Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX and MX platforms running Junos software

Alert Description

Junos Software Service Release version 24.4R2-S1 is now available for download for ACX and MX platforms from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For review

Solution

Junos Software service Release version 24.4R2-S1 is now available.

24.4R2-S1 - List of Fixed issues 

PR NumberSynopsisCategory: BBE Cloud Infrastructure
1890548
Major
BNG CUPS Controller will not deploy on a Multi-Geo RHOCP Multicluster
Product-Group=junos
Severity=Major
The BNG CUPS Controller will not roll out on a RHOCP multi-geography multi-cluster.
PR NumberSynopsisCategory: BBE network stack related issues
1897105
Major
Incorrect ARP responses observed in BNG CUPS software versions
Product-Group=junos
Severity=Major
The BNG ( Broadband Network Gateway ) was incorrectly sending ARP ( Address Resolution Protocol ) replies for non-local IP addresses. This was caused by improper target address matching and missing local route installations.
PR NumberSynopsisCategory: Border Gateway Protocol
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.
PR NumberSynopsisCategory: EVPN control plane issues
1846266
Major
The inet filters attached to the IRB interface will not function as expected
Product-Group=junos
Severity=Major
On Junos QFX5k and EX4k platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, inet filters applied to Integrated Routing and Bridging (IRB) interfaces will not function as expected, and the associated actions of the filter are not enforced.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1848993
Major
The data plane will be out of sync when migrating to EVPN A/A stitching with Vanila VXLAN (PIM Multicast)
Product-Group=junos
Severity=Major
On MX platforms, to improve the convergence of node failures in EVPN MH interconnects with Data Plane VXLAN, migrating to an Active-Active setup may cause the data plane to become out of sync for ARP entries. The gateway learns the MAC address and advertises it to the peer gateway. However, on the peer gateway, some MAC-IP entries may remain stuck in the 'Unresolved' (Ur) state.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1871420
Major
Fragmented packets dropped in EVPN-MPLS scenario due to the IRB interface MTU limitation
Product-Group=junos
Severity=Major
On all Junos platforms running in EVPN-MPLS (Ethernet Virtual Private Network over Multiprotocol Label Switching) scenarios, host-generated packets exceeding the IRB interface MTU (Maximum Transmission Unit) are fragmented. Only the first fragment is forwarded, while remaining fragments are dropped, leading to loss of control-plane traffic.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1881956
Major
IPv6 default route gets deleted from FIB by slaac daemon after an upgrade with an unsupported configuration
Product-Group=junos
Severity=Major
On all Junos OS platforms , deletion of IPv6 default route from FIB (Forward Information Base) by slaacd (Stateless Address AutoConfiguration Daemon ) is observed while recovering the device from amnesiac state after the OS upgrade with any unsupported or incompatible configuration.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1897240
Major
Chassis-Control restart triggers when configuring GRE interface across multiple routing-instances leading to kernel crash
Product-Group=junos
Severity=Major
On Junos series devices, the kernel crash occurs when creating and configuring a identical GRE(Generic Routing Encapsulation) interface across different routing-instances.
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1828196
Major
Error messages are seen due to high CPU utilization
Product-Group=junos
Severity=Major
On Junos MX and PTX platforms (non-AFT based), error messages are seen with the operations that involve high CPU utilization on the RE and/or FPC. This issue has no impact on traffic.
PR NumberSynopsisCategory: QFX analyzer, sflow
1850213
Minor
L3 multicast traffic not forwarded when multi-homing node is acting as source in VXLAN
Product-Group=junos
Severity=Minor
When Group Based Policy (GBP) is enabled on Junos OS and Junos OS Evolved, Layer 3 multicast traffic originating from a Multi-homing (MH) source node is not forwarded.
PR NumberSynopsisCategory: Resource Reservation Protocol
1896022
Major
More bandwidth may be admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
Severity=Major
If Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1886937
Major
Interfaces either fail to come up or flap or a delay is observed on MX10003 platforms when the interface is reset or the devices is restarted
Product-Group=junos
Severity=Major
On MX10003 platforms peering to third-party devices, interfaces remain down or flap or a delay is observed while it comes back up after the device is restarted or the Flexible PIC Concentrator (FPC) is restarted or when the interface is reset. The symptoms is not consistent and any of the mentioned behaviour could be seen. Due to the interface going down or in case of a flap/delay, services running over the interface will be impacted or traffic flowing through that interface will be dropped.
PR NumberSynopsisCategory: ZT/YT pfe CDA issues
1882845
Critical
MPC 10/11/12E, LC9600 and LC4800 Line cards and MX304, interface statistics stop after interrupt
Product-Group=junos
Severity=Critical
On all MX platforms with MPC 10/11/12E, LC9600 and LC4800 Line cards and MX304, in a race condition related to the interrupt handling, interface counters are stuck and not incrementing. Issue not reproducible and there is no service impact due to this issue.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1873253
Major
The "show system storage" command output should show only true and distinct storages
Product-Group=junos
Severity=Major
On all Junos platforms, the "show system storage" command output is modified to list only all real UFS filesystem ie { 'ffs', 'tmpfs', 'ufs' } instead of virtual filesystem like '/var/jails/rest-api'.

