Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

What's Changed

Learn about what changed in this release for SRX Series.

Class of Service

  • Configuring export profile parameters for dial-out telemetry traffic, such as 'dscp', 'forwarding-class', and 'payload-size', will now result in an error. Previously, these parameters were ignored because the telemetry traffic adhered to global configuration settings for host-bound traffic. This ensures clarity and prevents misconfiguration, aligning export profiles strictly with supported parameters.PR1818770

Content Security

  • Juniper NextGen Web filtering license warning enhancement (SRX Series and vSRX)—Starting in Junos OS Release 24.4R1, if you configure the Web Filtering type as juniper-enhanced or ng-juniper without a corresponding valid license, the system does not generate a warning message. You can confirm whether the Web Filtering is down due to a missing license using the show security utm web-filtering status comamnd.

    Earlier to this release, if you configure Web Filtering type as juniper-enhanced or ng-juniper without a valid license, the system generated a warning message.

    [See show security utm web-filtering status and Juniper NextGen Web Filtering Overview.]

EVPN

  • Option allow-transients is set by default for the EZ-LAG commit script—The EZ-LAG feature simplifies setting up EVPN multihoming configurations using a set of configuration statements and a commit script. The commit script applies transient configuration changes, which requires the allow-transients system commit scripts option to be set. Now the default system configuration sets the allow-transients option at the EZ-LAG commit script file level, removing the need to set this option manually. In earlier releases where this option isn't set by default, you must still configure the option explicitly either globally or only for the EZ-LAG commit script.

    [See Easy EVPN LAG Configuration Overview.]PR1842245

  • EVPN system log messages for CCC interface up and down events—Devices will now log EVPN and EVPN-VPWS interface up and down event messages for interfaces configured with circuit cross-connect (CCC) encapsulation types. You can look for error messages with message types EVPN_INTF_CCC_DOWN and EVPN_INTF_CCC_UP in the device system log file (/var/log/syslog).PR1822918

Flow-Based and Packet-Based Forwarding

  • IPv6 link-local source packets are dropped instead of forwarded—Packets with IPv6 link-local source addresses destined to non-link-local addresses are now dropped by the router. Previously, such packets could be forwarded, which is not compliant with RFC 4291. This change ensures standards-compliant behavior and prevents forwarding of packets with link-local scope beyond the local link.PR1839089

General Routing

  • In a firewall filter configured with a port-mirror-instance or port-mirror action, if l2-mirror action is also configured, then port-mirroring instance family should be any. In the absence of the l2-mirror action, port-mirroring instance family should be the firewall filter family.PR1818423

  • Deprecation of jnxLEDTable—The jnxLEDTable table is no longer supportedPR1848057

  • A new counter "Sessions hit due to high rate" is added to "show services service-sets screen-session-limit-counters" command for all subscriber traffic. This counter tracks the sessions that come up on the screen irrespective of the "alarm-without-drop" configuration. When "alarm-without-drop" option is disabled, all the counters display updated statistics. When "alarm-without-drop" is enabled, then: - The screen-drop counters on "show services service-sets statistic screen-drop" command do not increase. - The "sessions hit due to high rate" value is displayed.

    [See alarm-without-drop (IDS Screen Next Gen Services), show services service-sets statistic screen-drops (Next Gen Services), and show services service-sets statistic screen-session-limit-counters (Next Gen Services).]PR1849594

Interfaces and Chassis

  • Support added for interface-group match condition for MPLS firewall filter family. PR1818968

  • Autonegotiation in xe ports (SRX380)—Starting in Junos Release 24.2R2, autonegotiation is disabled by default on all the four xe ports of SRX380 Firewalls. It is recommended to disable the autonegotiation at the remote end devices. To change the autonegotiation default recommended behavior, use the set interfaces xe-x/y/z gigether-options auto-negotiation command.

  • Support for 4x10G uplink module—You can use the 4x10G uplink module to support both 10G and 1G transceivers and interfaces. The device automatically detects the presence of a 10G or 1G transceiver and creates a physical interface of the corresponding speed. [See Port Speed on EX4400 Switches.]PR1865200

Junos XML API and Scripting

  • Commit script input to identify software upgrades during boot time (ACX Series, EX Series, MX Series, QFX Series, SRX Series, and vSRX)—The junos-context node-set includes the sw-upgrade-in-progress tag. Commit scripts can test the sw-upgrade-in-progress tag value to determine if the commit is taking place during boot time and a software upgrade is in progress. The tag value is yes if the commit takes place during the first reboot after a software upgrade, software downgrade, or rollback. The tag value is no if the device is booting normally.

