Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

PTX QFX platforms running Junos EVOLVED software

Alert Description

Junos Software Service Release version 23.4R2-S5-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Please review.

Note: Due to telemetry-related regression issues - PR 1908677 and 1907660 - the 23.4R2-S5-EVO images for PTX platforms have been moved to "controlled" status. The images are available for download, but not listed on the software download site.

To download these images you can use the following URLs:

 

Description

URL

PTX10004/8/16 Series ".iso"

junos-evo-install-ptx-x86-64-23.4R2-S5.4-EVO.iso

https://webdownload.juniper.net/swdl/dl/secure/site/1/record/187367.html

PTX10004/8/16 Series USB ".img"


junos-evo-install-media-usb-ptx-x86-64-23.4R2-S5.4-EVO.img

https://webdownload.juniper.net/swdl/dl/secure/site/1/record/187370.html

PTX10004/8/16 Series - Limited ".iso"

junos-evo-install-ptx-x86-64-23.4R2-S5.4-EVO-limited.iso

https://webdownload.juniper.net/swdl/dl/secure/site/1/record/187368.html

PTX10004/8/16 Series - Limited USB ".img"

junos-evo-install-media-usb-ptx-limited-x86-64-23.4R2-S5.4-EVO.img

https://webdownload.juniper.net/swdl/dl/secure/site/1/record/187372.html

PTX fixed form factor ".iso"

junos-evo-install-ptx-fixed-x86-64-23.4R2-S5.4-EVO.iso

https://webdownload.juniper.net/swdl/dl/secure/site/1/record/187366.html

PTX fixed form factor USB ".img"

junos-evo-install-media-usb-ptx-fixed-x86-64-23.4R2-S5.4-EVO.img

https://webdownload.juniper.net/swdl/dl/secure/site/1/record/187371.html

PTX fixed form factor - Limited ".iso"

junos-evo-install-ptx-fixed-x86-64-23.4R2-S5.4-EVO-limited.iso

https://webdownload.juniper.net/swdl/dl/secure/site/1/record/187365.html

PTX fixed form factor - Limited USB ".img"

junos-evo-install-media-usb-ptx-fixed-limited-x86-64-23.4R2-S5.4-EVO.img

https://webdownload.juniper.net/swdl/dl/secure/site/1/record/187373.html

Solution

Junos Software service Release version 23.4R2-S5-EVO is now available.

