| Security Fundamentals / |
Authentication Header (AH) |
| Security Fundamentals / |
Encapsulating Security Payload (ESP) protocol |
| Security Fundamentals / |
Encryption Algorithms 3DES |
| Security Fundamentals / |
Encryption Algorithms AES 128, 192, and 256 |
| Security Fundamentals / |
Encryption Algorithms DES |
| Security Fundamentals / |
Encryption Algorithms NULL (authentication only) |
| Security Fundamentals / |
HMAC-SHA-256-128 authentication |
| Security Fundamentals / |
Hash Algorithms MD5 |
| Security Fundamentals / |
Hash Algorithms SHA-1 |
| Security Fundamentals / |
Hash Algorithms SHA-2 (SHA-256) |
| Security Fundamentals / |
IPSec Phase 2 Authentication Algorithm |
| Security Fundamentals / Flow-Based Processing (Security) / |
Aggressive aging |
| Security Fundamentals / Flow-Based Processing (Security) / |
Aggressive session aging |
| Security Fundamentals / Flow-Based Processing (Security) / |
Allow packet mode and flow mode on same device |
| Security Fundamentals / Flow-Based Processing (Security) / |
Central point architecture enhancements |
| Security Fundamentals / Flow-Based Processing (Security) / |
Central point session capacity |
| Security Fundamentals / Flow-Based Processing (Security) / |
Central point session scaling |
| Security Fundamentals / Flow-Based Processing (Security) / |
Datapath debugging |
| Security Fundamentals / Flow-Based Processing (Security) / |
Drop-flow to prevent security attack |
| Security Fundamentals / Flow-Based Processing (Security) / |
Enhanced monitoring and troubleshooting of the flow session |
| Security Fundamentals / Flow-Based Processing (Security) / |
Enhanced security flow session command |
| Security Fundamentals / Flow-Based Processing (Security) / |
Enhancement for show security flow statistics operational command |
| Security Fundamentals / Flow-Based Processing (Security) / |
Enhancement of Flow Reroute in Multiple Routing Table |
| Security Fundamentals / Flow-Based Processing (Security) / |
Enhancements to flow trace options |
| Security Fundamentals / Flow-Based Processing (Security) / |
Flow Session Connection Filter Option |
| Security Fundamentals / Flow-Based Processing (Security) / |
Flow and route Scaling |
| Security Fundamentals / Flow-Based Processing (Security) / |
Flow-based forwarding and security features: Multicast flow |
| Security Fundamentals / Flow-Based Processing (Security) / |
Flow-based processing |
| Security Fundamentals / Flow-Based Processing (Security) / |
Forwarding option: flow mode |
| Security Fundamentals / Flow-Based Processing (Security) / |
Fragmentation packet ordering using NP session cache |
| Security Fundamentals / Flow-Based Processing (Security) / |
Hash-based forwarding |
| Security Fundamentals / Flow-Based Processing (Security) / |
Hash-based session distribution |
| Security Fundamentals / Flow-Based Processing (Security) / |
IPFIX formatting for J-Flow functionality |
| Security Fundamentals / Flow-Based Processing (Security) / |
IPv6 Advanced Flow |
| Security Fundamentals / Flow-Based Processing (Security) / |
IPv6 support for network processor offloading |
| Security Fundamentals / Flow-Based Processing (Security) / |
Junos OS flow-based routing functionality |
| Security Fundamentals / Flow-Based Processing (Security) / |
Monitoring flow sessions |
| Security Fundamentals / Flow-Based Processing (Security) / |
NG-IOC cache increases |
| Security Fundamentals / Flow-Based Processing (Security) / |
NP cache and selective installation of NP cache |
| Security Fundamentals / Flow-Based Processing (Security) / |
NP cache scale-up |
| Security Fundamentals / Flow-Based Processing (Security) / |
PMI support for DS-Lite tunnel |
| Security Fundamentals / Flow-Based Processing (Security) / |
Packet-ordering function enhancements |
| Security Fundamentals / Flow-Based Processing (Security) / |
PowerMode Express |
| Security Fundamentals / Flow-Based Processing (Security) / |
Pre-fragmentation and post-fragmentation counters |
| Security Fundamentals / Flow-Based Processing (Security) / |
Preserving incoming fragment characteristics |
| Security Fundamentals / Flow-Based Processing (Security) / |
Reverse route packet mode |
| Security Fundamentals / Flow-Based Processing (Security) / |
SSL remote access VPN support by bypassing an application-based firewall |
| Security Fundamentals / Flow-Based Processing (Security) / |
Secure wire interface mode and forwarding |
| Security Fundamentals / Flow-Based Processing (Security) / |
Selective stateless packet forwarding |
| Security Fundamentals / Flow-Based Processing (Security) / |
Session limit performance enhancement on central point |
| Security Fundamentals / Flow-Based Processing (Security) / |
Stateless packet-based services option |
| Security Fundamentals / Flow-Based Processing (Security) / |
Streaming flow Session and packet data |
| Security Fundamentals / Flow-Based Processing (Security) / |
Strict packet order for multicast traffic |
| Security Fundamentals / Flow-Based Processing (Security) / |
Support for fat flow |
| Security Fundamentals / Flow-Based Processing (Security) / |
System session distribution mechanism in adaptive mode |
| Security Fundamentals / Flow-Based Processing (Security) / |
TCP MSS Adjustment for LNS Sessions |
| Security Fundamentals / Flow-Based Processing (Security) / |
TCP enhancement |
| Security Fundamentals / Flow-Based Processing (Security) / |
