This article describes a condition where Security Director Cloud (SDC) deletes a firewall policy associated with a managed SRX device, leading to a service outage. The policy is automatically flagged for deletion by SDC when the firewall policy itself is deleted or when the managed SRX device is unassigned from that policy.
A firewall policy on a managed SRX device is unexpectedly deleted by Security Director Cloud (SDC), resulting in traffic outage or service disruption.
This can occur in the following situations:
Note: Security Director Cloud (SDC) provides a clear warning message stating that “Policy configuration will be deleted from the unselected device(s) as well” when a deployment action is initiated. Administrators should carefully review this warning before proceeding with the Deploy operation.
Sample:
The corresponding job entry (e.g., undeploy-firewall-policies) indicates that SDC will remove all associated rules from the device. It is considered best practice to always review the Delta / View Configuration prior to deployment. This view displays the exact configuration changes that SDC plans to push to the managed device, helping prevent unintended policy removal or outages. This behavior and the associated warnings are documented in the Security Director Cloud User Guide.
Workaround:
To prevent this issue from occurring in the future, follow the steps below when replacing or re-importing firewall policies in Security Director Cloud (SDC):
a. Ensure the existing security policy is already imported and in sync with SDC.
b. If you plan to delete the existing policy and import a fresh policy from the device:
c. Before deployment:
d. Example: Refer to the image below for the Preview / Delta view showing the configuration changes that Security Director Cloud (SDC) will apply to the managed vSRX-JTAC-LAB device. This preview helps verify rule additions, deletions, or policy modifications before deployment.
If you face any further issues, please contact JUNIPER JTAC Support for assistance.