Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification (SRN)
Low/NotificationSoftware Release Notification (SRN)

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX running Junos software

Alert Description

Junos Software Service Release version 22.4R3-S8 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Please review

Solution

Junos Software service Release version 22.4R3-S8 is now available.

22.4R3-S8 - List of Fixed issues

PR NumberSynopsisCategory: SPC3 HW and SW Issues
1774707
Minor
SPC3 PIC heartbeat failure
Product-Group=junosvae
Severity=Minor
SRX high end chassis SPC3 card PIC can encounter an unexpecting condition not responding to heartbeats, leading to the SPC card reboot.
PR NumberSynopsisCategory: SRX ISSU infra related issues
1882569
Major
ISSU getting aborted due to configuration-synchronize failure on Junos SRX platforms
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having chassis cluster configuration-synchronize configured, ISSU (In-Service Software Upgrade) gets aborted due to a configuration synchronization (config-sync) failure and the Redundancy Group (RG) priority is set to 0, preventing a successful failover during the ISSU process resulting in the ISSU process gets aborted causing the upgrade failure.
PR NumberSynopsisCategory: "agentd" software daemon
1688613
Major
Telemetry sensor will not stream data if using key value as wildcard '*' character for gNMI in the PFE supported sensor
Product-Group=junos
Severity=Major
On MX platforms, when key value as wildcard '*' character for gNMI (gRPC Network Management Interface) in the PFE supported sensor is used, the telemetry sensor will not stream any data.
1826196
Major
The error messages will be observed while configuring native sensor paths
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms with telemetry enabled, configuring any native sensor path like "set services analytics sensor interface_stats resource /junos/system/linecard/optics " will not be enabled unless "/" is added at the end. This will not have any traffic impact.
PR NumberSynopsisCategory: MPC Fusion SW
1824215
Major
Incorrect speed assigned to 1G interfaces on MPC2E-3D-NG high-capacity line card modules.
Product-Group=junos
Severity=Major
During the insertion or removal of optics on 1 Gbps interfaces attached to MPC2E-3D-NG , the interface speed may be incorrectly set to 2 bps.
PR NumberSynopsisCategory: SRX2000/50000 issue
1793262
Minor
FPC reboot seen on SRX platforms with SPC3 card post RG failover
Product-Group=junosvae
Severity=Minor
On SRX5K platforms with SPC3 card, the FPC (Flexible PIC Concentrator) card reboots when a RG0 failover (in chassis cluster scenario) is performed. Due to this, traffic impact can be seen.
PR NumberSynopsisCategory: BBE ACI VLAN related issues
1836502
Major
The bbe-smgd process crashes when a BNG subscriber re-logs in after dvlan deletion
Product-Group=junos
Severity=Major
On all Junos MX Series platforms, when running the Broadband Network Gateway (BNG) in IP packet-trigger mode, a client re-login while the dvlan( dynamic Virtual Local Area Network) is in a deleting state causes the bbe-smgd (Broadband Edge - Subscriber Management Daemon) daemon to crash and generate a core dump.
PR NumberSynopsisCategory: Border Gateway Protocol
1679645
Minor
RSYNC session flaps between Master and Standby RE might result in errors on ephemeral commits during ISSU
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, errors might be seen on ephemeral commits during ISSU.
1851205
Major
Junos OS and Junos OS Evolved: When route validation is enabled, route validation cache connection establishment leads to an rpd crash (CVE-2025-52958)
Product-Group=junos
Severity=Major
A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100066 [juniper.net] for more information.
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
Severity=Major
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
Severity=Major
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned on a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB (Segment Routing Global Block), this mismatch can result in incorrect label forwarding.
1887911
Major
The rpd process crashes after BGP configuration commits involving group-split-size and RIB-sharding
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring "group-split-size" with BGP RIB-sharding(Border Gateway Protocol Routing Information Base Sharding) can lead to a crash in the routing protocol daemon (rpd) when a route update for a non-negotiated NLRI(Network Layer Reachability Information) is received in the update thread. This occurs if the NLRI is targeted at other BGP peers within the group that have negotiated it.
PR NumberSynopsisCategory: Issues related to Common BIOS on x86 based designs
1746973
Minor
Enhancement to automatically restore LKG image from an alternate location
Product-Group=junosvae
Severity=Minor
On VMhost based platforms, if BIOS gets corrupted, LKG image is used to restore BIOS. For some reason, if the LKG image itself gets corrupted, there is no way to recover the BIOS. The usual way to reinstate the LKG is manual, but with this fix it is automatic.
PR NumberSynopsisCategory: MX304 Chassis specific platform
1675268
Critical
MX304:: Observed spmbpfe core on RE1 when installed image on both the REs
Product-Group=junosvae
Severity=Critical
Sometimes cores are reported on backup RE during init after a reboot etc. When the backup RE initialization is being done and system is busy, some commands executed in context of spmbpfe are taking more time to complete due to the initial heavy lifting by the kernel, In this stage, if in case the commands from spmbpfe process do not complete for >2.5 seconds, then there are chances of spmbpfe cores. This is a temporary issue seen on backup RE during init time only. This may not be impacting because if in case spmbpfe process crashes due to this, it would restart by itself and continue to init and run once the initial high cpu condition has passed. It should not cause any functionality or performance impact; especially since it is reported only on backup RE.
1731237
Minor
MX304 Major Alarm " Host 0 detected AER correctable error" after RE switchover.
Product-Group=junosvae
Severity=Minor
MX304 Major Alarm " Host 0 detected AER correctable error" after RE switchover.
PR NumberSynopsisCategory: MX304 Routing Engine issues
1857833
Major
The chassisd process crash is seen after the device reboot when chassisd stalls after configuration commit
Product-Group=junos
Severity=Major
On all VMHost platforms, the chassisd crash can be seen, which can also lead to mastership switchover. This is mainly caused by a configuration commit (no specific configuration required) followed by a reboot.
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1856231
Minor
The "Input errors" shows 0 even when the "Resource errors" in "show interface extensive" CLI command have non-zero number
Product-Group=junos
Severity=Minor
On all Junos platforms, the "Resource error" were not accounted while calculating "input error" in "show interfaces extensive" CLI command. This is not traffic impacting.
PR NumberSynopsisCategory: Virtual-chassis platform/chassisd infrastructure PRs for MX
1774302
Major
MXVC:MPC10E can not reach VC-Mm when re1 is VC-Mm
Product-Group=junosvae
Severity=Major
MXVC:MPC10E can not reach VC-Mm when re1 is VC-Mm. The issue happens only for Linux Based cards and Ukern ie non Linux based cards will work fine.
PR NumberSynopsisCategory: MX Platform SW - UI management
1884816
Major
MIC details not polling when SNMP MIB walk is performed after Junos OS upgrade
Product-Group=junos
Severity=Major
Post upgrading the Junos OS for MX10K platform from 21.4R3-S3.4 to higher versions, the Simple Network Management Protocol (SNMP) Management Information Base (MIB) walk is not polling Modular Interface Card (MIC) details impacting the SNMP monitoring.
PR NumberSynopsisCategory: Software defects reported in Chivas NPI
1879559
Minor
VMHost RE 1 host lcmd Application failed alarm seen after image upgrade and install
Product-Group=junos
Severity=Minor
When VMHost image on both routing engines are installed and rebooted simultaneously, the EEPROM read issue is observed intermittently in RE1. This leads to CB driver not being loaded in RE1 and further leading to LCMD crash.
PR NumberSynopsisCategory: Device Configuration Daemon
1845370
Major
Interface not added back to AE bundle with multiple changes in single commit
Product-Group=junos
Severity=Major
On all Junos platforms when speed is changed on an interface which is part of AE bundle, interface will be removed and added with the updated speed. When some other operation such as interface disable is configured along with speed change on the interface in the same commit, then the interface is not removed and added to the bundle, it can cause other AE interfaces flap and traffic drop.
1865181
Major
Memory leak occurs when dcd daemon processes service configurations related signal in short interval of time
Product-Group=junos
Severity=Major
On all Junos platforms, memory leak in dcd (Device control daemon) process is observed when a specific signal related to configurations generated by other services is generated in short interval of time and sent to dcd to process, the memory consumption of dcd would increase and if it goes above the threshold the dcd process will crash and restart again. This is a rare case scenario and will not impact any other services.
PR NumberSynopsisCategory: ACX platform interface issues
1747140
Major
QSFP interfaces show additional flap during PFE bringup
Product-Group=junosvae
Severity=Major
On Junos ACX5448 platform, the QSFP (Quad Small Form-factor Pluggable) interfaces can possibly see a momentary flap during device or pfe bring up.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1906960
Minor
GNF will be in offline state and its mastership state is set to backup on both routing engines when RE is forced to boot from SSD2 or normal RE switchover on MX platforms
Product-Group=junos
Severity=Minor
On MX platforms supporting In-chassis Junos Node Slicing, the GNF (Guest Network Function ) will be in an offline state, and its mastership state is set to backup on both routing engines. This issue occurs when RE (Routing Engine) is forced to boot from SSD2 (Solid State Drive) or with normal RE switchover as well. This is a timing issue where both GNF's become masters and once this timing window is passed GNF will be in offline state, impacting the traffic.
PR NumberSynopsisCategory: Manageability for Node Virtualization
1712849
Minor
JDM Container 'show system cpu' CLI shows invalid or no output after GNF deployment
Product-Group=junosvae
Severity=Minor
On Junos platforms with containerized nodeslicing (JDM Container), deploying a GNF (Generic Network Function) causes the 'show system cpu' command inside JDM to fail, showing invalid or no output.
1896494
Minor
JDM to JDM connectivity is broken when a commit synchronize full is executed to pass GNF configuration between routing engines
Product-Group=junosvae
Severity=Minor
After doing software upgrade on node slicing system, connectivity between external REs running JDM instances breaks upon executing commit synchronize force full .Initially, connections between JDM instances and BSYS appear to be functioning properly.
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1872743
Major
Packet loss or retransmissions observed on MX platforms using SFP-T transceivers
Product-Group=junos
Severity=Major
On MX10004, MX10008 and MX10016 platforms with LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) transceiver will lead to packet loss or retransmissions on neighboring devices due to incorrect Inter-Packet Gap (IPG) handling.
1887864
Major
Packet loss observed with SFP-T modules on MX10K LC480 line cards due to IPG misalignment
Product-Group=junos
Severity=Major
On Junos MX10004, MX10008, and MX10016 platforms using LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) copper transceivers, both Juniper and NON-JNPR (third-party), causes incorrect handling of the Inter-Packet Gap (IPG). Packets are transmitted with an IPG of 5 bytes instead of the required 8 bytes, leading to packet loss or retransmissions on connected peer devices. The issue is silent, with no logs or alarms.
1899711
Minor
Unexpected packet retransmissions and traffic drops observed on SFP-T (1G copper) interfaces on LC480 line cards
Product-Group=junos
Severity=Minor
On MX10004, MX10008, and MX10016 platforms with LC480 line cards using 1G SFP-T (copper) transceivers, an issue in the PHY caused frames to be transmitted too closely together, leading to packet loss or retransmissions.
PR NumberSynopsisCategory: jdhcpd daemon refactored for evo
1816246
Major
[ACX7000 Series] DHCPv4/v6 packets may be dropped because DHCP packets are not routed to kernel after initial jdhcpd starts
Product-Group=junos
Severity=Major
Under certain conditions, the DHCP session database becomes unstable or JDHCPD not getting IFL/IFD events which cause DHCP packets to fail to route to the kernel and then leads to DHCP packet drop.
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1865403
Major
Memory leak is observed when Telemetry is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms having Telemetry configured, the memory allocations in 512 bytes slab that are seen to be growing in problem state, are related to write on a unix domain socket (internal to application). Since the data is not read, the send buffer keeps growing and the associated memory does not gets released. Every telemetry response from the producer does a 1 byte write on this socket and over a period of time the send buffer gets full. The default size of the unix socket send buffer is set to 512MB. But there is no functional impact.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1801258
Major
Traffic loss is seen on some of the streams on EVPN-VXLAN stitching setup
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms configured with EVPN-VXLAN, the proxy-flag was being reset to GLOBAL across all Bridge-Domains, even when modifications were made to just one. This flag plays a critical role in a Centrally Routed Bridging (CRB) topology, as it indicates the use of crb-proxy-mac for reARP (Reverse Address Resolution Protocol) operations. Due to this the reARP was skipped wrong for few BD traffic.
1889335
Minor
Traffic drop is observed in an EVPN multihoming as the MAC route points to the ESI interface when the CE (ESI) IFD flaps
