ON THIS PAGE
Known Behaviors and Issues
Known Behaviors
This section lists the known behaviors in Juniper Security Director Release 26.2.1.
-
During KVM deployment of Juniper Security Director, when you select the disk provisioning type in the automation software (see Step 2: Deploy the VM , step 7 in Deploy Juniper Security Director Using KVM), you are prompted to choose between Thin or Thick provisioning for the QCOW2 disk files.
If the KVM host is running Proxmox VE with ZFS-backed storage (for example, local-zfs or rpool), selecting thick provisioning does not result in fully pre-allocated disks. The disks behave as thin-provisioned disk without any warning during deployment.
Workaround
Use a host with a non-ZFS storage back-end, such as ext4 or XFS, to ensure thick provisioning is applied correctly. Starting with Juniper Security Director 26.2.1 release, the KVM automation software supports Ubuntu 22.04 LTS and 24.04 LTS, as well as RHEL, Debian, Oracle Linux, and Rocky Linux. These versions use ext4 by default and fully support thick provisioning.
See Juniper Security Director System Requirements for KVM for the complete list of supported host operating systems.
-
The KVM automation software (.bin) requires an active libvirt process as a prerequisite for VM deployment in regular mode. Proxmox VE manages virtualization through its own stack built directly on QEMU/KVM and does not use libvirt. As a result, running the automation software in regular mode on a Proxmox VE host fails during the prerequisite checks with a libvirt process is not active error. Attempting to install libvirt on Proxmox VE is not supported and might conflict with the Proxmox virtualization stack.
Workaround
On Proxmox VE, use the --no-run mode to extract the deployment artifacts from the .bin file and then proceed with manual VM deployment using the native Proxmox tools.
Starting with Juniper Security Director 26.2.1 release, the KVM automation software supports Ubuntu 22.04 LTS and 24.04 LTS, as well as RHEL, Debian, Oracle Linux, and Rocky Linux. See Juniper Security Director System Requirements for KVM for the complete list of supported host operating systems and Deploy Juniper Security Director Using KVM for details on the deployment parameters.
-
SRX400 and SRX440 Firewalls running Junos OS Evolved 25.4X300-D10 do not support the following features:
-
IPv6
-
Multicast
-
EVPN-VXLAN
-
VPLS
-
DHCPv6
-
Traffic policing and shaping on AE interfaces
-
PoE (Power over Ethernet)
-
Layer 2 Next-Generation (L2NG)
-
MNHA: multiple Services Redundancy Groups (SRGs)
-
CoS on secure tunnel interface (st0) and Link Services Interfaces
-
VRRP
-
NAT with ND Proxy (IPv6)
-
Secure Wire (Layer 2 transparent mode)
-
-
While configuring MNHA templates for SRX400 and SRX440 firewalls, if the minimum interval for liveness detection between HA peers (Liveness min interval) is set below 1000 ms, the template validation fails.
Workaround
Ensure that the Liveness min interval value is set to 1000 ms or higher.
-
When retrieving a resource through the REST API, fields that are set to their default values are not included in the response. This is standard behavior across all REST API endpoints and applies to every resource type. The default values by data type are:
Data Type Value Boolean false Integer 0 String "" (empty) Array [] (empty) Object {} (empty) What this means:
-
GET responses: If a field is absent from the API response, it means the field is set to its default value.
-
POST/PUT requests: When creating or updating a resource, you can omit any field from the request payload if you intend to use its default value. The system will automatically apply the default.
For example, when creating a source NAT rule with persistent NAT enabled but Address Mapping left as disabled (default), the GET API response does not include the address_mapping field within the persistent_nat_settings object. This occurs because the value (false) matches the Boolean default and is therefore not explicitly returned.
-
-
After upgrading to 26.2.1, a one-time background migration runs to enable new Advanced Filter fields (Source Zone, Destination Zone, Source Address, Destination Address, Services, and Applications) on the SRX Security Policy rule page.
During migration:
- Policy management global search is temporarily unavailable.
- Advanced Filter fields are visible but might return empty results until migration completes.
Workaround
Retry the global-search-migration job:
- Go to .
- Select the global-search-migration job and click .
