Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX MX PTX SRX vSRX platforms running Junos software

Alert Description

Junos Software Service Release version 23.4R2-S6 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Please review.

Note: QFX and EX platforms is available via TSB104284 [juniper.net].

Solution

Junos Software service Release version 23.4R2-S6 is now available.

23.4R2-S6 - List of Fixed issues

PR NumberSynopsisCategory: EVO Debug collector
1868326
Major
FPC commands repeatedly prompt for a password and fail when debug-collector is run by non-root users
Product-Group=junos
Severity=Major
On all Junos EVO platforms, when debug-collectors are run by non-root users the flexible physical interface card concentrators (FPC) commands repeated prompt for passwords. The commands will fail to run though the password is provided.
PR NumberSynopsisCategory: ISSU
1900759
Major
EX4650/QFX5120-48Y: ISSU fails with reason "error Host OS is not compatible; in-service-upgrade cannot continue"
Product-Group=junosvae
Severity=Major
EX4650/QFX5120-48Y: ISSU fails with reason "error Host OS is not compatible; in-service-upgrade cannot continue"
PR NumberSynopsisCategory: EX4300 Mutlicast implementation
1873129
Major
The PTP packets are dropped when IGMP snooping is enabled
Product-Group=junos
Severity=Major
On EX4400, EX4100, QFX5120 and EX4650 platforms running Junos Operation System (OS), when Internet Group Management Protocol (IGMP) snooping is enabled on Virtual Extensible Local Area Network (VXLAN) Virtual Local Area Network (VLAN), all unknown multicast packets will be dropped. As a result, PTP (Precision Time Protocol) packets that use reserved multicast addresses are also discarded affecting the synchronization of the device with the clock server.
PR NumberSynopsisCategory: Junos Node Unifier
1848754
Major
Junos OS: A low-privileged user can disable an interface (CVE-2025-52963)
Product-Group=junos
Severity=Major
An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, leading to a Denial-of-Service. Please refer to https://supportportal.juniper.net/JSA100078 [juniper.net] for more information.
PR NumberSynopsisCategory: SRX ISSU infra related issues
1882569
Major
ISSU getting aborted due to configuration-synchronize failure on Junos SRX platforms
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having chassis cluster configuration-synchronize configured, ISSU (In-Service Software Upgrade) gets aborted due to a configuration synchronization (config-sync) failure and the Redundancy Group (RG) priority is set to 0, preventing a successful failover during the ISSU process resulting in the ISSU process gets aborted causing the upgrade failure.
PR NumberSynopsisCategory: "agentd" software daemon
1752412
Critical
gRPC telemetry intermittently miss reporting is_wrap flag
Product-Group=junos
Severity=Critical
On all Junos platforms when telemetry is enabled, gRPC telemetry message contain a metadata flag is_wrap that indicate to the telemetry client that all telemetry data for the specific Xpath is reported for the specific round. This flag may not be reported intermittently in some edge cases.
1873990
Major
EX9208: Syslog message 'JINSIGHTD_SENSOR_RESUBSCRIPTION' every 5 sec
Product-Group=junos
Severity=Major
On EX9200 series switch, syslog message 'JINSIGHTD_SENSOR_RESUBSCRIPTION' is seen every 5 sec
1889924
Major
Data still seems to be streaming somewhere when the DialOut (Established) connection on the port is already closed
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, the existing gRPC-DialOut connection does not disconnect completely on the DUT, causing any other DialOut connections to fail.
PR NumberSynopsisCategory: MPC Fusion SW
1824215
Major
Incorrect speed assigned to 1G interfaces on MPC2E-3D-NG high-capacity line card modules.
Product-Group=junos
Severity=Major
During the insertion or removal of optics on 1 Gbps interfaces attached to MPC2E-3D-NG , the interface speed may be incorrectly set to 2 bps.
PR NumberSynopsisCategory: firewall filter for australia platform
1871431
Minor
Protocols involved with TCP/IP on a lsi interface have issues as TCP 3-way handshake cannot be completed
Product-Group=junos
Severity=Minor
On all SRX platforms, when a firewall filter is attached to a logical tunnel interface or a virtual routing instance to perform selective packet mode, it causes TCP packets on lsi interface to be discarded due to the TCP 3-way handshake is not established.
PR NumberSynopsisCategory: A20/A40 IOC card
1883027
Minor
SRX Firewalls with IOC3 triggers a temperature alert on the FPC 2 PLX PCIe Switch Chip
Product-Group=junos
Severity=Minor
On SRX5400, SRX5600, and SRX5800 platform with MPC3-40G10G and MPC3-100G10G (IOC3) interface card, a temperature alarm is triggered when the Peripheral Component Interconnect Express (PCIe) switch chip temperature exceeds 75 Celsius degrees.
PR NumberSynopsisCategory: BBE ACI VLAN related issues
1836502
Major
The bbe-smgd process crashes when a BNG subscriber re-logs in after dvlan deletion
Product-Group=junos
Severity=Major
On all Junos MX Series platforms, when running the Broadband Network Gateway (BNG) in IP packet-trigger mode, a client re-login while the dvlan( dynamic Virtual Local Area Network) is in a deleting state causes the bbe-smgd (Broadband Edge - Subscriber Management Daemon) daemon to crash and generate a core dump.
PR NumberSynopsisCategory: Border Gateway Protocol
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.
1859020
Minor
Incorrect subcode NOTIFICATION is sent when local interface is disabled for which multihop is configured for directly connected peer
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, when 'multihop' is configured on a directly connected interface towards a peer and the session goes in IDLE state due to no local interface (interface is disabled or down), the log messages shows 'subcode 6 'Other Configuration Change'' instead of 'subcode 9 'Hard Reset''.
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
Severity=Major
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
Severity=Major
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.
1887911
Major
The rpd process crashes after BGP configuration commits involving group-split-size and RIB-sharding
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring "group-split-size" with BGP RIB-sharding(Border Gateway Protocol Routing Information Base Sharding) can lead to a crash in the routing protocol daemon (rpd) when a route update for a non-negotiated NLRI(Network Layer Reachability Information) is received in the update thread. This occurs if the NLRI is targeted at other BGP peers within the group that have negotiated it.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1907660
Minor
Interface telemetry statistic /interfaces is not streamed correctly on Junos OS Evolved PTX platforms
Product-Group=junos
Severity=Minor
Interface telemetry statistic /interfaces may be streamed incorrectly on Junos OS Evolved PTX platforms. The counter may not be updated, or not update at regular intervals. There is no service impact except monitoring capability using telemetry.
PR NumberSynopsisCategory: MX304 fabric issues (ULC side)
1863674
Major
Link error reported on one PFE(Packet Forwarding Engine) will also report error on other PFE
Product-Group=junos
Severity=Major
On all Junos MX304 platforms, when a link error or training failure occurs, the "show chassis fabric fpcs extended" and "show chassis fabric plane extended" commands display incorrect PFE-to-plane mappings for plane numbers greater than 9. As a result, an incorrect PFE is shown as affected. Due to this incorrect mapping, a training failure, it shows both PFEs getting impacted.
PR NumberSynopsisCategory: MX304 Routing Engine issues
1877895
Major
Martian logs observed on the device.
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved OS, martian logs are observed on FPC (Flexible Physical Interface Card) and on Routing Engine 0.
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1825538
Minor
At the time of RE switchover the backup RE serial and part number values are replaced by the CB0 serial and part number values
Product-Group=junos
Severity=Minor
On MX304 platform, when RE (Routing Engine) switchover takes place the serial and part number values of back up RE is replaced with the values of CB (Control Board). This is a display issue and no impact on the traffic.
PR NumberSynopsisCategory: MX Platform SW - UI management
1884816
Major
MIC details not polling when SNMP MIB walk is performed after Junos OS upgrade
Product-Group=junos
Severity=Major
Post upgrading the Junos OS for MX10K platform from 21.4R3-S3.4 to higher versions, the Simple Network Management Protocol (SNMP) Management Information Base (MIB) walk is not polling Modular Interface Card (MIC) details impacting the SNMP monitoring.
PR NumberSynopsisCategory: Class of Service
1872595
Minor
CoS configured on logical interface does not work on Junos platform when CoS wildcard configurations applied using groups
Product-Group=junos
Severity=Minor
When Class of Service configurations for an Interface Device (IFD) are present both under the wildcard (applied via groups) and as specific configurations (applied directly under the class-of-service hierarchy) on Junos platform, the Interface Device (IFD) correctly takes the specific configurations as expected. However, the Interface Logical (IFL) configurations from the wildcard are not being applied via groups.
PR NumberSynopsisCategory: L2NG Access Security feature
1904091
Critical
During virtual chassis switchover causes default dead route creation
Product-Group=junos
Severity=Critical
On all Junos OS EX and QFX platforms in Virtual Chassis (VC) , during switchover, a race condition between the dcd (Device Control Daemon) and dhcpd (Dynamic Host Configuration Protocol Daemon) causes the dcd to delete Interface Address (IFA) objects that were previously configured by dhcpd. This results in the addition of a default dead route by rpd in the routing table of the new master switch after GRES, leading to services to be impacted.
PR NumberSynopsisCategory: Device Configuration Daemon
1865181
Major
Memory leak occurs when dcd daemon processes service configurations related signal in short interval of time
Product-Group=junos
Severity=Major
On all Junos platforms, memory leak in dcd (Device control daemon) process is observed when a specific signal related to configurations generated by other services is generated in short interval of time and sent to dcd to process, the memory consumption of dcd would increase and if it goes above the threshold the dcd process will crash and restart again. This is a rare case scenario and will not impact any other services.
