Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/Notificationsoftware Release Notification

Product Affected

EX and QFX platforms running JUNOS software

Alert Description

Junos Software Service Release version 23.4R2-S6 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

NOTICE:

Note 1: QFX5000s images having the designation of "... qfx-5e-64-23.4R2-S6.6 ..."  have been recalled due to the following issues:

  • PR1872756 impacting QFX5120-48T
  • PR1918388 impacting QFX5120-48Y

While these issues do not affect other QFX5120 sub-platforms (eg, QFX5120-32C), please discard the 23.4R2-6.6 images.

The new images are available on the download site on 2025-11-26. The image has the designation of "...qfx-5e-23.4R2-S6.10...".

 

Note 2: EX4400 images have been recalled for the following issue.

  • 1827595 - Broadcom SDK update to resolve issue with interface ports not working

Please discard EX4400 images that you have downloaded before November 26, 2025. 

The new images were posted on the download site on November 26, 2025. The replacement software images have the designation of "...ex-x86-64-23.4R2-S6.10..."

 

Important Notice EX4300-48MP:

EX4300-MP 23.4R2-S6 images have been moved to CONTROLLED due to an issue outlined in PR1925358. On EX4300-48MP systems, interfaces may disappear when using the following uplink modules:

  • 2-port QSFP+ / 1-port QSFP28 module

The 4-port dual-mode 10GbE/1GbE module with pluggable SFP+/SFP optics is not affected.

These images will not appear on the standard software download site. To access them, please review this note and use the download links provided below.

LABELDESCRIPTIONDOWNLOAD_URLBLOCKVERSION/RELEASEFILE SIZEMD5
EX4300-MP Serieshttps://webdownload.juniper.net/swdl/dl/secure/site/1/record/189966.htmlInstall Package23.4R2-S615610683826f6c2a1e8fe4904e5bf8624c4fc01ebf
Limited - EX4300-MP Serieshttps://webdownload.juniper.net/swdl/dl/secure/site/1/record/189967.htmlInstall Package23.4R2-S61541546439b587d85bcb4e7d6f4ad35cb3f3f45823

 

Solution

Junos Software service Release version 23.4R2-S6 is now available.

