Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 22.2R3-S7 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Please review for upgrade

Solution

Junos Software service Release version 22.2R3-S7 is now available.

22.2R3-S7 - List of Fixed issues 

PR NumberSynopsisCategory: ChassisD changes specific for ACX series
1794939
Major
Port goes down after adding interface configuration and changing the port from 1g copper to 10g fiber
Product-Group=junos
Severity=Major
On all Junos platforms, port goes down after unplugging the 1g copper and plugging 10g fiber and adding interface configuration because after unplugging the 1g copper (where autoneg is supported) , the auto-negotiationg structure does not get cleared and is still gets applied after plugging in the 10g fiber (where auto-negotiation is not supported).
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading using no-validate.
Product-Group=junos
Severity=Major
RPD might crash when upgrading without using no-validate. Use no-validate to avoid the crash.
PR NumberSynopsisCategory: BBE routing
1826324
Critical
The subscribers get stuck post GRES switchover
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms configured with subscriber management with GRES (Graceful Routing Engine Switchover) enabled, the subscribers will not come up after an ungraceful switchover as RE0( Routing Engine) went down and FPC's rebooted.
PR NumberSynopsisCategory: Border Gateway Protocol
1793435
Major
Route learning process degrades when multipath is enabled
Product-Group=junos
Severity=Major
BGP (Border Gateway Protocol) route learning rate shows degradation even if the BGP next hop trace option is disabled.
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.
1826685
Minor
Unexpected behaviour after BGP sessions reset for catastrophic BGP configuration changes
Product-Group=junos
Severity=Minor
On Junos and Junos Evolved platforms, when a catastrophic Border Gateway Protocol (BGP) configuration change occurs, creating a new peer structure due to this configuration change, the BGP state transitions from open-sent to established multiple times (until the local device finishes cleaning the old BGP session). This results in traffic impact as the peer is reset multiple times (until a new peer connection is established).
1848939
Major
The CPU for the rpd stuck at 100% on Junos platforms
Product-Group=junos
Severity=Major
On Junos platforms, where BGP import policy is running on a BGP multipath setup and BMP post-policy exclude-non-eligible knob is configured. In such cases when the route change from usable to non-usable state and vice-versa, the route is moved to the end of the peer gateway route list for BMP to process it latter. At the same time, BGP stop_rt cursor (used by BGP import policy) is moved to the end of the peer gateway route list. With some network churn and on-going multipath evaluations, the stop_rt cursor keeps moving to the end of the list for ever. This causes BGP import policy to never converge and CPU remains high for a long time.
1864676
Major
The rpd process will crash due to memory leak
Product-Group=junos
Severity=Major
The rpd process will crash due to a memory leak when configuration using apply-groups or ephemeral database for "routing-options autonomous-system independent-domain".
PR NumberSynopsisCategory: BGP BMP Software
1796530
Major
High CPU utilization due to BMP to be running with the longest and highest run count
Product-Group=junos
Severity=Major
In a rare situation, BMP might falls into a loop processing rib-in RM update messages but none of message being sent out. It can hog CPU for long time until the BMP station state is bounced. Since BMP task has low priority, it will yield CPU if there are other tasks jump in. So BMP will only hog CPU when system is idle and won't block other important tasks.
1843374
Major
The BMP rib-in-post route withdraw feed is not being generated towards the BMP station when an import policy is configured
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, the BMP rib-in-post route withdraw feed is not being generated towards the BMP station when an import policy is configured.
PR NumberSynopsisCategory: EVO L3 routing for BCM XGS Platforms
1828017
Minor
The pfemand crash will be observed when "clear bgp neighbor all" command is executed
Product-Group=junos
Severity=Minor
On all Junos and Evolved platforms, in a scaled setup when the "clear bgp neighbor all" command is executed or "restart l2-learning immediately" is executed, the pfemand crash will be seen which leads to the restarting of the Flexible Packet Forwarding Card (FPC).
PR NumberSynopsisCategory: QFX Access Control related
1872280
Major
The l2ald process crash is observed on non L2NG Junos platforms configured with "native-vlan-id" and "bridge-domains" on an IFL
Product-Group=junos
Severity=Major
On non L2NG (Layer2 Next Generation) Junos EX, MX and SRX platforms, the l2ald (Layer 2 Address Learning Daemon) process crash is observed when an IFL (Logical Interface) configured with "native-vlan-id" and "bridge-domains" and when certain config change takes place in an IFL which maps VLAN (Virtual Local Area Network) index to NULL. The dereferencing of this NULL pointer causes the crash.
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1820712
Minor
Traffic loss is observed after configuration addition or baseline configuration override with static VXLAN or EVPN-VXLAN configuration
Product-Group=junos
Severity=Minor
On all QFX/EX/PTX /ACX platforms, when the configuration addition or baseline configuration override happens with static VXLAN (Virtual Extensible Local Area Network) or EVPN-VXLAN (Ethernet Virtual Private Network - Virtual Extensible LAN) configuration, forwarding traffic is impacted as the next-hop is not resolved in correct order of configuration events.
PR NumberSynopsisCategory: Firewall Filter
1859894
Major
MIB2D stucked at 100% on MX10003
Product-Group=junos
Severity=Major
On all MX platforms, during interface flaps with interface-specific / list filters we may see an error "get_counter_list_async: failed in reading counter names (No such file or directory)" due to internal clean-up missing. Please, note that this error is also seen during the churn. This could result in MIB2D hitting at 100% CPU if error remains consistent. The best way to escape this 100% CPU is to restart MIB2d process as soon as the said error is noticed and keep repeating with same counter name.
PR NumberSynopsisCategory: DNS software support.
1826129
Major
Traffic outages due to memory shortage and core files
Product-Group=junos
Severity=Major
