Junos Space Security Director Release Notes 24.1

Published: 2025-06-30

Introduction

The Junos Space® Security Director application is a powerful and easy-to-use solution that enables you to secure your network by creating and publishing firewall policies, IPsec VPNs, NAT policies, IPS policies, and AppFW.

Note: You need IPS and AppFW licenses to push IPS policies and AppFW signatures to a device.

New and Changed Features

Junos Space Security Director Release 24.1R1

Note: Security Director Release 24.1R1 supports only non-FIPS mode.

Note: Security Director Release 24.1R2 supports Security Director Insights Release 24.1 R1 and above versions.

Note: Security Director 24.1R2 Hot Patch v1 is mandatory for Security Director Insights Policy Enforcer 24.1R1 to operate with Security Director Release 24.1R2.

Junos Space Security Director Release 24.1R3

Note: High Availability is not supported on Junos Space Security Director for SRX4700 firewall.

Junos Space Security Director Release 24.1R4

Junos Space Security Director supports sharing of point-to-point st0 logical interface when running IPsec VPN service using the IKED process, providing a migration path from the kmd process. Multiple VPNs objects can be configured to share a point-to-point st0 interface.

Supported Managed Devices

Security Director Release 24.1 can manage the following devices:

Supported Log Collection Systems

The following log collection systems are supported:

Note: Starting in Security Director Release 21.1R1, standalone Log Collector and Integrated Log Collector are not supported.

Supported Junos OS Releases

Security Director Release 24.1 supports the following Junos OS releases:

Note: EoL Junos releases might continue to work, but their support has not been tested.

SRX Series Firewalls require Junos OS Release 12.1 or later to synchronize the Security Director description field with the device.

The logical systems feature is supported only on devices running Junos OS Release 11.4 or later.

Note: To manage an SRX Series Firewall using Security Director, install the matching Junos OS schema on the Junos Space Network Management Platform. Mismatched schemas may display a warning message during the publish preview workflow.

Supported Policy Enforcer and Juniper® Advanced Threat Prevention (ATP) Cloud Releases

Table 1: Supported Policy Enforcer and Juniper ATP Cloud Releases
Security Director ReleaseCompatible Policy Enforcer ReleaseJunos OS Release (Juniper ATP Cloud Supported Devices)
21.3R121.3R1Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
22.1R122.1R1Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
22.2R122.2R1Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
22.3R122.3R1Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
23.1R123.1R1Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
24.1R124.1R1Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later

Note: Starting in Junos Space Security Director Release 24.1R1, standalone Policy Enforcer is not supported. Migration to Policy Enforcer running on Security Director Insights 24.1R1 is required.

Supported Browsers

Security Director Release 24.1 is best viewed on the following browsers:

Installation and Upgrade Instructions

Supported Software Versions

Junos Space Security Director is supported only on specific software versions mentioned in Table 2 on page 7.

Table 2: Supported Software Versions
Security Director VersionCompatible with Junos Space Network Management Platform Version
Security Director 24.1 R1Yes
Security Director 24.1 R2Yes, Yes
Security Director 24.1 R2 Hot Patch v1Yes, Yes
Security Director 24.1 R3Yes, Yes
Security Director 24.1 R3 Hot Patch v1Yes, Yes
Security Director 24.1 R3 Hot Patch v2Yes, Yes
Security Director 24.1 R3 Hot Patch v3Yes, Yes
Security Director 24.1 R3 Hot Patch v4Yes, Yes
Security Director 24.1 R4Yes

Installing and Upgrading Security Director Release 24.1R1

Caution: You must install the Junos Space 24.1R1 hot patch v1 before installing or upgrading Junos Space Security Director application.

Junos Space Security Director Release 24.1R1 is supported only on Junos Space Network Management Platform Release 24.1R1 that can run on the following devices:

Installing and Upgrading Security Director Release 24.1R2

Caution: You must install the Junos Space 24.1R1 hot patch v2 before installing or upgrading Junos Space Security Director application.

