Juniper Networks 5400, 5200, 208, 204, 500, 5XT Known Issues, Limitations of Features in ScreenOS

Page 29

Juniper Networks

NetScreen Release Notes

 

 

01958 – An internal mishandling of the MAC cache could cause a security appliance to crash.

01944 – The group addresses for V1-untrust zone were getting lost after upgrading a device from a previous release. The group address for v1-untrust was incorrectly set to a maximum of 8 groups while it should have been 32.

01812 – Using un-initialized memory space when creating an outgoing packet caused the device to fail.

5.Known Issues

This section describes known issues with the current release.

Section 5.1 “Limitations of Features in ScreenOS 5.0.0” identifies features that are not fully functional at the present time, and will be unsupported for this release. Juniper recommends that you do not use these features.

Section 5.2 “Compatibility Issues in ScreenOS 5.0.0 on page 30” describes known compatibility issues with other products, including but not limited to specific Juniper NetScreen appliances, other versions of ScreenOS, Internet browsers, Juniper management software and other vendor devices. Whenever possible, information is provided for ways to avoid the issue, minimize its impact, or in some manner work around it.

Section 5.3 “Known Issues in ScreenOS 5.0.0 on page 32” describes deviations from intended product behavior as identified by Juniper Networks Test Technologies through their verification procedures. Again, whenever possible, information is provided to assist the customer in avoiding or otherwise working around the issue.

5.1Limitations of Features in ScreenOS 5.0.0

The following limitations are present in ScreenOS 5.0.0.

No Support for Packet Attribute Features – The Juniper NetScreen- 5000 Series systems do not support the aggressive aging, maximum fragment size, path MTU (Maximum Transmission Unit), and Interface MTU features.

Vsys for Group IKE ID – Group IKE ID users cannot be used in a vsys if that vsys uses a shared untrust interface.

W/A: Use a private Untrust interface (tagged VLAN subinterface or dedicated physical interface) for the vsys.

ScreenOS 5.0.0r9-FIPS

P/N 093-1638-000, Rev. A

Page 29 of 42

Image 29
Contents Contents Version Summary New Features and Enhancements in ScreenOS 5.0.0r9-FIPS New Features and EnhancementsNew Features and Enhancements from ScreenOS 5.0.0r8 Set av http skipmime Unset av http skipmimeNew Features and Enhancements from ScreenOS 5.0.0r1 New Features and Enhancements from ScreenOS 5.0.0r6Addressed Issues in ScreenOS Changes to Default BehaviorAddressed Issues in ScreenOS 5.0.0r9-FIPS Get log system savedJuniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes VIP cannot be contacted VIP is now alive Addressed Issues from ScreenOS 5.0.0r8 Juniper Networks NetScreen Release Notes Get traffic log include Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Dhcp IP Pool not in the same subnet with gateway/interface Juniper Networks NetScreen Release Notes Addressed Issues from ScreenOS 5.0.0r6 Addressed Issues from ScreenOS 5.0.0r7Juniper Networks NetScreen Release Notes Set interface tunnel.2 nhtb 10.1.2.5 vpn Addressed Issues from ScreenOS 5.0.0r5Addressed Issues from ScreenOS 5.0.0r4 Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Addressed Issues from Previous Releases Juniper Networks NetScreen Release Notes Limitations of Features in ScreenOS Known IssuesGeneral Compatibility Issues Compatibility Issues in ScreenOSUpgrade Paths from Previous Releases Known Issues in ScreenOS 5.0.0r9-FIPS Known Issues in ScreenOSKnown Issues from ScreenOS 5.0.0r8 Known Issues from ScreenOS 5.0.0r6 Known Issues from ScreenOS 5.0.0r7Known Issues from ScreenOS 5.0.0r5 Known Issues from ScreenOS 5.0.0r4Known Issues from ScreenOS 5.0.0r3 for the 5000-M2 Known Issues from ScreenOS 5.0.0r1 Known Issues from ScreenOS 5.0.0r3Known Issues from ScreenOS 5.0.0r2 Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Known Issues from Previous Releases Getting Help