On all Junos SRX and vSRX series platforms Juniper networks Deep Packet Inspection (JDPI) gives events per packet. Domain Name System Firewall (DNSF) plugin is leaking memory while processing those events.
PR NumberSynopsisCategory: CoS support on DNX
1756150
Minor
The default ieee-8021p classifier not working for UNI interface for L2 services
Product-Group=junos
Severity=Minor
Default ieee-8021p classifier not working for UNI interface for L2 services in ACX platform.
PR NumberSynopsisCategory: AAA, auditd issues
1809994
Major
Audit core dump seen when tacplus accounting is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, the auditd process may core when sending Tacplus accounting records over a WAN (Wide Area Network) interface. There is no traffic loss and the process will come back up automatically.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1833660
Major
Stale MAC entries may remain in the MAC table of EVPN routing instances after rapid MAC-IP move scenarios
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms with EVPN-MPLS (Ethernet Virtual Private Network - Multiprotocol Label Switching) setup , stale MAC entries may remain in the MAC table of the EVPN (Ethernet Virtual Private Network) routing instances during rapid MAC-IP move scenarios. This can cause MAC tables to reach their limits preventing new MAC addresses learning and user registration.
PR NumberSynopsisCategory: EX4000 PFE issues
1847159
Major
Reachability issues are seen on interfaces that are aggregated without address-family
Product-Group=junos
Severity=Major
On Junos platforms, specifically on EX and QFX series aggregated interfaces configured without address-family results in reachability issues.
PR NumberSynopsisCategory: EX interfaces issues
1677708
Major
40g and 100g vc-ports are not coming UP on EX4400
Product-Group=junos
Severity=Major
On EX4400, the 40g or 100g vc-ports are not coming UP. The issue will be observed with either of the following triggers: 1. Renumbering Master switch 2. Reboot Master switch
1814093
Major
Multi-rate Gigabit Ethernet port on the EX4100 and EX4400 platforms does not receive or forward traffic
Product-Group=junos
Severity=Major
On all EX4100 and EX4400 platforms with mge ports, the mge (multi rate gigabit ethernet) port shows up but does not allow traffic to pass through after port initialization or port flap.
1831409
Major
On an EX4400 device with 4x25G Uplink module configured in 1GE or 25G speed, peer side of an interface with 10GBASE-T transceiver may remain up even when the IFD(xe-x/2/y) is not created
Product-Group=junos
Severity=Major
On an EX4400 device with 4x25G Uplink module configured in 1GE or 25G speed, peer side of an interface with 10GBASE-T transceiver may remain up even when the IFD(xe-x/2/y) is not created. For this to happen, a speed mismatched configuration is needed, where a 1G speed or a 25G speed is configured on the PIC 2.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1801237
Major
ARP won't be forwarded in VLAN associated VNI in VxLAN Fabric
Product-Group=junos
Severity=Major
On EX4100/EX4400/QFX5120 platforms where dot1x is configured with multiple supplicant mode, if the MAC (Media Access Control )+IP (Internet Protocol ) is not in the EVPN (Ethernet Virtual Private Network) database, there will be an ARP (Address Resolution Protocol ) and it will not work as the ARP is suppressed. It will be generated to specific VLAN in VxLAN and it is suppressed due to arp suppression.This issue is seen due to dot1x configured on the interfaces. This can be restored by restarting the FPC.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1834429
Minor
VRRP fails on 802.1Q VLAN Layer 3 logical interface on QFX10002-60C
Product-Group=junos
Severity=Minor
On Junos QFX10002-60C platform, VRRP (Virtual Router Redundancy Protocol) fails to work on 802.1Q VLAN (Virtual Local Area Network) tagging due to the lack of support for VRRP on Layer 3 logical interface. As a result, the VRRP VIP (Virtual IP) is unreachable, causing VRRP functionality to fail.
1865354
Major
Traffic to anycast IPv6 destination addresses dropped when using ECMP routes
Product-Group=junos
Severity=Major
On QFX10002-60C platforms when ECMP is required to get multiple-path to multiple hosts connected, and with IPV6 address configured as a destination address, the destination MAC rewrite process fails, due to the unilist nexthop for IPv6 destination is getting overwritten. This leads the IPv6 packets to the host, to get dropped over the ECMP routes.
PR NumberSynopsisCategory: SRX1500 platform software
1831955
Major
The SRX1500 drops the packet if MTU matches the MRU of the receiving device
Product-Group=junosvae
Severity=Major
On SRX1500 platforms, if the Maximum Transmission Unit (MTU) is configured to match the Maximum Receive Unit (MRU) of the receiving device, packet drops occur. This occurs because additional processing overhead increases the packet size beyond the MRU limit, causing the receiving device to drop the packets.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1845370
Major
Interface not added back to AE bundle with multiple changes in single commit
Product-Group=junos
Severity=Major
On all Junos platforms when speed is changed on an interface which is part of AE bundle, interface will be removed and added with the updated speed. When some other operation such as interface disable is configured along with speed change on the interface in the same commit, then the interface is not removed and added to the bundle, it can cause other AE interfaces flap and traffic drop.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1827648
Minor
ARP not learned on Switch Leading to Traffic Drop in EVPN-VXLAN Setup
Product-Group=junos
Severity=Minor
On all Junos QFX series platforms in an EVPN (Ethernet Virtual Private Network) VXLAN (Virtual Extensible Local Area Network) setup with CRB (Centralized Routing Bridge) architecture, ARP packets are not being learned, leading to traffic forwarding issues. This problem arises when ARP packets are sent from the firewall to the spine switches. The issue is linked to IRB (Integrated Routing and Bridging) handling and bridge domain re-incarnation, which triggers ARP request failures and impacts L3 forwarding.
PR NumberSynopsisCategory: jdhcpd daemon
1854827
Major
Unable to assign an IP address on management interface with DHCP configuration even if DHCP is bound after a power cycle
Product-Group=junos
Severity=Major
On all Junos devices, management interface does not get an IPv4 from Dynamic Host Configuration Protocol (DHCP) even if the interface is bound. When power cycle or reboot is triggered, management is lost without traffic impact.
PR NumberSynopsisCategory: Flow Module
1856521
Major
