Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX (For SRX platforms see TSB101938 [juniper.net])

Alert Description

Junos Software Service Release version 24.2R2-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For review

Solution

Junos Software service Release version 24.2R2-S2 is now available.

24.2R2-S2 - List of Fixed issues 

PR NumberSynopsisCategory: NFX Series Platform Software
1850987
Major
INSIGHTD messages logged every 5 seconds on NFX 250
Product-Group=junos
Severity=Major
INSIGHTD messages logged every 5 seconds on NFX 250, these are harmless and can be hidden from syslog. jinsightd[19158]: JINSIGHTD_SENSOR_RESUBSCRIPTION: RetrySubscription: Triggering Re-subscription. retry_count 40005 jinsightd[19158]: JINSIGHTD_SENSOR_RESUBSCRIPTION: RetrySubscription: Triggering Re-subscription. retry_count 40006
1858495
Major
The auto-negotiation is not working properly on NFX350 platform using 1 Gigabit Ethernet SFP
Product-Group=junos
Severity=Major
On NFX350 platforms connected to certain peer devices over SFP 1 Gigabit Ethernet (GE) with auto-negotiation enabled, a status mismatch occur during the initial handshake. As a result, the port status on the peer device appear as up/down affecting the traffic. This behavior does not occur when the peer device is an NFX250 or an SRX-Series platform.
PR NumberSynopsisCategory: SRX ISSU infra related issues
1882569
Major
ISSU getting aborted due to configuration-synchronize failure on Junos SRX platforms
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having chassis cluster configuration-synchronize configured, ISSU (In-Service Software Upgrade) gets aborted due to a configuration synchronization (config-sync) failure and the Redundancy Group (RG) priority is set to 0, preventing a successful failover during the ISSU process resulting in the ISSU process gets aborted causing the upgrade failure.
PR NumberSynopsisCategory: "agentd" software daemon
1779722
Minor
The interface fails to come up after FPC reboot if the streaming server and export profile are not configured correctly
Product-Group=junos
Severity=Minor
On all Junos and Junos evolved platforms with telemetry enabled, if the streaming server and export profile for reporting-rate are not properly configured in the analytics settings, rebooting the FPC would prevent any of the interfaces from coming up.
1839478
Major
/junos/system/linecard/interface/traffic/ sensor is seeing packet drops but there is no actual drops
Product-Group=junos
Severity=Major
On all MX devices with ULC line cards (MPC10/11 and LC4800/9600), when subscribing to the /junos/system/linecard/interface/traffic/ native telemetry subscription path, the exported data includes the following containers: /interfaces/interface//interfaces/interface/state//interfaces/interfaces/state/counters. The picd and evo-aftmand-bt daemons are responsible for exporting data for these paths. When running the CLI command "show network-agent statistics detail, " it shows packet and byte statistics for each sensor per daemon. The picd daemon reports some drops due to an error in the CLI's data reporting. However, no actual packet drops occur. The issue arises from a bug in the bookkeeping code that tracks packet statistics, causing the CLI to incorrectly show drops even when no packets have been lost. This issue only affects the CLI display and does not impact actual packet transmission.
1873990
Major
EX9208: Syslog message 'JINSIGHTD_SENSOR_RESUBSCRIPTION' every 5 sec
Product-Group=junos
Severity=Major
On EX9200 series switch, syslog message 'JINSIGHTD_SENSOR_RESUBSCRIPTION' is seen every 5 sec
PR NumberSynopsisCategory: firewall filter for australia platform
1871431
Minor
Protocols involved with TCP/IP on a lsi interface have issues as TCP 3-way handshake cannot be completed
Product-Group=junos
Severity=Minor
On all SRX platforms, when a firewall filter is attached to a logical tunnel interface or a virtual routing instance to perform selective packet mode, it causes TCP packets on lsi interface to be discarded due to the TCP 3-way handshake is not established.
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading using no-validate.
Product-Group=junos
Severity=Major
RPD might crash when upgrading and NOT using no-validate. Use no-validate to avoid the crash.
PR NumberSynopsisCategory: Border Gateway Protocol
1758786
Minor
Configuring max color value 2^32-1(4294967295) in transport-class does not create the corresponding transport-class color table
Product-Group=junos
Severity=Minor
On device configured with LSP with transport-class, when configuring max color value (2^32-1=4294967295), transport-class color table is not created and rpd may core. This issue only happens with configuring the max color value.
1853025
Major
Updating a source-file to load ROAs should be done by changing the name of the source file
Product-Group=junos
Severity=Major
Loading ROAs from a source-file was a feature introduced as a convenience feature and as such this only affects that feature. This feature is not in widespread use and was created to have a fallback ROA when all sessions go down. This problem scenario requires multiple reloads with the being modified back and forth to add and then delete and re-add the database configured in the import policy.
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.
1865114
Major
Valid BGP routes in RIB are displayed with verification state as Invalid
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, with resource public key infrastructure(RPKI ) enabled for the BGP, the valid routes are installed in the routing table with validation state invalid.However, the route is parsed by policy as a valid route.
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP-LU (Border Gateway Protocol-Labeled Unicast) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
Severity=Major
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
Severity=Major
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.
PR NumberSynopsisCategory: MX304 PSM issuues
1850857
Major
Chassis MX304 going offline due to Power-cycle
Product-Group=junosvae
Severity=Major
On all JUNOS Operating system MX304 platform, entire chassis is shutting down due to improper health checks triggered for the Power Entry Module (PEM). If a health check of the Power Entry Module (PEM) is triggered at the time when the power consumption in the chassis is less than the threshold (440W) required to run the health check, the issue might be triggered.
PR NumberSynopsisCategory: MX304 fabric issues (ULC side)
1863674
Major
Link error reported on one PFE(Packet Forwarding Engine) will also report error on other PFE
Product-Group=junos
Severity=Major
On all Junos MX304 platforms, when a link error or training failure occurs, the "show chassis fabric fpcs extended" and "show chassis fabric plane extended" commands display incorrect PFE-to-plane mappings for plane numbers greater than 9. As a result, an incorrect PFE is shown as affected. Due to this incorrect mapping, a training failure, it shows both PFEs getting impacted.
PR NumberSynopsisCategory: MX304 interface specific 
1893407
Major
Specific Ports on MX304 are not coming up when disabling and then enabling the interface manually
Product-Group=junos
Severity=Major
