Release Notes

Junos Space Security Director Release Notes 23.1R1

Published: 2025-07-10

Introduction

The Junos Space® Security Director application is a powerful and easy-to-use solution that enables you to secure your network by creating and publishing firewall policies, IPsec VPNs, NAT policies, IPS policies, and AppFW.

NOTE: You need IPS and AppFW licenses to push IPS policies and AppFW signatures to a device.

New and Changed Features

This section describes the new features and enhancements to existing features in Junos Space Security Director Release 23.1R1.

Supported Managed Devices

You can use Security Director Release 23.1R1 to manage the following devices:

Supported Log Collection Systems

The following log collection systems are supported:

NOTE: Starting in Security Director Release 21.1R1 onward, Juniper Networks is not supporting standalone Log Collector and Integrated Log Collector.

Supported Junos OS Releases

Security Director Release 23.1R1 supports the following Junos OS releases:

NOTE: EOL Junos releases might continue to work (support is not removed). However, Juniper Networks has not tested them.

SRX Series Firewalls require Junos OS Release 12.1 or later to synchronize the Security Director description field with the device.

The logical systems feature is supported only on the devices that run Junos OS Release 11.4 or later.

NOTE: To manage an SRX Series Firewall by using Security Director, Juniper Networks recommends that you install the matching Junos OS schema on the Junos Space Network Management Platform. If the Junos OS schemas do not match, a warning message is displayed during the publish preview workflow.

Supported Policy Enforcer and Juniper® Advanced Threat Prevention (ATP) Cloud Releases

Table 1 shows the supported Policy Enforcer and Juniper ATP Cloud releases.

Table 1: Supported Policy Enforcer and Juniper ATP Cloud Releases
Security Director Release Compatible Policy Enforcer Release Junos OS Release (Juniper ATP Cloud Supported Devices)
19.3R1 19.3R1 Junos OS Release 15.1X49-D120 and later
19.4R1 19.4R1 Junos OS Release 15.1X49-D120 and later
20.1R1 20.1R1 Junos OS Release 15.1X49-D120 and later
20.3R1 20.3R1 Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
21.1R1 21.1R1 Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
21.2R1 21.2R1 Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
21.3R1 21.3R1 Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
22.1R1 22.1R1 Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
22.2R1 22.2R1 Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
22.3R1 22.3R1 Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later
23.1R1 23.1R1 Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later

NOTE: For Policy Enforcer details, see Policy Enforcer Release Notes.

Supported Browsers

Security Director Release 23.1R1 is best viewed on the following browsers:

Installation and Upgrade Instructions

This section describes how you can install and upgrade Junos Space Security Director and Log Collector.

Installing and Upgrading Security Director Release 23.1R1

Junos Space Security Director Release 23.1R1 is supported only on Junos Space Network Management Platform Release 23.1R1 that can run on the following devices:

When you install Junos Space Security Director Release 23.1R1 hot patch V7, the following cronjob is added in existing crontab in all JBOSS nodes:

10 1 * * * /var/www/cgi-bin/ApplicationVisibility_DataReduction.sh >/dev/null 2>&1

The cronjob runs every day at 1:10 AM. The ApplicationVisibility_DataReduction.sh script is added in /var/www/cgi-bin.

If you want to purge the Application Visibility database, then in ApplicationVisibility_DataReduction.sh script, update APP_VISIBILITY=false to APP_VISIBILITY=true in all JBOSS nodes. However, purging is triggered only in VIP node.

By default, the data is retained for 7 days. You can modify the number of days for which you want to retain the data in Application Visibility database using the following parameters in ApplicationVisibility_DataReduction.sh script:

DAYS_IN_SECONDS_1=86400000
DAYS_IN_SECONDS_7=604800000
DAYS_IN_SECONDS_14=1209600000
DAYS_IN_SECONDS_21=1814400000
DAYS_IN_SECONDS_30=2592000000 # MODIFY HERE if needed: Replace Variable in next line for selected time SELECTED_DAYS=$DAYS_IN_SECONDS_7

For more information about installing and upgrading Security Director and Log Collector 23.1 (Security Director Insights VM), see Security Director Installation and Upgrade Guide.

Loading Junos OS Schema for SRX Series Firewalls

You must download and install the correct Junos OS schema to manage SRX Series devices. To download the correct schema, from the Network Management Platform list, select Administration > DMI Schema, and click Update Schema. See Updating a DMI Schema.