Data Plane CPU on one device spikes up to 95% during primary node system reboot in SRX cluster
Product-Group=junos
Severity=Major
On all SRX platforms in a cluster, during an HA switchover, especially with a large number of sessions (e.g., greater than 1M), CPU utilization spikes temporarily, reaching up to 95% for a brief period. This occurs during the primary node's reboot or HA switchover. The CPU spikes cause partial service impact, which can affect traffic for a short time during the event. Once the session scan is completed, CPU utilization should return to normal as the session synchronization and cleanup processes are finalized, reducing the load on the system and restoring traffic flow to its usual performance levels.
1859163
Minor
Security forwarding process crash may occur when multicast traffic triggers a route resolution request that needs to be processed for a pending session
Product-Group=junos
Severity=Minor
When multicast traffic triggers a route resolution request for a pending session, and the route is subsequently resolved, a race condition may occur if that pending session is terminated by a different thread before processing can continue. This can result in a crash of the flowd (security forwarding process). However, the control plane remains online and unaffected.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1789245
Major
ICL failure/recovery causes BFD to flap on other node
Product-Group=junos
Severity=Major
With restart-chassis control command on SRX4200/SRX4700/SRX5k, BFD ICL will flap.
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1860597
Major
Security log report messages w.r.t logical system is not generated
Product-Group=junos
Severity=Major
show security log report cli command for logical systems is not working for 24.2R2, 24.4R1-S2, if log report is disabled under root system. Work around is available for this issue.
PR NumberSynopsisCategory: Firewall Policy
1809563
Major
The "show security match-policies" command results in a timeout error
Product-Group=junos
Severity=Major
On all SRX platforms, when a scaled DNS (Domain Name System) configuration with approximately 500 entries is applied along with a policy configuration, issuing the "show security match-policies" command results in a timeout error. This issue has no functional impact.
1859554
Minor
Wrong service-name display in SRX RT_FLOW traffic log.
Product-Group=junos
Severity=Minor
On SRX platforms, wrong service-name might display in SRX RT_FLOW traffic log.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1864322
Major
On rare circumstances the kmd or iked process crash will be observed on using the third-party library API
Product-Group=junos
Severity=Major
On all Junos platforms using ipsec-key-management (daemon name kmd) or the ike-key-management (daemon name iked) service for the IPSec VPN functionality, under very rare scenarios the device can be extremely overloaded so that it cannot generate a random number required for the VPN negotiation after repeated attempts. When this occurs, the VPN negotiation daemon kmd or iked can crash. The VPN operation may or may not be temporarily impacted and will recover automatically.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1856161
Minor
License addition/deletion fails when the "set system license keys key " command is initially used and after the device is rebooted
Product-Group=junos
Severity=Minor
On all Junos platforms in VC (Virtual Chassis) setup the license addition/deletion fails when there is an attempt to add/delete the license again after a reboot if the license configuration initially was done via the "set system license keys key " command. Due to this issue the hard-enforced licenses are also deleted, which leads to an impact on the traffic.
PR NumberSynopsisCategory: lldp sw on MX platform
1811545
Major
The LLDP neighborship does not recover on AE interfaces
Product-Group=junos
Severity=Major
When LLDP is configured on interface all and there are AE interfaces configured, to disable LLDP on one of the AE "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, AE is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.
PR NumberSynopsisCategory: mc-ae interface
1850316
Major
Routing instance knob for ICCP backup liveness detection
Product-Group=junos
Severity=Major
added new config knob "set protocols iccp peer backup-liveness-detection routing-instance ", to configure routing instance name on which "backup-peer-ip" is reachable if it is other than default routing instance, currently it supports only mgmt_junos
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1802447
Major
failed to copy file '//var/etc/if_alias_map+' to 're1' error when user authenticated via tacacs comitting netconf configuration change
Product-Group=junos
Severity=Major
Commit error issue via netconf session
1872010
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
Severity=Major
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberSynopsisCategory: QFX access control list
1844634
Minor
QFX5120 : firewall filters counters are not getting scaled with error "Max Counter Reached 8193"
Product-Group=junosvae
Severity=Minor
QFX5120-48Y and QFX5120-32C device may observe the error message "Max Counter Reached 8193" when loading scaled firewall filers with counter action.
1876904
Major
Commit failure when configuring CCC firewall filter with user-vlan-id above 255 on Junos QFX5K platforms
Product-Group=junos
Severity=Major
On all Junos QFX5K platforms running versions 22.2, 22.4, or 23.2, configuring a Circuit Cross-Connect (CCC) family firewall filter with a user-vlan-id value higher than 255 results in a commit error. This prevents the user from creating a firewall filter with VLANs (Virtual Local Area Network) above 255, which disrupts traffic or allows unwanted traffic if certain traffic is being sent on those VLANs.
PR NumberSynopsisCategory: QFX L2 PFE
1820830
Major
Complete packet loss will be observed for the inter-VLAN traffic in EVPN-VXLAN CRB scenario
Product-Group=junosvae
Severity=Major
On Junos QFX and EX platforms in an EVPN-VXLAN (Extended Virtual Private Network- Virtual Extensible LAN) CRB (Centrally-Routed Bridging) scenario where the ingress leaf switch is configured with ESI (Ethernet Segment Identifier) lags (i.e. the server is multihomed), if there is an overlap between ESI lag(s) trunk ID with physical port number(s) and overlap of DMAC (destination MAC) between VGA (Virtual Gateway Address) MAC address 00:00:5e:00:01:01 (CRB setup with VGA / GW is on spine) with VRRP (Virtual Router Redundancy Protocol) MAC (specifically for the VRRP group 1 MAC address 00:00:5e:00:01:01) on the physical ports of the Leaf switches, then traffic loss will be observed for the inter-VLAN traffic.