Note: Junos Space Network Management Platform Release 24.1R2 is qualified and is compatible with Security Director Release 24.1R2.

Junos Space Security Director Release 24.1R2 is supported only on Junos Space Network Management Platform Release 24.1R1 that can run on the following devices:

Starting in Junos Space Security Director Release 24.1R2, the following cronjob is added in existing crontab in all JBOSS nodes:

10 1 * * * /var/www/cgi-bin/ApplicationVisibility_DataReduction.sh >/dev/null 2>&1

The cronjob runs every day at 1:10 AM. The ApplicationVisibility_DataReduction.sh script is added in /var/www/cgi-bin.

To purge the Application Visibility database, update APP_VISIBILITY=false to APP_VISIBILITY=true in the ApplicationVisibility_DataReduction.sh script. Purging is triggered only in the VIP node.

Data is retained for 7 days by default. You can modify the retention period using the following parameters in the ApplicationVisibility_DataReduction.sh script:

DAYS_IN_SECONDS_1=86400000
DAYS_IN_SECONDS_7=604800000
DAYS_IN_SECONDS_14=1209600000
DAYS_IN_SECONDS_21=1814400000
DAYS_IN_SECONDS_30=2592000000

Note: MODIFY HERE if needed: Replace Variable in next line for selected time SELECTED_DAYS=$DAYS_IN_SECONDS_7

Installing and Upgrading Security Director Release 24.1R3

Junos Space Security Director Release 24.1R3 is supported on Junos Space Network Management Platform Release 24.1R2 that can run on the following devices:

Installing and Upgrading Security Director Release 24.1R4

Junos Space Security Director Release 24.1R4 is supported only on Junos Space Network Management Platform Release 24.1R4 that can run on the following devices:

For more information about installing and upgrading Security Director, see the Security Director Installation and Upgrade Guide.

Loading Junos OS Schema for SRX Series Firewalls

You must download and install the correct Junos OS schema to manage SRX Series Firewalls. To download the correct schema, from the Network Management Platform list, select Administration > DMI Schema, and click Update Schema. See Updating a DMI Schema.

DMI Schema Compatibility for Junos OS Service Releases

The following tables explain how the Junos Space Network Management Platform chooses Device Management Interface (DMI) schemas for devices running Junos OS Service Releases.

If a Junos OS Service Release is installed on your device with a major release version of a DMI schema installed on Junos Space Network Management Platform, Junos Space chooses the latest corresponding major release of DMI schemas, as shown in Table 3 on page 11.

Table 3: Device with Service Release and Junos Space with FRS Release
Junos OS Version on the DeviceJunos Space DMI Schemas InstalledJunos Space Default VersionJunos Space Version Chosen for Platform
18.4R1-S118.4R1.8
18.3R1.1
18.2R1.118.4R1.8

If 18.4R1.8 version is not available, then Junos Space chooses the nearest lower version of DMI schema installed.

Table 4: Device with Service Release and Junos Space without matching DMI Schema
Junos OS Version on the DeviceJunos Space DMI Schemas InstalledJunos Space Default VersionJunos Space Version Chosen for Platform
18.4R1-S118.3R1.118.2R1.118.3R1.1

If a Junos OS Service Release is installed on your device without a matching DMI schema version in Junos Space Network Management Platform, Junos Space chooses the nearest lower version of DMI schema installed, as shown in Table 4 on page 11.

Table 5: Device with Service Release and Junos Space with more than one DMI Schemas
Junos OS Version on the DeviceJunos Space DMI Schemas InstalledJunos Space Default VersionJunos Space Version Chosen for Platform
18.4R1-S118.4R1.8
18.4R1.7
18.4R1.6
18.3R1.1
18.3R1.118.4R1.8

If 18.4R1.x versions are not available, then Junos Space chooses the nearest lower version of DMI schema installed.

