Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

July 14, 2026 Release

Juniper Security Director Cloud New Features: July 14, 2026

API Reference

  • API reference link—A new API reference link is available in the Help (?) menu included in the Juniper Security Director Cloud GUI. This link provides you quick access to the Security Director Cloud API documentation page to help you learn about API‑based network automation and security operations.

    [See Juniper Security Director Cloud GUI Overview.]

  • Supported APIs—The following functional areas are now supported through APIs:

    • Device management

    • Shared configuration objects

    • Firewall and NAT policies

    [See Security Director Cloud API Reference.]

Security

  • Support for variable zones—Standardize Security Policy and Network Address Translation (NAT) rules across devices with different zones by using variable zones. You can define a variable zone with a default zone and device-specific zone mappings to create a single rule. During deployment, the system resolves each variable zone to the appropriate device-specific zone. This approach eliminates duplicate rules, streamlines policy maintenance, and reduces configuration errors, thereby ensuring consistent enforcement across your environment.

    [See Variable Zones Overview and Create Variable Zones.]

  • Per device default Content Security and IPS Profiles—You can now configure default profiles for Content Security and intrusion prevention system (IPS) at the individual device-level, in addition to the existing default profiles at the organization (global) level.

    This feature enables administrators to override the global defaults defined in Security Settings and apply more granular, device-level security controls.

    [See Security Setting Overview and Create and Manage Device-Specific Profiles.]

  • Security policy report—You can now export your active security policies into downloadable files. With this feature, you can easily review, archive, and share your security configurations for audits, compliance reviews, or offline analysis. The reports are available in two formats:

    • PDF—A human-readable, print-friendly document.

    • JSON file—A machine-readable compressed file containing security policies in JSON format.

    [See Export and Download a Security Policy.]

  • Security policy deployment options—You can now choose whether to deploy security policies to all devices or only to selected devices that require updates.

    [See Deploy Security Policies.]

  • Advanced filter options on the Security Policies page—You can now filter security policy rules by attributes such as Name, Action, Source Zone, Destination Zone, Applications, Services, and other security policy configuration attributes. These filters help you search, review, and audit large policy rule bases.

    [See Security Policy Rules Overview.]

  • Improved IPsec VPN deletion workflows—You can now delete an IPsec VPN either only from Juniper Security Director Cloud or from both Juniper Security Director Cloud and the managed devices, depending on the IPsec VPN state. This enhancement simplifies the removal of unused IPsec VPNs, supports reimporting IPsec VPNs after out-of-band device changes on devices, and provides better visibility into delete operations. IPsec VPNs can now be deleted directly using the Delete option, without requiring the deploy action or IPsec VPNs to be in the intermediate flagged for delete state.

    [See Create and Manage Policy-Based Site-to-Site VPN, and Import IPsec VPNs.]

  • Drag-and-drop action to reorder policy rules and copy and paste shared objects for firewall and NAT—You can drag and drop firewall and NAT policy rules and rule groups to reorder them in the GUI. With this feature, you can use auto-scrolling, multi-row moves, and clear drop targets for rule reordering, eliminating manual resequencing. You can copy shared objects—Addresses, Services, Applications, and URL Categories from the Copy-Paste Objects panel and paste them into rule cells to accelerate consistent policy authoring. These capabilities streamline building and maintaining large policies.

    [See Reorder a Security Policy Rule, Add and Manage Security Policy Rules, Configure a Security Policy Rule, Common Operations on a NAT Policy Rule and Create a NAT Policy Rule.]

Inventory

  • Onboard and manage SRX400 and SRX440 Firewalls—You can now use Juniper Security Director Cloud to onboard and centrally manage SRX400 and SRX440 Firewalls. These AI-native next-generation firewalls run on Junos OS Evolved and combine routing and SD-WAN capabilities in compact, fanless devices.

    [See Add Devices to Juniper Security Director Cloud and Juniper Security Director Cloud Supported Firewalls.]

  • RMA device replacements—Use the Return Material Authorization (RMA) process to replace faulty devices. RMA process enables you to:

    • Mark devices for replacement.