23.4R2-S5-EVO - List of Fixed issues 

PR NumberSynopsisCategory: N/A:hw-balerion-power
1870153
Major
PTX10k2-36QDD showing incorrect Power Status
Product-Group=evo
Severity=Major
On a PTX10k2-36QDD system, the output of "show chassis environment" may incorrectly shows a disconnected PEM's status as "OK" instead of "Check".
PR NumberSynopsisCategory: JUNOS kernel/ukernel changes for ACX
1833705
Major
Configuration archival does not work using SFTP when using the mgmt_junos routing instance
Product-Group=evo
Severity=Major
On Junos OS and Junos OS Evolved platforms, when the SFTP protocol uses the mgmt_junos routing instance to communicate with the SFTP server, it will fail.
PR NumberSynopsisCategory: "agentd" software daemon
1779722
Minor
The interface fails to come up after FPC reboot if the streaming server and export profile are not configured correctly
Product-Group=evo
Severity=Minor
On all Junos and Junos evolved platforms with telemetry enabled, if the streaming server and export profile for reporting-rate are not properly configured in the analytics settings, rebooting the FPC would prevent any of the interfaces from coming up.
1856528
Major
Missing traffic statistics via telemetry on PTX EVO platforms with MPC10E, MPC11E, and LC9600 line cards
Product-Group=evo
Severity=Major
On PTX EVO platforms equipped with MPC10E, MPC11E, or LC9600 line cards, when telemetry monitoring is enabled and the sensor /junos/system/linecard/interface/traffic/ is subscribed to, some entries for interface traffic statistics might be missing. This occurs due to an issue where the volume of telemetry data per interface can lead to message fragmentation, resulting in incomplete data export.
PR NumberSynopsisCategory: PTX10001-36MR Timing
1872162
Major
PTX10001-36MR upon system reboot PTP stays permanent in Frequency Locked Phase Acquiring mode
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX10001-36MR platform having PTP (Precision Time Protocol) with with G.8275.1 profile and SyncE (Synchronous Ethernet) configured, PTP clock synchronization requires proper timestamp between the PTP clock mode and the PFEs (Packet Forwarding Engine). When the device reboots, the PTP clock mode could be initialized before the PFEs are online. This will not activate PTP clock mode in the PFEs, resulting in the PTP lock state being stuck in Acquiring mode, for which PTP synchronization will be impacted.
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading using no-validate.
Product-Group=evo
Severity=Major
RPD might crash when upgrading without using no-validate. Use no-validate to avoid the crash.
PR NumberSynopsisCategory: Border Gateway Protocol
1849568
Minor
L3VPN routes are not advertised to peer when BGP sessions with route-target filter flaps
Product-Group=evo
Severity=Minor
On all Junos and Junos OS Evolved platforms, after Border Gateway Protocol (BGP) sessions configured with 'family route-target' flaps, delayed route deletion causes the loss of the Route Target Filter (RTF), preventing the node from advertising L3VPN (Layer 3 Virtual Private Network) and direct routes (e.g., loopbacks and interface routes) to the BGP peer, leading to VPN route loss and service disruption.
1853025
Major
Updating a source-file to load ROAs should be done by changing the name of the source file
Product-Group=evo
Severity=Major
Loading ROAs from a source-file was a feature introduced as a convenience feature and as such this only affects that feature. This feature is not in widespread use and was created to have a fallback ROA when all sessions go down. This problem scenario requires multiple reloads with the being modified back and forth to add and then delete and re-add the database configured in the import policy.
1863551
Major
BGP route advertisement failure with as-override and peer-as configured at group level
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, BGP ( Border Gateway Protocol ) fails to advertise routes to external peers in an L3VPN ( Layer 3 Virtual Private Network ) environment when as-override is configured for a neighbor on the local device, and peer-as is applied at the group level. Since the routes are not advertised to peers, traffic matching those routes are dropped, causing service disruption.
1865114
Major
Valid BGP routes in RIB are displayed with verification state as Invalid
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms, with resource public key infrastructure(RPKI ) enabled for the BGP, the valid routes are installed in the routing table with validation state invalid.However, the route is parsed by policy as a valid route.
1875144
Minor
Longer convergence is seen for a BGP neighbor having validation configured in its import policy
Product-Group=evo
Severity=Minor
On all Junos and Junos Evolved platform, when any BGP peer has validation policy configured for import, it is observed that there is an extra walk to re-evaluate the routes in the loc-rib for validation even though the policy/unrelated configuration is changed for an unrelated peer.
PR NumberSynopsisCategory: EVO L3 routing for BCM XGS Platforms
1839359
Minor
ECMP next-hops fails to install due to the ECMP group table reaching its capacity in a scale environment on Junos Evolved QFX platforms
Product-Group=evo
Severity=Minor
On Junos OS Evolved QFX platforms in a scaled environment (approximately 4K ECMP(Equal-cost multipath) next-hops), installation of ECMP next-hops fails due to resource exhaustion when the ECMP group table reaches its limit. As a result, the device stops forwarding packets, causing traffic loss.
1840632
Major
Packets are incorrectly directed to an inappropriate filter and are lost due to TCAM exhaustion
Product-Group=evo
Severity=Major
On Junos OS Evolved QFX5k series platforms, the TCAM approaches its limit and becomes exhausted as the number of entries increases due to a large combination of matching items in a firewall filter term (2000 matching items), avoiding the filter installation in hardware and assigning a wrong filter ID leading to a potential loss of packets.
1862778
Major
OSPFv3 authentication with IPSEC doesn't work on Junos OS Evolved QFX platforms
Product-Group=evo
Severity=Major
On Junos OS Evolved QFX platforms having OSPFv3 (Open Shortest Path First version 3) authentication with IPsec (Internet Protocol Security) configured, OSPFv3 IPsec packets are not being sent for OSPF processing, as they are treated as unknown multicast packets. This causes OSPF neighborship issues, leading to traffic disruption.
1881679
Minor
Traffic dropped on IRB interface due to firewall filter with ip-options match condition
Product-Group=evo
Severity=Minor
On the Junos Evolved QFX platform, applying a firewall filter with ip-options as a match condition results in the device not properly honouring ip-options in packets.The issue happens due to software programming issue ip-options match condition was not getting programmed.
PR NumberSynopsisCategory: PFE COS features on BT based platforms
1879439
Minor
Rare evo-cda-bt crash in PTX10008 Junos OS Evolved with multiple FPCs when one FPC fails
Product-Group=evo
Severity=Minor
On all Junos Evolved PTX10008 platforms, the failure of one FPC (Flexible PIC Concentrator) can cause a rare evo-cda-bt crash on another FPC, resulting in a reboot.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1820118
Major
The aftman process crash is observed when IPv6 (IPv6 address with prefix length <= 88) filter configuration on the dsc interface
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX10001-36MR/PTX10008/PTX10016/PTX10004 platforms, the incorrect size lookup for IPv6 address with prefix length <= 88 causes aftman (Advanced Forwarding Management Process) process crash, resulting in traffic impact. The issue happens when IPv6 (IPv6 address with prefix length <= 88) filter configuration on the dsc interface.
1859044
Major
The IPv6 firewall filter applied on loopback 0 Is not processing NS and NA packets.
Product-Group=evo
Severity=Major
On PTX platforms running the Junos Evolved Operating System (OS), an Internet Protocol Version 6 (IPv6) filter applied to the Loopback 0 interface does not process incoming Neighbor Solicitation (NS) and Neighbor Advertisement (NA) packets in the Neighbor Discovery Protocol (NDP), though it does not impact traffic.
1859387
Major
PFH Interface Down After PFE Offline and Re-anchor
Product-Group=evo
Severity=Major