Table 6: Device with Service Release and Junos Space without more DMI Schemas
Junos OS Version on the DeviceJunos Space DMI Schemas InstalledJunos Space Default VersionJunos Space Version Chosen for Platform
18.4R1-S118.5R1.1
18.3R1.1
18.2R1.1
18.2R1.118.3R1.1

If a Junos OS Service Release is installed on your device without a corresponding DMI schema version in Junos Space Network Management Platform, then Junos Space chooses the nearest lower version of DMI schema installed, as shown in Table 6 on page 12.

For information about Junos OS compatibility, see Junos OS Releases Supported in Junos Space Network Management Platform.

Management Scalability

The following management scalability features are supported in Junos Space Security Director:

Note: You can manually configure the monitor polling on the Administration>Monitor Settings page.

#mysql -u <mysql-username> -p <mysql-password> sm_db;
mysql> update RuntimePreferencesEntity SET value=20 where
name='UPDATE_MAX_SUBJOBS_PER_NODE';
mysql> exit

Note: Contact Juniper Support team for MySQL username and password details.

Note: If you use a database dedicated setup (SSD hard disk VMs), the performance of publish and update is better compared with the performance in a normal two-node Junos Space fabric setup.

Known Behavior

This section contains the known behavior and limitations in Junos Space Security Director Release 24.1.

Known Issues

This section lists the known issues in Junos Space Security Director Release 24.1.

For the most complete and latest information about known Security Director defects, use the Juniper Networks online Junos Problem Report Search application.

Resolved Issues

Resolved Issues in Junos Space Security Director Release 24.1R1

This section lists the issues fixed in Junos Space Security Director Release 24.1R1:

For the most complete and latest information about resolved issues, use the Juniper Networks online Junos Problem Report Search application.

Resolved Issues in Junos Space Security Director Release 24.1R2

This section lists the issues fixed in Junos Space Security Director Release 24.1R2:

For the most complete and latest information about resolved issues, use the Juniper Networks online Junos Problem Report Search application.

Resolved Issues in Junos Space Security Director Release 24.1R4

This section lists the issues fixed in Junos Space Security Director Release 24.1R4:

Hot Patch Releases

Junos Space Security Director Release 24.1R2 Hot Patch Release

This section describes the installation procedure and resolved issues in Junos Space Security Director Release 24.1R2 hot patch.

During hot patch installation, the script performs the following operations:

Note: You must install the hot patch on Security Director Release 23.1R1 or on any previously installed hot patch. The hot patch installer backs up all the files which are modified or replaced during hot patch installation.

Installation Instructions

Perform the following steps in the CLI of the JBoss-VIP node only:

  1. Download the Security Director 24.1R2 Patch vX from the download site. Here, X is the hot patch version. For example, v1, v2, and so on.
  2. Copy the SD24.1R2-hotpatch-vX.tgz file to the /home/admin location of the VIP node.
  3. Verify the checksum of the hot patch for data integrity:
md5sum SD24.1R2-hotpatch-vX.tgz
  1. Extract the SD24.1R2-hotptach-vX.tgz file:
tar -zxvf SD24.1R2-hotpatch-vX.tgz
  1. Change the directory to SD24.1R2-hotpatch-vX.
cd SD24.1R2-hotpatch-vX
  1. Execute the patchme.sh script from the SD24.1R2-hotpatch-vX folder:
sh patchme.sh

The script detects whether the deployment is a standalone deployment or a cluster deployment and installs the patch accordingly.

A marker file, /etc/.SD24.1R2-hotpatch-vX, is created with the list of Red Hat Package Manager (RPM) details in the hot patch.

Note: We recommend that you install the latest available hot-patch version, which is the cumulative patch.

Resolved Issues in the Hot Patches

Table 7 on page 23 lists the resolved issues in Security Director Release 24.1R2 hot patch.

Table 7: Resolved Issues in the Hot Patch
PRDescriptionHot Patch Version
PR1835150The user is unable to download Summary Report.zip file in Security Director.v1

Junos Space Security Director Release 24.1R3 Hot Patch Release

This section describes the installation procedure and resolved issues in Junos Space Security Director Release 24.1R3 hot patch.

