On certain Juniper SRX platforms running Junos OS 24.4R1, site‑to‑site IPsec VPN traffic may intermittently stop forwarding when Class of Service (CoS) is configured on the secure tunnel (st0) interface.
In this condition, the VPN tunnel remains established and routing and security policies are correct; however, encrypted traffic is not transmitted out of the st0 interface. Flow sessions are successfully created and packet processing proceeds through encryption, but packets are silently dropped in the forwarding path.
The issue occurs intermittently and persists until a disruptive recovery action such as a reboot or changing the st0 unit number is performed.
This behavior is tracked by Juniper under Problem Report PR1901732.
When the issue occurs, the following symptoms may be observed:
Traffic forwarding is restored only after:
The issue is intermittent and may recur every few days.
Workaround:
Remove or avoid configuring CoS on the st0 interfaceReboot the affected SRX deviceChange the st0 interface unit number
Note:
Reboots and st0 unit number changes are disruptive and provide only temporary relief.Simply disabling and re‑enabling the st0 interface does not resolve the issue.
Solution:
Upgrade to a Junos OS release that includes the fix for PR1901732, which corrects the packet forwarding behavior when CoS is configured on the st0 interface.junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.4R1 junos:25.4R2 junos:26.1R1