Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Open Issues

Learn about open issues in this release for SRX Series devices.

For the most complete and latest information about known Junos OS defects, use the Juniper Networks online Junos Problem Report Search application.

General Routing

  • IPSec rekey fails when SRX is configured with kilobyte based lifetime in remote access solution. PR1527384

  • With ssl-proxy configured along with web-proxy, the client session might not get closed on the device until session timeout, even though the proxy session ends gracefully.PR1580526

  • Device does not drop session with server certificate chain more than 6.PR1663062

  • FIPS mode is not supported in this release for SRX devices.PR1697999

  • On Junos (FreeBSD) platforms, kernel panic was seen.PR1709013

Chassis Clustering

  • DSCP remarking is required to classify BFD packets as high priority. PR1693457

Flow-Based and Packet-Based Processing

  • For accelerated flows such as Express Path, the packet or byte counters in the session close log and show session output take into account only the values that accumulated while traversing the NP. PR1546430

Infrastructure

  • NTP time drift on the affected Junos releases. Earlier implementation of kvmclock with vDSO (virtual Dynamic Shared Object) which helps avoid the system call overhead for user space applications had problem of time drift, the latest set of changes takes care of initializing the clock after all auxiliary processors are launched so that the clock initialization is accurate.PR1691036

Layer 2 Ethernet Services

  • If a client sends a DHCP request packet, and option 55 includes PAD option (0), a DHCP ACK will not be sent back to the client. PR1201413

VPNs

  • First time when we add this command the existing active connections are not changed, only the new connection after this command will be taken into effect. PR1608715

  • On all SRX platforms in chassis cluster which support ISSU, when the JUNOS IKE package is present and IPSec VPN is configured, ISSU is not supported from any release before 22.4R1 to 22.4R1 or later. You can use CLI command 'show version' to confirm if JUNOS IKE package is present on your device.PR1722689