After the migration job is completed successfully, the advanced filter functionality is restored and operates normally. Contact JTAC if the issue persists.
-
If the SD device certificate deployment job fails during device onboarding, security log configuration might not be completed.
Workaround
Reconfigure the security log to trigger certificate installation and restore the logging configuration. For detailed instructions, see Configure Security Logs.
-
When you sign in with a custom role that includes only log access, the Monitor page displays only the Infected Hosts chart. This is expected because the infected host information is derived solely from logs—data that the role permits.
All other widgets on the Monitor page remain empty because they rely on additional data sources and permissions.
-
When you enable the database backup on the page, the following information is not included in the backup:
-
Logs
-
Generated reports
-
Global search results
-
Software images and packages uploaded from local drives
-
Historical device configurations
-
-
When you roll back a standalone device or a single node from an L2 cluster, the rollback job completes successfully. However, the landing page might not immediately show the updated OS version. The OS version remains unchanged until you manually resynchronize the device.
Workaround
Steps to manually resynchronize the device:
Select .
Select the device to resynchronize, and click .
A job is created for the resynchronization process and the details are displayed on the top of the page. Click to view the job.
-
After the Juniper Security Director upgrade:
-
The Insights and Dashboard pages display the top Screens data separately.
-
This view includes only data sent after the upgrade and does not show older data (sent before the upgrade) from the past month.
-
When you click Total Events on the Insights page, the All Security Events page might show a higher event count because it includes both older (before upgrade) and newer (after upgrade) Screens data.
-
-
After the Juniper Security Director upgrade:
-
The Insights and Dashboard pages display the top IDP data separately.
-
This view includes only data sent after the upgrade and does not show older data (sent before the upgrade) from the past month.
-
When you click Total Events on the Insights page, the All Security Events page might show a higher event count because it includes both older (before upgrade) and newer (after upgrade) IDP data.
-
-
You might see a tainted status for the Juniper Security Director VM after a reboot or power cycle. The tainted status does not indicate an error. The system logs the tainted status to indicate orchestration progress. Use the show health status command to view a summary of system progress.
-
Before restoring the database, if you've performed operations such as device discovery, uploading an image, or deleting an image, the resources for these operations might be out of sync with the restored database. This is because, the resources related to these operations are directly stored on to the file system.
-
For the SRX Series Firewalls that are auto-imported to Juniper Security Director, the default Content Security (also known as UTM) configuration on Juniper Security Director is preferred over the Content Security configuration that is imported from the device.
To prevent conflicts, perform the following steps:
After the devices are auto-imported, go to .
Review and modify the Content Security settings.
Go to , click .
Review and modify the default security configurations with system default profiles.
OR
Go to and disable Auto Import.
Manually import devices to Juniper Security Director.
For any conflicts, overwrite the Juniper Security Director settings with the default Content Security settings.
Note:The Content Security settings are global settings and must be configured after performing auto import or manual import to avoid any conflicts.
-
Juniper Security Director doesn't support legacy application security policies.
-
Juniper Security Director supports a global address book but it does not support a zone address book.
-
When you import a policy that has rules with unsupported configuration, Juniper Security Director shows information about these rules under Summary on the import wizard. After importing, these rules with unsupported configurations are grayed out and shown with a disabled icon to differentiate between system-disabled rules and a rule disabled by user. The Rule description also shows the reason for disabling these rules.
You cannot delete, edit, or perform any rule actions on these unsupported rules.
-
Juniper Security Director overwrites the user configuration performed directly from the device CLI or any other interface other than the portal.
To avoid conflicts, you can import the configurations and re-assign the devices from existing policies.
-
During backup and restore, customer-uploaded Juniper Security Director certificates are not restored from database backups. You’ll need to manually re-upload the certificates. See Update the Certificates for details.
-
When you view the data on the Dashboard and pages, you might face the following behaviors:
-
Some categories might not appear in the Sunburst chart if there is a large value gap between categories—for example, one category is 6000 and another is 5. This is expected behavior.
-
When you click the Total Events number in the grid table of the Insights pages, you might notice a discrepancy between the total events displayed there and those shown on the All Security Events page. This difference arises because the All Security Events page presents live data, whereas the Insights pages display aggregated data at discrete intervals.