On MX304 platforms running specific Junos releases from 24.2R2.12 to 24.2R2-S2.3, when any ET/100G ports from 2, 3, 4, 5, 10, 11, 12, 13 had been committed admin disable and 1 minute or more elapsed, the ports will not come up by removing admin disable.
PR NumberSynopsisCategory: MX304 LCMD specific issues
1851100
Major
Erroneous data read from a temperature sensor caused MX304 to reboot
Product-Group=junos
Severity=Major
On Junos MX304, due to erroneous data read from a temperature sensor, the device will shutdown.
PR NumberSynopsisCategory: MX Platform SW - ukern core dumps
1835871
Minor
FPC crashes and results in core during PIC offline
Product-Group=junos
Severity=Minor
On MX2008, MX2010 and MX2020 platforms with 2x100GE CFP2 OTN PIC (Physical Interface Card) , when the PIC goes offline it leads to FPC (Flexible PIC Concentrator) crash and crash file is generated. This is a rare timing issue and traffic impact on the forwarding traffic on that specific FPC is seen.
PR NumberSynopsisCategory: Class of Service
1872595
Minor
CoS configured on logical interface does not work on Junos platform when CoS wildcard configurations applied using groups
Product-Group=junos
Severity=Minor
When Class of Service configurations for an Interface Device (IFD) are present both under the wildcard (applied via groups) and as specific configurations (applied directly under the class-of-service hierarchy) on Junos platform, the Interface Device (IFD) correctly takes the specific configurations as expected. However, the Interface Logical (IFL) configurations from the wildcard are not being applied via groups.
PR NumberSynopsisCategory: Device Configuration Daemon
1824215
Major
Incorrect speed assigned to 1G interfaces on MPC2E-3D-NG high-capacity line card modules.
Product-Group=junos
Severity=Major
During the insertion or removal of optics on 1 Gbps interfaces attached to MPC2E-3D-NG , the interface speed may be incorrectly set to 2 bps.
1848768
Major
MTU configuration is not applied from the configuration group after commit and "warning" is seen
Product-Group=junos
Severity=Major
When configuring MTU on interfaces through a configuration-group and commit the changes, those are not saved on the configuration file.
PR NumberSynopsisCategory: Firewall Filter
1856854
Major
MIB2D will see 100% CPU utilization due to MIB2D walk fail
Product-Group=junos
Severity=Major
On PTX3000/PTX5000/PTX10008/PTX10016/QFX10008/PTX1000/PTX10002/QFX10002 platforms, MIB2D will see 100% CPU utilization due to MIB2D walk failure.
1872347
Major
System becomes unresponsive or crash due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=junos
Severity=Major
On Junos OS platforms, The system experiences memory exhaustion due to an mbuf (Memory Buffer) leak, system logs error message. This condition can cause the system to become unresponsive (hang state) or potentially crash, resulting in a VMcore file and service disruption. The issue arises when a firewall filter is applied to approximately 1k (1000) logical interfaces (IFLs), each filter containing over 250 terms and these filters are updated every 2-3 minutes, triggering updates for all filter attachments.
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1881742
Major
Packet Loss is observed when explicit Null is disabled for BGP-LU routes in ECMP Scenarios
Product-Group=junos
Severity=Major
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1872743
Major
Packet loss or retransmissions observed on MX platforms using SFP-T transceivers
Product-Group=junos
Severity=Major
On MX10004, MX10008 and MX10016 platforms with LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) transceiver will lead to packet loss or retransmissions on neighboring devices due to incorrect Inter-Packet Gap (IPG) handling.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1856132
Minor
FPC process crash observed due to heap memory errors with Inline CFM and VLAN Normalisation
Product-Group=junos
Severity=Minor
On Junos MX platform with line cards MPC1-MPC9, configuring an Inline CFM (Connectivity Fault Management) UP MEP (Maintenance Association End Point) session on an AE (Aggregated Ethernet) interface with VLAN normalisation and bridge or VPLS (Virtual Private LAN Services) encapsulation can result in heap memory errors. These errors may occur after an FPC reboot or when a new CFM peer is learned over VPLS, potentially leading to FPC process crash.
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1865403
Major
Memory leak is observed when Telemetry is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms having Telemetry configured, the memory allocations in 512 bytes slab that are seen to be growing in problem state, are related to write on a unix domain socket (internal to application). Since the data is not read, the send buffer keeps growing and the associated memory does not gets released. Every telemetry response from the producer does a 1 byte write on this socket and over a period of time the send buffer gets full. The default size of the unix socket send buffer is set to 512MB. But there is no functional impact.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1874476
Major
Transient traffic loss for CE in an EVPN MPLS setup with Multi-Homing
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms with EVPN MPLS, Multi-Homing scenarios, when there is a Multi-Homing peer node reboot, the destination route entries that were learned locally on IRB(Integrated Routing and Bridging) interface of rebooted node get deleted on other multi-homing peers without RE-ARP (Routing Engine-Address Resolution Protocol) causing transient traffic loss for CE (Customer Edge) traffic.
PR NumberSynopsisCategory: Configd, ffp issues
1877439
Minor
Traffic drop occurs on Junos Evolved platforms when prefix is moved between dynamic prefix-lists used in firewall filter
Product-Group=junos
Severity=Minor
On all Junos Evolved platforms, when a firewall filter is configured with a dynamic prefix-list that is referenced using an apply-path statement, moving a prefix from one such prefix-list to another where both prefix-lists match the apply-path pattern results in the prefix not being programmed in the PFE. This causes traffic loss for that prefix. The issue is triggered when the configuration includes apply-path pointing to both the source and destination prefix-lists, and a prefix is deleted from one and added to the other through a commit operation.
PR NumberSynopsisCategory: EVPN control plane issues
1889092
Major
The rpd EVPN module sends a redundant license message to the license infrastructure
Product-Group=junos
Severity=Major
On Junos platforms, when loading the baseline configuration or during BGP flaps or Routing Instance deactivation, and a large number of Group-Based Policy (GBP) tagged routes are removed, a redundant GBP license update message is sent to the license infrastructure for every route deletion. This issue has no impact on traffic.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1848993
Major
The data plane will be out of sync when migrating to EVPN A/A stitching with Vanila VXLAN (PIM Multicast)
Product-Group=junos
Severity=Major
