Description

This article explains whether the SD (Security Director )Cloud performs commit confirm on managed SRX devices or not, and when.

Symptoms

In the SRX device, 'show system commit' shows that the sduser, which is for SD Cloud, first performs commit confirmed and then commit.

In the example below, commit was performed within 5 seconds after the commit confirmed because the device sends the keepalive message or a response to SD Cloud.

 

0   2025-12-03 09:46:32 UTC by sduser via netconf
    EMS System Commit 8b353e69-e04f-4cb5-93f4-53861cf2f746 EMS_REQ_ID:f80fb0bf-e129-9c88-8bcc-a46ac6b19b67 confirmed commit
1   2025-12-03 09:46:23 UTC by sduser via netconf commit confirmed, rollback in 1mins
    EMS System Commit 8b353e69-e04f-4cb5-93f4-53861cf2f746 EMS_REQ_ID:f80fb0bf-e129-9c88-8bcc-a46ac6b19b67

Solution

How Commit Confirmed Works in Security Director Cloud:

 

Security Director Cloud uses a commit confirmed process when pushing configuration changes to managed SRX devices. After issuing a commit confirmed, the system waits for the device to acknowledge the commit within the configured Confirmed Commit Timeout (default: 60 seconds for Policy deployment).

If the device does not respond within this timeout, the configuration change is not applied, and the SRX device automatically rollback to its previously committed configuration.

 

Configuring the Confirmed Commit Timeout:

 

The Confirmed Commit Timeout value can be adjusted from the SD Cloud Portal > Organization settings.

 

NOTE: To avoid deployment issues, set the commit timeout to match the slowest device in your network. Find out how long the slowest device takes to commit and set the timeout to that time. For example, 120 seconds. This change only affects the specific SRX Series Firewall.

 

Modification History

2025-12-09 : Article Created

Related Information

Security Director Cloud User Guide