DMI Schema Compatibility for Junos OS Service Releases

The following tables explain how the Junos Space Network Management Platform chooses Device Management Interface (DMI) schemas for devices running Junos OS Service Releases.

If a Junos OS Service Release is installed on your device with a major release version of a DMI schema installed on Junos Space Network Management Platform, then Junos Space chooses the latest corresponding major release of DMI schemas, as shown in Table 2.

Table 2: Device with Service Release and Junos Space with FRS Release
Junos OS Version on the Device Junos Space DMI Schemas Installed Junos Space Default Version Junos Space Version Chosen for Platform
18.4R1-S1 18.4R1.8
18.3R1.1
18.2R1.1
18.2R1.1 18.4R1.8

If 18.4R1.8 version is not available, then Junos Space chooses the nearest lower version of DMI schema installed.

Table 2: Device with Service Release and Junos Space with FRS Release (Continued)
Junos OS Version on the Device Junos Space DMI Schemas Installed Junos Space Default Version Junos Space Version Chosen for Platform
18.4R1-S1 18.3R1.1 18.2R1.1 18.3R1.1

If a Junos OS Service Release is installed on your device without a matching DMI schema version in Junos Space Network Management Platform, then Junos Space chooses the nearest lower version of DMI schema installed, as shown in Table 3.

Table 3: Device with Service Release and Junos Space without matching DMI Schema
Junos OS Version on the Device Junos Space DMI Schemas Installed Junos Space Default Version Junos Space Version Chosen for Platform
18.4R1-S1 18.5R1.1
18.3R1.1
18.2R1.1
18.2R1.1 18.3R1.1

If more than one version of the DMI schemas are installed in Junos Space Platform for a single Junos OS Service Release version, Junos Space chooses the latest version of the DMI schema, as shown in Table 4.

Table 4: Device with Service Release and Junos Space with more than one DMI Schemas
Junos OS Version on the Device Junos Space DMI Schemas Installed Junos Space Default Version Junos Space Version Chosen for Platform
18.4R1-S1 18.4R1.8
18.4R1.7
18.4R1.6
18.3R1.1
18.3R1.1 18.4R1.8

If 18.4R1.x versions are not available, then Junos Space chooses the nearest lower version of DMI schema installed.

Table 4: Device with Service Release and Junos Space with more than one DMI Schemas (Continued)
Junos OS Version on the Device Junos Space DMI Schemas Installed Junos Space Default Version Junos Space Version Chosen for Platform
18.4R1-S1 18.3R1.1 18.2R1.1 18.3R1.1

If a Junos OS Service Release is installed on your device without a corresponding DMI schema version in Junos Space Network Management Platform, then Junos Space chooses the nearest lower version of DMI schema installed, as shown in Table 5.

Table 5: Device with Service Release and Junos Space without more DMI Schemas
Junos OS Version on the Device Junos Space DMI Schemas Installed Junos Space Default Version Junos Space Version Chosen for Platform
18.4R1.1 18.5R1.1
18.3R1.1
18.2R1.1
18.2R1.1 18.3R1.1

For information about Junos OS compatibility, see Junos OS Releases Supported in Junos Space Network Management Platform.

Management Scalability

The following management scalability features are supported in Junos Space Security Director:

#mysql -u <mysql-username> -p <mysql-password> sm_db;
mysql> update RuntimePreferencesEntity SET value=20 where
name='UPDATE_MAX_SUBJOBS_PER_NODE';
mysql> exit

NOTE: For MySQL username and password, contact Juniper Support.

Known Behavior

This section contains the known behavior and limitations in Junos Space Security Director Release 23.1R1.

Known Issues

This section lists the known issues in Junos Space Security Director Release 23.1R1.

For the most complete and latest information about known Security Director defects, use the Juniper Networks online Junos Problem Report Search application.

Resolved Issues

This section lists the issues fixed in Junos Space Security Director 23.1R1:

For the most complete and latest information about resolved issues, use the Juniper Networks online Junos Problem Report Search application.

For resolved issues in Policy Enforcer, see Policy Enforcer Release Notes.

Hot Patch Releases

This section describes the installation procedure and resolved issues in Junos Space Security Director Release 23.1R1 hot patch.

During hot patch installation, the script performs the following operation:

NOTE: You must install the hot patch on Security Director Release 23.1R1 or on any previously installed hot patch. The hot patch installer backs up all the files which are modified or replaced during hot patch installation.