-
When you view data in the charts for Infected Hosts and Top 5 URL Activity widgets that include timelines, the data might not be correctly sorted based on the selected timeline.
Workaround
Click any event in the Infected Hosts or Top 5 URL Activity widgets. You will be redirected to the All Security Events page, where you can view the specific event time details.
-
When you view data of the third-party DAG feeds on the SecIntel Feeds page, the data might not be complete because the third-party DAG feed might not be enabled even though the toggle switch is enabled.
-
When you failover an SRX Series Firewall, the data on the Insights page displays data for current active devices only. To view the logs, we recommend to choose both the devices of a cluster.
-
On the Insights page, the bubble chart does not appear for the Users, Events, Volume, or Sessions tabs when the selected metric has a value of zero. Since the bubble chart visualizes data based on nonzero values, no bubbles will be displayed.
-
When you click the number of Rules on the grid table of the Insights pages, a list of rules is displayed on a pane instead of the Security Policies page. This issue doesn't apply to the Insights Applications page.
-
-
When you export log data from page, the exported log data CSV file might fail to open on Windows if the filename (including folder path) is too long.
This is a known limitation in Microsoft Excel and Windows regarding maximum file path length. The issue does not affect Mac systems.
To avoid such error, move the CSV file to a folder with a shorter path before opening it.
Known Issues
This section lists the known issues in Juniper Security Director Release 26.2.1.
-
Unsupported gigether-options displayed in UI for SRX400 and SRX440 Firewalls—SRX400 and SRX440 Firewalls might display the gigether-options configuration in the UI under . However, gigether-options are not supported on SRX400 and SRX440 Firewalls. Do not configure gigether-options on SRX400 and SRX440 Firewalls.
-
Memory utilization is not displayed for SRX400 and SRX440 Firewalls—Juniper Security Director does not display memory utilization for SRX400 and SRX440 Firewalls in the following locations:
- On the page, the Device Health Status column does not display memory utilization.
- On the page, when you click an SRX400 or SRX440 Firewall in the
Host Name column and open the Overview
tab:
- The Chassis widget does not display memory utilization.
- The Memory widget is not available.
The absence of the memory widget does not affect any other monitoring, management capabilities, or device performance.
-
Manual signature installation failure on SRX400 and SRX440 Firewalls—In Juniper Security Director, manual installation of IPS and application signatures fails on SRX400 and SRX440 firewalls. When you go to , select the IPS and application signatures, and click , the installation job fails.
Workaround:
Use the automatic installation instead of the manual installation for SRX400 and SRX440 Firewalls. To do this:
Go to .
Select IPS Signatures and Application Signatures.
Click .
Enable Auto-update, configure the start date/time and update interval, and select the SRX400 and SRX440 Firewalls.
Click OK.
The automatic installation ensures the security package is installed and updated directly from the Juniper Networks security website, bypassing the manual download path.
Resynchronization job may fail after rollback-image on cluster devices—After performing a rollback image operation on a cluster device , the automatic resynchronize-with-network job can fail due to connection errors. During the rollback and reboot process, there is a brief interval when neither node is primary, causing the resynchronization attempt to fail. As a result, users may see ConnectionError messages during inventory discovery (hardware, interfaces, software, licenses, system, configuration, and certificates). While the device continues to function normally, its inventory data in Juniper Security Director is not updated until a successful resynchronization is completed
Workaround
After the rollback operation is complete and the cluster stabilizes, perform the following:
- Select .
- Select the device, and click .
-
Scheduled security policy deployment shows incorrect deployment type—When you schedule a security policy deployment using the Schedule at a later time option with the group-by option set to All devices, the job status might incorrectly display the deployment type as Only to selected devices. This is a display issue only. The scheduled deployment runs on all devices as configured. You can confirm the correct scope by checking the device list in the job details.
-
Report generation failure when SMTP server is not configured—After installing Juniper Security Director 26.2.1, using Send Report or Edit Recipients from without configuring an SMTP server might cause report generation failure. In some cases, the operation might incorrectly display a success message even though the report was not sent.
Workardound
Perform one of the following tasks:
-
Configure an SMTP server: Go to and configure the SMTP server. After SMTP server configuration, the Email Section will be available as expected for you to send report or edit recipients.