1850203
Minor
Duplication of DHCP request packets when unicast to VRRP gateway
Product-Group=junos
Severity=Minor
On Junos QFX5100, QFX5110, QFX5120, QFX5200, QFX5210, EX4100, EX4000, EX4400 and EX4300-48MP platforms, when a client sends a single DHCP (Dynamic Host Configuration Protocol) request, the switch generates and forwards two DHCP request messages to the VRRP (Virtual Router Redundancy Protocol) gateway. This behaviour causes the client to fail to renew its IP address, resulting in a loss of network connectivity.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1834627
Major
Vxlan overlay traffic is tagged with a native vlan when an underlay NNI is configured with a native vlan on all Junos QFX5K platforms
Product-Group=junos
Severity=Major
On all Junos QFX5K platforms, configuring a native VLAN on an underlay Network-to-Network Interface (NNI) that carries VxLAN (Virtual Extensible LAN) traffic results in the VLAN tag not being stripped as expected.Instead of treating the native VLAN traffic as untagged, the interface adds the VLAN tag, leading to packet drops at the remote end.
1866130
Minor
Command "show pfe vxlan" is not supported on QFX5200 devices
Product-Group=junos
Severity=Minor
Support added for "show pfe vxlan" CLI command on QFX 5200 devices
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1773567
Major
100G optics settings to CAUI4 on Junos QFX5120-48T platforms
Product-Group=junos
Severity=Major
The port interface on the 100G optics of the QFX5120-48T platform is incorrectly configured
1820286
Major
The remote end of port JNP-SFPP-10GE-T doesn't shut down when the hardware is rebooted using request system reboot
Product-Group=junos
Severity=Major
On all Junos QFX devices or any platform which is using qfx-5e image, the interface JNP-SFPP-10GE-T does not get disabled using the CLI command "request system reboot" causing the remote end interface to show active.
1845158
Major
Interface flap between the QFX5120 and QFX5210 with QSFP-100G-LR4-T2 optics
Product-Group=junos
Severity=Major
When the 100G port with QSFP-100G-LR4-T2 is used the interface is negotiating to CAUI4 and when this happens the Speed needs to be explicitly set which was missing in the code.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1823771
Major
The SFP 10GBASE-T part No. 740-083295 on platforms running Junos/Junos EVO is unable to detect a linkdown
Product-Group=junos
Severity=Major
On Junos/Junos EVO platforms with the SFP 10GBASE-T part No. 740-083295 Link up/Link down is randomly not detected.
1847904
Major
CTLE Values mismatch for 100G-BASE-SR4/100G-BASE-SR4-T2 in QFX5120-48T
Product-Group=junosvae
Severity=Major
The CTLE for 100G-BASE-SR4/100G-BASE-SR4-T2 is set wrong value on QFX5120-48T platform.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1830588
Critical
The rpd process crashes on all Junos and Junos OS Evolved platforms
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms when recursively resolved routes changed or deleted, route churn could potentially lead to the rpd process crash.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1861451
Major
BGP PIC failover is taking longer than expected when IS-IS as an IGP enabled with LFA
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, in a BGP-L3VPN (Border Gateway Protocol - Layer 3 Virtual Private Network) setup when configured with BGP PIC (Prefix-Independent Convergence) on an ingress PE's (Provider Edge) VRF (Virtual Routing and Forwarding) routing-instance and having IS-IS (Intermediate System-to-Intermediate System) as an IGP (Interior Gateway Protocol) which if enabled with LFA (Loop Free Alternative), BGP PIC failover is taking loger time than expected due to lag in the route change for the BGP path to be used. This is causing traffic loss until global convergence.
PR NumberSynopsisCategory: HA functionality on ASP
1853304
Major
Traffic was lost on MX platforms following a Routing Engine failover
Product-Group=junos
Severity=Major
On Junos MX240/MX480/MX960/MX2010/MX2020 platforms which support TLB (Traffic-Load Balancer) the PFE (Packet Forwarding Engine) is not properly synchronized with the new master RE (Routing Engine) after a RE failover causing traffic loss
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1825447
Major
The SNMP performance degrade is observed while querying interface counters
Product-Group=junos
Severity=Major
On all Junos platforms, SNMP (Simple Network Management Protocol) performance issues will be seen while querying interface counters for more than 1000 interfaces, which results in SNMP timeouts and throttle drops however there is no impact to the traffic.
PR NumberSynopsisCategory: SRX Advanced Anti-Malware module
1851786
Major
Intermittent traffic drops are seen due to large memory allocation for unidentified files
Product-Group=junos
Severity=Major
On all SRX platforms with Advanced-Anti-Malware (AAMW) policy enabled, intermittent traffic loss is observed with error message "memory shortage in fail close mode" due to large number of files or URLs with unidentified IDs.
PR NumberSynopsisCategory: SRX branch platforms
1845997
Major
Packet drops are observed in the VPLS environment on SRX380 platforms in packet mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms in packet mode, when VLAN (Virtual Local Area Network)-VPLS (Virtual Private LAN Service) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 (Layer 2) unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.
1848557
Major
Local or peer device's interface reflects down after SRX380's reboot
Product-Group=junos
Severity=Major
On SRX380 platforms, the local interface status or the peer device's interface reflects down after SRX380's reboot when both devices are configured with auto-negotiation on the SRX380's 4x10GbE ports.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1865649
Major
Traffic drop from subscriber will be observed when rpf-check knob is enabled under subscriber dynamic-profile with static underlying VLAN interface
Product-Group=junos
Severity=Major
On all Junos MX platforms with BBE subscribers (Broadband Edge) over static IFLs (Logical Interface) with static underlying VLAN (Virtual Local Area Network) interface and ISSU (In-Service Software Upgrade) is performed, traffic drop will be observed when rpf-check (Reverse-path forwarding) knob is enabled under subscriber dynamic-profile.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1850604
Major
Packet duplication and flooding issues are seen when vpls bridge domain is configured on an aggregated Ethernet and label-switched interface across multiple line cards
Product-Group=junos
Severity=Major
