This article describes an issue where the Security Director Cloud deletes security policies from the SRX firewall, causing outages after the SD Cloud upgrade.
SD Cloud randomly deletes Firewall Policies from the managed SRX device(s), causing an outage.
The issue is happening in cases where the device has multiple policies and multiple policies are selected for deployment, and only in certain cases.
For example, For a given device, if there were 3 policies P1, P2, P3 deployed to device (before 24.4 upgrade) and new policy P4(after 24.4 upgrade) is created.
Rule deletion issue is seen in below cases:
For ex: User deploys P1 to the device successfully and later selects P1 & P2/P3. This is causing the policies of P1 to be deleted.
The recent 24.4(Upgraded on March 27th) upgrade included policy performance-related improvements.
During combination of existing and new policy deployments, rules for existing policies are incorrectly getting marked as deleted and causing the above issue.
Workaround: While Juniper is working on the fix, below workarounds can be used if the device has multiple policies:
Either you can delete the device from SD Cloud and re-discover it, and then assign all the policies back to the device and then deploy, or you can try to follow below:
(Note: This needs to be done only for the very first time, and in subsequent deploys, we can deploy multiple policies in any combination).
(Note: This needs to be done only for the very first time, and in subsequent deploys, we can deploy multiple policies in any combination ).