Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


Open Issues

Learn about open issues in this release for vSRX.

For the most complete and latest information about known Junos OS defects, use the Juniper Networks online Junos Problem Report Search application.

General Routing

  • The tag RT_FLOW_SESSION_XXX is missing in stream mode. PR1565153

  • When the device is downgraded to a release earlier than Junos OS Release 21.1 and then upgraded again to Junos OS Release 21.1, the appiddb tables might not get populated properly and have 0 entries. For such cases, after upgrading, uninstall and reinstall signature package. PR1567199

  • Under very rare conditions for HA cluster deployment, when it does RG0 failover and at same time, the control link is down, then it will hit this mib2d core because the master RE and secondary RE are out of syncing dcd.snmp_ix information. PR1571677

  • On SRX Series devices, the auto re-enrollment of a CMPv2 certificate might lead to a PKID core due to OpenSSL version mismatch. PR1580442

  • With SSL proxy configured along with web proxy, the client session might not closed on the device even though proxy session ends gracefully. PR1580526

  • Getting UNKNOWN instead of HTTP-PROXY for application and UNKNOWN instead of GOOGLE-GEN in RT-FLOW close messages These messages can be seen in the RT-flow close log and these are due to JDPI not engaged for the session. This may affect the app identification for the web-proxy session traffic. PR1588139

  • The request system power-off command cannot completely shutdown vSRX3.0 if Mellanox SR-IOV is used as revenue ports. The system will hang after peer_proxy: 5447: Peer proxy (class: 0, type: 10, index: 0, vksid: 0, state: 1) is marked for the closing. The power state is still on until forcefully shut it off from hypervisor. PR1604063


  • If any VPN related configuration changes are done from the CLI and committed, click on the Monitor> Network > IPsec VPN menu again to see the latest changes. PR1571751

  • UI lists the IPSec VPNs information for uncommitted IPSec VPNs configuration under Monitor -> Netwrok -> IPSec VPN. PR1576609

Routing Policy and Firewall Filters

  • When you set the global-configuration of the SSL Proxy with enable-proxy-on-default-fw-policy-match, the traffic hits the pre-id policy instead of the default policy for the Yahoo traffic. PR1542790