23.4R2-S6 - List of Fixed issues

PR NumberSynopsisCategory: ISSU
1900759
Major
EX4650/QFX5120-48Y: ISSU fails with reason "error Host OS is not compatible; in-service-upgrade cannot continue"
Product-Group=junosvae
Severity=Major
EX4650/QFX5120-48Y: ISSU fails with reason "error Host OS is not compatible; in-service-upgrade cannot continue"
PR NumberSynopsisCategory: EX4300 Mutlicast implementation
1873129
Major
The PTP packets are dropped when IGMP snooping is enabled
Product-Group=junos
Severity=Major
On EX4400, EX4100, QFX5120 and EX4650 platforms running Junos Operation System (OS), when Internet Group Management Protocol (IGMP) snooping is enabled on Virtual Extensible Local Area Network (VXLAN) Virtual Local Area Network (VLAN), all unknown multicast packets will be dropped. As a result, PTP (Precision Time Protocol) packets that use reserved multicast addresses are also discarded affecting the synchronization of the device with the clock server.
PR NumberSynopsisCategory: Junos Node Unifier
1848754
Major
Junos OS: A low-privileged user can disable an interface (CVE-2025-52963)
Product-Group=junos
Severity=Major
An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, leading to a Denial-of-Service. Please refer to https://supportportal.juniper.net/JSA100078 [juniper.net] for more information.
PR NumberSynopsisCategory: "agentd" software daemon
1752412
Critical
gRPC telemetry intermittently miss reporting is_wrap flag
Product-Group=junos
Severity=Critical
On all Junos platforms when telemetry is enabled, gRPC telemetry message contain a metadata flag is_wrap that indicate to the telemetry client that all telemetry data for the specific Xpath is reported for the specific round. This flag may not be reported intermittently in some edge cases.
1873990
Major
EX9208: Syslog message 'JINSIGHTD_SENSOR_RESUBSCRIPTION' every 5 sec
Product-Group=junos
Severity=Major
On EX9200 series switch, syslog message 'JINSIGHTD_SENSOR_RESUBSCRIPTION' is seen every 5 sec
1889924
Major
Data still seems to be streaming somewhere when the DialOut (Established) connection on the port is already closed
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, the existing gRPC-DialOut connection does not disconnect completely on the DUT, causing any other DialOut connections to fail.
PR NumberSynopsisCategory: Border Gateway Protocol
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.
1859020
Minor
Incorrect subcode NOTIFICATION is sent when local interface is disabled for which multihop is configured for directly connected peer
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, when 'multihop' is configured on a directly connected interface towards a peer and the session goes in IDLE state due to no local interface (interface is disabled or down), the log messages shows 'subcode 6 'Other Configuration Change'' instead of 'subcode 9 'Hard Reset''.
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
Severity=Major
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
Severity=Major
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.
1887911
Major
The rpd process crashes after BGP configuration commits involving group-split-size and RIB-sharding
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring "group-split-size" with BGP RIB-sharding(Border Gateway Protocol Routing Information Base Sharding) can lead to a crash in the routing protocol daemon (rpd) when a route update for a non-negotiated NLRI(Network Layer Reachability Information) is received in the update thread. This occurs if the NLRI is targeted at other BGP peers within the group that have negotiated it.
PR NumberSynopsisCategory: Class of Service
1872595
Minor
CoS configured on logical interface does not work on Junos platform when CoS wildcard configurations applied using groups
Product-Group=junos
Severity=Minor
When Class of Service configurations for an Interface Device (IFD) are present both under the wildcard (applied via groups) and as specific configurations (applied directly under the class-of-service hierarchy) on Junos platform, the Interface Device (IFD) correctly takes the specific configurations as expected. However, the Interface Logical (IFL) configurations from the wildcard are not being applied via groups.
PR NumberSynopsisCategory: L2NG Access Security feature
1904091
Critical
During virtual chassis switchover causes dead route creation
Product-Group=junos
Severity=Critical
On all Junos OS EX and QFX platforms in Virtual Chassis (VC) , During switchover, a race condition between the DCD (Device Control Daemon) and DHCPD (Dynamic Host Configuration Protocol Daemon) causes the DCD to delete Interface Address (IFA) objects that were previously configured by DHCPD. This results in the addition of a default dead route in the routing table, leading to services to be impacted.
PR NumberSynopsisCategory: QFX Access Control related
1901304
Major
[ex4000]:: Dot1x client remains in server-fail vlan post radius-reachability timer expiry
Product-Group=junos
Severity=Major
As a best practice dot1x server-timeout should be configured higher than radius-timeout * (retries + 1). Radius reachability feature is supposed to trigger periodic check if server is reachable and if it is then trigger reauth for all the clients in server-fail. There is a corner case which breaks this feature where no action is taken when reachability timer fires. In such scenario client will remain in server-fail unless its reauth timer fires.
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
Severity=Major
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.
PR NumberSynopsisCategory: Configd, ffp issues
1877439
Minor
Traffic drop occurs on Junos Evolved platforms when prefix is moved between dynamic prefix-lists used in firewall filter
Product-Group=junos
Severity=Minor
On all Junos Evolved platforms, when a firewall filter is configured with a dynamic prefix-list that is referenced using an apply-path statement, moving a prefix from one such prefix-list to another where both prefix-lists match the apply-path pattern results in the prefix not being programmed in the PFE. This causes traffic loss for that prefix. The issue is triggered when the configuration includes apply-path pointing to both the source and destination prefix-lists, and a prefix is deleted from one and added to the other through a commit operation.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1882996
Major
xnm-ssl feature fails without loopback interface configuration on Junos Evolved platforms.
Product-Group=junos
Severity=Major
On Junos Evolved platforms, the xnm-ssl feature does not function unless a loopback address (lo0.0) is explicitly configured. The feature is not applicable to Junos (non-EVO) platforms. To ensure proper operation, configure 127.0.0.1/32 on lo0.0.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1848993
Major
The data plane will be out of sync when migrating to EVPN A/A stitching with Vanila VXLAN (PIM Multicast)
Product-Group=junos
Severity=Major
On MX platforms, to improve the convergence of node failures in EVPN MH interconnects with Data Plane VXLAN, migrating to an Active-Active setup may cause the data plane to become out of sync for ARP entries. The gateway learns the MAC address and advertises it to the peer gateway. However, on the peer gateway, some MAC-IP entries may remain stuck in the 'Unresolved' (Ur) state.
PR NumberSynopsisCategory: EX4100 PFE
1901837
Minor
PFE crashes on QFX5K and EX4K platforms in standalone and VC setups due to logging of PFE
Product-Group=junos
Severity=Minor
On Junos QFX5K and EX4K platforms, both in standalone and VC (Virtual Chassis) deployments, the PFE (Packet Forwarding Engine) unexpectedly crashes and restarts due to UKERN_GBL and DDOS packet logging in PFE because of incorrect file access in JUNOS code, resulting in an fxpc crash file being generated.
PR NumberSynopsisCategory: EX interfaces issues
1810482
Major
[Optics] EX4100-48MP : Hot swapping 1G SFPT optics ports are not coming up .
Product-Group=junos
Severity=Major
1G Optics Hot Swapping with 1G SFP-T link may not comeup.
1825281
Major
Random ports of EX4400 will not be created on upgrade or reboot
Product-Group=junos
Severity=Major
On EX4400, random interfaces will not be created when the device is upgraded or rebooted. Interfaces will not be listed in the device and will affect all functionalities of the optic or interface.
PR NumberSynopsisCategory: EX4400 PFE software
1866815
Major
On Junos QFX5000 series and EX4000 series platforms, an fxpc process crash triggers an FPC reboot
Product-Group=junos
Severity=Major
On QFX5000 series and EX4000 series platforms running Junos Operating System (OS), during normal operation, the fxpc process crashes due to a routing entry continues to reference a HOLD next-hop after the associated topology neighbor has already been removed by the system causing the Flexible Physical Interface Card (PIC) Concentrator (FPC) to reboot and generate a crash file.
1893742
Major
FXPC crash on EX4k VC during GRES operation
Product-Group=junos
Severity=Major
On EX4400 and EX4100 VC(Virtual Chassis) environment with filter configuration, FXPC(Flexible Packet Processing Complex) crash occur during GRES(Graceful Routing Engine Switchover) operation. When the issue occur, the impacted FPC will go to offline and come online again.
1894136
Major
Physical Interface device remains down by continuous system reboots on EX and QFX5K platforms
Product-Group=junos
Severity=Major
On Junos EX and QFX5K platforms in a scaled setup having high number of Virtual Chassis members (5 or more VC members) , the physical interface device (IFD) remains down when continuous system reboots are performed (5-6 reboots), thus impacting network availability. This is a rare case scenario.
PR NumberSynopsisCategory: EX4400 platform
1814463
Minor
EX4400: MIST: Wrong PSU state is updating in the mist
Product-Group=junos
Severity=Minor
Unsupported PEM/PSU is shown as online (green)in the MIST Dashboard and the output of "show chassis environment" for that PSU shows the status as present/OK. No functional impact.
PR NumberSynopsisCategory: EX optics issues
1858986
Major
EX4400: Error message 'Failed to read eeprom' intermittently on SFP-T
Product-Group=junos
Severity=Major
On EX4400, error message 'Failed to read eeprom' is seen intermittently on SFP-T.
1890164
Major
On some EX or QFX platforms, 25G interfaces remain down with a default FEC(Forward Error Correction) 74 value when peer device has default FEC as None
Product-Group=junos
Severity=Major
