Juniper Networks 208, 5200, 204, 500, 5XT, 5400 manual Upgrade Paths from Previous Releases

Page 31

Juniper Networks

NetScreen Release Notes

 

 

Freeswan - The Freeswan 1.3 VPN client is incompatible with ScreenOS 5.0.0 in certain configurations due to IKE features that Freeswan does not fully support. The result is that Phase 2 negotiations and Phase 2 SA will not complete if the following commands are enabled in 5.0.0:

set ike initiator-set-commit set ike responder-set-commit set ike initial-contact

W/A: Unset these commands to ensure compatible configuration on the Juniper Networks security appliance.

Compatible Web Browsers - The WebUI for ScreenOS 5.0.0 was tested with and supports Microsoft Internet Explorer (IE) browser versions 5.5 and above, and Netscape Navigator 6.X for Microsoft Windows platforms, and Microsoft Internet Explorer version 5.1 for MacOS 10.x. Other versions of these and other browsers, were reported to display erroneous behavior.

SNMP Trap Type Values Different in ScreenOS 5.0.0 – ScreenOS 5.0.0 uses a different numbering system than previous ScreenOS releases to identify trap types. SNMP maps specific integers to indicate specific trap types, or events that generate traps. For example, the traditional SNMP trap type value for a Cold Start is 0. However, different vendors deploy different values to indicate different trap types. Please check the ScreenOS Messages Guide for the correct values in ScreenOS 5.0.0.

5.2.1 Upgrade Paths from Previous Releases

For detailed information on how to upgrade any Juniper Networks security appliance from ScreenOS 4.0.0 and later to ScreenOS 5.0.0, refer to the NetScreen ScreenOS Migration Guide. The migration guide provides step-by- step upgrade procedures and important information about upgrading Juniper Networks security appliances.

Important: To avoid downtime while upgrading devices in an NSRP configuration (active-passive or active/active), refer to the NetScreen ScreenOS Migration Guide which describes procedures to upgrade the devices without causing any downtime.

The migration guide also provides a step-by-step procedure to downgrade a Juniper Networks security appliance from ScreenOS 5.0.0 to ScreenOS 4.0.0 and later using the exec downgrade CLI command.

ScreenOS 5.0.0r9-FIPS

P/N 093-1638-000, Rev. A

Page 31 of 42

Image 31
Contents Contents Version Summary Set av http skipmime Unset av http skipmime New Features and EnhancementsNew Features and Enhancements in ScreenOS 5.0.0r9-FIPS New Features and Enhancements from ScreenOS 5.0.0r8New Features and Enhancements from ScreenOS 5.0.0r1 New Features and Enhancements from ScreenOS 5.0.0r6Get log system saved Changes to Default BehaviorAddressed Issues in ScreenOS Addressed Issues in ScreenOS 5.0.0r9-FIPSJuniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes VIP cannot be contacted VIP is now alive Addressed Issues from ScreenOS 5.0.0r8 Juniper Networks NetScreen Release Notes Get traffic log include Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Dhcp IP Pool not in the same subnet with gateway/interface Juniper Networks NetScreen Release Notes Addressed Issues from ScreenOS 5.0.0r6 Addressed Issues from ScreenOS 5.0.0r7Juniper Networks NetScreen Release Notes Addressed Issues from ScreenOS 5.0.0r4 Addressed Issues from ScreenOS 5.0.0r5Set interface tunnel.2 nhtb 10.1.2.5 vpn Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Addressed Issues from Previous Releases Juniper Networks NetScreen Release Notes Limitations of Features in ScreenOS Known IssuesGeneral Compatibility Issues Compatibility Issues in ScreenOSUpgrade Paths from Previous Releases Known Issues in ScreenOS 5.0.0r9-FIPS Known Issues in ScreenOSKnown Issues from ScreenOS 5.0.0r8 Known Issues from ScreenOS 5.0.0r4 Known Issues from ScreenOS 5.0.0r7Known Issues from ScreenOS 5.0.0r6 Known Issues from ScreenOS 5.0.0r5Known Issues from ScreenOS 5.0.0r3 for the 5000-M2 Known Issues from ScreenOS 5.0.0r2 Known Issues from ScreenOS 5.0.0r3Known Issues from ScreenOS 5.0.0r1 Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Juniper Networks NetScreen Release Notes Known Issues from Previous Releases Getting Help