On all PTX Series with Junos OS Evolved, after performing several 'request chassis fpc slot <#> pfe-instance <#> restart' commands, BFD (Bidirectional Forwarding Detection) session flapping is observed, leading to partial service impact on the control plane. This issue is accompanied by the PFH (Packet Forwarding Host) interface down after the PFE (Packet Forwarding Engine) goes offline and subsequently re-anchors.
PR NumberSynopsisCategory: MX304 timing software
1869538
Minor
PTP FPGA ethernet interface down and cause PTP stuck in initializing state
Product-Group=evo
Severity=Minor
On Junos OS Evolved platforms and MX304 device with PTP (Precision Time Protocol) enabled, on bootup or FPC reboot, device will encounter issues with time synchronization, including devices going out of phase, disconnecting, or remaining in freerun state, potentially impacting applications that rely on precise timing. PTP will be stuck in initializing state.
PR NumberSynopsisCategory: QFX Access Control related
1851299
Minor
EX3400 Dot1x Radius accounting send incorrect value to the server for Acct-Input-Gigawords/ Acct-Output-Gigawords
Product-Group=evo
Severity=Minor
With Dot1x Radius Authentication and Accounting, when the Stop Accounting (due to disconnect) is sent to the Radius server the Acct-Input-Gigawords and the Acct-Output-Gigawords contains unexpectedly large value.
1872280
Major
The l2ald process crash is observed on non L2NG Junos platforms configured with "native-vlan-id" and "bridge-domains" on an IFL
Product-Group=evo
Severity=Major
On non L2NG (Layer2 Next Generation) Junos EX, MX and SRX platforms, the l2ald (Layer 2 Address Learning Daemon) process crash is observed when an IFL (Logical Interface) configured with "native-vlan-id" and "bridge-domains" and when certain config change takes place in an IFL which maps VLAN (Virtual Local Area Network) index to NULL. The dereferencing of this NULL pointer causes the crash.
PR NumberSynopsisCategory: Device Configuration Daemon
1848768
Major
MTU configuration is not applied from the configuration group after commit and "warning" is seen
Product-Group=evo
Severity=Major
When configuring MTU on interfaces through a configuration-group and commit the changes, those are not saved on the configuration file.
PR NumberSynopsisCategory: Firewall Filter
1872347
Critical
System becomes unresponsive or crash due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=evo
Severity=Critical
On Junos OS platforms, The system experiences memory exhaustion due to an mbuf (Memory Buffer) leak, system logs error message. This condition can cause the system to become unresponsive (hang state) or potentially crash, resulting in a VMcore file and service disruption. The issue arises when a firewall filter is applied to approximately 1k (1000) logical interfaces (IFLs), each filter containing over 250 terms and these filters are updated every 2-3 minutes, triggering updates for all filter attachments.
PR NumberSynopsisCategory: Firewall support for DNX
1853767
Major
Firewall Policer causing unintended packet drops when VRF route leak with static route to next-table is enabled
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX7024, ACX7100-32C/ACX7100-48L, ACX7509 series platforms when configured as layer 3 VPN (Virtual Private Network) PE (Provider Edge), enabling VRF (Virtual Routing and Forwarding) route leak with static route to next-table, the firewall policer drops packets.
1859053
Major
The firewall filter using "next-ip" as an action is not forwarding the packets on Junos Evolved ACX platforms if the "next-ip" is resolved to a static route that points to itself
Product-Group=evo
Severity=Major
On Junos Evolved ACX Platforms, when a firewall filter applied on an interface has the action set to "next-ip" with next-hop IP address defined which is if resolves in a direct route other than any routing protocol and to trigger ARP (Address Resolution Protocol) if static route is configured for this IP which points to itself, packets are not getting forwarded out causing traffic to impact.
PR NumberSynopsisCategory: Host path software for ACX platform
1821807
Major
Excessive logging in various log files is observed on EVO ACX platforms
Product-Group=evo
Severity=Major
On all Junos OS Evolved ACX platforms, the log message 'packetio[10514]: [t:17681] [Info] JUNIPER:: DevDb params are not needed for other platform productId:257' appears in the messages file and the JournalCtl. This message has no functional impact, but it should be logged only once during PFE initialization following a reboot and not continuously.
1851810
Major
The Devdb messages will be seen continuously on ACX EVO platforms
Product-Group=evo
Severity=Major
On ACX EVO platforms, due to the Discard filter programmed and the traffic hitting continuously on the same discard filter, the Devdb messages continuously keeps flooded.
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1854763
Minor
The post-convergence-lfa configuration causes a suboptimal-routing
Product-Group=evo
Severity=Minor
A suboptimal routing of traffic can be seen post configuring the post-convergence-lfa due to failover ID miss programming in the PFE.
1866442
Minor
ACX7K is seeing an info level log from evo-pfemand tied to removeEcmpNhInHw
Product-Group=evo
Severity=Minor
ACX7K is seeing an info level log from evo-pfemand tied to removeEcmpNhInHw
PR NumberSynopsisCategory: BGP MPLS VPN specific issues
1865858
Major
The FEC leak will be seen on all ACX EVO platforms
Product-Group=evo
Severity=Major
On all Junos OS Evolved ACX platforms, the hardware FEC (Forwarding Equivalence Class) resource leak will be seen when the programming of the MPLS (Multi-Protocol Label Switching) labels associated with the unilist nexthops fails due to any reason, which will lead to FEC resource exhaustion over time. As a result, further unilist NHIDs (Next-Hop IDs) can't be installed in the PFE (packet Forwarding Engine), resulting in traffic loss.
PR NumberSynopsisCategory: EVO ARP related PRs
1777973
Major
IPv6 neighborship can't be established if inet6 address is explicitly configured as unnumbered lo0.0
Product-Group=evo
Severity=Major
In Junos OS Evolved platforms the IPv6 neighborship can't be established if the inet6 address is explicitly configured as unnumbered lo0.0. In the affected releases, the system assumed the preferred-source-address knob to be present and thus affecting the NDP (Neighbor Discovery protocol) learning which impacts the traffic.
1817691
Minor
Proxy-arp restricted is not working as expected
Product-Group=evo
Severity=Minor
On all Junos OS Evolved platforms, when proxy-arp restricted is configured, the router will still respond to ARP (Address Resolution Protocol) requests even if the target IP address is within the same subnet and on the same interface as the ARP requester.
PR NumberSynopsisCategory: EVO Netstack icmpd
1822994
Minor
DNS (Domain Name System) resolution fails when nameserver is reachable via a routing instance bound to a line card port on releases prior to 24.1R1-Junos OS Evolved
Product-Group=evo
Severity=Minor
On Junos OS Evolved based platforms, while using ping, traceroute, or other utility that requires host name resolution, an error is raised indicating hostname resolution has failed.
PR NumberSynopsisCategory: Binding Queue
1859621
Minor
SNMP walk failure due to missing OID after FCO/TPA delete compression
Product-Group=evo
Severity=Minor
On all PTX Junos and Junos evolved platforms, an issue occurs when performing SNMP walks, resulting in the error No Such Instance currently exists at this OID. This is caused by a lifecycle management problem involving FCO (Factory Configuration Object) and TPA (Third-Party Attachment) objects. Specifically, when both FCO (IFDO) and TPA (IfSnmpInfo) are deleted in quick succession, only the FCO delete notification is sent, skipping the FCO modification callback that the TPA would typically trigger a delete event. As a result, the SNMP index mapping associated with the TPA is not properly updated, leading to missing entries during SNMP walks.
PR NumberSynopsisCategory: Issues related to EVO dependency layer including object graphs, incompletes, anomalies and nkdb
1854283
Major
[DCF14] [EVPN-VxLAN] After running a series of negative trigger tests on scale setup for 16 hours, traffic loss is seen in one IPv6 stream on ptx10001-36mr in CRB Spine and Border Router Role
Product-Group=evo
Severity=Major
1857091
Major
evo-aftmand-bt crash on Junos OS Evolved platforms triggered by rapid interface or route changes
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, the evo-aftmand-bt process crashes in a rare scenario involving rapid interface changes, such as interface flaps, configuration modifications, or reboots occurring within a short time interval. This crash results in a Packet Forwarding Engine (PFE) restart and traffic loss.