Trace and debug of data packets |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Express Path (formerly known as services offloading) |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Express Path (formerly known as services offloading) for ALG traffic |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Express Path (formerly known as services offloading) for IPv6 |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Express Path for Flow Processing |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Express Path session status CLI monitoring improvement and traffic logging |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Express Path support for Fragmentation |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Express Path+ |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Express Path+ for Layer 2 secure-wire traffic |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
MNHA support for Express Path |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Service Offload (SOF) Out Of Order (OOO) Detection for TCP Traffic |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Services Offloading: End-to-end debugging in services-offload mode |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Services Offloading: NP-IOC support |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Services Offloading: Per-wing statistics counters |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Services Offloading: Services-offload traffic across different network processors |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Services Offloading: Session scale up for NP-IOC in services-offload mode |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Services offloading low latency firewall |
| Security Fundamentals / Flow-Based Processing (Security) / Express Path / |
Services offloading of DS-Lite packet processing |
| Security Fundamentals / IP Security (IPsec) / |
8,000 IPsec tunnels |
| Security Fundamentals / IP Security (IPsec) / |
Anti-Replay |
| Security Fundamentals / IP Security (IPsec) / |
Anti-replay window |
| Security Fundamentals / IP Security (IPsec) / |
ChaCha20-Poly1305 authenticated encryption algorithm |
| Security Fundamentals / IP Security (IPsec) / |
CoS-Based IPsec VPNs |
| Security Fundamentals / IP Security (IPsec) / |
Configuring forwarding class on IPsec VPNs |
| Security Fundamentals / IP Security (IPsec) / |
Diffie-Hellman (PFS) Group 1 |
| Security Fundamentals / IP Security (IPsec) / |
Diffie-Hellman (PFS) Group 2 |
| Security Fundamentals / IP Security (IPsec) / |
Diffie-Hellman (PFS) Group 5 |
| Security Fundamentals / IP Security (IPsec) / |
Diffie-Hellman Group 1 |
| Security Fundamentals / IP Security (IPsec) / |
Diffie-Hellman Group 2 |
| Security Fundamentals / IP Security (IPsec) / |
Diffie-Hellman Group 5 |
| Security Fundamentals / IP Security (IPsec) / |
Dynamic IP address |
| Security Fundamentals / IP Security (IPsec) / |
Dynamic Policy for Dialup (based of IKE/IPSec) |
| Security Fundamentals / IP Security (IPsec) / |
ECDSA authentication for IKE SA and AES-GCM encryption for IPsec SA |
| Security Fundamentals / IP Security (IPsec) / |
Enhanced QoS using DSCP per SA in IPsec VPN with iked process |
| Security Fundamentals / IP Security (IPsec) / |
Enhancements to increase traffic selector flexibility |
| Security Fundamentals / IP Security (IPsec) / |
Extended Sequence Number |
| Security Fundamentals / IP Security (IPsec) / |
Group key acknowledgment messages |
| Security Fundamentals / IP Security (IPsec) / |
Hard lifetime limit |
| Security Fundamentals / IP Security (IPsec) / |
Hub & Spoke VPN |
| Security Fundamentals / IP Security (IPsec) / |
IPSec ESP authentication-only mode in PMI |
| Security Fundamentals / IP Security (IPsec) / |
IPSec PIC redundancy enhancements |
| Security Fundamentals / IP Security (IPsec) / |
IPSec tunnel termination in routing-instances |
| Security Fundamentals / IP Security (IPsec) / |
IPsec Distribution Profile |
| Security Fundamentals / IP Security (IPsec) / |
IPsec cleanup when local gateway address |
| Security Fundamentals / IP Security (IPsec) / |
IPsec invalid SPI notification |
| Security Fundamentals / IP Security (IPsec) / |
IPsec packet fragmentation enhancements |
| Security Fundamentals / IP Security (IPsec) / |
IPsec support |
| Security Fundamentals / IP Security (IPsec) / |
IPv6 traffic over IPsec tunnels |
| Security Fundamentals / IP Security (IPsec) / |
Improvements in VPN Debug Capabilities |
| Security Fundamentals / IP Security (IPsec) / |
Improvements in VPN debugging capabilities |
| Security Fundamentals / IP Security (IPsec) / |
Increased IKE security associations |
| Security Fundamentals / IP Security (IPsec) / |
Initial Contact |
| Security Fundamentals / IP Security (IPsec) / |
Inline IPsec |
| Security Fundamentals / IP Security (IPsec) / |
Invalid SPI response |
| Security Fundamentals / IP Security (IPsec) / |
Lifetime-kilobytes, install-interval, and idle-time options with iked process |
| Security Fundamentals / IP Security (IPsec) / |
Load redistribution |
| Security Fundamentals / IP Security (IPsec) / |
Multicast over IPSec tunnels |
| Security Fundamentals / IP Security (IPsec) / |
Multiple peer addresses in DPD configuration with iked process |
| Security Fundamentals / IP Security (IPsec) / |
Multiple traffic selectors on a route-based VPN |
| Security Fundamentals / IP Security (IPsec) / |
NCP Exclusive Remote Access Client connections to IPsec VPN gateways |
| Security Fundamentals / IP Security (IPsec) / |
NHTB - Next Hop Tunnel Binding |
| Security Fundamentals / IP Security (IPsec) / |