When establish a physical connection between EX4650/QFX5120-48Y and EX4100/EX4400 using 10G/25G dual-rate SFP28 LR /SR optics over the 4x25G uplink ports, 25G interfaces remain down with a default FEC 74 value instead of FEC None when peer device has default FEC as None for this 25G LR /SR optics.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1884163
Major
IFL Memory Leak on QFX10K8/16 device
Product-Group=junos
Severity=Major
On QFX10K8/16 , IFL memory is not freed on non-local interface of FPC during configuration changes (eg: IFL delete/deactivate) for L3IFL/L2IFL on AE/Scalar interfaces. Fix is present in common code and risky. It is a day one issue and the per IFL leak is minimal (0.00016% of total Kernel heap size) .
PR NumberSynopsisCategory: ISIS routing protocol
1847557
Critical
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.
1859099
Minor
Memory leak is observed for certain topologies when TI-LFA is configured
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms , where IS-IS/OSPF is enabled and TI-LFA (post-convergence-lfa) is configured in a SR (Segment Routing) environment. In a scenario where the computed backup paths to reach a destination is fetched from the more than one originator, duplicate paths gets computed for certain topology combinations and the clean-up of infosid list doesn't happen this leads to memory leak that might eventually lead to high memory usage and result in rpd crash and thus impacting traffic.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1895790
Major
Backup node stuck in cold sync failure after all FPCs reset due to SPC crash files in SRX chassis cluster
Product-Group=junos
Severity=Major
On all SRX platforms, in a chassis cluster scenario, the SPCs on the backup node crash. After the crash files are fully generated, this triggers a reset of all FPCs. Following the crash and FPC resets, the backup node enters a cold sync failure state and remains in that state until it is manually rebooted.
PR NumberSynopsisCategory: Platform infra to support jvision
1837761
Major
Missing telemetry data for FRUs when subscribed to /components/component
Product-Group=junos
Severity=Major
On all Junos platforms, the/components/component/state/mfg-name leaf is not being streamed for any FRUs, such as RE, CB, FPC, FT, and PEM, when subscribed to /components/component via on-change and periodic mode of subscription.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
1895433
Minor
The enable-pxe-boot is not working as expected on specific EX or QFX platforms with Easy EVPN LAG single home server topology
Product-Group=junos
Severity=Minor
The enable-pxe-boot option does not work as expected for Easy EVPN LAG (Ethernet Virtual Private Network Link Aggregation Group) single home server topology configuration on specific EX or QFX platforms. The enable-pxe-boot configuration knob does not generate the "force-up" configuration. Consequently, the physical link remains down until "force-up" is manually added on physical child interface. It causes LACP (Link Aggregation Control Protocol) to go down when singled homed server is added with LACP.
1909786
Critical
Selection of VGA-IP as source IP for RE-ARP packet causes incorrect ARP updation of VGA-IP getting bound with IRB-MAC at end-hosts
Product-Group=junos
Severity=Critical
Selection of VGA-IP as source IP for RE-ARP packet causes incorrect ARP updation of VGA-IP getting bound with IRB-MAC at end-hosts
PR NumberSynopsisCategory: Label Distribution Protocol
1789663
Major
Unexpected rpd restart when LDP and RSVP are configured for telemetry streaming data
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms with LDP (Label Distribution Protocol) and RSVP (Resource Reservation Protocol) for traffic engenierring (TE) configured, whenever there is a state getting changes (e.g., ldp session deleted) will cause rpd to restart causing service impact.
PR NumberSynopsisCategory: authd (AAA) library code
1860913
Major
The authd process crashes when /etc/resolv.conf file is empty
Product-Group=junos
Severity=Major
On Junos OS Evolved ACX platforms, when DHCP (Dynamic Host Control Protocol) local server is configured without domain-name specified, the authd process crash may be observed. There will be no forwarding traffic impact due this issue, however, new DHCP client requests will not be answered.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when RSVP-TE (Resource Reservation Protocol - Traffic Engineering) is configured with MBB (make-before-break) setup, if the protected link of the primary LSP (Label Switched Path) goes down and if "clear mpls lsp" or "clear rsvp session" commands are executed, then LSP switches to new instance from the old which will be on higher IGP (Interior Gateway Protocol) metric. However, after re-optimization, LSP will not get switched to better IGP metric path and remain in old instance. Traffic drop can be seen due to this double fault events.
1878360
Minor
memory leak in lsp_regex_cache_entry block (lsp_regex_cache_entry_add)
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, when configured with RSVP (Resource Reservation Protocol) LSPs (label-switched path) and when MPLS (Multi-Protocol Label Switching) protocol activate/deactivate is performed, the rpd memory leak is observed. There is no service impact due to this issue.
PR NumberSynopsisCategory: Multicast Routing
1863470
Major
The rpd crash due to memory corruption in PIM/MSDP network
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, enabling PIM (Protocol Independent Multicast) or MSDP (Multicast Source Discovery Protocol) may cause a rare memory corruption during the update of the MSDP Source Active route. This issue primarily affects highly scaled environments, leading to rpd (routing protocol daemon) coredumps and potential traffic loss.
1876458
Major
MX960 mcsnoopd core dump during rt_mcnh_nh_release
Product-Group=junos
Severity=Major
When the mcsnoopd process (use for L2 multicast) creating a new NH , our system takes a reference to it. However, if this reference is released too quickly, the old NH might be deleted before its references are fully cleared. This may cause the mcsnoopd process to restart.
PR NumberSynopsisCategory: Multicast for L3VPNs
1747703
Major
The MVPN traffic starts dropping after RE switchover
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Dual RE and MVPN ((Multicast Virtual Private Network) enabled, when the user initiates a GRES ( Graceful Routing Engine Switchover) switchover, it triggers a route change from the MVPN . During this process, there's a gap where traffic loss is observed because the flood next hop pointed to by the route gets deleted.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1874365
Minor
Route for disabled fxp0 interface remains in PFE after re-enabling the interface
Product-Group=junos
Severity=Minor
On Junos platforms, when the fxp0 management interface is configured with an IP address and then disabled, a user route with a reject next-hop is created and installed in the PFE. After re-enabling the interface, this reject route is removed from the forwarding table but remains in the PFE. Rebooting the Routing Engine clears the stale route
1881956
Major
IPv6 default route gets deleted from FIB by slaac daemon after an upgrade with an unsupported configuration
Product-Group=junos
Severity=Major
On all Junos OS platforms , deletion of IPv6 default route from FIB (Forward Information Base) by slaacd (Stateless Address AutoConfiguration Daemon ) is observed while recovering the device from amnesiac state after the OS upgrade with any unsupported or incompatible configuration.
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1872704
Major
NTS for NTP not working even after the Ceritficate is validated with External servers like Chrony and NTPSec
Product-Group=junos
Severity=Major
NTS for NTP not working even after the Ceritficate is validated with External servers like Chrony and NTPSec
PR NumberSynopsisCategory: TCP/UDP transport layer
1864027
Minor
TCP listening sockets are not displayed correctly
Product-Group=junos
Severity=Minor
On Junos OS platforms, TCP (Transmission Control Protocol) listening sockets may be absent from command outputs due to NULL values in netstat application.
PR NumberSynopsisCategory: OSPF routing protocol
1827435
Major
OSPF LSA flooding is impacted after database recovers from 'ignore' state when 'database-protection' is triggered
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when the LSA (Link State Advertisement) count exceeds the maximum number configured under 'database-protection' feature in OSPFV2 (Open Shortest Path First Version 2), the OSPF database (DB) enters into 'ignore' state. When the DB is recovered, OSPF LSA flooding is stopped on some interfaces.
PR NumberSynopsisCategory: Express Chip L3 software
1865171
Critical
FPC crashes if the BGP protocol next-hop gets resolved over a discard logical interface (dsc.0)
Product-Group=junos
Severity=Critical
On Junos OS PTX and QFX10k platforms, FPC crashes and reboot is seen due to the corruption of the data structures associated with dsc.0 (Discard Interface).
1877538
Major
Multicast traffic loss is seen when MVPN with node protection is enabled
Product-Group=junos
Severity=Major
On Junos PTX and QFX10K platforms with node protection enabled on a Multicast Virtual Private Network (MVPN) scenario, multicast traffic loss will be seen when the number of child links in an aggregated ethernet (AE) interface for bypass Label Switched Path (LSP) egress interface is higher than primary LSP and one of the child links goes down on primary LSP egress interface.
PR NumberSynopsisCategory: Protocol Independant Multicast
1857699
Major
Native_Multicast:: : Protocol PIM Interface disable command not working
Product-Group=junos
Severity=Major
Disabling the PIM interface underneath the [edit protocols pim interfaces ] hierarchy may still show PIM as still being UP instead of DOWN.
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.
PR NumberSynopsisCategory: Issues related to PKI daemon
1892297
Major
The pkid crash is observed during enrolment of device's local certificate through SCEP
Product-Group=junos
Severity=Major
On Junos OS platforms that use the pki service (public key Infrastructure) for device's local certificate enrolment via SCEP (Simple Certificate Enrolment Protocol), the pki daemon crashes during the enrolment process due to the user misconfiguration in CA (Certificate Authority) profile, specifically the key-usage of the CA certificate for the CA profile lacks the certificate-signing, resulting in impact to services relying on certificate verification.
PR NumberSynopsisCategory: QFX access control list
1863813
Minor
On particular QFX and EX devices firewall filter counters display double the actual packet count
