As part of the hardening changes made to DCOM, recent Microsoft updates for newer Windows systems will enforce an Authentication-Level of RPC_C_AUTHN_LEVEL_PKT_INTEGRITY or higher for activation. This level will prevent the SRX from opening a WMI communication channel to patched systems unless the SRX is upgraded to a Junos release that supports it.According to Microsoft KB5004442 [juniper.net] , the hardening changes will be enabled by default in Q1 2022. The changes can be disabled using a registry key. However, the hardening changes will be permanently enabled with no ability to disable them starting in Q2 2022.To prevent impact to services provided by the Integrated User Firewall as a result of the hardening changes, actions are required on the SRX in the short and long term timelines.
The short term solution is to disable the hardening changes applied by the Microsoft Update. The steps, which involves changing the value of the registry key RequireIntegrityActivationAuthenticationLevel , can be found in Microsoft's KB article here: https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c [juniper.net]The longer term solution is to upgrade to a Junos release that will support the hardened authentication level. Please note that as per the KB article, Microsoft announced to remove the ability to disable the higher authentication level requirement in an update in Q2 of 2022. Therefore, a Junos upgrade is mandatory to ensure uninterrupted service with Integrated User Firewall (with AD integration) on the SRX.For SRX300-series and SRX550M, the fix is available in Junos releases 20.2R3-S8, 20.4R3-S8, 21.2R3-S6, 22.4R3, 23.2R1 and higher releases. Please refer to PR-1683420 for the complete list.For all other SRX and NFX platforms, the fix is available in Junos releases 19.4R3-S8, 20.4R3-S3, 21.2R3, 21.3R2, 21.4R2, 22.1R1 and higher releases. Please refer to PR-1637548 for the complete list.
2023-07-13: Updated TSB to add the PR1683420 fixed releases specifically for SRX Branch platforms.2022-02-28: Updated TSB to reflect that the fix is available on the latest Junos releases.2022-05-25: Added to the FAQ and updated the list of fixed releases.