Description

The Junos OS on SRX devices can be upgraded and downgraded using the following CLI commands.

On SRX5K-RE3-128G / SRX1600 / SRX2300 / SRX4300:

request vmhost software add <Junos_upgrade_image_file_name>


On all other SRX devices:

request system software add <Junos_upgrade_image_file_name>

From which releases to which other releases a direct upgrade is supported is defined in the Junos upgrade/downgrade policy, documented in the Release-Notes document of the Junos releases.

This article explains the Junos upgrade/downgrade policy and exceptions for SRX platforms. This aims to help you find the best upgrade path for your SRX device.

Solution

Junos upgrade/downgrade policy

The Junos upgrade/downgrade policy is documented in Release-Notes as the follows.

"Support for upgrades and downgrades that span more than three Junos OS releases at a time is not provided, except for releases that are designated as Extended End-of-Life (EEOL) releases. EEOL releases provide direct upgrade and downgrade paths. You can upgrade directly from one EEOL release to the next EEOL release even though EEOL releases generally occur in increments beyond three releases. You can upgrade or downgrade to the EEOL release that occurs directly before or after the currently installed EEOL release, or to two EEOL releases before or after."


To summarize, this means the following rule applies:

  • From any release, you can jump a maximum of three (3) releases up/down.
  • From EEOL releases you can jump a maximum of two (2) EEOL releases up/down.

 

What are EEOL releases

EEOL stands for Extended End-of-Life. EEOL releases are Junos releases which receive Engineering support for three years or more. You can see which releases are EEOL on Junos OS Dates & Milestones by looking at the dates at "FRS Date" (First Release Shipping Date) and "End of Engineering".

From Junos 23.x onwards, only the even numbered releases (xx.y, where y is 2 or 4) are getting released and posted to the Juniper Downloads site. See TSB70981 [juniper.net] for more information. These can generally all be considered as EEOL releases.
From Junos 20.1 to 22.4, generally, only the even numbered releases (xx.y, where y is 2 or 4) are EEOL releases. The uneven releases, (xx.y, where y is 1 or 3) are non-EEOL releases.
From Junos 17.3 to Junos 19.4, all releases are EEOL releases.
Junos 15.1X49 was an EEOL release.
 

Exceptions to the rule

- Additional direct upgrade paths have been qualified

  • From Junos 15.1X49 directly to 19.4R3 or 19.4R3 based Service Releases is supported for all SRX platforms (ISSU is not supported).  (*5)
  • From Junos 15.1X49 directly to 18.4R3 or 18.4R3 based Service Releases is supported for all SRX platforms (ISSU is not supported).  (*5)
  • From Junos 18.4R3 or 18.4R3 based Service Releases directly to 19.4R3 or 19.4R3 based Service Releases is supported for all SRX platforms.

- From Junos 12.3X48, direct upgrade to releases higher than Junos 15.1X49 is not supported.



Upgrade table 

To make it easy to lookup for each Junos release for SRX from which earlier releases it is supported to directly upgrade to it, please see the below table.

Before performing the upgrade, please make sure to check the Notes section below for possible caveats and limitations which may apply.
 

Target Junos releaseDirect upgrade supported from
25.425.2, 24.4, 24.2
25.224.4, 24.2, 23.4
24.4(*2)24.2, 23.4, 23.2
24.223.4, 23.2, 22.4
23.423.2, 22.4, 22.3
23.222.4, 22.3, 22.2
22.422.3, 22.2, 22.1, 21.4
22.322.2, 22.1, 21.4
22.222.1, 21.4, 21.3, 21.2
22.121.4, 21.3, 21.2
21.421.3, 21.2, 21.1, 20.4
21.321.2, 21.1, 20.4
21.221.1, 20.4, 20.3, 20.2
21.120.4, 20.3, 20.2
20.420.3, 20.2, 20.1, 19.4
20.320.2, 20.1, 19.4
20.220.1, 19.4, 19.3, 19.2
20.119.4, 19.3, 19.2
19.419.3, 19.2, 19.1, 18.4, 15.1X49
19.319.2, 19.1, 18.4
19.219.1, 18.4, 18.3, 18.2
19.118.4, 18.3, 18.2
18.418.3, 18.2, 18.1, 17.4, 15.1X49
18.318.2, 18.1, 17.4
18.218.1, 17.4, 17.3
18.117.4, 17.3
17.417.3, 15.1X49
17.315.1X49
15.1X4912.3X48


 

Examples of upgrade paths


To upgrade your SRX device from Junos 21.4R3 to 24.2R1
Path: 21.4R3 --> 22.4R3 --> 24.2R1

To upgrade your SRX device from Junos 21.4R3 to 23.4R2-S3
Path: 21.4R3 --> 22.4R3 --> 23.4R2-S3

To upgrade your SRX device from Junos 19.4R3 to 22.2R1
Path: 19.4R3 --> 20.4R3 --> 21.4R2 --> 22.2R1  (*3,4)

To upgrade your SRX device from Junos 18.2R3 to 20.4R1
Path: 18.2R3 --> 18.4R3 --> 19.4R3 --> 20.4R1

To upgrade your SRX device from Junos 17.4R3 to 19.4R3-S2
Path: 17.4R3 --> 18.2R3 --> 18.4R3 --> 19.4R3-S2

To upgrade your SRX device from Junos 15.1X49-D170 to 20.4R1
Path: 15.1X49-D170 --> 19.4R3 --> 20.4R1


Note: Instead of upgrading Junos, another option is to fresh install the SRX device using an install-media image of the target release, which does not have any requirements regarding previously installed Junos release.

