What's Changed
Learn about what changed in this release for SRX Series.
General Routing
-
A new counter "Sessions hit due to high rate" is added to
show services service-sets screen-session-limit-counterscommand for all subscriber traffic. This counter tracks the sessions that come up on the screen irrespective of thealarm-without-dropconfiguration. Whenalarm-without-dropoption is disabled, all the counters display updated statistics. When "alarm-without-drop" is enabled, then, the screen-drop counters onshow services service-sets statistic screen-dropcommand do not increase. As a result, the "sessions hit due to high rate" value is displayed.[See alarm-without-drop (IDS Screen Next Gen Services), show services service-sets statistic screen-drops (Next Gen Services), and show services service-sets statistic screen-drops (Next Gen Services).]PR1849594
-
Certificate enrollment system logs (Junos)—We've added system logs to notify if there is an SCEP and CMPv2 certificate failure. On SCEP certificate enrollment failure, you can see the PKID_SCEP_EE_CERT_ENROLL_FAIL message. On CMPv2 certificate enrollment failure, you can see the PKID_CMPV2_EE_CERT_ENROLL_FAIL message. [See System Log Explorer.]PR1853769
-
Support for 4x10G uplink module—You can use the 4x10G uplink module to support both 10G and 1G transceivers and interfaces. The device automatically detects the presence of a 10G or 1G transceiver and creates a physical interface of the corresponding speed. [See Port Speed on EX4400 Switches.]PR1865200
-
When you run the
request vmhost zeroizecommand to zeroize a single Routing Engine on a dual Routing Engine device, the CLI incorrectly displays a message indicating that it will zeroize both Routing Engines.PR1869854 -
G.8275.1 profile configuration with PTP, SyncE, and hybrid mode (Junos)—On all Junos platforms, when configuring the G.8275.1 profile, it is mandatory to configure Precision Time Protocol (PTP), Synchronous Ethernet (SyncE), and hybrid mode. Earlier, the system would not raise a commit error even if the required hybrid and SyncE configurations were missing while configuring G.8275.1 profile. However, going forward you will not be able to configure the G.8275.1 profile without configuring PTP, SyncE and hybrid mode to be compliant with the ITU-T standards.
-
The "Assertion atributes missing" is corrected to "Assertion attributes missing" field, displayed in
show network-access aaa statistics samlcommand output.PR1878686 -
Configuration Limits for SSL Proxy Profiles—We've updated the limits for Trusted CA certificates, Server certificates, and URL categories in both SSL forward proxy and SSL reverse proxy configurations. These changes ensure compliance with the maximum configuration blob size limit of 56,986 bytes.
Changes in Limit Size:
- Trusted CA certificate/Server certificates: Maximum limit?400 (reduced from 1024)
- URL categories: Maximum limit?800 (unchanged)
Configuration Statements:
user@host# set services ssl proxy profile profile-name trusted-ca (all | [ca-profile] ) user@host# set services ssl proxy profile profile-name server-certificate user@host# set services ssl proxy profile profile-name whitelist-url-categories [whitelist url categories]Note: In the reverse proxy configuration, ensure combined size of server certificates and URL categories does not exceed 56,986 bytes. If the combined size exceeds the limit, the following error message is displayed during commit: This error provides a breakdown of memory usage, helping you adjust the configuration accordingly.ERROR: Maximum blob size (56986 bytes) exceeded...current blob size is 57014 bytes. 400 Server certs are taking 54400 bytes, and 27 URL categories are taking 1728 bytes.
[See [Configuring SSL Proxy.]PR1883249
-
Captive Portal Web Login Page (SRX Series)—Firewall users must keep the captive portal web login page open after they successfully authenticate. The system automatically logs the user out of the captive portal when the login page is closed.
[See Captive Portal Authentication and Configure a Custom Logo and Banner Messages.]PR1883454
-
ARP restriction for VLAN IDs 3072 to 4094 (SRX4700)—You cannot configure VLAN IDs ranging from 3072 to 4094. This ensures correct network behavior and prevents potential conflicts within these VLAN ranges, promoting network stability and reliability.PR1884412
-
log-tag functionality—The log-tag functionality is introduced in
set services service-set. PR1885614 -
You can now enable zeroization on a vSRX 3.0 Virtual Firewall using CLI to destroy Critical Security Parameters (CSPs). Run the request system zeroize command to zeroize the system configuration and keys. When you run this command all the configuration information is removed, and the key values are reset and the vSRX 3.0 firewall is reverted to factory defaults after reboot. PR1887312
-
New option for debug collector data storage path—We've included the option
outdirto specify an output directory for storing debug collector data in a customised path. This allows you to organise and access diagnostic information more efficiently, adapting storage to your specific requirements.[See request system debug-info.]