New ARI-TS routing protocol type for IPsec VPN traffic selector routes |
| Security Fundamentals / IP Security (IPsec) / |
Packet size configuration for IPsec datapath verification |
| Security Fundamentals / IP Security (IPsec) / |
Packet-based IPsec services |
| Security Fundamentals / IP Security (IPsec) / |
Passing of traffic during a policy mismatch between key server and group member |
| Security Fundamentals / IP Security (IPsec) / |
Policy-based VPN |
| Security Fundamentals / IP Security (IPsec) / |
Remote Access |
| Security Fundamentals / IP Security (IPsec) / |
Route-based VPN |
| Security Fundamentals / IP Security (IPsec) / |
SSL remote access VPNs by encapsulating IPsec traffic over TCP connections |
| Security Fundamentals / IP Security (IPsec) / |
Simplified packet drop identification for IPsec VPN services |
| Security Fundamentals / IP Security (IPsec) / |
Static IP address |
| Security Fundamentals / IP Security (IPsec) / |
Tunnel Mode with clear/copy/set Don't Fragement bit |
| Security Fundamentals / IP Security (IPsec) / |
Tunnel distribution profile and redistribution |
| Security Fundamentals / IP Security (IPsec) / |
VPN Monitoring |
| Security Fundamentals / IP Security (IPsec) / |
VPN monitoring and datapath verification with the iked process |
| Security Fundamentals / IP Security (IPsec) / |
VPN session affinity |
| Security Fundamentals / IP Security (IPsec) / |
VPN support for inserting Services Processing Cards |
| Security Fundamentals / IP Security (IPsec) / |
Verification of the IPsec data path before a point-to-point secure tunnel (st0) interface is activated |
| Security Fundamentals / IP Security (IPsec) / |
Virtual router support for route-based VPNs |
| Security Fundamentals / IP Security (IPsec) / AutoVPN / |
Auto Discovery VPN (ADVPN) protocol |
| Security Fundamentals / IP Security (IPsec) / AutoVPN / |
Auto Discovery VPN (ADVPN) protocol with iked process |
| Security Fundamentals / IP Security (IPsec) / AutoVPN / |
AutoVPN Protocol Independent Multicast (PIM) point-to-multipoint mode |
| Security Fundamentals / IP Security (IPsec) / AutoVPN / |
AutoVPN RIP support for unicast traffic |
| Security Fundamentals / IP Security (IPsec) / AutoVPN / |
AutoVPN hubs |
| Security Fundamentals / IP Security (IPsec) / AutoVPN / |
AutoVPN preshared key |
| Security Fundamentals / IP Security (IPsec) / AutoVPN / |
AutoVPN spokes |
| Security Fundamentals / IP Security (IPsec) / AutoVPN / |
AutoVPN spokes and Auto Discovery VPN (ADVPN) partners |
| Security Fundamentals / IP Security (IPsec) / AutoVPN / |
AutoVPN with traffic selectors |
| Security Fundamentals / IP Security (IPsec) / AutoVPN / |
MNHA ADVPN in node-local tunnel deployment |
| Security Fundamentals / IP Security (IPsec) / Configuration Payload / |
Config Mode (draft-dukes-ike-mode-cfg-03) |
| Security Fundamentals / IP Security (IPsec) / Dead Peer Detection / |
Configurable interval and threshold values for IKEv2 dead peer detection |
| Security Fundamentals / IP Security (IPsec) / Dead Peer Detection / |
Dead peer detection (DPD) |
| Security Fundamentals / IP Security (IPsec) / Dead Peer Detection / |
Enhancement to IPSec dead peer detection |
| Security Fundamentals / IP Security (IPsec) / Dynamic VPN / |
Dynamic VPN Client |
| Security Fundamentals / IP Security (IPsec) / Dynamic VPN / |
Dynamic virtual private network enhancement - Grouping of users |
| Security Fundamentals / IP Security (IPsec) / Dynamic VPN / |
Dynamic virtual private network enhancement - IKE and IPsec configuration validation |
| Security Fundamentals / IP Security (IPsec) / Dynamic VPN / |
Dynamic virtual private network enhancement - Removal of the requirement to configure Web management services |
| Security Fundamentals / IP Security (IPsec) / Group VPN / |
Enhanced Group VPNv2 member features |
| Security Fundamentals / IP Security (IPsec) / Group VPN / |
Group VPN member |
| Security Fundamentals / IP Security (IPsec) / Group VPN / |
Group VPN members supported with Group VPNv2 servers |
| Security Fundamentals / IP Security (IPsec) / Group VPN / |
Group VPN on AMS interface |
| Security Fundamentals / IP Security (IPsec) / Group VPN / |
Group VPN with dynamic policies |
| Security Fundamentals / IP Security (IPsec) / Group VPN / |
Group VPNv2 servers and members |
| Security Fundamentals / IP Security (IPsec) / Group VPN / |
GroupVPN failover to backup router |
| Security Fundamentals / IP Security (IPsec) / IPSec Services Line Cards / |
Diffie-Hellman group15, group16, and group24 for IKE SAs and Ipsec policies |
| Security Fundamentals / IP Security (IPsec) / IPSec Services Line Cards / |
Distinguished name support in IPSec |
| Security Fundamentals / IP Security (IPsec) / IPSec Services Line Cards / |
IKE and IPsec on NAPT-44 and NAT64 |
| Security Fundamentals / IP Security (IPsec) / IPSec Services Line Cards / |
IPSec, stateful firewall, and CGNAT services |
| Security Fundamentals / IP Security (IPsec) / IPSec Services Line Cards / |
IPsec multipath forwarding with UDP encapsulation |
| Security Fundamentals / IP Security (IPsec) / IPSec Services Line Cards / |
IPsec tunnel MTU |
| Security Fundamentals / IP Security (IPsec) / IPSec Services Line Cards / |
Interoperability of MPC10E with MX-SPC3 for IPSec services steering |
| Security Fundamentals / IP Security (IPsec) / IPSec Services Line Cards / |
Optimizing the SNMP walk execution time for IPsec statistics |
| Security Fundamentals / IP Security (IPsec) / Juniper Secure Connect / |
