Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX running Junos Evolved software

Alert Description

Junos Software Service Release version 24.4R2-S1-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Review

Solution

Junos Software service Release version 24.4R2-S1-EVO is now available.

24.4R2-S1-EVO - List of Fixed issues 

PR NumberSynopsisCategory: EVO L3 routing for BCM XGS Platforms
1896299
Major
[QFX5K-EVO]Spine which has VGA does not reply to traceroute in EVPN-VXLAN CRB environment
Product-Group=evo
Severity=Major
In an EVPN-VXLAN CRB environment, when performing traceroute from CE to Spine's Peer device, Spine's VGA does not return a reply.
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1885670
Minor
IGMP or MLD packets associated with CCC services will be dropped instead of being forwarded
Product-Group=evo
Severity=Minor
On Junos Evolved PTX10008, PTX10016, and PTX10002-36QDD platforms, Internet Group Management Protocol (IGMP) or Multicast Listener Discovery (MLD) packets associated with Circuit Cross-Connect (CCC) services such as EVPN-VPWS (Ethernet VPN-Virtual Private Wire Service (VPWS) or L2Circuit ingressing into the Provider-Edge (PE) device will be dropped instead of being forwarded.
PR NumberSynopsisCategory: BX PFE firewall issues
1877486
Minor
Ethernet-Switching Flood Filter Stops Working When Policer Action Is Added
Product-Group=evo
Severity=Minor
On BX-based EVO PTX platforms (e.g., Balerion, Aegon, Octomore), applying a flood filter with a policer in a single commit can result in the filter not functioning properly due to incorrect handling of interface child members and slice mask processing, causing degraded performance
PR NumberSynopsisCategory: Express BX PFE L3 Features
1886060
Major
PFEs will enter FAULT state when multiple PFEs are on-lined / off-lined / restarted at the same time
Product-Group=evo
Severity=Major
On all Junos-Evolved PTX platforms, If multiple PFEs ( packet forwarding engine ) are on-lined / off-lined / restarted at the same time, without any delay in between the PFE activities ( on-lined / off-lined / restarted ) then one or more PFE will go fault state and all ports belonging to those PFEs become unusable.
PR NumberSynopsisCategory: CoS support on DNX
1893395
Minor
Classification of traffic is not working due to Forwarding Class to Queue mapping configuration failure.
Product-Group=evo
Severity=Minor
Error Message "Failed to program the hardware with error table is full, during = jbcm_cosq_gport_queue_offset_mapping_set" can be seen while modifying the class-of-service config.
PR NumberSynopsisCategory: Firewall support for DNX
1888201
Major
Commit can fail if apply-path contains pattern-matching tokens other than the wildcard <*>
Product-Group=evo
Severity=Major
When the apply-path contains pattern-matching tokens other than the wildcard <*>, prefix list validation may fail, causing the commit to fail.
PR NumberSynopsisCategory: ACX IRB specific issues
1900224
Minor
ACX7k IFL configured with output-traffic-control-profile continues to use IFD VOQ until ethernet-switching table is cleared.
Product-Group=evo
Severity=Minor
When modifying the output-traffic-control-profile of a logical interface associated with and IRB with active traffic flows, the flows will continue to use the previously configured egress queues until the mac-address is cleared from the ethernet-switching MAC table.
PR NumberSynopsisCategory: DNX L2 related features
1855369
Major
Storm Control stops working on all LAG members after deactivating one or more interfaces on Junos OS Evolved ACX7K platforms
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX7K platforms, when storm control is configured on a LAG (Link Aggregation Group) interface and one or more LAG member interfaces are deactivated, storm control stops working on all remaining active members. This results in an immediate increase in BUM (Broadcast, Unknown Unicast, and Multicast) traffic on the egress interface.
PR NumberSynopsisCategory: Binding Queue
1885455
Major
application rpd-agent may restart with a coredump after interface related event changes.