On MX platforms, to improve the convergence of node failures in EVPN MH interconnects with Data Plane VXLAN, migrating to an Active-Active setup may cause the data plane to become out of sync for ARP entries. The gateway learns the MAC address and advertises it to the peer gateway. However, on the peer gateway, some MAC-IP entries may remain stuck in the 'Unresolved' (Ur) state.
PR NumberSynopsisCategory: EX interfaces issues
1825281
Major
Random ports of EX4400 will not be created on upgrade or reboot
Product-Group=junos
Severity=Major
On EX4400, random interfaces will not be created when the device is upgraded or rebooted. Interfaces will not be listed in the device and will affect all functionalities of the optic or interface.
1833177
Major
EX2300/EX3400 : The status LED of uplink port is not working properly
Product-Group=junos
Severity=Major
On EX2300 and EX3400, the status LED of uplink port always displays green regardless of the status of the link.
1877524
Minor
Inserting any unsupported optics in 4x25G ULM will cause any port on the ULM to go down
Product-Group=junos
Severity=Minor
On 4x25G ULM(uplink module) any port can go down, when inserting unsupported Juniper or Non-Juniper optics in this ULM.
1886889
Minor
snmp mib walk DomCurrentLaneAlarms does not show proper lanes Values in the latest builds
Product-Group=junos
Severity=Minor
snmp mib walk was not working due to the lane index get issue. Getting the maximum number of lanes for qsfp optics was wrong here. Now it default defined.
PR NumberSynopsisCategory: EX4400 PFE software
1870016
Minor
Traffic will be dropped due to IPv4 header checksum mismatch on EX4400 platform
Product-Group=junos
Severity=Minor
On EX4400 platform, if the switch is acting as a routing transit device, and if the value of the IPv4 header checksum is 0xFFFF in the ingress traffic, the checksum of the IPv4 header will not be recalculated even though the TTL (time to live) value has been reduced. This will lead to traffic being dropped by the next transit-device due to the bad checksum.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1859778
Minor
Traffic looped back upon changing VRF name
Product-Group=junos
Severity=Minor
On all Junos QFX and EX platforms with VRF or EVPN-VXLAN, the issue is seen when the VRF (Virtual Routing and Forwarding) is renamed, on renaming multiple VRFs a large chunk of routes are reinstalled on PFE (Packet Forwarding Engine). When PFE receives an ARPND (Address Resolution Protocol Neighbour Discovery) route install with a NH ID(Next-hop identifier) that was previously in-use but with new params(dmac, gport, vplag id, intf). DCPFE incorrectly assumes it is a replace and updates the existing route programmed in hardware. This results in hardware having incorrectly programmed routes resulting in packets to be send to incorrect destinations. This will happen only when same hw-nh-idx/route is shared between multiple NHs and one NH receives an update. This was seen when VRF was renamed.
PR NumberSynopsisCategory: EX POE
1879702
Major
There is a PoE short circuit alarm after upgrading the device
Product-Group=junos
Severity=Major
On all Junos EX2300, EX3400, EX4400, EX4300 platforms running in Virtual Chassis or Standalone and during normal operation of the switch when POE (Power Over Ethernet) get port status command fails to read then software reads the garbage value from the response buffer and sends to chassisd due to which it results in PoE short Circuit alarm. However, this is a non-existent PoE alarm and non-impacting issue.
PR NumberSynopsisCategory: Express PFE FW Features
1855459
Major
On some PTX and QFX platform parity error causes packet drop
Product-Group=junos
Severity=Major
On Junos PTX1000, PTX5000, QFX10000, PTX10002-60C, QFX10002-60C, QFX10008, QFX10016 and PTX10000 platforms when IPv6 filter is configured that has a match condition of source/ destination address greater than 64 bits, it results in packet drops due to transient hardware parity error that occurs on the prefix table. This will only reject what is permitted, does not allow unpermitted packets unless default term is accept and is a rare issue.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
PR NumberSynopsisCategory: SRX1500 platform software
1876867
Major
FPC goes offline and srxpfe core dump is generated during the system normal operation or boot-up
Product-Group=junosvae
Severity=Major
FPC (Flexible PIC Concentrators) on SRX1500 device goes offline and generates srxpfe core dump on system boot-up or normal operation in a rare timing scenario. This issue cause a traffic impact.
PR NumberSynopsisCategory: ACX7332 & ACX7348 Platform Software
1809091
Minor
ACX7024 sees a vmcore and restarts or potentially hangs on reboot
Product-Group=junos
Severity=Minor
ACX7024 sees a vmcore and restarts or potentially hangs on reboot
1842389
Major
Evo-pfemand process crashes on ACX7348/ACX7332/ACX7024/ACX7509 platforms
Product-Group=junos
Severity=Major
On ACX7348/ACX7332/ACX7024/ACX7509 platforms, evo-pfemand process crashes after evo-pfemand application restarts or after a RE(Routing Engine) switchover resulting in impact on forwarding traffic.
PR NumberSynopsisCategory: Express ASIC interface
1845309
Major
Framing errors observed on the peer router when connected to PTX5K with FR optics
Product-Group=junos
Severity=Major
On Junos PTX5K platform with QSFP56-DD-4X100G-FR, when 15xQSFP28 PIC. Physical Coding Sublayer (PCS) error observed on the peer router side FR optics when 100G FR optics used, if more number of PCS error may possibility for network impact.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1871420
Major
Fragmented packets dropped in EVPN-MPLS scenario due to the IRB interface MTU limitation
Product-Group=junos
Severity=Major
On all Junos platforms running in EVPN-MPLS (Ethernet Virtual Private Network over Multiprotocol Label Switching) scenarios, host-generated packets exceeding the IRB interface MTU (Maximum Transmission Unit) are fragmented. Only the first fragment is forwarded, while remaining fragments are dropped, leading to loss of control-plane traffic.
PR NumberSynopsisCategory: ISIS routing protocol
1847557
Critical
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.
PR NumberSynopsisCategory: jdhcpd daemon
1872292
Major
DNS resolution will fail for DNS entries written to "resolv.conf"
Product-Group=junos
Severity=Major
On all Junos platforms with ZTP (Zero-Touch Provisioning) configuration, when the configuration is completely removed, DNS (Domain Name System) resolution for DNS entries written to "resolv.conf" will fail.
PR NumberSynopsisCategory: jl2tpd daemon
1877876
Major
L2TP subscriber is unable to connect when configuration is loaded over default config on all Junos platforms with L2TP subscribers
Product-Group=junos
Severity=Major
On all Junos platforms with L2TP (Layer 2 Tunneling Protocol) subscribers if source-gateway-address is not configured, new L2TP subscribers will not be able to connect when configuration is loaded over default config.
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1788400
Major
SNMP walk timeout
Product-Group=junos
Severity=Major
On Junos MX platform with MSMPC card, NMS (Network Management System) times out when polling any data from jnxSpSvcSetIfTable OID.
PR NumberSynopsisCategory: Flow Module
1854492
Major
Junos SRX platforms with chassis cluster configured experience flowd crash due to a race condition in multicast session handling