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, in an Ethernet Virtual Private Network (EVPN) MultiHoming setup with Ethernet Segment Identifier (ESI) configured under logical Interface (IFL) (CE-facing), when the corresponding IFD (Physical Interface) flaps, the MAC route will point to the ESI interface, while it should point to the Multihoming CE (Customer Edge) interface. This results in traffic loss.
PR NumberSynopsisCategory: EVO Socket replication
1895827
Major
Adding a new key to authentication-key-chain causes kernel crash
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, when setting/changing the tolerance value of key-chain to max value of 4294967295 and committing and then adding a new key to a key-chain and performing a commit action will result in kernel crash. Device self-recovers after the crash. "show system core-dumps" can be used to check the core. Core name starts with vmcore*
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1848993
Major
The data plane will be out of sync when migrating to EVPN A/A stitching with Vanila VXLAN (PIM Multicast)
Product-Group=junos
Severity=Major
On MX platforms, to improve the convergence of node failures in EVPN MH interconnects with Data Plane VXLAN, migrating to an Active-Active setup may cause the data plane to become out of sync for ARP entries. The gateway learns the MAC address and advertises it to the peer gateway. However, on the peer gateway, some MAC-IP entries may remain stuck in the 'Unresolved' (Ur) state.
PR NumberSynopsisCategory: EX4100 RE, Platform Infra, Drivers
1875603
Minor
EX4100/EX4400/EX4000 (Standalone or VC): Fan Spinning Underspeed or Overspeed Minor Alarm
Product-Group=junos
Severity=Minor
On EX4100, EX4400, and EX4000 platforms (including VC setups), alarms occasionally are raised for fan underspeed or overspeed on FPCs when the fan speed momentarily exceeds or falls below the software-defined thresholds. These alarms are observed even during normal fan operation and do not indicate a real hardware failure. There is no traffic or service impact. This is a cosmetic issue that only generates yellow (minor) chassis alarms.
PR NumberSynopsisCategory: EX interfaces issues
1825281
Major
Random ports of EX4400 will not be created on upgrade or reboot
Product-Group=junos
Severity=Major
On EX4400, random interfaces will not be created when the device is upgraded or rebooted. Interfaces will not be listed in the device and will affect all functionalities of the optic or interface.
1833177
Major
Show chassis led displays green when link is down on EX2300 and EX3400
Product-Group=junos
Severity=Major
On EX2300 and EX3400 platforms, after execute 'show chassis led', the status LED of uplink port always displays green even when link is down. Physical LED status functions correctly.
PR NumberSynopsisCategory: EX4400 PFE software
1866815
Major
On Junos QFX5000 series and EX4000 series platforms, an fxpc process crash triggers an FPC reboot
Product-Group=junos
Severity=Major
On QFX5000 series and EX4000 series platforms running Junos Operating System (OS), during normal operation, the fxpc process crashes due to a routing entry continues to reference a HOLD next-hop after the associated topology neighbor has already been removed by the system causing the Flexible Physical Interface Card (PIC) Concentrator (FPC) to reboot and generate a crash file.
1894136
Major
Physical Interface device remains down by continuous system reboots on EX and QFX5K platforms
Product-Group=junos
Severity=Major
On Junos EX and QFX5K platforms in a scaled setup having high number of Virtual Chassis members (5 or more VC members) , the physical interface device (IFD) remains down when continuous system reboots are performed (5-6 reboots), thus impacting network availability. This is a rare case scenario.
PR NumberSynopsisCategory: EX POE
1876675
Major
On EX4100/EX4400s platforms PoE powered devices connected do not come up when adding a second power supply unit
Product-Group=junos
Severity=Major
On EX4100/EX4400s platforms using Perpetual PoE and Fast PoE, if power is lost due to one PSU (Power Supply Unit) being removed and the system shuts down, the PoE-powered devices will not automatically power back on when the system is restarted using the other PSU (e.g., switching from slot 0 to slot 1 or vice versa).
1879702
Major
There is a PoE short circuit alarm after upgrading the device
Product-Group=junos
Severity=Major
On all Junos EX2300, EX3400, EX4400, EX4300 platforms running in Virtual Chassis or Standalone and during normal operation of the switch when POE (Power Over Ethernet) get port status command fails to read then software reads the garbage value from the response buffer and sends to chassisd due to which it results in PoE short Circuit alarm. However, this is a non-existent PoE alarm and non-impacting issue.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1884163
Major
IFL Memory Leak on QFX10K8/16 device
Product-Group=junos
Severity=Major
On QFX10K8/16 , IFL memory is not freed on non-local interface of FPC during configuration changes (eg: IFL delete/deactivate) for L3IFL/L2IFL on AE/Scalar interfaces. Fix is present in common code and risky. It is a day one issue and the per IFL leak is minimal (0.00016% of total Kernel heap size) .
PR NumberSynopsisCategory: SRX1500 platform software
1815083
Major
False SNMP traps for power supply unit failure generated on Junos SRX1500 platforms
Product-Group=junos
Severity=Major
On Junos SRX1500 platforms, false SNMP traps for power supply unit failure generated due to the hardware issue. It has no traffic impact.
1876867
Major
FPC goes offline and srxpfe core dump is generated during the system normal operation or boot-up
Product-Group=junosvae
Severity=Major
FPC (Flexible PIC Concentrators) on SRX1500 device goes offline and generates srxpfe core dump on system boot-up or normal operation in a rare timing scenario. This issue cause a traffic impact.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1706125
Major
ifHCOutOctets unexpected spikes in value
Product-Group=junos
Severity=Major
On SRX4100 and SRX4200 platforms, the ifHCOutOctets interface counter values may sometimes incorrectly spike and exceed interface speed.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1846294
Major
Memory Leak: Memory leak is detected with rpd task blocks "rpd-trace"
Product-Group=junos
Severity=Major
Memory Leak: Memory leak is detected with rpd task blocks "rpd-trace"
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1827648
Minor
ARP not learned on Switch Leading to Traffic Drop in EVPN-VXLAN Setup
Product-Group=junos
Severity=Minor
On all Junos QFX series platforms in an EVPN (Ethernet Virtual Private Network) VXLAN (Virtual Extensible Local Area Network) setup with CRB (Centralized Routing Bridge) architecture, ARP packets are not being learned, leading to traffic forwarding issues. This problem arises when ARP packets are sent from the firewall to the spine switches. The issue is linked to IRB (Integrated Routing and Bridging) handling and bridge domain re-incarnation, which triggers ARP request failures and impacts L3 forwarding.
1871420
Major
Fragmented packets dropped in EVPN-MPLS scenario due to the IRB interface MTU limitation
Product-Group=junos
Severity=Major
On all Junos platforms running in EVPN-MPLS (Ethernet Virtual Private Network over Multiprotocol Label Switching) scenarios, host-generated packets exceeding the IRB interface MTU (Maximum Transmission Unit) are fragmented. Only the first fragment is forwarded, while remaining fragments are dropped, leading to loss of control-plane traffic.
PR NumberSynopsisCategory: ISIS routing protocol
1847557
Critical
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.
1859099
Minor
Memory leak is observed for certain topologies when TI-LFA is configured
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms , where IS-IS/OSPF is enabled and TI-LFA (post-convergence-lfa) is configured in a SR (Segment Routing) environment. In a scenario where the computed backup paths to reach a destination is fetched from the more than one originator, duplicate paths gets computed for certain topology combinations and the clean-up of infosid list doesn't happen this leads to memory leak that might eventually lead to high memory usage and result in rpd crash and thus impacting traffic.
PR NumberSynopsisCategory: jdhcpd daemon
1872292
Major
DNS resolution will fail for DNS entries written to "resolv.conf"
Product-Group=junos
Severity=Major
On all Junos platforms with ZTP (Zero-Touch Provisioning) configuration, when the configuration is completely removed, DNS (Domain Name System) resolution for DNS entries written to "resolv.conf" will fail.
PR NumberSynopsisCategory: Flow Module
1872613
Minor
PFE crash is observed when PFE processes the traffic passing through the dedicated fabric link
Product-Group=junos
Severity=Minor
On the Junos OS SRX4600 platform, when PFE (Packet Forwarding Engine) processes the IPv4/IPv6 traffic passes through the dedicated fabric link, PFE crash is observed. This issue happens when PMI (PowerMode IPsec) is enabled (by default) and flow session accessing stale values.
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
Severity=Major
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.
PR NumberSynopsisCategory: SRX PFE side multicast
1854130
Major
PIM IP ESP packet fragments dropped in SRX platform
Product-Group=junos
Severity=Major
Protocol Independent Multicast (PIM) fragmented packets using IP Protocol 50 (Encapsulating Security Payload - ESP) are dropped when traversing SRX devices operating in flow mode.
1877771
Major
The flowd process crash is observed on all Junos SRX platforms in multicast scenario with PIM
Product-Group=junos
Severity=Major
On all Junos SRX platforms, the flowd process crash will be observed when device is acting as MHR (Middle Hop Router) and PIM (Protocol Independent Multicast) register packet from FHR (First Hop Router) tries to build the control/data session for the same PIM register packet.
PR NumberSynopsisCategory: SRX PFE side GRE/IPIP/DS-Lite/IPSec/PIM/VXLAN tunnel
1880253
Major
Traffic drops will be observed for any traffic going over the GRE tunnel post the st0 tunnel interface flap
Product-Group=junos
Severity=Major
On Junos OS SRX platforms with Generic Routing Encapsulation (GRE) over a Secure Interface Tunnel (st0) is configured, if the st0 interface flaps, the GRE tunnel comes up before the st0 interface(which is due to a timing issue), results in a mismatch in the hash values between session packets and the GRE tunnel, which will cause traffic drop.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1850967
Major
Traffic loss and high CPU utilization of iked on SRX MNHA from back-to-back HA transitions
Product-Group=junos
Severity=Major
On SRX platforms with MNHA (Multi-Node High Availability), back-to-back state transitions in HA (High Availability) before the control plane is ready cause the iked (Internet Key Exchange daemon) to get stuck at high CPU utilization, resulting in traffic loss.
1895790
Major
Backup node stuck in cold sync failure after all FPCs reset due to SPC crash files in SRX chassis cluster
Product-Group=junos
Severity=Major
On all SRX platforms, in a chassis cluster scenario, the PFE crashes on the backup node. After the crash files are fully generated, this triggers a reset of all FPCs. Following the crash and FPC resets, the backup node enters a cold sync failure state and remains in that state until it is manually rebooted.
PR NumberSynopsisCategory: l2 flow module
1852047
Major
Traffic drops are observed when SRX380 platform is configured in l2 transparent-bridge mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms, traffic drops are observed due to the default drop ACL (Access Control List) (L2 unknown unicast packets) getting applied. The issue happens when the device is configured in L2 (Layer 2) transparent-bridge mode.
PR NumberSynopsisCategory: Firewall Policy
1847877
Major
The mgd process crash is observed during large amount of configurations
Product-Group=junos
Severity=Major
On all SRX platforms, the Management Daemon (mgd) core is seen after a large number of configurations executed when configuring the network address book and attach it to a security policy.
1859554
Minor
Wrong service-name display in SRX RT_FLOW traffic log.
Product-Group=junos
Severity=Minor
On SRX platforms, wrong service-name might display in SRX RT_FLOW traffic log.
PR NumberSynopsisCategory: JSR Application Services
1792714
Major
pub-brokerd crash due to rapid connect-disconnect events on SRX platforms with MNHA
Product-Group=junos
Severity=Major
On all SRX platforms with Multi-Node High Availability (MNHA) enabled, a rare corner-case scenario involving a rapid sequence of connection attempts immediately followed by disconnections can trigger an unhandled assertion in the pub-brokerd process. This results in a core dump and full-service disruption on the affected node. Automatic recovery is not supported in this scenario, and manual intervention is required. The issue is rare and relies on a specific timing condition.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1877966
Minor
Some new VPN tunnels are not coming up on SRX5K platforms with SPC3
Product-Group=junos
Severity=Minor
On SRX5K platforms with SPC3 installed, IPSec (Internet Protocol Security ) tunnels with iked which reuses the same IKE (Internet Key Exchange) gateway peer IP, could be observed not re-establishing.
1889298
Major
On SRX devices running Multi-Node High Availability (MNHA), the iked process crashed due to repeated negotiation failures, which led to a VPN outage.
Product-Group=junos
Severity=Major
On SRX devices running Multi-Node High Availability (MNHA) and IPSec, the IKED process may crash due to a high number of unsuccessful VPN negotiations. To restore the VPN environment, the active node must be rebooted.
1892539
Major
IKE Processing Order Causing Gateway Misconfiguration and Tunnel Failures
Product-Group=junos
Severity=Major
On SRX platforms, when both gateways, the local-address and the IFA (Interface address) are changed and if the IKE (Internet Key Exchange) configuration is processed before the IFA update, gateways lacking an explicit local-address will be misconfigured, leading to tunnel failures.
PR NumberSynopsisCategory: PFE infra to support jvision
1706155
Minor
The PFE fabric telemetry data(128.0.0.xx -> 128.0.0.1 udp 2000) was forwarded to data port