During hot patch installation, the script performs the following operations:

Note: You must install the hot patch on Security Director Release 23.1R1 or on any previously installed hot patch. The hot patch installer backs up all the files which are modified or replaced during hot patch installation.

Installation Instructions

Perform the following steps in the CLI of the JBoss-VIP node only:

  1. Download the Security Director 24.1R3 Patch vX from the download site. Here, X is the hot patch version. For example, v1, v2, and so on.
  2. Copy the SD24.1R3-hotpatch-vX.tgz file to the /home/admin location of the VIP node.
  3. Verify the checksum of the hot patch for data integrity:
md5sum SD24.1R3-hotpatch-vX.tgz
  1. Extract the SD24.1R3-hotptach-vX.tgz file:
tar -zxvf SD24.1R3-hotpatch-vX.tgz
  1. Change the directory to SD24.1R3-hotpatch-vX.
cd SD24.1R3-hotpatch-vX
  1. Execute the patchme.sh script from the SD24.1R3-hotpatch-vX folder:
sh patchme.sh

The script detects whether the deployment is a standalone deployment or a cluster deployment and installs the patch accordingly.

A marker file, /etc/.SD24.1R3-hotpatch-vX, is created with the list of Red Hat Package Manager (RPM) details in the hot patch.

Note: We recommend that you install the latest available hot-patch version, which is the cumulative patch.

Resolved Issues in the Hot Patches

Table 8 on page 25 lists the resolved issues in Security Director Release 24.1R3 hot patch.

Table 8: Resolved Issues in the Hot Patch
PRDescriptionHot Patch Version
PR1866711In Security Director Release 24.1R3, the metadata filter under Configure > Firewall Policy > Standard Policies page fails to perform intersection (AND) or union (OR) functions.v4
PR1858790The user is unable to search services with port numbers in Security Director Release 24.1R2.v3
PR1846929The user is unable to install IDP signatures offline and is unable to schedule new poll license jobs.v3
PR1864422Security Director fails to push the address book entries to the SRX Series Firewall.v3
PR1854243The databases are out of sync in Security Director.v2
Workaround:1. Login to the JBoss CLI using the following command: /usr/local/jboss/bin/jboss-cli.sh --connect --user=admin --password=$(grep jboss.admin /etc/sysconfig/ JunosSpace/pwd | awk -F= '{print $2}') --controller=jmp-CLUSTER 2. Run the following command in the JBoss CLI and set tcp-keep-alive to false. /profile=full-ha/ subsystem=undertow/ server=default-server/http-listener=default:write-attribute(name=tcp-keep-alive, value=false) 3. Verify the value /profile=full-ha/ subsystem=undertow/ server=default-server/http-listener=default:read-resource 4. Stop JBoss and JBoss-dc on the VIP node and JBoss on the non-VIP node. 5. Start JBoss and JBoss-dc on the VIP node and JBoss on the non-VIP node.
PR1853552The user is unable to modify the system log configuration in Security Director.v2
PR1849595The user is unable to view data in the Application tab under Monitor > Applications. The page displays An error occurred while requesting the data message.v1
PR1851141The user is unable to configure rule sets for a NAT policy using change control workflow.v1
PR1852966The user is unable to install AppSecure license on the vSRX Virtual Firewall through Security Director.v1
PR1852986The user is unable to scroll down on the IDP policy rules list under Configure > IPS Policy > Policies in Security Director 24.1R1.v1

Finding More Information

For the latest, most complete information about known and resolved issues, see the Juniper Networks Problem Report Search application at: http://prsearch.juniper.net.

Juniper Networks Feature Explorer is a Web-based application that helps you to explore and compare feature information to find the correct software release and hardware platform for your network. Find Feature Explorer at: https://apps.juniper.net/feature-explorer/.