-
IPv6 DNS resolution option in security log stream configuration (SRX Series Firewalls and vSRX3.0)—You can enable the
prefer-ipv6-dnsoption under theshow security log stream s1 hostconfiguration hierarchy to prioritize IPv6 address resolution for DNS queries. This option ensures that IPv6 addresses are used instead of the default IPv4 addresses. This configuration enhances IPv6 network compatibility and supports environments that require IPv6 addressing. PR1898261
Intrusion Detection and Prevention (IDP)
-
Improved Handling of IDP Policy Compilation Status (SRX Series)—Previously, if an IDP policy compilation failed and a subsequent commit did not involve IDP changes, the compilation status could be lost or appear blank. This has been resolved--the system now retains and displays the last known policy compilation status, even when later commits do not trigger policy recompilation or when the policy is unloaded due to configuration changes. There is no change in the underlying IDP functionality, only in how the status message is preserved.PR1881146
J-Web
-
You can upgrade the zone-based address book to global address books in Global Addresses page. To do this, click Upgrade in the right-side corner of the Global Addresses table. Then, click Yes to continue with the upgrade and click OK to complete. During the upgrade, the system appends the zone name to the zone address name.PR1872686
Network Management and Monitoring
-
Shell Command Logging Enhancement—All shell commands executed on the device and root sessions are now logged by default. This enhancement ensures enhanced security and auditability by capturing all commands entered in any shell environment, preventing bypassing audit logging.PR1867216
-
Deprecation of shell option—The shell option no longer requires a separate configuration and is now the default behavior. Deprecating the shell option enhances efficiency and simplifies management tasks.PR1892385
Routing Policy and Firewall Filters
-
IPv6 address range support in address book configuration—You can configure IPv6 address ranges within the address book, enabling more flexible network management. With this feature IPv6 range configurations can be split into multiple prefixes. You must handle this feature carefully as it transforms ranges into multiple prefixes.PR1896637
Routing Protocols
-
SNMP Trap Behavior Honors Logical-System Hierarchy (Junos OS)—The
snmp-options backward-traps-only-from-establishedconfiguration now correctly applies when set under a logical system. In earlier releases, the setting needed acommit fullor a corresponding global configuration to take effect. Logical-system-specific values are activated with a standardcommitand don't depend on global scope.PR1837269 -
Peer Auto-Discovery Configuration Validation—A new commit-time validation check has been introduced for BGP peer auto-discovery configurations. This check ensures that required address parameters remain correctly configured when modifying BGP groups that use peer auto-discovery, preventing invalid configurations that could lead to unexpected behavior. Specifically, when peer auto-discovery is enabled, either extended-nexthop or local-ipv4-address must be configured to ensure correct next-hop advertisement in BGP updates carrying IPv4 prefixes sent by dynamically discovered peers. The validation prevents the removal of the extended-nexthop statement unless local-ipv4-address is explicitly configured. If neither option is present, the commit is rejected. This enhancement improves the robustness of BGP auto-discovery peering setups by detecting invalid configurations at commit time, reducing the risk of operational issues and improving overall system stability during configuration changes.PR1850469
-
Holddown Route definition—A holddown route is redefined as a Route that is in pending delete state because a protocol has an existing interest bit set on it.
[See show route.]PR1853954
-
Modification of SRTE Advertisement Policy Name Display—BGP will now not generate and not display the "Advertised Policy Name" field for BGP-SRTE routes in show command output when the "Name TLV" is not received in the tunnel encapsulation attribute with the BGP-SRTE NLRI. The field will only be displayed when the "Name TLV" is received. This update eliminates ambiguity by ensuring multiple NLRIs do not display the same policy name, providing clearer and more accurate route information in command outputs.PR1853958
Subscriber Access Management
-
Addition of
message-authenticatorandno-message-authenticatorattributes underaccess radius-server,access profile radius-server, andsystem radius-serverhierarchies—Setmessage-authenticatorif you require the RADIUS server to include the Message Authenticator attribute in replies to Access-Request messages. Setno-message-authenticatorto not require that attribute.PR1871147
User Interface and Configuration
-
Updated Annotate Command Behavior—The annotate command now correctly handles multi-line comments that start with `#`. This change ensures that all lines of a multi-line comment remain comments, preventing unauthorized configuration changes when the configuration is committed, reloaded, or rollbacked. These improvements enhance security by mitigating potential privilege escalation attacks from users with limited configuration editing permissions.PR1868636
-
Changes to the
show system storagecommand output (ACX Series, EX Series, MX Series, PTX Series, QFX Series, and SRX Series)—We've updated theshow system storagecommand output to include only true (physical) storage and exclude any host/hypervisor level storage. In earlier releases, the output also includes a container/jail storage, which does not have a separate storage of its own.[See show system storage.]PR1875391
-
Enhanced Permission Checks for Rename/Copy Operations—New permission checks have been introduced for rename and copy operations within the configuration hierarchy. These checks parse the hierarchy being modified to ensure the user has the required permissions for the hierarchy and its sub-hierarchies. If permissions are insufficient, the operation will fail and a "Permission denied" error will be displayed. This enhancement ensures that configuration modifications are performed only by authorised users, improving security and preventing unintended changes to critical system settings.PR1882303
-
Stale ui-state.db data in persistent NETCONF sessions post-mgd restart—Existing NETCONF sessions might fetch stale data from ui-state.db after mgd -N restart. New sessions correctly map the refreshed database. Scripts must establish new sessions post-restart to access updated values. Functional configuration remains unaffected. [Script failures monitoring "local-host" NETCONF sessions]—Scripts might fail when including "local-host" NETCONF sessions in monitoring operations. Internal sessions are now excluded from tracking. Scripts must filter out "local-host" sessions. No impact to internal application functionality.PR1888557
VPNs
-
Support for hmac-sha-384/512 authentication in PMI (SRX Series Firewalls and vSRX 3.0)?You can configure hmac-sha-384 and hmac-sha-512 authentication algorithms with PowerMode IPsec (PMI) when running IPsec VPN with the iked process.
[See PowerMode IPsec.]PR1891750