Specifications

Security
Packet types added for DDoS protection L2TP policers (MX Series with MPCs, T4000
with FPC5)The following eight packet types have been added to the DDoS protection
L2TP protocol group to provide flexibility in controlling L2TP packets:
scccncdn
sccrqhello
stopccniccn
unclassifiedicrq
Previously, no individual packet types were available for this protocol group and all
L2TP packets were policed the same based on the aggregate policer value. The default
values for the bandwidth and burst policers for all packet types is 20,000 pps. The
default recover-time is 300 seconds for each of the L2TP packet types.
Services Applications
Restriction for RPM probe test data-size—In Junos OS Release 13.2 and earlier releases,
the data-size statement at the [edit services rpm probe owner test test-name] hierarchy
level did not enforce any additional restrictions when the hardware-timestamp was
included. Starting in Junos OS Release 13.3, the data-size value must be at least 100
bytes smaller than the default MTU of the interface of the RPM client interface when
the hardware-timestamp statement is used.
[edit services rpm probe owner test test-name]
hardware-time-stamp;
data-size size;
New ranges for TWAMP server connections—In Junos OS Release 13.2 and earlier
releases, the maximum-connections statement at the [edit services rpm twamp server]
hierarchy level had a range of 1 through 2048. Starting in Junos OS Release 13.3, the
maximum-connections statement has a range of 1 through 1000. In Junos OS Release
13.2 and earlier releases, the maximum-connections-per-client statement at the [edit
services rpm twamp server] hierarchy level had a range of 1 through 1024. Starting in
Junos OS Release 13.3, the maximum-connections-per-client statement has a range
of 1 through 500.
New range for data-size statement—In Junos OS Release 13.2 and earlier releases,
the data-size statement at the [edit services rpm probe owner test test-name] hierarchy
level had a range of 0 through 65507. Starting in Junos OS Release 13.3R1, the data-size
statement has a range of 0 through 65400.
Restriction for NAT rules with translation type stateful-nat-64—In Junos OS Release
13.2 and earlier releases, the following restriction was not enforced by the CLI: if the
translation-type statement in the then statement of a NAT rule was set to
stateful-nat-64, the range specified by the destination-address-range or the
destination-prefix-list in the from statement needed to be within the range specified
Copyright © 2015, Juniper Networks, Inc.60
Release Notes: Junos OS Release 13.3R6 for the EX Series, M Series, MX Series, PTX Series, and T Series