Alert Type

SRN - Software Release Notification
Low/Notificationsoftware release notification
Low/NotificationSoftware Release Notification

Product Affected

SRX platforms running Junos software -- (For other platforms see TSB101325 [juniper.net])

Alert Description

Junos Software Service Release version 24.2R2-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For review

Solution

Junos Software service Release version 24.2R2-S2 is now available.

24.2R2-S2 - List of Fixed issues 

PR NumberSynopsisCategory: SRX ISSU infra related issues
1882569
Major
ISSU getting aborted due to configuration-synchronize failure on Junos SRX platforms
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having chassis cluster configuration-synchronize configured, ISSU (In-Service Software Upgrade) gets aborted due to a configuration synchronization (config-sync) failure and the Redundancy Group (RG) priority is set to 0, preventing a successful failover during the ISSU process resulting in the ISSU process gets aborted causing the upgrade failure.
PR NumberSynopsisCategory: firewall filter for australia platform
1871431
Minor
Protocols involved with TCP/IP on a lsi interface have issues as TCP 3-way handshake cannot be completed
Product-Group=junos
Severity=Minor
On all SRX platforms, when a firewall filter is attached to a logical tunnel interface or a virtual routing instance to perform selective packet mode, it causes TCP packets on lsi interface to be discarded due to the TCP 3-way handshake is not established.
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading using no-validate.
Product-Group=junos
Severity=Major
RPD might crash when upgrading and NOT using no-validate. Use no-validate to avoid the crash.
PR NumberSynopsisCategory: Border Gateway Protocol
1758786
Minor
Configuring max color value 2^32-1(4294967295) in transport-class does not create the corresponding transport-class color table
Product-Group=junos
Severity=Minor
On device configured with LSP with transport-class, when configuring max color value (2^32-1=4294967295), transport-class color table is not created and rpd may core. This issue only happens with configuring the max color value.
1853025
Major
Updating a source-file to load ROAs should be done by changing the name of the source file
Product-Group=junos
Severity=Major
Loading ROAs from a source-file was a feature introduced as a convenience feature and as such this only affects that feature. This feature is not in widespread use and was created to have a fallback ROA when all sessions go down. This problem scenario requires multiple reloads with the being modified back and forth to add and then delete and re-add the database configured in the import policy.
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.
1865114
Major
Valid BGP routes in RIB are displayed with verification state as Invalid
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, with resource public key infrastructure(RPKI ) enabled for the BGP, the valid routes are installed in the routing table with validation state invalid.However, the route is parsed by policy as a valid route.
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP-LU (Border Gateway Protocol-Labeled Unicast) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
Severity=Major
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
Severity=Major
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned from a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB(Segment Routing Label Block), this mismatch can result in incorrect label forwarding.
PR NumberSynopsisCategory: MX Platform SW - UI management
1884816
Major
MIC details not polling when SNMP MIB walk is performed after Junos OS upgrade
Product-Group=junos
Severity=Major
Post upgrading the Junos OS for MX10K platform from 21.4R3-S3.4 to higher versions, the Simple Network Management Protocol (SNMP) Management Information Base (MIB) walk is not polling Modular Interface Card (MIC) details impacting the SNMP monitoring.
PR NumberSynopsisCategory: Class of Service
1872595
Minor
CoS configured on logical interface does not work on Junos platform when CoS wildcard configurations applied using groups
Product-Group=junos
Severity=Minor
When Class of Service configurations for an Interface Device (IFD) are present both under the wildcard (applied via groups) and as specific configurations (applied directly under the class-of-service hierarchy) on Junos platform, the Interface Device (IFD) correctly takes the specific configurations as expected. However, the Interface Logical (IFL) configurations from the wildcard are not being applied via groups.
PR NumberSynopsisCategory: Device Configuration Daemon
1824215
Major
Incorrect speed assigned to 1G interfaces on MPC2E-3D-NG high-capacity line card modules.
Product-Group=junos
Severity=Major
During the insertion or removal of optics on 1 Gbps interfaces attached to MPC2E-3D-NG , the interface speed may be incorrectly set to 2 bps.
1848768
Major
MTU configuration is not applied from the configuration group after commit and "warning" is seen
Product-Group=junos
Severity=Major