PR NumberSynopsisCategory: Firewall Filter
1856854
Major
MIB2D will see 100% CPU utilization due to MIB2D walk fail
Product-Group=junos
Severity=Major
On PTX3000/PTX5000/PTX10008 /PTX10016/QFX10008 /PTX1000/PTX10002/ QFX10002 platforms, MIB2D will see 100% CPU utilization due to MIB2D walk failure.
PR NumberSynopsisCategory: ACX platform interface issues
1887528
Minor
Optics fail to come up post reboot
Product-Group=junos
Severity=Minor
On all ACX5448 platforms, read errors are observed on 1G copper optics (SFP-T) modules during the device reboot, resulting in the 1G optics ports remaining down and impacting all services.
1896458
Minor
SFP-T port will not come up after system restart
Product-Group=junos
Severity=Minor
On Junos ACX5448 platforms, when the port with SFP-T copper optics is disabled or chassisd is restarted, Tx is disabled before the media is identified. This is a timing issue. The port will not come up even if disable is removed from the configuration. Reinserting the transceiver will resolve the issue.
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1881742
Major
Packet Loss is observed when explicit Null is disabled for BGP-LU routes in ECMP scenarios
Product-Group=junos
Severity=Major
On Junos ACX5448 and ACX710 platforms, traffic drop is observed for the Labeled Unicast (BGP-LU) route prefixes with Equal-Cost Multipath (ECMP) forwarding path when explicit null is disabled.
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1887864
Major
Packet loss observed with SFP-T modules on MX10K LC480 line cards due to IPG misalignment
Product-Group=junos
Severity=Major
On Junos MX10004, MX10008, and MX10016 platforms using LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) copper transceivers, both Juniper and NON-JNPR (third-party), causes incorrect handling of the Inter-Packet Gap (IPG). Packets are transmitted with an IPG of 5 bytes instead of the required 8 bytes, leading to packet loss or retransmissions on connected peer devices. The issue is silent, with no logs or alarms.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1889335
Minor
Traffic drop is observed in an EVPN multihoming as the MAC route points to the ESI interface when the CE (ESI) IFD flaps
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, in an Ethernet Virtual Private Network (EVPN) MultiHoming setup with Ethernet Segment Identifier (ESI) configured under logical Interface (IFL) (CE-facing), when the corresponding IFD (Physical Interface) flaps, the MAC route will point to the ESI interface, while it should point to the Multihoming CE (Customer Edge) interface. This results in traffic loss.
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1823278
Minor
Traffic blackhole on MACsec enabled interfaces due to ARP packet drops
Product-Group=junos
Severity=Minor
On Junos OS Evolved ACX7509, ACX7348 and ACX7332 platforms, traffic drops will be seen on MACsec enabled interfaces after RE (Routing Engine) switchover or picd restart. This is due to ARP (Address Resolution Protocol) packets of size less than 64 bytes being errenously discarded on MACsec interfaces as Runt discards. This will result in traffic blackholing on those interfaces.
PR NumberSynopsisCategory: EVO Socket replication
1895827
Major
Adding a new key to authentication-key-chain causes kernel crash
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, when setting/changing the tolerance value of key-chain to max value of 4294967295 and committing and then adding a new key to a key-chain and performing a commit action will result in kernel crash. Device self-recovers after the crash. "show system core-dumps" can be used to check the core. Core name starts with vmcore*
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
Severity=Major
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.
PR NumberSynopsisCategory: Configd, ffp issues
1877439
Minor
Traffic drop occurs on Junos Evolved platforms when prefix is moved between dynamic prefix-lists used in firewall filter
Product-Group=junos
Severity=Minor
On all Junos Evolved platforms, when a firewall filter is configured with a dynamic prefix-list that is referenced using an apply-path statement, moving a prefix from one such prefix-list to another where both prefix-lists match the apply-path pattern results in the prefix not being programmed in the PFE. This causes traffic loss for that prefix. The issue is triggered when the configuration includes apply-path pointing to both the source and destination prefix-lists, and a prefix is deleted from one and added to the other through a commit operation.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1882996
Major
xnm-ssl feature fails without loopback interface configuration on Junos Evolved platforms.
Product-Group=junos
Severity=Major
On Junos Evolved platforms, the xnm-ssl feature does not function unless a loopback address (lo0.0) is explicitly configured. The feature is not applicable to Junos (non-EVO) platforms. To ensure proper operation, configure 127.0.0.1/32 on lo0.0.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1848993
Major
The data plane will be out of sync when migrating to EVPN A/A stitching with Vanila VXLAN (PIM Multicast)
Product-Group=junos
Severity=Major
On MX platforms, to improve the convergence of node failures in EVPN MH interconnects with Data Plane VXLAN, migrating to an Active-Active setup may cause the data plane to become out of sync for ARP entries. The gateway learns the MAC address and advertises it to the peer gateway. However, on the peer gateway, some MAC-IP entries may remain stuck in the 'Unresolved' (Ur) state.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1884163
Major
IFL Memory Leak on QFX10K8/16 device
Product-Group=junos
Severity=Major
On QFX10K8/16 , IFL memory is not freed on non-local interface of FPC during configuration changes (eg: IFL delete/deactivate) for L3IFL/L2IFL on AE/Scalar interfaces. Fix is present in common code and risky. It is a day one issue and the per IFL leak is minimal (0.00016% of total Kernel heap size) .
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1883530
Critical
FPC crash is seen on certain Junos platforms when firewall filter is configured for subscribers
Product-Group=junos
Severity=Critical
On MX platforms with MPC10E, MPC11E, LC9600 line-cards and MX304 with subscriber-management enabled, Flexible PIC Concentrator (FPC) crashes in a rare scenario and crash files are generated when filters are configured for subscribers . This will lead to traffic impact since the line-card reboots and subscribers are re-logged.
PR NumberSynopsisCategory: SRX1500 platform software
1896794
Major
On SRX1500 platforms, after PFE crash, FPC cannot come online
Product-Group=junosvae
Severity=Major
On SRX1500 platforms, when transit packets get stuck, PFE crash and PFE core-dump is generated. FPC remains 'present' state until reboot, all the services running on that FPC will be impacted.
PR NumberSynopsisCategory: MX LC4800 Interface software
1773437
Minor
Traffic failed for packet size bigger than 86 after change port speed to 400G then back to 100G
Product-Group=junos
Severity=Minor
On MX10004 and MX10008 platforms, when 100G interfaces are configured on any port the traffic fails for packet sizes larger than 86 bytes after an interface reconfiguration that involves changing the port speed from 100G to 400G and then back to 100G. As a result, the 100G interface is unable to send packets exceeding 86 bytes to its peer, which leads to traffic disruption.
PR NumberSynopsisCategory: MX Inline Jflow
1852278
Minor
With rib-sharding enabled, IPFIX exports wrong SrcAS / DstAS fields
Product-Group=junos
Severity=Minor
With rib-sharding enabled, IPFIX exports wrong SrcAS / DstAS fields
1861100
Minor
System journal logs are flooded without enabling debugging when inline monitoring is configured
Product-Group=junos
Severity=Minor
On MX304 platform and all MX platforms having MPC10E/MPC11E/LC9600 line cards, when inline monitoring is configured, system journal is being flooded with IPFIX headers by default, without enabling any debugging.
PR NumberSynopsisCategory: ISIS routing protocol
1847557
Critical
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.
1859099
Minor
Memory leak is observed for certain topologies when TI-LFA is configured
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms , where IS-IS/OSPF is enabled and TI-LFA (post-convergence-lfa) is configured in a SR (Segment Routing) environment. In a scenario where the computed backup paths to reach a destination is fetched from the more than one originator, duplicate paths gets computed for certain topology combinations and the clean-up of infosid list doesn't happen this leads to memory leak that might eventually lead to high memory usage and result in rpd crash and thus impacting traffic.
PR NumberSynopsisCategory: jdhcpd daemon
1810213
Minor
System crash occurs due to duplicate DHCP-assigned IP addresses
Product-Group=junos
Severity=Minor
On all Junos platforms, a system crash (vmcore) occurs if two DHCP clients are assigned the same IP address, typically during Zero Touch Provisioning (ZTP), lab setups, or automated provisioning, leading to duplicate entries across interfaces such as irb and vme. The Dynamic Configuration Daemon (DCD) does not detect or prevent this condition, allowing the conflict to pass silently. This defect causes partial service impact, devices crash and reboot.
PR NumberSynopsisCategory: JFlow bug tracker for SRX platforms
1863356
Minor
The flowd process crash on SRX with IPFIX and MPLS enabled
Product-Group=junos
Severity=Minor
On all SRX Series platforms, enabling IPFIX (IP Flow Information Export) on devices configured with MPLS (Multiprotocol Label Switching) results in flowd process crash. Traffic is interrupted due to the crash.
PR NumberSynopsisCategory: jl2tpd daemon
1877876
Major
L2TP subscriber is unable to connect when configuration is loaded over default config on all Junos platforms with L2TP subscribers
Product-Group=junos
Severity=Major
On all Junos platforms with L2TP (Layer 2 Tunneling Protocol) subscribers if source-gateway-address is not configured, new L2TP subscribers will not be able to connect when configuration is loaded over default config.
PR NumberSynopsisCategory: Flow Module
1832547
Minor
The flowd process crash is observed on certain SRX platforms
Product-Group=junos
Severity=Minor
On certain Junos SRX devices upon initiation of session scan, flowd process might crash due to session getting deleted/re-routed. This could result switchover of redundancy group in case of high availability.