PR NumberSynopsisCategory: software upgrade infra issues
1868309
Minor
The command output for 'show system snapshot' randomly returns "Error: Snapshot is in progress ... Please retry later!"
Product-Group=evo
Severity=Minor
On all Junos OS Evolved platforms, when 'show system snapshot' command is executed an error message "Error: Snapshot is in progress ...Please retry later!" is thrown. This occurs randomly and is an expected behaviour.
PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1845336
Major
Memory leak during interface flap events on Junos Evolved Platforms
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, a memory leak is observed during continuous interface creation and deletion. The internal interface management logic allocates memory during interface (IFD) creation but fails to properly release it during deletion. Over time, this leads to increased memory consumption across multiple system applications. In high-scale environmentswith approximately 30 million interface flaps observed in a real deploymentthis leads to memory exhaustion and result in application restarts, potentially impacting services.
1859501
Minor
Interfaces with the same outer VLAN ID but different inner vlans or inner-lists/ranges are reporting a commit error
Product-Group=evo
Severity=Minor
On all Junos OS Evolved platforms, When an interface configured with the same outer VLAN ID but with different inner vlans or inner-lists/ranges, reports a commit error.
1867231
Major
Transit multicast traffic is getting blackhole due to peer interface flap
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, when peer interface flaps which connected to AE (Aggregated Ethernet) interface leading to synchronization of the interface up events with PFE (Packet Forwarding Engine) gets delayed. This issue results in the transit multicast traffic getting blackhole.
1867603
Major
Coredump during LAG disable
Product-Group=evo
Severity=Major
Pre-conditions are: 1. Aggregate Ethernet interface is configured with/without lacp 2. Aggregate Ethernet interface is configured with BFD configs. Trigger is: 3. With the specified configuration, if any config change is issued on AE IFL then it results in aggd core. 4. One such example is [edit interfaces ae2301 unit 0] + disable; There is no work-around, so none is mentined.
1880635
Major
Interface remains administratively down state, fails to recover after execution of CLI command "request interface bounce"
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX platforms, executing the CLI command "request interface bounce" causes the member Ethernet interface (et-x/x/x), which is part of the Aggregated Ethernet (AE) bundle, to remain in an administratively down state and not recover after the defined interval. As a result, this condition can cause a traffic impact.
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1854932
Major
TCP connection stalls with BGP Explicit Null and MPLS forwarding on certain Junos Evolved PTX platforms when sending packets exceeding MTU limit
Product-Group=evo
Severity=Major
On Junos Evolved PTX10001, PTX10004 and PTX10008 platforms, if LDP(Label Distribution Protocol) is initially established over IP protocol, and later transitions to MPLS(Multiprotocol Label Switching) encapsulation (mpls-forwarding), the outgoing TCP(Transmission Control Protocol) packet size is not adjusted to account for added MPLS label. As a result, packets exceeding the configured interface MTU(Maximum Transmission Unit) are dropped before transmission. Since the receiving side does not receive these packets, the LDP session eventually times out due to "hold time expiry".
1865403
Major
Memory leak is observed when Telemetry is configured
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms having Telemetry configured, the memory allocations in 512 bytes slab that are seen to be growing in problem state, are related to write on a unix domain socket (internal to application). Since the data is not read, the send buffer keeps growing and the associated memory does not gets released. Every telemetry response from the producer does a 1 byte write on this socket and over a period of time the send buffer gets full. The default size of the unix socket send buffer is set to 512MB. But there is no functional impact.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1852152
Major
The l2ald-agent process crashes when the scale of IFBDs within a single VLAN exceeds the capacity of the Rx rtsock buffer, causing an overflow
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms, scaling of IFBDs (Interface Family Bridge Domain) within a single VLAN(Virtual Local Area Network) will result in the formation of rtsock messages that exceed the Rx size of the rtsock buffer (8192 bytes). This will cause the l2ald-agent (Layer 2 Address Learning Daemon) process to crash. There will be no traffic impact.
1853879
Major
The IRB VGA is not shown after deleting one of the IRB interfaces with the same VGA address configured
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, when two different IP addresses under an IRB interface are configured with the same virtual-gateway-address (VGA), and one of the IP addresses is deleted, the VGA IP address gets cleaned up in the router/switch resulting in traffic loss in the remaining address entry.
1859302
Major
EVPN next-hop installation for ESI over VTEP fails after remote device restart on PTX and QFX platforms.
Product-Group=evo
Severity=Major
On all Junos Evolved PTX and QFX series platforms, running EVPN (Ethernet Virtual Private Network) and ESI LAG (Ethernet Segment Identifier Link Aggregation Group) is causing issues with the next-hop installation after restarting of remote or peer devices, which affects the overall network stability and performance.
1874476
Major
Transient traffic loss for CE in an EVPN MPLS setup with Multi-Homing
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms with EVPN MPLS, Multi-Homing scenarios, when there is a Multi-Homing peer node reboot, the destination route entries that were learned locally on IRB(Integrated Routing and Bridging) interface of rebooted node get deleted on other multi-homing peers without RE-ARP (Routing Engine-Address Resolution Protocol) causing transient traffic loss for CE (Customer Edge) traffic.
PR NumberSynopsisCategory: Lacp related problems and issues.
1859633
Minor
LACP session destroy time is not getting updated in PFE
Product-Group=evo
Severity=Minor
On all Junos Evolved platforms, the LACP session destroys time is not being updated in the PFE due to the session history limit being exceeded (50 sessions). This issue does not cause a functional impact but generates unnecessary log messages, which can be misleading to users.
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1808773
Minor
On ACX7348/ACX7332 all traffic is blocked on FPC after RE Switchover
Product-Group=evo
Severity=Minor
On ACX7348/ACX7332 with MACsec enabled in channelized interfaces, after performing a double RE switchover (primary RE swap to backup and then back to active), traffic in FPC1 stops in being forwarded.
1823278
Minor
Traffic blackhole on MACsec enabled interfaces due to ARP packet drops
Product-Group=evo
Severity=Minor
On Junos OS Evolved ACX7509, ACX7348 and ACX7332 platforms, traffic drops will be seen on MACsec enabled interfaces after RE (Routing Engine) switchover or picd restart. This is due to ARP (Address Resolution Protocol) packets of size less than 64 bytes being errenously discarded on MACsec interfaces as Runt discards. This will result in traffic blackholing on those interfaces.
PR NumberSynopsisCategory: EVO-AFT Infrastructure PFE related issues
1869773
Critical
Applying a Layer2 filter on interface on results in protocol flaps and traffic disruption on other interfaces on the same PFE
Product-Group=evo
Severity=Critical
Applying a Layer2 filter on and interface on Junos OS Evolved PTX platforms results in protocol flaps and traffic disruption on other interfaces on the same PFE. Please refer TSB96988 [juniper.net] for more details.
PR NumberSynopsisCategory: Express PFE MPLS for EVO platforms
1874004
Major
Route installation for MPLS labels fails when an RSVP LSP goes down
Product-Group=evo
Severity=Major