Revision History

Table 9: Revision History Table
ReleaseRelease DateUpdates
Junos Space Security Director Release 24.1R430 June, 2025-Revision 9Updated the following:
• New and Changed Features
• Installation and Upgrade Instructions
• Known Issues
• Resolved Issues
Junos Space Security Director Release 24.1R3 Hot Patch V415 April, 2025-Revision 8Added a Resolved Issue in Junos Space Security Director Release 24.1R3 Hot Patch V4
Junos Space Security Director Release 24.1R3 Hot Patch V326 March, 2025-Revision 7Added Resolved Issues in Junos Space Security Director Release 24.1R3 Hot Patch V3
Junos Space Security Director Release 24.1R3 Hot Patch V219 February, 2025-Revision 6Added Resolved Issues in Junos Space Security Director Release 24.1R3 Hot Patch V2
Junos Space Security Director Release 24.1R3 Hot Patch V13 February, 2025-Revision 5Added Resolved Issues in Junos Space Security Director Release 24.1R3 Hot Patch V1
Junos Space Security Director Release 24.1R330 December, 2024-Revision 4Updated the following:
• New and Changed Features
• Installation and Upgrade Instructions
Junos Space Security Director Release 24.1R2 Hot Patch V129 October, 2024-Revision 3• Added Resolved Issues in Junos Space Security Director Release 24.1R2 Hot Patch V1
• Updated the Note under New and Changed Feature section.
Junos Space Security Director Release 24.1R21 October, 2024-Revision 2Added the following sections:
• Resolved Issues in Junos Space Security Director Release 24.1R2
• Installing and Upgrading Security Director Release 24.1R2
Updated the note in the New and Changed Feature section.
Junos Space Security Director Release 24.1R130 May, 2024-Revision 1Initial Release Notes

Copyright © 2025 Juniper Networks, Inc. All rights reserved.

Juniper Networks, the Juniper Networks logo, Juniper, and Junos are registered trademarks of Juniper Networks, Inc. and/or its affiliates in the United States and other countries. All other trademarks may be property of their respective owners.

Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice.

PDF preview unavailable. Download the PDF instead.

junos-space-release-notes-sd-24.1 Microsoft Word for Microsoft 365

Related Documents

PreviewJunos Space Security Director Insights Release Notes 24.1
Release notes for Junos Space Security Director Insights version 24.1, detailing new features, compatibility, installation, known issues, and resolved issues.
PreviewJunos Space Security Director Release Notes 23.1R1
Release notes for Junos Space Security Director version 23.1R1, detailing new and changed features, supported devices, and resolved issues.
PreviewJunos OS Release 24.4R1 Release Notes
Discover the new and changed features, limitations, and known and resolved issues in Junos OS Release 24.4R1. This document covers various Juniper Networks hardware platforms including ACX, cRPD, cSRX, EX, JRR, Juniper Secure Connect, MX, NFX, QFX, SRX Series Firewalls, and vSRX Virtual Firewall.
PreviewJunos OS Release 24.2R2 Release Notes
This document provides release notes for Junos OS Release 24.2R2, detailing new and changed features, limitations, and known and resolved problems for Juniper Networks hardware and software.
PreviewJuniper Junos Space Network Management Platform Release 24.1R1 Release Notes
This document provides release notes for Juniper Junos Space Network Management Platform Release 24.1R1, detailing new features, installation and upgrade instructions, supported hardware and devices, and known issues.
PreviewJunos Space Security Director Release 16.2R1 Release Notes
This document provides release notes for Junos Space Security Director Release 16.2R1, detailing new features, enhancements, known issues, and installation/upgrade instructions for managing Juniper Networks security devices.
PreviewJunos OS Security Policies User Guide for Security Devices
A comprehensive guide to understanding and configuring security policies for Juniper Networks' Junos OS on security devices. This document covers essential concepts, configuration examples, and best practices for network security.
PreviewJunos OS Release 24.4R2 Release Notes
Release notes for Junos OS Release 24.4R2, detailing new and changed features, limitations, and known/resolved issues for various Juniper Networks hardware platforms including ACX, cRPD, cSRX, EX, JRR, Juniper Secure Connect, MX, NFX, QFX, SRX, and vSRX.