1854492
Major
Junos SRX platforms with chassis cluster configured experience flowd crash due to a race condition in multicast session handling
Product-Group=junos
Severity=Major
On Junos SRX platforms with chassis cluster configured, a crash is observed in multicast scenario due to a race condition where a link flap changes the ingress interface while a session is being aged out, leading to invalid session data access. This causes the flowd process to crash, resulting in a coredump and eventually the system crashes.
1878164
Major
A flowd crash triggered on SRX platforms in L2 transparent mode
Product-Group=junos
Severity=Major
On SRX platforms(vSRX/SRX300/SRX320/SRX340/SRX345/SRX380/SRX550/SRX550 HM/SRX1500/SRX1600/SRX2300/SRX4100/SRX4200/SRX4300/SRX4600) configured in Layer 2 transparent mode with static ARP entries, initiating bidirectional TCP traffic can cause a flow daemon (flowd) crash.
PR NumberSynopsisCategory: SRX PFE side multicast
1877771
Major
The flowd process crash is observed on all Junos SRX platforms in multicast scenario with PIM
Product-Group=junos
Severity=Major
On all Junos SRX platforms, the flowd process crash will be observed when device is acting as MHR (Middle Hop Router) and PIM (Protocol Independent Multicast) register packet from FHR (First Hop Router) tries to build the control/data session for the same PIM register packet.
PR NumberSynopsisCategory: SRX PFE side GRE/IPIP/DS-Lite/IPSec/PIM/VXLAN tunnel
1884150
Major
Policy match failure for VXLAN EVPN type-5 cross vrf traffic
Product-Group=junos
Severity=Major
On all SRX platforms, Ethernet Virtual Private Network (EVPN) Type-5 Virtual Extensible LAN (VXLAN) cross-Virtual Routing and Forwarding (VRF) traffic fails to match security policies when the ingress and egress VRFs are mapped to different VRF groups.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1895790
Major
Backup node stuck in cold sync failure after all FPCs reset due to SPC crash files in SRX chassis cluster
Product-Group=junos
Severity=Major
On all SRX platforms, in a chassis cluster scenario, the PFE crashes on the backup node. After the crash files are fully generated, this triggers a reset of all FPCs. Following the crash and FPC resets, the backup node enters a cold sync failure state and remains in that state until it is manually rebooted.
PR NumberSynopsisCategory: l2 flow module
1852047
Major
Traffic drops are observed when SRX380 platform is configured in l2 transparent-bridge mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms, traffic drops are observed due to the default drop ACL (Access Control List) (L2 unknown unicast packets) getting applied. The issue happens when the device is configured in L2 (Layer 2) transparent-bridge mode.
PR NumberSynopsisCategory: JSR Application Services
1792714
Major
pub-brokerd crash due to rapid connect-disconnect events on SRX platforms with MNHA
Product-Group=junos
Severity=Major
On all SRX platforms with Multi-Node High Availability (MNHA) enabled, a rare corner-case scenario involving a rapid sequence of connection attempts immediately followed by disconnections can trigger an unhandled assertion in the pub-brokerd process. This results in a core dump and full-service disruption on the affected node. Automatic recovery is not supported in this scenario, and manual intervention is required. The issue is rare and relies on a specific timing condition.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1892539
Major
IKE Processing Order Causing Gateway Misconfiguration and Tunnel Failures
Product-Group=junos
Severity=Major
On SRX platforms, when both gateways, the local-address and the IFA (Interface address) are changed and if the IKE (Internet Key Exchange) configuration is processed before the IFA update, gateways lacking an explicit local-address will be misconfigured, leading to tunnel failures.
PR NumberSynopsisCategory: Platform infra to support jvision
1837761
Major
Missing telemetry data for FRUs when subscribed to /components/component
Product-Group=junos
Severity=Major
On all Junos platforms, the/components/component/state/mfg-name leaf is not being streamed for any FRUs, such as RE, CB, FPC, FT, and PEM, when subscribed to /components/component via on-change and periodic mode of subscription.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
1895433
Minor
The enable-pxe-boot is not working as expected on specific EX or QFX platforms with Easy EVPN LAG single home server topology
Product-Group=junos
Severity=Minor
The enable-pxe-boot option does not work as expected for Easy EVPN LAG (Ethernet Virtual Private Network Link Aggregation Group) single home server topology configuration on specific EX or QFX platforms. The enable-pxe-boot configuration knob does not generate the "force-up" configuration. Consequently, the physical link remains down until "force-up" is manually added on physical child interface. It causes LACP (Link Aggregation Control Protocol) to go down when singled homed server is added with LACP.
1909786
Critical
Selection of VGA-IP as source IP for RE-ARP packet causes incorrect ARP updation of VGA-IP getting bound with IRB-MAC at end-hosts
Product-Group=junos
Severity=Critical
Selection of VGA-IP as source IP for RE-ARP packet causes incorrect ARP updation of VGA-IP getting bound with IRB-MAC at end-hosts
PR NumberSynopsisCategory: Label Distribution Protocol
1789663
Major
Unexpected rpd crash when huge amount of telemetry data is being streamed
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms with telemetry enabled, in escenarios where huge amount of data is being streamed, when streaming data crosses the limit (i.e size based defer limit is at 15kb and time-based defer limit 100 ms) there will be a defer and continue. If configuration changes occur during this deffering state that affected the last streamed XPath (the specific data path being monitored), it will cause rpd (routing protocol deamon) to crash causing traffic drop and core file will be generated. No workaroung is provided, rpd will restart automatically.
PR NumberSynopsisCategory: authd (AAA) library code
1860913
Major
The authd process crashes when /etc/resolv.conf file is empty
Product-Group=junos
Severity=Major
On Junos OS Evolved ACX platforms, when DHCP (Dynamic Host Control Protocol) local server is configured without domain-name specified, the authd process crash may be observed. There will be no forwarding traffic impact due this issue, however, new DHCP client requests will not be answered.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1883473
Major
Packet drops are observed when MACsec with bounded-delay is configured due to key rollover
Product-Group=junos
Severity=Major
On Junos OS MX304, MX platforms with line cards LC4800 and LC4802, and Junos OS Evolved ACX platforms with MACsec (Media Access Control security) with bounded-delay is configured, packet drops will be observed as valid packets will be incorrectly identified as replays and dropped because they fall outside the allowed replay protection window. The issue happens when the expected PN (Packet Number) on the receiver becomes unsynchronized with the sender during a key rollover event.
PR NumberSynopsisCategory: MPC10E timing and synchronization
1878254
Major
1PPS measurement failed for class-B over 100GE to 100GE port combinations using SR4 optics
Product-Group=junos
Severity=Major
On Junos MX240, MX480, and MX960 platforms, when using SR4 100 G (Short Reach 4-lane 100 Gigabit Ethernet) optics with FEC91 (Forward Error Correction) mode enabled, additional delays are introduced in the optics that fails class-B mask on PTP (Precision Time Protocol) on the particular interface.
1881618
Major
MPC10E: Huge 1PPS error is seen for 15 to 20 minutes with SCB3E post DUT in phase aligned state
Product-Group=junos
Severity=Major
In SCBE3 system with G.8275.1 profile, PTP pps output measured at the calnex may take 15-20mins to align with packet metrics and a huge offset will be seen in the 15-20mins window.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when RSVP-TE (Resource Reservation Protocol - Traffic Engineering) is configured with MBB (make-before-break) setup, if the protected link of the primary LSP (Label Switched Path) goes down and if "clear mpls lsp" or "clear rsvp session" commands are executed, then LSP switches to new instance from the old which will be on higher IGP (Interior Gateway Protocol) metric. However, after re-optimization, LSP will not get switched to better IGP metric path and remain in old instance. Traffic drop can be seen due to this double fault events.
1878360
Minor
memory leak in lsp_regex_cache_entry block (lsp_regex_cache_entry_add)
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, when configured with RSVP (Resource Reservation Protocol) LSPs (label-switched path) and when MPLS (Multi-Protocol Label Switching) protocol activate/deactivate is performed, the rpd memory leak is observed. There is no service impact due to this issue.
PR NumberSynopsisCategory: Multicast Routing
1863470
Major
The rpd crash due to memory corruption in PIM/MSDP network
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, enabling PIM (Protocol Independent Multicast) or MSDP (Multicast Source Discovery Protocol) may cause a rare memory corruption during the update of the MSDP Source Active route. This issue primarily affects highly scaled environments, leading to rpd (routing protocol daemon) coredumps and potential traffic loss.
1876458
Major
MX960 mcsnoopd core dump during rt_mcnh_nh_release
Product-Group=junos
Severity=Major
When the mcsnoopd process (use for L2 multicast) creating a new NH , our system takes a reference to it. However, if this reference is released too quickly, the old NH might be deleted before its references are fully cleared. This may cause the mcsnoopd process to restart.
PR NumberSynopsisCategory: Multicast for L3VPNs
1747703
Major
The MVPN traffic starts dropping after RE switchover
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Dual RE and MVPN ((Multicast Virtual Private Network) enabled, when the user initiates a GRES ( Graceful Routing Engine Switchover) switchover, it triggers a route change from the MVPN . During this process, there's a gap where traffic loss is observed because the flood next hop pointed to by the route gets deleted.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1874365
Minor
Route for disabled fxp0 interface remains in PFE after re-enabling the interface
Product-Group=junos
Severity=Minor