On all Junos Evolved PTX platforms in a Multi-Protocol Label Switching (MPLS) environment, where the device is the ingress router in a Label Distribution Protocol (LDP) over Resource Reservation Protocol (RSVP) topology, all traffic to remote Layer 3 Virtual Private Network (L3VPN) destinations is blackholed when an RSVP Label Switching Path (LSP) goes down (e.g., cleared or flapped). This happens because the route installation for MPLS labels in the Packet Forwarding Engine (PFE) hardware fails, resulting in missing or incorrect forwarding entries.
PR NumberSynopsisCategory: Category to track runtime issues during package install
1822040
Major
ACX7024 SSH connection unresponsive multiple times after filesystem errors resulting from "uswitchd" crash.
Product-Group=evo
Severity=Major
SSH connection unresponsive multiple times after filesystem errors resulting from "uswitchd" crash.
PR NumberSynopsisCategory: AAA, auditd issues
1862203
Minor
Radius authentication is failing when Challenge Token is entered
Product-Group=evo
Severity=Minor
On all Junos and Evo platforms, the Radius Multi-Factor Authentication (MFA) failing for user login if the password and token were provided in two separate steps.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1864996
Major
Device sends route advertisements on a deleted interface
Product-Group=evo
Severity=Major
On the QFX5230-64CD platform running Junos Evolved 23.4X100-D30-EVO or later, disabling RA (router-advertisement) on an interface does not prevent the device from continuing to send RA messages. Furthermore, the interface status still indicates that RA is active despite the configuration change.
PR NumberSynopsisCategory: EVPN control plane issues
1846096
Critical
RPD restart immediately on EVPN Designated Forwarder PE with Graceful-restart results in 100% traffic loss for 12-15 secs
Product-Group=evo
Severity=Critical
With a EVPN PE running 24.2, 24.4 releases with Graceful restart enabled, if RPD is restarted or flaps, traffic loss for 15s could be seen to Multihomed CEs
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1833660
Major
Stale MAC entries may remain in the MAC table of EVPN routing instances after rapid MAC-IP move scenarios
Product-Group=evo
Severity=Major
On all Junos OS and Junos OS Evolved platforms with EVPN-MPLS (Ethernet Virtual Private Network - Multiprotocol Label Switching) setup , stale MAC entries may remain in the MAC table of the EVPN (Ethernet Virtual Private Network) routing instances during rapid MAC-IP move scenarios. This can cause MAC tables to reach their limits preventing new MAC addresses learning and user registration.
PR NumberSynopsisCategory: Express PFE FW Features
1790275
Major
Incorrect peak utilization shown in show npu memory info due to touched bucket method
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, peak utilization for Key Hash Table (KHT) resources is computed using the "touched bucket" method, where a bucket is marked as used if any of its three cells are occupied. This calculation inflates the actual resource usage. The logic has been updated to use the "scaled bucket" method, which accounts for unutilized cells within a bucket and provides a more accurate and consistent peak utilization value aligned with instant usage metrics.
PR NumberSynopsisCategory: ACX7332 ACX7348 Interfaces software
1818810
Major
On ACX7348 and ACX7332 , Jack Out Jack In of FPC blocks MACSEC traffic
Product-Group=evo
Severity=Major
On ACX7348 and ACX7332 Junos Evolved Platforms during Jack out of FPC, MACSEC resources are not properly cleaned up, this results in initialisation failure and MACSEC traffic getting blocked after FPC is Jacked In.
PR NumberSynopsisCategory: ACX7332 & ACX7348 Platform Software
1809091
Minor
ACX7024 sees a vmcore and restarts or potentially hangs on reboot
Product-Group=evo
Severity=Minor
ACX7024 sees a vmcore and restarts or potentially hangs on reboot
PR NumberSynopsisCategory: ACX7509 Linecard (FPC) related issues
1821275
Minor
100G LR4 optics did not come up after upgrade on Junos Evolved ACX7509 platform
Product-Group=evo
Severity=Minor
On all Junos Evolved ACX7509 platform, interfaces configured with QSFP-100GBASE-LR4/ 2X100GBASE-LR4 optics could fail to come up following a software upgrade or system reboot. As a result, the 100G-LR4 interface/link will remain down after the upgrade or reboot, leading to a complete loss of traffic.
PR NumberSynopsisCategory: jdhcpd daemon
1843596
Minor
DHCPv6 Renew from a dual-stack CPE may be ignored if DHCP server is using DUID type 3 (DUID-LL) and DHCPv6 binding doesn't exist
Product-Group=evo
Severity=Minor
DHCPv6 Renew packets from dual-stack CPE could be silently ignored by MX configured as DHCPv6 local server if such DHCPv6 binding doesn't exist.
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .
PR NumberSynopsisCategory: authd (AAA) library code
1860913
Major
The authd process crashes when /etc/resolv.conf file is empty
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX platforms, when DHCP (Dynamic Host Control Protocol) local server is configured and the /etc/resolv.conf file is empty with no data/domain information the authd process crash observed. There will be no forwarding traffic impact due this issue and there will be no issue to existing sessions. However, new sessions will have login issue.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1845079
Minor
Unnecessary trace log files related to licenses are generated
Product-Group=evo
Severity=Minor
On Junos platforms agile-licensing infra, when upgrading to 23.4R1 and above, unnecessary trace log files related to licenses are generated. This issue has no impact on traffic.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1850387
Minor
The dot1xd crash on MACsec enabled ports due to key length limit
Product-Group=evo
Severity=Minor
On Junos and Junos OS Evolved platforms supporting MACsec (Media Access Control security), when secret key-chain with more than 64 character is configured, it results in crash for dot1xd service causing traffic impact on all MACsec enabled ports.
PR NumberSynopsisCategory: Multicast for L3VPNs
1861726
Major
The MVPN traffic forwarding is affected when BGP PIC is enabled
Product-Group=evo
Severity=Major
On all Junos OS and Junos OS Evolved platforms, enabling BGP-PIC (Border Gateway Protocol-Prefix Independent Convergence) is causing the issues with forwarding MVPN (Multicast Virtual Private Network) traffic.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1849296
Minor
The self-generated traffic on Junos platforms use the incorrect source IP with ECMP configuration
Product-Group=evo
Severity=Minor
On all Junos platforms configured with Equal-Cost Multi-Path (ECMP) routing, self-generated traffic selects an incorrect source (Internet Protocol) IP address. As a result, the peer device lacks the relevant route information, causing self-generated traffic to be dropped. This issue is specific to ECMP configurations and does not impact data traffic.
PR NumberSynopsisCategory: Path computation client daemon
1823220
Minor
Authentication failure will be seen for routing protocols when MD5 is configured for routing protocols and PCEP on Junos OS Evolved platforms post reboot
Product-Group=evo
Severity=Minor
When MD5 is configured for PCEP (Path Computation Element Protocol) on Junos OS Evolved platforms, MD5 will not work for other protocols after reboot. Authentication failure will be seen and it causes a connectivity issue or a service impact.
PR NumberSynopsisCategory: Phone-Home-Client Infrastructure
1811521
Major
PHC gets initiated and sends DNS request to Juniper server "redirect.juniper.net" even when device is supposed to get provisioned using ZTP with vendor specific option 43
Product-Group=evo
Severity=Major
Rarely, on all Junos platforms, PHC (Phone Home Client) is signaled to attempt bootstrapping by AIU (Auto Image Upgrade) when legacy ZTP (Zero Touch Provisioning) fails if vendor specific options (option 43 is sent by DHCP server) are not valid. This is followed by PHC sending DNS request to resolve "redirect.juniper.net" which is the redirect Juniper Server even if DHCP is released by ZTP and no IP is expected to be present.
1871802
Critical
High memory and CPU usage due to unintended phone-home client activation
Product-Group=evo
Severity=Critical
On Junos OS Evolved platforms, high memory and CPU usage may occur if the phone-home client (PHC) is unintentionally triggered, such as when the device boots with factory default settings or when phone-home is manually configured. This can lead to system slowness, crashes, and eventual device reboots.
PR NumberSynopsisCategory: Protocol Independant Multicast
1826383
Major
Rapid increment of "Hardware input drops" on command output "show pfe statistics traffic" due to PFE trapcode "dlu.ucode.ip_mc_iif_mismatch"
