Support Support Downloads Knowledge Base Juniper Support Portal Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

[EOL/EOE] [NSM] Cannot manage transparent firewall in FIPS mode



Article ID: KB27971 KB Last Updated: 17 Oct 2020Version: 3.0

Note: A product listed in this article has either reached hardware End of Life (EOL) OR software End of Engineering (EOE).  Refer to End of Life Products & Milestones for the EOL, EOE, and End of Support (EOS) dates.

This article describes why a firewall device running in transparent mode (L2) with Federal Information Processing Standards (FIPS) mode enabled cannot be managed via NSM.


A firewall is running in transparent mode (L2) with FIPS mode enabled.  The device cannot be managed via NSM.


This is a limitation of FIPS mode on the device.


The NSM traffic is generated from the self zone, which is a functional zone.  As such, we cannot create a policy to send the traffic through an Advanced Encryption Standard (AES) tunnel, which is an FIPS requirement. Configuring a route based VPN places the device into L2/L3 mixed mode, which is not supported.

Modification History:
2020-10-17: Tagged article for EOL/EOE.
2020-09-21: Article reviewed for accuracy; no changes required

Related Links

Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search