 


 

24.4R2-S1 - List of Known issues 

PR NumberSynopsisCategory: "agentd" software daemon
1820119
Major
Sensor data is not streamed via gNMI
Product-Group=junos
On all Junos Evolved Platforms, sensor data is not streamed via gNMI.

Resolved In: evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:22.4R0-J0-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.3R3-S4 junos:22.3X60 junos:22.4R3-S4 junos:22.4R3-S5 junos:22.4X4 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S3 junos:23.4X30 junos:24.2R1-S1 junos:24.2R2 junos:24.2X1 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: BBE multicast related issues
1882756
Major
The bbe-smgd process crash triggered by a multicast event failure
Product-Group=junos
On all MX platforms with Broadband Edge Subscriber Management configured, the bbe-smgd process crashes when the multicast sync service add publish fails. This crash is automatically recovered by the system without requiring manual intervention.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: BBE
1891388
Major
BNG User Plane: Changing the BNG Controller name is allowed with subscribers on the user-plane
Product-Group=junos
BNG user plane: Changing the BNG Controller name is allowed after the user-plane is already associated with the BNG Controller and subscribers are logged in. This leaves the system in a bad state.

Resolved In:
1892276
Major
Updating BNG-UP IP Address leaves user-plane in READY state.
Product-Group=junos
Updating BNG-UP IP Address leaves user-plane in READY state.

Resolved In:
1890895
Major
BNG Controller: Issue with changing the IP address of an active BNG user-plane
Product-Group=junos
BNG Controller: Issue with changing the IP address of an active BNG user-plane

Resolved In:
1886696
Major
BNG Controller: When running with local static pools, a subscriber group is allowed to be deleted with active sessions
Product-Group=junos
When using static address pools BNG Controller allows for the SGRP using the pool to be deleted while subscribers are still logged in.

Resolved In:
PR NumberSynopsisCategory: Border Gateway Protocol
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D49-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:20.3X75-D52 junos:22.3X60 junos:23.2R2-S5 junos:25.2R1
1863551
Major
BGP route advertisement failure with as-override and peer-as configured at group level
Product-Group=junos
On all Junos and Junos OS Evolved platforms, BGP ( Border Gateway Protocol ) fails to advertise routes to external peers in an L3VPN ( Layer 3 Virtual Private Network ) environment when as-override is configured for a neighbor on the local device, and peer-as is applied at the group level. Since the routes are not advertised to peers, traffic matching those routes are dropped, causing service disruption.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S5-EVO junos:23.2R2-S4 junos:23.4R2-S6 junos:24.2R2-S1 junos:24.4R1-S2 junos:24.4R2 junos:25.2R1
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D20-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.2R3-S10 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-J4 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned from a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB(Segment Routing Label Block), this mismatch can result in incorrect label forwarding.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1889749
Major
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.

Resolved In: evo:24.2R2-S3-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.2R3-S8-J22 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Firewall Filter
1856854
Major
MIB2D will see 100% CPU utilization due to MIB2D walk fail
Product-Group=junos
On PTX3000/PTX5000/PTX10008 /PTX10016/QFX10008 /PTX1000/PTX10002/ QFX10002 platforms, MIB2D will see 100% CPU utilization due to MIB2D walk failure.

