Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


Resolved Issues

Learn about the issues fixed in this release for SRX Series devices.

For the most complete and latest information about known Junos OS defects, use the Juniper Networks online Junos Problem Report Search application.

Application Layer Gateways (ALGs)

  • H.323 traffic failure caused by RAS packet drops when incorrect route lookup performed. PR1688986

  • The first FTPS session will not work on SRX5000 line leading to a traffic drop.PR1715918

  • SIP ALG not working and traffic is dropped. PR1728638

Authentication and Access Control

  • Connection fails are observed on Junos despite a valid auth entry. PR1692398

Chassis Clustering

  • New secondary node to go into a disabled state after ISSU and failover RG0 because of fabric link failure. PR1678772

  • The secure tunnel interface does not work properly in SRX standalone mode. PR1702763

  • From Junos OS Release 20.4 onwards,St0.16000 to st0.16385 will not be allowed to be configured in HA and MNHA mode. PR1704670

Class of Service (CoS)

  • QoS scheduler map incorrect when using wildcard interface configuration: " interface unit * " starting with Junos OS Release 21.1. PR1734013

Flow-Based and Packet-Based Processing

  • VPN logs in monitor hierarchy on J-Web not being seen. PR1691095

  • Packet loss is observed for IPsec sessions when PMI is enabled. PR1692885

  • The core files are generated when user is changing interface configuration. PR1704623

  • A flowd process stops on SRX4100, SRX4200, SRX4600, vSRX, and SRX5000 line with SPC3 card when a route is changed frequently. PR1705996

  • The IPv6 source-level fragmented SCTP packets passing through an IPsec tunnel will be dropped. PR1708876

  • The traffic will fail when accessing the routing instance interface IP from external IP. PR1719437

  • IPv6 Neighbor Discovery is failing on VLAN tagging interface. PR1720570

General Routing

  • Security log verification is failing as the contents of binary log file in logical systems are not as expected. PR1587360

  • SRX4600 packet drop or srxpfe generates core files. PR1620773

  • BGP down due to BFD expired; failover restored services. PR1630981

  • On SRX5600 and SRX5800, the SNMP MIB queries may result in occasional response timeouts. PR1631149

  • IMAP or IMAPS email permitted counter is not incremented in AAMW email statistics while testing whole email block. PR1646661

  • No system or chassis alarm will be seen when device booting from backup partition. PR1646943

  • The show fwauth user details is not displaying group information. PR1659115

  • SRX4600 HA might not failover properly due to a hardware failure. PR1683213

  • On all Junos logical systems the RPD process stops due to JET client invoking RPC handled by RPD process. PR1692738

  • IPsec tunnel is not getting established back after the execution of clear security ike sa command. PR1694604

  • TCP packet drops are seen when services-offload is enabled. PR1702138

  • The flowd process stops and generates core files when TLS 1.3 session ticket is received on SSL-I. PR1705044

  • Unable to onboard SRX on a Yang based Orchestrator. PR1705679

  • TX would be stuck and no packet can be transferred by the SPC3 card. PR1706756

  • Setting the security log profile without a category or stream will lead to srxpfe process stops. PR1708777

  • The ECDSA certificate based websites are not accessible when the SSL proxy is enabled from Junos OS Release 22.1R1 onwards. PR1709386

  • SRX4600 doesn't support aggregated Ethernet interfaces. PR1711467

  • The targeted-broadcast feature will not work on some SRX platforms. PR1711729

  • Continuous vmcores observed on the secondary node when committing set system management-instance command. PR1712727

  • The fabric link flapped which initiated a Packet Forwarding Engine pause. PR1713263

  • RA can be sent in response to an invalid RS. PR1713485

  • Continuous vmcores observed on the secondary node when committing the "set system management-instance" command. PR1713759

  • The firewall web-authentication feature will not work after enabling Juniper secure connect. PR1714845

  • The NSD process may report an error message. PR1715297

  • The SSL session drops because of the wrong SNI value. PR1716893

  • Errors seen under interfaces in slot0 option. PR1717095

  • The srxpfe core has been seen on secondary SRX during ISSU. PR1717503

  • The flowd process stops when the web proxy packet reinjection fails. PR1719703

  • With SD-WAN configuration on SRX, flowd process generates core files if APBR rule is not attached to SLA. PR1719965

  • Local route is not added in the secondary FIB and KRT queue is stuck. PR1721032

  • Configuration download failing for FQDN style realm name + no default-profile knob with previous versions of Juniper Secure Connect client. PR1721631

  • Nstraced process is running high on the primary node after the Junos OS upgrade. PR1727122

Interfaces and Chassis

  • Traffic fail seen on irb interface for network control forwarding class when verifying DSCP classification based on single and multiple code-points. PR1611623

  • Incompatible or unsupported configuration is not getting validated correctly during ISSU or normal upgrade causing the traffic loss. PR1692404

Intrusion Detection and Prevention (IDP)

  • Network outage caused during change in IDP policy. PR1705491


  • The address-book address-book name attach zone is unexpectedly removed when address-book entry is added or removed by J-Web. PR1712454

  • Exclude selected is unexpectedly enabled in security policy configuration. PR1735314

Layer 2 Ethernet Services

  • DHCPv6 client options missing in solicit messages if TLV's exceeds a certain length. PR1702831

Network Address Translation (NAT)

  • ICMP based traceroute is not showing any hops after SRX when SRX is configured with NAT64. PR1706541

  • Some sessions will not be deleted when the NAT rule is deleted from the system. PR1712738

Network Management and Monitoring

  • The source address on syslog at custom routing-instance not applied right after rebooting. PR1689661

Platform and Infrastructure

  • After RG0 failover, node priority are set to zero for node0 with relinquish monitoring failure. PR1670772

  • The vmcores can be seen on SRX5000 line when the fxp0 interface is configured under management-instance. PR1714002

Routing Policy and Firewall Filters

  • Packet drops are seen for SRX destined traffic with self-traffic-policy. PR1698021

  • Security policies go out of synchronize during ISSU. PR1698508

  • The flowd process stops when the security policy updated with changing IP address related to the FQDN. PR1713576

  • The NSD process stops when ISSU is performed on the cluster. PR1724777

  • Traffic impact is observed when the security policy is configured with a huge number of addresses and on addition or deletion of these policies. PR1725567

Routing Protocols

  • The traffic drops are seen for the static route after VRRP failover when VRRP VIP is set as next-hop for that static route. PR1687884

Unified Threat Management (UTM)

  • utmd core has seen at commit when *.* or *.*.* is configured at url-pattern. PR1715260

  • Memory leak is observed on all Junos SRX platforms with http-persist and http-reassembly configuration. PR1725359

User Interface and Configuration

  • The mustd process crash might be observed with persist-group-inheritance. PR1638847


  • Routes flapping when configuration changes are applied to custom routing instance. PR1654516

  • IKE cookies didn't change in rekey lifetime expire cases after manual failover. PR1690921

  • IPsec VPNs will disconnect after ISSU. PR1696102

  • Cold synchronize status of MNHA nodes may go into INCOMPLETE state after bootup. PR1710374

  • The iked process stops when VPN tunnels parameters are not matching. PR1716092

  • ISSU is aborted and flowd process pause is observed. PR1722122