Managed SRX devices are unable to retrieve the IDP signature package through SD Cloud. When the device relies on a routing instance for outbound connectivity, the signature download initiated by SD Cloud fails. The SD Cloud UI reports a download failure, and device-side NETCONF trace options show errors during the curl execution of the sigpack download command.
Error snippet from SRX device netconf traceoption for the reference:
May 2 04:51:48 [NETCONF] - [98853] Outgoing: <output>May 2 04:51:48 [NETCONF] - [98853] Outgoing: ld-elf32.so.1: /usr/lib32/nss_vrf.so.1: Undefined symbol "rtslib_open"
SD Cloud currently does not support the use of routing-instances when delivering IPS/IDP signature packages to managed devices.Because the SDC-initiated file download is not VRF-aware, the device cannot complete the signature retrieval when a routing-instance is required for external connectivity. Support for routing-instances in SD Cloud signature delivery is targeted for SDC 25.3 (Q4 release Tentively ).
Until routing-instance support is available natively, use the following workaround:
Workaround: Configure signature updates directly on each SRX
For each affected SRX device that uses a routing-instance for internet access:
This ensures the SRX keeps its signature database updated automatically, bypassing the need for SD Cloud to install signatures manually.
If you face any further issues, please contact JUNIPER JTAC Support for assistance.