-
Remove email recipients before generating reports:
-
Go to .
Select the report and click and remove all configured email addresses.
Generate the report again. The report will be generated successfully without email delivery.
-
-
-
Inconsistent IP or FQDN validations in UI and CLI messages—Some UI and CLI messages still use older terminology for virtual IP addresses. You might see inconsistent validation or audit-log details when you change UI, device connection, or log collector addresses on the page. The device count in validation messages might not match the number of devices on the page. This does not affect basic system operation. When you see unexpected messages, verify the final configuration on the Devices page and in system logs.
-
VM deployment on KVM fails with USB CD-ROM device bus type—When deploying a VM on KVM, using a USB bus type for the CD-ROM can lead to the error: Error mounting CD-ROM: mount: /media/cdrom: special device /dev/sr0 does not exist. This occurs because the USB bus type for the CD-ROM is unsupported, causing the mount operation to fail. You can use USB bus type for virtual disk.
-
Deployment failure on devices —After deploying the VM and onboarding devices to Juniper Security Director, following discrepancies are observed:
-
On the Juniper Security Director UI, page shows the device management status as Down.
-
On the device, the output from the SSH client command show system connections | match 7804 indicates that the status is ESTABLISHED, indicating a stale connection.
Due to these discrepancies, the device-bound configurations will not function.
Workaround:
For a successful deployment, login to device through SSH or console and execute restart service-deployment command.
-
VM snapshot revert error—When you take a snapshot using the option and attempt to revert to a previous VM version using REVERT, the status might indicate that the snapshot reversal is complete. However, powering on the VM can result in an error, causing the snapshot revert to fail.
Workaround:
Login to vSphere Client.
Right-click the VM, select .
Right-click the VM, select Edit Settings
Under Virtual Hardware, select the CD/DVD drive's Connect At Power On check-box.
Right-click the VM, select .
-
CLI admin password validation during VM deployment—During VM deployment, when you configure Juniper Security Director OVA parameters on the Customize template page, the cliadmin user password field accepts any password with 8 characters. However, during the installation process, the system enforces strict validations and rejects the password that does not meet the specified requirements. This discrepancy might result in installation failure.
Workaround:
Perform the following steps to set the password that complies with the requirements:
In the vSphere client, right-click the VM and select .
Click Yes to confirm and power off the VM.
Select the VM and go to the Configure tab and click vApp Options. In the vApp Options section, locate the Properties table.
Select CLI_PASSWORD and select SET VALUE.
Enter the password that meets the following requirements:
Must be at least 8 characters long and not more than 32 characters.
Must not be dictionary words.
Must include at least three of the following:
Numbers (0-9)
Uppercase letters (A-Z)
Lowercase letters (a-z)
Special characters (~!@#$%^&*()_-+={}[];:"'<,>.?/|\)
Click OK.
Right-click the VM, select .
Once the VM powers on, navigate to the Summary tab and click LAUNCH WEB CONSOLE to monitor the software bundle installation status.
A successful installation requires approximately 30 minutes. If the installation lasts longer, check the web console for potential errors. You can ssh to the VM IP with the CLI admin user and use show bundle install status command to view the installation status.
-
New user activation—When you add a user to Juniper Security Director on the page, the user receives an email with a link to set a password and join the organization. The email incorrectly states that the link is valid for 7 days. The actual validity for setting the password is 24 hours. If the user does not set the password within 24 hours, the link expires and shows an invalid request error.
Workaround:
Log in to Juniper Security Director UI.
Go to , select the user to resend the activation link.
Click to resend the activation link.
-
Security log configuration timeout during device discovery—During device discovery, the
configure-security-logjob might timeout or fail after running for a long time. Consequently, the page displays security log status as Not configured.Workaround:
Manually configure the security logs. For details, see Configure Security Logs.
-
MNHA resynchronization job failure—When you reboot a device after enabling or disabling Multinode High Availability (MNHA) configuration, the job fails with a sync inventory issue. The device’s inventory and configuration status remain stuck in an out of sync state.
Workaround:
Perform a manual resynchronization to restore inventory and configuration status.
Select .
