Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 25.2R1-S1 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Review content for upgrade consideration

Solution

Junos Software service Release version 25.2R1-S1 is now available.

25.2R1-S1 - List of Fixed issues

PR NumberSynopsisCategory: ISSU
1900759
Major
EX4650/QFX5120-48Y: ISSU fails with reason "error Host OS is not compatible; in-service-upgrade cannot continue"
Product-Group=junosvae
Severity=Major
EX4650/QFX5120-48Y: ISSU fails with reason "error Host OS is not compatible; in-service-upgrade cannot continue"
PR NumberSynopsisCategory: NFX Series Platform Software
1858495
Major
The auto-negotiation is not working properly on NFX350 platform using 1 Gigabit Ethernet SFP
Product-Group=junos
Severity=Major
On NFX350 platforms connected to certain peer devices over SFP 1 Gigabit Ethernet (GE) with auto-negotiation enabled at both ends, a communication issue occur during the initial connection between devices, causing a mismatch in their status. As a result, the port status on the peer device appear as up/down affecting the traffic.
PR NumberSynopsisCategory: "agentd" software daemon
1885622
Major
The aaasd process stops responding for RPC calls
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with gRPC configured, the aaasd process rejects incoming RPCs. This issue occurs in some rare cases, and aaasd will stop listening for authentication requests from reverse proxy. This issue does not cause a traffic impact.
PR NumberSynopsisCategory: A20/A40 IOC card
1883027
Minor
SRX Firewalls with IOC3 triggers a temperature alert on the FPC 2 PLX PCIe Switch Chip
Product-Group=junos
Severity=Minor
On SRX5400, SRX5600, and SRX5800 platform with MPC3-40G10G and MPC3-100G10G (IOC3) interface card, a temperature alarm is triggered when the Peripheral Component Interconnect Express (PCIe) switch chip temperature exceeds 75 Celsius degrees.
PR NumberSynopsisCategory: Border Gateway Protocol
1887911
Major
The rpd process crashes after BGP configuration commits involving group-split-size and RIB-sharding
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring "group-split-size" with BGP RIB-sharding(Border Gateway Protocol Routing Information Base Sharding) can lead to a crash in the routing protocol daemon (rpd) when a route update for a non-negotiated NLRI(Network Layer Reachability Information) is received in the update thread. This occurs if the NLRI is targeted at other BGP peers within the group that have negotiated it.
1889749
Major
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.
PR NumberSynopsisCategory: BBE Remote Access Server
1862071
Major
The 'bbe-smgd' process crashes in BNG with APM environment when loopback interface is moved/removed from a routing-instance through cli
Product-Group=junos
Severity=Major
On Junos MX platforms which supports 'subscriber-management', in a BNG (Broadband Network Gateway) with APM (Address Pool Manager) address allocation environment having "domain-profile" configuration with "dhcp-gateway-address-last-octet" knob enabled, when a loopback interface is moved/removed from a routing-instance through cli, "bbe-smgd" crash can be observed. The existing traffic is unaffected due to this issue, however, new subscriber logins and logout will be impacted if "bbe-smgd" is not running.
PR NumberSynopsisCategory: MX Platform SW - UI management
1884816
Major
MIC details not polling when SNMP MIB walk is performed after Junos OS upgrade
Product-Group=junos
Severity=Major
Post upgrading the Junos OS for MX10K platform from 21.4R3-S3.4 to higher versions, the Simple Network Management Protocol (SNMP) Management Information Base (MIB) walk is not polling Modular Interface Card (MIC) details impacting the SNMP monitoring.
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1887864
Major
Packet loss observed with SFP-T modules on MX10K LC480 line cards due to IPG misalignment
Product-Group=junos
Severity=Major
On Junos MX10004, MX10008, and MX10016 platforms using LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) copper transceivers, both Juniper and NON-JNPR (third-party), causes incorrect handling of the Inter-Packet Gap (IPG). Packets are transmitted with an IPG of 5 bytes instead of the required 8 bytes, leading to packet loss or retransmissions on connected peer devices. The issue is silent, with no logs or alarms.
PR NumberSynopsisCategory: EVO Socket replication
1895827
Major
Adding a new key to authentication-key-chain causes kernel crash
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, when setting/changing the tolerance value of key-chain to max value of 4294967295 and committing and then adding a new key to a key-chain and performing a commit action will result in kernel crash. Device self-recovers after the crash. "show system core-dumps" can be used to check the core. Core name starts with vmcore*
