Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Troubleshoot Disconnected SRX Series Firewalls

Troubleshoot disconnected SRX Series Firewalls and get packet captures (PCAPs) for additional insights.

Troubleshoot SRX Series Firewalls Shown as Disconnected

If the Juniper Mist™ portal shows a Juniper Networks® SRX Series Firewall as disconnected when it is online and reachable locally, you can troubleshoot the issue using the steps listed in this topic. You need console access or SSH access to the firewall to perform the troubleshooting steps.

  1. Check if the SRX Series Firewall is running on the supported Junos OS version.

    For WAN Assurance, you need Junos OS version 19.4 and later for SRX300, SRX320, SRX340, SRX345, SRX380, SRX550M, and SRX1500. For the SRX1600, SRX2300, and SRX4300, devices must run Junos OS Release 24.2R1.17 and later. For the SRX4120 and SRX4700, you need Junos OS version of 24.4R1-S2 or later.

    You can use the show version CLI command to check the version.

  2. Check if the SRX Series Firewall has a valid IP address.

    Use the show interfaces terse command.

    You should see the integrated routing and bridging (IRB) interface (irb.0) with an IP address. You might see multiple IRB interfaces, depending on the SRX Series model (or in the case of a chassis cluster high availability configuration).

    At least one IRB interface needs to have a valid IP address. The Firewall can also connect using a management IP address, which you can see on the fxp0 interface.

    Ensure that:

    • Either the IRB or fxp0 interface has a valid IP address.

    • The Admin and Link states are up.

  3. Ensure that the firewall can reach the gateway as shown in the following sample.
  4. Check if your device can reach the Internet. Initiate a ping test toward any public server (for example, 8.8.8.8).
  5. Check if the firewall can resolve oc-term.mistsys.net.

    If the firewall is note resolving oc-term.mistsys.net, make sure that the firewall has a DNS server configured.

    If the firewall doesn't have a DNS server, configure the server as shown in the following example:
  6. Ensure firewall ports are open (for example: tcp port 2200 for oc-term.mistsys.net).

    See the following table to determine which port to enable, depending on your cloud environment:

    Table 1: Ports to Enable in Different Juniper Mist Clouds
    Service Type Global 01 Global 02 Europe 01
    SRX Series redirect.juniper.net (TCP 443) redirect.juniper.net (TCP 443) redirect.juniper.net (TCP 443)
    ztp.mist.com (TCP 443) ztp.gc1.mist.com (TCP 443) ztp.eu.mist.com (TCP 443)
    oc-term.mistsys.net (TCP 2200) oc-term.gc1.mist.com (TCP 2200) oc-term.eu.mist.com (TCP 2200)

    You can check the connections using the following command:

  7. Check the system time on the firewall to make sure the time is correct.

    If the system time is not correct, configure it. For more information, see Configure Date and Time Locally.

  8. Check device-id to make sure it is in the format <org_id>.<mac_addr>, as shown below:

    See outbound-ssh for more information.

    You can also examine the log messages by using the command show log messages.

  9. Deactivate and then reactivate the outbound SSH, as shown below:
    • To deactivate:
    • To reactivate:
  10. If you are adding the SRX device for the first time, do the following:
    • Delete the present Juniper Mist configuration from the firewall using the delete command.
    • Onboard the firewall again. For details on getting your SRX Series Firewall up and running in the Mist cloud, see Cloud-Ready SRX Firewalls .
    • Verify system service outbound-ssh and system connections using the following commands:
      • show system services outbound-ssh
      • show system connections | grep 2200