Product-Group=junos
Severity=Minor
The packets with internal ip address 128.0.0.xx -> 128.0.0.1 and upd port 2000 might be forwarded out the default egress interfaces. Such packets are telemetry data for PFE fabric sensor, which should be sent to routing-engine only.
PR NumberSynopsisCategory: Platform infra to support jvision
1740142
Minor
Incorrect GNMI sensor interval time used by some FPCs due to satellite configuration
Product-Group=junos
Severity=Minor
On Junos Fusion setup, when the satellite configuration is present, extended ports are used and subscribe to /junos/system/linecard/interface/traffic/ from telemetry, the telemetry data is exported at incorrect GNMI sensor interval time for some FPCs. Extended ports are not qualified for telemetry support.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: authd (AAA) library code
1860913
Major
The authd process crashes when /etc/resolv.conf file is empty
Product-Group=junos
Severity=Major
On Junos OS Evolved ACX platforms, when DHCP (Dynamic Host Control Protocol) local server is configured without domain-name specified, the authd process crash may be observed. There will be no forwarding traffic impact due this issue, however, new DHCP client requests will not be answered.
PR NumberSynopsisCategory: PTX1000 platform
1770739
Critical
Reboot on PTX1k with image 22.3x60 causes fpc to reboot with "Fatal ASIC initialization error, Offlining FPC" Error message
Product-Group=junosvae
Severity=Critical
Reboot on PTX1k with image 22.3x60 causes fpc to reboot with "Fatal ASIC initialization error, Offlining FPC" Error message times
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1727066
Major
Extremely fast interface flaps in MPC10E line-card causes cpu to hog which leads to fpc reboot.
Product-Group=junos
Severity=Major
Extremely fast interface flaps in MPC10E line-card causes cpu to hog which leads to fpc reboot.
PR NumberSynopsisCategory: SW PRs for MPC10E PMB
1731258
Major
MPC10 and MPC11 line cards experiencing unexpected reboots
Product-Group=junosvae
Severity=Major
Line cards such as MPC10 and MPC11 experience unexpected reboots because of CPU C-states which are enabled by default thus impacting the customer production traffic.
PR NumberSynopsisCategory: Multicast Routing
1863470
Major
The rpd crash due to memory corruption in PIM/MSDP network
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, enabling PIM (Protocol Independent Multicast) or MSDP (Multicast Source Discovery Protocol) may cause a rare memory corruption during the update of the MSDP Source Active route. This issue primarily affects highly scaled environments, leading to rpd (routing protocol daemon) coredumps and potential traffic loss.
1876458
Major
MX960 mcsnoopd core dump during rt_mcnh_nh_release
Product-Group=junos
Severity=Major
When the mcsnoopd process (use for L2 multicast) creating a new NH , our system takes a reference to it. However, if this reference is released too quickly, the old NH might be deleted before its references are fully cleared. This may cause the mcsnoopd process to restart.
PR NumberSynopsisCategory: MX10K platform
1751785
Major
FPC reboots observed during ISSU on MX10008/MX10016 resulting in ISSU being unsuccessful
Product-Group=junosvae
Severity=Major
Unified in-service software upgrade (ISSU) on MX10008/MX10016 containing LC480 cards might fail and result in the FPCs to reboot causing traffic interruption and potential service impact. ISSU error would also be reported during this time and lead the reboot of the FPCs.
PR NumberSynopsisCategory: Track Mt Rainier RE platform software issues
1776854
Major
VM Core with the reason "panic: deadlres_td_sleep_q: possible deadlock detected" might be seen on all JUNOS vmhost platforms
Product-Group=junosvae
Severity=Major
PR1735843 has fixed a VM core on ACX5448 platform with the reason "panic: deadlres_td_sleep_q: possible deadlock detected". The same issue might also be seen on all other JUNOS vmhost platforms but with a different root cause.
1782062
Minor
The interface fxp0 deactivation or activation is not captured due to improper date format
Product-Group=junosvae
Severity=Minor
On MX VMHost platforms, the interface fxp0 state is not captured since the script to bring up the interface is not parsing the output from the date field.
PR NumberSynopsisCategory: Olympus MX/SPC3 Node slicing
1880218
Minor
GNFs in Junos Node Slicing will stop responding when both REs are rebooted at the same time and master RE fails to recover
Product-Group=junos
Severity=Minor
On Junos MX480/MX960/MX2008/MX2010/MX2020 platforms using Node Slicing (in-chassis model), if both REs (Routing Engines) in the BSYS (Base System) are rebooted at the same time and master RE fails to come back up without switching mastership, the GNFs (Guest Network Functions) will become unresponsive. This will cause all services running on those GNFs to be impacted.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1874365
Minor
Route for disabled fxp0 interface remains in PFE after re-enabling the interface
Product-Group=junos
Severity=Minor
On Junos platforms, when the fxp0 management interface is configured with an IP address and then disabled, a user route with a reject next-hop is created and installed in the PFE. After re-enabling the interface, this reject route is removed from the forwarding table but remains in the PFE. Rebooting the Routing Engine clears the stale route
1881956
Major
IPv6 default route gets deleted from FIB by slaac daemon after an upgrade with an unsupported configuration
Product-Group=junos
Severity=Major
On all Junos OS platforms , deletion of IPv6 default route from FIB (Forward Information Base) by slaacd (Stateless Address AutoConfiguration Daemon ) is observed while recovering the device from amnesiac state after the OS upgrade with any unsupported or incompatible configuration.
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1872704
Major
NTS for NTP not working even after the Ceritficate is validated with External servers like Chrony and NTPSec
Product-Group=junos
Severity=Major
NTS for NTP not working even after the Ceritficate is validated with External servers like Chrony and NTPSec
PR NumberSynopsisCategory: Wind River Linux Distribution issues in NG-RE
1911820
Major
Device getting stuck in boot phase during upgrade because of expired libvirt certificate
Product-Group=junos
Severity=Major
On Junos platforms running the VMHOST system, devices are getting stuck in the boot phase during an upgrade because of expired libvirt certificate. See https://kb.juniper.net/TSB103739 [juniper.net]
PR NumberSynopsisCategory: Express Chip L3 software
1713279
Major
Next-hop programming issue at PFE on Junos PTX and QFX10k platforms when the member of unilist is in hold state
Product-Group=junos
Severity=Major
On PTX Series routers and the QFX10000 line of switches, traffic going over unilist is dropped when unilist member goes from next-hop hold state to unicast/aggregate state.
1877538
Major
Multicast traffic loss is seen when MVPN with node protection is enabled
Product-Group=junos
Severity=Major
On Junos PTX and QFX10K platforms with node protection enabled on a Multicast Virtual Private Network (MVPN) scenario, multicast traffic loss will be seen when the number of child links in an aggregated ethernet (AE) interface for bypass Label Switched Path (LSP) egress interface is higher than primary LSP and one of the child links goes down on primary LSP egress interface.
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.
PR NumberSynopsisCategory: Issues related to PKI daemon
1892297
Major
The pkid crash is observed during enrolment of device's local certificate through SCEP
Product-Group=junos
Severity=Major
On Junos OS platforms that use the pki service (public key Infrastructure) for device's local certificate enrolment via SCEP (Simple Certificate Enrolment Protocol), the pki daemon crashes during the enrolment process due to the user misconfiguration in CA (Certificate Authority) profile, specifically the key-usage of the CA certificate for the CA profile lacks the certificate-signing, resulting in impact to services relying on certificate verification.
PR NumberSynopsisCategory: PTX10K Routing Engine
1830696
Major
The lcmd process will crash on backup RE on PTX10k8/16
Product-Group=junosvae
Severity=Major
On Junos PTX10k8/16 platforms the 'lcmd ' (Linux Chassis Management Daemon) crash can be seen on the backup RE (Routing Engine) during bootup. There is no service impact because of this issue.
PR NumberSynopsisCategory: QFX platform fabric mgmt for Express ASIC chip
1833086
Major
IBM | qfx10008 | 21.4R3-S5.4 | FPC 0 SIB Link Error | Link error is reported even with lower threshold
Product-Group=junos
Severity=Major
CRC errors can be seen because of the HW degrading with age. Although the CRC errors are not crossing the threshold but links report error. The patch has been added to address such event with additional logs.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1886612
Major
Next-hop entries are not getting programmed in ECMP unilist group after device upgrade
Product-Group=junos
Severity=Major
On Junos OS QFX5k and EX4k platforms, when static ECMP (Equal-Cost Multi-Path) is configured, traffic loss will be observed due to a next-hop programming issue. The device fails to install the next-hop entries in hardware for static ECMP routes, resulting in traffic not being forwarded as expected after a device upgrade.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
Severity=Major
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on specific Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.
1878555
Major
Transit unicast ARP requests are dropped instead of being forwarded
Product-Group=junos
Severity=Major
On Junos QFX5K and EX46xx platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) environment, when "no-arp-trap" is enabled, transit unicast Address Resolution Protocol (ARP) packets that are not destined for the local switch Integrated Routing and Bridging Media Access Control (IRB MAC) are dropped instead of being forwarded across the leaf nodes.
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1845045
Major
On QFX5120-48YM port remains down when speed shifts from 1G to 10G
Product-Group=junos
Severity=Major
On QFX5120-48YM, if a port is transitioned directly from 1G to 10G either by swapping the SFP or by changing port and chassis speed settings without intermediate reset. The 10G link will remain down.
1890867
Major
QFX5120 - SFP+ Modules disappear/down post upgrade
Product-Group=junos
Severity=Major
On QFX5120-48T platforms, QSA-SFP+ adapter(100G/40G ) modules disappear/go down after software upgrade. Due to unsupported QSA usage in the impacted release, which will trigger a dcpfe (Dataplane Packet Forwarding Engine) crash.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1847904
Major
CTLE Values mismatch for 100G-BASE-SR4/100G-BASE-SR4-T2 in QFX5120-48T
Product-Group=junosvae
Severity=Major
The CTLE for 100G-BASE-SR4/100G-BASE-SR4-T2 is set wrong value on QFX5120-48T platform.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1841548
Minor
The "show system core-dumps | display json" OR "get-system-core-dumps" will give an invalid JSON output
Product-Group=junos
Severity=Minor
On all Junos platforms, "show system core-dumps | display json" or "get-system-core-dumps" will give an invalid JSON output. The crash files will not be displayed in JSON format.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
PR NumberSynopsisCategory: Resource Reservation Protocol
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
Severity=Major
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1817865
Minor
The "snmp packet-size " command not working for SNMPv3
Product-Group=junos
Severity=Minor
If the "snmp packet-size " is configured on Junos and Junos Evolved platforms. , the responded SNMPv3 packet could be of larger size causing more fragmentation and packet overhead for SNMP traffic.
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1869450
Major
Subscribers failed to establish DS-Lite softwires due to stale softwire entries
Product-Group=junos
Severity=Major
On Junos MX Series platforms using MS-MPC or MX-SPC3 line cards with DS-Lite softwires subscriber services and the session-limit-per-prefix option enabled, the softwire extension reference count will not be properly decremented during subscriber session teardown. These stale softwire entries cause traffic failures when the same subscriber connects to a different AFTR (Address Family Transition Router). This will not impact new subscriber sessions with any AFTR, nor will it affect existing subscriber sessions with the same AFTR.
PR NumberSynopsisCategory: all ipv6 flow bugs on srx platforms
1807541
Major
SRX4600 with SOF is observed to continue sending ipv6 traffic out a downed member link.
Product-Group=junos
Severity=Major
If a bundled member link is removed either physically (cable disconnection) or by configuration (admin down), it may be observed that ipv6 traffic is continuing to send out that downed link.
PR NumberSynopsisCategory: SRX branch platforms
1877323
Major
Unexpected primary role assignment on SRX after node0 reboot
Product-Group=junos
Severity=Major
On all Branch SRX series platforms(SRX300/SRX320/SRX340/SRX345/SRX380), rebooting node0 with chassis cluster enabled causes the High Availability (HA) control link to establish after the initial hold timer expires. As a result, node0 assumes the primary role unexpectedly, leading to a split-brain condition where both nodes operate as primary.
1877428
Major
Stale user session displayed in "show system users" after ssh session disconnected.
Product-Group=junos
Severity=Major
On all platforms running FreeBSD6, such as the SRX3xx or QFX5100 series, once an SSH session is disconnected, the stale user entry may still be displayed in "show system users" or still counted in hrSystemNumUsers OID.
1893957
Minor
SRX configured with a native VLAN ID other than 1 experienced DHCP assignment issues and ARP resolution failures to the default gateway
Product-Group=junos
Severity=Minor
In SRX configured with a native VLAN ID other than 1, connected devices successfully obtain DHCP IP addresses but are unable to resolve ARP for the default gateway. Although the SRX sends ARP replies, these responses do not reach the connected devices. Corresponding packet discards are observed in the Packet Forwarding Engine (PFE), indicating that the ARP replies are being dropped before reaching the endpoints.
