Dmytro,
The limit is not for the active routes but for the BGP routes database, so with 1.4 million BGP routes you are exceeding the capacity of the SRX and you could expect problems:
show route summary
Autonomous system number: xxxxx
Router ID: x.x.x.x
inet.0: 740559 destinations, 1464998 routes (241210 active, 0 holddown, 985427 hidden)
Direct: 4 routes, 4 active
Local: 4 routes, 4 active
BGP: 1464986 routes, 241198 active
Static: 3 routes, 3 active
Aggregate: 1 routes, 1 active
request pfe execute target fwdd command "show services mum"
================ master ================
SENT: Ukern command: show services mum
Memory usage manager: gsm
Total free space to start with: 127898960
Active customers: 1
Max customers: 12
Yellow zone limit: 31974740
Orange zone limit: 23021812
Red zone limit: 11510906
Operational zone: Yellow
request pfe execute target fwdd command "show services objcache"
================ master ================
SENT: Ukern command: show services objcache
objs objs
obj obj objs in cpu in total total
obj cache name size align in use caches depot objects bytes
------------------------------------------------------------------------------
ADVPN Trigger Pool 88 4 0 0 0 0 0
ALG PST NAT BINDING POOL 16 4 0 0 0 0 0
Client Group Name 72 4 0 0 0 0 0
DIP IN pool 76 4 0 0 0 0 0
FTO pool 76 4 241261 19 0 241280 18337280
Maybe this specifc SRX has extra firewall features enabled or is processing more traffic, that will consume more memory than the others firewalls thus making that the exceed on the BGP routes affects it more? How has the SRX behave when you left it for several days with the problem, does it eventually gets stable?
Note that this problem could eventually trigger high CPU utilization as well. The numbers mentioned in the datasheet are those which have been calculated when running BGP alone on the device and nothing else.
It looks like you might need to work with your ISP to reduce the subnets length to try and keep the routes' database size smaller than the limit specified. If all you need is routing with multiple BGP routers sending the complete Internet routing table then I suggest looking at Juniper’s routing platforms (like MX series) which are better suited for such requirements.
I dont like to provide bad news but Juniper will not support scenarios where the limits specified are exceeded.