Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


Open Issues

Learn about open issues in this release for SRX Series devices.

For the most complete and latest information about known Junos OS defects, use the Juniper Networks online Junos Problem Report Search application.

Chassis Clustering

  • 10G DAC cable is not supported at CTL/FAB link at SRX4100/4200 Cluster setup. Hardware Compatibility Tool ( reports 10G DAC cables are as "supported", but CTL and FAB links are out of scope. - SRX-SFP-10GE-DAC-1M - SRX-SFP-10GE-DAC-3MPR1636365

Flow-Based and Packet-Based Processing

  • For accelerated flows such as Express Path, the packet or byte counters in the session close log and show session output take into account only the values that accumulated while traversing the NP. PR1546430

Interfaces and Chassis

  • Traffic drop might be seen on irb interface on SRX1500 for network control forwarding class when verifying dscp classification based on single and multiple code-points. PR1611623

Platform and Infrastructure

  • In Mac-OS platforms when Juniper Secure Connect client connects successfully, the client is not getting minimized to tray icon and needs to be minimized manually.PR1525889

  • IPSec rekey fails when SRX is configured with kilobyte based lifetime in remote access solution. PR1527384

  • With ssl-proxy configured along with web-proxy, the client session might not get closed on the device until session timeout, even though the proxy session ends gracefully.PR1580526

  • On MX platforms the JDM (Juniper Device Manager) server could not be created in in-chassis mode of junos node slicing, which results in mgd process crash and affects GNF's (Guest Network Function) provisioning. PR1583324

  • HA AP mode on-box logging in LSYS and Tenant, Intermittently Security log contents of binary log file in LSYS are not as expected PR1587360

  • SMTPS sessions are not getting identified when traffic is sent from IXIA (BPS) profile. PR1635929

  • Firewall-authentication with user-firewall based RADIUS access has syslog missing the username and rule.PR1654842

  • On SRX series platform with chassis cluster enabled, the reth (Redundant Ethernet) interface might not come up due to speed mismatch when the reth interface speed is changed after RG0 (redundancy group) failover.PR1658276

  • On SRX platforms using authentication-scheme (pass-through/web-auth/web-redir) and authentication sources (firewall-user/ldap/radius) do not display the complete user's group information because the display buffer for showing group names for an authentication entry is too small.PR1673125

  • For logical system, tenant logical interface with unit 0 and without vlan tagging/ vlan id can be created from Network>Connectivity>Interfaces. Same cannot be done from Logical system or tenant workflow.PR1676235

  • On SRX380, the Autonegotiation status on the 1G/10G ports may be incorrectly displayed as "Incomplete". This has no impact to traffic.PR1703002


  • Tunnel debugging configuration is not synchronized to the backup node. It needs to be configured again after RG0 failover. PR1450393