Application bypass in Juniper Secure Connect |
| Security Fundamentals / IP Security (IPsec) / Juniper Secure Connect / |
Automated Certificate Management Environment (ACME) protocol |
| Security Fundamentals / IP Security (IPsec) / Juniper Secure Connect / |
Juniper Secure Connect |
| Security Fundamentals / IP Security (IPsec) / Juniper Secure Connect / |
Juniper Secure Connect integration with JIMS |
| Security Fundamentals / IP Security (IPsec) / Juniper Secure Connect / |
Multiple certificates and Multiple domains |
| Security Fundamentals / IP Security (IPsec) / Juniper Secure Connect / |
Prelogon compliance checks |
| Security Fundamentals / IP Security (IPsec) / Juniper Secure Connect / |
SAML-based user authentication in Juniper Secure Connect |
| Security Fundamentals / IP Security (IPsec) / PowerMode IPsec / |
PowerMode IPsec |
| Security Fundamentals / IP Security (IPsec) / PowerMode IPsec / |
PowerMode IPsec for NAT-T |
| Security Fundamentals / IP Security (IPsec) / PowerMode IPsec / |
PowerMode IPsec for QuickAssist Technology |
| Security Fundamentals / IP Security (IPsec) / PowerMode IPsec / |
PowerMode IPsec fragment |
| Security Fundamentals / IP Security (IPsec) / PowerMode IPsec / |
SPU Forwarding in PowerMode Ipsec |
| Security Fundamentals / IP Security (IPsec) / Site-to-Site VPN / |
4in4 and 6in6 policy-based site-to-site VPN, manual key |
| Security Fundamentals / IP Security (IPsec) / Site-to-Site VPN / |
4in4 and 6in6 route-based site-to-site VPN, manual key |
| Security Fundamentals / IP Security (IPsec) / Site-to-Site VPN / |
Site-to-site VPN support for NAT-T |
| Security Fundamentals / IP Tunneling / |
MAP-E configuration of confidentiality |
| Security Fundamentals / Internet Key Exchange (IKE) / |
4in4 and 6in6 policy-based site-to-site VPN, AutoKey IKEv1 |
| Security Fundamentals / Internet Key Exchange (IKE) / |
4in4 and 6in6 route-based site-to-site VPN, AutoKey IKEv1 |
| Security Fundamentals / Internet Key Exchange (IKE) / |
BGP, OSPF, and OSPFv3 authentication and encryption using manual IPsec SA |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Binding trusted CAs to an IKE Policy |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Certificate-based authentication for IKE |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Cryptographic algorithm support for IPsec and IKE |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Extended Sequence Number using IKEv2 |
| Security Fundamentals / Internet Key Exchange (IKE) / |
External Extended Authentication (Xauth) to a RADIUS server for remote access connections |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKE Diffie Hellman Group 14 support |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKE Phase 1 |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKE Phase 1 lifetime |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKE Phase 2 |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKE Phase 2 lifetime |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKE and IPsec enhancements |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKE responder-only mode |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKE/ESP |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKEv1 authentication, preshared key |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKEv2 - Signature authentication |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKEv2 configuration payload improvements |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKEv2 configuration payload support with RADIUS |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKEv2 message fragmentation |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKEv2 reauthentication |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IKEv2 with NAT-T and dynamic endpoint VPN |
| Security Fundamentals / Internet Key Exchange (IKE) / |
IPSEC IKEv1 |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Idle timers for IKE |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Increase in IKE tunnel setup rate |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Internet Key Exchange (IKE) support |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Internet Key Exchange Protocol daemon (IKED) |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Internet Key Exchange version 2 (IKEv2) |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Manual proxy-ID (Phase 2 ID) configuration |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Migration of policy-based VPNs to route-based VPNs |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Multiple certificate types support on IKEv2 |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Offload cryptographic operations to hardware engine |
| Security Fundamentals / Internet Key Exchange (IKE) / |
PKI: 3DES encryption |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Preshared key (PSK) |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Protocol Requirements for IP Modular Encryption (PRIME) IKEv2 AES-GCM |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Remote Access user IKE peer |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Remote Access user-group IKE peer - group IKE ID |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Robust protection against DDoS attacks on IKE protocol with iked process |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Soft lifetime |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Suite B cryptographic suites |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Support for Remote Access peers with shared IKE identity + mandatory XAuth |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Support group IKE IDs for Dynamic VPN configuration |