    [See Global Parameters and Variables in Junos OS Automation Scripts.]

Licensing

  • Field name update in the CLI output (Junos)—Starting in this release, the show system license command output field name changed from "invalid" to "license not installed". PR1812126

Network Address Translation (NAT)

  • On the NFX and SRX series platforms, a peer device behind a NAT device may experience communication failure over the IPsec tunnel. This occurs if the NAT port number or IP address changes and the DPD 'always-send' is configured, causing the next DPD or rekey process to fail to update the port number in the existing tunnel NAT-T flow session. As a workaround, use the CLI, set security ike gateway gateway-name dead-peer-detection optimized.PR1862835

  • Optimized dead peer detection for NAT-T (SRX Series Firewall and NFX Series)—When the NAT-T remote port changes, incoming Dead Peer Detection (DPD) from the peer device may create a new session, leading to session mismatches and traffic interruptions. To prevent this, you can enable optimized dead peer detection. Use the command set security ike gateway gateway-name dead-peer-detection optimized to ensure that any new session created during incoming DPD expires, and the existing tunnel NAT-T session is updated with the new port number, allowing traffic to resume.

    [See Understanding NAT-T.]PR1863648

Network Management and Monitoring

  • DES deprecation for SNMPv3 (Junos)—The Data Encryption Standard (DES) privacy protocol for SNMPv3 is deprecated due to weak security and vulnerability to cryptographic attacks. For enhanced security, configure the triple Data Encryption Standard (3DES) or the Advanced Encryption Standard (CFB128-AES-128 Privacy Protocol) as the encryption algorithm for SNMPv3 users.

    [See privacy-3des and privacy-aes128.]

PKI

  • Enhancement to fix output with Junos PyEz for duplicate keys in PKI (MX Series, SRX Series, EX Series)—In earlier releases, though the CLI output displayed all the duplicate keys for the corresponding hash algorithms in PKI using show security pki local-certificate detail | display json command, for the same requested data, Junos PyEz displayed the last key only. Starting this release, the CLI output and the PyEz displays all the duplicate keys with the enhanced tags.

Routing Protocols

  • iBGP RR Update for Link Bandwidth Aggregation—In iBGP Route Reflector (RR) deployments, aggregation policies may advertise BGP Link Bandwidth (LBW) values that differ from the arithmetic sum of LBWs that multiple Provider Edges (PEs) provide. The update clarifies and enforces correct LBW calculation on RRs because the RRs recompute bandwidth locally instead of summing it cumulatively. Users might observe changes in the LBW values that RRs advertise, which can influence traffic-engineering behavior.PR1806864

  • Update to IGMP snooping membership command options—The instance option is now visible when issuing the show igmp snooping membership ? command. Earlier, the instance option was available but not visible when ? was issued to view all possible completions for the show igmp snooping membership command.

    [See show igmp snooping membership.]PR1810650

  • IS-IS minimum SPF holdown time—We have reduced the minimum value for configuring holddown times in the IS-IS Shortest Path First (SPF) algorithm. You can now set the holddown time to a minimum of 1 second (1000 milliseconds).

    [See spf-options (Protocols IS-IS).]PR1812701

  • Support for RFC 8950 compliant next hop encoding (Junos OS)—Enables advertising IPv4 and VPN IPv4 NLRI with IPv6 next hops over IPv6 BGP sessions. This capability aligns with extended next-hop encoding standards and improves interoperability across multi-vendor environments. The configuration is now visible and fully user configurable, ensuring standards-based behavior for IPv4 NLRI over IPv6 next hops.

    [See Supported Standards for BGP.]PR1814314

  • Display Issue in IS-IS Protocol (Junos OS)—A display issue has been identified in the IS-IS protocol where the ISO address is not picked up properly, and the system identifier (system ID) does not show the correct value when loopback interfaces per routing instance are configured. This issue affects all platforms supporting the IS-IS protocol. You notice that the system ID value in the show isis overview command output reflects the system ID of the primary instance's loopback interface for all routing instances, rather than the locally configured ISO addresses for each routing instance. Despite this display inaccuracy, the actual system IDs utilized by the IS-IS protocol remain correct and can be verified through the show isis hostname command or by inspecting IS-IS packets.

    [See Configuring an ISO System Identifier for the Router.]PR1816371

  • Configure IGMP snooping traceoptions (ACX Series, EX Series, QFX Series, and SRX Series)—Global traceoptions for IGMP snooping are disabled. Enable IGMP snooping traceoptions either for a specific vlan by configuring edit protocols igmp-snooping vlan v100 traceoptions file igmp_snooping.log or for all vlans with the configuration statement edit protocols igmp-snooping vlan all traceoptions file igmp_snooping_all_vlans.log.