PR NumberSynopsisCategory: MX10002 Platform SW - Platform s/w defects
1755585
Minor
VMHost memory exhaustion results in image installation failure and brings down the RE during the upgrade
Product-Group=junosvae
Severity=Minor
On VM Host platforms, if the available memory is lower than 7.5G, the VM Host software install fails and an error message is displayed regarding the lack of space. If a reboot is followed after such failed installation, the RE (Routing Engine) goes dead or boots from secondary disk.
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1876314
Minor
Intermittent link-up failure on MX10003 after peer device reboot
Product-Group=junos
Severity=Minor
On Juniper MX10003 platforms equipped with MIC1, interfaces using QSFP optics fail to come up or remain down after a connected third-party device is rebooted. This behavior results from a timing mismatch, where the software delays link initialization while waiting for a stable optical signal, potentially missing the brief window when the remote device restarts its transmit signal. This is an interoperability issue and may require manual intervention for service restoration.
1886937
Major
Interfaces either fail to come up or flap or a delay is observed on MX10003 platforms when the interface is reset or the devices is restarted
Product-Group=junos
Severity=Major
On MX10003 platforms peering to third-party devices, interfaces remain down or flap or a delay is observed while it comes back up after the device is restarted or the Flexible PIC Concentrator (FPC) is restarted or when the interface is reset. The symptoms is not consistent and any of the mentioned behaviour could be seen. Due to the interface going down or in case of a flap/delay, services running over the interface will be impacted or traffic flowing through that interface will be dropped.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1871698
Major
Filter-Based Forwarding (FBF) failed for over unicast IRB over AE on MX and EX platforms
Product-Group=junos
Severity=Major
On all Junos MX with MPC10, MPC11, MX304 and EX92K platforms, when Integrated routing and bridging (IRB) interface is configured over Aggregate Ethernet (AE), the packet is received on an l3 IRB which is processed through a filter based forwarding (FBF) which forwards the traffic over an IRB which has an underlay as L2 AE interface. When the packet is forwarded over the l2 AE, the packet gets dropped because the egress PFE calculation is incorrect resulting in a traffic drop.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1875040
Major
The BUM traffic is dropped due to interoperability issue in combination of MPC 1-9 and MPC10E/MPC11E line cards in a WECMP setup
Product-Group=junos
Severity=Major
The Broadcast, unknown Unicast, and Multicast (BUM) traffic such as Ethernet Virtual Private Network (EVPN) or Virtual Private LAN Service(VPLS) etc. is dropped on the egress Flexible PIC Concentrator (FPC) in a weighted Equal Cost Multi-Path (ECMP) setup with non-zero balances when ingress traffic arrives on a different line card. This issue arises only in interoperability scenarios where a combination of MPC 1-9 and MPC10E/MPC11E line cards are used for ingress and egress processing resulting in forwarding issues.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1839268
Minor
Line card crashes due to high scale subscribers
Product-Group=junos
Severity=Minor
On Junos MX platforms with MPC5, 7, 8, 9 line cards, FPC crash observed in PPPoE subscriber scenario.
1846055
Critical
PPE traps and traffic wedges are seen when subscribers are forwarded through Soft-GRE tunnel
Product-Group=junos
Severity=Critical
On all Junos MX platforms with MPC2-9 linecards, when subscribers are forwarded through the Soft-GRE (dynamic GRE tunnel), hardware memory corruption occurs resulting in PPE (Packet Processing Engines) traps being generated and traffic is impacted.
1865649
Major
Traffic drop from subscriber will be observed when rpf-check knob is enabled under subscriber dynamic-profile with static underlying VLAN interface
Product-Group=junos
Severity=Major
On all Junos MX platforms with BBE subscribers (Broadband Edge) over static IFLs (Logical Interface) with static underlying VLAN (Virtual Local Area Network) interface and ISSU (In-Service Software Upgrade) is performed, traffic drop will be observed when rpf-check (Reverse-path forwarding) knob is enabled under subscriber dynamic-profile.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1837840
Major
Incorrect color-aware srTCM marking with yellow packet loss priority
Product-Group=junos
Severity=Major
There was a software side limitation on the highest CBS that can be configured for MPCs that have LU type lookup chips due to a hardware PR. The Hardware PR was resolved in MX240/ MX480/ MX960/ MX2008/ MX2010/ MX2020/ MX10003/ MX10008/MX10016/ EX9200/EX9204/EX9208/ EX9214/ EX9251/EX9253/ SRX5400/SRX5600/SRX5800 platforms, but the software-side limitation was not removed for the same. Due to this limitation, whenever the CBS was configured above its limit (earlier 33m), the low-level parameters used to get configured such that the packets would not have any credits available, resulting in them getting marked as RED.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1874503
Major
An IPv6 neighbor solicitation packet is dropped at the ingress PE router when it is received with more than two VLAN tags.
Product-Group=junos
Severity=Major
On Junos platforms having 'arp-supression' suppression enbabled, when IPV6 neighbor solicitation packets are received with more than two tags in an EVPN (EThernet Virtual Private Network) instance, the NDP (Neighbour Discovery Protocol) packets that are suppressed to the host path are incorrectly processed through a wrong DDOS policer, as the hop-limit value from the IPV6 header is not properly retrieved, causing them to be dropped by the packet forwarding engine.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1858741
Minor
IPv6 link cannot be used for around 10 seconds after DAD finishing due to NS delay.
Product-Group=junos
Severity=Minor
If both IPv4/IPv6 addresses are configured and both IPv4/IPv6 traffic is sent, there may be a 10 second delay in NS completion. This may occur when the egress interface is disabled/enabled and triggers NH resolution.
1864237
Critical
Observing out-of-order packets when the TCP traffic gets passed over AE bundle and tunnelled via MPLSoUDP tunnel
Product-Group=junos
Severity=Critical
On Junos OS platforms, When "dynamic tunnels" configured and "set chassis loopback-dynamic-tunnel" knob is used and when TCP (Transmission Control Protocol) traffic passed via MPLSoUDP (Multi-Protocol Label Switching Over User Datagram Protocol) tunnel through an outgoing AE (Aggregated Ethernet) bundle interface having member interfaces, use of either inner or outer header hash calculations lead to out-of-order packets at the egress. It causes service impact on related flow of traffic due to out-of-order packets.
1880860
Major
FPC crash is seen on MX series when disabling AE IFL in mixed-speed configuration without enhanced-ip enabled
Product-Group=junos
Severity=Major
On MX platforms using ukern line cards (MPC2-9, LC480, LC2101, MX10K3), disabling an AE(Aggregated Ethernet) IFL configured with mixed-speed member links and without enhanced-ip enabled causes the associated FPC to crash and reboot.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1829031
Minor
An authentication failure occurs when the TACACS+ server detects an error in sending authentication response
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved products configured with TACACS+(Terminal Access Controller Access Control System Plus) authentication method, authentication seems to fail when TACACS+ server detects an error in sending authentication response to the host device. This impacts authentication and user cannot login into the device.
1862890
Major
Junos OS and Junos OS Evolved: Device allows login for user with expired password (CVE-2025-60010)
Product-Group=junos
Severity=Major
A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change. Please refer to https://supportportal.juniper.net/JSA103168 [juniper.net] for more details.
PR NumberSynopsisCategory: Configuration management, ffp, load action
1816534
Minor
BGP IPv6 session control packets are discarded when changing the ipv6 neighbor-address using 'replace pattern'
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, when prefix-list is used to define apply-path and the prefix-list is also used in a firewall filter, and if IPv6 BGP neighbour address is changed, BGP control packets are dropped resulting in the session not coming up.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1771132
Major
Junos OS: When a user with the name ftp or anonymous is configured unauthenticated filesystem access is allowed (CVE-2025-59980)
Product-Group=junos
Severity=Major
An Authentication Bypass by Primary Weakness in the File Transfer Protocal (FTP) server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device. Please refer to https://supportportal.juniper.net/JSA103167 [juniper.net] for more details.
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
Product-Group=junos
Severity=Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
1854070
Minor
cli coredump genarated when the size of buffer area (user input) increased to 1GB
Product-Group=junos
Severity=Minor
Cli coredump genarated when the size of buffer area (user input) increased to 1GB.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1795952
Minor
The eventd crashes if eventd traceoptions is enabled
Product-Group=junos
Severity=Minor
When traceoptions is enabled for event-options, eventd crash may be observed.
1848106
Major
The eventd process crash occurs due to flooding of out of memory logs
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, eventd process crashes is observed. This happens when eventd process is processing the flooding of out of memory logs generated by any of the processes running on FPC (Flexible PIC Concentrator). This is traffic impacting depending on the process with memory issues.
PR NumberSynopsisCategory: Issues related to NETCONF
1906621
Major
RPC reply delayed for commit during NETCONF over SSH session on Junos TVP-based VMhost platforms
Product-Group=junos
Severity=Major
On JUOS VM Host-based platforms, when performing NetConf "", an internal script caused its PID to be displayed in the NETCONF session during commit.
PR NumberSynopsisCategory: PTX/QFX10002/8/16 specific software components
1882584
Minor
SERDES link errors observed on SIB8 modules due to power rail instability
Product-Group=junosvae
Severity=Minor
On Junos platforms utilizing the JNP10008-SF (aka SIB8), systems experience CRC errors on fabric links between the SIB and the FPC (Flexible PIC Concentrator). These errors are attributed to electrical noise on an internal power rail within the SIB. This condition will lead to multiple FPC-to-SIB link failures, potentially affecting traffic forwarding and overall fabric stability.
PR NumberSynopsisCategory: MX10K linecard
1784824
Major
LC480 line card crashed with reference to posix_interface_abort () at ../src/pfe/platform/linux/posix_interface.c:2729
Product-Group=junos
Severity=Major
LC480 may restart unexpectedly during boot up.
1785182
Minor
On Junos MX and SRX platforms silent FPC reboot is observed with no generation of crash files
Product-Group=junosvae
Severity=Minor
On Junos platforms with MPC7E, MPC8E, MPC9E. LC1201, LC480, MS-SPC3, SRX5K-SPC3 cards. When one of these line cards have uncorrectable memory issue, the line card reboots silently without generating any crash files.
PR NumberSynopsisCategory: MX10K platform
1784080
Critical
FPC reboot seen on MX platforms with PMB memory correctable errors
Product-Group=junosvae
Severity=Critical
On all MX platforms that support MPC7/MPC8/MPC9/MX10k-LC2101/EX9200-40XS/EX9200-12QS, an unexpected FPC (Flexible PIC Concentrator) reboot may be seen along with PMB memory correctable errors. Service impact can be seen till the FPC restart completes.
PR NumberSynopsisCategory: PTX/QFX100002/8/16 platform software
1867698
Minor
FPC crashes with "Last Reboot Reason: CPU Watchdog Reset" on PTX10K platforms
Product-Group=junosvae
Severity=Minor
On Junos PTX10k platforms with LC1101, LC1102, LC1103, LC1104 & LC1105 linecards, the FPC (Flexible PIC Concentrator) crashes with the reboot reason "CPU Watchdog Reset" due to the system placing the PCI (Peripheral Component Interconnect) bridge port into a low-power state. This causes the system to hang, triggering a watchdog reset resulting in FPC reboot.
PR NumberSynopsisCategory: VMHOST platforms software
1766977
Minor
"VMHost RE 0 Disk 2 Write Cache disable" alarm is raised
Product-Group=junosvae
Severity=Minor
On all Junos platforms, Disk write cache can be enabled/disabled by default from vendor. Backup disk write cache alarm raises in primary disk when backup Disk write cache is disabled. There is no service impact only alarm will raises.
PR NumberSynopsisCategory: Track Windriver Linux issues
1631579
Critical
A few line cards will be stuck in the 'Present' state and later go 'Offline'
Product-Group=junosvae
Severity=Critical
A system equipped with specific line cards, the line cards will be stuck in the 'Present' state and later go 'Offline' after the line card or router is rebooted. Ideally, the Line Card should go 'Online' instead it goes 'Offline'.
PR NumberSynopsisCategory: usf ipsec related issues
1796469
Critical
Commit triggers SI- interface flap on MX Series due to bandwidth mismatch
Product-Group=junos
Severity=Critical
On all MX Series platforms running Junos OS 22.1R1 and later, if Service Interfaces (SIs) are configured without explicitly setting bandwidth, the system compares the default CLI input (zero) with the platform-derived bandwidth value. This mismatch causes unintended SI interface re-creation (flaps) on the corresponding PIC and FPC.
1876801
Major
IPsec-inside-IPsec tunnel establishment fails on MX platforms with SPC3 cards
Product-Group=junos
Severity=Major
On MX platforms equipped with SPC3 cards, the establishment of the inner IPsec tunnel fails in an IPsec-inside-IPsec tunnel setup. This occurs because the service PIC's forwarding process incorrectly attempts to punt IKE packets to the Route Engine (RE) and cannot resolve the required internal fabric path.