On MX240/MX480/MX960/MX2008/MX2010/MX2020/MX10003/MX10008/MX10016/MX10004 platforms with vpls (Virtual private LAN service) bridge domain configured, when the core facing ecmp (Equal cost multipath) are across multiple line cards and when MAC is learned up to MAC limit, packet flooding might be seen continuously for 5 mins after uplink or downlink going down causing network congestion.
1871698
Major
Filter-Based Forwarding (FBF) failed for over unicast IRB over AE on MX and EX platforms
Product-Group=junos
Severity=Major
On Junos MX with MPC10, MPC11, MX304 and EX92K platforms, when Integrated routing and bridging (IRB) interface is configured over Aggregate Ethernet (AE), the packet is received on an l3 IRB which is processed through a filter based forwarding (FBF) which forwards the traffic over an IRB which has an underlay as L2 AE interface. When the packet is forwarded over the l2 AE, the packet gets dropped because the egress PFE calculation is incorrect resulting in a traffic drop.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1858076
Major
The aftd process crash is seen on Junos OS platforms running MPC10, MPC11, LC4800, LC9600 line cards and in Junos OS platforms MX304, EX9200-15C
Product-Group=junos
Severity=Major
On Junos OS platforms running MPC10, MPC11, LC4800, LC9600 line cards and in Junos OS platforms MX304, EX9200-15C, aftd process crash is seen resulting in crash of FPC (Flexible PIC Concentrator) line card while the route module of PFE (Packet Forwarding Engine) processing route churns as simultaneous actions (add/delete/read) by multiple threads on the process.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1837840
Major
Incorrect color-aware srTCM marking with yellow packet loss priority
Product-Group=junos
Severity=Major
There was a software side limitation on the highest CBS that can be configured for MPCs that have LU type lookup chips due to a hardware PR. The Hardware PR was resolved in MX240/ MX480/ MX960/ MX2008/ MX2010/ MX2020/ MX10003/ MX10008/MX10016/EX9200/EX9204/EX9208/EX9214/EX9251/EX9253/SRX5400/SRX5600/SRX5800 platforms, but the software-side limitation was not removed for the same. Due to this limitation, whenever the CBS was configured above its limit (earlier 33m), the low-level parameters used to get configured such that the packets would not have any credits available, resulting in them getting marked as RED.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1846365
Major
Traffic drops after link flap on active-active ESI setup with MAC pinning enabled
Product-Group=junos
Severity=Major
On MX platforms with ukern (legacy) FPC (Flexible PIC Concentrator) based in trio chipset and configured in an active-active ESI (Ethernet Segment Identifier) setup, traffic will be dropped after a flap of the DF (Designated Forwarder) or BDF (Backup Designated Forwarder) LAG (Link Aggregation Group) interface member.
1856573
Minor
The 'show snmp mib walk jnxMac' shows incorrect entries and VLAN ID to be 0
Product-Group=junos
Severity=Minor
On all MX platforms having MPC10E, MPC11E, LC9600 and MX304, when the SNMP query is run using the command "show snmp mib walk jnxMac" . The output of jnxMacStatsEntry provides statistics from one of logical unit only even if there are multiple logical units configured and the VLAN ID information shows up as "0", instead of the actual VLAN ID. This is a display issue with no impact.
1874503
Major
An IPv6 neighbor solicitation packet is dropped at the ingress PE router when it is received with more than two VLAN tags.
Product-Group=junos
Severity=Major
On Junos platforms having 'arp-supression' suppression enbabled, when IPV6 neighbor solicitation packets are received with more than two tags in an EVPN (EThernet Virtual Private Network) instance, the NDP (Neighbour Discovery Protocol) packets that are suppressed to the host path are incorrectly processed through a wrong DDOS policer, as the hop-limit value from the IPV6 header is not properly retrieved, causing them to be dropped by the packet forwarding engine.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1829031
Minor
An authentication failure occurs when the TACACS+ server detects an error in sending authentication response
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved products configured with TACACS+(Terminal Access Controller Access Control System Plus) authentication method, authentication seems to fail when TACACS+ server detects an error in sending authentication response to the host device. This impacts authentication and user cannot login into the device.
PR NumberSynopsisCategory: Configuration management, ffp, load action
1854461
Major
TFTP server crashes when configuration to limit connections are not reflected
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms configured as Trivial File Transfer Protocol (TFTP) server , "connection-limit" or "rate-limit" values are not updated as per configured values and server crashes.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1821824
Major
The CLI session can be terminated after load override and rollback operations are executed simultaneously
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms, performing a load override operation simultaneously with a rollback can cause the mgd (management daemon) process to crash. This issue is extremely rare and occurs due to a race condition. There is no impact on traffic forwarding. However, the crash results in the closure of the active CLI (Command Line Interface) session. Access can be restored by re-establishing the session through login.
PR NumberSynopsisCategory: Issues related to NETCONF
1800859
Minor
Configuration push to device using RPC resulted in incorrect policy order
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms,  RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.
PR NumberSynopsisCategory: web filterig issues
1854519
Major
FPC crashing when web filtering type set to "juniper-enhanced" or "NG-juniper"
Product-Group=junos
Severity=Major
On all SRX platforms, when the web-filtering type set to "juniper-enhanced" or "NG-juniper" (NextGen-juniper), it might cause FPC (Flexible Port Concentrator) card crash and with "srxpfe" or "lcore" crash files generated.
PR NumberSynopsisCategory: PTX/QFX10002/8/16 specific software components
1734703
Major
Speed configuration mismatch causes the ukern core on Junos PTX10008 and PTX10016 platforms
Product-Group=junos
Severity=Major
On Junos PTX10008 and PTX10016 platforms, when the speed configuration on the interface is not matching with the speed of the optics present in the port, it causes memory corruption because of this FPC will crash and restart. Traffic loss till the FPC restarts after the ukern core.

