Description

SRX Series Firewall that supports junos-ike package to run the IPsec VPN service using the iked process.

As a result, iked and ikemd process runs on the routing engine by default instead of IPsec key management daemon (kmd).

    Symptoms

    .

    Solution

    Platform

    Junos OS Release with junos-ike Package

    SRX5K-SPC3 with RE3

    19.4R1 and later as default package

    SRX5K-SPC3 with RE2

    18.2R1 and later as optional package

    vSRX Virtual Firewall

    20.3R1 and later as optional package

    SRX1500

    22.3R1 and later as optional package

    SRX4100, SRX4200, SRX4600

    22.3R1 and later as optional package

    SRX1600, SRX2300, SRX4300

    23.4R1 and later as default package

     

    • SHA 512-bit IKE authentication algorithm under IKE Settings for Site-Site to VPN, NCP Exclusive Client and Juniper Secure Connect. Juniper Networks® SRX Series Firewalls use these authentication algorithms to verify the authenticity and integrity of a packet.


    To enable the IKED in case the user wants to use this:

    root@srx> request system software add optional://junos-ike.tgz
    Verified junos-ike signed by PackageProductionECP256_2024 method ECDSA256+SHA256

    The command is hidden, so it needs to be manually entered.

    As of now this feature is still not supported for branch devices.

    Modification History

    8/22/2024: Format change.

    06/26/2025: Small update about branch SRX.

    Related Information

    https://www.juniper.net/documentation/us/en/software/junos/vpn-ipsec/topics/topic-map/security-ipsec-vpn-overview.html
    https://www.juniper.net/documentation/us/en/software/junos/release-notes/23.4/junos-release-notes-23.4r1/topics/new-features/feature-descriptions/jweb-3.html
    https://www.juniper.net/documentation/us/en/software/junos/vpn-ipsec/topics/topic-map/security-ipsec-vpn-overview.html