On Junos platforms, when the fxp0 management interface is configured with an IP address and then disabled, a user route with a reject next-hop is created and installed in the PFE. After re-enabling the interface, this reject route is removed from the forwarding table but remains in the PFE. Rebooting the Routing Engine clears the stale route
1881956
Major
IPv6 default route gets deleted from FIB by slaac daemon after an upgrade with an unsupported configuration
Product-Group=junos
Severity=Major
On all Junos OS platforms , deletion of IPv6 default route from FIB (Forward Information Base) by slaacd (Stateless Address AutoConfiguration Daemon ) is observed while recovering the device from amnesiac state after the OS upgrade with any unsupported or incompatible configuration.
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1872704
Major
NTS for NTP not working even after the Ceritficate is validated with External servers like Chrony and NTPSec
Product-Group=junos
Severity=Major
NTS for NTP not working even after the Ceritficate is validated with External servers like Chrony and NTPSec
PR NumberSynopsisCategory: TCP/UDP transport layer
1864027
Minor
TCP listening sockets are not displayed correctly
Product-Group=junos
Severity=Minor
On Junos OS platforms, TCP (Transmission Control Protocol) listening sockets may be absent from command outputs due to NULL values in netstat application.
PR NumberSynopsisCategory: OSPF routing protocol
1827435
Major
OSPF LSA flooding is impacted after database recovers from 'ignore' state when 'database-protection' is triggered
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when the LSA (Link State Advertisement) count exceeds the maximum number configured under 'database-protection' feature in OSPFV2 (Open Shortest Path First Version 2), the OSPF database (DB) enters into 'ignore' state. When the DB is recovered, OSPF LSA flooding is stopped on some interfaces.
PR NumberSynopsisCategory: Express Chip L3 software
1865171
Critical
FPC crashes if the BGP protocol next-hop gets resolved over a discard logical interface (dsc.0)
Product-Group=junos
Severity=Critical
On Junos OS PTX and QFX10k platforms, FPC crashes and reboot is seen due to the corruption of the data structures associated with dsc.0 (Discard Interface).
1877538
Major
Multicast traffic loss is seen when MVPN with node protection is enabled
Product-Group=junos
Severity=Major
On Junos PTX and QFX10K platforms with node protection enabled on a Multicast Virtual Private Network (MVPN) scenario, multicast traffic loss will be seen when the number of child links in an aggregated ethernet (AE) interface for bypass Label Switched Path (LSP) egress interface is higher than primary LSP and one of the child links goes down on primary LSP egress interface.
PR NumberSynopsisCategory: Protocol Independant Multicast
1857699
Major
Native_Multicast:: : Protocol PIM Interface disable command not working
Product-Group=junos
Severity=Major
Disabling the PIM interface underneath the [edit protocols pim interfaces ] hierarchy may still show PIM as still being UP instead of DOWN.
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.
PR NumberSynopsisCategory: Issues related to PKI daemon
1892297
Major
The pkid crash is observed during enrolment of device's local certificate through SCEP
Product-Group=junos
Severity=Major
On Junos OS platforms that use the pki service (public key Infrastructure) for device's local certificate enrolment via SCEP (Simple Certificate Enrolment Protocol), the pki daemon crashes during the enrolment process due to the user misconfiguration in CA (Certificate Authority) profile, specifically the key-usage of the CA certificate for the CA profile lacks the certificate-signing, resulting in impact to services relying on certificate verification.
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
Severity=Major
In stressful conditions, FPC crash observed and core file generated when PKID (public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured.
PR NumberSynopsisCategory: QFX access control list
1863813
Minor
On particular QFX and EX devices firewall filter counters display double the actual packet count
Product-Group=junos
Severity=Minor
When Filter-Based Forwarding (FBF) or Policy-Based Routing (PBR) is configured with firewall filter counters on platforms QFX5120, EX4650, EX4100, EX4400, the CLI output for FBF/PBR filter statistics shows double the actual packet count, there is no workaround for this issue.
PR NumberSynopsisCategory: QFX PFE Class of Services
1894833
Minor
PFE crash observed during VXLAN classifier unbind or EZ-LAG commit operations
Product-Group=junos
Severity=Minor
On Junos QFX5k platforms, a PFE (Packet Forwarding Engine) crash is observed when unbinding VXLAN (Virtual Extensible LAN) access ports or classifiers with large number of SVP (Source Virtual Port) associations, or after committing EZ-LAG (Easy EVPN LAG) configurations with large VLAN-ID list leading to excessive CPU utilization, watchdog timeout, and eventually a crash.
PR NumberSynopsisCategory: QFX L2 PFE
1885220
Minor
Unable to learn the MAC address on a QFX5k platform interface when using "interface-mac-limit" command
Product-Group=junosvae
Severity=Minor
On all Junos QFX5k platform, unable to learn the MAC address on a switch interface when using "interface-mac-limit" command.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1886612
Major
Next-hop entries are not getting programmed in ECMP unilist group after device upgrade
Product-Group=junos
Severity=Major
On Junos OS QFX5k and EX4k platforms, when static ECMP (Equal-Cost Multi-Path) is configured, traffic loss will be observed due to a next-hop programming issue. The device fails to install the next-hop entries in hardware for static ECMP routes, resulting in traffic not being forwarded as expected after a device upgrade.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1878555
Major
Transit unicast ARP requests are dropped instead of being forwarded
Product-Group=junos
Severity=Major
On Junos QFX5K and EX46xx platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) environment, when "no-arp-trap" is enabled, transit unicast Address Resolution Protocol (ARP) packets that are not destined for the local switch Integrated Routing and Bridging Media Access Control (IRB MAC) are dropped instead of being forwarded across the leaf nodes.
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
Severity=Major
On Junos QFX5k and EX4k platforms, if VPLAG(Virtual Private Link Aggregation group) is configured and if there is event change which could make ECMP(Equal Cost Monitoring Protocol) programming to change like ECMP link flap, dcpfe restart, system reboot etc which causes traffic loss.
PR NumberSynopsisCategory: RPD Interfaces related issues
1842546
Major
Memory leak is detected when interfaces are configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, 72-byte size memory leak is seen when interface configuration is added. But there is no traffic impact due to this issue.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1848971
Major
Configuring BGP rib-sharding and generate route will cause rpd process to crash
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring BGP (Border Gateway Protocol) rib-sharding and generate routes will cause the rpd process to crash.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1815837
Minor
Configure low file size in traceoptions while logging volume is high will lead to high CPU and RPD scheduler slips causing operational impact
Product-Group=junos
Severity=Minor
If the file size is too small and the amount of traceoptions volume is too high it can cause scheduler slips and operational impact.
PR NumberSynopsisCategory: Resource Reservation Protocol
1881906
Major
BFD session failure causes LSP to go down and the inactive route remains in the routing table leads to traffic black hole
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms, when an RSVP (Resource Reservation Protocol) LSP (Label Switched Path) goes down due to a failure in the associated BFD (Bidirectional Forwarding Detection) session, and the corresponding route remains in the routing/forwarding table causing traffic black-holing. If there are other active LSPs to the same destination, those active routes are preferred over the inactive route associated with the failed LSP.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1817865
Minor
The "snmp packet-size " command not working for SNMPv3
Product-Group=junos
Severity=Minor
If the "snmp packet-size " is configured on Junos and Junos Evolved platforms. , the responded SNMPv3 packet could be of larger size causing more fragmentation and packet overhead for SNMP traffic.
PR NumberSynopsisCategory: SRX branch platforms
1877428
Major
Stale user session displayed in "show system users" after ssh session disconnected.
Product-Group=junos
Severity=Major
On all platforms running FreeBSD6, such as the SRX3xx or QFX5100 series, once an SSH session is disconnected, the stale user entry may still be displayed in "show system users" or still counted in hrSystemNumUsers OID.
1893957
Minor
SRX configured with a native VLAN ID other than 1 experienced DHCP assignment issues and ARP resolution failures to the default gateway
Product-Group=junos
Severity=Minor
In SRX configured with a native VLAN ID other than 1, connected devices successfully obtain DHCP IP addresses but are unable to resolve ARP for the default gateway. Although the SRX sends ARP replies, these responses do not reach the connected devices. Corresponding packet discards are observed in the Packet Forwarding Engine (PFE), indicating that the ARP replies are being dropped before reaching the endpoints.
1895179
Major
The kern.maxfiles limit exceeded observed due to log rotation resulting in unresponsive SSH
Product-Group=junos
Severity=Major
On all Junos OS platforms, Configuring multiple syslog servers causes duplicate routing-instance map entries, leading to an eventd file descriptor leak during log rotations. Once the threshold is exceeded, the SSH connection becomes unresponsive.
PR NumberSynopsisCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1803105
Major
PTP attribute changes on upstream device causes best clock master slot switchover
Product-Group=junos
Severity=Major
On all MX platforms(except MX80) with multi line card chassis, when PTP slave or stateful streams are configured across multiple linecards with clock from same PTP time provider and the announce msg parameters changes from the upstream device, the best master clock (BMC) slot switchover is observed and is restored back within few seconds. Although the slot time interval is very less, it can still lead to major impact as the active PTP slot and clock path is switched over and results in re-routing of the clocks.