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1884781
Major
Slow configuration commit observed on devices with a single Routing Engine (RE)
Product-Group=junos
Severity=Major
On all Junos OS Evolved platforms with single RE and the system type is cluster, a commit delay is observed when operating with a single RE. This occurs because the system attempts to synchronize with the second RE by default, but since it's not present, the process waits and causes the delay in commit.
PR NumberSynopsisCategory: EVPN control plane issues
1889092
Major
The rpd EVPN module sends a redundant license message to the license infrastructure
Product-Group=junos
Severity=Major
On Junos platforms, when loading the baseline configuration or during BGP flaps or Routing Instance deactivation, and a large number of Group-Based Policy (GBP) tagged routes are removed, a redundant GBP license update message is sent to the license infrastructure for every route deletion. This issue has no impact on traffic.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1848993
Major
The data plane will be out of sync when migrating to EVPN A/A stitching with Vanila VXLAN (PIM Multicast)
Product-Group=junos
Severity=Major
On MX platforms, to improve the convergence of node failures in EVPN MH interconnects with Data Plane VXLAN, migrating to an Active-Active setup may cause the data plane to become out of sync for ARP entries. The gateway learns the MAC address and advertises it to the peer gateway. However, on the peer gateway, some MAC-IP entries may remain stuck in the 'Unresolved' (Ur) state.
PR NumberSynopsisCategory: EX interfaces issues
1886889
Minor
snmp mib walk DomCurrentLaneAlarms does not show proper lanes Values in the latest builds
Product-Group=junos
Severity=Minor
snmp mib walk was not working due to the lane index get issue. Getting the maximum number of lanes for qsfp optics was wrong here. Now it default defined.
PR NumberSynopsisCategory: EX4400 PFE software
1866815
Major
On Junos QFX5000 series and EX4000 series platforms, an fxpc process crash triggers an FPC reboot
Product-Group=junos
Severity=Major
On QFX5000 series and EX4000 series platforms running Junos Operating System (OS), during normal operation, the fxpc process crashes due to a routing entry continues to reference a HOLD next-hop after the associated topology neighbor has already been removed by the system causing the Flexible Physical Interface Card (PIC) Concentrator (FPC) to reboot and generate a crash file.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1822662
Major
SRX:MNHA:ICL:[Longevity] - MNHA Conn State and ICL are down after 48+ hours of device being up with background traffic.
Product-Group=junos
Severity=Major
MNHA Conn State is going down after 48+ hours with some background traffic when MNHA ICL is configured with link-encryption
PR NumberSynopsisCategory: jpppd daemon
1870878
Minor
Simultaneous login by multiple PPPoE subs with same MAC address fails
Product-Group=junos
Severity=Minor
On Junos MX platform with subscriber management enabled, simultaneous login by multiple PPPoE subs with same MAC address fails
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1788400
Major
SNMP walk timeout
Product-Group=junos
Severity=Major
On Junos MX platform with MSMPC card, NMS (Network Management System) times out when polling any data from jnxSpSvcSetIfTable OID.
PR NumberSynopsisCategory: SRX PFE side multicast
1877771
Major
The flowd process crash is observed on all Junos SRX platforms in multicast scenario with PIM
Product-Group=junos
Severity=Major
On all Junos SRX platforms, the flowd process crash will be observed when device is acting as MHR (Middle Hop Router) and PIM (Protocol Independent Multicast) register packet from FHR (First Hop Router) tries to build the control/data session for the same PIM register packet.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1895423
Major
Increase the number of virtual IP addresses to 2000 for MNHA in switching mode
Product-Group=junos
Severity=Major
On certain SRX platforms, when grid-id is not configured, the previous implementation will be used to support 32 VIPs for each (Services Redundancy Group) SRG. Now with this change grid-id and virtual-mac-id are configured, VMAC (Virtual MAC) will be generated with a combination of grid-id, srg-id and virtual-mac-id. Value of grid ID is from 1 to 15. Value of virtual-mac-id is from 0 to 15. A physical or AE (Aggregated Ethernet) interface within an SRG is configured with the same virtual-mac-id. This solution will support 2K VIPs for each SRG, a physical or AE interface configured in multiple SRGs, 16 physical or AE interfaces in each SRG and 15 MNHA (Multi-Node High Availability) pairs in one L2 switch domain.