Product-Group=evo
Severity=Major
The issue is due to the PIM Join-load-balance feature. When the router has multiple ECMP paths to reach the multicast source and is configured for PIM Join-load-balance, Load balancing of Join will be done creating an active upstream path and a standby upstream path. When multicast streams are received on the standby upstream path, an IIF_MISMATCH is generated, consequently Standby path gets converted into Active path & PIM Prune will be sent on old active path and periodic joins will be cancelled on old Active path. However, in this case, protocol PIM prematurely removes the old active path without sending a prune on that path and removing the periodic old active joins. There can be another scenario where there is transition from one standby path to another standby path. In that case also old standby path needs to be pruned and periodic joins needs to be cancelled.
PR NumberSynopsisCategory: Category for QFX5K EVO Platform Software PRs related to Chas
1816064
Major
QFX5130-48C/QFX5130-48CM: In rare cases, "FPC 0 Volt Sensor Fail" or "FPC 0 Voltage Threshold Crossed" alarm seen after bootup
Product-Group=evo
Severity=Major
In rare cases, "FPC 0 Volt Sensor Fail" or "FPC 0 Voltage Threshold Crossed" alarm is seen after bootup on QFX5130-48C/QFX5130-48CM.
1838417
Major
Route modification or deletion will be blocked on Junos Evolved QFX platforms if the next-hop installation fails in a scaled environment
Product-Group=evo
Severity=Major
On Junos OS Evolved QFX platforms in a scaled environment (approximately 32K), a next-hop installation failure will occur when next-hop resources are exhausted. In such scenarios, route modifications or deletions will be blocked, resulting in stale entries persisting in the next-hop and routing tables. This leads to traffic loss.
1841882
Major
QFX5240-64OD/QD: Update BIOS to v41.01.08.06
Product-Group=evo
Severity=Major
Customers are recommended to Upgrade the BIOS to v41.01.08.06.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1868085
Major
The rpd process crashes and asserts are seen due to memory leak
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, rpd process crashes and asserts are seen due to a memory leak when BGP sharding is enabled and 'show route' is performed continuously.
PR NumberSynopsisCategory: Issue related to mcnh routing infrastructure within RPD
1876781
Major
Transient traffic loss during multicast route convergence scenarios
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms, a rare issue related to route updates, it occurs when in a platform with multiple FPCs (Flexible PIC Concentrators) the MCNH (Multicast Next-Hop) runs in a timing issue causing a deletion of an in-use route before the traffic is pointed to a new one coming from a route update, causing traffic loss.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1861451
Major
BGP PIC failover is taking longer than expected when IS-IS as an IGP enabled with LFA
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, in a BGP-L3VPN (Border Gateway Protocol - Layer 3 Virtual Private Network) setup when configured with BGP PIC (Prefix-Independent Convergence) on an ingress PE's (Provider Edge) VRF (Virtual Routing and Forwarding) routing-instance and having IS-IS (Intermediate System-to-Intermediate System) as an IGP (Interior Gateway Protocol) which if enabled with LFA (Loop Free Alternative), BGP PIC failover is taking loger time than expected due to lag in the route change for the BGP path to be used. This is causing traffic loss until global convergence.
1863248
Major
On all Junos OS Evolved platforms, traffic loss will be seen after switching the LSP from SRTE to L-ISIS
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms with Segment Routing Traffic-Engineering (SRTE) and Labeled- Intermediate System- Intermediate System (L-ISIS) configuration, when a service route is resolved over SRTE route in inet6color.0 and if the SRTE path in inet6color.0 is deactivated/goes down, the SRTE route is deleted and service route starts resolving over L-ISIS. However traffic loss for 20 minutes or more is seen after switching the Label Switched path (LSP) from SRTE to L-ISIS path.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1817450
Minor
Route on backup shard is not resolved under certain conditions
Product-Group=evo
Severity=Minor
after protocol BGP is deactivated, the resolution tables __raass_ at backup RPD are marked as deleted, and not resurrected post commit sync.
1845425
Major
Traffic blackhole is observed for IPv4 /32 LDP prefixes advertised over BGP-LU when BGP sharding is configured
Product-Group=evo
Severity=Major
On Junos OS MX and Junos OS Evolved PTX platforms with MPLS (Multiprotocol Label Switching) and BGP (Border Gateway Protocol) sharding configured, the route is not resolved as the resolver does not request PNH (Protocol Next Hop) information from RaaS (Routing as a Service) server although BGP added the route resolution in the inet.3 table. This issue leads to IPv4 /32 LDP (Label Distribution Protocol) prefixes advertised over BGP-LU (BGP Label Unicast) not being installed in the mpls.0 table i.e. corresponding labels being marked as hidden in the MPLS routing table (mpls.0), preventing proper traffic forwarding, leading to a traffic blackhole.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=evo
Severity=Major
On all Junos, Junos OS Evolved, and cRPD platforms, due to deadlock in internal processes, BGP (Border Gateway Protocol) route advertisement fails leading to traffic disruption.
PR NumberSynopsisCategory: Resource Reservation Protocol
1864949
Major
User traffic dropped after ISIS went down on one side with trapcode observed
Product-Group=evo
Severity=Major
On all JUNOS and JUNOS evolved Operating Systems, if a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in unexpected traffic blackholing on the router at the downstream end of the flapping link.
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.
PR NumberSynopsisCategory: PTX10K Timing/Sync-E issues tracking
1823281
Minor
PLL Alarm observed on CB0
Product-Group=evo
Severity=Minor
On all Junos Evolved PTX10004, PTX10008 and PTX10016 platforms, a phase-locked loop alarm is observed on the control board 0 due to clock fault resulting in impact in timing features however no services will be impacted.
1855958
Major
Chassis synchronization clock enters holdover state upon secondary BITS input failure
Product-Group=evo
Severity=Major
On chassis based using EVO systems with more than one BITS (building-integrated timing supply) port platforms, after secondary BITS failure, chassis clock goes into holdover state.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1842862
Minor
MPC10 continuously generates "VBFMAN:PPMAN-SERVICE-TIMEOUT: Session Down notification callback not found distribKey" error messages after GRES
Product-Group=evo
Severity=Minor
If BFD liveness detection is enabled and used for DHCP subscribers terminated on MPC10/11 line card and GRES is performed, this MPC may start to continuously generate error messages if such subscribers log out.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1839362
Minor
The commit error is seen in backup RE on MX platforms
Product-Group=evo
Severity=Minor
On all MX platforms, the commit fails in Backup RE during configuration commit where "fast-synchronise" and "graceful-switchover" are being committed together.
PR NumberSynopsisCategory: ACX7000 interface software related issues.
1869296
Major
100G links do not come up with TX LOS on ACX7100-32C platform
Product-Group=evo
Severity=Major
On ACX7100-32C platform, when the device is rebooted, 100G links do not not come up with TX LOS.
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1867003
Major
IS-IS adjacency between CE devices is not established over L2 circuit
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX10003 platform, In scenario where IS-IS (Intermediate System to Intermediate System) adjacency forming between CE (Customer Edge) devices over Layer2 circuit ("encapsulation vlan-ccc") through PTX10003 as a PE (Provider Edge) in this connectivity, IS-IS hello (IIH) packets from host CE incorrectly direct to connected PE instead of forwarding it to the remote CE over this Layer2 circuit. This is causing failure to establish the IS-IS adjacency between the CE devices. In certain upgrade scenarios where a PE device is upgraded to an affected release, the IS-IS adjacency between the CE devices may fail to establish causing service imapct.