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1886937
Major
Interfaces either fail to come up or flap or a delay is observed on MX10003 platforms when the interface is reset or the devices is restarted
Product-Group=junos
Severity=Major
On MX10003 platforms peering to third-party devices, interfaces remain down or flap or a delay is observed while it comes back up after the device is restarted or the Flexible PIC Concentrator (FPC) is restarted or when the interface is reset. The symptoms is not consistent and any of the mentioned behaviour could be seen. Due to the interface going down or in case of a flap/delay, services running over the interface will be impacted or traffic flowing through that interface will be dropped.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1878195
Major
Heap memory threshold value is not taking effect post GRES/Switchover if configured to a higher value
Product-Group=junos
Severity=Major
On Junos OS platforms with MPC10, MPC11, LC4800, LC9600 line cards and on MX304, if heap memory threshold is configured with the higher value, post GRES (Graceful Routing Engine Switchover) or switchover, threshold gets overwritten to default. Drop in subscribers can be seen if heap usage is more than the default threshold in case of Subscriber Management is enabled.
PR NumberSynopsisCategory: ZT/YT pfe CDA issues
1882845
Critical
MPC 10/11/12E, LC9600 and LC4800 Line cards and MX304, interface statistics stop after interrupt
Product-Group=junos
Severity=Critical
On all MX platforms with MPC 10/11/12E, LC9600 and LC4800 Line cards and MX304, in a race condition related to the interrupt handling, interface counters are stuck and not incrementing. Issue not reproducible and there is no service impact due to this issue.
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1851317
Minor
Packet drops are observed on rate-limited queues
Product-Group=junos
Severity=Minor
On MX platforms with MPC10E, MPC11E, MX304 and JNP10K-LC9600 with Class-of-Service (COS), packet drops are seen in rate-limited queues with high, medium-high or strict-high priority due to shallow buffer-size.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1857934
Major
Traffic drop is observed after removing the layer-2 policer from the IFL
Product-Group=junos
Severity=Major
On Junos MX platforms with MPC10/ MPC11/LC9600/MX304 and EX9K platforms, after an FPC or router reboot if the layer-2 policer is deleted later, traffic drop is observed on the interface where layer-2 policer was attached.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1862500
Minor
MX304 or MPC10/11/LC9600 aftd-trio process memory leak when polling NPU sensor data
Product-Group=junos
Severity=Minor
On Linux-based PFE platforms like MX304, MPC10, MPC11, and LC9600, streaming NPU sensor data via Telemetry may leak memory
1875040
Major
The BUM traffic is dropped due to interoperability issue in combination of MPC 1-9 and MPC10E/MPC11E line cards in a WECMP setup
Product-Group=junos
Severity=Major
The Broadcast, unknown Unicast, and Multicast (BUM) traffic such as Ethernet Virtual Private Network (EVPN) or Virtual Private LAN Service(VPLS) etc. is dropped on the egress Flexible PIC Concentrator (FPC) in a weighted Equal Cost Multi-Path (ECMP) setup with non-zero balances when ingress traffic arrives on a different line card. This issue arises only in interoperability scenarios where a combination of MPC 1-9 and MPC10E/MPC11E line cards are used for ingress and egress processing resulting in forwarding issues.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1846055
Critical
PPE traps and traffic wedges are seen when subscribers are forwarded through Soft-GRE tunnel
Product-Group=junos
Severity=Critical
On all Junos MX platforms with MPC2-9 linecards, when subscribers are forwarded through the Soft-GRE (dynamic GRE tunnel), hardware memory corruption occurs resulting in PPE (Packet Processing Engines) traps being generated and traffic is impacted.
1865649
Major
Traffic drop from subscriber will be observed when rpf-check knob is enabled under subscriber dynamic-profile with static underlying VLAN interface
Product-Group=junos
Severity=Major
On all Junos MX platforms with BBE subscribers (Broadband Edge) over static IFLs (Logical Interface) with static underlying VLAN (Virtual Local Area Network) interface and ISSU (In-Service Software Upgrade) is performed, traffic drop will be observed when rpf-check (Reverse-path forwarding) knob is enabled under subscriber dynamic-profile.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1870522
Minor
STP/RSTP/MSTP/VSTP enters a disputed and blocked state when the anchor FPC of an AE link, with members distributed across multiple FPCs, goes offline
Product-Group=junos
Severity=Minor
On MX and EX9200 series platforms that operate in hyper mode by default, STP (Spanning Tree Protocol)/RSTP (Rapid Spanning Tree Protocol)/MSTP (Multiple Spanning Tree Protocol)/VSTP (VLAN Spanning Tree Protocol) transitions to a disputed and blocked state if the members of the AE (Aggregated Ethernet) link in the anchor FPC (Flexible PIC Concentrator) goes offline.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1880860
Major
FPC crash is seen on MX series when disabling AE IFL in mixed-speed configuration without enhanced-ip enabled
Product-Group=junos
Severity=Major
On MX platforms using ukern line cards (MPC2-9, LC480, LC2101, MX10K3), disabling an AE(Aggregated Ethernet) IFL configured with mixed-speed member links and without enhanced-ip enabled causes the associated FPC to crash and reboot.
PR NumberSynopsisCategory: DDos Support on MX
1807538
Major
DDOS related Error messages can be seen on MX platforms
Product-Group=junos
Severity=Major
On certain Junos MX platforms with SCFD (Suspicious Control Flow Detection) enabled, error messages related to DDOS (Distributed Denial Of Service) protection can seen when traffic volume is high with varied flows. There is no service impact because of this issue.
1860439
Minor
DDOS/SCFD culprit-flows display wrong PPS on the detected subscriber demux0 interfaces
Product-Group=junos
Severity=Minor
DDOS/SCFD culprit-flows display wrong PPS on the detected subscriber demux0 interfaces.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.
PR NumberSynopsisCategory: Configuration management, ffp, load action
1854461
Major
Configured TFTP server connection and rate limits are not applied
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms configured as Trivial File Transfer Protocol (TFTP) server , "connection-limit" or "rate-limit" values are not updated as per configured values.
PR NumberSynopsisCategory: Ephemeral Database
1839322
Major
The commit-syncd configuration generates commit-syncd cores observed at vlogging_event
Product-Group=junos
Severity=Major
On EX-series platforms running Junos Operatin System (OS), configured as a Virtual Chassis (VC) with an ephemeral database (DB) and commit sync enabled, executing the commit-syncd process creates a configuration file that is reused for commits on other VC members. In the problematic scenario, the configuration file is missing during the second iteration, leading to a commit-syncd core without impacting the device.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1872820
Major
The dcd process crashes when deactivating only 'swap' under ' interfaces <> unit <> output-vlan-map' with no other attributes present
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, this issue affects configurations where Virtual Local Area Network (VLAN) mapping is used, particularly in scenarios where only the swap attribute is applied under 'interfaces <> unit <> output-vlan-map'. Sequence of 'Deactivate -> Activate -> Commit' of the config hieararchy leads to crash of the device control daemon (dcd) process, potentially causing service disruption.
1873253
Major
The "show system storage" command output should show only true and distinct storages
Product-Group=junos
Severity=Major
On all Junos platforms, the "show system storage" command output is modified to list only all real UFS filesystem ie { 'ffs', 'tmpfs', 'ufs' } instead of virtual filesystem like '/var/jails/rest-api'.
1878430
Major
The mgd process crash is seen on all Junos and Junos Evolved platforms when FQDN is configured along with ephemeral database
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, Fully Qualified Domain Name(FQDN) configured in static database in presence of ephemeral database instances results in the mgd process crash. As a result, mgd session gets terminated and commit fails. There is no traffic impact due to this issue. The issue is seen with FQDNs that resolve to multiple IP addresses.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1853209
Major
Syslog forwarding intermittently stops post DUT reboot on virtual devices.
Product-Group=junos
Severity=Major
On virtual devices, on reboot, vpn may take time to come up. Meanwhile since mgmt_junos is first in the routing table, syslog gets bound to mgmt_junos and hence forwarding stops.
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1882490
Minor
BFD fail to establish over an IPsec tunnel on Juniper MX Series with the SPC3
Product-Group=junos
Severity=Minor
On Juniper MX Series platforms equipped with Services Processing Card version 3 (SPC3), Bidirectional Forwarding Detection (BFD) session establishment over an Internet Protocol Security (IPsec) tunnel may fail due to an unintended Time to Live (TTL) decrement on self-generated BFD traffic.
PR NumberSynopsisCategory: usf ipsec related issues
1796469
Critical
Commit triggers SI- interface flap on MX Series due to bandwidth mismatch
Product-Group=junos
Severity=Critical
On all MX Series platforms running Junos OS 22.1R1 and later, if Service Interfaces (SIs) are configured without explicitly setting bandwidth, the system compares the default CLI input (zero) with the platform-derived bandwidth value. This mismatch causes unintended SI interface re-creation (flaps) on the corresponding PIC and FPC.
1884595
Minor
Allow default route to be created provided st0 IFL is in a non-default routing instance.
Product-Group=junos
Severity=Minor
ARI now allows default route to be pushed if the corresponding st0 interface is configured in a specific routing instance.
PR NumberSynopsisCategory: usf jflow related issues
1900449
Minor
SPC3 continues to crash after attempting to configure NETFLOW inline-service flow-table-size and mpls-flow-table-size
Product-Group=junos
Severity=Minor
On all Junos OS MX240/MX480/MX960 devices with SPC3 (Services Processing Card version 3) card installed, the card will crash when there is NetFlow inline-service flow-table-size and mpls-flow-table-size configured