Product-Group=junos
Severity=Major
On Junos SRX platforms with chassis cluster configured, a crash is observed in multicast scenario due to a race condition where a link flap changes the ingress interface while a session is being aged out, leading to invalid session data access. This causes the flowd process to crash, resulting in a coredump and eventually the system crashes.
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
Severity=Major
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
PR NumberSynopsisCategory: l2 flow module
1856200
Major
PFE crash due to invalid cached next hop during reinjection on SRX5k
Product-Group=junos
Severity=Major
On SRX5k devices, the PFE (Packet Forwarding Engine) may suddenly crash with a core dump written and force a restart against all line cards during massive interface or route changes when the system caches and reinjects an invalid next hop.
PR NumberSynopsisCategory: JSR Application Services
1792714
Major
pub-brokerd crash due to rapid connect-disconnect events on SRX platforms with MNHA
Product-Group=junos
Severity=Major
On all SRX platforms with Multi-Node High Availability (MNHA) enabled, a rare corner-case scenario involving a rapid sequence of connection attempts immediately followed by disconnections can trigger an unhandled assertion in the pub-brokerd process. This results in a core dump and full-service disruption on the affected node. Automatic recovery is not supported in this scenario, and manual intervention is required. The issue is rare and relies on a specific timing condition.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1877966
Minor
Some new VPN tunnels are not coming up on SRX5K platforms with SPC3
Product-Group=junos
Severity=Minor
On SRX5K platforms with SPC3 installed, IPSec (Internet Protocol Security ) tunnels with iked which reuses the same IKE (Internet Key Exchange) gateway peer IP, could be observed not re-establishing.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1817705
Critical
The l2ald crash is observed when adding scaled EVPN-VXLAN configuration on Junos platforms
Product-Group=junos
Severity=Critical
On Junos platforms, if disk is full, when scaling configuration is moved to baseline configuration and move back to scaling configuration, l2ald try to create a source VTEP, but old VTEP is still in the middle of deletion, so kernel return EBUSY and l2ald will retry. If retry too many times, l2ald insist and core.
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .
PR NumberSynopsisCategory: authd (AAA) library code
1860913
Major
The authd process crashes when /etc/resolv.conf file is empty
Product-Group=junos
Severity=Major
On Junos OS Evolved ACX platforms, when DHCP (Dynamic Host Control Protocol) local server is configured without domain-name specified, the authd process crash may be observed. There will be no forwarding traffic impact due this issue, however, new DHCP client requests will not be answered.
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1727066
Major
Extremely fast interface flaps in MPC10E line-card causes cpu to hog which leads to fpc reboot.
Product-Group=junos
Severity=Major
Extremely fast interface flaps in MPC10E line-card causes cpu to hog which leads to fpc reboot.
PR NumberSynopsisCategory: MPC11 ULC platform software related issues.
1881499
Major
MX2010: MPC11E - FPC 1 temp sensor DDR4 A failed
Product-Group=junos
Severity=Major
DDR temp sensor is designed to be used periodically to get temps to send to chassisd. The temp sensors reside may have an intermittent contention that can cause these read failures resulting in DDR4 Temp Sensor Fail" logs on MPC11E linecards.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, an out-of-memory condition in the rpd process caused by uncontrolled memory allocation leads to the rpd process crashing.
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when RSVP-TE (Resource Reservation Protocol - Traffic Engineering) is configured with MBB (make-before-break) setup, if the protected link of the primary LSP (Label Switched Path) goes down and if "clear mpls lsp" or "clear rsvp session" commands are executed, then LSP switches to new instance from the old which will be on higher IGP (Interior Gateway Protocol) metric. However, after re-optimization, LSP will not get switched to better IGP metric path and remain in old instance. Traffic drop can be seen due to this double fault events.
PR NumberSynopsisCategory: Multicast Routing
1876458
Major
MX960 mcsnoopd core dump during rt_mcnh_nh_release
Product-Group=junos
Severity=Major
The root cause is, when the system comes up after reboot, in MCSNOOPD (/usr/sbin/mcsnoopd used for L2 multicast), the lsi interfaces are learned. In MCSNOOPD, when there are 4 lsi interfaces learned, we create a nexthop(assume VE NH1) with all these 4 lsi as members and we use it in the routes for forwarding the traffic. When MCSNOOPD learns 5th lsi interface, as per internal NH(nexthop) allocation logic, we allocate a new nh(assume VE NH2) containing all these 5 lsi interfaces and free the old NH(VE NH1). The old freed NH(VE NH1) is accessed and tried to be freed again in another part of the code flow which is causing MCSNOOPD core(/usr/sbin/mcsnoopd). The fix is to free the old NH(VE NH1) in a common place instead of freeing in multiple places.
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1873938
Major
The SPC3 card resets due to kernel memory exhaustion in MX Series platforms with highly scaled routing tables and Inline Active Flow Monitoring configured
Product-Group=junos
Severity=Major
On MX240, MX480 and MX960 platforms with MX-SPC3 (Services Processing Card) service cards, when Inline Active Flow Monitoring (inline-jflow) is configured in a highly scaled routing environment (~4M routes), the SPC3 service card runs out of kernel memory, resulting in the PIC going offline or resetting and the services running on the SPC3 card gets disrupted.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1881956
Major
IPv6 default route gets deleted from FIB by slaac daemon after an upgrade with an unsupported configuration
Product-Group=junos
Severity=Major
On all Junos OS platforms , deletion of IPv6 default route from FIB (Forward Information Base) by slaacd (Stateless Address AutoConfiguration Daemon ) is observed while recovering the device from amnesiac state after the OS upgrade with any unsupported or incompatible configuration.
PR NumberSynopsisCategory: TCP/UDP transport layer
1864027
Minor
TCP listening sockets are not displayed correctly
Product-Group=junos
Severity=Minor
On Junos OS platforms, TCP (Transmission Control Protocol) listening sockets may be absent from command outputs due to NULL values in netstat application.
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1828196
Major
Error messages are seen due to high CPU utilization
Product-Group=junos
Severity=Major
On Junos MX and PTX platforms (non-AFT based), error messages are seen with the operations that involve high CPU utilization on the RE and/or FPC. This issue has no impact on traffic.
PR NumberSynopsisCategory: Express Chip L3 software
1877538
Major
Multicast traffic loss is seen when MVPN with node protection is enabled
Product-Group=junos