Product-Group=junos
Severity=Minor
When Filter-Based Forwarding (FBF) or Policy-Based Routing (PBR) is configured with firewall filter counters on platforms QFX5120, EX4650, EX4100, EX4400, the CLI output for FBF/PBR filter statistics shows double the actual packet count, there is no workaround for this issue.
PR NumberSynopsisCategory: QFX L2 PFE
1885220
Minor
Unable to learn the MAC address on a switch interface when using "interface-mac-limit" command
Product-Group=junosvae
Severity=Minor
On all Junos QFX 5k platform, unable to learn the MAC address on a switch interface when using "interface-mac-limit" command.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1886612
Major
Next-hop entries are not getting programmed in ECMP unilist group after device upgrade
Product-Group=junos
Severity=Major
On Junos OS QFX5k and EX4k platforms, when static ECMP (Equal-Cost Multi-Path) is configured, traffic loss will be observed due to a next-hop programming issue. The device fails to install the next-hop entries in hardware for static ECMP routes, resulting in traffic not being forwarded as expected after a device upgrade.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1878555
Major
Transit unicast ARP requests are dropped instead of being forwarded
Product-Group=junos
Severity=Major
On Junos QFX5K and EX46xx platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) environment, when "no-arp-trap" is enabled, transit unicast Address Resolution Protocol (ARP) packets that are not destined for the local switch Integrated Routing and Bridging Media Access Control (IRB MAC) are dropped instead of being forwarded across the leaf nodes.
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
Severity=Major
On Junos QFX5k and EX4k platforms, if VPLAG(Virtual Private Link Aggregation group) is configured and if there is event change which could make ECMP(Equal Cost Monitoring Protocol) programming to change like ECMP link flap, dcpfe restart, system reboot etc which causes traffic loss.
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1845045
Major
On QFX5120-48YM port remains down when speed shifts from 1G to 10G
Product-Group=junos
Severity=Major
On QFX5120-48YM, if a port is transitioned directly from 1G to 10G either by swapping the SFP or by changing port and chassis speed settings without intermediate reset. The 10G link will remain down.
1890867
Major
QFX5120 - SFP+ Modules disappear/down post upgrade
Product-Group=junos
Severity=Major
On QFX5120-48T platforms, QSA-SFP+ adapter(100G/40G ) modules disappear/go down after software upgrade. Due to unsupported QSA usage in the impacted release, which will trigger a dcpfe (Dataplane Packet Forwarding Engine) crash.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1882472
Major
JMA package fails to initialise after a power cycle on EX4650/QFX-5E series devices
Product-Group=junos
Severity=Major
On Junos EX4650/QFX-5E series, after installing the JMA(Junos Mist Agent) package, a graceful reboot (using request system reboot or request system halt) is required to commit the changes. An abrupt power cycle before a graceful reboot causes the system to lose the installed JMA package.
1902869
Critical
Significant system slowness is observed post software upgrade on QFX5120-48YM
Product-Group=junosvae
Severity=Critical
On QFX5120-48YM devices, after performing a software upgrade to versions containing the fix for PR1882472, users may observe significant system slowness immediately following the first boot. This slowness manifests as degraded performance across multiple system parameters, including increased reboot time, slower interface initialization, and longer service restoration periods.
PR NumberSynopsisCategory: Category for QFX5K EVO Platform Software PRs related to Inte
1853302
Major
QFX5240: "set interfaces interface-range et-all member et-0/0/*" config is not supported.
Product-Group=junos
Severity=Major
On QFX5240 "set interfaces interface-range et-all member et-0/0/*" config is not supported.
PR NumberSynopsisCategory: RPD Interfaces related issues
1842546
Major
Memory leak is detected when interfaces are configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, 72-byte size memory leak is seen when interface configuration is added. But there is no traffic impact due to this issue.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1848971
Major
Configuring BGP rib-sharding and generate route will cause rpd process to crash
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring BGP (Border Gateway Protocol) rib-sharding and generate routes will cause the rpd process to crash.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1815837
Minor
Configure low file size in traceoptions while logging volume is high will lead to high CPU and RPD scheduler slips causing operational impact
Product-Group=junos
Severity=Minor
If the file size is too small and the amount of traceoptions volume is too high it can cause scheduler slips and operational impact.
PR NumberSynopsisCategory: Resource Reservation Protocol
1881906
Major
BFD session failure causes LSP to go down and the inactive route remains in the routing table leads to traffic black hole
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms, when an RSVP (Resource Reservation Protocol) LSP (Label Switched Path) goes down due to a failure in the associated BFD (Bidirectional Forwarding Detection) session, and the corresponding route remains in the routing/forwarding table causing traffic black-holing. If there are other active LSPs to the same destination, those active routes are preferred over the inactive route associated with the failed LSP.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1817865
Minor
The "snmp packet-size " command not working for SNMPv3
Product-Group=junos
Severity=Minor
If the "snmp packet-size " is configured on Junos and Junos Evolved platforms. , the responded SNMPv3 packet could be of larger size causing more fragmentation and packet overhead for SNMP traffic.
PR NumberSynopsisCategory: SRX branch platforms
1877428
Major
Stale user session displayed in "show system users" after ssh session disconnected.
Product-Group=junos
Severity=Major
On all platforms running FreeBSD6, such as the SRX3xx or QFX5100 series, once an SSH session is disconnected, the stale user entry may still be displayed in "show system users" or still counted in hrSystemNumUsers OID.
1893957
Minor
SRX Cluster Loaded with McD Configuration Experienced DHCP Assignment Failures and ARP Resolution Issues to the Default Gateway
Product-Group=junos
Severity=Minor
In SRX clusters configured with the McD template, connected devices obtain DHCP IP addresses but fail to resolve ARP for the default gateway. ARP replies are sent by the SRX but do not reach the connected devices, with corresponding packet discards observed in the Packet Forwarding Engine (PFE).
1895179
Major
The kern.maxfiles limit exceeded observed due to log rotation resulting in unresponsive SSH
Product-Group=junos
Severity=Major
On all Junos OS platforms, Configuring multiple syslog servers causes duplicate routing-instance map entries, leading to an eventd file descriptor leak during log rotations. Once the threshold is exceeded, the SSH connection becomes unresponsive.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1870522
Minor
STP/RSTP/MSTP/VSTP enters a disputed and blocked state when the anchor FPC of an AE link, with members distributed across multiple FPCs, goes offline
Product-Group=junos
Severity=Minor
On MX and EX9200 series platforms that operate in hyper mode by default, STP (Spanning Tree Protocol)/RSTP (Rapid Spanning Tree Protocol)/MSTP (Multiple Spanning Tree Protocol)/VSTP (VLAN Spanning Tree Protocol) transitions to a disputed and blocked state if the members of the AE (Aggregated Ethernet) link in the anchor FPC (Flexible PIC Concentrator) goes offline.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.
PR NumberSynopsisCategory: Configuration management, ffp, load action
1854461
Major
Configured TFTP server connection and rate limits are not applied
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms configured as Trivial File Transfer Protocol (TFTP) server , "connection-limit" or "rate-limit" values are not updated as per configured values.
PR NumberSynopsisCategory: Ephemeral Database
1839322
Major
The commit-syncd configuration generates commit-syncd cores observed at vlogging_event
Product-Group=junos
Severity=Major
On EX-series platforms running Junos Operatin System (OS), configured as a Virtual Chassis (VC) with an ephemeral database (DB) and commit sync enabled, executing the commit-syncd process creates a configuration file that is reused for commits on other VC members. In the problematic scenario, the configuration file is missing during the second iteration, leading to a commit-syncd core without impacting the device.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1872820
Major
The dcd process crashes when deactivating only 'swap' under ' interfaces <> unit <> output-vlan-map' with no other attributes present
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, this issue affects configurations where Virtual Local Area Network (VLAN) mapping is used, particularly in scenarios where only the swap attribute is applied under 'interfaces <> unit <> output-vlan-map'. Sequence of 'Deactivate -> Activate -> Commit' of the config hieararchy leads to crash of the device control daemon (dcd) process, potentially causing service disruption.
1873253
Major
The "show system storage" command output should show only true and distinct storages
Product-Group=junos
Severity=Major
On all Junos platforms, the "show system storage" command output is modified to list only all real UFS filesystem ie { 'ffs', 'tmpfs', 'ufs' } instead of virtual filesystem like '/var/jails/rest-api'.
1878430
Major
The mgd process crash is seen on all Junos and Junos Evolved platforms when FQDN is configured along with ephemeral database
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, Fully Qualified Domain Name(FQDN) configured in static database in presence of ephemeral database instances results in the mgd process crash. As a result, mgd session gets terminated and commit fails. There is no traffic impact due to this issue. The issue is seen with FQDNs that resolve to multiple IP addresses.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1853209
Major
Syslog forwarding intermittently stops post DUT reboot on virtual devices.
Product-Group=junos
Severity=Major
On virtual devices, on reboot, vpn may take time to come up. Meanwhile since mgmt_junos is first in the routing table, syslog gets bound to mgmt_junos and hence forwarding stops.