When configuring MTU on interfaces through a configuration-group and commit the changes, those are not saved on the configuration file.
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1881742
Major
Packet Loss is observed when explicit Null is disabled for BGP-LU routes in ECMP scenarios
Product-Group=junos
Severity=Major
On Junos ACX5448 and ACX710 platforms, traffic drop is observed for the Labeled Unicast (BGP-LU) route prefixes with Equal-Cost Multipath (ECMP) forwarding path when explicit null is disabled.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1856132
Minor
FPC process crash observed due to heap memory errors with Inline CFM and VLAN Normalisation
Product-Group=junos
Severity=Minor
On Junos MX platform with line cards MPC1-MPC9, configuring an Inline CFM (Connectivity Fault Management) UP MEP (Maintenance Association End Point) session on an AE (Aggregated Ethernet) interface with VLAN normalisation and bridge or VPLS (Virtual Private LAN Services) encapsulation can result in heap memory errors. These errors may occur after an FPC reboot or when a new CFM peer is learned over VPLS, potentially leading to FPC process crash.
PR NumberSynopsisCategory: Configd, ffp issues
1877439
Minor
Traffic drop occurs on Junos Evolved platforms when prefix is moved between dynamic prefix-lists used in firewall filter
Product-Group=junos
Severity=Minor
On all Junos Evolved platforms, when a firewall filter is configured with a dynamic prefix-list that is referenced using an apply-path statement, moving a prefix from one such prefix-list to another where both prefix-lists match the apply-path pattern results in the prefix not being programmed in the PFE. This causes traffic loss for that prefix. The issue is triggered when the configuration includes apply-path pointing to both the source and destination prefix-lists, and a prefix is deleted from one and added to the other through a commit operation.
PR NumberSynopsisCategory: EVPN control plane issues
1889092
Major
The rpd EVPN module sends a redundant license message to the license infrastructure
Product-Group=junos
Severity=Major
On Junos platforms, when loading the baseline configuration or during BGP flaps or Routing Instance deactivation, and a large number of Group-Based Policy (GBP) tagged routes are removed, a redundant GBP license update message is sent to the license infrastructure for every route deletion. This issue has no impact on traffic.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1848993
Major
The data plane will be out of sync when migrating to EVPN A/A stitching with Vanila VXLAN (PIM Multicast)
Product-Group=junos
Severity=Major
On MX platforms, to improve the convergence of node failures in EVPN MH interconnects with Data Plane VXLAN, migrating to an Active-Active setup may cause the data plane to become out of sync for ARP entries. The gateway learns the MAC address and advertises it to the peer gateway. However, on the peer gateway, some MAC-IP entries may remain stuck in the 'Unresolved' (Ur) state.
PR NumberSynopsisCategory: SRX1500 platform software
1876867
Major
FPC goes offline and srxpfe core dump is generated during the system normal operation or boot-up
Product-Group=junosvae
Severity=Major
FPC (Flexible PIC Concentrators) on SRX1500 device goes offline and generates srxpfe core dump on system boot-up or normal operation in a rare timing scenario. This issue cause a traffic impact.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1871420
Major
Fragmented packets dropped in EVPN-MPLS scenario due to the IRB interface MTU limitation
Product-Group=junos
Severity=Major
On all Junos platforms running in EVPN-MPLS (Ethernet Virtual Private Network over Multiprotocol Label Switching) scenarios, host-generated packets exceeding the IRB interface MTU (Maximum Transmission Unit) are fragmented. Only the first fragment is forwarded, while remaining fragments are dropped, leading to loss of control-plane traffic.
PR NumberSynopsisCategory: ISIS routing protocol
1847557
Critical
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.
PR NumberSynopsisCategory: jdhcpd daemon
1872292
Major
DNS resolution will fail for DNS entries written to "resolv.conf"
Product-Group=junos
Severity=Major
On all Junos platforms with ZTP (Zero-Touch Provisioning) configuration, when the configuration is completely removed, DNS (Domain Name System) resolution for DNS entries written to "resolv.conf" will fail.
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1788400
Major
SNMP walk timeout
Product-Group=junos
Severity=Major
On Junos MX platform with MSMPC card, NMS (Network Management System) times out when polling any data from jnxSpSvcSetIfTable OID.
PR NumberSynopsisCategory: Flow Module
1854492
Major
Junos SRX platforms with chassis cluster configured experience flowd crash due to a race condition in multicast session handling
Product-Group=junos
Severity=Major
On Junos SRX platforms with chassis cluster configured, a crash is observed in multicast scenario due to a race condition where a link flap changes the ingress interface while a session is being aged out, leading to invalid session data access. This causes the flowd process to crash, resulting in a coredump and eventually the system crashes.