| Security Fundamentals / Internet Key Exchange (IKE) / |
Traffic selectors for IKEv2 site-to-site VPNs |
| Security Fundamentals / Internet Key Exchange (IKE) / |
X.509 encoding for IKE |
| Security Fundamentals / Internet Key Exchange (IKE) / |
XAuth (draft-beaulieu-ike-xauth-03) |
| Security Fundamentals / Logging & Reporting / |
Accelerating security and traffic logging |
| Security Fundamentals / Logging & Reporting / |
CPU resource for on-box reporting |
| Security Fundamentals / Logging & Reporting / |
DNS logging in on-box reporting |
| Security Fundamentals / Logging & Reporting / |
Database file size capacity for on-box reporting |
| Security Fundamentals / Logging & Reporting / |
Enhanced VPN support for inactive-tunnel reporting and syslog |
| Security Fundamentals / Logging & Reporting / |
Filtering and Search using new expression option for on-box reporting |
| Security Fundamentals / Logging & Reporting / |
Improved session close log |
| Security Fundamentals / Logging & Reporting / |
Interim logging for NAT port block allocation |
| Security Fundamentals / Logging & Reporting / |
Log profiles and templates for customized logging |
| Security Fundamentals / Logging & Reporting / |
Logging Infrastructure Support for RADIUS Accounting |
| Security Fundamentals / Logging & Reporting / |
Logging and reporting function |
| Security Fundamentals / Logging & Reporting / |
Logging and session-close reasons |
| Security Fundamentals / Logging & Reporting / |
Logical interfaces summary |
| Security Fundamentals / Logging & Reporting / |
Multiple system log servers (control-plane logs) |
| Security Fundamentals / Logging & Reporting / |
Off-box logging |
| Security Fundamentals / Logging & Reporting / |
On-box logging |
| Security Fundamentals / Logging & Reporting / |
On-box logging modernization |
| Security Fundamentals / Logging & Reporting / |
Secure File Transfer Protocol (SFTP) support on Smart Download |
| Security Fundamentals / Logging & Reporting / |
Session Logging with NAT |
| Security Fundamentals / Logging & Reporting / |
System Logging |
| Security Fundamentals / Logging & Reporting / |
System logging (syslog) over IPv6 |
| Security Fundamentals / Logging & Reporting / |
Traffic log enhancement |
| Security Fundamentals / Logging & Reporting / |
WELF (WebTrends Enhanced Log file Format) |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Auto-reboot |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Automatic generation of self-signed certificates |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Automatic reenrollment support for IPSec digital certificates before expiration |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
CRL update at user-specified interval |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Certificate - Configure local certificate sent to peer |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Certificate - Configure requested CA of peer certificate |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Certificate - Encoding: PKCS7 |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Certificate - Encoding: X509 |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Certificate - RSA signature |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Certificate Enrollment |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Certificate Revocation Lists/Certificate revocation checks |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Certificate chaining |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Configure subject alt-name: e-mail, IP, FQDN fields |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Configure subject name for certificates: CN, OU, O, L, ST, C, e-mail, and DC fields |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
DSA Public/Private key-pair (512,1024,2048) |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Digital certificate validation |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Dynamic Update of Default Trusted CA Bundle |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Encoding types for Certificate installation |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Manual enrollment with PKCS10 file |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Manual installation - DER-encoded |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Manual installation - PEM-encoded |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Manual key management |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Online Certificate Status Protocol (OCSP) |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Online certificate revocation list (CRL) retrieval through LDAP and HTTP |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Online retrieval - HTTP |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Online retrieval - LDAP |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI over IPv6 |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI usability enhancements |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI-based link encryption |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Automatic certificate re-enrollment: SCEP |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Automatic local certificate re-enrollment: SCEP |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: CA profile: Routing instance |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: CA