When High-End SRX-Series chassis have policies with one or more ALG’s (application layer gateways) enabled, which are applied to in-transit traffic, this may trigger a number of failure conditions which could cause various types of denials of service to traffic in-transit. Continued in-transit traffic matching ALG rules can create a sustained denial of service. This issue affects both standalone or cluster mode configurations with different denial of service permutations. Standalone:
The following software releases have been updated to resolve this specific issue: Junos OS 12.1X46-D50, 12.1X47-D23, 12.1X47-D35, 12.3X48-D25, 15.1X49-D40 and subsequent releases. This issue is being tracked as PR 1150971 and is visible on the Customer Support website. KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.
The following workarounds may be used to mitigate, reduce or resolve the risk of the problem from occuring:
2016-07-13: Initial publication 2016-07-22: Added language that any and all ALG's are impacted by this JSA.