This article goes over a common issue on new SRX deployments on Mist.
Traffic is bypassing our custom security policies entirely. Security policy logs and flow session lookups show zero hit counts on the intended rules. Instead, the firewall engine evaluates the traffic all the way down the line, resulting in drops caught by the global implicit default policy (default-policy-logical-system-00/2 or default-policy deny-all).
On the WAN Edge configuration, Application Visibility, set the the option to "Device HAS an APP Track license".
If set to "Use site setting...", then go to Site Configuration and set "My SRX devices have an App Track license".
After saving this, the SRX will take about an hour to update, if this is needed faster, you can download manually the App-Track Database via CLI commands:
request services application-identification download
request services application-identification download status
request services application-identification install