 


 

22.2R3-S7 - List of Known issues 

PR NumberSynopsisCategory: Border Gateway Protocol
1719498
Major
In MPLS L3VPN-BGP multipath scenario route calculation or recalculation causes the rpd process to crash
Product-Group=junos
On all Junos and Junos Evolved platforms, memory leak is observed in Multi-protocol Label Switching (MPLS) Layer3 and labelled routes scenario when Border Gateway Protocol (BGP) with multipath is configured. Multiple route changes and deletion overtime that triggers this memory leak can lead the rpd to run out of memory causing the rpd process to crash.

Resolved In: evo:21.4R3-S4-EVO evo:22.1R3-S3-EVO evo:22.2R3-S1-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.4R3-S2-J16 junos:21.4R3-S2-J22 junos:21.4R3-S4 junos:21.4R3-S5 junos:21.4R3-S6 junos:22.1R3-S3 junos:22.2R3-J7 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1 junos:23.3R1 junos:24.2R2
1776851
Minor
Internal Border Gateway Protocol (IBGP) sessions to Route Reflector (RR) are flapping due to " UPDATE prefix length 0 invalid ".
Product-Group=junos
On all Junos and Junos Evolved platforms when a too-short NLRI for RTC packets was detected, Internal Border Gateway Protocol (IBGP) sessions to Route Reflector (RR) are flapping due to " UPDATE prefix length 0 invalid ".

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO junos:19.1R3-S12 junos:19.2R3-S9 junos:20.2R3-S9 junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S8 junos:21.4R3-S7 junos:22.1R3-S6 junos:22.3R3-S3 junos:22.4R3-S1 junos:23.2R2 junos:23.4R2 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: QFX Access Control related
1851299
Minor
EX3400 Dot1x Radius accounting send incorrect value to the server for Acct-Input-Gigawords/ Acct-Output-Gigawords
Product-Group=junos
With Dot1x Radius Authentication and Accounting, when the Stop Accounting (due to disconnect) is sent to the Radius server the Acct-Input-Gigawords and the Acct-Output-Gigawords contains unexpectedly large value.

Resolved In: evo:23.4R2-S5-EVO evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2-S1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Manageability for Node Virtualization
1882183
Major
Commit synchronise on the JDM is failing for the first time with the rpm jns-jdm-vmhost-22.2-R3.S7.3.x86_64.rpm.
Product-Group=junos
NV-JDM (both inchassis / external) may fail to successfully complete first commit sync operation with other JDM, if the other JDM was restarted before doing commit sync. Next and following commit sync operations complete successfully.

Resolved In:
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1844623
Major
Stale MAC-IP entries are not cleared in an EVPN-VXLAN scenario when encapsulate-inner-vlan or decapsulate-accept-inner-vlan or both knobs are present
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when decapsulate-accept-inner-vlan or encapsulate-inner-vlan or both knobs are configured for a VXLAN (Virtual Extensible Local Area Network) and when any action corresponding to MAC-IP entries cleanup takes place, the MAC-IP entries will not be cleaned up from kernel. This will result in anomalies in device and could also lead to a core crash.

Resolved In: evo:21.4R3-S10-EVO evo:22.2R3-S6-EVO evo:22.4R3-S6-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:23.4X100-D20-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.4R3-S10 junos:22.4R3-S6 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1808773
Minor
On ACX7348/ACX7332 all traffic is blocked on FPC after RE Switchover
Product-Group=junos
On ACX7348/ACX7332 with MACsec enabled in channelized interfaces, after performing a double RE switchover (primary RE swap to backup and then back to active), traffic in FPC1 stops in being forwarded.

Resolved In: evo:23.4R2-S5-EVO evo:24.4R1-EVO junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1
PR NumberSynopsisCategory: EVPN control plane issues
1862755
Critical
EVPN/ETREE not learning MAC's on Root
Product-Group=junos
Media Access Control (MAC) is not learnt in Ethernet Virtual Private Network(EVPN) or Ethernet Tree(ETREE).

Resolved In: junos:24.4R2 junos:25.3R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1718165
Major
ARP learning issues are observed post-execution of the CLI command 'clear bridge mac-table' or 'clear ethernet-switching table' in the EVPN-MPLS over IRB environment
Product-Group=junos
On all Junos and Junos Evolved platforms, L3 (Layer 3) traffic will be impacted when ARP (Address Resolution Protocol) entries get deleted for the MAC (Media Access Control) address having a bad state post execution of the CLI 'clear bridge mac-table' or 'clear ethernet-switching table' command in the EVPN-MPLS (Ethernet VPN - Multiprotocol Label Switching) over IRB (Integrated routing and bridging) environment.

Resolved In: evo:21.4R3-S6-EVO evo:22.1R3-S5-EVO evo:22.2R3-S3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: EX interfaces issues
1823688
Major
Interface goes down after a dc-pfe (Data Centre Packet Forwarding Engine) process restart in a Virtual Chassis environment on EX4400 platform
Product-Group=junos
On a EX4400 virtual chassis environment, if the dc-pfe process restart for any reasons or restarted manually, then there is a possibility of some interfaces going down.

Resolved In: junos:24.2R2-S1 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: EX4400 PFE software
1795807
Minor
Cos rewrite rules does not work properly when input/output-vlan-map swap are configured
Product-Group=junos
On Junos EX4400 platforms enabled with CoS rewrite, if there is rewrite-rule applied to the input/output-vlan-map swap interface, the rewrite-rule of the logical interfaces does not work properly since the priority value for the queue is not updating. There is no traffic impact due to this, only CoS rewrite value is not updating.

Resolved In: junos:21.4R3-S9 junos:22.4R3-S2 junos:23.2R2-S1 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: EX4400 platform
1814463
Minor
EX4400: MIST: Wrong PSU state is updating in the mist
Product-Group=junos
Unsupported PEM/PSU is shown as online (green)in the MIST Dashboard and the output of "show chassis environment" for that PSU shows the status as present/OK. No functional impact.

