length is 32 and the value displayed is 31.
The value of the id-data-presentation field denotes the IPv4 address or IPv6 prefix
details. If the fully qualified domain name (FQDN) is specified instead of the address
for the local peer of the IPsec association, it is displayed instead of the address
details.
Remote Identity—Protocol, address or prefix, and port number of the remote entity
of the IPsec association. The format is id-type-name
(proto-name:port-number,[0..id-data-len] = iddata-presentation). The protocol is
always displayed as any because it is not user-configurable in the IPsec rule. Similarly,
the port number field in the output is always displayed as 0 because it is not
user-configurable in the IPsec rule. The value of the id-data-len parameter can be
one of the following, depending on the address configured in the IPsec rule:
For an IPv4 address, the length is 4 and the value displayed is 3.
For a subnet mask of an IPv4 address, the length is 8 and the value displayed is 7.
For a range of IPv4 addresses, the length is 8 and the value displayed is 7.
For an IPv6 address prefix, the length is 16 and the value displayed is 15.
For a subnet mask of an IPv6 address prefix, the length is 32 and the value displayed
is 31.
For a range of IPv6 address prefixes, the length is 32 and the value displayed is 31.
The value of the id-data-presentation field denotes the IPv4 address or IPv6 prefix
details. If the fully qualified domain name (FQDN) is specified instead of the address
for the remote peer of the IPsec association, it is displayed instead of the address
details.
The “Understanding Aggregated Mulitservices Interfaces” and the “Example:
Configuring an Aggregated Mulitservices Interface (AMS)” topics in the Services
Interface Configuration Guide incorrectly state that when member-failure-options is
not configured, the default behavior is to redistribute the traffic among the available
interfaces. The correct behavior is that when the member-failure-options statement
is not configured, the default behavior is to drop member traffic with a rejoin timeout
of 120 seconds.
The functionality to log the cflowd records in a log file before they are exported to a
cflowd server (by including the local-dump statement at the [edit forwarding-options
sampling instance instance-name family (inet |inet6 |mpls) output flow-server hostname]
hierarchy level) is not supported when you configure inline flow monitoring (by including
151Copyright © 2015, Juniper Networks, Inc.
Documentation Updates