 

Extended Solution

22.4R3-S8 - List of Known issues

PR NumberSynopsisCategory: EX4300 Mutlicast implementation
1873129
Major
The PTP packets are dropped when IGMP snooping is enabled
Product-Group=junosvae
On EX4400, EX4100, QFX5120 and EX4650 platforms running Junos Operation System (OS), when Internet Group Management Protocol (IGMP) snooping is enabled on Virtual Extensible Local Area Network (VXLAN) Virtual Local Area Network (VLAN), all unknown multicast packets will be dropped. As a result, PTP (Precision Time Protocol) packets that use reserved multicast addresses are also discarded affecting the synchronization of the device with the clock server.

Resolved In: junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: NFX Series Platform Software
1858495
Major
The auto-negotiation is not working properly on NFX350 platform using 1 Gigabit Ethernet SFP
Product-Group=junos
On NFX350 platforms connected to certain peer devices over SFP 1 Gigabit Ethernet (GE) with auto-negotiation enabled at both ends, a communication issue occur during the initial connection between devices, causing a mismatch in their status. As a result, the port status on the peer device appear as up/down affecting the traffic.

Resolved In: junos:24.2R2-S2 junos:24.4R2 junos:25.2R1-S1 junos:25.4R1
PR NumberSynopsisCategory: "agentd" software daemon
1779722
Minor
The interface fails to come up after FPC reboot if the streaming server and export profile are not configured correctly
Product-Group=junos
On all Junos and Junos evolved platforms with telemetry enabled, if the streaming server and export profile for reporting-rate are not properly configured in the analytics settings, rebooting the FPC would prevent any of the interfaces from coming up.

Resolved In: evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:25.1R1-EVO junos:23.4R2-S5 junos:24.2R2-S2 junos:25.1R1
PR NumberSynopsisCategory: SRX2000/50000 issue
1904267
Major
In SRX high availability cluster, RG0 failover to secondary node fails as srxpfe daemons failed to reconnect to routing-engine on secondary
Product-Group=junos
On all Junos OS SRX except branch SRX platforms, in high availability scenario, during redundancy group (RG0) failover, all the FPC PICs need to reconnect to the new primary routing-engine on secondary node within 16 seconds timer. However, this is not happening which is causing a connection reset and impacting traffic.

Resolved In: junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R3-S9 junos:23.2R2-S6 junos:24.2R2-S4 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: A20/A40 IOC card
1883027
Minor
SRX Firewalls with IOC3 triggers a temperature alert on the FPC 2 PLX PCIe Switch Chip
Product-Group=junos
On SRX5400, SRX5600, and SRX5800 platform with MPC3-40G10G and MPC3-100G10G (IOC3) interface card, a temperature alarm is triggered when the Peripheral Component Interconnect Express (PCIe) switch chip temperature exceeds 75 Celsius degrees.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S1 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: BBE multicast related issues
1882756
Major
The bbe-smgd process crash triggered by a multicast event failure
Product-Group=junos
On all MX platforms with Broadband Edge Subscriber Management configured, the bbe-smgd process crashes when the multicast sync service add publish fails. This crash is automatically recovered by the system without requiring manual intervention.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1807182
Minor
Interface and protocol flaps is observed when BFD authentication is enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms with BFD (Bidirectional Forwarding Detection) authentication enabled, interface flap is observed and subsequent protocols will go down. This could result in traffic disruption for that protocol leading to outages.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO junos:20.3X75-D46 junos:21.2R3-S9 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Border Gateway Protocol
1629213
Minor
External BGP multihop and accept-remote-nexthop feature should not be used together
Product-Group=junos
When you configure BGP with both EBGP "multihop" and "accept-remote-nexthop" together, it might not update the EBGP peer's next-hop interface correctly upon interface flap, causing packet forwarding drops.