 

Extended Solution

23.4R2-S6 - List of Known issues

PR NumberSynopsisCategory: ISSU
1898501
Major
EX4650/QFX5120-48Y: ISSU incompatibility with previous releases
Product-Group=junosvae
EX4650/QFX5120-48Y: Older releases (that do not contain the 1882472 fix) are ISSU incompatible with current releases that have 1882472 fix.

Resolved In:
PR NumberSynopsisCategory: NFX Series Platform Software
1850987
Major
INSIGHTD messages logged every 5 seconds on NFX 250
Product-Group=junos
INSIGHTD messages logged every 5 seconds on NFX 250, these are harmless and can be hidden from syslog. jinsightd[19158]: JINSIGHTD_SENSOR_RESUBSCRIPTION: RetrySubscription: Triggering Re-subscription. retry_count 40005 jinsightd[19158]: JINSIGHTD_SENSOR_RESUBSCRIPTION: RetrySubscription: Triggering Re-subscription. retry_count 40006

Resolved In: junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
1858495
Major
The auto-negotiation is not working properly on NFX350 platform using 1 Gigabit Ethernet SFP
Product-Group=junos
On NFX350 platforms connected to certain peer devices over SFP 1 Gigabit Ethernet (GE) with auto-negotiation enabled at both ends, a communication issue occur during the initial connection between devices, causing a mismatch in their status. As a result, the port status on the peer device appear as up/down affecting the traffic.

Resolved In: junos:24.2R2-S2 junos:24.4R2 junos:25.2R1-S1 junos:25.4R1
PR NumberSynopsisCategory: SRX Fleming L2NG platform support
1868103
Minor
CoS shaping is not functional on IRB interfaces when the SRX1600 is in switching mode
Product-Group=junos
On SRX1600 platform, Class of Service (CoS) shaping does not work on IRB (Integrated Routing and Bridging) interfaces.

Resolved In: junos:24.2R2-S1 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Accounting Profile
1692411
Minor
Error messages are observed and incorrect values are returned for SNMP requests for pfe traffic statistics
Product-Group=junos
Below log messages will be seen while using SNMP and trying to poll "show pfe statistics notification" through MIB OID - 1.3.6.1.4.1.2636.3.44.1.1.2.1.2. "pfed: PFED_NOTIF_GLOBAL_STAT_UNKNOWN: xxxx"

Resolved In: evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.3R3-S5 junos:22.1R3-S3 junos:22.2R3-S3 junos:22.4R2-S2 junos:22.4R3 junos:22.4R3-S7 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
1911801
Major
AE IFL COS queues failed to be provisioned when there are 64 AE members and 100 IFLs configured on AE on MX platform 2020
Product-Group=junos
Trigger and cause: when an AE IFD is having 64 members under it, then sometimes COS queue stats CLI show/clear command for that AE IFL is not diplayed correctly/does not work properly. This is an intermittent issue when the RE DB max size is exceeded to store all the COS queue stats. Impact: CLI show command / Queue stats telemetry will not display the queue stats correctly intermittently on such scale. There is no impact to actual COS feature for any IFL. Workaround: when the number of children legs in AE IFD is reduced, this issue is not seen.

Resolved In:
PR NumberSynopsisCategory: "agentd" software daemon
1805445
Major
Return Error for unsupported options with GNMI RPCs
Product-Group=junos
On Junos and Junos OS Evolved platforms, the error message returned with unsupported encoding is changed for gnmi RPCs. It has no traffic impact.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.3X60 junos:23.4R2-S7 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.1R1
1839478
Major
/junos/system/linecard/interface/traffic/ sensor is seeing packet drops but there is no actual drops
Product-Group=junos
On all MX devices with ULC line cards (MPC10/11 and LC4800/9600), when subscribing to the /junos/system/linecard/interface/traffic/ native telemetry subscription path, the exported data includes the following containers: /interfaces/interface//interfaces/interface/state//interfaces/interfaces/state/counters. The picd and evo-aftmand-bt daemons are responsible for exporting data for these paths. When running the CLI command "show network-agent statistics detail, " it shows packet and byte statistics for each sensor per daemon. The picd daemon reports some drops due to an error in the CLI's data reporting. However, no actual packet drops occur. The issue arises from a bug in the bookkeeping code that tracks packet statistics, causing the CLI to incorrectly show drops even when no packets have been lost. This issue only affects the CLI display and does not impact actual packet transmission.

Resolved In: evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.2R2 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: MX YT-ZF Linecards Fabric Software Category
1891047
Minor
SFB is stuck in CMTY_SFB_STATE_OFFLINE_ACK_WAIT state and does not come offline or online
Product-Group=junos
SFB ( Switch Fabric Board ) is stuck in transitioning to offline, when SFB offline (sfb slot X offline) is attempted after disabling fabric planes (fabric plane X offline).

Resolved In: junos:24.2R2-S2-J5 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: BBE multicast related issues
1882756
Major
The bbe-smgd process crash triggered by a multicast event failure
Product-Group=junos
On all MX platforms with Broadband Edge Subscriber Management configured, the bbe-smgd process crashes when the multicast sync service add publish fails. This crash is automatically recovered by the system without requiring manual intervention.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Border Gateway Protocol
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:23.4X100-D40-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP-LU (Border Gateway Protocol-Labeled Unicast) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.

Resolved In: evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-J6 junos:24.2R2-S1-J4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
1889749
Major
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.

Resolved In: evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.2R3-S8-J22 junos:23.2R2-S6 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.

Resolved In: evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R1-S2-J10 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Express BT PFE L3 Features
1886043
Major
Few telemetry paths are not exported after router reboot
Product-Group=junos
Following a router reboot, the router management socket, telemetry infrastructure, and RE daemons (such as mib2d and rpd) become operational before AFT telemetry producers. Consequently, the external telemetry collector can establish a connection (e.g. sensor: "/interfaces" ; sample-mode) with the device as soon as the telemetry infrastructure and management interface are up and running. Since AFT-based producers require several minutes to come up. Therefore, na-grpcd sends a consolidated initial sync completion message to the external collector based on the local init-sync responses from the telemetry producers present at telemetry subscription time (mostly RE based producers). When an AFT application (evo-aftman-bt) becomes operational, a sensor is installed within it (if applicable).However, it is possible that the application has not consumed, thus not exported the interfaces data at the initial sync time (local to the application). As zero-suppression is activated after initial sync, a few statistics with a zero value will not be exported by the device.

Resolved In: evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:24.4R2-EVO evo:24.4X200-D20-EVO evo:24.4X200-D30-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: MX304 line card platform software
1884399
Major
FPC host /var/log/ is missing messages file for certain MX platform linecards
Product-Group=junos
This behavior of FPC's empty /var/log/messages is expected. Same observation is seen on MX304, LC4800, LC9600, MPC11E These platforms are ULC based evo platforms and does not required rsyslog daemon to log Logs expected in messages log file will be present in journalctl log and have to refer it for any such logs This is working as per the design for ULC based cards

Resolved In:
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1681716
Major
The device goes down when an FRU has over-temperature
Product-Group=junos
On MX240, MX480, and MX960, when the temperature for a particular FRU is above the over-temperature condition, the chassisd will start the timer(240 secs). If the over-temperature condition persists after completing 240secs, the chassis will be shut down instead of bringing down the particular FRU. This will impact the whole device traffic.

Resolved In:
PR NumberSynopsisCategory: Firewall Filter
1903874
Minor
[MX10008] cmd='ls -i /var/etc/filters/filter-define.conf' is logged every 1 second instead of every 30 seconds
Product-Group=junos
Root-Cause Client session not cleanedup on switching to backup router which was previously master and had clients connected on it. This left over session causes -ve timer t/o which treats it like expired clients and take immediate action w/o waiting for 30sec. below logs will be seen per second >show log messages | match filter-define | last 20 Aug 19 17:18:32.151 2025 root@re1 as root: cmd='ls -i /var/etc/filters/filter-define.conf' Aug 19 17:18:33.211 2025 rshd[52966]: root@re1 as root: cmd='ls -i /var/etc/filters/filter-define.conf' Aug 19 17:18:34.298 2025 rshd[52970]: root@re1 as root: cmd='ls -i /var/etc/filters/filter-define.conf' Aug 19 17:18:35.351 2025 rshd[52974]: root@re1 as root: cmd='ls -i /var/etc/filters/filter-define.conf' Aug 19 17:18:36.402 2025 rshd[52979]: root@re1 as root: cmd='ls -i /var/etc/filters/filter-define.conf' Impact No functional impact, only the lookup of masters data happens per second instead of 30 sec

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S7 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: EVPN ELAN/E-TREE
1882561
Minor
EVPN-MPLS BUM Traffic Disruption Due to Incorrect QinQ STag Insertion
Product-Group=junos
On Junos OS ACX5448/ACX710 platforms, the traffic towards the MPLS (Multiprotocol Label Switching) core Provider Edge (PE), specifically BUM (Broadcast, Unknown Unicast, and Multicast) traffic, has a QinQ (802.1ad) Service Tag (STag) added to the Customer (CTag). This insertion can disrupt traffic forwarding, leading to malformed packets or corruption of the destination MAC address in the inner Ethernet header.