 


 

23.4R2-S6 - List of Known issues

PR NumberSynopsisCategory: ISSU
1898501
Major
EX4650/QFX5120-48Y: ISSU incompatibility with previous releases
Product-Group=junosvae
EX4650/QFX5120-48Y: Older releases (that do not contain the 1882472 fix) are ISSU incompatible with current releases that have 1882472 fix.

Resolved In:
PR NumberSynopsisCategory: Accounting Profile
1692411
Minor
Error messages are observed and incorrect values are returned for SNMP requests for pfe traffic statistics
Product-Group=junos
Below log messages will be seen while using SNMP and trying to poll "show pfe statistics notification" through MIB OID - 1.3.6.1.4.1.2636.3.44.1.1.2.1.2. "pfed: PFED_NOTIF_GLOBAL_STAT_UNKNOWN: xxxx"

Resolved In: evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.3R3-S5 junos:22.1R3-S3 junos:22.2R3-S3 junos:22.4R2-S2 junos:22.4R3 junos:22.4R3-S7 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: "agentd" software daemon
1805445
Major
Return Error for unsupported options with GNMI RPCs
Product-Group=junos
On Junos and Junos OS Evolved platforms, the error message returned with unsupported encoding is changed for gnmi RPCs. It has no traffic impact.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.3X60 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.1R1
1839478
Major
/junos/system/linecard/interface/traffic/ sensor is seeing packet drops but there is no actual drops
Product-Group=junos
On all MX devices with ULC line cards (MPC10/11 and LC4800/9600), when subscribing to the /junos/system/linecard/interface/traffic/ native telemetry subscription path, the exported data includes the following containers: /interfaces/interface//interfaces/interface/state//interfaces/interfaces/state/counters. The picd and evo-aftmand-bt daemons are responsible for exporting data for these paths. When running the CLI command "show network-agent statistics detail, " it shows packet and byte statistics for each sensor per daemon. The picd daemon reports some drops due to an error in the CLI's data reporting. However, no actual packet drops occur. The issue arises from a bug in the bookkeeping code that tracks packet statistics, causing the CLI to incorrectly show drops even when no packets have been lost. This issue only affects the CLI display and does not impact actual packet transmission.