Select the device to resynchronize, and click .
A job is created for the resynchronization process and the details are displayed on the top of the page
-
ICAP profile server routing instance limitation—
-
When you edit the routing instance of a deployed ICAP profile server and redeploy it, the routing instance is removed automatically.
-
When you import an ICAP profile server with a routing instance and deploy it in Juniper Security Director, the routing instance is removed during the deployment process.
-
When you import an ICAP profile server without a routing instance and deploy it in Juniper Security Director, the deployment succeeds. However, if you later edit the profile server to add a routing instance and redeploy it, the routing instance is removed automatically.
Workaround:
Create a new ICAP profile server with a routing instance.
Deploy the ICAP profile server with the security policy.
-
-
Image installation issue on Juniper Security Director—You may notice image installation failures if there are issues copying the image from Juniper Security Director to the device. Image transfers are faster when both Juniper Security Director and the device are in the same geographic region, and slower when they are in different regions. In such cases, we recommend that you stage the image using the remote server option. For optimal transfer speed and reliability, ensure that the remote server and the device are in the same region.
Workaround:
-
For failure due to copying image file from Juniper Security Director to device:
Ensure that the device can access the location of the image.
Go to .
Click Upload and select From remote server.
Enter the URL for the remote server where the image is located. You can generate the URL on the product-specific Support page of the Juniper Networks website. See Add an Image for details.
-
For failure due to upgrade path: refer Junos OS documentation to understand the upgrade path for specific Junos OS release.
-
-
When you configure SRX Series Firewalls in the Device Configurations tab, you might face the following issues:
Setting Known Issue Workaround Basic Settings > Management > SNMP If you configure Remote Engine for SNMP, the configuration deployment fails because the Privacy configuration is deployed before the Authentication configuration.
The following error message is displayed:
deploy failed with error:[ErrorSeverity:error,ErrorPath:,ErrorMessage: Authentication should be configured before configuring the privacy ,BadElement:]Configure the Remote Engine user settings in the following sequence:
- Select the Authentication method while adding a Remote Engine user at SNMP > V3 > USM > Remote Engine > User.
- Deploy the device configuration.
- Select the Privacy setting.
- Deploy the device configuration again.
Network Settings > Interfaces If you configure both the unit number and the VLAN ID as the outer tag for interfaces, the configuration deployment fails.
The following error message is displayed:
error: 'unit' statement cannot be included along with 'vlan-tags-outer' statementDo not configure both the options as the outer tag for interfaces. Select either Vlan_tag_mode or Unit as the outer tag.
Network Settings > Interfaces If you configure Pic Set for interfaces, the configuration deployment fails.
The following error message is displayed:
Segmentation fault (core dumped)Configure Pic Set only for interfaces of the SRX5400, SRX5600, and SRX5800 SRX Firewalls. Security Settings > User Firewall > Device Information The existing configuration of onboarded SRX Series Firewalls is not displayed on the User Firewall page because of a mismatch of the Authentication Source field name between the Juniper Security Director GUI and the device CLI.
None Advanced Settings > Security > GTP > Message IE Profile V2 If you don't configure all the mandatory settings for Message IE Profile V2, the configuration is not deployed on the devices even though the Juniper Security Director GUI displays a success message.
Configure all the mandatory settings for Message IE Profile V2.
See message-ie-profile-v2 for the mandatory settings.
Advanced Settings > Security > Grouped IE Profile If you don't configure all the mandatory settings while adding a Grouped IE Profile, the configuration is not deployed on the devices even though the Juniper Security Director GUI displays a success message.
Configure all the mandatory settings for Grouped IE Profile.
See grouped-ie-profile for the mandatory settings.
Advanced Settings > Protocols > IS-IS Instance If you don't configure all the mandatory settings while adding an IS-IS Instance, the configuration is not deployed on the devices even though the Juniper Security Director GUI displays a success message.
Configure all the mandatory settings for IS-IS Instance.
See level (IS-IS Interfaces) for the mandatory settings.
Network Settings > Forwarding Options > Load Balance > Indexed Load Balance If you enable Indexed Load Balance while configuring Load Balance, the configurations are not deployed on the devices even though the Juniper Security Director GUI displays a success message.
