SRX dropped the received ISAKMP packet that had been fragmented. This packet reached a length of 1902 bytes due to its X-509 certificate payload and was consequently fragmented by the upstream network device.
Remove or deactivate below screen options:
set security screen ids-option anti-attack ip block-frag
https://www.juniper.net/documentation/us/en/software/junos/denial-of-service/topics/topic-map/security-ip-attack.html#id-example-dropping-fragmented-ip-packets
https://www.juniper.net/documentation//us/en/software/junos/cli-reference/topics/ref/statement/security-edit-ip-screen.html
New article created