Resolved In: evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.2R2 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Border Gateway Protocol
1854194
Major
Handling cores when always-compare-med is configured in BGP path selection
Product-Group=junos
When using rib-groups, which copy inet.3 routes to inet.0 and inet6.3, configuring path-selection always-compare-med triggers a local RIB evaluation that will miss inet6.3 because inet6.3 tables are not initialized as a BGP RIB. As a result, Inet6.3 routes will not get updated.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7-J1 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D49-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:20.3X75-D52 junos:22.3X60 junos:23.2R2-S5 junos:25.2R1
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:23.4X100-D40-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP-LU (Border Gateway Protocol-Labeled Unicast) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.

Resolved In: evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-J6 junos:24.2R2-S1-J4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned from a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB(Segment Routing Label Block), this mismatch can result in incorrect label forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1889749
Major
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.

Resolved In: evo:24.2R2-S3-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.2R3-S8-J22 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.

Resolved In: evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R1-S2-J10 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Firewall Filter
1903874
Minor
[MX10008] cmd='ls -i /var/etc/filters/filter-define.conf' is logged every 1 second instead of every 30 seconds
Product-Group=junos
Root-Cause Client session not cleanedup on switching to backup router which was previously master and had clients connected on it. This left over session causes -ve timer t/o which treats it like expired clients and take immediate action w/o waiting for 30sec. below logs will be seen per second >show log messages | match filter-define | last 20 Aug 19 17:18:32.151 2025 root@re1 as root: cmd='ls -i /var/etc/filters/filter-define.conf' Aug 19 17:18:33.211 2025 rshd[52966]: root@re1 as root: cmd='ls -i /var/etc/filters/filter-define.conf' Aug 19 17:18:34.298 2025 rshd[52970]: root@re1 as root: cmd='ls -i /var/etc/filters/filter-define.conf' Aug 19 17:18:35.351 2025 rshd[52974]: root@re1 as root: cmd='ls -i /var/etc/filters/filter-define.conf' Aug 19 17:18:36.402 2025 rshd[52979]: root@re1 as root: cmd='ls -i /var/etc/filters/filter-define.conf' Impact No functional impact, only the lookup of masters data happens per second instead of 30 sec

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: EVPN ELAN/E-TREE
1882561
Minor
EVPN-MPLS BUM Traffic Disruption Due to Incorrect QinQ STag Insertion
Product-Group=junos
On Junos OS ACX5448/ACX710 platforms, the traffic towards the MPLS (Multiprotocol Label Switching) core Provider Edge (PE), specifically BUM (Broadcast, Unknown Unicast, and Multicast) traffic, has a QinQ (802.1ad) Service Tag (STag) added to the Customer (CTag). This insertion can disrupt traffic forwarding, leading to malformed packets or corruption of the destination MAC address in the inner Ethernet header.

Resolved In: junos:24.4R2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
1846266
Major
The inet filters attached to the IRB interface will not function as expected
Product-Group=junos
On Junos QFX5k and EX4k platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, inet filters applied to Integrated Routing and Bridging (IRB) interfaces will not function as expected, and the associated actions of the filter are not enforced.

Resolved In: junos:24.4R1-S1 junos:24.4R1-S3 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.2R1-S1
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:25.2R2 junos:25.3R1
1901044
Major
EVPN ETREE BUM traffic is not forwarded after restart routing immediately
Product-Group=junos
EVPN ETREE BUM traffic is not forwarded after restart routing immediately

Resolved In:
PR NumberSynopsisCategory: EX4000 PFE issues
1847159
Major
Reachability issues are seen on interfaces that are aggregated without address-family
Product-Group=junos
On Junos platforms, specifically on EX and QFX series aggregated interfaces configured without address-family results in reachability issues.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S7 junos:24.2R2-S3 junos:24.4R1 junos:24.4R1-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: EX optics issues
1887303
Major
[EX4400-48F] One of the 10gBase-T transceiver is not detected - showing as "Partial" Unknown in PFE
Product-Group=junos
In the EX4400-48F systems, a 10G-BaseT transceiver that was earlier up may not come up post a reboot/image upgrade event; The transceiver may go undetected causing the interface to not be created in the system.

Resolved In:
PR NumberSynopsisCategory: Interface Information Display
1741282
Major
JUNOS MX | iflset stats not getting cleared after issuing clear interfaces stats all and clear interfaces interface-set statistics all CLI command
Product-Group=junos
JUNOS MX | iflset stats not getting cleared after issuing clear interfaces stats all and clear interfaces interface-set statistics all CLI command

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO junos:24.2R2-S1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1861810
Major
The process rpd is cored while adding or removing dynamic-tunnels
Product-Group=junos
On all Junos Evolved platforms, the indexing of next hop while adding or deleting dynamic tunnels causes the rpd process to core and restart. This is a timing issue.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S1-J8-EVO evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S5 junos:24.2R2-S2 junos:24.2R2-S4 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1871420
Major
Fragmented packets dropped in EVPN-MPLS scenario due to the IRB interface MTU limitation
Product-Group=junos
On all Junos platforms running in EVPN-MPLS (Ethernet Virtual Private Network over Multiprotocol Label Switching) scenarios, host-generated packets exceeding the IRB interface MTU (Maximum Transmission Unit) are fragmented. Only the first fragment is forwarded, while remaining fragments are dropped, leading to loss of control-plane traffic.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: ISIS routing protocol
1841108
Major
Traffic drop is seen after GRES on ISIS peer
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in an ISIS(Intermediate System-Intermediate System) graceful restart scenario, helper node sends and programs its locally configured hold-time (180 secs) instead of the "Restart-duration" received as hold-time from DUT (210 secs), due to this incorrect update, the hold timer expires at the helper node before the GR (Graceful Restart) is complete on DUT and it causes a flap of ISIS adjacency on peer/helper Node.