The following error message is displayed if you deploy the configuration using CLI:
Could not retrieve the two-level-multi-next-hop settingDon't enable Indexed Load Balance. The option is not applicable to SRX Series Firewalls.
Advanced Settings > Chassis > Network Services If you configure ethernet for Network Services, the configuration deployment fails because the option is not applicable to SRX Series Firewalls.
Don’t configure ethernetb for Network Services in SRX Series Firewalls. The option is not applicable to SRX Series Firewalls.
Advanced Settings > Chassis If you configure Ambient Temperature, the configuration deployment fails because the option is applicable only to specific SRX Series Firewalls.
The following error message is displayed:
:[ErrorSeverity:error,ErrorPath:,ErrorMessage:Invalid trailing data 'C' for numeric value: '40C',BadElement:40C]Configure Ambient Temperature only on the supported SRX Series Firewalls.
See Feature Explorer for the supported models.
Advanced Settings > Protocols > PPP If you configure PPP services for Protocols, the configuration deployment fails because the option is applicable only to specific SRX Series Firewalls.
Configure PPP services for Protocols using CLI only on SRX4000 and SRX1600 Series Firewalls.
See Point-to-Point protocol (PPP) for how to configure PPP using CLI.
Advanced Settings > Protocols > R2CP If you configure Port any for Client Port Value while configuring the R2CP protocols in the device CLI, the setting changes to Not configured on the Juniper Security Director GUI after deploying the device configuration.
Configure a specific port for Client Port Value on the Juniper Security Director GUI. Device Configurations If you configure an onboarded device, the configuration deployment shows as out-of-band changes.
Wait 5 to 10 minutes for the device onboarding process to complete before updating and deploying the device configuration. Device Configurations If you configure certain device settings, the configuration deployment fails because the settings might be applicable only to specific SRX Series Firewalls. For example,
- Advanced Settings -> Services -> Hosted-services
- Advanced Settings->Services > Mobile Flow Tap
- Advanced Settings->Services > Network Slicing
Configure the settings applicable to the SRX Series Firewalls.
See Feature Explorer for the supported models.
Device Configurations If you deactivate device settings in the SRX Series Firewalls using CLI, the device configuration deployment might fail when you configure settings on the Device Configurations tab of the Juniper Security Director GUI.
Activate and commit the settings or delete the settings using CLI before configuring the settings using the Juniper Security Director GUI.
-
Security policy import failure due to hidden commands—If hidden commands exist in SRX Series Firewalls, importing and deploying security policies might fail due to version incompatibility. This issue can affect configurations such as Content Security and security policies.
Workaround:
Delete any hidden or undocumented commands from SRX Series Firewalls, re-import the policy configuration to Juniper Security Director, and then deploy the security policy.
-
SMB protocol issue in AAMW profile—Devices running versions before Junos OS 21.1 experience commit failures when using the Server Message Block (SMB) protocol option in the predefined Advanced Anti-Malware (AAMW) profile.
Workaround:
Clone the default AAMW profile and disable the SMB protocol. Use the cloned profile in the Security Policy or global options to ensure successful commits.
-
Clock synchronization upgrade issue—When you upgrade a device to Junos OS 21.1 or later using a software image, you might encounter an error message indicating that in-service software upgrade (ISSU) is not supported for Clock Synchronization (SyncE).
Workaround:
Upgrade the cluster from CLI using the workaround provided in https://prsearch.juniper.net/problemreport/PR1632810.
-
Log visibility limitations for SRX Series Firewall—You cannot view certain logs in Juniper Security Director for SRX Series Firewalls running Junos OS version 21.4 R3-S3.4 and later. The logs affected include:
-
Web filtering logs
-
RT_FLOW logs
-
Content Security logs
-
-
Peer synchronization in Multinode High Availability—If peer synchronization is enabled for Multinode High Availability solution, then any deployment or configuration change might result in multiple synchronization jobs.
Workaround:
Delete the
set system commit peers-synchronizecommand from device configuration for Multinode High Availability solution. - Custom server certificate updates—Uploading a new custom Server Certificate in Juniper Security Director does not terminate active user sessions, and requires manual page refreshes for the certificate to take effect.