    [See Configuration of IGMP snooping traceoptions on L2NG platforms.]PR1820227

  • Display Alignment Update for show isis database extensive—We have improved the display alignment in the output of the "show isis database extensive" command. Application-specific text is now presented after legacy information and without misalignment in traffic engineering metrics when the L-Flag is set, enhancing data readability and usability.PR1822385

  • IS-IS Routing Table Display Change—When you filter routes using the show isis route or show isis route flex-algorithm-id id command with the destination prefix, all the route types for that destination prefix are displayed.PR1828221

  • Upgrade limit-bandwidth from 32-bit to 64-bit for Extended Bandwidth Support (All platforms)—The limit-bandwidth action in routing policy statements currently supports a maximum value of 4.2 G because it uses a 32-bit field. Update the implementation with a 64-bit (uint64) field to allow higher bandwidth advertisements.PR1829950

  • RTC Route Display Fixed (Junos OS and Junos OS Evolved)—The latest update corrects the display issue for RTC routes associated with transport targets in BGP show command output. Earlier versions failed to format (pretty-print) those routes correctly in the show route and show route table bgp.rtarget.0 protocol rtarget outputs, leading to readability problems. This enhancement now presents RTC routes in a clear format, making routing table inspections and troubleshooting more efficient.PR1839269

  • Extension of traceoptions support for VLANs in IGMP/MLD snooping—The traceoptions option is supported under the [edit routing-instance protocols igmp-snooping vlan] and [edit routing-instance protocols mld-snooping vlan] hierarchy. traceoptions can be enabled for both specific and all vlans.

    [See vlan (IGMP Snooping) and vlan (MLD Snooping).]PR1845242

  • Peer Auto-Discovery Configuration Validation—A new commit-time validation check has been introduced for BGP peer auto-discovery configurations. This check ensures that required address parameters remain correctly configured when modifying BGP groups that use peer auto-discovery, preventing invalid configurations that could lead to unexpected behavior. Specifically, when peer auto-discovery is enabled, either extended-nexthop or local-ipv4-address must be configured to ensure correct next-hop advertisement in BGP updates carrying IPv4 prefixes sent by dynamically discovered peers. The validation prevents the removal of the extended-nexthop statement unless local-ipv4-address is explicitly configured. If neither option is present, the commit is rejected. This enhancement improves the robustness of BGP auto-discovery peering setups by detecting invalid configurations at commit time, reducing the risk of operational issues and improving overall system stability during configuration changes.PR1850469

  • BGP Task Progress Monitoring—The show task jobs extensive command now displays progress for BGP-specific jobs including BGP init policy walk, BGP group join, BGP Peer Reconfig, New policy flash update, and BGP RIB reconfig. This provides network administrators with detailed visibility into BGP task completion status, improving operational transparency and diagnostics.PR1857368

Unified Threat Management (UTM)

  • Juniper NextGen Web filtering license warning enhancement (SRX Series and vSRX)]—Starting in Junos OS Release 24.4R1, if you configure the Web Filtering type as juniper-enhanced or ng-juniper without a corresponding valid license, the system does not generate a warning message. You can confirm whether the Web Filtering is down due to a missing license using the show security utm web-filtering status command.

    Earlier to this release, if you configure Web Filtering type as juniper-enhanced or ng-juniper without a valid license, the system generated a warning message.

    [See show security utm web-filtering status and Juniper NextGen Web Filtering Overview.]PR1825483

  • Sophos antivirus configuration for ISSU (SRX Series)]—To use the Sophos antivirus while performing an in-service software upgrade (ISSU), remove the following configuration options.

    • edit security utm default-configuration anti-virus forwarding-mode holdset

    • edit security utm default-configuration anti-virus forwarding-mode inline-tap

    This caution applies only to ISSU upgrades and not to standalone upgrades. Once you complete the ISSU, you can re-enable the above configurations. The Sophos antivirus feature perform as usual when both devices come up.

    [See Sophos Antivirus Configuration Overview.]PR1839461

User Interface and Configuration

  • Compact format deprecated for JSON-formatted state data (ACX Series, EX Series, MX Series, QFX Series, SRX Series, and vSRX)—We've removed the compact option at the [edit system export-format state-data json] hierarchy level because Junos devices no longer support emitting JSON-formatted state data in compact format.