Resolved In: evo:22.3X80-D49-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:21.2R3-S9 junos:22.4X50 junos:23.2R2 junos:23.2R2-J14 junos:23.3R1
1793714
Major
BGP routes may not get advertised when always-wait-for-krt-drain is configured with BGP sharding
Product-Group=junos
On all Junos and Junos Evolved platforms, when 'delay-route-advertisements always-wait-for-krt-drain' is configured, the EoR (End of Record) from the source peer of the routes is not received in the BGP (Border Gateway Protocol) peer which is sent by a BGP speaker to indicate the end of a record or a sequence of updates. This is due to the BGP router advertiser being stuck in the wait-for-inbound-convergence state, which may cause the KRT (Kernel Routing Table) queue to get stuck, thereby halting the advertisement of BGP routes.

Resolved In: evo:22.2R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:22.2R3-S5 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
1814289
Minor
The IBGP session stuck in active state with 'local-as alias AS_X' when peers have different global AS configuration
Product-Group=junos
On all Junos and Junos Evolved platforms, when "local-as alias" configuration knob is used on an IBGP session, it won't be able to get established in the scenario where peers have different global AS, but the same "local-as alias".

Resolved In: evo:23.4R2-S3-EVO evo:23.4X100-D30-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:23.4R2-S3 junos:24.2R2 junos:24.4R1
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X80-D49-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.2R2-EVO junos:21.2R3-S9 junos:21.2X35 junos:22.2R3-S6 junos:22.2R3-S7 junos:22.4R3-J1 junos:22.4R3-S4 junos:23.2R2-S3 junos:23.4R2-S1 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.2R1-S2 junos:25.2R2
1826685
Minor
Unexpected behaviour after BGP sessions reset for catastrophic BGP configuration changes
Product-Group=junos
On Junos and Junos Evolved platforms, when a catastrophic Border Gateway Protocol (BGP) configuration change occurs, creating a new peer structure due to this configuration change, the BGP state transitions from open-sent to established multiple times (until the local device finishes cleaning the old BGP session). This results in traffic impact as the peer is reset multiple times (until a new peer connection is established).

Resolved In: evo:22.2R3-S7-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:20.3X75-D441 junos:20.3X75-D52 junos:22.2R3-S7 junos:22.4R3-S6-J11 junos:22.4R3-S7-J1 junos:22.4X8 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:25.1R1
1854194
Major
Handling cores when always-compare-med is configured in BGP path selection
Product-Group=junos
When using rib-groups, which copy inet.3 routes to inet.0 and inet6.3, configuring path-selection always-compare-med triggers a local RIB evaluation that will miss inet6.3 because inet6.3 tables are not initialized as a BGP RIB. As a result, Inet6.3 routes will not get updated.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7-J1 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:23.4X100-D40-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP-LU (Border Gateway Protocol-Labeled Unicast) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.

Resolved In: evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-J6 junos:24.2R2-S1-J4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
1889749
Major
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.

Resolved In: evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.2R3-S8-J22 junos:23.2R2-S6 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Express BT PFE L3 Features
1878029
Major
Restarting the evo-aftmand-bt or evo-cda-bt process disrupts PHY synchronization within the timingd service resulting in timing errors
Product-Group=junos
On Junos OS Evolved PTX10001-36MR platform with PTP (Precision Time Protocol) configured, a synchronization issue will occur between the PTP FPGA (Field Programmable Gate Array) and the MAC (Media Access Control)/PHY (Physical Layer). This results in timing errors on the local device, which may also propagate to downstream devices. The issue typically arises after restarting the evo-aftmand-bt or evo-cda-bt processes, which impacts the socket connection between these processes and the timingd service. As a result, timingd is no longer able to communicate with these components as expected.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: MX304 timing software
1841695
Major
The "show chassis synchronization extensive" command output shows syncE is locked to both primary and secondary sources after switching between primary and secondary sources
Product-Group=junos
On MX304/MX10k8 platforms, by setting the primary interface port down so that syncE switches to secondary source and then bring back the primary interface either through port down or LMIC offline and online, the "show chassis synchronization extensive" command output shows syncE is locked to both primary and secondary sources.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1881742
Major
Packet Loss is observed when explicit Null is disabled for BGP-LU routes in ECMP scenarios
Product-Group=junos
On Junos ACX5448 and ACX710 platforms, traffic drop is observed for the Labeled Unicast (BGP-LU) route prefixes with Equal-Cost Multipath (ECMP) forwarding path when explicit null is disabled.

Resolved In: junos:23.4R2-S2-J16 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1808773
Minor
On ACX7348/ACX7332 all traffic is blocked on FPC after RE Switchover
Product-Group=junos
On ACX7348/ACX7332 with MACsec enabled in channelized interfaces, after performing a double RE switchover (primary RE swap to backup and then back to active), traffic in FPC1 stops in being forwarded.

Resolved In: evo:23.4R2-S5-EVO evo:24.4R1-EVO junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
1841965
Major
RPD core-dump on 22.2R3-S4
Product-Group=junos
RPD core occurs when we have an L3 instance (instance type: VRF) and an L2 instance for EVPN (instance type: MAC-VRF) with duplicate MAC detection enabled.

Resolved In: evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1846266
Major
The inet filters attached to the IRB interface will not function as expected
Product-Group=junos
On Junos QFX5k and EX4k platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, inet filters applied to Integrated Routing and Bridging (IRB) interfaces will not function as expected, and the associated actions of the filter are not enforced.

Resolved In: junos:24.4R1-S1 junos:24.4R1-S3 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.2R1-S1
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: EX interfaces issues
1789999
Major
[interfaces]:Ex-Hardening:Local/Remote fault insertion from TG is failing
Product-Group=junos
Ex-Hardening:Local/Remote fault insertion from TG is failing

Resolved In:
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1679965
Major
MSFT EXR - AE Bundle with LACP went down, even though members links are up and running.On performing process restart of "firewall" & parallely changing the Firewall filter Mode from "physical -> interface.
Product-Group=junos
Changing a filter from interface-specific to physical-interface-filter (or visa versa) while also restarting the firewall process may result in issues with LACP. To avoid this, deactivate the filter before changing the mode.

Resolved In:
PR NumberSynopsisCategory: MX10K LC2101 Timing
1845497
Major
Incorrect warning message is seen post hyper-mode configuration change and mismatch of hyper-mode between FPC and RE impacts performance
Product-Group=junos
On all Junos MX platforms that supports hyper-mode and dual RE (Routing Engine), GRES (Graceful Routing Engine Switchover) upon disabling the hyper-mode, ideally, both the REs needs to be rebooted but it is observed that upon disabling the hyper-mode, the system shows an incorrect warning which says to reboot system and not all routing engines, so as per the warning message when only one of the routing engines is rebooted, here in this case when RE0 is rebooted, RE1 becomes the master but FPC (Flexible Physical Interface Cards Concentrators) is not getting rebooted. Again when mastership is switched back to RE0, FPC is not rebooted as GRES is configured. This causes the FPC to be still in hyper-mode whereas RE remains in non hyper-mode. This mismatch of hyper-mode between the FPC and RE impacts functionality related to performance and feature support. In this case, PTP (Precision Time Protocol) toggles from phase aligned to acquiring but this could impact other feature support as well. The same issue is also observed when hyper mode is changed from non hyper-mode to hyper-mode.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S5 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1861810
Major
The rpd process crash is observed while adding and removing dynamic-tunnels with scaled tunnel configuration
Product-Group=junos
On all Junos Evolved platforms, the indexing of next hop while adding and deleting dynamic tunnels causes the rpd process to crash and restart. This is a timing issue.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S1-J8-EVO evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.2R2-S4 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: jl2tpd daemon
1877876
Major
L2TP subscriber is unable to connect when configuration is loaded over default config on all Junos platforms with L2TP subscribers
Product-Group=junos
On all Junos platforms with L2TP (Layer 2 Tunneling Protocol) subscribers if source-gateway-address is not configured, new L2TP subscribers will not be able to connect when configuration is loaded over default config.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1852968
Major
The SRX platform may experience a flowd process crash and generate core dump files when the ALG feature is enabled
Product-Group=junos
On SRX platforms running the Junos Operating System (OS) with Application Layer Gateway (ALG) enabled, in rare scenarios, flowd process can crash and crash files are generated. While the platform eventually recovers, traffic loss will occur during this process.

Resolved In: junos:22.4R3-S10 junos:22.4R3-S9 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: SRX PFE side GRE/IPIP/DS-Lite/IPSec/PIM/VXLAN tunnel
1884150
Major
Policy match failure for VXLAN EVPN type-5 cross vrf traffic
Product-Group=junos
On all SRX platforms, Ethernet Virtual Private Network (EVPN) Type-5 Virtual Extensible LAN (VXLAN) cross-Virtual Routing and Forwarding (VRF) traffic fails to match security policies when the ingress and egress VRFs are mapped to different VRF groups.

Resolved In: junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
PR NumberSynopsisCategory: Firewall Policy
1882193
Critical
On SRX platform flowd process is generating crash files.
Product-Group=junos
On Junos OS SRX platforms, a crash in the flowd process occurs when the system attempts to retrieve interface information. During this process, an invalid memory address is accessed while copying the interface memory address from the database. This issue typically arises when accessing interface details to check session status on the backup device.

Resolved In: junos:24.4R2 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1894033
Critical
SRX5K traffic disruption due to REPFE policy sync issues from FQDN and file-serialization Errors
Product-Group=junos
On SRX5K series devices with file-serialization enabled, frequent policy synchronization issues occur between the Routing Engine (RE) and Packet Forwarding Engine (PFE) . This can result in traffic matching the incorrect default deny policy instead of matching the expected user-defined security policy. The issue is triggered during commit or request security policies check/resync operations, particularly when Fully Qualified Domain Name(FQDN)-based address objects are involved and have short Domain Name System Time to Live(DNS TTLs).

Resolved In: junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
PR NumberSynopsisCategory: Platform infra to support jvision
1817967
Major
Product annotation is missing for sensors on the MX, PTX, and EX92XX platforms
Product-Group=junos
Product annotation files with correct product support/exclude information for specific sensors with respect to platform MX, PTX and EX92XX products. Request customer to enable CLI "set services analytics product-path-check no-path-check" configure to override product annotation issue.

Resolved In: evo:23.2R2-S2-EVO evo:23.4R2-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:23.2R2-S2 junos:23.4R2-S1 junos:23.4R2-S5 junos:24.2R1-S1 junos:24.2R2 junos:24.2X1 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1887225
Minor
Stale MAC routes pointing to SVLBNH cause traffic drop on QFX5K
Product-Group=junos
On all QFX-5K devices where EVPN-VXLAN is configured. Some MAC(Media Access Control) Routes were left pointing to stale SVLBNH(Shared Virtual LAN Bridging Next Hop). This showed up in PFE (Packet Forwarding Engine) as traffic "traffic directed to CPU" and not getting forwarded in Data Plane (dropped).