PR NumberSynopsisCategory: Firewall Policy
1894033
Critical
SRX5K traffic disruption due to REPFE policy sync issues from FQDN and file-serialization Errors
Product-Group=junos
Severity=Critical
On SRX5K series devices with file-serialization enabled, frequent policy synchronization issues occur between the Routing Engine (RE) and Packet Forwarding Engine (PFE) . This can result in traffic matching the incorrect default deny policy instead of matching the expected user-defined security policy. The issue is triggered during commit or request security policies check/resync operations, particularly when Fully Qualified Domain Name(FQDN)-based address objects are involved and have short Domain Name System Time to Live(DNS TTLs).
PR NumberSynopsisCategory: IPSEC/IKE VPN
1804885
Major
Added more flags to "ike traceoptions flag" configuration statement
Product-Group=junos
Severity=Major
New flags have been added under traceoptions. See the "External-Description" field for more detail.
1892539
Major
IKE Processing Order Causing Gateway Misconfiguration and Tunnel Failures
Product-Group=junos
Severity=Major
On SRX platforms, when both gateways, the local-address and the IFA (Interface address) are changed and if the IKE (Internet Key Exchange) configuration is processed before the IFA update, gateways lacking an explicit local-address will be misconfigured, leading to tunnel failures.
PR NumberSynopsisCategory: Software Junos/JunosEvolved lab product
1903528
Major
vJunos-switch and vJunos-router can now be deployed on AMD servers
Product-Group=junos
Severity=Major
vJunos-switch and vJunos-router could previously only be deployed on Intel CPU based servers. This fix allows them to be deployed on AMD CPU based servers as well.
PR NumberSynopsisCategory: Mapping of Address and Port with Encapsulation
1889830
Major
The mgd process crashes after MAP-E configuration and reboot
Product-Group=junos
Severity=Major
On NFX platforms, when MAP-E (Mapping of Address and Port with Encapsulation) configurations are loaded and the device is rebooted, the mgd (Management Daemon) process crashes, leading to crash file generation under /var/tmp/.
PR NumberSynopsisCategory: JNP10K-RE3 CB Centralized MX timing
1848235
Major
Loss of synchronization are observed when SyncE/PTP configurations are changed
Product-Group=junos
Severity=Major
On MX10004 and MX10008 platforms with JNP10K-RE3 and LC480 line cards, when the device is set up with G8275.1 PTP( Precision time protocol) profile or SyncE (Synchronous Ethernet ) and GRES, performing a GRES switchover causes DPLL-2 to go from "lock" to "unlock." This can lead to a loss of synchronization which can disrupt timing-sensitive services like PTP and SyncE.
PR NumberSynopsisCategory: MPC11 ULC platform software related issues.
1881499
Minor
On MPC11E linecards, Periodic error messages are logged as "Temp sensor DDR4 A failed"
Product-Group=junos
Severity=Minor
DDR temp sensor is designed to be used periodically to get temps to send to chassisd. The temp sensors reside may have an intermittent contention that can cause these read failures resulting in DDR4 Temp Sensor Fail" logs on MPC11E linecards.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1874365
Minor
Route for disabled fxp0 interface remains in PFE after re-enabling the interface
Product-Group=junos
Severity=Minor
On Junos platforms, when the fxp0 management interface is configured with an IP address and then disabled, a user route with a reject next-hop is created and installed in the PFE. After re-enabling the interface, this reject route is removed from the forwarding table but remains in the PFE. Rebooting the Routing Engine clears the stale route
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1879079
Major
SRX5600 and SRX5800 SPC3 are going offline after software upgrade
Product-Group=junos
Severity=Major
On SRX5600 and SRX5800 platforms configured in active/passive cluster, upgrading to Junos OS versions 24.4R2.1 or 25.X results in the Services Processing Card 3 (SPC3) on the primary node transitioning to an 'offline' state.
PR NumberSynopsisCategory: Issues related to PKI daemon
1892297
Major
The pkid crash is observed during enrolment of device's local certificate through SCEP
Product-Group=junos
Severity=Major
On Junos OS platforms that use the pki service (public key Infrastructure) for device's local certificate enrolment via SCEP (Simple Certificate Enrolment Protocol), the pki daemon crashes during the enrolment process due to the user misconfiguration in CA (Certificate Authority) profile, specifically the key-usage of the CA certificate for the CA profile lacks the certificate-signing, resulting in impact to services relying on certificate verification.
