The Junos OS on SRX devices can be upgraded and downgraded using the following CLI commands.
On SRX5K-RE3-128G / SRX1600 / SRX2300 / SRX4300:
request vmhost software add <Junos_upgrade_image_file_name>
On all other SRX devices:
request system software add <Junos_upgrade_image_file_name>
From which releases to which other releases a direct upgrade is supported is defined in the Junos upgrade/downgrade policy, documented in the Release-Notes document of the Junos releases.
This article explains the Junos upgrade/downgrade policy and exceptions for SRX platforms. This aims to help you find the best upgrade path for your SRX device.
The Junos upgrade/downgrade policy is documented in Release-Notes as the follows.
To summarize, this means the following rule applies:
EEOL stands for Extended End-of-Life. EEOL releases are Junos releases which receive Engineering support for three years or more. You can see which releases are EEOL on Junos OS Dates & Milestones by looking at the dates at "FRS Date" (First Release Shipping Date) and "End of Engineering".
From Junos 23.x onwards, only the even numbered releases (xx.y, where y is 2 or 4) are getting released and posted to the Juniper Downloads site. See TSB70981 [juniper.net] for more information. These can generally all be considered as EEOL releases.From Junos 20.1 to 22.4, generally, only the even numbered releases (xx.y, where y is 2 or 4) are EEOL releases. The uneven releases, (xx.y, where y is 1 or 3) are non-EEOL releases.From Junos 17.3 to Junos 19.4, all releases are EEOL releases.Junos 15.1X49 was an EEOL release.
- Additional direct upgrade paths have been qualified
- From Junos 12.3X48, direct upgrade to releases higher than Junos 15.1X49 is not supported.
To make it easy to lookup for each Junos release for SRX from which earlier releases it is supported to directly upgrade to it, please see the below table.Before performing the upgrade, please make sure to check the Notes section below for possible caveats and limitations which may apply.
To upgrade your SRX device from Junos 21.4R3 to 24.2R1Path: 21.4R3 --> 22.4R3 --> 24.2R1To upgrade your SRX device from Junos 21.4R3 to 23.4R2-S3Path: 21.4R3 --> 22.4R3 --> 23.4R2-S3To upgrade your SRX device from Junos 19.4R3 to 22.2R1Path: 19.4R3 --> 20.4R3 --> 21.4R2 --> 22.2R1 (*3,4)To upgrade your SRX device from Junos 18.2R3 to 20.4R1Path: 18.2R3 --> 18.4R3 --> 19.4R3 --> 20.4R1To upgrade your SRX device from Junos 17.4R3 to 19.4R3-S2Path: 17.4R3 --> 18.2R3 --> 18.4R3 --> 19.4R3-S2To upgrade your SRX device from Junos 15.1X49-D170 to 20.4R1Path: 15.1X49-D170 --> 19.4R3 --> 20.4R1Note: Instead of upgrading Junos, another option is to fresh install the SRX device using an install-media image of the target release, which does not have any requirements regarding previously installed Junos release.
For details on ISSU and ICU support on SRX platforms, refer to KB17946 [juniper.net] - [SRX] ISSU/ICU upgrade limitations on SRX firewalls
For finding Suggested Releases to Consider and Evaluate, see the SRX section of KB21476 - Junos Software Versions - Suggested Releases to Consider and Evaluate [juniper.net]
TSB92728 [juniper.net] - SRX300-series requirements for upgrade to Junos 24.4R1 and higher from earlier releases.
TSB18251 [juniper.net] / PR1568757 - For upgrades to Junos version 21.2 or higher from Junos versions below 21.2, the no-validate option needs to be used in the request system software upgrade or the request system software in-service-upgrade command. Note: this does not apply to SRX300 series and SRX550HM.