Resolved In: evo:23.4R2-S6-EVO evo:24.4R2-S1-EVO evo:25.4R1-EVO junos:24.4R2-S1 junos:25.4R1
PR NumberSynopsisCategory: Label Distribution Protocol
1906611
Major
RPD crash observed after LDP P2MP LSP identifier wrap around due to duplicate identifier allocation
Product-Group=junos
On all Junos and Junos Evolved platforms, when the Label Distribution Protocol(LDP) Point-to-Multipoint (P2MP) Label Switched Path (LSP) identifier counter exceeds its maximum range (224) and wraps around, the routing process daemon (RPD) crashes because a duplicate identifier is incorrectly allocated. This condition occurs only after extremely prolonged system uptime, combined with continuous P2MP tunnel flapping, typically exceeding 16 million flaps. A crash of the routing process daemon results in complete service impact.

Resolved In: evo:26.1R1-EVO
PR NumberSynopsisCategory: lldp sw on MX platform
1900111
Major
In Fusion Provider Edge deployments, aggregator does not establish LLDP neighborship with satellite interfaces
Product-Group=junos
In Junos Fusion Provider Edge deployment, when satellite device is rebooted and subsequently LLDP is enabled on a satellite interface, it does not transmit Link Layer Discovery Protocol (LLDP) packages on the enabled interface resulting in the LLDP neighborship not being established and LLDP-MED (Media Endpoint Discovery), an extension of LLDP, stopping working and causing any Voice over IP phones connected to the interface to lose connectivity

Resolved In: evo:22.4R3-S9-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:25.4R1
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1885185
Major
AE interface going down on specific MX platform with exclude-protocol being re-configured under MACsec.
Product-Group=junos
When exclude protocol is configured with MACsec(Media Access Control Security) on IFD (Interface Device), a delete AE(Aggregated Ethernet) interface can cause the exclude protocol filters to not clean up on MX platforms with MPC10 and MPC11 linecards . When MACsec is reconfigured on the same link with AE, AE interface goes down.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=junos
On all Junos and Junos Evolved platforms, an out-of-memory condition in the rpd process caused by uncontrolled memory allocation leads to the rpd process crashing.

Resolved In: evo:24.2R2-S2-EVO evo:25.2R1-EVO junos:22.3X60 junos:23.4R2-S4-J9 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
On all Junos and Junos Evolved platforms, when RSVP-TE (Resource Reservation Protocol - Traffic Engineering) is configured with MBB (make-before-break) setup, if the protected link of the primary LSP (Label Switched Path) goes down and if "clear mpls lsp" or "clear rsvp session" commands are executed, then LSP switches to new instance from the old which will be on higher IGP (Interior Gateway Protocol) metric. However, after re-optimization, LSP will not get switched to better IGP metric path and remain in old instance. Traffic drop can be seen due to this double fault events.

Resolved In: evo:22.3X50-EVO evo:23.2R2-S4-J2-EVO evo:23.2R2-S5-EVO evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.2R3-J10 junos:22.4R3-S7-J1 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Odin Timing software
1810429
Major
ACX710 PTP ports marked 'passive' instead of 'master' during T-GM selection
Product-Group=junos
In a scenario where two T-GM devices (Telecom Grandmaster clocks) have identical BMCA (Best Master Clock Algorithm) parameters, except for steps removed or grandmaster ID, the ACX710 running the G.8275.1 profile can experience a failure in proper PTP (Precision Time Protocol) clock synchronization. This issue arises because the default BMCA is used instead of the expected Alternate BMCA profile in G.8275.1. This mismatch leads to incorrect PTP clock states, with master ports being marked as 'Passive' instead of 'Master'.

Resolved In: junos:23.2R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1800020
Minor
The image installation should fail when ARM 64-bit image tried to install in ARM 32-bit hardware and vice-versa
Product-Group=junos
On all Junos EX 64-bit/32-bit ARM platforms(EX2300/EX3400/EX4100), the image installation should fail when ARM 64-bit image tried to install in ARM 32-bit hardware and vice-versa. But the device proceeds with reboot and installation of the image and get stuck in u-boot after reboot. There will be complete service impact if install gets to reboot.

Resolved In: junos:22.4R3-S2 junos:23.2R2-S3 junos:23.4R1-S2 junos:23.4R2 junos:24.1R1 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
em0 mgmt port is unreachable after RE switchover
Product-Group=junos
On MX10008 with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1876690
Major
ntp process may restart when issue the "show system ntp threshold" command
Product-Group=junos
The ntp (or xntpd) process is initialized when the "show system ntp threshold" command is issued. This has no impact to system operation.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1897240
Major
Chassis-Control restart triggers when configuring GRE interface across multiple routing-instances leading to kernel crash
Product-Group=junos
On Junos series devices, the kernel crash occurs when creating and configuring a identical GRE(Generic Routing Encapsulation) interface across different routing-instances.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Express Chip L3 software
1827286
Major
The icmpv4/v6 ping fails with ddos-protection* icmp configuration
Product-Group=junos
The PTX10008, PTX10002-60C, or QFX10002-60C platforms may not send back ICMPv4/v6 reply packets properly due to defects leading to misprogramming of hardware. Ping with v4/v6 from another device to the PTX10008, PTX10002-60C, or QFX10002-60C platform will fail.

Resolved In: junos:22.4R3-S5 junos:22.4X50
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1694798
Minor
On MX Series Routers, subscriber login failures with DHCPv6 over PPPoE
Product-Group=junos
On MX series devices, subscriber login failures and scaling limitations were observed in high-scale PPPoE(Point-to-Point Protocol over Ethernet) dual-stack deployments using DHCPv6( Dynamic Host Configuration Protocol version 6). This issue occurred when subscriber sessions attempted to re-login immediately after termination, causing a flow conflict in the Packet Forwarding Engine (PFE).

Resolved In: evo:23.2R1-EVO junos:21.4R3-S12 junos:22.4R3-S6-J15 junos:22.4R3-S9 junos:23.2R1
PR NumberSynopsisCategory: PTX10K Routing Engine
1754884
Minor
After reboot, /var/db/scripts/ has incorrect file permissions
Product-Group=junos
On PTX10008/PTX10016/QFX10002-36q/QFX10002-60c/QFX10002-72q/QFX10008/QFX1001 platforms, Python based scripts will not execute due to permission issue.

Resolved In: junos:20.3X75-D36 junos:20.3X75-D441 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: QFX platform optics related issues
1465214
Major
The QSFP-100G-PSM4 could not be correctly identified on QFX5200 or QFX5110 platforms
Product-Group=junos
On QFX5200 or QFX5110 platforms, when frequent hot swap of optics module happens, the QSFP-100G-PSM4 could become undetected and related links won't come up.

Resolved In: junos:18.4R3 junos:19.1R3 junos:19.2R2 junos:19.3R3 junos:19.4R1 junos:20.1R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1878555
Major
Transit unicast ARP requests are dropped instead of being forwarded
Product-Group=junosvae
On Junos QFX5K and EX46xx platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) environment, when "no-arp-trap" is enabled, transit unicast Address Resolution Protocol (ARP) packets that are not destined for the local switch Integrated Routing and Bridging Media Access Control (IRB MAC) are dropped instead of being forwarded across the leaf nodes.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:23.4R2-S7 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.2R2 junos:25.3R1
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
On Junos QFX5k and EX4k platforms, if VPLAG(Virtual Private Link Aggregation group) is configured and if there is event change which could make ECMP(Equal Cost Monitoring Protocol) programming to change like ECMP link flap, dcpfe restart, system reboot etc which causes traffic loss.

Resolved In: junos:21.2R3-S10 junos:21.4R3-S12 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1670240
Major
The dcpfe process might generate core-dumps and FPC might crash after line card reboot or switchover
Product-Group=junos
On QFX10K, PTX10K, PTX5K, PTX3K, and PTX1K platforms, the dcpfe process might generate core-dumps and FPC might crash after line card boot or switchover. The BIST (Built-in Self Test) might report an error in the HMC (Hybrid Memory Cube) and restart the dcpfe process causing FPC crash.

Resolved In: junos:20.2R3-S5 junos:20.3R3-S5 junos:21.2R3-S4 junos:21.3R3-S3 junos:21.4R3 junos:22.1R2 junos:22.1R3 junos:22.2R2 junos:22.3R1 junos:22.4R1
1695183
Major
PTX1000 resources exhaustion causing host loopback wedge
Product-Group=junos
Junos PTX1000 platforms will experience resource exhaustion 64 days after the reboot. Due to this the device will drop all the control plane traffic resulting in complete service impact. see https://kb.juniper.net/TSB71154 [juniper.net]

Resolved In: junos:21.2R3-S7 junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3X60 junos:22.4R2 junos:22.4R3-S2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1800862
Major
On all dual disk QFX5K platforms having QFX-5e image with secondary (sdb) disk failure, WRITE DMA errors are observed and the device goes unresponsive
Product-Group=junos
Due to a the disk failure reboot support was not added for dual disk scenario, hence system was not booting in case of disk failure on sdb (the other disk) on QFX platform.

Resolved In: junos:22.2R3-S5 junos:24.2R2-S3
1882472
Major
JMA package fails to initialise after a power cycle on EX4650/QFX-5E series devices
Product-Group=junos
On Junos EX4650/QFX-5E series, after installing the JMA(Junos Mist Agent) package, a graceful reboot (using request system reboot or request system halt) is required to commit the changes. An abrupt power cycle before a graceful reboot causes the system to lose the installed JMA package.

Resolved In: junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: MPC5E, MPC6E specific timing and synchronization
1872093
Major
SyncE clock event stuck at "Clock abort" and PTP stops working on all Junos and Junos OS Evolved platforms
Product-Group=junos
Initial FSM design augmented to handle internal recovery from SyncE clock abort, if and only if, it took longer than 30secs for clksyncd to receive SyncE clock qualification message form the PFE. In all other SyncE clock abort cases, recovery is possible externally as specified under Workaround. This is not a bug but enhancement in FSM design.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1830588
Critical
The rpd process crashes on all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted
Product-Group=junos
On all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted, route churn will potentially lead to the rpd process crash.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:23.2R2-S3-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:23.4R2-S5-EVO evo:24.2R2-EVO evo:24.4R2-S1-J1-EVO evo:25.1R1-EVO junos:22.2R3-S7 junos:22.3X60 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2-S2 junos:25.1R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:25.2R2 junos:25.3R1 junos:25.4R1 junos:25.4R2 junos:26.1DCB
PR NumberSynopsisCategory: Resource Reservation Protocol
1881906
Major
BFD session failure causes LSP to go down and the inactive route remains in the routing table leads to traffic black hole
Product-Group=junos
On Junos OS and Junos OS Evolved platforms, when an RSVP (Resource Reservation Protocol) LSP (Label Switched Path) goes down due to a failure in the associated BFD (Bidirectional Forwarding Detection) session, and the corresponding route remains in the routing/forwarding table causing traffic black-holing. If there are other active LSPs to the same destination, those active routes are preferred over the inactive route associated with the failed LSP.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
1896022
Major
More bandwidth admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
On all Junos and Junos evolved platforms with Point of Local Repair Router, in a Multiprotocol Label Switching(MPLS) Label Switched Paths (LSPs) set-up if the ingress router is configured with link-protection , if Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S9 junos:23.2R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Scuba fabric software
1811474
Major
In Junos MX platforms specifically MX2010 and MX2020 with SFB2 Fabric installed replacing MPC9E linecards with MPC6E linecards results in all SFB2 fabric get into check state and FPCs becomes destination error and offline
Product-Group=junos
On Junos MX platforms specifically MX2010 and MX2020 with SFB2 (Switch Fabric Board) Fabric installed, after inserting and powering on a new MPC6E in slot (swapping specifically with MPC9E linecard), fabric get into check state and all FPCs goes as unreachable destinations and gets offlined. Due to this, traffic loss can occur.

