Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Resolved Issues

Learn about the issues fixed in this release for SRX Series.

Application Layer Gateways (ALGs)

  • The flowd crash might be observed on SRX5k series platforms where Central Point is present PR1658370

  • SIP 200 OK(INVITE) response packets are dropped leading to SIP Call failure PR1677554

Chassis Clustering

  • In the MNHA SRG scenario on the IPv6 switching mode, not using 'Virtual MAC' as the source MAC address for G-NDP PR1670309

  • GTP control packets might be incorrectly dropped/passed if there is more than one APN IMSI filter configured PR1673879

Class of Service (CoS)

  • "show interfaces queue interface" command output not correctly displaying bps values for throughput higher than 4.25Gbps PR1596172

Flow-Based and Packet-Based Processing

  • The hardware acceleration flag was not properly updated on RT_FLOW_SESSION_CLOSE logs. Additionally, the values for "Services-offload-sessions" for customers using SPC2's in their SRX5000-Series devices was incorrect. PR1629216

  • The gre-performance-acceleration might cause VPLS traffic drop PR1661409

  • In SD-WAN the association between VRF instance and VRF group fails for ISSU from 19.2~21.1 to 22.2R1 PR1661935

  • vSRX not processing fragmented packets PR1668898

  • On SRX5K series devices with IOC2 line-cards installed, when running JUNOS 21.2R1 or later where Automated Express Path is enabled by default, sessions traversing the IOC2 card may time out early, leading to traffic loss and unpredictable flow behaviour. This issue does not affect traffic traversing IOC3 and IOC4 cards. PR1688658

Interfaces and Chassis

  • 22.2TOT :SecPDT:Unified L4/L7 Use Case Sky ATP: reth1 interface down and DCD cores observed on node1 during test on 22.2TOT image PR1657021

J-Web

  • Various page errors have been corrected in JWeb PR1658330

  • J-Web page not properly loaded for a user using a username including .(dot) PR1665006

  • All the security policies on Junos SRX platforms can get deleted while trying to delete any particular policy via J-Web PR1681549

Network Address Translation (NAT)

  • The NAT ports exhaust when address-pooling pair is configured in SRX devices PR1651939

Network Management and Monitoring

  • High logging rate may cause 'eventd' to increase RE CPU utilization PR1661323

Platform and Infrastructure

  • 21.4R1:IPSEC:pkid.core-tarball found @ pkid_request_security_pki_local_cert_verify (msp=0x1abc940, csb=0xffffdb60, unparsed=0x1a7402e "certificate-id") at ../../../../../../../src/junos/usr.sbin/pkid/pkid_ui.c:1076 PR1624844

  • A major alarm DPDK (data plane development kit) Tx stuck issue of SRX4100/4200 PR1626562

  • SMS Channel Down alarm on primary node of HA pair after upgrade PR1629972

  • 22.1TOT : SnP :SRX5K_SPC3 : Observing Error "usp_ipc_client_recv_:ipc_pipe_read() " due to coredump,when checking "show security monitoring" cli command, in the latest 22.1(22.1I-20220108.0.0529) build. PR1641995

  • 21.3R2:NCP Secure Connect:Licensing: remote-access-juniper-std license not getting freed up while disconnect/reconnect after RG0 failover PR1642653

  • Packet loss might be seen on SRX4100 and SRX4200 devices from 20.2R2 PR1650112

  • 22.1R1:AUTH:unable to get the "firewall-authentication users" details on node 1 PR1651129

  • The fxp0 interface might remain 'UP' when the cable is disconnected PR1656738

  • 22.2R1:: MISC:: mspmand core found @sarena_free @mum_free @jsf_shm_free @jssl_mem_pool_free @jsf_openssl_free @CRYPTO_free @ssl_cert_free @jssl_config_dtor @msvcs_plugin_send_control_rt PR1657027

  • Archived file which created by non-root user may not include some files under /var/log/ directory PR1657958

  • The PFE may crash when a large amount of traffic is submitted to ATP Cloud for inspection PR1661766

  • Ssl-proxy: Cache miss counter increments twice instead of one PR1663678

  • SRX alarming "SMS control channel down" without SMS feature configured PR1666420

  • 22.1 DCB: IPv6 feature not working on 5K platform. PR1668473

  • The Forwarding plane crashes during HA failover PR1672378

  • Information about users groups is not displayed completely PR1673125

  • A FlowD crash might occur when AAMW (Advanced-Anti-Malware) encounters a memory leak PR1675722

  • Netbios traffic (IRB broadcast) is getting dropped post upgrade on the SRX platform PR1675853

  • PKID process crashes when validating the certificate chain of a certificate PR1679067

  • "NSD_CLEAR_POLICY_DNS_CACHE_ENTRY_IP" log is not found on the device after keeing DNS cache entry unchanged PR1684268

Routing Policy and Firewall Filters

  • The utility 'monitor security packet-drop' now correctly reports policy-related drops for unified policy (includes the exact policy that dropped the packet) PR1576150

  • Security policy state may be invalid on SRX platforms PR1669386

  • The rpd process crashes whenever it is getting shut down with router reboot, rpd restart, RE switchover, software upgrade PR1670998

  • SRX stops refreshing the FQDNs used in the security policies and NAT PR1680749

Routing Protocols

  • The BSR information might not be flooded over NG-MVPN PR1664211

User Interface and Configuration

  • IPSec tunnel will flap post MNHA configuration commit PR1669104

  • "gethostbyname: Host name lookup failure" is displayed during commit PR1673176

VLAN Infrastructure

  • Traffic Stops when the mac address of a node changes in L2 secure-wire SOF PR1597681

  • OSPF neighbor won't establish under Transparent mode when neighborship across different zone PR1599891

VPNs

  • 21.4Th :SPC3-Config payload :Tunnel bringing up failed from strongswan when changing the configuration IKE in VR and observed the " NO_PROPOSAL_CHOSEN notify error" message PR1627963

  • Severity is unknown at some IPSec syslog messages PR1629793

  • Vmcore is seen on Junos platforms when data plane IPSec is configured PR1648249

  • The Juniper secure connect VPN users may face login issues intermittently PR1655140

  • Packets traversing through a policy-based VPN get dropped when PowerMode is enabled PR1663364

  • IPSec tunnels may flap on SRX platforms PR1665332

  • 22.2R1: Master Password for Configuration Encryption and FIPS mode should not be enabled together PR1665506

  • High Control Plane CPU utilisation while the kmd process is stuck after the core file PR1673391