Resolved In: junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Issues related to EX MACsec
1830395
Major
Commit error on using more than 31 characters authentication-key-chain-name
Product-Group=junos
On all Junos and Junos Evolved platforms, when authentication-key-chain-name is configured with more than 31 characters, commit error is seen due to which MACSEC will not work with the configuration.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Signature Database
1822319
Minor
Not able to update IDP signature DB when using Proxy server
Product-Group=junos
On all Junos and Junos OS Evolved platforms, the IDP signature download issue is seen with squid proxy server of a specific version like 6.6 is installed.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1826194
Minor
The rpd crash is observed during upgrade or restart
Product-Group=junos
On all Junos and Junos Evolved platforms, rpd crash is observed during upgrade or restart since kernel takes more time to update ifstate information.

Resolved In: evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:23.4X100-D40-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.1R1-EVO junos:21.4R3-S10 junos:22.4R3-S5 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: ISIS routing protocol
1847557
Minor
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.

Resolved In: evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO junos:22.4R3-S2-J13 junos:23.4R2-S4-J9 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Juniper Device Manager VM Mgmt and infrastructure function
1675919
Critical
NFX350 :: JDI_REGRESSION:PLATFORM:SWITCHING:JDM:: Core "localhost.libvirtMib_suba.15909.1656455866.core.tgz" is seen on NFX-350 boxes
Product-Group=junos
NFX350 :: JDI_REGRESSION:PLATFORM:SWITCHING:JDM:: Core "localhost.libvirtMib_suba.15909.1656455866.core.tgz" is seen on NFX-350 boxes

Resolved In:
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1776782
Minor
Host device cannot resolve target IP's ARP when client uses virtual mac address
Product-Group=junos
On Junos or Junos OS Evolved platforms which supports EVPN-MPLS/EVPN-VXLAN, device will not reply for ARP (Address Resolution Protocol) requests when source MAC (Media Access Control) of ethernet header and ARP source MAC are different and ARP target address are exists in mac-ip-table. Traffic drop will be seen.

Resolved In: evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:22.4R3-S2 junos:23.2R2-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1798780
Critical
The system goes into a bad state when an SFB ungraceful offline happens due to a fatal Interrupt
Product-Group=junos
On MX platforms with SFB, in case of a fatal error encountered during SFB reboot ( due to hardware issue or ungrateful power restart ), SPMB will try to offline this SFB during bootup. At the same time, the system is busy training the fabric links to begin it online. This may cause a system-wide traffic impact due to the fabric not being consistent.

Resolved In: junos:21.2R3-S9 junos:22.4R3-S7 junos:23.2R2-S2 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1698889
Major
The rpd process will crash when rpd is restarted
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when MPLS (Multiprotocol Label Switching) statistics is configured without LSP (Label-Switched Path) configuration, the rpd process will crash and impact the routing protocols. This leads to traffic disruption due to the loss of routing information.

Resolved In: evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.4R3-EVO evo:23.1R1-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:20.3X75-D43 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2-S2 junos:22.4R3 junos:23.1R1 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1568757
Major
The image validation is not supported during upgrading from Pre 21.2 to 21.2 and onward
Product-Group=junos
When upgrading from releases before Junos OS Release 21.2 to Release 21.2 and onward, validation and upgrade might fail. The upgrade requires using the 'no-validate' option to complete successfully. https://kb.juniper.net/TSB18251 [juniper.net]

Resolved In:
1695867
Major
VMHOST based platforms rebooted unexpectedly due to corruption in the system
Product-Group=junos
On all Junos platforms with VMHOST, the device rebooted unexpectedly due to a minor corruption in the system.

Resolved In: junos:19.1R3-S14 junos:19.2R3-S11 junos:19.3R3-S12 junos:19.4R3-S15 junos:20.2R3-S10 junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D46 junos:20.3X75-D52 junos:21.2R3-S5 junos:21.3R3-S4 junos:21.4R3-S4 junos:22.1R3-S2 junos:22.2R3 junos:22.3R2-S1 junos:22.3R3 junos:22.4R1-S2 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: vMX Data Plane Issues
1669261
Minor
vMX crashes due to MBUF leaks
Product-Group=junos
vMX platforms (MX150) will crash as a result of the MBUF (Memory Buffer) leak.

Resolved In: junos:20.3X75-D43 junos:20.3X75-D46 junos:20.4R3-S5 junos:21.4R3 junos:22.1R3 junos:22.3R1 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R1 junos:24.2R2
PR NumberSynopsisCategory: Phone-Home-Client Infrastructure
1811521
Major
PHC gets initiated and sends DNS request to Juniper server "redirect.juniper.net" even when device is supposed to get provisioned using ZTP with vendor specific option 43
Product-Group=junos
Rarely, on all Junos platforms, PHC (Phone Home Client) is signaled to attempt bootstrapping by AIU (Auto Image Upgrade) when legacy ZTP (Zero Touch Provisioning) fails if vendor specific options (option 43 is sent by DHCP server) are not valid. This is followed by PHC sending DNS request to resolve "redirect.juniper.net" which is the redirect Juniper Server even if DHCP is released by ZTP and no IP is expected to be present.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S5-EVO evo:24.2R2-EVO junos:21.4R3-S10 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S5 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: vMX Platform Infrastructure related issue tracking
1729152
Minor
The FPC crash or flap in protocols will be seen as soon as port-mirroring or firewall filters with syslog action is enabled
Product-Group=junos
On MX150 platform, when port-mirroring or firewall with syslog configuration is enabled, there will be a memory leak which will cause depletion of buffer memory which will lead to flap in the protocols or the (Flexible PIC Concentrators) FPC crash. This will impact the traffic.

Resolved In: junos:19.1R3-S12 junos:19.2R3-S9 junos:19.3R3-S11 junos:19.4R3-S14 junos:20.2R3-S9 junos:20.3X75-D36 junos:20.3X75-D440 junos:20.3X75-D46 junos:20.3X75-D52 junos:21.2R3-S9 junos:21.2X32-D30 junos:21.4R3-S7 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S2 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R1-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on specific Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.