Severity=Major
On Junos PTX and QFX10K platforms with node protection enabled on a Multicast Virtual Private Network (MVPN) scenario, multicast traffic loss will be seen when the number of child links in an aggregated ethernet (AE) interface for bypass Label Switched Path (LSP) egress interface is higher than primary LSP and one of the child links goes down on primary LSP egress interface.
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.
PR NumberSynopsisCategory: Issues related to PKI daemon
1876497
Minor
Wrong digest algorithm is used for ECDSA key based certificate requests using PKI
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, when generating Elliptic Curve Digital Signature Algorithm (ECDSA) based Certificate Signing Request (CSR) using Public Key Infrastructure (PKI), SHA-384 digest is used even when other digest algorithm is specified in Command Line Interface (CLI). This issue will impact services that are based on these certificates when the services are configured for specific digest algorithm.
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
Severity=Major
On Junos MX platform with subscriber management enabled, interface flapping causes PPPoE subscriber login failures, resulting in AC (Access Concentrator)System errors.
PR NumberSynopsisCategory: QFX access control list
1856361
Major
Port mirroring fails due to mismatched analyzer and outgoing interface configuration
Product-Group=junos
Severity=Major
On Junos EX and QFX5120 platforms, the system fails to retrieve the necessary analyzer details, preventing the port mirroring action from being applied in the filter entry. As a result, the system defaults to the reject action, causing the expected mirrored traffic to be missed, and packet captures are not generated.
PR NumberSynopsisCategory: QFX PFE Class of Services
1884644
Major
CCL:QFX5200 The protocols get violated before the configured aggregate bandwidth in DDOS
Product-Group=junos
Severity=Major
In case of burst scenario where the number of packets sent are more the buffer, the packets get dropped. This will result in ddos violation for that protocol. With the below cli user can increase or decrease the buffer alpha value which in turn increase or decreases the buffer. This helps in resolving the violations "set class-of-service shared-buffer egress buffer-partition multicast dynamic-threshold "
PR NumberSynopsisCategory: QFX L2 PFE
1889275
Major
The PFE keeps on rebooting due to DCPFE process crash on specific QFX platforms while performing upgrade to 20.4R1 or above releases
Product-Group=junos
Severity=Major
When software upgrade is performed to 20.4R1 or above releases on QFX5210/QFX5110/QFX5200 with access-security features(maces/dot1x), PFE keeps on crashing due to DCPFE process crash. All interfaces connected to an impacted PFE go down and it causes a traffic impact.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1876359
Minor
ON QFX5K and EX4K platforms a log is required for route leaking when destination table hits a platform limitation
Product-Group=junos
Severity=Minor
On Junos QFX5K and Junos EX4K switches, route leaking for IPv4 requires a minimum route mask of /16, and the leak destination table must have a prefix length longer than or equal to that of the leak prefix for proper routing. When this doesn't occur, traffic forwarding is affected, and there is no log associated with this event
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
Severity=Major
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on specific Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.
1878555
Major
Transit unicast ARP requests are dropped instead of being forwarded
Product-Group=junos
Severity=Major
On Junos QFX5K and EX46xx platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) environment, when "no-arp-trap" is enabled, transit unicast Address Resolution Protocol (ARP) packets that are not destined for the local switch Integrated Routing and Bridging Media Access Control (IRB MAC) are dropped instead of being forwarded across the leaf nodes.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1823771
Major
The SFP 10GBASE-T part No. 740-083295 on platforms running Junos/Junos EVO is unable to detect a linkdown
Product-Group=junos
Severity=Major
On Junos/Junos EVO platforms with the SFP 10GBASE-T part No. 740-083295 Link up/Link down is randomly not detected.
1855372
Minor
[QFX5120-32C] LEDs do not work properly with QSFP or without optics
Product-Group=junosvae
Severity=Minor
This is a display issue. There is no service impact when this issue occurs. Port 0-29, 31-33 When It is plugged in the Optics and connect the cable, it is in link-up status. However, the LEDs on the ports do not light up or blink. Port 30 The rightmost LED lights up even though no Optics is plugged in.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1884953
Major
Image upgrade failure can occur if the /var/log/journal on the host grows too large on qfx5120-48ym-8c
Product-Group=junosvae
Severity=Major
Image upgrade failure can occur if the /var/log/journal on the host grows too large on qfx5120-48ym-8c.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1868085
Major
The rpd process crashes and asserts are seen due to memory leak
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, rpd process crashes and asserts are seen due to a memory leak when BGP sharding is enabled and 'show route' is performed continuously.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1858750
Critical
Route change is not synced after rpd restart due to rib-fib inconsistency
Product-Group=junos
Severity=Critical
On all Junos OS Evolved platforms, after rpd (Routing Protocol Daemon) restart, the route change is not sent from routing daemon RIB(Routing Information Base) to forwarding plane FIB (Forwarding Information Base). This results in traffic drop.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1813582
Minor
Static route refreshes age when commit full is performed
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, with import policy defined in the rib-group and commit full is performed, static route refreshes age. There is no service impact due to this issue. This issue is not seen with normal commit.
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=junos
Severity=Major
On all Junos, Junos OS Evolved, and cRPD platforms, due to deadlock in internal processes, BGP (Border Gateway Protocol) route advertisement fails leading to traffic disruption.
PR NumberSynopsisCategory: Resource Reservation Protocol
1864823
Major
The rpd with per-priority subscription configuration
Product-Group=junos
Severity=Major
The heap memory allocated to store the per-priority subscription values must be retained if the parsing of 'protocols rsvp interface <*> subscription' config hierarchy is successful. However, the heap pointer 'prio_subscr_value' is freed even if the parsing is successful resulting in memory-use-after-free causing the rpd (Routing Protocol Daemon).
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.
1871664
Minor
The rpd process crash is seen due to internal message handling issue in RSVP
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms with RSVP(Resource Reservation Protocol) enabled, the rpd(Routing Process Daemon) process crash is seen. The issue is seen in rare scenario where message-id after the wrap around runs into collision in RSVP IO(Input Output) database due to 32bit limitation.