PR1590099 - The no-validate option with the request system software in-service-upgrade command does not take effect on SRX platforms. As a workaround, use the no-compatibility-check option instead. This issue is fixed in Junos 20.3R3-S5, 20.4R3-S4, 21.1R3-S3 and 21.2R1 and higher releases
Notes for upgrading from Junos 15.1X49 releases to 19.4R3 or 19.4R3 based Service Releases:
Junos OS upgrade from 15.1X49 directly to 19.4R3 or 19.4R3 based Service Releases is supported for all SRX platforms (ISSU is not supported). Note: for SRX5000 series, do not use 19.4R3-S2 or 19.4R3-S9 and higher in this upgrade path as the upgrade would fail (using 19.4R3-S3 up to S8 will work as expected).
In case you would need to roll back or downgrade from 19.4 to the 15.1X49 release on SRX1500, SRX4100/4200, SRX5k, or vSRX, all files on the device may be lost. Hence it is important to back up the relevant files (configuration, license-keys, etc) before the upgrade and have console access during the upgrade and during a potential rollback if required.
For vSRX the following limitations apply when upgrading from 15.1X49 directly to 19.4R3 or 19.4R3 based Service Releases:
The file system mounted on /var usage must be below 14% of capacity.Check this withroot@vsrx> show system storage | match " /var$" /dev/vtbd1s1f 2.7G 82M 2.4G 3% /var Note: The CLI command ‘request system storage cleanup’ may help reach that percentage if needed
root@vsrx> show system storage | match " /var$" /dev/vtbd1s1f 2.7G 82M 2.4G 3% /var
The Junos upgrade image must be placed in the directory /var/host-mnt/var/tmp/request system software add /var/host-mnt/var/tmp/
request system software add /var/host-mnt/var/tmp/
It is recommended to deploy a new vSRX VM instead of performing a Junos upgrade. That also gives the option to move from vSRX to the newer and more recommended vSRX 3.0.
ISSU is not supported when upgrading from Junos 15.1X49 to any higher versions.
KB34945 [juniper.net] - When Junos Space Security Director is used for managing the SRX configuration and the AppFW, IDP, or UTM features are used, then when upgrading to Junos 18.2R1 or higher, the SRX configuration needs to be migrated to the new Unified Policies style and Security Director version 19.3 or higher is required.
Starting with Junos OS Release 17.3, when you upgrade from Junos OS Release 15.1X49 to Junos OS Release 17.3 or higher, or downgrade from Junos OS Release 17.3 or higher to Junos OS Release 15.1X49, you must update the IPS signature package by downloading and installing the IPS signature package update.
Junos 21.4 is the last supported version for SRX5000 Series 2nd Generation Hardware: RE2, SPC2, IOC2, SCB2 (SCBE) and chassis with non-enhanced midplane. For details, please see the Hardware EOL overview.
Junos 22.2 is the last supported version for SRX550HM. For details see TSB69677 [juniper.net].
Junos 22.4 is the last supported version for the legacy vSRX (2.0) architecture. Please use vSRX 3.0 instead. For details see TSB69852 [juniper.net].
2026-03-18: Corrected a typo in the upgrade command request vmhost software add. 2026-01-08: Added a note on where to find the status of FIPS and Common Criteria releases.2025-08-25: Updated the article with command to check the upgrade path from SVL server2025-07-11: Updated the article with the latest Junos release.2025-01-10: Updated the article with Junos 24.4 and added the note regarding the SRX300-series limitation for upgrade path and methods (TSB92728 [juniper.net]).2024-12-09: Updated the article with latest Junos releases2024-04-08: Updated Note 4 to inform that only for SRX5k, a direct upgrade from 15.1X49 to 19.4R3-S9+ will not work. Upgrade to S3-S8 will work as expected, hence it is recommended to use that in the upgrade path.2023-12-18: Added the Upgrade Table and updated the article with the latest Junos releases information. Also added a note regarding the SRX550HM last supported version.2022-10-20: Added notes wrt the last supported version for certain SRX5k parts and vSRX (2.0).2022-08-23: Updated some upgrade paths and notes.2020-10-14: Added related link to "Upgrade to Junos OS Release 19.4R3 and 20.2R3 for SRX Series".
request vmhost software add