Product-Group=evo
Severity=Major
The rpd-agen application may restart either immediately or latently - after interface are activate, deactivated, created, or removed.via.
PR NumberSynopsisCategory: Issues related to EVO dependency layer including object graphs, incompletes, anomalies and nkdb
1901341
Major
Anomalies observed on master during RE switchover
Product-Group=evo
Severity=Major
This issue is likely to occur during multiple RE switchover with a loaded interface configuration. Note that this issue occurs due to very rare combination of events and would not be seen in most use cases. There is no service impact when the issue occurs, and router operations are unaffected though there is a memory leak.
PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1898055
Minor
Unexpected commit failure will be observed when deactivating of unit or changing any configuration and performing a commit operation
Product-Group=evo
Severity=Minor
On Junos OS Evolved platforms, if input-vlan-map and output-vlan-map are configured, an unexpected commit failure may occur when deactivating a unit (e.g., unit ) or making any configuration changes followed by a commit operation. This issue results in commit failure errors and prevents further configuration changes.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1889335
Minor
Traffic drop is observed in an EVPN multihoming as the MAC route points to the ESI interface when the CE (ESI) IFD flaps
Product-Group=evo
Severity=Minor
On all Junos and Junos Evolved platforms, in an Ethernet Virtual Private Network (EVPN) MultiHoming setup with Ethernet Segment Identifier (ESI) configured under logical Interface (IFL) (CE-facing), when the corresponding IFD (Physical Interface) flaps, the MAC route will point to the ESI interface, while it should point to the Multihoming CE (Customer Edge) interface. This results in traffic loss.
PR NumberSynopsisCategory: EVO-AFT Infrastructure PFE related issues
1898307
Major
[EVPN VxLAN OISM] Aegon-Interop: pfe went offline after perform PFE power off/on multiple times
Product-Group=evo
Severity=Major
On all Junos OS & Junos OS Evolved PTX platforms , PFEs may fail to come online if they are subjected to rapid power-off and power-on configuration changes.
PR NumberSynopsisCategory: EVO Socket replication
1895827
Major
Adding a new key to authentication-key-chain causes crash
Product-Group=evo
Severity=Major
On all Junos Evolved platform, while adding a new key to key-chain, while previous one was added with max tolerance value, kernel crash is observed. Device self-recovers after the crash.
PR NumberSynopsisCategory: SNMP, mib2d issues
1890712
Minor
The snmpwalk for OID ifJnxInputErrors is not working on Junos Evolved platforms
Product-Group=evo
Severity=Minor
On all Junos Evolved platforms, the snmpwalk for OID ifJnxInputErrors (1.3.6.1.4.1.2636.3.3.1.1.36) is not working. This issue has no impact on traffic.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1848993
Major
The data plane will be out of sync when migrating to EVPN A/A stitching with Vanila VXLAN (PIM Multicast)
Product-Group=evo
Severity=Major
On MX platforms, to improve the convergence of node failures in EVPN MH interconnects with Data Plane VXLAN, migrating to an Active-Active setup may cause the data plane to become out of sync for ARP entries. The gateway learns the MAC address and advertises it to the peer gateway. However, on the peer gateway, some MAC-IP entries may remain stuck in the 'Unresolved' (Ur) state.
PR NumberSynopsisCategory: Express PFE CFM
1810549
Major
Non-Impactful CFMMAN Parse Error on First CFM CCM PDU During FPC/PFE Online Transition
Product-Group=evo
Severity=Major
On Junos Evolved PTX platforms, the log message "CFMMAN: Parse Error: CFM CCM pkt TLV parsing error" may appear when an FPC or PFE is restarted and comes online. This message indicates that a CFM Continuity Check Message (CCM) was truncated, leading to an error while parsing the TLV (Type-Length-Value) fields in the packet. The error is transient and typically affects only a small number (usually 1 or 2) of CCM packets received immediately after the FPC or PFE becomes operational. It has no functional impact on CFM sessions or overall network operations. CFM continues to function normally, and no persistent degradation is observed. This issue does not consistently affect any specific CFM session and occurs only during the brief initialisation period of the hardware component.