1881906
Major
BFD session failure causes LSP to go down and the inactive route remains in the routing table leads to traffic black hole
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms, when an RSVP (Resource Reservation Protocol) LSP (Label Switched Path) goes down due to a failure in the associated BFD (Bidirectional Forwarding Detection) session, and the corresponding route remains in the routing/forwarding table causing traffic black-holing. If there are other active LSPs to the same destination, those active routes are preferred over the inactive route associated with the failed LSP.
PR NumberSynopsisCategory: HA functionality on ASP
1853304
Major
Traffic was lost on MX platforms following a Routing Engine failover
Product-Group=junos
Severity=Major
On Junos MX240/MX480/MX960/MX2010/MX2020 platforms which support TLB (Traffic-Load Balancer) the PFE (Packet Forwarding Engine) is not properly synchronized with the new master RE (Routing Engine) after a RE failover causing traffic loss
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1869450
Major
Subscribers failed to establish DS-Lite softwires due to stale softwire entries
Product-Group=junos
Severity=Major
On Junos MX Series platforms using MS-MPC or MX-SPC3 line cards with DS-Lite softwires subscriber services and the session-limit-per-prefix option enabled, the softwire extension reference count will not be properly decremented during subscriber session teardown. These stale softwire entries cause traffic failures when the same subscriber connects to a different AFTR (Address Family Transition Router). This will not impact new subscriber sessions with any AFTR, nor will it affect existing subscriber sessions with the same AFTR.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
Severity=Major
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.
PR NumberSynopsisCategory: SRX branch platforms
1873583
Minor
TCP RST packet gets dropped when used with rst-invalidate-session
Product-Group=junos
Severity=Minor
On all SRX platforms, when the rst-invalidate-session option is enabled, SRX devices drop a TCP (Transmission Control Protocol) RST(Reset) packet that arrives immediately after a TCP SYN (TCP Synchronize) packet, before a full session is established, leading to TCP protocols errors resulting in connectivity issues.
1877323
Major
Unexpected primary role assignment on SRX after node0 reboot
Product-Group=junos
Severity=Major
On all Branch SRX series platforms(SRX300/SRX320/SRX340/SRX345/SRX380), rebooting node0 with chassis cluster enabled causes the High Availability (HA) control link to establish after the initial hold timer expires. As a result, node0 assumes the primary role unexpectedly, leading to a split-brain condition where both nodes operate as primary.
PR NumberSynopsisCategory: MX10003/MX204 Timing/Sync-E issues tracking
1863091
Major
FPC will crash in MX10003 during the Master switchover to RE1 or Master set to RE1
Product-Group=junos
Severity=Major
MX10003 FPC (Flexible PIC Concentrators) will crash if Primary RE (Routing Engine) switchover to RE1 (Routing Engine 1) or RE1 is set to Master from release 21.2 and above.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1878195
Major
Heap memory threshold value is not taking effect post GRES/Switchover if configured to a higher value
Product-Group=junos
Severity=Major
On Junos OS platforms with MPC10, MPC11, LC4800, LC9600 line cards and on MX304, if heap memory threshold is configured with the higher value, post GRES (Graceful Routing Engine Switchover) or switchover, threshold gets overwritten to default. Drop in subscribers can be seen if heap usage is more than the default threshold in case of Subscriber Management is enabled.
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1851317
Minor
Packet drops are observed on rate-limited queues
Product-Group=junos
Severity=Minor
On MX platforms with MPC10E, MPC11E, MX304 and JNP10K-LC9600 with Class-of-Service (COS), packet drops are seen in rate-limited queues with high, medium-high or strict-high priority due to shallow buffer-size.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1871698
Major
Filter-Based Forwarding (FBF) failed for over unicast IRB over AE on MX and EX platforms
Product-Group=junos
Severity=Major
On Junos MX with MPC10, MPC11, MX304 and EX92K platforms, when Integrated routing and bridging (IRB) interface is configured over Aggregate Ethernet (AE), the packet is received on an l3 IRB which is processed through a filter based forwarding (FBF) which forwards the traffic over an IRB which has an underlay as L2 AE interface. When the packet is forwarded over the l2 AE, the packet gets dropped because the egress PFE calculation is incorrect resulting in a traffic drop.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1875040
Major
The BUM traffic is dropped due to interoperability issue in combination of MPC 1-9 and MPC10E/MPC11E line cards in a WECMP setup
Product-Group=junos
Severity=Major
The Broadcast, unknown Unicast, and Multicast (BUM) traffic such as Ethernet Virtual Private Network (EVPN) or Virtual Private LAN Service(VPLS) etc. is dropped on the egress Flexible PIC Concentrator (FPC) in a weighted Equal Cost Multi-Path (ECMP) setup with non-zero balances when ingress traffic arrives on a different line card. This issue arises only in interoperability scenarios where a combination of MPC 1-9 and MPC10E/MPC11E line cards are used for ingress and egress processing resulting in forwarding issues.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1837840
Major
Incorrect color-aware srTCM marking with yellow packet loss priority
Product-Group=junos
Severity=Major
There was a software side limitation on the highest CBS that can be configured for MPCs that have LU type lookup chips due to a hardware PR. The Hardware PR was resolved in MX240/ MX480/ MX960/ MX2008/ MX2010/ MX2020/ MX10003/ MX10008/MX10016/EX9200/EX9204/EX9208/EX9214/EX9251/EX9253/SRX5400/SRX5600/SRX5800 platforms, but the software-side limitation was not removed for the same. Due to this limitation, whenever the CBS was configured above its limit (earlier 33m), the low-level parameters used to get configured such that the packets would not have any credits available, resulting in them getting marked as RED.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1870522
Minor
STP/RSTP/MSTP/VSTP enters a disputed and blocked state when the anchor FPC of an AE link, with members distributed across multiple FPCs, goes offline
Product-Group=junos
Severity=Minor
On MX and EX9200 series platforms that operate in hyper mode by default, STP (Spanning Tree Protocol)/RSTP (Rapid Spanning Tree Protocol)/MSTP (Multiple Spanning Tree Protocol)/VSTP (VLAN Spanning Tree Protocol) transitions to a disputed and blocked state if the members of the AE (Aggregated Ethernet) link in the anchor FPC (Flexible PIC Concentrator) goes offline.
1874097
Minor
Telemetry is not reporting statistics for an IRB interfaces
Product-Group=junos
Severity=Minor
