Description

The TCP session cannot be established in the PMI path for IPSec sessions with a non-Juniper device if the packet is less than 64 bytes the sender will add padding. If padding is not removed, the application will not be able to process the packet resulting in packet drop.

Symptoms

On SRX4K series, and vSRX platforms with PMI (Power-mode) enabled, when using IPSec tunnels, IPSec packets sent out by the SRX that contain a small IP packet (less than 64 bytes) may be dropped by a non-Juniper IPSec VPN peer. Power-mode is enabled by default in Junos 21.3R1 and higher.

Solution

Please upgrade to a fixed version as per PR1692885:

https://prsearch.juniper.net/problemreport/PR1692885

 

Workaround:

Disable power-mode:

-For Junos release 21.3R1 and higher:

 set security flow power-mode-disable

-For Junos release below 21.3R1: 

delete security flow power-mode-ipsec

 

Note: The IPSec tunnels will bounce when disabling PMI.

Modification History

2023-09-24 Updated

2025-05-30 The format has been updated.

 

Related Information

Enable PowerMode IPsec processing. PMI is a new mode of operation that provides IPsec performance improvements.

For SRX4100, SRX4200 devices running Junos OS Release 18.4R1, SRX4600 devices running Junos OS Release 20.4R1, and vSRX Virtual Firewall instances running Junos OS Release 18.3R1, you can enable or disable the PMI. Starting in Junos OS Release 21.1R1, you can enable or disable the PMI on MX-SPC3 services card.

If you use Junos OS Release 18.3R1, you must reboot the device for the configuration to take effect.

From Junos OS Release 18.4R1 and later, you don’t need reboot the device after enabling or disabling this feature.

Packets cannot go through the PMI when firewall or advanced security services are combined with IPsec. Hence, PMI must not be used when firewall or advanced security services are combined with IPsec.

https://www.juniper.net/documentation/us/en/software/junos/vpn-ipsec/topics/ref/statement/security-flow-power-mode-ipsec.html