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
Severity=Major
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.
PR NumberSynopsisCategory: l2 flow module
1856200
Major
PFE crash due to invalid cached next hop during reinjection on SRX5k
Product-Group=junos
Severity=Major
On SRX5k devices, the PFE (Packet Forwarding Engine) may suddenly crash with a core dump written and force a restart against all line cards during massive interface or route changes when the system caches and reinjects an invalid next hop.
PR NumberSynopsisCategory: JSR Application Services
1792714
Major
pub-brokerd crash due to rapid connect-disconnect events on SRX platforms with MNHA
Product-Group=junos
Severity=Major
On all SRX platforms with Multi-Node High Availability (MNHA) enabled, a rare corner-case scenario involving a rapid sequence of connection attempts immediately followed by disconnections can trigger an unhandled assertion in the pub-brokerd process. This results in a core dump and full-service disruption on the affected node. Automatic recovery is not supported in this scenario, and manual intervention is required. The issue is rare and relies on a specific timing condition.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1877966
Minor
Some new VPN tunnels are not coming up on SRX5K platforms with SPC3
Product-Group=junos
Severity=Minor
On SRX5K platforms with SPC3 installed, IPSec (Internet Protocol Security ) tunnels with iked which reuses the same IKE (Internet Key Exchange) gateway peer IP, could be observed not re-establishing.
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .
PR NumberSynopsisCategory: authd (AAA) library code
1860913
Major
The authd process crashes when /etc/resolv.conf file is empty
Product-Group=junos
Severity=Major
On Junos OS Evolved ACX platforms, when DHCP (Dynamic Host Control Protocol) local server is configured without domain-name specified, the authd process crash may be observed. There will be no forwarding traffic impact due this issue, however, new DHCP client requests will not be answered.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, an out-of-memory condition in the rpd process caused by uncontrolled memory allocation leads to the rpd process crashing.
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when RSVP-TE (Resource Reservation Protocol - Traffic Engineering) is configured with MBB (make-before-break) setup, if the protected link of the primary LSP (Label Switched Path) goes down and if "clear mpls lsp" or "clear rsvp session" commands are executed, then LSP switches to new instance from the old which will be on higher IGP (Interior Gateway Protocol) metric. However, after re-optimization, LSP will not get switched to better IGP metric path and remain in old instance. Traffic drop can be seen due to this double fault events.
PR NumberSynopsisCategory: Multicast Routing
1876458
Major
MX960 mcsnoopd core dump during rt_mcnh_nh_release
Product-Group=junos
Severity=Major
The root cause is, when the system comes up after reboot, in MCSNOOPD (/usr/sbin/mcsnoopd used for L2 multicast), the lsi interfaces are learned. In MCSNOOPD, when there are 4 lsi interfaces learned, we create a nexthop(assume VE NH1) with all these 4 lsi as members and we use it in the routes for forwarding the traffic. When MCSNOOPD learns 5th lsi interface, as per internal NH(nexthop) allocation logic, we allocate a new nh(assume VE NH2) containing all these 5 lsi interfaces and free the old NH(VE NH1). The old freed NH(VE NH1) is accessed and tried to be freed again in another part of the code flow which is causing MCSNOOPD core(/usr/sbin/mcsnoopd). The fix is to free the old NH(VE NH1) in a common place instead of freeing in multiple places.
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1873938
Major
The SPC3 card resets due to kernel memory exhaustion in MX Series platforms with highly scaled routing tables and Inline Active Flow Monitoring configured
Product-Group=junos
Severity=Major
On MX240, MX480 and MX960 platforms with MX-SPC3 (Services Processing Card) service cards, when Inline Active Flow Monitoring (inline-jflow) is configured in a highly scaled routing environment (~4M routes), the SPC3 service card runs out of kernel memory, resulting in the PIC going offline or resetting and the services running on the SPC3 card gets disrupted.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1881956
Major
IPv6 default route gets deleted from FIB by slaac daemon after an upgrade with an unsupported configuration
Product-Group=junos
Severity=Major
On all Junos OS platforms , deletion of IPv6 default route from FIB (Forward Information Base) by slaacd (Stateless Address AutoConfiguration Daemon ) is observed while recovering the device from amnesiac state after the OS upgrade with any unsupported or incompatible configuration.
PR NumberSynopsisCategory: TCP/UDP transport layer
1864027
Minor
TCP listening sockets are not displayed correctly
Product-Group=junos
Severity=Minor
On Junos OS platforms, TCP (Transmission Control Protocol) listening sockets may be absent from command outputs due to NULL values in netstat application.