On Junos OS Evolved and MX platforms with MPC10E/MPC11E/LC9600 line cards, MX304 and EX9k with EX9200-15C line cards , telemetry is not reporting statistics for the IRB (Integrated Routing and Bridging) interfaces, even though they are up and running.
1874503
Major
An IPv6 neighbor solicitation packet is dropped at the ingress PE router when it is received with more than two VLAN tags.
Product-Group=junos
Severity=Major
On Junos platforms having 'arp-supression' suppression enbabled, when IPV6 neighbor solicitation packets are received with more than two tags in an EVPN (EThernet Virtual Private Network) instance, the NDP (Neighbour Discovery Protocol) packets that are suppressed to the host path are incorrectly processed through a wrong DDOS policer, as the hop-limit value from the IPV6 header is not properly retrieved, causing them to be dropped by the packet forwarding engine.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1858741
Minor
IPv6 link cannot be used for around 10 seconds after DAD finishing due to NS delay.
Product-Group=junos
Severity=Minor
If both IPv4/IPv6 addresses are configured and both IPv4/IPv6 traffic is sent, there may be a 10 second delay in NS completion. This may occur when the egress interface is disabled/enabled and triggers NH resolution.
1880860
Major
FPC crash is seen on MX series when disabling AE IFL in mixed-speed configuration without enhanced-ip enabled
Product-Group=junos
Severity=Major
On MX platforms using ukern line cards (MPC2-9, LC480, LC2101, MX10K3), disabling an AE(Aggregated Ethernet) IFL configured with mixed-speed member links and without enhanced-ip enabled causes the associated FPC to crash and reboot.
PR NumberSynopsisCategory: DDos Support on MX
1848317
Major
SCFD flow variation leads to error messages or process crash
Product-Group=junos
Severity=Major
On all Junos MX platforms with line cards MPC10/11/LC9600/LC4800 and SCFD (Suspicious Control Flow Detection) enabled, when there are numerous flows being added, deleted, or modified simultaneously, the system experiences error messages or process crashes due to thread synchronization issues. The process crash will cause the FPC to restart.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1855393
Major
User root is shown as incorrect after power cycle of the device
Product-Group=junos
Severity=Major
After a power cycle, telnet login through the console fails. The issue occurs randomly and does not happen after every power cycle. To recover the device, another power cycle should be performed.
1874078
Major
Unable establish gnmi session using Radius and TACACS auth
Product-Group=junos
Severity=Major
Unable establish gnmi session using Radius and TACACS auth. Currently JADE (Junoscript authentication daemon) utility which does authentication for telemetry on cRPD has support for local authentication.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1839362
Minor
The commit error is seen in backup RE on MX platforms
Product-Group=junos
Severity=Minor
On all MX platforms, the commit fails in Backup RE during configuration commit where "fast-synchronise" and "graceful-switchover" are being committed together.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1863354
Minor
Command line freezes when Ctrl+Z is used
Product-Group=junos
Severity=Minor
In Junos OS Releases 24.2 and later(BSD 15), pressing Ctrl+Z in the Command Line Interface CLI suspends the process and causes it to become unresponsive. This behaviour is observed on systems using the and Berkeley Software Distribution BSD15 platform.
1872820
Major
The dcd process crashes when deactivating only 'swap' under ' interfaces <> unit <> output-vlan-map' with no other attributes present
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, this issue affects configurations where Virtual Local Area Network (VLAN) mapping is used, particularly in scenarios where only the swap attribute is applied under 'interfaces <> unit <> output-vlan-map'. Sequence of 'Deactivate -> Activate -> Commit' of the config hieararchy leads to crash of the device control daemon (dcd) process, potentially causing service disruption.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1843602
Major
TCP session between syslog server and device remains in closed state
Product-Group=junos
Severity=Major
On all Junos platforms, a TCP (Transmission Control Protocol) connection issue occurs between the device and syslog server after an idle period exceeding 2 hours. The session gets terminated and remains in a closed state without initiating any new session until the syslog server configuration is deleted and added again. This impacts disruption in log forwarding to the remote syslog server.
1848106
Major
The eventd process crash occurs due to flooding of out of memory logs
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, eventd process crashes is observed. This happens when eventd process is processing the flooding of out of memory logs generated by any of the processes running on FPC (Flexible PIC Concentrator). This is traffic impacting depending on the process with memory issues.
PR NumberSynopsisCategory: MX10K linecard
1865576
Major
Due to race condition the FPC on MX platform crashes
Product-Group=junos
Severity=Major
On MX platforms with LC480, LC2101, and LC2103 a crash file is generated, resulting in the ukern rebooting and a complete reboot of the LC.
PR NumberSynopsisCategory: Virtual Private LAN Services
1850803
Minor
A traffic outage is seen when disabling and enabling the LACP configuration
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms that support EVPN Egress Link Protection, the AE(Aggregated Ethernet) member-link "Device flags" keeps "Present Running PFE-Gone" even after the LACP(Link Aggregation Control Protocol) configuration is re-enabled.
PR NumberSynopsisCategory: VSRX platform software
1789508
Major
Interface speed changes when added to aggregated-ethernet bundle on vSRX3.0 platform
Product-Group=junos
Severity=Major
On vSRX3.0 platform, speed of the gigabit-ethernet (ge) interface reduces to 1G when added as a part of Aggregated-Ethernet (AE) bundle. This issue does not cause traffic impact but can affect Class of Service (CoS) configuration of the interface.
PR NumberSynopsisCategory: Track Windriver Linux issues
1631579
Critical
A few line cards will be stuck in the 'Present' state and later go 'Offline'
Product-Group=junos
Severity=Critical
A system equipped with specific line cards, the line cards will be stuck in the 'Present' state and later go 'Offline' after the line card or router is rebooted. Ideally, the Line Card should go 'Online' instead it goes 'Offline'.
PR NumberSynopsisCategory: usf ipsec related issues
1876801
Major
IPsec-inside-IPsec tunnel establishment fails on MX platforms with SPC3 cards
Product-Group=junos
Severity=Major
On MX platforms equipped with SPC3 cards, the establishment of the inner IPsec tunnel fails in an IPsec-inside-IPsec tunnel setup. This occurs because the service PIC's forwarding process incorrectly attempts to punt IKE packets to the Route Engine (RE) and cannot resolve the required internal fabric path.
1884595
Minor
Allow default route to be created provided st0 IFL is in a non-default routing instance.
Product-Group=junos
Severity=Minor
ARI now allows default route to be pushed if the corresponding st0 interface is configured in a specific routing instance.