Resolved In: junos:24.4R2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:24.1B1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4X30-D30 junos:23.4X9 junos:24.1B1 junos:24.1R1 junos:24.2R1 junos:24.4R2-S3
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
1846266
Major
The inet filters attached to the IRB interface will not function as expected
Product-Group=junos
On Junos QFX5k and EX4k platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, inet filters applied to Integrated Routing and Bridging (IRB) interfaces will not function as expected, and the associated actions of the filter are not enforced.

Resolved In: junos:24.4R1-S1 junos:24.4R1-S3 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.2R1-S1
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1901044
Major
EVPN ETREE BUM traffic is not forwarded after restart routing immediately
Product-Group=junos
EVPN ETREE BUM traffic is not forwarded after restart routing immediately

Resolved In:
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1861810
Major
The process rpd is cored while adding or removing dynamic-tunnels
Product-Group=junos
On all Junos Evolved platforms, the indexing of next hop while adding or deleting dynamic tunnels causes the rpd process to core and restart. This is a timing issue.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S1-J8-EVO evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.2R2-S4 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1871420
Major
Fragmented packets dropped in EVPN-MPLS scenario due to the IRB interface MTU limitation
Product-Group=junos
On all Junos platforms running in EVPN-MPLS (Ethernet Virtual Private Network over Multiprotocol Label Switching) scenarios, host-generated packets exceeding the IRB interface MTU (Maximum Transmission Unit) are fragmented. Only the first fragment is forwarded, while remaining fragments are dropped, leading to loss of control-plane traffic.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:20.2R3-S11 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: ISIS routing protocol
1841108
Major
Traffic drop is seen after GRES on ISIS peer
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in an ISIS(Intermediate System-Intermediate System) graceful restart scenario, helper node sends and programs its locally configured hold-time (180 secs) instead of the "Restart-duration" received as hold-time from DUT (210 secs), due to this incorrect update, the hold timer expires at the helper node before the GR (Graceful Restart) is complete on DUT and it causes a flap of ISIS adjacency on peer/helper Node.

Resolved In: evo:21.4R3-S10-EVO evo:22.3X80-D47-EVO evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S6 junos:23.2R2-S4 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Flow Module
1895420
Major
Memory allocation failures might occur on certain SRX platforms
Product-Group=junos
When traffic is processed application services which uses tcp proxy in flowd, the usage of object cache increases and possible to drop traffic.

Resolved In: junos:24.2R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
PR NumberSynopsisCategory: Firewall Policy
1859767
Major
Core is generated on the SRX Secondary node when performing an upgrade
Product-Group=junos
On SRX platforms working in HA cluster, with security policies configured with source identity, can generate a core in the secondary node when we upgrade the nodes from releases before 23.3 to releases starting from 23.3R1.

Resolved In: junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:25.1R1 junos:25.2R1
1894033
Critical
SRX5K traffic disruption due to REPFE policy sync issues from FQDN and file-serialization Errors
Product-Group=junos
On SRX5K series devices with file-serialization enabled, frequent policy synchronization issues occur between the Routing Engine (RE) and Packet Forwarding Engine (PFE) . This can result in traffic matching the incorrect default deny policy instead of matching the expected user-defined security policy. The issue is triggered during commit or request security policies check/resync operations, particularly when Fully Qualified Domain Name(FQDN)-based address objects are involved and have short Domain Name System Time to Live(DNS TTLs).

Resolved In: junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Key Management Daemon
1869769
Major
The kmd process crashes when device with MS-MPC has DPD enabled and a SA is deleted
Product-Group=junos
On all MX platforms with MS-MPC (Multiservices Modular PIC Concentrator), when DPD (Dead Peer Detection) is enabled under IPsec/IKE (Internet Key Exchange) VPN settings and for any reason an IPsec SA (Security Association) is deleted, the kmd process crashes. Due to the kmd process restart some disruption in tunnel establishment is seen.

Resolved In: junos:22.4R3-S7
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1892944
Minor
EX4300 VC L2ALD core after upgrade from 21.4R3-S3.4 to latest 21.4R3-S6 and above versions
Product-Group=junos
On EX4300 switch running Junos version 21.4R3-S6 and above, when SNMP polling is done for oid 1.3.6.1.2.1.17.7.1.4.5.1 with redundant-trunk-group interfaces configured there will be L2ALD memory leak seen on the switch.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.4R3-S12 junos:25.2R2 junos:25.3R1 junos:25.4R1
1905196
Minor
Stale entry in MAC-IP table affects ARP resolution
Product-Group=junos
On all Junos OS platforms, when an IP address already exists in the MAC-IP table as a remote entry and then an IRB (Integrated Routing and Bridging) interface is configured with the same IP address but a different MAC address, then the L2ALD (Layer 2 Address Learning Daemon) does not handle the update correctly, leading to incorrect ARP (Address Resolution Protocol) resolution.

Resolved In: evo:23.4R2-S7-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.4R2-S7 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1873587
Minor
[MX] "smid ../../../../../../src/junos/lib/libsdb/licsubs/bsd12/liblicense_subs_os.c liblic_subs_total_active_licenses_in_use XXX" logs flood in license_flex_subs_trace.log.
Product-Group=junos
"smid ../../../../../../src/junos/lib/libsdb/licsubs/bsd12/liblicense_subs_os.c liblic_subs_total_active_licenses_in_use XXX" messages can be seen so frequent interval in license_flex_subs_trace.log.

Resolved In: junos:24.2R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Odin Timing software
1810429
Major
ACX710 PTP ports marked 'passive' instead of 'master' during T-GM selection
Product-Group=junos
In a scenario where two T-GM devices (Telecom Grandmaster clocks) have identical BMCA (Best Master Clock Algorithm) parameters, except for steps removed or grandmaster ID, the ACX710 running the G.8275.1 profile can experience a failure in proper PTP (Precision Time Protocol) clock synchronization. This issue arises because the default BMCA is used instead of the expected Alternate BMCA profile in G.8275.1. This mismatch leads to incorrect PTP clock states, with master ports being marked as 'Passive' instead of 'Master'.

Resolved In: junos:23.2R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
em0 mgmt port is unreachable after RE switchover
Product-Group=junos
On MX10008 with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1876690
Major
ntp process may restart when issue the "show system ntp threshold" command
Product-Group=junos
The ntp (or xntpd) process is initialized when the "show system ntp threshold" command is issued. This has no impact to system operation.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1909719
Critical
Junos and Junos OS Evolved platforms experience high CPU after FPC reboot causing unpredictable issues with protocols (OSPF/ISIS/BGP, etc.) managed by PPMD
Product-Group=junos
After upgrading or rebooting Junos/Junos OS Evolved platforms, a CPU spike may be observed in the PPMD (Periodic Packet Management Daemon) process due to repeated internal message failures. This can lead to BFD (Bidirectional Forwarding Detection) authentication failures. Additionally, other protocols that rely on authentication and PPMD for packet distribution may also be affected, potentially resulting in traffic loss.

Resolved In: evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:21.2R3-S10 junos:21.2R3-S9-J5 junos:23.4R2-S5-J23 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1912250
Major
BFD sessions will not come up on Junos OS and Junos OS Evolved platforms due to keychain names overlapping
Product-Group=junos
On Junos OS and Junos OS Evolved platforms, where BFD with authentication key chain names are overlapping due to which BFD (Bidirectional Forwarding Detection) sessions will not come up in few scenarios like restart bfdd, restart ppmd, restart FPC.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.4R2-S6-J1 junos:25.4R1
PR NumberSynopsisCategory: RPD Interfaces related issues
1741485
Major
Unnecessary rsync messages causing issues
Product-Group=junos


Resolved In: evo:24.1R1-EVO junos:24.1R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1851629
Minor
Next-hop APIs to support LDP stitching cases over BGP routes pointing to list of indirects
Product-Group=junos
On all Junos and Junos Evolved platforms this is an enhancement for Nexthop APIs to support LDP stitching cases over BGP routes pointing to list of indirects next-hops.

Resolved In: evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.2R2
PR NumberSynopsisCategory: Resource Reservation Protocol
1881609
Minor
RSVP hello messages uses secondary address when primary/preferred address are present for same interface
Product-Group=junos
On all Junos and Junos OS Evolved platforms where RSVP (Resource Reservation Protocol) configuration is present and a RSVP enabled interface has 2 IP address of which one is configured as primary/preferred in that case the RSVP Hello message uses the secondary IP address to form neighborship.