 




Extended Solution

23.4R2-S5-EVO - List of Known issues 

PR NumberSynopsisCategory: ACX7020 Lite Platform interface issues
1855426
Minor
All the physical links remain down post performing "restart evo-pfemand"
Product-Group=evo
On Junos Evolved ACX platforms, all the physical links remain in down condition post restarting "evo-pfemand", due to ports were enabled before the PFE (Packet Forwarding Engine) related modules bringups and configurations.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO
PR NumberSynopsisCategory: Border Gateway Protocol
1789863
Major
The rpd crash can be seen when large number of VRF instances are created and bgp peering terminated
Product-Group=evo
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) crash will be observed when BGP (Border Gateway Protocol) is terminated by the user and if large number of VRF instances are created. This happens as some BGP internal data structure is not cleaned up properly. This crash can lead to a temporary traffic drop, but the system will automatically recover.

Resolved In: evo:21.4X9-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=evo
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:25.2R1-EVO junos:20.3X75-D52 junos:25.2R1
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=evo
On Junos platforms, in BGP multipath scenario, it is observed that due to a software issue, the forwarding table does not show multipath next-hop for newly added route in case of high number of next-hop.

Resolved In: evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: QOS issues in EVO for BCM XGS Platforms
1865671
Major
ECN copy support from VXLAN header to inner Header on Type-5 decap tunnels
Product-Group=evo
On Junos OS Evolved QFX5230 and QFX5240 platforms, a new support has been added to copy ECN from VXLAN header to inner Header on Type-5 decap tunnels.

Resolved In: evo:23.4X100-D31-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO
PR NumberSynopsisCategory: CoS support on DNX
1773980
Minor
Traffic forwarding will be affected over physical interface if user try to configure "hierarchical-scheduler" knob on AE member interface
Product-Group=evo
On Junos Evolved ACX and PTX platforms, Traffic forwarding will be affected over physical interface if user try to configure "hierarchical-scheduler" knob on AE(aggregate-ethernet) enabled physical interface.

Resolved In: evo:23.2R2-EVO evo:23.2R2-S1-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:23.2R2 junos:23.4R1-S1 junos:23.4R1-S1-J6 junos:23.4R2
PR NumberSynopsisCategory: Firewall support for DNX
1869363
Minor
The router incorrectly assume the VRRP Master role on Junos Evolved ACX platforms
Product-Group=evo
On Junos Evolved ACX platforms, dual VRRP mastership may be seen with VRRP configuration and having filter configuration with log/syslog action. Due to the issue, the VRRP advertisements were not processed correctly, it was receiving the advertisements but getting discarded when log action is configured on the filter, so it assumed the master role. The issue may affect traffic using VRRP protocol.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO
PR NumberSynopsisCategory: DNX L2 related features
1841573
Minor
High CPU utilization observed on all Junos Evolved ACK7k platforms
Product-Group=evo
On all Junos Evolved ACX7k platforms, high CPU utilization is observed when multiple IFLs (logical interface) are configured over the same IFD (physical interface device). The Broadcom (Brcm) MACs become out of sync with Routing Engine (RE) MACs, performance is affected, and then there is potential traffic disruption.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO
PR NumberSynopsisCategory: DNX VPLS
1807349
Critical
Traffic drop is observed when evo-pfemand is restarted in VPLS scenario
Product-Group=evo
On Junos Evolved ACX platforms, when Virtual Private LAN Service (VPLS) is configured, on restarting evo-pfemand deamon, the VPLS next-hop lookup fails, impacting traffic.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S2-J11-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO
PR NumberSynopsisCategory: Issues related to EVO dependency layer including object graphs, incompletes, anomalies and nkdb
1874151
Critical
Rare assert with an Junos Evolved process
Product-Group=evo
This is a rare chance of a process panic. This can be seen in Evo apps. If seen in forwarding apps it can result in system reboot and resulting traffic loss.

Resolved In: evo:23.4X100-D31-EVO evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: management ethernet related issues - mgmt-ethd daemon
1800373
Critical
CPU hike will be observed when scaled BGP converge through management interface
Product-Group=evo
In large scale scenario when BGP routes resolved over WAN interface goes down, all the BGP routes will get re-converged through management interface which results into CPU hike on Junos OS Evolved platforms.

Resolved In: evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.3X80-D45-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO
PR NumberSynopsisCategory: System Management daemon and related issues
1859095
Minor
On Junos OS Evolved based platforms "Sysman.re" crash file might be observed in particular conditions
Product-Group=evo
On all Junos OS Evolved based platforms, when the RE (Routing Engine) node experiences switchover, offline/online transitions, or rebooting, a 'Sysman.re' crash file might appear in rare cases and could cause traffic impact.

Resolved In: evo:23.4X100-D40-EVO evo:24.4R2-EVO evo:25.3R1-EVO junos:25.2R1
PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1875917
Major
Disabling a single AE IFL in a MAC-VRF can bring the entire AE interface down
Product-Group=evo
On all Junos Evolved platforms, under MAC-VRF routing configurations, when any Layer 3 IFL is deactivated, it causes the associated AE interface to go administratively down, leading to complete traffic disruption across the AE bundle.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: EVO Services Jflow PRs for defect & enhancement requests
1816542
Major
A router running sampling may see the msvcs-db daemon run at 99.9% for an extended period
Product-Group=evo
A router running sampling may see the msvcs-db daemon run at 99.9% for an extended period

Resolved In: evo:21.4X9-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:23.2R2-J11-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1602717
Major
Ephemeral/dynamic port range has been modified in EVO platforms
Product-Group=evo
On all EVO platforms, near-end port is not within RFC/IANA standards as ephemeral/dynamic port range has been modified.

Resolved In: evo:20.4R3-EVO evo:20.4X80-D12-EVO evo:21.2R2-EVO evo:21.2R3-EVO evo:21.3R1-EVO evo:21.3R2-EVO evo:22.4R3-EVO junos:21.1R3-S5 junos:21.2R3 junos:21.3R2
PR NumberSynopsisCategory: evil gateway + anything else built for dev test + enhancemen
1824540
Major
The "request system debug-info" takes too long time than expected
Product-Group=evo
On Junos Evolved PTX10008 and PTX10016, the "request system debug-info" takes too long time than expected. This issue has no impact on device functionality.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:24.2R2-EVO evo:24.4R1-EVO
PR NumberSynopsisCategory: Express PFE FW Features
1731896
Minor
Implement reset to zero of kht-peak-utilization in `show npu memory info`
Product-Group=evo
New enhancement added to have the ability to reset the peak utilization value in 'show npu memory' info command to zero. All FLT stats will be reset together using the 'clear npu memory info' command that is newly added as part of this PR.