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.
PR NumberSynopsisCategory: Issues related to PKI daemon
1876497
Minor
Wrong digest algorithm is used for ECDSA key based certificate requests using PKI
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, when generating Elliptic Curve Digital Signature Algorithm (ECDSA) based Certificate Signing Request (CSR) using Public Key Infrastructure (PKI), SHA-384 digest is used even when other digest algorithm is specified in Command Line Interface (CLI). This issue will impact services that are based on these certificates when the services are configured for specific digest algorithm.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1868085
Major
The rpd process crashes and asserts are seen due to memory leak
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, rpd process crashes and asserts are seen due to a memory leak when BGP sharding is enabled and 'show route' is performed continuously.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1858750
Critical
Route change is not synced after rpd restart due to rib-fib inconsistency
Product-Group=junos
Severity=Critical
On all Junos OS Evolved platforms, after rpd (Routing Protocol Daemon) restart, the route change is not sent from routing daemon RIB(Routing Information Base) to forwarding plane FIB (Forwarding Information Base). This results in traffic drop.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1813582
Minor
Static route refreshes age when commit full is performed
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, with import policy defined in the rib-group and commit full is performed, static route refreshes age. There is no service impact due to this issue. This issue is not seen with normal commit.
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=junos
Severity=Major
On all Junos, Junos OS Evolved, and cRPD platforms, due to deadlock in internal processes, BGP (Border Gateway Protocol) route advertisement fails leading to traffic disruption.
PR NumberSynopsisCategory: Resource Reservation Protocol
1864823
Major
The rpd with per-priority subscription configuration
Product-Group=junos
Severity=Major
The heap memory allocated to store the per-priority subscription values must be retained if the parsing of 'protocols rsvp interface <*> subscription' config hierarchy is successful. However, the heap pointer 'prio_subscr_value' is freed even if the parsing is successful resulting in memory-use-after-free causing the rpd (Routing Protocol Daemon).
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.
1871664
Minor
The rpd process crash is seen due to internal message handling issue in RSVP
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms with RSVP(Resource Reservation Protocol) enabled, the rpd(Routing Process Daemon) process crash is seen. The issue is seen in rare scenario where message-id after the wrap around runs into collision in RSVP IO(Input Output) database due to 32bit limitation.
1881906
Major
BFD session failure causes LSP to go down and the inactive route remains in the routing table leads to traffic black hole
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms, when an RSVP (Resource Reservation Protocol) LSP (Label Switched Path) goes down due to a failure in the associated BFD (Bidirectional Forwarding Detection) session, and the corresponding route remains in the routing/forwarding table causing traffic black-holing. If there are other active LSPs to the same destination, those active routes are preferred over the inactive route associated with the failed LSP.
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1869450
Major
Subscribers failed to establish DS-Lite softwires due to stale softwire entries
Product-Group=junos
Severity=Major
On Junos MX Series platforms using MS-MPC or MX-SPC3 line cards with DS-Lite softwires subscriber services and the session-limit-per-prefix option enabled, the softwire extension reference count will not be properly decremented during subscriber session teardown. These stale softwire entries cause traffic failures when the same subscriber connects to a different AFTR (Address Family Transition Router). This will not impact new subscriber sessions with any AFTR, nor will it affect existing subscriber sessions with the same AFTR.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
Severity=Major
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.
PR NumberSynopsisCategory: SRX branch platforms
1873583
Minor
TCP RST packet gets dropped when used with rst-invalidate-session
Product-Group=junos
Severity=Minor
On all SRX platforms, when the rst-invalidate-session option is enabled, SRX devices drop a TCP (Transmission Control Protocol) RST(Reset) packet that arrives immediately after a TCP SYN (TCP Synchronize) packet, before a full session is established, leading to TCP protocols errors resulting in connectivity issues.
1877323
Major
Unexpected primary role assignment on SRX after node0 reboot
Product-Group=junos
Severity=Major
On all Branch SRX series platforms(SRX300/SRX320/SRX340/SRX345/SRX380), rebooting node0 with chassis cluster enabled causes the High Availability (HA) control link to establish after the initial hold timer expires. As a result, node0 assumes the primary role unexpectedly, leading to a split-brain condition where both nodes operate as primary.
