- play_arrow Junos OS Release Notes for ACX Series
- play_arrow Junos OS Release Notes for cRPD
- play_arrow Junos OS Release Notes for cSRX
- play_arrow Junos OS Release Notes for EX Series
- play_arrow Junos OS Release Notes for JRR Series
- play_arrow Junos OS Release Notes for MX Series
- play_arrow What's New
- EVPN
- High Availability
- Interfaces
- Junos Telemetry Interface
- Licensing
- MPLS
- Network Address Translation (NAT)
- Network Management and Monitoring
- Precision Time Protocol (PTP)
- Routing Protocols
- Securing GTP and SCTP Traffic
- Source Packet Routing in Networking (SPRING) or Segment Routing
- Subscriber Management and Services
- VPNs
- Additional Features
- What's Changed
- Known Limitations
- Open Issues
- Resolved Issues
- Migration, Upgrade, and Downgrade Instructions
- play_arrow Junos OS Release Notes for NFX Series
- Junos OS Release Notes for PTX Series
- play_arrow Junos OS Release Notes for QFX Series
- play_arrow Junos OS Release Notes for SRX Series
- play_arrow What's New
- Authentication and Access Control
- Chassis Cluster-specific
- Flow-based and Packet-based Processing
- Intrusion Detection and Prevention
- J-Web
- Licensing
- Network Address Translation (NAT)
- Network Management and Monitoring
- Securing GTP and SCTP Traffic
- Software Installation and Upgrade
- Content Security
- VPNs
- What's Changed
- Known Limitations
- Open Issues
- Resolved Issues
- Migration, Upgrade, and Downgrade Instructions
- play_arrow Junos OS Release Notes for vMX
- play_arrow Junos OS Release Notes for vRR
- Licensing
- Finding More Information
- Requesting Technical Support
- Revision History
VPNs
Introduction of prelogon compliance checks (SRX Series and vSRX 3.0)—In Junos OS Release 23.1R1, we introduce prelogon compliance for Juniper Secure Connect. This functionality validates the current status of a connecting client device prior to the authentication (that is, before user's login). You can configure different match criteria on the SRX Series firewall to allow or reject client devices.
You can configure this feature using the statement
compliance pre-logon name
at:[edit security remote-access]
hierarchy level to configure prelogon compliance rules.[edit security remote-access profile realm-name]
hierarchy level to associate a prelogon compliance rule to the remote-access profile.
[See prelogon compliance checks.]
Support for application bypass in Juniper Secure Connect (SRX Series and vSRX 3.0)—Starting in Junos OS Release 23.1R1, you can use Juniper Secure Connect to send specific application traffic directly to its destination instead of passing it through the VPN tunnel. You can accomplish this functionality by specifying domain names and protocols for the specified applications that would bypass the VPN tunnel. The bypass feature simplifies the administrator and end-user experience.
When you configure the application bypass feature and establish a remote-access VPN tunnel, the configuration automatically enables a stateful firewall rule rejecting incoming connections on other adapters, which prevents the device from becoming a bastion host.
You can configure this feature on SRX Series firewalls and on vSRX 3.0 virtual firewalls by using
application-bypass
at the [edit security remote-access client-config name
] hierarchy level.[See Application Bypass.]
Support for multiple certificates and multiple domains (SRX Series and vSRX 3.0)—Starting in Junos OS Release 23.1R1, with support for multiple certificates and multiple domains, we now allow Juniper Secure Connect connection profiles with different URLs without any certificate warning.