Resolved In: evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S5-J3 junos:22.4R3-S7 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: CoS support on DNX
1897336
Major
ARP resolution and device discovery failure is observed due to unexpected VLAN tags on ARP replies
Product-Group=junos
On ACX710 and ACX5448 platforms, due to VLAN edit profile remapping and VLAN translation, all the packets are getting VLAN-tagged. The RE ( Routing Engine ) drops ARP ( Address Resolution Protocol ) reply packets that contain VLAN ( Virtual Local Area Network ) tags, if the interface encapsulation was set to ethernet-ccc and VLAN configuration was removed. As a result, ARP resolution fails, leading to ping and device discovery failure.

Resolved In: junos:24.2R2-S3 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: EVPN control plane issues
1839959
Critical
The MAC+IP table and mac-table are not in sync in the EVPN-MPLS active-active multihomed scenario leading to traffic loss
Product-Group=junos
On all Junos and Junos OS Evolved platforms that supports ESI lag interface and in an EVPN-MPLS (Ethernet Virtual Private Network - Multi Protocol Label Switching) active-active multihomed scenario, when the multihomed access interfaces are flapped in quick succession, it results in an unresolved destination route for the specific IP host. This is occurred due to race condition within l2ald (Layer 2 Address learning daemon) followed by an interface flap which causes the locally learned MAC to go missing from the mac-table on the other PE router.

Resolved In: evo:21.4R3-S10-EVO evo:22.2R3-S6-EVO evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO junos:21.4R3-S10 junos:21.4R3-S4-J26 junos:22.2R3-S6 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S4 junos:23.4R2-S5 junos:24.4R1
PR NumberSynopsisCategory: ISIS routing protocol
1886347
Major
partial traffic drops seen on NSR switchover for Indirect route Going over L-ISIS transport route having "sensor-based-stats" configured under protocols isis
Product-Group=junos
On Junos and EVO platforms, After a Graceful Routing Engine Switchover (GRES), in New master, Indirect routes gets updated to the PFE and result in traffic loss when the transport is L-ISIS with telemetry traffic sensors enabled. In this scenario, Indirect routes going over L-ISIS route. Reason for Indirect route change is due to Underlying L-ISIS route next-hop getting changed. L-ISIS route next-hop getting changed due to ?Sensor-based-stats? configuration which does not support NSR functionality. Hence After Switchover, New Master Create sensors and Installed in the L-ISIS next-hop result in L-ISIS next-hop changed. Once L-ISIS routes nex-thop gets changed, Indirect routes under going for re-resolution which cause traffic impact.

Resolved In:
PR NumberSynopsisCategory: Flow Module
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.

Resolved In: junos:22.4R3-S8 junos:23.2R2-S3-J13 junos:23.2R2-S3-J15 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.3R1
PR NumberSynopsisCategory: Key Management Daemon
1869769
Major
The kmd process crashes when device with MS-MPC has DPD enabled and a SA is deleted
Product-Group=junos
On all MX platforms with MS-MPC (Multiservices Modular PIC Concentrator), when DPD (Dead Peer Detection) is enabled under IPsec/IKE (Internet Key Exchange) VPN settings and for any reason an IPsec SA (Security Association) is deleted, the kmd process crashes. Due to the kmd process restart some disruption in tunnel establishment is seen.

Resolved In: junos:22.4R3-S7
PR NumberSynopsisCategory: Multiprotocol Label Switching
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=junos
On all Junos and Junos Evolved platforms, an out-of-memory condition in the rpd process caused by uncontrolled memory allocation leads to the rpd process crashing.