PR NumberSynopsisCategory: QFX L2 PFE
1883866
Major
Error messages "LBCM-L2, brcm_port_family_detach(), 8814:IFF detach failed for IFD esi IFL xxxxxx with err -1" will be observed on Junos QFX5k and EX4k Platforms
Product-Group=junos
Severity=Major
On Junos QFX5k and EX4k Platforms, if psuedo esi is configured, and flap of interface/clear bgp is done, Error messages "LBCM-L2, brcm_port_family_detach(), 8814:IFF detach failed for IFD esi IFL xxxxxx with err -1" will be observed.
1885220
Minor
Unable to learn the MAC address on a switch interface when using "interface-mac-limit" command
Product-Group=junosvae
Severity=Minor
On all Junos QFX 5k platform, unable to learn the MAC address on a switch interface when using "interface-mac-limit" command.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
Severity=Major
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on specific Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1845045
Major
On QFX5120-48YM port remains down when speed shifts from 1G to 10G
Product-Group=junos
Severity=Major
On QFX5120-48YM, if a port is transitioned directly from 1G to 10G either by swapping the SFP or by changing port and chassis speed settings without intermediate reset. The 10G link will remain down.
1890867
Major
QFX5120 - SFP+ Modules disappear/down post upgrade
Product-Group=junos
Severity=Major
On QFX5120-48T platforms, QSA-SFP+ adapter(100G/40G ) modules disappear/go down after software upgrade. Due to unsupported QSA usage in the impacted release, which will trigger a dcpfe (Dataplane Packet Forwarding Engine) crash.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1855372
Minor
[QFX5120-32C] LEDs do not work properly with QSFP or without optics
Product-Group=junosvae
Severity=Minor
This is a display issue. There is no service impact when this issue occurs. Port 0-29, 31-33 When It is plugged in the Optics and connect the cable, it is in link-up status. However, the LEDs on the ports do not light up or blink. Port 30 The rightmost LED lights up even though no Optics is plugged in.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1882472
Major
JMA package fails to initialise after a power cycle on EX4650/QFX-5E series devices
Product-Group=junos
Severity=Major
On Junos EX4650/QFX-5E series, after installing the JMA(Junos Mist Agent) package, a graceful reboot (using request system reboot or request system halt) is required to commit the changes. An abrupt power cycle before a graceful reboot causes the system to lose the installed JMA package.
PR NumberSynopsisCategory: Resource Reservation Protocol
PR NumberSynopsisCategory: SRX branch platforms
1889549
Major
The XE interfaces of SRX380 platform with 1G SFP (fiber) are flapping continuously when LACP is enabled
Product-Group=junos
Severity=Major
When LACP (Link Aggregation Control Protocol) is enabled using 1G SFP(Small Form-factor Pluggable)-fiber (such as SFP-SX, SFP-LX etc) over XE interfaces, frequent state transitions will repeatedly trigger configuration updates. Due to LACP instability, the interfaces will continuously flap. As a result, the port configuration will be re-applied automatically which leads to a loop of re-configurations until the LACP state stabilizes.
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1886937
Major
Interfaces either fail to come up or flap or a delay is observed on MX10003 platforms when the interface is reset or the devices is restarted
Product-Group=junos
Severity=Major
On MX10003 platforms peering to third-party devices, interfaces remain down or flap or a delay is observed while it comes back up after the device is restarted or the Flexible PIC Concentrator (FPC) is restarted or when the interface is reset. The symptoms is not consistent and any of the mentioned behaviour could be seen. Due to the interface going down or in case of a flap/delay, services running over the interface will be impacted or traffic flowing through that interface will be dropped.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1886757
Minor
Alarms for high usage in /var partition are not generated
Product-Group=junosvae
Severity=Minor
On Junos SRX4600/SRX4700/SRX1600/SRX2300/SRX4300 platforms, alarms for high usage at /var partition storage is not reported.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1885754
Major
MX304 LNS: FPC restart and aft-trio core after LMIC OIR when SI pool spans both MICs
Product-Group=junos
Severity=Major