Resolved In: evo:25.3R1-EVO junos:25.3R1
1872657
Major
PTX10003 EVO parity error recovery from shadow copy
Product-Group=evo
Parity error recovery mechanism has been missing for the FLT block in ZX ASIC. With this PR, it will be fixed.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1846294
Major
Memory Leak: Memory leak is detected with rpd task blocks "rpd-trace"
Product-Group=evo
Memory Leak: Memory leak is detected with rpd task blocks "rpd-trace"

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.2R1-EVO junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: JDHCP is a daemon for EVO platform to handle DHCP protocol
1884983
Major
[ACX7509] DHCPv4/v6 packets may be dropped because DHCP packets are not routed to kernel after initial jdhcpd starts
Product-Group=evo
Under certain conditions, the DHCP registration to IFL/IFD event fails and JDHCPD does not get IFL/IFD events which cause DHCP packets to fail to route to the kernel and then leads to DHCP packet drop. Doing a simple restart of dhcp process would resolve the issue . CLI command :- "restart jdhcpd"

Resolved In:
PR NumberSynopsisCategory: Multiprotocol Label Switching
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=evo
On all Junos and Junos Evolved platforms, an out-of-memory condition in the rpd process caused by uncontrolled memory allocation leads to the rpd process crashing.

Resolved In: evo:25.2R1-EVO junos:23.4R2-S4-J9 junos:23.4R2-S5 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Multi Protocol Label Switch OAM
1884920
Major
PDT: PTX10k4 OAM BFD session flap continously after FPC restart
Product-Group=evo
Unidimensional BFD scale supported for RSVP BFD(Centralized BFD) is 4k bfd sessions in PTX10k4

Resolved In:
PR NumberSynopsisCategory: Multicast Routing
1863470
Major
The rpd crash due to memory corruption in PIM/MSDP network
Product-Group=evo
On all Junos and Junos Evolved platforms, enabling PIM (Protocol Independent Multicast) or MSDP (Multicast Source Discovery Protocol) may cause a rare memory corruption during the update of the MSDP Source Active route. This issue primarily affects highly scaled environments, leading to rpd (routing protocol daemon) coredumps and potential traffic loss.

Resolved In: evo:23.2R2-S2-J10-EVO evo:23.2R2-S4-EVO evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S4 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1829765
Major
uKern DDOS Aggregate stats not updated for BFD packets at system wide and FPC level
Product-Group=evo
BFD Aggregate policer in 22.4R3S5 polices BFD Single-Hop packets. Hence the BFD Aggregate statistics may not reflect accurate statistics for other BFD packets like Multihop and Bundle. This will be fixed in upcoming release.

Resolved In:
PR NumberSynopsisCategory: QFX5K EVO Platform Optic
1862893
Major
Traffic forwarding fails to recover after manually removing and reinserting the Direct Attached Copper cable
Product-Group=evo
On Junos Evolved QFX5K, when the Direct Attached Copper cable is removed and reinserted, traffic forwarding does not recover.

Resolved In: evo:23.4X100-D31-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1687890
Minor
BGP inactive route's RSVP LSP information is not printed in 'show route <> extensive' output when sharding is enabled.
Product-Group=evo
With sharding enabled, when BGP route is resolved over RSVP LSP, LSP name is not displayed in 'show route <> extensive' output for inactive route. This will fixed via RLI [ Umbrella RLI to fix small Topgun Sharding Gaps]

Resolved In: evo:24.1R1-EVO junos:24.1R1
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1840635
Major
Vmhost upgrade fails due to vrf instance validation error
Product-Group=evo
During vmhost image upgrades on Junos PTX10008/PTX10016 routers running Junos 22.4R3 and above versions, when more than two VRF(Virtual Routing and Forwarding) instances are configured, the configuration validation fails with the "RT Instance: Maximum 2 vrf instances are supported" error. This impacts the vmhost image upgrade on the device. via CLI when using the "request vmhost software add reboot" command.

Resolved In: junos:20.3X75-D36
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1757389
Minor
"show route detail" shows "State: " for routes when route-record is enabled
Product-Group=evo
On all Junos and Junos OS Evolved platforms with route-record enabled, some routes will be seen in State: due to race condition. There is no functionality issue, this is a display issue.

Resolved In: evo:22.4R3-EVO evo:22.4R3-S1-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:24.1R1-EVO evo:24.4R2-EVO junos:23.2R1-S2 junos:23.2R2-J14 junos:23.4R1-S1 junos:24.1R1
PR NumberSynopsisCategory: Issues related to control plane security
1860970
Minor
SIB HA wait timeout error upon graceful RE switchover
Product-Group=evo
SSH issue from the Routing Engine to the FPC causes SIB HA timeout error upon RE switchover. All the SIBs will be reset as a result of that.

Resolved In:
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Major
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=evo
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd application may not come online anymore after toggle mastership between Routing Engines with event-options and archive-sites configured
Product-Group=evo
Upon several mastership switches master-eventd application might stay offline after switchover if event-options is configured with archive-sites events triggered. The switchover is performed while the archive-site is not reachable on the new Master RE. master-eventd is the application responsible for directing all journal messages local and from remote nodes to syslog. An Alarm is generated to report such an event. master-eventd application is only operating on the Master Routing Engine.

Resolved In:
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=evo
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1842518
Major
The device become unresponsive in a race condition due to maximum process (maxproc) limit
Product-Group=evo
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.

Resolved In: evo:22.2R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S4 junos:23.4X30-D20 junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: PTX/QFX100002/8/16 interface software
1817562
Major
DFE tuning stuck due to configuration error preventing interface from coming up
Product-Group=evo
On Junos PTX10008, PTX10016 and PTX platforms with FPC3-PTX, after a router reboot or FPC (Flexible PIC Concentrator) restart, DFE (Decision Feedback Equalisation) tuning is initiated on all active interfaces. If a tuning failure occurs due to a FEC (Forward Error Correction) mismatch, the process gets stuck. Even after correcting the error, the interface remains down as the system cannot initiate a new DFE tuning until the previous attempt completes.

Resolved In: junos:22.4R3-S4 junos:22.4R3-S5 junos:22.4R3-S7 junos:23.2R2-S3 junos:23.4R2-S5 junos:24.4R1
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1842666
Minor
IPv6 Neighbor Discovery Packets Punted to RE Instead of Transiting via Core Interface
Product-Group=evo
In a cross-connect (L2Circuit) scenario, IPv6 Neighbor Advertisement (NA) and Neighbor Solicitation (NS) packets originating from the CE side are being punted to the Routing Engine (RE) instead of passing through the L2Circuit over the core interface.

Resolved In: evo:23.2R2-S1-J11-EVO evo:23.2R2-S1-J14-EVO evo:23.4R2-S3-J25-EVO evo:23.4R2-S4-J21-EVO evo:24.2R2-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.1R1-EVO

 


 

Modification History

First publication 2025-06-27