PR NumberSynopsisCategory: MX10003/MX204 Timing/Sync-E issues tracking
1863091
Major
FPC will crash in MX10003 during the Master switchover to RE1 or Master set to RE1
Product-Group=junos
Severity=Major
MX10003 FPC (Flexible PIC Concentrators) will crash if Primary RE (Routing Engine) switchover to RE1 (Routing Engine 1) or RE1 is set to Master from release 21.2 and above.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1878195
Major
Heap memory threshold value is not taking effect post GRES/Switchover if configured to a higher value
Product-Group=junos
Severity=Major
On Junos OS platforms with MPC10, MPC11, LC4800, LC9600 line cards and on MX304, if heap memory threshold is configured with the higher value, post GRES (Graceful Routing Engine Switchover) or switchover, threshold gets overwritten to default. Drop in subscribers can be seen if heap usage is more than the default threshold in case of Subscriber Management is enabled.
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1851317
Minor
Packet drops are observed on rate-limited queues
Product-Group=junos
Severity=Minor
On MX platforms with MPC10E, MPC11E, MX304 and JNP10K-LC9600 with Class-of-Service (COS), packet drops are seen in rate-limited queues with high, medium-high or strict-high priority due to shallow buffer-size.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1875040
Major
The BUM traffic is dropped due to interoperability issue in combination of MPC 1-9 and MPC10E/MPC11E line cards in a WECMP setup
Product-Group=junos
Severity=Major
The Broadcast, unknown Unicast, and Multicast (BUM) traffic such as Ethernet Virtual Private Network (EVPN) or Virtual Private LAN Service(VPLS) etc. is dropped on the egress Flexible PIC Concentrator (FPC) in a weighted Equal Cost Multi-Path (ECMP) setup with non-zero balances when ingress traffic arrives on a different line card. This issue arises only in interoperability scenarios where a combination of MPC 1-9 and MPC10E/MPC11E line cards are used for ingress and egress processing resulting in forwarding issues.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1837840
Major
Incorrect color-aware srTCM marking with yellow packet loss priority
Product-Group=junos
Severity=Major
There was a software side limitation on the highest CBS that can be configured for MPCs that have LU type lookup chips due to a hardware PR. The Hardware PR was resolved in MX240/ MX480/ MX960/ MX2008/ MX2010/ MX2020/ MX10003/ MX10008/MX10016/ EX9200/EX9204/EX9208/ EX9214/ EX9251/EX9253/ SRX5400/SRX5600/SRX5800 platforms, but the software-side limitation was not removed for the same. Due to this limitation, whenever the CBS was configured above its limit (earlier 33m), the low-level parameters used to get configured such that the packets would not have any credits available, resulting in them getting marked as RED.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1870522
Minor
STP/RSTP/MSTP/VSTP enters a disputed and blocked state when the anchor FPC of an AE link, with members distributed across multiple FPCs, goes offline
Product-Group=junos
Severity=Minor
On MX and EX9200 series platforms that operate in hyper mode by default, STP (Spanning Tree Protocol)/RSTP (Rapid Spanning Tree Protocol)/MSTP (Multiple Spanning Tree Protocol)/VSTP (VLAN Spanning Tree Protocol) transitions to a disputed and blocked state if the members of the AE (Aggregated Ethernet) link in the anchor FPC (Flexible PIC Concentrator) goes offline.
1874097
Minor
Telemetry is not reporting statistics for an IRB interfaces
Product-Group=junos
Severity=Minor
On Junos OS Evolved and MX platforms with MPC10E/MPC11E/LC9600 line cards, MX304 and EX9k with EX9200-15C line cards , telemetry is not reporting statistics for the IRB (Integrated Routing and Bridging) interfaces, even though they are up and running.
1874503
Major
An IPv6 neighbor solicitation packet is dropped at the ingress PE router when it is received with more than two VLAN tags.
Product-Group=junos
Severity=Major
On Junos platforms having 'arp-supression' suppression enbabled, when IPV6 neighbor solicitation packets are received with more than two tags in an EVPN (EThernet Virtual Private Network) instance, the NDP (Neighbour Discovery Protocol) packets that are suppressed to the host path are incorrectly processed through a wrong DDOS policer, as the hop-limit value from the IPV6 header is not properly retrieved, causing them to be dropped by the packet forwarding engine.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1858741
Minor
IPv6 link cannot be used for around 10 seconds after DAD finishing due to NS delay.
Product-Group=junos
Severity=Minor
If both IPv4/IPv6 addresses are configured and both IPv4/IPv6 traffic is sent, there may be a 10 second delay in NS completion. This may occur when the egress interface is disabled/enabled and triggers NH resolution.
1880860
Major
FPC crash is seen on MX series when disabling AE IFL in mixed-speed configuration without enhanced-ip enabled
Product-Group=junos
