Re: [j-nsp] MX204 update from 21.4R3-S4 to 21.4R3-S5

2023-11-09 Thread Richard McGovern via juniper-nsp
I believe if you cipher is set to one that Juniper no longer supports, i.e. that knob selection is depreciated, the upgrade will not complete. The change in cipher support is due to new vulnerability findings. SSH Vulnerability, "Deprecated SSH Cryptographic Settings" with Vulnerability Result

Re: [j-nsp] MX204 update from 21.4R3-S4 to 21.4R3-S5

2023-11-09 Thread Andreas S. Kerber via juniper-nsp
Am Thu, Nov 09, 2023 at 12:43:18PM +0300 schrieb Muhammad Aamir: > *try below and do to upgrade again.* > *deactivate system services ssh ciphers * Thanks Aamir! we had an ancient ssh key-exchange statement configured. After removing that, the installation worked fine. Thanks again! Andreas

Re: [j-nsp] MX204 update from 21.4R3-S4 to 21.4R3-S5

2023-11-09 Thread Muhammad Aamir via juniper-nsp
*try below and do to upgrade again.* *deactivate system services ssh ciphers * *Regards,* *Aamir* On Thu, Nov 9, 2023 at 12:28 PM Andreas S. Kerber via juniper-nsp < juniper-nsp@puck.nether.net> wrote: > Anybody successfully updated MX204 from 21.4R3-S4 to 21.4R3-S5? > Got a few MX204 and

[j-nsp] MX204 update from 21.4R3-S4 to 21.4R3-S5

2023-11-09 Thread Andreas S. Kerber via juniper-nsp
Anybody successfully updated MX204 from 21.4R3-S4 to 21.4R3-S5? Got a few MX204 and trying to "request vmhost software add" fails on each of them. Anybody got a hint for me? $ request vmhost software add /var/tmp/junos-vmhost-install-mx-x86-64-21.4R3-S5.4.tgz Junos Validation begin. Procedure

Re: [j-nsp] backup routing engine authente from in-band interface

2023-11-09 Thread Saku Ytti via juniper-nsp
On Thu, 9 Nov 2023 at 10:38, Chen Jiang via juniper-nsp wrote: > Just want to confirm if Juniper backup routing engine could authenticate > users from in-band interface like ge-0/0/0 to the AAA server? > > If not, do we have a solution? The scenario is MX960 with dual RE and no > OOB network.

[j-nsp] backup routing engine authente from in-band interface

2023-11-09 Thread Chen Jiang via juniper-nsp
Hi! Experts Just want to confirm if Juniper backup routing engine could authenticate users from in-band interface like ge-0/0/0 to the AAA server? If not, do we have a solution? The scenario is MX960 with dual RE and no OOB network. But need to authenticate users login backup RE from AAA.