Resolved In: evo:21.4R3-S10-EVO evo:22.3X80-D47-EVO evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S6 junos:23.2R2-S4 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1892944
Minor
EX4300 VC L2ALD core after upgrade from 21.4R3-S3.4 to latest 21.4R3-S6 and above versions
Product-Group=junos
On EX4300 switch running Junos version 21.4R3-S6 and above, when SNMP polling is done for oid 1.3.6.1.2.1.17.7.1.4.5.1 with redundant-trunk-group interfaces configured there will be L2ALD memory leak seen on the switch. It can be verified using command: show ethernet-switching debug-statistics memory | match l2ald_mib_dot1dTp_lookup ---(refreshed at 2025-09-03 20:28:30 IST)--- Allocated Allocated Allocated Memory (current) (total) (freed) (owner) 6532 450708 444176 [l2ald_mib_dot1dTp_lookup (0x1bd9f60)] ---(refreshed at 2025-09-03 20:28:35 IST)--- Allocated Allocated Allocated Memory (current) (total) (freed) (owner) 6856 473064 466208 [l2ald_mib_dot1dTp_lookup (0x1bd9f60)] ---(refreshed at 2025-09-03 20:28:40 IST)--- Allocated Allocated Allocated Memory (current) (total) (freed) (owner) 7280 502320 495040 [l2ald_mib_dot1dTp_lookup (0x1bd9f60)]

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.3R1 junos:25.4R1
1905196
Minor
Stale entry in MAC-IP table affects ARP resolution
Product-Group=junos
On all Junos OS platforms, when an IP address already exists in the MAC-IP table as a remote entry and then an IRB (Integrated Routing and Bridging) interface is configured with the same IP address but a different MAC address, then the L2ALD (Layer 2 Address Learning Daemon) does not handle the update correctly, leading to incorrect ARP (Address Resolution Protocol) resolution.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1873587
Minor
[MX] "smid ../../../../../../src/junos/ lib/libsdb/licsubs/ bsd12/liblicense_subs_os.c liblic_subs_total_active_licenses_in_use XXX" logs flood in license_flex_subs_trace.log.
Product-Group=junos
"smid ../../../../../../src/junos/lib/ libsdb/licsubs/bsd12/liblicense_subs_os.c liblic_subs_total_active_licenses_in_use XXX" messages can be seen so frequent interval in license_flex_subs_trace.log.

Resolved In: junos:24.2R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
em0 mgmt port is unreachable after RE switchover
Product-Group=junos
On MX10008 with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1876690
Major
ntp process may restart when issue the "show system ntp threshold" command
Product-Group=junos
The ntp (or xntpd) process is initialized when the "show system ntp threshold" command is issued. This has no impact to system operation.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1790234
Major
JUNOS_REG: QFX5210: dcpfe core seen at __kernel_vsyscall, tvp_watchdog, dcbcm_driver_read32, soc_dcbcm_ipoll_check, cpu_sched_update_timers
Product-Group=junos
QFX5210: dcpfe core seen at __kernel_vsyscall, tvp_watchdog, dcbcm_driver_read32, soc_dcbcm_ipoll_check, cpu_sched_update_timers

Resolved In:
PR NumberSynopsisCategory: RPD Interfaces related issues
1741485
Major
Unnecessary rsync messages causing issues
Product-Group=junos


Resolved In: evo:24.1R1-EVO junos:24.1R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1868085
Major
The rpd process crashes and asserts are seen due to memory leak
Product-Group=junos
On all Junos and Junos Evolved platforms, rpd process crashes and asserts are seen due to a memory leak when BGP sharding is enabled and 'show route' is performed continuously.

Resolved In: evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
1868487
Major
The rpd process crashes during ISSU or switchover on all Junos SRX platforms
Product-Group=junos
On all SRX platforms, routing protocol daemon (RPD) process crash core is caused a result of error generated from kernel during switchover or ISSU (In-Service Software Upgrade) or cluster set-up. As a result of the core, the control plane gets freezed causing traffic to drop.

Resolved In: evo:24.4R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:25.3R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1851629
Minor
Next-hop APIs to support LDP stitching cases over BGP routes pointing to list of indirects
Product-Group=junos
On all Junos and Junos Evolved platforms this is an enhancement for Nexthop APIs to support LDP stitching cases over BGP routes pointing to list of indirects next-hops.

Resolved In: evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.2R2
PR NumberSynopsisCategory: RPD policy options
1887006
Minor
Deleting duplicate entries in a route-filter-list or source-filter-list can disrupt policy evaluation, leading to route withdrawal and traffic disruption for services using the filter-list
Product-Group=junos
On all Junos and Junos OS Evolved platforms, deleting one of multiple duplicate entries in a route-filter-list or source-filter-list can cause the remaining entry to be ignored. This leads to incorrect policy application for any service using that filter-list, resulting in route withdrawal, traffic loss, or other service disruptions.

Resolved In: evo:22.3X80-D49-EVO evo:25.4R1-EVO junos:25.4R1
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1757389
Minor
"show route detail" shows "State: " for routes when route-record is enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms with route-record enabled, some routes will be seen in State: due to race condition. There is no functionality issue, this is a display issue.

Resolved In: evo:22.4R3-EVO evo:22.4R3-S1-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:24.1R1-EVO evo:24.4R2-EVO junos:23.2R1-S2 junos:23.2R2-J14 junos:23.4R1-S1 junos:24.1R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1792192
Major
Missing HELLO object in RSVP Hello messages after RE failovers in the NSR mode
Product-Group=junos
In rare unknown condition after RE switchover, rsvp hello can have local instance to be zero due to wrong information synced from master RE by mirroring process. When rsvp neighbor is created and never received hello exchange with neighbor, the replication entry which is synced to standby RE will have most of the information as zero, including the local instance, which is used to generate hello object. After RE switchover, rsvp hello will have local instance to be zero due to the wrong information synced from master RE by mirroring process. This is addressed by update the replication entry once all the parameters of the rsvp neighbor is filled, so standby RE will receive the right info, also for future protection, backup RE will avoid creating neighbor until after switchover and setting a new local instance if it is zero.

Resolved In: evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:23.2R2-S4 junos:24.4R2 junos:25.2R1 junos:25.3R1
1881609
Minor
RSVP hello messages uses secondary address when primary/preferred address are present for same interface
Product-Group=junos
On all Junos and Junos OS Evolved platforms where RSVP (Resource Reservation Protocol) configuration is present and a RSVP enabled interface has 2 IP address of which one is configured as primary/preferred in that case the RSVP Hello message uses the secondary IP address to form neighborship.