Severity=Major
On MX platforms using ukern line cards (MPC2-9, LC480, LC2101, MX10K3), disabling an AE(Aggregated Ethernet) IFL configured with mixed-speed member links and without enhanced-ip enabled causes the associated FPC to crash and reboot.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1855393
Major
User root is shown as incorrect after power cycle of the device
Product-Group=junos
Severity=Major
After a power cycle, telnet login through the console fails. The issue occurs randomly and does not happen after every power cycle. To recover the device, another power cycle should be performed.
1874078
Major
Unable establish gnmi session using Radius and TACACS auth
Product-Group=junos
Severity=Major
Unable establish gnmi session using Radius and TACACS auth. Currently JADE (Junoscript authentication daemon) utility which does authentication for telemetry on cRPD has support for local authentication.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1839362
Minor
The commit error is seen in backup RE on MX platforms
Product-Group=junos
Severity=Minor
On all MX platforms, the commit fails in Backup RE during configuration commit where "fast-synchronise" and "graceful-switchover" are being committed together.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1863354
Minor
Command line freezes when Ctrl+Z is used
Product-Group=junos
Severity=Minor
In Junos OS Releases 24.2 and later(BSD 15), pressing Ctrl+Z in the Command Line Interface CLI suspends the process and causes it to become unresponsive. This behaviour is observed on systems using the and Berkeley Software Distribution BSD15 platform.
1872820
Major
The dcd process crashes when deactivating only 'swap' under ' interfaces <> unit <> output-vlan-map' with no other attributes present
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, this issue affects configurations where Virtual Local Area Network (VLAN) mapping is used, particularly in scenarios where only the swap attribute is applied under 'interfaces <> unit <> output-vlan-map'. Sequence of 'Deactivate -> Activate -> Commit' of the config hieararchy leads to crash of the device control daemon (dcd) process, potentially causing service disruption.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1843602
Major
TCP session between syslog server and device remains in closed state
Product-Group=junos
Severity=Major
On all Junos platforms, a TCP (Transmission Control Protocol) connection issue occurs between the device and syslog server after an idle period exceeding 2 hours. The session gets terminated and remains in a closed state without initiating any new session until the syslog server configuration is deleted and added again. This impacts disruption in log forwarding to the remote syslog server.
1848106
Major
The eventd process crash occurs due to flooding of out of memory logs
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, eventd process crashes is observed. This happens when eventd process is processing the flooding of out of memory logs generated by any of the processes running on FPC (Flexible PIC Concentrator). This is traffic impacting depending on the process with memory issues.
PR NumberSynopsisCategory: Virtual Private LAN Services
1850803
Minor
A traffic outage is seen when disabling and enabling the LACP configuration
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms that support EVPN Egress Link Protection, the AE(Aggregated Ethernet) member-link "Device flags" keeps "Present Running PFE-Gone" even after the LACP(Link Aggregation Control Protocol) configuration is re-enabled.
PR NumberSynopsisCategory: VSRX platform software
1789508
Major
Interface speed changes when added to aggregated-ethernet bundle on vSRX3.0 platform
Product-Group=junos
Severity=Major
On vSRX3.0 platform, speed of the gigabit-ethernet (ge) interface reduces to 1G when added as a part of Aggregated-Ethernet (AE) bundle. This issue does not cause traffic impact but can affect Class of Service (CoS) configuration of the interface.
PR NumberSynopsisCategory: Track Windriver Linux issues
1631579
Critical
A few line cards will be stuck in the 'Present' state and later go 'Offline'
Product-Group=junos
Severity=Critical
A system equipped with specific line cards, the line cards will be stuck in the 'Present' state and later go 'Offline' after the line card or router is rebooted. Ideally, the Line Card should go 'Online' instead it goes 'Offline'.
PR NumberSynopsisCategory: usf ipsec related issues
1876801
Major
IPsec-inside-IPsec tunnel establishment fails on MX platforms with SPC3 cards
Product-Group=junos
Severity=Major
On MX platforms equipped with SPC3 cards, the establishment of the inner IPsec tunnel fails in an IPsec-inside-IPsec tunnel setup. This occurs because the service PIC's forwarding process incorrectly attempts to punt IKE packets to the Route Engine (RE) and cannot resolve the required internal fabric path.
1884595
Minor
Allow default route to be created provided st0 IFL is in a non-default routing instance.
Product-Group=junos
Severity=Minor
ARI now allows default route to be pushed if the corresponding st0 interface is configured in a specific routing instance.