Installation Instructions

Perform the following steps in the CLI of the JBoss-VIP node only:

  1. Download the Security Director 23.1R1 Patch vX from the download site. Here, X is the hot patch version. For example, v1, v2, and so on.
  2. Copy the SD23.1R1-hotpatch-vX.tgz file to the /home/admin location of the VIP node.
  3. Verify the checksum of the hot patch for data integrity:
  4. md5sum SD23.1R1-hotpatch-vX.tgz
  5. Extract the SD23.1R1-hotptach-vX.tgz file:
  6. tar -zxvf SD23.1R1-hotpatch-vX.tgz

    NOTE: For only Security Director 23.1R1 Hot Patch v7, extract the SD23.1R1-hotptach-v7.tgz file:

    tar -xvf SD23.1R1-hotpatch-v7.tgz
  7. Change the directory to SD23.1R1-hotpatch-vX.
  8. cd SD23.1R1-hotpatch-vX
  9. Execute the patchme.sh script from the SD23.1R1-hotpatch-vX folder:
  10. sh patchme.sh

    The script detects whether the deployment is a standalone deployment or a cluster deployment and installs the patch accordingly.

    A marker file, /etc/.SD23.1R1-hotpatch-vX, is created with the list of Red Hat Package Manager (RPM) details in the hot patch.

    NOTE: We recommend that you install the latest available hot-patch version, which is the cumulative patch.

New and Enhanced Features in the Hot Patch

Junos Space Security Director Release 23.1R1 hot patch includes the following enhancements:

Supported Devices in the Hot Patch

Table 6 lists the devices supported in Security Director 23.1R1 Hot Patch Releases.

Table 6: Supported Devices in the Hot Patch
Supported Device Hot Patch Release Version
SRX1600 Junos Space Security Director 23.1R1 Hot Patch v2
SRX2300 Junos Space Security Director 23.1R1 Hot Patch v3

Resolved Issues in the Hot Patches

Table 7 lists the resolved issues in Security Director Release 23.1R1 hot patch.