On MX304 routers acting as LNS, an FPC restart and aftd-trio core may occur if a MIC is offlined (LMIC OIR) while the service-device pool of SI interfaces spans both MICs on the same FPC. This may result in transient loss of subscriber sessions and service impact.
PR NumberSynopsisCategory: ZT/YT LUSS SW driver
1868224
Major
PPE errors will be seen during ISSU
Product-Group=junos
Severity=Major
On Junos platforms with MPC10, MPC11 and LC9600 line cards, PPE (Packet Processing Engine) errors and partial traffic impact will be seen during ISSU (In-service software upgrade). The problem will self-rectify at the end of ISSU.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1885611
Minor
Traffic disruption on MX platforms with MPC line cards when processing invalid Layer 2 circuit packets
Product-Group=junos
Severity=Minor
On MX platforms with MPC (1-9) line cards, when an invalid Layer 2 circuit packet containing explicit Time-To-Live (TTL)=1, Entropy Label Indicator (ELI), and entropy label without valid labels is processed, the system reports reorder ID timeout errors and CMD reorder ID errors, followed by CMERROR 0x2203cc, which disables the Packet Forwarding Engine (PFE) and causes traffic disruption. No workaround is available.
1891110
Major
A GRE tunnel configured with a tunnel key drops MPLS-encapsulated traffic
Product-Group=junos
Severity=Major
On MX platforms with line cards MPC1-9, a Generic Routing Encapsulation (GRE) tunnel configured with a tunnel key drops Multi-Protocol Label Switching (MPLS) encapsulated traffic as it is unable to find the key.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1871866
Minor
if specify 'extensive' option with the curl command using the rest API but the brief data is returned.
Product-Group=junos
Severity=Minor
When using the REST API, if there is no specifiable string behind the 'extensive' option on the URI in the curl command(i.e., if the last string in curl URI is extensive), brief data is returned. curl -u http:///rpc/get-route-information?extensive
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1872820
Major
The dcd process crashes when deactivating only 'swap' under ' interfaces <> unit <> output-vlan-map' with no other attributes present
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, this issue affects configurations where Virtual Local Area Network (VLAN) mapping is used, particularly in scenarios where only the swap attribute is applied under 'interfaces <> unit <> output-vlan-map'. Sequence of 'Deactivate -> Activate -> Commit' of the config hieararchy leads to crash of the device control daemon (dcd) process, potentially causing service disruption.
1878430
Major
The mgd process crash is seen on all Junos and Junos Evolved platforms when FQDN is configured along with ephemeral database
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, Fully Qualified Domain Name(FQDN) configured in static database in presence of ephemeral database instances results in the mgd process crash. As a result, mgd session gets terminated and commit fails. There is no traffic impact due to this issue. The issue is seen with FQDNs that resolve to multiple IP addresses.
1889570
Major
Device enters Amnesiac mode when converting Routing Engine from non-USF mode to USF mode
Product-Group=junos
Severity=Major
On all Junos MX platforms, converting the Routing Engine (RE) from non-USF mode (non-unified services framework) to USF mode (unified services framework) and rebooting the device causes the system to boot into Amnesiac mode unexpectedly. This occurs because the required USF related package sets are not mounted during the boot process.
PR NumberSynopsisCategory: Issues related to NETCONF
1879816
Major
GNMI get native configuration garbage reply when there is no configuration related to openconfig
Product-Group=junos
Severity=Major
The native configuration is observed when there is no configuration related to openconfig but if there are configuration related to openconfig, the native config is not seen. This is just a corner case and no service impact is observed.
PR NumberSynopsisCategory: Web-Management UI
1887595
Major
J-Web EX app-package upload fails via web interface on EX series running Junos 25.1/25.2
Product-Group=junos
Severity=Major
On all EX Series platforms running Junos OS 25.1 or 25.2, uploading the J-Web EX application package via the J-Web GUI (Update > Upload) fails due to a regression in appweb behavior. This prevents users from upgrading the app package through the web interface. Manual installation using CLI is required as a workaround. There is no impact to traffic or ongoing services. The users will not be able to update the J-Web EX application package via the GUI interface, which will delay or block planned upgrades through J-Web.