profile: Source address |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: CRL: Disable verification on CRL download failure |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Certificate format: DER |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Certificate format: PEM |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Certificate request generation |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Certificate revocation per CA: CRL |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Certificate revocation per CA: OSCP |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: DES encryption |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Export key pair: DER |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Export key pair: PEM |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Export local certificate: DER |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Export local certificate: PEM |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: HTTP web proxy support |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Key pair and size: ECDSA 256 |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Key pair and size: ECDSA 384 |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Key pair and size: ECDSA 521 |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Key pair and size: RSA 2048 |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Load CA certificate from file |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Load CRL from file |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Load local certificate from file |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Local certificate enrollment: SCEP |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Manual certificate re-enrollment |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: OSCP: Disable revocation check for received CA certificate |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: OSCP: Disable revocation check when connection fails |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: OSCP: Fallback to CRL when connection fails |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Private key pair generation |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: SCEP digest: SHA-1 hash |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: SCEP digest: SHA-256 hash |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: SCEP digest: SHA-384 hash |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: SCEP digest: md5 hash |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKI: Self-signed certificate generation: PKCS10 format |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
PKID SSL support services |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Peer certificate revocation check |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Peer certificate verification (signature and validity period) |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
RSA Public/Private key-pair (1024, 2048, 4096) |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Self-signed digital certificates for enabling SSL services |
| Security Fundamentals / Public Key Infrastructure (PKI) / |
Separation of Administrative Roles (Cryptographic/Audit/Security) |
| Security Fundamentals / Public Key Infrastructure (PKI) / IPSec VPN Control Plane / |
Passive mode tunneling support |
| Security Fundamentals / Public Key Infrastructure (PKI) / IPSec VPN Data Plane / |
PKI notifications support for CMPv2 protocol with the jsd process |
| Security Fundamentals / Public Key Infrastructure (PKI) / PKI: Certificate authorities / |
PKI: Certificate Authorities (CAs) |
| Security Fundamentals / Public Key Infrastructure (PKI) / PKI: Certificate authorities / |
PKI: Certificate authorities: Baltimore |
| Security Fundamentals / Public Key Infrastructure (PKI) / PKI: Certificate authorities / |
PKI: Certificate authorities: Entrust, Microsoft, and Verisign |
| Security Fundamentals / Public Key Infrastructure (PKI) / PKI: Certificate authorities / |
PKI: Certificate authorities: Microsoft |
| Security Fundamentals / Public Key Infrastructure (PKI) / PKI: Certificate authorities / |
PKI: Certificate authorities: Netscape |
| Security Fundamentals / Public Key Infrastructure (PKI) / PKI: Certificate authorities / |
PKI: Certificate authorities: RSA Keon |
| Security Fundamentals / Public Key Infrastructure (PKI) / PKI: Certificate authorities / |
PKI: Certificate authorities: Verisign |
| Security Fundamentals / Public Key Infrastructure (PKI) / PKI: Certificate authorities / |
PKI: Certificate authority configuration |
| Security Fundamentals / Public Key Infrastructure (PKI) / PKI: Certificate authorities / |
PKI: Certificate authority enrollment: CMPv2 |
| Security Fundamentals / Public Key Infrastructure (PKI) / PKI: Certificate authorities / |
PKI: Certificate authority enrollment: SCEP |
| Security Fundamentals / SRX Platform Features / |
64-bit support for Junos OS security features |
| Security Fundamentals / SRX Platform Features / |
Chassis components control |
| Security Fundamentals / SRX Platform Features / |
Enhanced CPU core allocation for the Routing Engine |
| Security Fundamentals / SRX Platform Features / |
Enhanced X2 interface monitoring |
| Security Fundamentals / SRX Platform Features / |
Enhancement in Resource Management |
| Security Fundamentals / SRX Platform Features / |
Layer 7 Security Services for EVPN-VXLAN Tunnel Inspection |
| Security Fundamentals / SRX Platform Features / |
Management interface |
