Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

New Features

Deployment

  • Minimal resource settings for Juniper Security Director VM—You can now use minimal resource settings when you deploy the Juniper Security Director VM to reduce overhead. Existing users must redeploy their VMs to apply minimal resource settings.

    [See Juniper Security Director System Requirements for KVM, Juniper Security Director System Requirements for ESXi Server, and Juniper Security Director System Requirements for Microsoft Azure.]

  • Download software bundle over HTTP or HTTPS—Use the HTTP or HTTPS software bundle download option to deploy and upgrade your Juniper Security Director VM.

    [See Upgrade Juniper Security Director.]

  • Deploy Juniper Security Director VM using ARM template—Use the Azure Resource Manager (ARM) template to deploy your Juniper Security Director VM on Microsoft Azure.

    [See Deploy Juniper Security Director Using an ARM Template on Microsoft Azure.]

  • Deploy Juniper Security Director VM through Microsoft Azure Marketplace—You can now easily deploy a Juniper Security Director VM directly from the Azure Marketplace.

    For assistance with Azure Marketplace deployments, contact the HPE Networking SRX PLM team at net-srx-plm@hpe.com.

  • Tenant organization creation without SMTP—Juniper Security Director no longer requires SMTP configuration for tenant onboarding and user management. Now, users will not receive email notifications for credential creation. This feature enhancement impacts the following scenarios:

    • VM deployment—The system automatically creates a root-admin user during the deployment process. After the deployment is complete, sign in as root-admin using the password you set during organization creation.
    • Add users and reset passwords—Admin users can create users, reset passwords, but the system won't notify the users. You must manually and securely share the new credentials with the users.
    • Upgrade existing VMs—Existing tenants who upgrade their VMs to the latest release can continue using their current credentials. After upgrading to the latest release, set the root-admin password when prompted and securely share it.

    [See Log In to the Juniper Security Director Web UI, Add a User, and Reset User Password.]

  • KVM installer for non-Ubuntu Linux distributions—In addition to Ubuntu 22.04 LTS and Ubuntu 24.04 LTS, you can now use the KVM installer to deploy the Juniper Security Director VM on non-Ubuntu Linux guest operating systems. The latest supported distributions include:

    • Red Hat Enterprise Linux (RHEL)

    • Debian

    • Oracle Linux

    • Rocky Linux

    [See System Requirements for KVM.]

Inventory

  • Onboard and manage SRX400 and SRX440 Firewalls—You can now use Juniper Security Director to onboard and centrally manage SRX400 and SRX440 Firewalls. These AI-native next-generation firewalls run on Junos OS Evolved and combine routing and SD-WAN capabilities in compact, fanless devices.

    [See Add Devices and Juniper Security Director 26.2.1 Supported Firewalls.]

  • RMA device replacements—Use the Return Material Authorization (RMA) process to replace faulty devices. RMA process enables you to:

    • Mark devices for replacement.

    • Manage the device life cycle through RMA states.

    • Deploy the saved configuration from your old device to the replacement device to restore service and minimize downtime.

    You can place up to 10 standalone devices in the RMA state simultaneously.

    [See RMA Overview, Place Devices in RMA State, and Reactivate Replacement Device.]

  • Predefined MNHA configuration templates—You can now use predefined configuration templates for Multinode High Availability (MNHA) deployments. These ready-to-use templates let you configure MNHA without using the CLI. Deploy either one or both of the following configuration templates based on your requirements:

    • MNHA-STATELESS-ACTIVE-ACTIVE-ROUTING—Configure MNHA with services redundancy group (SRG) 0 in active-active stateless routing mode.

    • MNHA-ACTIVE-BACKUP-ALL-MODES—Configure MNHA with SRG 1 in active-backup mode for all deployment types (routing, switching, or hybrid) with the managed IPsec services.

    [See Configuration Templates Overview and Group and Ungroup MNHA Devices.]