 


 

24.2R2-S2 - List of Known issues 

PR NumberSynopsisCategory: "agentd" software daemon
1889924
Major
OCST-Infra/gNMI-DialOut: Data still seems to be streaming somewhere when the DialOut (Established) connection on the port is already closed
Product-Group=junos
The existing gRPC-DialOut connection do not disconnect completely on the DUT, causing any other DialOut connections to fail.

Resolved In: evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: A20/A40 IOC card
1883027
Minor
SRX Firewalls with IOC3 triggers a temperature alert on the FPC 2 PLX PCIe Switch Chip
Product-Group=junos
On SRX5400, SRX5600, and SRX5800 platform with MPC3-40G10G and MPC3-100G10G (IOC3) interface card, a temperature alarm is triggered when the Peripheral Component Interconnect Express (PCIe) switch chip temperature exceeds 75 Celsius degrees.

Resolved In: junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S1 junos:25.2R2
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.4R1 junos:25.1R1
1839959
Critical
The MAC+IP table and mac-table are not in sync in the EVPN-MPLS active-active multihomed scenario leading to traffic loss
Product-Group=junos
On all Junos and Junos OS Evolved platforms that supports ESI lag interface and in an EVPN-MPLS (Ethernet Virtual Private Network - Multi Protocol Label Switching) active-active multihomed scenario, when the multihomed access interfaces are flapped in quick succession, it results in an unresolved destination route for the specific IP host. This is occurred due to race condition within l2ald (Layer 2 Address learning daemon) followed by an interface flap which causes the locally learned MAC to go missing from the mac-table on the other PE router.

Resolved In: evo:21.4R3-S10-EVO evo:22.2R3-S6-EVO evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO junos:21.4R3-S10 junos:21.4R3-S4-J26 junos:22.2R3-S6 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S4 junos:23.4R2-S5 junos:24.4R1
PR NumberSynopsisCategory: Signature Database
1883645
Minor
Not able to download IDP signature via routing instance
Product-Group=junos
On SRX platforms, SRX fails to download IDP signature via routing instance

Resolved In: junos:24.4R1-S3-J2 junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1843627
Critical
Memory leak when deactivating/reactivating routing instances with vrf-table-label
Product-Group=junos
On all Junos Evolved platforms, a memory leak occurs when a routing instance configured with "vrf-table-label" is deactivated and then reactivated, followed by a Routing Engine (RE) switchover on dual RE systems. This issue causes a slow memory leak in the system.

