- play_arrow Junos OS Release Notes for ACX Series
- play_arrow Junos OS Release Notes for cSRX
- play_arrow Junos OS Release Notes for EX Series
- play_arrow Junos OS Release Notes for JRR Series
- play_arrow Junos OS Release Notes for MX Series
- play_arrow Junos OS Release Notes for NFX Series
- play_arrow Junos OS Release Notes for PTX Series
- play_arrow Junos OS Release Notes for QFX Series
- play_arrow Junos OS Release Notes for SRX Series
- play_arrow Junos OS Release Notes for vMX
- play_arrow Junos OS Release Notes for vRR
- Licensing
- Finding More Information
- Requesting Technical Support
- Revision History
Open Issues
Learn about open issues in this release for vSRX.
For the most complete and latest information about known Junos OS defects, use the Juniper Networks online Junos Problem Report Search application.
Flow-Based and Packet-Based Processing
The ICMPv6 tcp sequence info is missing in the icmp v6 error generated. PR1611202
Due to JUNOS CLI framework's implementation, Current fix has a caveat that customer had better keep 1~2 minutes gap between two configuration commits if there are lots of security policies which need time to be processed. PR1625531
Platform and Infrastructure
With ssl-proxy configured along with web-proxy, the client session might not closed on the device even though proxy session ends gracefully. PR1580526
AMR when it is enabled in non-cso v6 over v6 mode with IPsec tunnels, the first session after reboot or forward restart, will not have multipath treatment, post that the feature works fine. PR1643570
Device does not drop session with server certificate chain more than 6.PR1663062
When client tries to do a TLS 1.3 session resumption and the proxy is not able to honor the resumption request, ideally the cache miss counter has to be incremented once. But due to this bug, it gets incremented twice.PR1663678
VPNs
When using Group VPN, in certain cases, the PUSH ACK message from the group member to the group key server may be lost. The group member can still send rekey requests for the TEK SAs before the hard lifetime expiry. Only if the key server sends any new PUSH messages to the group members, those updates would not be received by the group member since the key server would have removed the member from registered members list.PR1608290