Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Software Support

 

Software Downloads

Table 1 displays the supported versions and download links for software components associated with CSO Release 5.1.1.​

Note
  • Before you onboard devices, ensure that the device is running the software version that is recommended in this release notes.

  • CSO Release 5.1.1 extends Beta support for Junos OS Release 19.3R2-S1.

Table 1: Software Components Associated with CSO Release 5.1.1

Product

Supported Version

Download Link

Juniper Identity Management Service (JIMS)

1.1.5R1

Pre-bundled with CSO.

EX Series switches

Junos OS Release 18.4R2

Junos OS Release 18.4R3

Junos OS Release 18.4R2

Junos OS Release 18.4R3

NFX150 CPE device

Junos OS Release 18.2X85-D12

Junos OS Release 19.3R2-S1

NFX250 CPE device

Junos OS Release 15.1X53-D497

Junos OS Release 18.4R3

SRX Series CPE devices

Junos OS Release 15.1X49-D172

Junos OS Release 19.3R2-S1

SRX300, SRX320, SRX340, SRX345, and SRX550 High Memory Services Gateway (SRX550M) (as spoke devices):

SRX Series Next-Generation Firewall devices

Junos OS Release 18.4R1

Junos OS Release 19.3R2-S1

SRX300, SRX320, SRX340, SRX345, and SRX550:

SRX Series Provider Hub device

Junos OS Release 15.1X49-D172

SRX1500

SRX4100, SRX4200:

SRX Series Enterprise Hub devices

Junos OS Release 15.1X49-D172

Junos OS Release 19.3R2-S1

vSRX for SD-WAN devices

Junos OS Release 15.1X49-D172

Junos OS Release 19.3R2-S1

For hub devices and spoke devices:

vSRX for next-generation firewall devices

Junos OS Release 18.4R1

Junos OS Release 19.3R2-S1

We recommend that you use Junos OS Release 15.1X49-D172 in your production environment instead of Junos OS Release 19.3R2-S1 because of the following known limitations in Junos OS Release 19.3R2-S1:

  • Connection fails when traffic is sent through an NFX250 device on which vSRX is installed. [PR 1483425]

  • In an SRX3xx dual CPE cluster, ZTP does not progress if the secure OAM tunnel from the primary node is down. [PR 1484382, PR 1484389]

  • Sometimes, vSRX when running on an NFX250 device does not show the ge- interfaces after you upgrade the image from Junos OS Release 15.1X49-D172.1 to Junos OS Release 19.3R2-S1. [PR 1482360]

  • In an SRX1500 dual-CPE cluster, you cannot add a license to the backup node by using the request system license add command. [PR 1485128]

  • GRE interface in an NFX150 device may appear as down, even though it is actually up. [PR 1456184]

  • Zero-touch provisioning (ZTP) of a device running Junos OS Release 19.3R2-S1 may fail due to failure in installing the default-trusted certificate authority (CA). [PR 1472607]

  • Full mesh dynamic VPN tunnel formed through a device running Junos OS 19.3R2-S1 may not come up. [PR 1482984]

  • LAN traffic may be interrupted while configuring a full mesh DVPN tunnel on a device running Junos OS Release 19.3R2-S1. [PR 1484083]

  • During ZTP of an SRX1500 dual CPE cluster, the devices in the cluster reboot automatically. [PR 1484257]

Software Installation Requirements for NFX Series Network Services Platform

When you set up a distributed deployment with an NFX150 or an NFX250 device, you must use Administration Portal or the CSO API to:

  1. Upload the software image to CSO.Note

    Only an SP administrator can upload the software image to CSO. If you are an OpCo administrator or a tenant administrator and if you need to upload the required software image, contact Juniper Networks Technical Assistance Center (JTAC).

  2. Specify this image as the boot image when you configure activation data.

For more information on NFX series documentation, see https://www.juniper.net/documentation/product/en_US/nfx150 and https://www.juniper.net/documentation/product/en_US/nfx250 .