  • Remote Console for SSH access—Use Remote Console to establish a SSH connection to an SRX Series Firewall from the Juniper Security Director portal. This capability enables you to securely access SRX Series Firewalls directly from the Juniper Security Director portal without switching tools. As a result, this capability reduces operational overhead and accelerates day-to-day tasks such as configuration updates, health checks, and troubleshooting. The centralized, on-demand SSH access improves productivity, shortens issue resolution time, and enhances overall device management efficiency.

    [See Access an SRX Device Using Remote Console.]

Security

  • Support for variable zones—Standardize Security Policy and Network Address Translation (NAT) rules across devices with different zones by using variable zones. You can define a variable zone with a default zone and device-specific zone mappings to create a single rule. During deployment, the system resolves each variable zone to the appropriate device-specific zone. This approach eliminates duplicate rules, streamlines policy maintenance, and reduces configuration errors, thereby ensuring consistent enforcement across your environment.

    [See Variable Zones Overview and Create Variable Zones.]

  • Per device default Content Security and IPS Profiles—You can now configure default profiles for Content Security and intrusion prevention system (IPS) at the individual device-level, in addition to the existing default profiles at the organization (global) level.

    This feature enables administrators to override the global defaults defined in Security Settings and apply more granular, device-level security controls.

    [See Security Setting Overview and Create and Manage Device-Specific Profiles.]

  • Security policy report—You can now export your active security policies into downloadable files. With this feature, you can easily review, archive, and share your security configurations for audits, compliance reviews, or offline analysis. The reports are available in two formats:

    • PDF—A human-readable, print-friendly document.

    • JSON file—A machine-readable compressed file containing security policies in JSON format.

    [See Export and Download a Security Policy.]

  • Security policy deployment options—You can now choose whether to deploy security policies to all devices or only to selected devices that require updates.

    [See Deploy Security Policies.]

  • Advanced filter options on the Security Policies page—You can now filter security policy rules by attributes such as Name, Action, Source Zone, Destination Zone, Applications, Services, and other security policy configuration attributes. These filters help you search, review, and audit large policy rule bases.

    [See Security Policy Rules Overview.]

  • Improved IPsec VPN deletion workflows—You can now delete an IPsec VPN either only from Juniper Security Director or from both Juniper Security Director and the managed devices, depending on the IPsec VPN state. This enhancement simplifies the removal of unused IPsec VPNs, supports reimporting IPsec VPNs after out-of-band device changes on devices, and provides better visibility into delete operations. IPsec VPNs can now be deleted directly using the Delete option, without requiring the deploy action or IPsec VPNs to be in the intermediate flagged for delete state.

    [See Create and Manage Policy-Based Site-to-Site VPN, and Import IPsec VPNs.]

  • Drag-and-drop action to reorder policy rules and copy and paste shared objects for firewall and NAT—You can drag and drop firewall and NAT policy rules and rule groups to reorder them in the GUI. With this feature, you can use auto-scrolling, multi-row moves, and clear drop targets for rule reordering, eliminating manual resequencing. You can copy shared objects—Addresses, Services, Applications, and URL Categories from the Copy-Paste Objects panel and paste them into rule cells to accelerate consistent policy authoring. These capabilities streamline building and maintaining large policies.

    [See Reorder a Security Policy Rule, Add and Manage Security Policy Rules, Configure a Security Policy Rule, Common Operations on a NAT Policy Rule and Create a NAT Policy Rule.]

API Reference

  • API reference link—A new API reference link is now available under the Help (?) menu in the Juniper Security Director. You can directly access the Security Director API portal enabling API‑based network automation and security operations.

    [See Juniper Security Director GUI Overview.]

  • Supported APIs—The following functional areas are now supported through APIs:

    • Device management including device discovery profiles.

    • Shared configuration objects

    • Firewall and NAT policies

    You can directly access the Security Director API portal under the Help (?) menu.