| Security Fundamentals / SRX Platform Features / |
Resource-manager commands |
| Security Fundamentals / SRX Platform Features / |
SPU Monitoring |
| Security Fundamentals / SRX Platform Features / |
USB Enable/Disable |
| Security Fundamentals / Security Policies / |
Multiple zones for policies |
| Security Fundamentals / Security Policies / Address Book / |
Address books |
| Security Fundamentals / Security Policies / Address Book / |
Address sets |
| Security Fundamentals / Security Policies / Address Book / |
Dynamic-address group rescan enhancement |
| Security Fundamentals / Security Policies / Address Book / |
Global address book (objects or sets) |
| Security Fundamentals / Security Policies / Address Book / |
IPv6 address configuration: Address books |
| Security Fundamentals / Security Policies / Address Book / |
Negated address support |
| Security Fundamentals / Security Policies / Address Book / |
Nested Address Group |
| Security Fundamentals / Security Policies / Address Book / |
Predefined addresses |
| Security Fundamentals / Security Policies / Address Book / |
User addresses and address groups |
| Security Fundamentals / Security Policies / Group-Based Policies / |
EVPN-VXLAN: Group-based policies |
| Security Fundamentals / Security Policies / Group-Based Policies / |
Filter-based forwarding for GBP-tagged traffic |
| Security Fundamentals / Security Policies / Group-Based Policies / |
GBP filters: Default discard policy rules |
| Security Fundamentals / Security Policies / Group-Based Policies / |
GBP filters: Longest prefix match in IP-based GBP firewall filters |
| Security Fundamentals / Security Policies / Group-Based Policies / |
GBP filters: MAC-based and IP-based GBP filters |
| Security Fundamentals / Security Policies / Group-Based Policies / |
GBP tag propagation with EVPN-VXLAN to EVPN-VXLAN stitching |
| Security Fundamentals / Security Policies / Group-Based Policies / |
GBP tagging and policy enforcement |
| Security Fundamentals / Security Policies / Group-Based Policies / |
Group-based policy in VXLAN architecture |
| Security Fundamentals / Security Policies / Group-Based Policies / |
Micro and macro segmentation with GBP using Mist Access Assurance |
| Security Fundamentals / Security Policies / Group-Based Policies / |
VXLAN group-based policy with ingress and egress configuration |
| Security Fundamentals / Security Policies / Group-Based Policies / |
VXLAN-GBP profiles and additional L4 matches for GBP policy filters |
| Security Fundamentals / Security Policies / Security Policy / |
Bundle Feeds in Dynamic Address Groups |
| Security Fundamentals / Security Policies / Security Policy / |
Custom policy Applications |
| Security Fundamentals / Security Policies / Security Policy / |
Debug improvement of policy PFE control thread |
| Security Fundamentals / Security Policies / Security Policy / |
Display dynamic-applications and URL category hit counts in a security policy |
| Security Fundamentals / Security Policies / Security Policy / |
Dynamic routing protocols predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
Enhancements to configuring security policies |
| Security Fundamentals / Security Policies / Security Policy / |
Global policy |
| Security Fundamentals / Security Policies / Security Policy / |
HTTPS |
| Security Fundamentals / Security Policies / Security Policy / |
Hit-count tracking |
| Security Fundamentals / Security Policies / Security Policy / |
Hypertext Transfer Protocol (HTTP) |
| Security Fundamentals / Security Policies / Security Policy / |
IP-related predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
IPs from DNS snooping cache |
| Security Fundamentals / Security Policies / Security Policy / |
IPv6 address configuration: Security policy rule matching |
| Security Fundamentals / Security Policies / Security Policy / |
Increase in number of address objects per policy |
| Security Fundamentals / Security Policies / Security Policy / |
Instant messaging predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
Internet Control Message Protocol (ICMP) predefined policy application |
| Security Fundamentals / Security Policies / Security Policy / |
Internet-related predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
Juniper Entropy Beacon |
| Security Fundamentals / Security Policies / Security Policy / |
Mail predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
Maintain flow session stability during policy configuration changes |
| Security Fundamentals / Security Policies / Security Policy / |
Management predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
Maximum number of addresses per security policy increased |
| Security Fundamentals / Security Policies / Security Policy / |
Maximum number of security policies increased |
| Security Fundamentals / Security Policies / Security Policy / |
Microsoft predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
Miscellaneous predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
New match criteria for user role firewall policies |
| Security Fundamentals / Security Policies / Security Policy / |
New operational commands for security policy configuration |
| Security Fundamentals / Security Policies / Security Policy / |
Optional application configuration in a unified policy |
| Security Fundamentals / Security Policies / Security Policy / |
Per-policy support for 3072 application items |
| Security Fundamentals / Security Policies / Security Policy / |
Policy Attachment and Detachment for ALG |