 


 

25.2R1-S1 - List of Known issues

PR NumberSynopsisCategory: ISSU
1898501
Major
EX4650/QFX5120-48Y: ISSU incompatibility with previous releases
Product-Group=junosvae
EX4650/QFX5120-48Y: Older releases (that do not contain the 1882472 fix) are ISSU incompatible with current releases that have 1882472 fix.

Resolved In:
PR NumberSynopsisCategory: EX4300 Mutlicast implementation
1873129
Major
The PTP packets are dropped when IGMP snooping is enabled
Product-Group=junos
On EX4400, EX4100, QFX5120 and EX4650 platforms running Junos Operation System (OS), when Internet Group Management Protocol (IGMP) snooping is enabled on Virtual Extensible Local Area Network (VXLAN) Virtual Local Area Network (VLAN), all unknown multicast packets will be dropped. As a result, PTP (Precision Time Protocol) packets that use reserved multicast addresses are also discarded affecting the synchronization of the device with the clock server.

Resolved In: junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: NFX Layer 3 Features Software
1882713
Critical
NFX250/NFX350 Node 0 FPC0 when rebooted node fpc0 and fpc 1 doesnt come back at all
Product-Group=junos
Restart of FPC slot 0 on either node 0 or node 1 is not supported

Resolved In:
PR NumberSynopsisCategory: SPC3 HW and SW Issues
1837905
Major
SPC3 flowd heartbeat lost during interface failover
Product-Group=junos
On SRX5400/SRX5600/SRX5800 with SPC3, if the file-serialization is enabled (default in releases after 24.4R1), the flowd process will miss heartbeat messages during interface failover. This results in service disruption.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: BBE multicast related issues
1882756
Major
The bbe-smgd process crash triggered by a multicast event failure
Product-Group=junos
On all MX platforms with Broadband Edge Subscriber Management configured, the bbe-smgd process crashes when the multicast sync service add publish fails. This crash is automatically recovered by the system without requiring manual intervention.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Control plane EVPN multicast
1872219
Major
On rebooting DCI GW device, multicast traffic drop is observed in the highly scaled config.
Product-Group=junos
On rebooting DCI (Data Center Interconnect) Gateway device, while the device is coming up, multicast traffic drop is observed in the highly scaled config. The traffic drop is observed in the following condition. The rebooted device was the EVPN DF on I-ESI and after coming up, the DF election is triggered and the device is elected as EVPN DF on I-ESI. After coming up and elected as DF, the device builds the multicast routes afresh. This results in traffic drop.