Resolved In: evo:23.4R2-S4-EVO evo:23.4R2-S5-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.4R2-S4 junos:23.4R2-S5 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1762490
Minor
JDI-RCT-MPC10E: Ksyncd crash on backup RE after fpc reboot
Product-Group=junos
On MX series, when PS over RLT is configured where all member LTs are hosted on the same FPC and user restarts this FPC then on rare occasion, ksyncd crash can occur on backup RE. However, there is no impact on the master and only backup RE is affected. This issue is not consistent and seen only once out of ~10 or 15 fpc restart operations.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Flowd for Multicast on SRX platforms
1877771
Major
The flowd process crash is observed on all Junos SRX platforms in multicast scenario with PIM
Product-Group=junos
On all Junos SRX platforms, the flowd process crash will be observed when device is acting as MHR (Middle Hop Router) and PIM (Protocol Independent Multicast) register packet from FHR (First Hop Router) tries to build the control/data session for the same PIM register packet.

Resolved In: junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1801028
Major
VPN TPS performance is degraded on SRX5K series
Product-Group=junos
VPN TPS performance is degraded in Release 24.2R2 on SRX5K series with dpdk-22.11.

Resolved In: junos:24.4R1
PR NumberSynopsisCategory: Security platform jweb support
1876075
Minor
Upgrade and Downgrade will fail from J-Web in SRX4600
Product-Group=junos
On SRX4600, upgrades and downgrades will fail from J-Web with the error message: "Installation Progress failed at Receive Package File" from release 23.4 and above.

Resolved In: junos:23.4R2-S5 junos:24.2R2-S3 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Key Management Daemon
1869769
Major
The kmd process crashes when device with MS-MPC has DPD enabled and a SA is deleted
Product-Group=junos
On all MX platforms with MS-MPC (Multiservices Modular PIC Concentrator), when DPD (Dead Peer Detection) is enabled under IPsec/IKE (Internet Key Exchange) VPN settings and for any reason an IPsec SA (Security Association) is deleted, the kmd process crashes. Due to the kmd process restart some disruption in tunnel establishment is seen.

Resolved In: junos:22.4R3-S7
PR NumberSynopsisCategory: Multiprotocol Label Switching
1874592
Critical
Recommended way to modify maximum-labels on production MX router
Product-Group=junos
Changing maximum-labels is a catastrophic change which interacts across interface daemon, rpd daemon, mpls protocol, kernel and PFE in nature. This is effective for all types of MPC line cards. Failing to follow recommended steps to modify maximum-labels on production router can lead to mpls traffic impact

Resolved In:
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:25.4R1-EVO
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
em0 mgmt port is unreachable after RE switchover
Product-Group=junos
On MX10008 with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In:
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1851629
Minor
Next-hop APIs to support LDP stitching cases over BGP routes pointing to list of indirects
Product-Group=junos
On all Junos and Junos Evolved platforms this is an enhancement for Nexthop APIs to support LDP stitching cases over BGP routes pointing to list of indirects next-hops.

Resolved In: evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.2R2
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1806872
Critical
Junos OS: MX Series: When specific SIP packets are processed the MS-MPC will crash (CVE-2025-52982)
Product-Group=junos
An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA100088 [juniper.net] for more information.

Resolved In: junos:21.2R3-S9 junos:22.2R3-S6 junos:22.4R3-S6
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1885754
Major
MX304 acting as an LNS saw an FPC restart and core dump in aft-trio after offlining a MIC
Product-Group=junos
MX304 acting as an LNS saw an FPC restart and core dump in aft-trio after offlining a MIC

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: VMHOST platforms software
1856565
Minor
High memory consumption in VMhost causes FPC reboot
Product-Group=junos
On all VMhost based platforms, excessive file accumulation in the /var/tmp directory of the host side triggers FPC reboots, resulting in network traffic disruption. This condition occurs when available space falls below 65% (usage exceeds 35%).

Resolved In: junos:22.4R3-S7 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1

 

Modification History

First publication 2025-08-14