Description

This article describes a condition where Security Director Cloud (SDC) deletes a firewall policy associated with a managed SRX device, leading to a service outage. The policy is automatically flagged for deletion by SDC when the firewall policy itself is deleted or when the managed SRX device is unassigned from that policy.

Symptoms

A firewall policy on a managed SRX device is unexpectedly deleted by Security Director Cloud (SDC), resulting in traffic outage or service disruption.

 

This can occur in the following situations:

  • The firewall policy is manually deleted in SDC.
  • The SRX device is unassigned from the firewall policy in SDC, causing the policy to be flagged for deletion.

Solution

Note: Security Director Cloud (SDC) provides a clear warning message stating that “Policy configuration will be deleted from the unselected device(s) as well” when a deployment action is initiated. Administrators should carefully review this warning before proceeding with the Deploy operation.

Sample:


The corresponding job entry (e.g., undeploy-firewall-policies) indicates that SDC will remove all associated rules from the device. It is considered best practice to always review the Delta / View Configuration prior to deployment. This view displays the exact configuration changes that SDC plans to push to the managed device, helping prevent unintended policy removal or outages. This behavior and the associated warnings are documented in the Security Director Cloud User Guide

 

Workaround:

To prevent this issue from occurring in the future, follow the steps below when replacing or re-importing firewall policies in Security Director Cloud (SDC):

a. Ensure the existing security policy is already imported and in sync with SDC.

b. If you plan to delete the existing policy and import a fresh policy from the device:

  • Import the new (fresh) firewall policy into SDC.
  • After the import, delete the older firewall policy.
  • When the old policy is deleted, SDC will automatically flag it for removal from the device.

 

c. Before deployment:

  • Confirm that the newly imported firewall policy has the intended device assigned.
  • Select both the old (flagged) and new policies for the device during deployment.
  • Review the Delta / View Configuration carefully to verify the exact changes SDC will push to the device.
  • Only proceed with deployment once the expected configuration is confirmed.



d. Example: Refer to the image below for the Preview / Delta view showing the configuration changes that Security Director Cloud (SDC) will apply to the managed vSRX-JTAC-LAB device. This preview helps verify rule additions, deletions, or policy modifications before deployment.

If you face any further issues, please contact JUNIPER JTAC Support for assistance.

Modification History

2025-11-03 : Article Created