Resolved In: evo:25.3R1-EVO junos:25.3R1
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated

Resolved In: evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1896022
Major
More bandwidth may be admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
If Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S9 junos:23.2R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1899178
Critical
Service session drops are observed when CPU throttling is configured on platforms with service cards installed
Product-Group=junos
On all Junos MX platforms that have MS-MPC or MS-MIC service cards installed, the use of the CPU throttling can cause the production service sessions to be dropped.

Resolved In: junos:21.2R3-S10 junos:21.2R3-S6-J16 junos:22.4R3-S7-J5
1901021
Major
Service-Set Configuration Bug Leading to Kernel Panic on Junos MX
Product-Group=junos
On Junos MX platforms with MS-MPC, when new rules are added to a service-set, the configuration size increases incrementally. This growth will cause failures during the commit process, potentially leading to a kernel panic. As a result, new configurations may not be successfully applied.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1806872
Critical
Junos OS: MX Series: When specific SIP packets are processed the MS-MPC will crash (CVE-2025-52982)
Product-Group=junos
An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA100088 [juniper.net] for more information.

Resolved In: junos:21.2R3-S9 junos:22.2R3-S6 junos:22.4R3-S6
PR NumberSynopsisCategory: SRX branch platforms
1845997
Major
Packet drops are observed in the VPLS environment on SRX380 platforms in packet mode
Product-Group=junos
On Junos OS SRX380 platforms in packet mode, when VLAN (Virtual Local Area Network)-VPLS (Virtual Private LAN Service) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 (Layer 2) unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.

Resolved In: junos:20.2R3-S10 junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:24.2R2 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1889549
Major
The XE interfaces of SRX380 platform with 1G SFP (fiber) are flapping continuously when LACP is enabled
Product-Group=junos
When LACP (Link Aggregation Control Protocol) is enabled using 1G SFP(Small Form-factor Pluggable)-fiber (such as SFP-SX, SFP-LX etc) over XE interfaces, frequent state transitions will repeatedly trigger configuration updates. Due to LACP instability, the interfaces will continuously flap. As a result, the port configuration will be re-applied automatically which leads to a loop of re-configurations until the LACP state stabilizes.

Resolved In: junos:24.2R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1712727
Major
Continuous vmcores observed on the secondary node when committing set system management-instance command
Product-Group=junos
On Junos SRX4600 device, when the "set system management-instance" command is synced to the secondary node, continuous VMcores are observed on primary and secondary nodes. The secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until management-instance knob is removed using "delete system management-instance"

Resolved In: junos:20.2R3-S8 junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S5 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S2 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.1R2 junos:23.2R1
1886757
Minor
Alarms for high usage in /var partition are not generated
Product-Group=junosvae
On Junos SRX4600/SRX4700/SRX1600/SRX2300/SRX4300 platforms, alarms for high usage at /var partition storage is not reported.

Resolved In: evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:25.2R1-S1 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1885754
Major
MX304 LNS: FPC restart and aft-trio core after LMIC OIR when SI pool spans both MICs
Product-Group=junos
On MX304 routers acting as LNS, an FPC restart and aftd-trio core may occur if a MIC is offlined (LMIC OIR) while the service-device pool of SI interfaces spans both MICs on the same FPC. This may result in transient loss of subscriber sessions and service impact.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1897464
Major
Memory allocation failure in all the FPCs inside the NH partition
Product-Group=junos
On all Junos OS platforms, the Cassis-alloc memory allocator fails to allocate memory in rare cases. This issue occurs when the system rounds up memory requests (for example, from 256 units to 512), but the allocation failure handling logic only considers the original requested size. Although extremely uncommon, this mismatch leads to repeated allocation failures on most of the FPCs, which leads to traffic drops and complete service impact.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:21.2R3-S10 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1704583
Major
Change in firewall filter triggers transient traffic drops in FPC
Product-Group=junos
On all Junos MX platforms with MPC10E/MPC11E/LC9600 line cards and on MX304, change or modification in Firewall filters will trigger transient packet drops.

Resolved In: evo:23.1R1-EVO evo:23.2R1-EVO junos:22.2R3-S3 junos:22.4R3 junos:23.1R1 junos:23.2R1
1840815
Major
[MX304] L2 policer may not work after rebooting chassis or fpc.
Product-Group=junos
After rebooting chassis or fpc, L2 policer may not work sometimes due to not reflecting configuration properly.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:21.2R3-S9 junos:23.2R2-J16 junos:23.2R2-S3 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1731587
Minor
Telemetry data not sent for /junos/services/label-switched-path/usage/ on MPC11E cards
Product-Group=junos
Telemetry Stats are not visible for MPLS LSP( RSVP Based) when the core interface is MPC11/MPC10.

Resolved In: junos:21.2R3-S6 junos:21.4R3-S5 junos:22.2R3-S3
1878057
Major
The out-of-order delete messages are seen after core facing interface with SCU configuration flaps
Product-Group=junos
On Junos MX platforms with MPC10E/MPC11E/LC4800/LC9600 line cards and on MX304, when core facing AE (Aggregated Ethernet) or FTI (Flexible Tunnel Interface) interface links are flapped and if they are having SCU (Source Class Usage) configuration with strict RPF (Reverse Path Forwarding) check, the out-of-order delete messages are seen which can lead to memory leak and further impact traffic.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2X1 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1891110
Major
A GRE tunnel configured with a tunnel key drops MPLS-encapsulated traffic
Product-Group=junos
On MX platforms with line cards MPC1-9, a Generic Routing Encapsulation (GRE) tunnel configured with a tunnel key drops Multi-Protocol Label Switching (MPLS) encapsulated traffic as it is unable to find the key.

Resolved In: junos:23.2R2-S5 junos:24.2R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1593200
Critical
Junos OS: A low privileged user can elevate their privileges to the ones of the highest privileged J-Web user logged in
Product-Group=junos
A Generation of Error Message Containing Sensitive Information vulnerability in the CLI of Juniper Networks Junos OS allows a locally authenticated attacker with low privileges to elevate these to the level of any other user logged in via J-Web at this time, potential leading to a full compromise of the device. Refer to https://kb.juniper.net/JSA11270 [juniper.net] for more information.

Resolved In: evo:21.1R2-S1-EVO evo:21.2R1-S2-EVO evo:21.2R2-EVO evo:21.2R3-EVO evo:21.3R1-EVO evo:21.3R2-EVO evo:21.4R1-EVO junos:15.1R7-S11 junos:18.3R3-S6 junos:18.4R2-S9 junos:18.4R3-S10 junos:19.1R2-S3 junos:19.1R3-S7 junos:19.2R1-S8 junos:19.2R3-S4 junos:19.3R3-S4 junos:19.4R3-S6 junos:20.1R3-S2 junos:20.2R3-S3 junos:20.3R3-S1 junos:20.3X75-D442 junos:20.4R3-S1 junos:21.1R2-S1 junos:21.1R3 junos:21.2R1-S1 junos:21.2R2 junos:21.2R3 junos:21.3R1 junos:21.3R2 junos:21.4R1 junos:22.3X60 junos:24.4R1-S3
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: PTX/QFX10002/8/16 specific software components
1882584
Minor
SERDES link errors observed on SIB8 modules due to power rail instability
Product-Group=junos
On Junos platforms utilizing the JNP10008-SF (aka SIB8), systems experience CRC errors on fabric links between the SIB and the FPC (Flexible PIC Concentrator). These errors are attributed to electrical noise on an internal power rail within the SIB. This condition will lead to multiple FPC-to-SIB link failures, potentially affecting traffic forwarding and overall fabric stability.

Resolved In: junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4X50
PR NumberSynopsisCategory: VMHOST platforms software
1795506
Minor
A non service impacting warning message 'Failed to set 'memory.limit' will be observed
Product-Group=junos
On all Junos OS Evolved platforms a warning message "Failed to set 'memory.limit_in_bytes' attribute on '/user.slice' to '-1': Invalid argument" would be observed.

Resolved In: evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:24.2R1-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2X1 junos:24.4R1
PR NumberSynopsisCategory: Virtual Private LAN Services
PR NumberSynopsisCategory: usf ipsec related issues
1876801
Major
IPsec-inside-IPsec tunnel establishment fails on MX platforms with SPC3 cards
Product-Group=junos
On MX platforms equipped with SPC3 cards, the establishment of the inner IPsec tunnel fails in an IPsec-inside-IPsec tunnel setup. This occurs because the service PIC's forwarding process incorrectly attempts to punt IKE packets to the Route Engine (RE) and cannot resolve the required internal fabric path.

Resolved In: junos:22.4R3-S8 junos:22.4X6 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

Resolved In: evo:25.4R1-EVO junos:20.2R3-S11 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Unified Services Framework
1912459
Critical
The nsd process crash will be seen on MX platforms when configuration change is commited using ephemeral database
Product-Group=junos
On MX platforms with SPC3 line cards, when the ephemeral configuration-database is configured, parsing of the respective hierarchies by nsd (Network Security Domain) was faulty and leads to the daemon crash.

Resolved In: evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S5-J32 junos:24.2R2-S4 junos:25.4R1

 

Modification History

First publication 2025-11-21