Table 7: Resolved Issues in the Hot Patch
PR Description Hot Patch Version
PR1876844 Scheduled IDP download job is getting cancelled when we install IDP signature on device via API. v9
PR1880172 Junos Space cancelled "Download IPS/Application Signatures" Recurring Job without user intervention. v9
PR1877436 SD doesn't push IDP SigDB files to the node 1 after failover. v9
PR1872029 Hotpatch script fails to install RPM on second node. v9
PR1873983 IDP installation is failing with the error "FileNotFoundException". v9
PR1866443 Import of variable in SD from CSV file fails. v9
PR1851141 Unable to "Configure Rule Sets" for one NAT policy - Change Control. v9
PR1850807 Security Director 23.1R1 column filter/search returning wrong results when "service" is filtered. v9
PR1845339 Warning Symbol Showing Inconsistently in SD Firewall Policy Page. v9
PR1795041 The IDP policy update is successful, but the SRX Series Firewall CLI failed due to mismatches between nodeo and node1 in the NSM-download file. v8
PR1852966 The user is unable to install AppSecure license on the vSRX Virtual Firewall through Security Director. v8
PR1854243 The databases are out of sync in Security Director. v8
PR1863612 Multiple jobs are stuck in pending state in Security Director. v8
PR1741255 The Application Visibility page does not show the exact number of applications in the Security Director UI. v7
PR1764875 The Application Visibility page takes longer than usual to display data in Security Director. v7
PR1769834 UTM default configuration pushes extra configurations from Security Director. v7
PR1788204 The user is unable to view UTM categories in Security Director UI. v7
PR1791715 The user is unable to fetch GeoIP from PE, the progress bar is stuck at zero percent in Security Director. v7
PR1803773 The Source Zone category under Web Filtering does not show any data in Security Director UI. v7
PR1814140 The user is unable to push multiple metadata-based policies in custom LSYS from Security Director. v7
PR1816006 The user is unable to import the firewall policy in Security Director. v7
PR1816247 When you try to publish a VPN job in Security Director, it fails with "Another publish, unpublish, preview or update job is in progress for this device. Re-try after some time." error message. v7
PR1817001 The user is unable to login to Security Director with a system generated password. v7
PR1821775 Policy based VPN is missing from the security policy rule. v7
PR1823959 The user is unable to change the MTU size from the Create Hub & Spoke (Establishment All Peers) VPN page in Security Director. v7
PR1825006 When the user tries to select the source NAT pool in a sub domain, Security Director displays NAT pools across all sub domains in the drop-down list. v7
PR1827777 Error while importing a variable using CSV in Security Director. v7
PR1835150 The user is unable to download Summary Report.zip file in Security Director, fails with File wasn't available on site error. v7
PR1829529 Snapshot policy job takes longer than usual to complete after upgrading from Security Director Release 21.3R1 to Security Director Release 23.1R1. v6
PR1809047 The configuration preview takes longer than usual to complete in Security Director. v5
PR1762212 The user is unable to import the CSV file for variable objects in Security Director. v5
PR1784546 The user is unable to preview, publish, and update a configuration in Security Director. The job fails with Zone [junos-host ] does not exist in device error message. v5
PR1787314 The user is unable to delete the details of users and roles from Security Director. v5
PR1787570 The Rollback function is not working properly in Security Director. v5
PR1798433 The user is unable to upload the latest-space-update zip file to the IDP signature database offline. v5
PR1803701 Firewall Policy preview fails when you upgrade from Security Director Release 21.3R1 to Security Director Release 23.1R1. v5
PR1811578 IDP packet capture process fails to run on the JBoss VIP node. v5
PR1783380 When user tries to delete a security policy rule between two zones, Security Director generates two delete statements and the update fails. v4
PR1782360 User is unable to create static route under Security Director 22.3R1.20 while using host/32. v4
PR1774699 IP filter tab search is not working as expected. v4
PR1763709 User is unable to publish a policy. v4
PR1741484 User is unable to change password from Security Director > My Profile >Change Password. v4
PR1764858 When user selects the application session under appvisibility page, Security Director redirects to the wrong filter under all events. v3
PR1756160 Devices missing from the UTM Install Category page. v3
PR1755886 During NAT policy import, Security Director creates address object with value 0.0.0.0/0 and not any IP4 addresses. v3
PR1754759 Security Director fails to search rule name for imported rules. v3
PR1765982 Security Director API fails to prevent creation of duplicate addresses. v3
PR1771392 User is unable to add an extranet device without an IP address when creating a site-to-site IPSec VPN where the remote site has a dynamic IP address. v3
PR1752533 LC under Insights Nodes disappears after discovery. v3
PR1724644 Frequent syslog data parsing and circuit_breaking_exception error appears while fetching it through curl query. v2
PR1751227 Security director is unable to get the policy hit count using the rest API. v2
PR1741255 The application visibility feature shows incorrect application data in Security Director. v2
PR1754290 VPN publishing jobs fail. v2
PR1755392 When you search for a policy in Security Director through the rest API, the source or destination address of the policy is not displayed. v2
PR1732842 The Pie chart is not displayed in the generated report because of the exceeding character limit in the URL. v2
PR1746082 When you schedule a job to generate a report, it fails with exceptions. v1
PR1741255 The application visibility feature shows incorrect application data in Security Director. v1
PR1728629 User is unable to sort the columns on the Logging Devices page in Security Director. v1
PR1743599 Security Director displays the Tunnel Status as UNKNOWN when user tries to create a VPN through the UI. v1
PR1737807 When you try to preview the changes done to a policy before publishing, it fails with Calculating XML Edit Config error message. v1
PR1737807 Security Director deletes the routing options autonomous-system configuration, when you try to update the devices with IPsec VPN. v1
PR1736563 Security Director modifies the device setup by adding a set of VPN configurations. v1
PR1735089 Security Director deletes the configurations for the policy-based VPNs that do not get imported to Security Director. v1
PR1727372 The VPN Monitoring page does not load the data in Security Director Release 22.3R1. v1
PR1698920 Security Director shows invalid configuration in the update configuration preview. v1
PR1744985 After upgrading Security Director to 23.1R1 release, report generation fails with an error. v1

NOTE: If the hot patch contains a UI fix, then you must clear the browser's cache to reflect the latest changes.

Known Issues in the Hot Patch

Junos Space Security Director Release 23.1R1 hot patch includes the following known issue:

The user is unable to update IPS Policy for multiple logical systems when one of the logical systems is configured with all-attack signature. The job fails with Device is down error message. PR1827871

Finding More Information

For the latest, most complete information about known and resolved issues with Junos Space Network Management Platform and Junos Space Management Applications, see the Juniper Networks Problem Report Search application at: http://prsearch.juniper.net.