PR NumberSynopsisCategory: Express PFE FW Features
1876672
Major
SCU/DCU match is not working when configured along with the forwarding-class
Product-Group=evo
Severity=Major
On PTX Junos OS Evolved platforms, the SCU/DCU (Source class usage/ Destination class usage) match is not working when it is configured along with the forwarding-class.
PR NumberSynopsisCategory: ACX7332 & ACX7348 Platform Software
1900115
Major
PCIe fatal error resulting in an unexpected device reboot and evo-pfemand crash on Junos OS Evolved ACX7322 platform
Product-Group=evo
Severity=Major
On the Junos OS Evolved ACX7332 platform, an unexpected device reboot and evo-pfemand (Evolved Packet Forwarding Engine management process) process crash will be observed, due to PCIe (Peripheral Component Interconnect Express) fatal error "DPC: ERR_FATAL PCI error". This error results in a PCIe link-down event, causing a loss of signal to the external TCAM (Ternary Content Addressable Memory). When the TCAM becomes unavailable, any software attempt to access the TCAM can trigger a PCIe link failure, leading to a complete traffic impact. These events are logged in the system's journal logs.
PR NumberSynopsisCategory: ACX7509 Linecard (FPC) related issues
1893886
Major
Auto-negotiation mismatches leading to connectivity issues on Junos OS Evolved ACX7509, ACX7332, and ACX7348 platforms
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX7509, ACX7332, and ACX7348 platforms having auto-negotiation is configured on a 1G interface, connectivity issues will occur under certain conditions: system reboots or FPC (Flexible PIC Concentrator) restarts or changes in auto-negotiation settings on the peer side. In these scenarios, ARP (Address Resolution Protocol) resolution will fail due to a mismatch in the auto-negotiation state between the local and peer interfaces. The local interface will incorrectly appear as UP, while the peer interface shows as DOWN, leading to link-level inconsistencies and loss of connectivity.
PR NumberSynopsisCategory: Resource Reservation Protocol
1896022
Major
More bandwidth may be admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=evo
Severity=Major
If Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.
PR NumberSynopsisCategory: PTX10K specific platform PRs
1900735
Major
Evo PTX PFE instance stuck in fault state after restart
Product-Group=evo
Severity=Major
One or more PFEs may transition to fault state if multiple PFEs are restarted rapidly.
PR NumberSynopsisCategory: Issues related to control plane security
1899669
Major
After zeroize, Devid not programmed alarm will be seen and SzTP operations may be affected
Product-Group=evo
Severity=Major
After zeroize, Devid not programmed alarm will be seen and SzTP operations may be affected
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1873253
Major
The "show system storage" command output should show only true and distinct storages
Product-Group=evo
Severity=Major
On all Junos platforms, the "show system storage" command output is modified to list only all real UFS filesystem ie { 'ffs', 'tmpfs', 'ufs' } instead of virtual filesystem like '/var/jails/rest-api'.
PR NumberSynopsisCategory: ACX7000 interface software related issues.
1885817
Major
ACX7k DWDM optics wavelength not applied after reboot
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX7K platforms, the DWDM (Dense Wavelength Division Multiplexing) optics wavelength is not applied after reboot. Hence, the system defaulted to the standard wavelength mode rather than the explicitly configured wavelength. When the wavelength is defaulted to the standard wavelength mode, the link will be up and with no data traffic impact, and it's a corner case, and is specific to DWDM optics only.