| Security Fundamentals / Security Policies / Security Policy / |
Policy Verification (to avoid shadow policies) |
| Security Fundamentals / Security Policies / Security Policy / |
Policy application timeouts |
| Security Fundamentals / Security Policies / Security Policy / |
Policy applications and application sets |
| Security Fundamentals / Security Policies / Security Policy / |
Policy rematch |
| Security Fundamentals / Security Policies / Security Policy / |
Real-time DNS snooping for dynamic FQDN policy updates |
| Security Fundamentals / Security Policies / Security Policy / |
Security Policies |
| Security Fundamentals / Security Policies / Security Policy / |
Security Policy |
| Security Fundamentals / Security Policies / Security Policy / |
Security and tunnel predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
Security policies for self-traffic |
| Security Fundamentals / Security Policies / Security Policy / |
Security policies to add source and destination addresses to security feeds |
| Security Fundamentals / Security Policies / Security Policy / |
Security policy firewall authentication now provides user identities for user role firewall provisioning |
| Security Fundamentals / Security Policies / Security Policy / |
Security policy reports |
| Security Fundamentals / Security Policies / Security Policy / |
Setting the TCP MSS value per security policy |
| Security Fundamentals / Security Policies / Security Policy / |
Streaming video predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
Sun remote procedure protocol (RPC) predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
Support to configure micro-applications in a unified policy |
| Security Fundamentals / Security Policies / Security Policy / |
TCP Session Check Per Policy |
| Security Fundamentals / Security Policies / Security Policy / |
UNIX predefined policy applications |
| Security Fundamentals / Security Policies / Security Policy / |
Unified policies support for zone-context and global-level policies |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication Customizable Banners |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication HTTP |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication IPv6 support |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication Policy checks group-expressions |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication Policy checks user-groups |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication Policy checks users |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication Viewing current/historical user auth state |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication over SSL |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication via LDAP client |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication via Local User Database |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication via RADIUS client |
| Security Fundamentals / Security Policies / Security Policy / |
User Web Authentication via SecurID client |
| Security Fundamentals / Security Policies / Security Policy / |
Web authentication |
| Security Fundamentals / Security Policies / Security Zones / |
Binding interfaces to a security zone |
| Security Fundamentals / Security Policies / Security Zones / |
Functional security zones |
| Security Fundamentals / Security Policies / Security Zones / |
Secure wire mode and mixed mode (Layer 2 and Layer 3) |
| Security Fundamentals / Security Policies / Security Zones / |
Security zone |
| Security Fundamentals / Security Policies / Security Zones / |
Security zones, interfaces, and authentication |
| Security Fundamentals / Security Policies / Security Zones / |
Unidirectional session refreshing for security zones |
| Security Fundamentals / Security Policies / Security Zones / |
Zone based segmentation |
| Security Fundamentals / Security Screens / |
Bypass IP block fragmentation check with allowlist configuration |
| Security Fundamentals / Security Screens / |
Firewall Screens |
| Security Fundamentals / Security Screens / |
Global IP allowlist support for all screen options |
| Security Fundamentals / Security Screens / |
IP fragmentation |
| Security Fundamentals / Security Screens / |
IPv6 support for screens |
| Security Fundamentals / Security Screens / |
Screen II - Support for syn flood, ip spoofing |
| Security Fundamentals / Security Screens / |
TCP proxy for TCP WS option |
| Security Fundamentals / Security Screens / |
TCP proxy short-circuit |
| Security Fundamentals / Stateful Firewalls / |
FIN scan |
| Security Fundamentals / Stateful Firewalls / |
IP fragments |
| Security Fundamentals / Stateful Firewalls / |
Land attack |
| Security Fundamentals / Stateful Firewalls / |
Loose/Strict IP source routing |
| Security Fundamentals / Stateful Firewalls / |
NOn-SYN flags |
| Security Fundamentals / Stateful Firewalls / |
Operating system probes |
| Security Fundamentals / Stateful Firewalls / |
Reconnaissance using IP options |
| Security Fundamentals / Stateful Firewalls / |
SYN Cookie |
| Security Fundamentals / Stateful Firewalls / |
SYN Proxy |
| Security Fundamentals / Stateful Firewalls / |
SYN flood |
| Security Fundamentals / Stateful Firewalls / |
Screen |
| Security Fundamentals / Stateful Firewalls / |
Session table flood |
| Security Fundamentals / Stateful Firewalls / |
Stateful Firewall |
| Security Fundamentals / Stateful Firewalls / |
TCP SYN cookie |
| Security Fundamentals / Stateful Firewalls / |
WinNuke attack protection |