When using JSC 24.4.14 or later to connect to an SRX device running Junos OS 23.x, the connection fails and JSC displays the following error: "Invalid vpn_connection_token value"
The following log entries may be observed in the JSC logs:
Configuration download: JuniperLogin: Start with auth-method password
Configuration download: JuniperLogin: Invalid vpn_connection_token value
ERROR - Configuration download: JuniperLogin: Invalid vpn_connection_token value
ERROR - Configuration download: Finished with error -> JuniperLogin: Invalid vpn_connection_token value
Configuration download: JuniperLogin: Login succeeded
MONITOR: LMC - Connection failed, logon time expired
Although the login process may initially succeed, JSC is unable to complete the connection and configuration download. As a result, the session eventually times out, and the connection fails with the "Invalid vpn_connection_token value" error.
This is a known issue. The problem occurs because Trusted Network Detection (TND) is not supported on Junos OS 23.x releases, which can cause JSC 24.4.14 and later versions to fail with the "Invalid vpn_connection_token value" error.
The issue has been resolved in the following Junos OS releases: 23.2R1, 23.4R2-S4, 24.2R2 and later. For the complete list of affected and fixed releases, refer to PR1719565.
If upgrading the SRX device to a fixed Junos OS release is not currently possible, use a JSC version earlier than 24.4.14 as a temporary workaround.
2025-09-24 : Article Created2026-07-25 : Fixed the format and Rewritten the content for better clarity