Description

This article explains the reasons why the SecIntel feed download via Policy Enforcer appears as expired.

Symptoms

During the issue, while downloading the SecIntel feed, the downloaded feeds appear as expired. This can be observed in the following output:

root@srx> request services security-intelligence download status  
node0:  
--------------------------------------------------------------------------  
Security Intelligence feed download status:  
Start time: Fri Feb 21 05:33:27 2025  
Start downloading the latest manifest.  
Start parsing the manifest file.  
Start handling new category: Blacklist.  
Start downloading the schema for the Blacklist category.  
Start parsing the schema for the Blacklist category.  
Successfully parsed schema version 8fd10593fa for the Blacklist category.  
Start handling new feed `blacklist_ip` in root-logical-system `junos-default-vrf` under the Blacklist category.  
Feed `blacklist_ip` (20211227.4) in root-logical-system `junos-default-vrf` under the Blacklist category is expired.  

Solution

This issue typically occurs when the policy-enforcer is unable to download the latest feeds from the ATP cloud. As a result, the available feeds become outdated or expired. 

To resolve this issue:  

1. Verify the connectivity between the policy-enforcer and the ATP cloud.  

2. If connectivity is established but the issue persists, contact Juniper Technical Assistance Center (JTAC) for further support.  

Modification History

2025-02-24 : Article Created