Resolved Issues
Learn about the issues fixed in this release for vSRX.
For the most complete and latest information about known Junos OS defects, use the Juniper Networks online Junos Problem Report Search application.
Content Security
-
Change in content-filter return codes when action is block and notification is protocol-only. PR1845496
General Routing
-
RTO traffic loss and accumulation of session on secondary node is observed when RTO traffic not evenly distributed to all FLT threads. PR1819911
-
Dedicated-offload-cpu requires a full restart of vSRX 3.0 in Junos OS Release 24.4R1. PR1842550
-
Auto-re-enrollment for local certificate once fail, not trigger again. PR1845573
-
vSRX 3.0 kernel panic when deployed in Qemu version 8.1 and above. PR1845886
-
Intermittent traffic drops are seen due to large memory allocation for unidentified files. PR1851786
-
PIM IP ESP packet fragments are dropped. PR1854130
-
Split brain scenario is observed on vSRX 3.0 with public cloud MNHA deployment. PR1855010
-
Missing vCPU after downgrading from Junos OS release 25.2 to lower versions. PR1871397
-
The srxpfe process stops responding on vSRX platform after set disables on the ge- interface and then rollback. PR1874848
-
On vSRX 3.0 platforms, MNHA link fails to come up when MNHA ICL tunnel is enabled alongside dedicated-offload-cpu. PR1875491
Flow-Based and Packet-Based Processing
-
In vSRX orphan backup sessions will exhaust session resources due to high backup session timeout value. PR1846897
-
Type 5 VXLAN traffic drops are observed when SRX Series Firewall run as L3-VNI gateway and the ingress and egress traffic goes to the same Type-5 VXLAN peer. PR1847419
-
Data Plane CPU on one device spikes up to 95% during primary node system reboot in SRX cluster PR1856521
Network Address Translation (NAT)
-
New CLI for RSI updated to collect more NAT information. PR1825372
Platform and Infrastructure
-
FTP default mode changed from active to passive on Junos OS release 24.2R2. PR1874525
Routing Policy and Firewall Filters
VPNs
-
ICL connection getting established with wrong source interface IP when trying to establish ICL connection between pub-broker and sub-broker with loopback interface IP's. This resulting in IPsec session sync failure between master and backup MNHA devices. PR1840788
-
The show chassis high-availability information CLI says SRG1 control plane state as Ready ICL connection between Pub-Broker Sub-broker is not established properly and IPsec sessions are not synchronize between primary and standby MNHA peers. PR1840803
-
IPsec tunnel distribution table on the Routing Engine is not cleaned up hitting SRXPFE generates core files when DPD is configured. PR1850526
-
On vSRX 3.0 platforms IPsec tunnels do not redistributed with dedicated-offload-cpu knob enabled. PR1860693