Extended Solution

24.2R2-S2 - List of Known issues 

PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.4R1 junos:25.1R1
1839959
Critical
The MAC+IP table and mac-table are not in sync in the EVPN-MPLS active-active multihomed scenario leading to traffic loss
Product-Group=junos
On all Junos and Junos OS Evolved platforms that supports ESI lag interface and in an EVPN-MPLS (Ethernet Virtual Private Network - Multi Protocol Label Switching) active-active multihomed scenario, when the multihomed access interfaces are flapped in quick succession, it results in an unresolved destination route for the specific IP host. This is occurred due to race condition within l2ald (Layer 2 Address learning daemon) followed by an interface flap which causes the locally learned MAC to go missing from the mac-table on the other PE router.

Resolved In: evo:21.4R3-S10-EVO evo:22.2R3-S6-EVO evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO junos:21.4R3-S10 junos:21.4R3-S4-J26 junos:22.2R3-S6 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S4 junos:23.4R2-S5 junos:24.4R1
PR NumberSynopsisCategory: EX interfaces issues
1742075
Major
[Interfaces]: Error messages are seen after zeroise and JOJI of optics "fpc0 BCM Error: API bcm_plp_seahawks_module_read(phy_info, addr, (offset + i), TVP_DRV_I2C_RW_OP_LENGTH, data) at tvp_bcm_seahawks_eeprom_read:766 -> -8"
Product-Group=junos
On EX4400-48F, whenever JOJI of optics is performed, the below messages are expected BCM Error: API bcm_plp_seahawks_module_read(phy_info, addr, offset, size, data) at tvp_bcm_seahawks_eeprom_read:952 -> -8

Resolved In:
PR NumberSynopsisCategory: N/A:sw-hamilton-timing
1874475
Minor
PTP LAG interface GRES issue
Product-Group=junos
PTP on one particular LAG interface stops working on ULC in the below scenario -Load override existing LAG+PTP config with some baseline config -Replace baseline config with the previous LAG+PTP config -Perform GRES and then on the new master we see that one of the slave LAG interfaces do not receive PTP packets. Issue is only seen in above scenario and all other GRES scenarios work correctly wrt PTP

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Signature Database
1883645
Minor
Not able to download IDP signature via routing instance
Product-Group=junos
On SRX platforms, SRX fails to download IDP signature via routing instance

Resolved In: junos:24.4R1-S3-J2 junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1843627
Critical
Memory leak when deactivating/reactivating routing instances with vrf-table-label
Product-Group=junos
On all Junos Evolved platforms, a memory leak occurs when a routing instance configured with "vrf-table-label" is deactivated and then reactivated, followed by a Routing Engine (RE) switchover on dual RE systems. This issue causes a slow memory leak in the system.

Resolved In: evo:23.4R2-S4-EVO evo:23.4R2-S5-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.4R2-S4 junos:23.4R2-S5 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1762490
Minor
JDI-RCT-MPC10E: Ksyncd crash on backup RE after fpc reboot
Product-Group=junos
On MX series, when PS over RLT is configured where all member LTs are hosted on the same FPC and user restarts this FPC then on rare occasion, ksyncd crash can occur on backup RE. However, there is no impact on the master and only backup RE is affected. This issue is not consistent and seen only once out of ~10 or 15 fpc restart operations.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1801028
Major
VPN TPS performance is degraded on SRX5K series
Product-Group=junos
VPN TPS performance is degraded in Release 24.2R2 on SRX5K series with dpdk-22.11.

Resolved In: junos:24.4R1
PR NumberSynopsisCategory: Security platform jweb support
1876075
Minor
Upgrade and Downgrade will fail from J-Web in SRX4600
Product-Group=junos
On SRX4600, upgrades and downgrades will fail from J-Web with the error message: "Installation Progress failed at Receive Package File" from release 23.4 and above.

Resolved In: junos:23.4R2-S5 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Key Management Daemon
1869769
Major
The kmd process crashes when device with MS-MPC has DPD enabled and a SA is deleted
Product-Group=junos
On all MX platforms with MS-MPC (Multiservices Modular PIC Concentrator), when DPD (Dead Peer Detection) is enabled under IPsec/IKE (Internet Key Exchange) VPN settings and for any reason an IPsec SA (Security Association) is deleted, the kmd process crashes. Due to the kmd process restart some disruption in tunnel establishment is seen.

Resolved In: junos:22.4R3-S7
PR NumberSynopsisCategory: Multiprotocol Label Switching
1874592
Critical
Recommended way to modify maximum-labels on production MX router
Product-Group=junos
Changing maximum-labels is a catastrophic change which interacts across interface daemon, rpd daemon, mpls protocol, kernel and PFE in nature. This is effective for all types of MPC line cards. Failing to follow recommended steps to modify maximum-labels on production router can lead to mpls traffic impact

Resolved In:
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
em0 mgmt port is unreachable after RE switchover
Product-Group=junos
On MX10008 with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In:
PR NumberSynopsisCategory: PTX10K Routing Engine
1770585
Minor
Junos VMhost upgrade will continue to reboot the box even if the upgrade has failed due to tar errors when the reboot option is used
Product-Group=junos
Issue identified when upgrading VMhost, but applies to all Junos platforms that support VMhost. When there are tar errors during the upgrade, and the reboot option is used in the upgrade command, the machine will still reboot the RE despite that the upgrade was not completed correctly. This will break the routing engine. It is necessary to stop the reboot, if error or tar problems occurred during the upgrade.

Resolved In: junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1865432
Critical
The dcpfe crash is seen in the EVPN-VXLAN scenario
Product-Group=junos
On QFX5120-48Y and QFX5120-32C platforms, dcpfe crash is seen due to inline BFD (Bidirectional Forwarding Detection) configured in EVPN-VXLAN (Ethernet VPN - Virtual Extensible Local Area Network) scenario.

Resolved In: junos:23.4R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1851629
Minor
Next-hop APIs to support LDP stitching cases over BGP routes pointing to list of indirects
Product-Group=junos
On all Junos and Junos Evolved platforms this is an enhancement for Nexthop APIs to support LDP stitching cases over BGP routes pointing to list of indirects next-hops.

Resolved In: evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.2R2
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1806872
Critical
Junos OS: MX Series: When specific SIP packets are processed the MS-MPC will crash (CVE-2025-52982)
Product-Group=junos
An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA100088 [juniper.net] for more information.

Resolved In: junos:21.2R3-S9 junos:22.2R3-S6 junos:22.4R3-S6
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1885754
Major
MX304 acting as an LNS saw an FPC restart and core dump in aft-trio after offlining a MIC
Product-Group=junos
MX304 acting as an LNS saw an FPC restart and core dump in aft-trio after offlining a MIC

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
Product-Group=junos
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: MX10K linecard
1784824
Major
[./sw-vale-mx-indus] [generic] MX10004 :: LC480 line card crashed with reference to posix_interface_abort () at ../src/pfe/platform/linux/posix_interface.c:2729
Product-Group=junos
n/a

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: VMHOST platforms software
1856565
Minor
High memory consumption in VMhost causes FPC reboot
Product-Group=junos
On all VMhost based platforms, excessive file accumulation in the /var/tmp directory of the host side triggers FPC reboots, resulting in network traffic disruption. This condition occurs when available space falls below 65% (usage exceeds 35%).

Resolved In: junos:22.4R3-S7 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1

 

Modification History

First publication 2025-07-28