Resolved In: evo:24.2R2-S2-EVO evo:25.2R1-EVO junos:22.3X60 junos:23.4R2-S4-J9 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Multicast Routing
1876458
Major
MX960 mcsnoopd core dump during rt_mcnh_nh_release
Product-Group=junos
The root cause is, when the system comes up after reboot, in MCSNOOPD (/usr/sbin/mcsnoopd used for L2 multicast), the lsi interfaces are learned. In MCSNOOPD, when there are 4 lsi interfaces learned, we create a nexthop(assume VE NH1) with all these 4 lsi as members and we use it in the routes for forwarding the traffic. When MCSNOOPD learns 5th lsi interface, as per internal NH(nexthop) allocation logic, we allocate a new nh(assume VE NH2) containing all these 5 lsi interfaces and free the old NH(VE NH1). The old freed NH(VE NH1) is accessed and tried to be freed again in another part of the code flow which is causing MCSNOOPD core(/usr/sbin/mcsnoopd). The fix is to free the old NH(VE NH1) in a common place instead of freeing in multiple places.

Resolved In: evo:22.4R3-S8-EVO evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Phone-Home-Client Infrastructure
1871802
Critical
High memory and CPU usage due to unintended phone-home client activation
Product-Group=junos
On Junos OS Evolved platforms, high memory and CPU usage may occur if the phone-home client (PHC) is unintentionally triggered, such as when the device boots with factory default settings or when phone-home is manually configured. This can lead to system slowness, crashes, and eventual device reboots.

Resolved In: evo:23.4R2-S5-EVO evo:24.2R2-S3-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.2R2-S3 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1868085
Major
The rpd process crashes and asserts are seen due to memory leak
Product-Group=junos
On all Junos and Junos Evolved platforms, rpd process crashes and asserts are seen due to a memory leak when BGP sharding is enabled and 'show route' is performed continuously.

Resolved In: evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1881906
Major
BFD session failure causes LSP to go down and the inactive route remains in the routing table leads to traffic black hole
Product-Group=junos
On Junos OS and Junos OS Evolved platforms, when an RSVP (Resource Reservation Protocol) LSP (Label Switched Path) goes down due to a failure in the associated BFD (Bidirectional Forwarding Detection) session, and the corresponding route remains in the routing/forwarding table causing traffic black-holing. If there are other active LSPs to the same destination, those active routes are preferred over the inactive route associated with the failed LSP.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1899178
Critical
Service session drops are observed when CPU throttling is configured on platforms with service cards installed
Product-Group=junos
On all Junos MX platforms that have MS-MPC or MS-MIC service cards installed, the use of the CPU throttling can cause the production service sessions to be dropped.

Resolved In: junos:21.2R3-S10 junos:21.2R3-S6-J16
1901021
Major
Service-Set Configuration Compression Bug Leading to Kernel Panic on Junos MX
Product-Group=junos
When new rules are added to a service-set, the configuration size increases incrementally. To ensure the configuration is accessible to the receiver, it must be compressed. However, a bug in the compression logic causes failures during this process, which can lead to kernel panic and prevent new configurations from being successfully applied.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: SRX branch platforms
1897579
Minor
Packet drops are observed on SRX380 platforms in packet mode
Product-Group=junos
On Junos OS SRX380 (cluster/standalone) platforms in packet mode, when L2 (Layer 2) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.

Resolved In: junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.

Resolved In: evo:23.4R2-S6-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
Product-Group=junos
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.

Resolved In: evo:23.2R2-S5-EVO evo:24.4R2-EVO evo:25.1R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: VMHOST platforms software
1856565
Minor
High memory consumption in VMhost causes FPC reboot
Product-Group=junos
On all VMhost based platforms, excessive file accumulation in the /var/tmp directory of the host side triggers FPC reboots, resulting in network traffic disruption. This condition occurs when available space falls below 65% (usage exceeds 35%).

Resolved In: junos:22.4R3-S7 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: usf ipsec related issues
1876801
Major
IPsec-inside-IPsec tunnel establishment fails on MX platforms with SPC3 cards
Product-Group=junos
On MX platforms equipped with SPC3 cards, the establishment of the inner IPsec tunnel fails in an IPsec-inside-IPsec tunnel setup. This occurs because the service PIC's forwarding process incorrectly attempts to punt IKE packets to the Route Engine (RE) and cannot resolve the required internal fabric path.

Resolved In: junos:22.4R3-S8 junos:22.4X6 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

Resolved In: evo:25.4R1-EVO junos:25.2R2 junos:25.4R1

 

Modification History

First publication 2025-10-03