Juniper Networks Feature Explorer is a Web-based application that helps you to explore and compare Junos Space Network Management Platform and Junos Space Management Applications feature information to find the correct software release and hardware platform for your network. Find Feature Explorer at: http://pathfinder.juniper.net/feature-explorer/.

Juniper Networks Content Explorer is a Web-based application that helps you explore Juniper Networks technical documentation by product, task, and software release, and download documentation in PDF format. Find Content Explorer at: http://www.juniper.net/techpubs/content-applications/content-explorer/.

Revision History

Revision History
Release Release Date Updates
Junos Space Security Director Release 23.1R1 Hot Patch V9 10 July, 2025—Revision 10 Added Resolved Issues
Junos Space Security Director Release 23.1R1 Hot Patch V8 27 February, 2025—Revision 9 Added Resolved Issues
Junos Space Security Director Release 23.1R1 Hot Patch V7 13 November, 2024—Revision 8 Added Resolved Issues and updated the Installation and Upgrade Instructions section.
Junos Space Security Director Release 23.1R1 Hot Patch V6 2 September, 2024—Revision 7 Added Resolved Issues
Junos Space Security Director Release 23.1R1 Hot Patch V5 6 August, 2024—Revision 6 Added the following in the Hot Patch:
• Resolved Issues
• Known Issues
Junos Space Security Director Release 23.1R1 Hot Patch V4 21 February, 2023—Revision 5 Added Resolved Issues
Junos Space Security Director Release 23.1R1 Hot Patch V3 14 December, 2023—Revision 4 Added the following in the Hot Patch:
• New and Enhanced Features
• Supported Devices
• Resolved Issues
Junos Space Security Director Release 23.1R1 Hot Patch V2 14 September, 2023—Revision 3 Added the following in the Hot Patch:
• New and Enhanced Features
• Supported Devices
Junos Space Security Director Release 23.1R1 Hot Patch V1 31 July, 2023—Revision 2 Added Resolved Issues
Junos Space Security Director Release 23.1R1 8 June, 2023—Revision 1 Intial Release Notes

Copyright © 2025 Juniper Networks, Inc. All rights reserved.

Juniper Networks, the Juniper Networks logo, Juniper, and Junos are registered trademarks of Juniper Networks, Inc. and/or its affiliates in the United States and other countries. All other trademarks may be the property of their respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice.

PDF preview unavailable. Download the PDF instead.

junos-space-release-notes-sd-23.1 Adobe PDF Library 25.1.51

Related Documents

Preview Juniper Networks Junos Space Security Director Release 23.1R1 Release Notes
This document provides release notes for Juniper Networks Junos Space Security Director Release 23.1R1, detailing new and changed features, supported devices and software, installation instructions, known behaviors, known issues, and resolved issues.
Preview Junos Space Security Director Release Notes 24.1R1
Release notes for Juniper Networks Junos Space Security Director version 24.1R1, detailing new and changed features, supported devices, compatibility, known behavior, and resolved issues.
Preview Juniper Advanced Threat Prevention Cloud User Guide
This user guide provides comprehensive instructions for configuring and monitoring Juniper Advanced Threat Prevention (ATP) Cloud features. Learn how to protect your network against evolving security threats using the ATP Cloud portal.
Preview Juniper Advanced Threat Prevention Cloud CLI Reference Guide
Comprehensive CLI reference for Juniper Advanced Threat Prevention Cloud, detailing configuration and operational commands for SRX Series devices. Essential for network security professionals.
Preview Juniper Networks Junos Space Security Director 21.1R1 Release Notes
Official release notes for Juniper Networks Junos Space Security Director version 21.1R1, detailing new features, supported devices and Junos OS releases, installation instructions, known issues, and resolved issues.
Preview Junos Space Security Director Release Notes 24.1
Release notes for Junos Space Security Director version 24.1, detailing new and changed features, supported devices, OS releases, known issues, and resolved issues.
Preview Juniper Advanced Threat Prevention Cloud Administration Guide
Configure, monitor, and manage Juniper ATP Cloud features to protect all hosts in your network against evolving security threats.
Preview Juniper Networks Security Director User Guide
Comprehensive guide to Juniper Networks Security Director for managing network security policies, threat detection, application visibility, and device configuration. Learn to implement firewall, UTM, IPS, VPN, and NAT policies.