Resolved Issues: 21.4R2
- Flow-Based and Packet-Based Processing
- General Routing
- Infrastructure
- Intrusion Detection and Prevention (IDP)
- J-Web
- Routing Protocols
- Unified Threat Management (UTM)
- VPNs
Flow-Based and Packet-Based Processing
-
On SRX-Series devices using Unified Policies with IPv6, when attempting to reject certain dynamic-applications a flowd core could be generated PR1601806
General Routing
-
SRX_RIAD:CSRX:LOG: RT-Log pattern is not matching in 21.1R1, 21.2R2, 21.2R1 and 21.4R1. PR1565153
-
PKID core during auto-re-enrollment of CMPv2 certificates. PR1580442
-
20.1R3:SRX-RIAD:vSRX3.0: Web-proxy: Getting UNKNOWN instead of HTTP-PROXY for application and UNKNOWN instead of GOOGLE-GEN in RT-FLOW close messages PR1588139
-
During SaaS probing, due to race condition between APP entry addition and session processing, this core is seen. PR1622787
-
On SRX Series devices running DNS Security, if a DGA was detected and the action in the configuration was set to 'permit', under rare circumstances, a log would not be generated by the device. PR1624076
-
The application package installation might fail with error in SRX platforms PR1626589
-
vSRX3 on VMware ESXi versions 7.0u2 or 7.0u3 with i40e SR-IOV: Traffic stopped after reboot PR1627481
-
vSRX: "Resource errors" in "show interfaces extensive" PR1629986
-
Signature package update may fail and the appid process may crash on SRX devices PR1632205
-
On SRX Series devices running DNS Security, a dataplane memory leak may occur within the DNSF plugin when entries age-out of the DNSF cache PR1633519
-
Application group name is not found for micro apps in CLI show output PR1640040
-
The pfe crash may occur on JUNOS SRX platforms PR1642914
Infrastructure
-
The failover process may become slow in a vSRX cluster if the gstatd daemon stops running PR1626423
Intrusion Detection and Prevention (IDP)
-
21.2R3:SRX345:vSRX3.0:Device is hanging while checking the cli " show security idp attack attack-list policy combine-policy" PR1616782
J-Web
Routing Protocols
-
Memory leak in 'global data shm' process might lead to traffic outage PR1626704
Unified Threat Management (UTM)
VPNs
-
The process kmd might crash if the ike gateway is configured with two ip-address PR1626830
-
Issue in Certificate-based VPN tunnels initiation while using GCP KMS PR1628722
-
On all SRX products, when nat traversal is configured and working for an ipsec tunnel, there is a chance that the tunnel might stop processing packets after a rekey PR1636458