 

ISSU / ICU

For details on ISSU and ICU support on SRX platforms, refer to  KB17946 [juniper.net]  - [SRX] ISSU/ICU upgrade limitations on SRX firewalls

 

Notes

  1. For finding Suggested Releases to Consider and Evaluate, see the SRX section of KB21476 - Junos Software Versions - Suggested Releases to Consider and Evaluate [juniper.net]

  2. TSB92728 [juniper.net] - SRX300-series requirements for upgrade to Junos 24.4R1 and higher from earlier releases.

  3. TSB18251 [juniper.net] / PR1568757 - For upgrades to Junos version 21.2 or higher from Junos versions below 21.2, the no-validate option needs to be used in the request system software upgrade or the request system software in-service-upgrade command. Note: this does not apply to SRX300 series and SRX550HM.

  4. PR1590099 - The no-validate option with the request system software in-service-upgrade command does not take effect on SRX platforms. As a workaround, use the no-compatibility-check option instead. This issue is fixed in Junos 20.3R3-S5, 20.4R3-S4, 21.1R3-S3 and 21.2R1 and higher releases

  5. Notes for upgrading from Junos 15.1X49 releases to 19.4R3 or 19.4R3 based Service Releases:

    • Junos OS upgrade from 15.1X49 directly to 19.4R3 or 19.4R3 based Service Releases is supported for all SRX platforms (ISSU is not supported). Note: for SRX5000 series, do not use 19.4R3-S2 or 19.4R3-S9 and higher in this upgrade path as the upgrade would fail (using 19.4R3-S3 up to S8 will work as expected).

    • In case you would need to roll back or downgrade from 19.4 to the 15.1X49 release on SRX1500, SRX4100/4200, SRX5k, or vSRX, all files on the device may be lost. Hence it is important to back up the relevant files (configuration, license-keys, etc) before the upgrade and have console access during the upgrade and during a potential rollback if required.

    • For vSRX the following limitations apply when upgrading from 15.1X49 directly to 19.4R3 or 19.4R3 based Service Releases:

      • The file system mounted on /var usage must be below 14% of capacity.
        Check this with
        root@vsrx> show system storage | match " /var$"
        /dev/vtbd1s1f 2.7G 82M 2.4G 3% /var

        Note: The CLI command ‘request system storage cleanup’ may help reach that percentage if needed

      • The Junos upgrade image must be placed in the directory /var/host-mnt/var/tmp/
        request system software add /var/host-mnt/var/tmp/

      • It is recommended to deploy a new vSRX VM instead of performing a Junos upgrade. That also gives the option to move from vSRX to the newer and more recommended vSRX 3.0.
         

    • ISSU is not supported when upgrading from Junos 15.1X49 to any higher versions.

    • KB34945 [juniper.net] - When Junos Space Security Director is used for managing the SRX configuration and the AppFW, IDP, or UTM features are used, then when upgrading to Junos 18.2R1 or higher, the SRX configuration needs to be migrated to the new Unified Policies style and Security Director version 19.3 or higher is required.

    • Starting with Junos OS Release 17.3, when you upgrade from Junos OS Release 15.1X49 to Junos OS Release 17.3 or higher, or downgrade from Junos OS Release 17.3 or higher to Junos OS Release 15.1X49, you must update the IPS signature package by downloading and installing the IPS signature package update.

  6. Junos 21.4 is the last supported version for SRX5000 Series 2nd Generation Hardware: RE2, SPC2, IOC2, SCB2 (SCBE) and chassis with non-enhanced midplane. For details, please see the Hardware EOL overview.

  7. Junos 22.2 is the last supported version for SRX550HM. For details see TSB69677 [juniper.net].

  8. Junos 22.4 is the last supported version for the legacy vSRX (2.0) architecture. Please use vSRX 3.0 instead. For details see TSB69852 [juniper.net].

  9. If you require FIPS or Common Criteria certified releases, you can view the status of those releases at the Compliance Advisor pages for FIPS and Common Criteria.

Modification History

2026-03-18: Corrected a typo in the upgrade command request vmhost software add
2026-01-08: Added a note on where to find the status of FIPS and Common Criteria releases.
2025-08-25: Updated the article with command to check the upgrade path from SVL server
2025-07-11: Updated the article with the latest Junos release.
2025-01-10: Updated the article with Junos 24.4 and added the note regarding the SRX300-series limitation for upgrade path and methods (TSB92728 [juniper.net]).
2024-12-09: Updated the article with latest Junos releases
2024-04-08: Updated Note 4 to inform that only for SRX5k, a direct upgrade from 15.1X49 to 19.4R3-S9+ will not work. Upgrade to S3-S8 will work as expected, hence it is recommended to use that in the upgrade path.
2023-12-18: Added the Upgrade Table and updated the article with the latest Junos releases information. Also added a note regarding the SRX550HM last supported version.
2022-10-20: Added notes wrt the last supported version for certain SRX5k parts and vSRX (2.0).
2022-08-23: Updated some upgrade paths and notes.
2020-10-14: Added related link to "Upgrade to Junos OS Release 19.4R3 and 20.2R3 for SRX Series".

Related Information