    • Manage the device life cycle through RMA states.

    • Deploy the saved configuration from your old device to the replacement device to restore service and minimize downtime.

    You can place up to 10 standalone devices in the RMA state simultaneously.

    [See RMA Overview, Place Devices in RMA State, and Reactivate Replacement Device.]

  • Predefined MNHA configuration templates—You can now use predefined configuration templates for Multinode High Availability (MNHA) deployments. These ready-to-use templates let you configure MNHA without using the CLI. Deploy either one or both of the following configuration templates based on your requirements:

    • MNHA-STATELESS-ACTIVE-ACTIVE-ROUTING—Configure MNHA with services redundancy group (SRG) 0 in active-active stateless routing mode.

    • MNHA-ACTIVE-BACKUP-ALL-MODES—Configure MNHA with SRG 1 in active-backup mode for all deployment types (routing, switching, or hybrid) with the managed IPsec services.

    [See Configuration Templates Overview and Group and Ungroup MNHA Devices.]

  • Remote Console for SSH access—Use Remote Console to establish a SSH connection to an SRX Series Firewall from the Juniper Security Director Cloud portal. This capability enables you to securely access SRX Series Firewalls directly from the Juniper Security Director Cloud portal without switching tools. As a result, this capability reduces operational overhead and accelerates day-to-day tasks such as configuration updates, health checks, and troubleshooting. The centralized, on-demand SSH access improves productivity, shortens issue resolution time, and enhances overall device management efficiency.

    [See Access an SRX Device Using Remote Console.]

General

  • Security Director Copilot (Beta)—Meet our new Security Director Copilot, an AI-powered assistant built into the Juniper Security Director Cloud interface. Designed to help you work faster and smarter, Security Director Copilot empowers you to:

    • Ask questions using natural language and take actions instantly.

    • Simplify everyday tasks such as onboarding devices, configuring devices, and creating security policies with guided, easy-to-follow actions.

    • Access real-time threat insights with smart, contextual guidance.

    • Resume work seamlessly with saved chat history.

    Note:

    Security Director Copilot is powered by AI. AI-generated content might be incorrect. Verify the information before following any AI guidance.

    [See Security Director Copilot Overview (Beta).]

Admin

Subscription data refresh—You can now refresh your data on the Subscriptions page to get the latest data from the Juniper Agile Licensing (JAL) portal after you upgrade or change your subscriptions. This option is available only to users with paid subscriptions and permission to add and manage subscriptions.

[See Add and Manage Subscriptions.]

Juniper Security Director Cloud Bug Fixes: July 14, 2026

  • Missing text on ATP enrollment page—The Advanced Threat Prevention (ATP) device enrollment and disenrollment pages displayed placeholder text for UI titles. This issue is now resolved.

  • Device synchronization failure after restoring a database backup—In rare cases, restoring a database backup to a newly deployed system using the same management IP address and hostname (FQDN) as the original instance caused device configurations to fail resynchronizing automatically. This issue is now resolved.

  • Subscription not displayed when managing device licenses—Subscription licenses were not displayed when you select a device and click Manage Subscription under Inventory > Devices. This is because, Juniper Security Director licenses could be incorrectly activated and added as cloud subscriptions. This issue is now resolved.

  • Security policy deployment fails due to stale rule metadata—Security policy deployment might fail with an “application or application-set not found” error due to outdated rule metadata after modifying a rule’s zone pair. This caused mismatched configurations. This issue is now resolved.

  • Firewall rule analysis incorrectly mark rules as unused in multi-device policies—Firewall rule analysis might incorrectly mark a rule as unused if any device in a multi-device policy had no hits, ignoring activity on other devices. Organization-level thresholds were also applied incorrectly. This issue is now resolved. Rule analysis now considers hit activity across all devices and marks rules as unused only when no hits occur within the defined threshold period.

  • Resolve device configuration hangs on SRX Series Firewalls—Previously, the resolve device configuration operation on SRX Series Firewalls could hang in a loading state and fail to process changes or report errors. This is because of the parsing issues when response data was received in separate chunks. This issue is resolved now.