Resolved In: evo:25.3R1-EVO junos:25.3R1
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated

Resolved In: evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1896022
Major
More bandwidth may be admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
If Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.

Resolved In: evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1874097
Minor
Telemetry is not reporting statistics for an IRB interfaces
Product-Group=junos
On Junos OS Evolved and MX platforms with MPC10E/MPC11E/LC9600 line cards, MX304 and EX9k with EX9200-15C line cards , telemetry is not reporting statistics for the IRB (Integrated Routing and Bridging) interfaces, even though they are up and running.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J15 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1891110
Major
A GRE tunnel configured with a tunnel key drops MPLS-encapsulated traffic
Product-Group=junos
On MX platforms with line cards MPC1-9, a Generic Routing Encapsulation (GRE) tunnel configured with a tunnel key drops Multi-Protocol Label Switching (MPLS) encapsulated traffic as it is unable to find the key.

Resolved In: junos:23.2R2-S5 junos:24.2R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Major
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
1818692
Major
Configuration commit fails due to mustd process crash
Product-Group=junos
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP

Resolved In: evo:21.4R3-S9-EVO evo:22.2R3-S6-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:23.4X100-D21-EVO evo:23.4X100-D30-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.2X32-D30 junos:21.2X33 junos:21.2X35 junos:21.2X40 junos:21.2X9 junos:21.4R3-S9 junos:21.4X30 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.3X60 junos:22.4R3-S5 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S3 junos:23.4X30-D30 junos:24.2R1-S1 junos:24.2R2 junos:24.2X1 junos:24.4R1
1845657
Major
Baseline configuration commit takes more time with 256000 MAC configurations
Product-Group=junos
On all Junos and Junos OS Evolved platforms with dual RE (Routing Engine), the baseline configuration commit takes more time when the device has 256000 MAC (Media Access Control) configurations configured under groups. It is a scaling issue, and occurs when a large number (256000 or more) of MAC configurations are configured. This has no impact to network traffic.

Resolved In: evo:24.4R1-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R1-S2 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1593200
Critical
Junos OS: A low privileged user can elevate their privileges to the ones of the highest privileged J-Web user logged in
Product-Group=junos
A Generation of Error Message Containing Sensitive Information vulnerability in the CLI of Juniper Networks Junos OS allows a locally authenticated attacker with low privileges to elevate these to the level of any other user logged in via J-Web at this time, potential leading to a full compromise of the device. Refer to https://kb.juniper.net/JSA11270 [juniper.net] for more information.

Resolved In: evo:21.1R2-S1-EVO evo:21.2R1-S2-EVO evo:21.2R2-EVO evo:21.2R3-EVO evo:21.3R1-EVO evo:21.3R2-EVO evo:21.4R1-EVO junos:15.1R7-S11 junos:18.3R3-S6 junos:18.4R2-S9 junos:18.4R3-S10 junos:19.1R2-S3 junos:19.1R3-S7 junos:19.2R1-S8 junos:19.2R3-S4 junos:19.3R3-S4 junos:19.4R3-S6 junos:20.1R3-S2 junos:20.2R3-S3 junos:20.3R3-S1 junos:20.3X75-D442 junos:20.4R3-S1 junos:21.1R2-S1 junos:21.1R3 junos:21.2R1-S1 junos:21.2R2 junos:21.2R3 junos:21.3R1 junos:21.3R2 junos:21.4R1 junos:22.3X60 junos:24.4R1-S3
1818319
Minor
Clear ephemeral DBs on reboot/power cycle irrespective of platform/optimizations.
Product-Group=junos
Ephemeral databases were incorrectly persisting across system reboots on certain platforms (Emerald/EX4100-F-12T:EX4100-H-12MP) where boot time optimization is enabled. This behavior violated the ephemeral database design principle and could lead to undefined system behavior.

Resolved In: junos:22.4R3-S7 junos:23.4R2-S5 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Issues related to NETCONF
1800859
Minor
Configuration push to device using RPC resulted in incorrect policy order
Product-Group=junos
On all Junos and Junos OS Evolved platforms, RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.

Resolved In: evo:21.4R3-S9-EVO evo:22.2R3-S7-EVO evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:22.4R0-J0-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R1-S1-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.2X32-D30 junos:21.2X33 junos:21.2X35 junos:21.2X40 junos:21.2X9 junos:21.4R3-S9 junos:22.2R3-S7 junos:22.3X60 junos:22.4R3-S5 junos:22.4R3-S7 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S3 junos:23.4X30-D30 junos:24.2R1-S1 junos:24.2R2 junos:24.2X1 junos:24.3R1 junos:25.1R1
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: PTX/QFX10002/8/16 specific software components
1882584
Minor
SERDES link errors observed on SIB8 modules due to power rail instability
Product-Group=junos
On Junos platforms utilizing the JNP10008-SF (aka SIB8), systems experience CRC errors on fabric links between the SIB and the FPC (Flexible PIC Concentrator). These errors are attributed to electrical noise on an internal power rail within the SIB. This condition will lead to multiple FPC-to-SIB link failures, potentially affecting traffic forwarding and overall fabric stability.

Resolved In: junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4X50
PR NumberSynopsisCategory: VMHOST platforms software
1795506
Minor
A non service impacting warning message 'Failed to set 'memory.limit' will be observed
Product-Group=junos
On all Junos OS Evolved platforms a warning message "Failed to set 'memory.limit_in_bytes' attribute on '/user.slice' to '-1': Invalid argument" would be observed.

Resolved In: evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:24.2R1-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.4R1
PR NumberSynopsisCategory: usf ipsec related issues
1876801
Major
IPsec-inside-IPsec tunnel establishment fails on MX platforms with SPC3 cards
Product-Group=junos
On MX platforms equipped with SPC3 cards, the establishment of the inner IPsec tunnel fails in an IPsec-inside-IPsec tunnel setup. This occurs because the service PIC's forwarding process incorrectly attempts to punt IKE packets to the Route Engine (RE) and cannot resolve the required internal fabric path.

Resolved In: junos:22.4R3-S8 junos:22.4X6 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

Resolved In: evo:25.4R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1

 

Modification History

2025-12-15 - update that the issue does not affect the 4-port dual-mode 10GbE/1GbE module with pluggable SFP+/SFP optics. The issue only affects the 2-port QSFP+ / 1-port QSFP28 module

2025-12-12 Update to include a notice about EX4300-48MP

First publication 2025-10-30