 


24.4R2-S1-EVO - List of Known issues 

PR NumberSynopsisCategory: "agentd" software daemon
1896423
Major
With pre-gnmi telemetry streaming zero counters may get streamed atmost once when subscribed
Product-Group=evo
With pre-gnmi telemetry (telemetrySubscribe) streaming, when the subscription is made with need_eos flag set to false, where initial sync is not requested, there is a possibility that counters with zeros are also will be sent atmost once. If collector is not interested in those zeros counter can ignore those data., as its streamed only once. This is not an issue if collector is requesting with need_eos set to true in the request as zeros counters are already being sent atleast once in this scenario.

Resolved In:
PR NumberSynopsisCategory: QOS issues in EVO for BCM XGS Platforms
1880166
Major
ECN CE bit is not set in an EVPN-VxLAN scenario
Product-Group=evo
On QFX5130/QFX5700 platforms, in Ethernet VPN-Virtual Extensible LAN (EVPN-VxLAN) scenario, the Explicit Congestion Notification (ECN) Congestion Experienced (CE) bit will not be set for ECN-capable traffic when there is congestion. Since the CE bit is not set, packets will be dropped.

Resolved In: evo:23.4X100-D40-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.4R1-EVO
PR NumberSynopsisCategory: Express BT PFE L3 Features
1878029
Major
Restarting the evo-aftmand-bt or evo-cda-bt process disrupts PHY synchronization within the timingd service resulting in timing errors
Product-Group=evo
On Junos OS Evolved PTX10001-36MR platform with PTP (Precision Time Protocol) configured, a synchronization issue will occur between the PTP FPGA (Field Programmable Gate Array) and the MAC (Media Access Control)/PHY (Physical Layer). This results in timing errors on the local device, which may also propagate to downstream devices. The issue typically arises after restarting the evo-aftmand-bt or evo-cda-bt processes, which impacts the socket connection between these processes and the timingd service. As a result, timingd is no longer able to communicate with these components as expected.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1825059
Major
EVO: RPC and CLI validation failed for cli "show ethernet-switching table"
Product-Group=evo
RPC and CLI validation failed for cli "show ethernet-switching table"

Resolved In:
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1867244
Major
All engineering-supported releases of Junos OS and Junos OS Evolved on all platforms are not vulnerable CVE-2025-0167 CVE-2025-0665 CVE-2025-0725
Product-Group=evo
Upon engineering evaluation of these three CVE IDs, Juniper Networks has determined that all engineering-supported releases of Junos OS and Junos OS Evolved on all platforms are not vulnerable CVE-2025-0167 CVE-2025-0665 CVE-2025-0725. While there is no risk associated with these 3 CVE IDs, customers are advised to follow current IETF Security Best Current Practices, including but not limited to restricting access to authorized users, devices, and networks.

Resolved In:
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1879375
Critical
MACsec traffic impact due to incorrect port mapping.
Product-Group=evo
MACsec traffic can be impacted due to incorrect port mapping. When MACsec IFL is configured with a custom EAPOL ethertype profile on dual VLAN tagged interfaces, traffic fails in one direction while the MACsec session appears up. This issue is observed during WAN MACsec use cases on PTX10002-36QDD and PTX10003-80C platforms. The issue does not occur when MACsec IFL is disabled. This regression was introduced in release 25.2R1 via PR#1797197.

Resolved In: evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Express ptx-evo PFE L3 Features
1836337
Major
Packet loss is observed when the "indirect-next-hop-change-acknowledgements" command is missing from the junos-default configuration
Product-Group=evo
On Junos Evolved PTX10003 platform the command "indirect-next-hop-change-acknowledgements" is required in the junos-default configuration. If the said command is missing, it will result in packet loss.

Resolved In: evo:25.1R1-EVO junos:25.1R1
PR NumberSynopsisCategory: Evo Firewall
1896496
Minor
Traffic drop observed for two policer with same initial name and term names
Product-Group=evo
On all Junos OS Evolved platforms, when two policers with the same initial name(First 15 characters of rate estimator name) and term names are configured, since the rate estimator name (combination of filter term name and policer name) which gets truncated to 15 characters, the two policers start using the same rate estimator and it can lead to possible early drops by the policer, based on the current traffic rate of the two policers.

Resolved In: evo:24.4R2-S1-J1-EVO evo:25.4R1-EVO
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1871034
Major
on QFX5130, duplicate-mac-detect action discard does not work . The action shutdown port should be used instead.
Product-Group=evo
When duplicate-mac-detect feature is configured, if the mac moves from leaf to network in a VXLAN enviroment, the action discard does not take effect. The mac move is prevented. As an alternate, use the action shutdown port instead which is also one of the supported options.