  • Access privileges for request support information command (ACX Series, EX Series, MX Series, PTX Series, QFX Series, SRX Series Firewalls, and vSRX Virtual Firewall)—The request support information command is designed to generate system information for troubleshooting and debugging purposes. Users with the specific access privileges maintenance, view, and view-configuration can execute request support information command.

  • Changes to the show system information and show version command output (ACX Series, EX Series, MX Series, QFX Series, SRX Series, and vSRX)—The show system information command output lists the Hostname field first instead of last. The show version command output includes the Family field. The Family field identifies the device family under which the device is categorized, for example, junos, junos-es, junos-ex, or junos-qfx.

    [See show system information and show version.]

  • Change to the commit process—In prior Junos OS releases, if you use the commit prepare command and modify the configuration before activating the configuration using the commit activate command, the prepared commit cache becomes invalid due to the interim configuration change. As a result, you cannot perform a regular commit operation using the commit command. The CLI shows an error message: 'error: Commit activation is pending, either activate or clear commit prepare'. If you now try running the commit activate command, the CLI shows an error message: 'error: Prepared commit cache invalid, failed to activate'. You then must clear the prepared configuration using the clear system commit prepared command before performing a regular commit operation. From this Junos and Junos OS Evolved release, when you modify a device configuration after 'commit prepare' and then issue a 'commit', the OS detects that the prepared cache is invalid and automatically clears the prepared cache before proceeding with regular 'commit' operation.

    [See Commit Preparation and Activation Overview, commit prepare, and commit activate.PR1806197

  • Encrypted Boot Halt When grub-startup.cfg Is Deleted - Fix Adds Missing /soft Golden File to Restore Automatic Recovery (Junos OS)—Deleting grub-startup.cfg when file-system encryption is enabled can cause the device to stop at the GRUB prompt. During encrypted boot, GRUB cannot access the required golden file under /soft, so it is unable to regenerate the missing boot configuration. In this condition, manual recovery is required by running insmod reboot followed by reboot. This forces the system to boot from the secondary disk. However, the primary boot entry does not reappear automatically, so normal self-recovery does not occur. This software release adds the missing golden file under /soft, allowing GRUB to correctly rebuild grub-startup.cfg even when encryption is enabled. After upgrading, automatic recovery of the primary boot entry is restored, and no user action is required.PR1843118

  • Local Commit Without Peer Synchronization (Junos OS)—We've introduced a new configuration option commit no-peers-synchronize. This option allows you to execute configuration commits locally without synchronizing the changes with peer routers, even if the system is configured to synchronize commits by default. This feature enables greater control and flexibility in making local configuration changes without affecting peer router configurations.

    [See commit.]PR1825074

VPN

  • Compliance check is added for Juniper Secure Connect (SRX Series and vSRX 3.0)—In Junos OS, we have added a compliance check to enforce that only Juniper Secure Connect clients can establish remote access VPN connections, and to reject connection requests from non-compliant remote access clients. You'll notice this behavior for the VPN connection using the remote access profile attached to the IPsec VPN object.

  • Changes to syslog messages for IPsec VPN service (SRX Series and vSRX 3.0)—We've made changes to the syslog messages for the IPsec VPN service. You'll notice that: Tunnel-id field is added to the KMD_PM_SA_ESTABLISHED syslog messages when running IPsec VPN service using the kmd process. - New syslog message IKE_VPN_SA_ESTABLISHED is added for an IPsec rekey event when running IPsec VPN service using the iked process.

  • Changes to the lifetime-kilobytes option in IPsec VPN Security Association (SRX Series Firewalls, and vSRX 3.0)—The minimum allowed IPsec proposal lifetime-kilobytes value is changed from 64KB to 64000KB for IPsec VPN Security Association.

    [See proposal (Security IPsec).]

  • Support for iPadOS for prelogon compliance checks in Juniper Secure Connect (SRX Series and vSRX3.0)—You can configure prelogon compliance checks on your firewall to allow or reject endpoints running iPadOS. Use the ipados option at the [edit security remote-access compliance pre-logon name term name match platform] hierarchy level to enforce these checks. This ensures that only compliant iPadOS devices are permitted access, enhancing the security of your network.

    [See compliance (Juniper Secure Connect).]

  • Invalid CLI command removal for IPsec VPN with iked process (SRX Series and vSRX 3.0)—When running IPsec VPN services using the iked process, your firewall no longer displays the unsupported Junos OS CLI command clear security ike respond-bad-spi-count. This update prevents invalid command displays for the unrecognized CLIs. You can continue to use the command with the kmd process.

    [See clear security ike respond-bad-spi-count.]