Resolved In:
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1845045
Major
On QFX5120-48YM port remains down when speed shifts from 1G to 10G
Product-Group=junos
On QFX5120-48YM, if a port is transitioned directly from 1G to 10G either by swapping the SFP or by changing port and chassis speed settings without intermediate reset. The 10G link will remain down.

Resolved In: junos:25.3R1
PR NumberSynopsisCategory: N/A:sw-rio-timing
1830382
Major
The PTP global info parameters announce-interval, synchronization-interval, and delay-response-interval unicast packets are not captured as expected
Product-Group=junos
On the Junos ACX5448 platform, the PTP min and max announce, sync and delay-request/response do not match with the configured values in the CLI output "show ptp global-information".

Resolved In: junos:21.2R3-S9 junos:23.4R2-S5 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Routing Information Protocol
1726028
Major
RIPng neighbor state is down when virtual IP is configured over an IRB interface
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a virtual IP is configured over an IRB (Integrated routing and bridging) interface, IFA (Inband Flow Analyzer) having the virtual IP is considered by RIPng (Routing Information Protocol Next Generation) and hence an IFA having a non-virtual ip is discarded with an error causing the RIPng neighbor state to be down. This results in impact on the forwarding traffic.

Resolved In: evo:21.4R3-S10-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:21.2R3-S8-J21 junos:21.2R3-S9 junos:21.4R3-S10 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: RPD Interfaces related issues
1798801
Major
MPLS/RSVP LSP self-ping behaviour differs from expected behaviour causing self-ping time out
Product-Group=junos
On Junos OS Platforms, configured with Multiprotocol Label Switching (MPLS)/Resource Reservation Protocol(RSVP) Label Switched Path(LSP) and firewall filter applied on the loopback with prefix list that does not include the interface address of local router, self-ping time out is observed.

Resolved In: evo:22.2R3-S4-EVO evo:22.3X50-EVO evo:23.4R2-EVO evo:24.1R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:20.3X75-D46 junos:20.3X75-D52 junos:21.2R3-S9 junos:22.2R3-S4 junos:22.4R3-S2 junos:23.4R2 junos:24.1R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1704714
Major
Incorrect reporting of element 47 of ipfix/jflow service
Product-Group=junos


Resolved In: evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.2R1-EVO evo:23.3R1-EVO evo:23.3R2-EVO junos:20.3X75-D46 junos:20.3X75-D52 junos:21.2R3-S9 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1706887
Major
PathErr originated when next-hop lookup fails at a PLR post FRR may sometimes carry an incorrect error-origin
Product-Group=junos
On all Junos and Junos Evolved platforms, when next-hop lookup fails at a point of local repair (PLR) post fast-reroute (FRR), the PathErr that is originated should carry the incoming Traffic Engineering TE-link address as the error-origin. In certain circumstances when there is a next-hop change post FRR, the PathErr originated may end up carrying a different local address as the error-origin. This PathErr doesn't get acknowledged by the Previous Hop (PHOP) node, resulting in multiple retransmissions. In a scaled setup, this can potentially cause an unnecessary storm of PathErr messages. The fix involves introducing a new field in nhop_result_t to carry the error address. This is used when providing a custom error source address to routines that generate and send PathErr. This ensures that the PathErr doesn't inadvertently carry an irrelevant address as the error source.

Resolved In: evo:22.3R3-EVO evo:22.3X50-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:20.3X75-D43 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.4R2
1819948
Minor
LSP re-optimization issue has been observed
Product-Group=junos
On all Junos and Junos Evolved platforms, the LSP (Label Switched Path) re-optimization issue has been observed. LSP bandwidth change is unsuccessful due to bandwidth unavailable RSVP (Resource Reservation Protocol) PathErr.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D441 junos:20.3X75-D46 junos:21.4R3-S10 junos:22.4R3-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Scuba fabric software
1811474
Major
In Junos MX platforms specifically MX2010 and MX2020 with SFB2 Fabric installed replacing MPC9E linecards with MPC6E linecards results in all SFB2 fabric get into check state and FPCs becomes destination error and offline
Product-Group=junos
On Junos MX platforms specifically MX2010 and MX2020 with SFB2 (Switch Fabric Board) Fabric installed, after inserting and powering on a new MPC6E in slot (swapping specifically with MPC9E linecard), fabric get into check state and all FPCs goes as unreachable destinations and gets offlined. Due to this, traffic loss can occur.

Resolved In: junos:20.3X75-D46 junos:21.2R3-S9 junos:22.2R3-J11 junos:23.2R2-S2-J2 junos:23.2R2-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: MX10003/MX204 Platform SW - Chassisd s/w defects
1818517
Minor
Fan Tray Outer Fan running at over speed alarm is reporting after upgrade
Product-Group=junosvae
For MX10003 fan min and max threshold were -40 and +20 set. If fan RPM goes below/beyond those RPM, s/w start raising alarms. Similarly for MX204 fan min and max threshold were -20 and +20 set. On log analyzing, its seen FAN RPM was running +34% , that was beyond ma threshold. After discussing with h/w team, min & max threshold values are now decided -40 and +40. Due to this FAN RPM will be in bandwidth and no alarm will be seen.

Resolved In: junos:22.4R3-S3-J7 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1842518
Major
The device become unresponsive in a race condition due to maximum process (maxproc) limit
Product-Group=junos
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.

Resolved In: evo:22.2R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S4 junos:23.4X30-D20 junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:25.1R1
1847834
Major
Multiple daemons crash upon ephemeral or static db commits
Product-Group=junos
On all Junos platforms with ephemeral configuration, multiple daemons like chassisd, dcd, l2ald, l2cpd, mib2d and transportd crash upon ephemeral or static db commits causing service traffic impact. The services will self recover after the issue is hit in the network.

Resolved In: evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R2-EVO evo:24.4R1-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:21.4R3-S11 junos:21.4X12-X1 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S4 junos:23.4X30-D20 junos:24.2R2 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1

 

Modification History

First publication 2025-06-24