Resolved In:
PR NumberSynopsisCategory: Express PFE FW Features
1882315
Minor
Firewall policy configured to match IP payloads fail matching on MPLS packets
Product-Group=evo
On Junos Evolved PTX platforms, when configuring a firewall policy, specifying family any, and matching on inner IP payload (IPv4 or IPv6), matching does not work on Multiprotocol Label Switching (MPLS) packets

Resolved In: evo:24.4R2-S1-J1-EVO evo:25.4R1-EVO junos:25.4R1
PR NumberSynopsisCategory: Category for JET(JUNOS Extension Toolkit) related issues
1894461
Major
Removal of the suffix when the hostname is used as the target ID in the gRPC-tunnel configuration
Product-Group=evo
On all Junos Evolved platforms, when hostname is used as the target ID in the gRPC-tunnel configuration, it includes the routing engine information as a suffix ("-re0" or "-re1"), the suffix part is now removed. is now removed. This issue has no impact on traffic.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Phone-Home-Client Infrastructure
1871802
Critical
High memory and CPU usage due to unintended phone-home client activation
Product-Group=evo
On Junos OS Evolved platforms, high memory and CPU usage may occur if the phone-home client (PHC) is unintentionally triggered, such as when the device boots with factory default settings or when phone-home is manually configured. This can lead to system slowness, crashes, and eventual device reboots.

Resolved In: evo:23.4R2-S5-EVO evo:24.2R2-S3-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.2R2-S3 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1830588
Critical
The rpd process crashes on all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted
Product-Group=evo
On all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted, route churn will potentially lead to the rpd process crash.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:23.2R2-S3-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:23.4R2-S5-EVO evo:24.2R2-EVO evo:25.1R1-EVO junos:22.2R3-S7 junos:22.3X60 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:25.1R1
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1815837
Minor
Configure low file size in traceoptions while logging volume is high will lead to high CPU and RPD scheduler slips causing operational impact
Product-Group=evo
If the file size is too small and the amount of traceoptions volume is too high it can cause scheduler slips and operational impact.

Resolved In: evo:22.3X80-D49-EVO evo:23.4R2-S6-EVO evo:24.2R2-S1-EVO evo:24.4R2-S2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:24.2R2-S1 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1881609
Minor
MX : RSVP hello messages sent with IP from "secondary" subnet
Product-Group=evo
On all Junos and Junos OS Evolved platforms where RSVP (Resource Reservation Protocol) configuration is present and a RSVP enabled interface has 2 IP address of which one is configured as primary/preferred in that case the RSVP Hello message uses the secondary IP address to form neighborship.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Issues related to control plane security
1860970
Minor
SIB HA wait timeout error upon graceful RE switchover
Product-Group=evo
SSH issue from the Routing Engine to the FPC causes SIB HA timeout error upon RE switchover. All the SIBs will be reset as a result of that.

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1704406
Major
VMX :: JDI-REG-VIRTUAL: Observed xml validation failure seen for "show host | display xml validate" and The emitted XML is INVALID.
Product-Group=evo
"show host" is not properly XMLized. So from a netconf channel the XML output is encapsulated in an tag. If any automation tool plans to use the XML output of this CLI command, it may have to do some logic on its side (as the response is not 100% XMLized)

Resolved In:
PR NumberSynopsisCategory: Issues related to NETCONF
1792554
Minor
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241
Product-Group=evo
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241

Resolved In:
PR NumberSynopsisCategory: ACX724 platform issues
1884419
Major
Host 0 Active Disk Usage Exceeded is not getting cleared even if the usage is less
Product-Group=evo
On Junos Evolved ACX7024 and ACX7024X, the "Active Disk Usage Exceeded" alarm is raised and not cleared even if the usage is less than 50%. This issue has no impact on traffic.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO

 


 

Modification History

First publication 2025-09-29