Description

This informational article provides information on how to enroll the SRX cluster devices to SkyATP. Need to verify some key points before start enrolling the SRX Hardware firewalls cluster.

Solution

Before enrolling your devices with the Juniper SkyATP cloud, set up your HA cluster as described in your HA product documentation. For vSRX deployments, make sure that a separate ATP license key is applied to each node on the cluster.  When enrolling your devices, you only need to enroll primary node. The Juniper SkyATP cloud will recognize this is an HA cluster and will automatically enroll the secondary node.

Both devices, however, must be licensed accordingly. For example, if you want premium features, both devices must be entitled with the premium license.

On occasion, because of hardware failure, a device needs to be returned for repair or replacement. For these cases, contact Juniper Networks, Inc. to obtain a Return Material Authorization (RMA) number and follow the RMA Procedure.

Once you transfer your license keys to the new device, it may take up to 24 hours for the new serial number to be registered with the Juniper SkyATP cloud service.

After any serial number change on the SRX Series device, a new RMA serial number needs to be re-enrolled with Juniper SkyATP cloud. This means that you must enroll your replacement unit as a new device. Juniper SkyATP does not have an “RMA state”, and does not see these as replacement devices from a configuration or registration point of view. Data is not automatically transferred to the replacement SRX Series device from the old device.

Enroll procedure for cluster nodes in case of RMA :
  1. Replace the faulty device with new device in the cluster by following the information provided in [SRX] RMA replacement of a node in a Chassis Cluster
  2. Once the cluster is stable, disenroll the primary device from SkyATP cloud using the procedure mentioned in [Sky ATP] How to disenroll an SRX device from the ATP cloud
  3. Enroll the Primary device to SkyATP cloud so that SkyATP cloud can fetch the new device information.
    NOTE: The RMA device added to cluster doesn't have to be primary for SkyATP to fetch the new serial number and device information.

Modification History

2023-09-11: Added RMA replacement of a node in a Chassis Cluster procedure and SkyATP Disenroll procedure links. Updated vSRX license note to reflect a separate license per node. Removed outdated note related to active-active not being supported

 

2025-11-21: Removed the link which was not working and added the correct link.
 

 

Related Information