Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Announcement: Try the Ask AI chatbot for answers to your technical questions about Juniper products and solutions.

close
header-navigation

Release Notes: Junos OS Release 21.2R2 for the ACX Series, cSRX, EX Series, JRR Series, Juniper Secure Connect, Junos Fusion, MX Series, NFX Series, PTX Series, QFX Series, SRX Series, vMX, vRR, and vSRX

keyboard_arrow_up
close
keyboard_arrow_left
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

Open Issues

date_range 14-Oct-21

Learn about open issues in this release for vSRX.

For the most complete and latest information about known Junos OS defects, use the Juniper Networks online Junos Problem Report Search application.

General Routing

  • The tag RT_FLOW_SESSION_XXX is missing in stream mode. PR1565153

  • When the device is downgraded to a release earlier than Junos OS Release 21.1 and then upgraded again to Junos OS Release 21.1, the appiddb tables might not get populated properly and have 0 entries. For such cases, after upgrading, uninstall and reinstall signature package. PR1567199

  • Under very rare conditions for HA cluster deployment, when it does RG0 failover and at same time, the control link is down, then it will hit this mib2d core because the master RE and secondary RE are out of syncing dcd.snmp_ix information. PR1571677

  • On SRX Series devices, the auto re-enrollment of a CMPv2 certificate might lead to a PKID core due to OpenSSL version mismatch. PR1580442

  • With SSL proxy configured along with web proxy, the client session might not closed on the device even though proxy session ends gracefully. PR1580526

  • Getting UNKNOWN instead of HTTP-PROXY for application and UNKNOWN instead of GOOGLE-GEN in RT-FLOW close messages These messages can be seen in the RT-flow close log and these are due to JDPI not engaged for the session. This may affect the app identification for the web-proxy session traffic. PR1588139

  • The request system power-off command cannot completely shutdown vSRX3.0 if Mellanox SR-IOV is used as revenue ports. The system will hang after peer_proxy: 5447: Peer proxy (class: 0, type: 10, index: 0, vksid: 0, state: 1) is marked for the closing. The power state is still on until forcefully shut it off from hypervisor. PR1604063

J-Web

  • If any VPN related configuration changes are done from the CLI and committed, click on the Monitor> Network > IPsec VPN menu again to see the latest changes. PR1571751

  • UI lists the IPSec VPNs information for uncommitted IPSec VPNs configuration under Monitor -> Netwrok -> IPSec VPN. PR1576609

Routing Policy and Firewall Filters

  • When you set the global-configuration of the SSL Proxy with enable-proxy-on-default-fw-policy-match, the traffic hits the pre-id policy instead of the default policy for the Yahoo traffic. PR1542790

footer-navigation