VPNs
-
Support for dynamic update of trusted CA bundle (SRX1500, SRX4100, SRX4200, SRX4600, SRX5400, SRX5600, SRX5800, vSRX 3.0 and NFX350)—Starting in Junos OS Release 23.2R1, we support the dynamic update of default trusted CA certificates. With this feature, you have the latest list of default trusted CA certificates on Junos OS devices. You can easily download, install, and update the certificate bundle periodically.
-
Support for additional platform for cryptographic acceleration techniques (SRX1500, SRX4100, SRX4200, SRX4600)—Starting in Junos OS Release 23.2R1, the SRX Series Firewalls (SRX1500, SRX4100, SRX4200, SRX4600) offload the DH, ECDH and ECDSA cryptographic operations to the hardware cryptographic engine. We already support these operations on SRX5000 line of devices and vSRX 3.0. The SRX5000 line of devices continue to offload the cryptographic operations to the hardware cryptographic engine whereas the vSRX Virtual Firewall continues to offload these operations to a data plane CPU thread. This feature requires that the
junos-ike
package is installed on all the devices.