Resolved In:
PR NumberSynopsisCategory: EX4100 RE, Platform Infra, Drivers
1887725
Major
Observed hog messages during reboot test
Product-Group=junos
During bootup of the switch hog messages can be observed in /var/log/messages without any functional impact.

Resolved In:
PR NumberSynopsisCategory: EX interfaces issues
1723924
Major
[optics] [opticstag] EX4400-48F :: RLI-53126: Carrier tranistions is not setting properly for channelized ports on non-DUT Lagavulin for QSFP28-100G-AOC-30M 740-064980 of FINISAR
Product-Group=junos
EX4400-48F :: RLI-53126: Carrier tranistions is not setting properly for channelized ports on non-DUT Lagavulin for QSFP28-100G-AOC-30M 740-064980 of FINISAR

Resolved In:
PR NumberSynopsisCategory: EX optics issues
1887303
Major
[EX4400-48F] One of the 10gBase-T transceiver is not detected - showing as "Partial" Unknown in PFE
Product-Group=junos
In the EX4400-48F systems, a 10G-BaseT transceiver that was earlier up may not come up post a reboot/image upgrade event; The transceiver may go undetected causing the interface to not be created in the system.

Resolved In:
PR NumberSynopsisCategory: EX POE
1876675
Major
On EX4100/EX4400s platforms PoE powered devices connected do not come up when adding a second power supply unit
Product-Group=junos
On EX4100/EX4400s platforms using Perpetual PoE and Fast PoE, if power is lost due to one PSU (Power Supply Unit) being removed and the system shuts down, the PoE-powered devices will not automatically power back on when the system is restarted using the other PSU (e.g., switching from slot 0 to slot 1 or vice versa).

Resolved In: junos:22.4R3-S8 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: SRX1500 platform software
1896794
Major
On SRX1500 platforms, after PFE crash, FPC cannot come online
Product-Group=junosvae
On SRX1500 platforms, when transit packets get stuck, PFE crash and PFE core-dump is generated. FPC remains 'present' state until reboot, all the services running on that FPC will be impacted.

Resolved In: junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Express ASIC interface
1845309
Major
Framing errors observed on the peer router when connected to PTX5K with FR optics
Product-Group=junos
On Junos PTX5K platform with QSFP56-DD-4X100G-FR, when 15xQSFP28 PIC. Physical Coding Sublayer (PCS) error observed on the peer router side FR optics when 100G FR optics used, if more number of PCS error may possibility for network impact.

Resolved In: junos:22.3X60 junos:22.3X60-J2 junos:23.2R2-S5 junos:24.2R2-S2
PR NumberSynopsisCategory: flow ha module
1888480
Major
24.4R1 : Moneypenny : MNHA SRX4700 : After restart routing on the ACTIVE MNHA SRX1A & when cold sync is Complete on both the nodes, the backup node shows majority of the sessions as ACTIVE
Product-Group=junos
Restart routing will cause almost of update wing to warm RTO lost when it's not retransmission by default due to failover CPU usage consideration, and then session state will be broken. Suggest to disable preemption and configure "set security flow high-availability rto-retransmission" to work around it with a little high CPU usage during failover.

Resolved In:
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
em0 mgmt port is unreachable after RE switchover
Product-Group=junos
On MX10008 with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
On Junos QFX5k and EX4k platforms, if VPLAG(Virtual Private Link Aggregation group) is configured and if there is event change which could make ECMP(Equal Cost Monitoring Protocol) programming to change like ECMP link flap, dcpfe restart, system reboot etc which causes traffic loss.

Resolved In: junos:21.2R3-S10 junos:22.4R3-S9 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated

Resolved In: evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.

Resolved In: evo:23.4R2-S6-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

Resolved In: evo:25.4R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1

 


 

Modification History

First publication 2025-11-06