Resolved In: junos:20.3X75-D46 junos:21.2R3-S9 junos:22.2R3-J11 junos:22.2R3-J9 junos:22.4X4 junos:23.2R2-S2-J2 junos:23.2R2-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.2R3-S6-J26 junos:23.2R2-S4 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: security-intelligence feature on SRX
1527716
Major
The rpm may cause a host-specific route pointing to an unconfigured default gateway
Product-Group=junos
On all SRX Series platforms with services rpm and services ip-monitoring configuration, when the outgoing interface of the route is down, it is observed that the routes still exist, the traffic will be dropped.

Resolved In: evo:20.2R3-EVO evo:20.3R2-EVO evo:21.1R1-EVO junos:18.4R3-S7 junos:19.2R3-S2 junos:19.4R3-S2 junos:20.2R2 junos:20.2R3 junos:20.3R2 junos:20.4R1 junos:21.1R1
PR NumberSynopsisCategory: SRX branch platforms
1889549
Major
The XE interfaces of SRX380 platform with 1G SFP (fiber) are flapping continuously when LACP is enabled
Product-Group=junos
When LACP (Link Aggregation Control Protocol) is enabled using 1G SFP(Small Form-factor Pluggable)-fiber (such as SFP-SX, SFP-LX etc) over XE interfaces, frequent state transitions will repeatedly trigger configuration updates. Due to LACP instability, the interfaces will continuously flap. As a result, the port configuration will be re-applied automatically which leads to a loop of re-configurations until the LACP state stabilizes.

Resolved In: junos:24.2R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1842873
Minor
Load balance hash-key forwarding persists when switching to Layer 3-only
Product-Group=junos
On Junos SRX4600, SRX1600, SRX2300 and SRX4300 platforms, when switching load balance from L3+L4 to L3, hash-key forwarding fails; the device retains L3+L4.

Resolved In: junos:23.4R2-S5 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1886757
Minor
Alarms for high usage in /var partition are not generated
Product-Group=junosvae
On Junos SRX4600/SRX4700/SRX1600/SRX2300/SRX4300 platforms, alarms for high usage at /var partition storage is not reported.

Resolved In: evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:25.2R1-S1 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1885754
Major
MX304 LNS: FPC restart and aft-trio core after LMIC OIR when SI pool spans both MICs
Product-Group=junos
On MX304 routers acting as LNS, an FPC restart and aftd-trio core may occur if a MIC is offlined (LMIC OIR) while the service-device pool of SI interfaces spans both MICs on the same FPC. This may result in transient loss of subscriber sessions and service impact.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1870522
Minor
STP/RSTP/MSTP/VSTP enters a disputed and blocked state when the anchor FPC of an AE link, with members distributed across multiple FPCs, goes offline
Product-Group=junos
On MX and EX9200 series platforms that operate in hyper mode by default, STP (Spanning Tree Protocol)/RSTP (Rapid Spanning Tree Protocol)/MSTP (Multiple Spanning Tree Protocol)/VSTP (VLAN Spanning Tree Protocol) transitions to a disputed and blocked state if the members of the AE (Aggregated Ethernet) link in the anchor FPC (Flexible PIC Concentrator) goes offline.

Resolved In: junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1891110
Major
A GRE tunnel configured with a tunnel key drops MPLS-encapsulated traffic
Product-Group=junos
On MX platforms with line cards MPC1-9, a Generic Routing Encapsulation (GRE) tunnel configured with a tunnel key drops Multi-Protocol Label Switching (MPLS) encapsulated traffic as it is unable to find the key.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S5 junos:24.2R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.

Resolved In: evo:23.4R2-S6-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:20.2R3-S11 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Configuration management, ffp, load action
1854461
Major
Configured TFTP server connection and rate limits are not applied
Product-Group=junos
On all Junos and Junos Evolved platforms configured as Trivial File Transfer Protocol (TFTP) server , "connection-limit" or "rate-limit" values are not updated as per configured values.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:22.2R3-S7 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
1845657
Major
Baseline configuration commit takes more time with 256000 MAC configurations
Product-Group=junos
On all Junos and Junos OS Evolved platforms with dual RE (Routing Engine), the baseline configuration commit takes more time when the device has 256000 MAC (Media Access Control) configurations configured under groups. It is a scaling issue, and occurs when a large number (256000 or more) of MAC configurations are configured. This has no impact to network traffic.

Resolved In: evo:24.4R1-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R1-S2 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1745565
Major
The mgd process crash is observed when 'show' is executed from the configuration mode
Product-Group=junos
On all Junos platforms, when 'show' is executed from the configuration mode, a mgd process crash is observed which has no functionality impact.

Resolved In: evo:20.4R3-S9-EVO evo:21.2R3-S6-EVO evo:21.3R3-S5-EVO evo:22.2R2-S2-J3-EVO evo:22.2R3-S1-J3-EVO evo:22.2R3-S1-J4-EVO evo:22.2R3-S2-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D36-EVO evo:22.3X80-D37-EVO evo:22.4R1-S2-J5-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R1-S1-EVO evo:23.1R2-EVO evo:23.2R1-J1-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:20.3X75-D46 junos:20.4R3-S9 junos:21.2R3-S6 junos:21.2X32-D20 junos:21.2X32-D30 junos:21.2X33 junos:21.2X8 junos:21.3R3-S5 junos:21.3X31 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.3X60 junos:22.4R2-S1 junos:22.4R3 junos:22.4R3-S5 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3B1 junos:23.3R1 junos:23.4R1 junos:25.1R1
1842518
Major
The device become unresponsive in a race condition due to maximum process (maxproc) limit
Product-Group=junos
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.

Resolved In: evo:22.2R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:22.4R3-S7-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-C1-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:21.4R3-S10-J6 junos:21.4R3-S12 junos:22.2R3-S6 junos:22.3X60 junos:22.4R3-S6 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S4 junos:23.4X1 junos:23.4X30-D20 junos:23.4X30-D30 junos:24.2R1-S2 junos:24.2R2 junos:24.2X1 junos:24.4R1 junos:25.1R1
1914952
Minor
The error message will be seen on CLI when 'clear log messages' command is issued
Product-Group=junos
On Junos platforms with BSD6 image, Error message will be seen on CLI when clear log messages command is issued.

Resolved In: evo:25.2R2-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2
PR NumberSynopsisCategory: Issues related to XML, JSON handling
1831811
Minor
CLI crashes for "show log | display json | no-more" execution if the log size is more than the process max stack size limit
Product-Group=junos
CLI crashes for "show log | display json | no-more" execution if the log size is more than the process max stack size limit.

Resolved In: evo:22.2R3-S7-EVO evo:23.2R2-S4-EVO evo:23.4R2-S3-C1-EVO evo:23.4R2-S5-EVO evo:23.4X100-D31-EVO evo:24.2R2-S1-EVO evo:24.4R1-EVO junos:22.2R3-S7 junos:23.2R2-S3-C21 junos:23.2R2-S4 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5 junos:23.4X30-D20 junos:23.4X30-D30 junos:24.2R2-S1 junos:24.2X1 junos:24.4R1
PR NumberSynopsisCategory: Issues related to YANG Data Models
1725934
Major
ODL controller is throwing unavailable capabilities error for few of the Openconfig Yang modules
Product-Group=junos
ODL controller is throwing unavailable capabilities error for few of the Openconfig Yang modules

Resolved In: evo:21.4R3-S6-EVO evo:22.2R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.2B1-EVO evo:23.2R1-EVO evo:23.3R1-EVO evo:23.4R1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:21.4R3-S6 junos:21.4X7 junos:22.2R3-S6 junos:22.3X60 junos:23.2R2
1826630
Major
Annotations are improperly structured in NETCONF after enabling YANG compliance
Product-Group=junos
When the YANG(Yet Another Next Generation)-compliant knob is configured, annotations containing non-alphanumeric characters are written as-is, instead of being escaped into their corresponding formats.

Resolved In: evo:22.4R0-J0-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-C1-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S5 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S4 junos:23.4X1 junos:23.4X30-D20 junos:23.4X30-D30 junos:24.2R1-S2 junos:24.2R2 junos:24.2X1 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1913169
Major
smdp process crashes during upgrade activity on Junos Fusion aggregation device
Product-Group=junos
In a Junos Fusion deployment with the MX platforms acting as an AD (Aggregation Device), performing a Junos upgrade on AD causes the spmd (Satellite Platform and Management Daemon) process to crash.

Resolved In: junos:22.4R3-S7-J7 junos:22.4R3-S9 junos:23.2R2-S6
PR NumberSynopsisCategory: VMHOST platforms software
1898108
Major
"re_rainier_perform_misc_checks:Failed to perform RE memory size check" from chassisd are flooding continuously and do not stop
Product-Group=junos
On Junos MX platforms, missing /bin/timeout utility can result in "re_rainier_perform_misc_checks:Failed to perform RE memory size check" from chassisd are flooding continuously.

Resolved In: junos:23.4R2-S6 junos:23.4R2-S7
PR NumberSynopsisCategory: QFX10002 Platform
1869232
Major
CRC errors increase continuously after interface flap on some 100G transceivers with Rx CDR LOL support
Product-Group=junos
On Junos PTX10002-60C, and QFX10002-60C platforms, when using 100G QSFP modules with CDR LOL support, CRC errors have been observed on odd-numbered ports, leading to traffic disruptions.

Resolved In: junos:22.4R3-S7-J1 junos:22.4R3-S9
1889649
Minor
Host loopback wedge detected on PTX10002-60C during VMHost reboot
Product-Group=junos
On PTX10002-60C platform, when VMHost reboot is performed during the initialization there are host loopback wedge seen on the device. Since they occurs during the initialization they do not impact any service.

Resolved In: junos:22.4R3-S7-J1
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1882490
Minor
BFD fail to establish over an IPsec tunnel on Juniper MX Series with the SPC3
Product-Group=junos
On Juniper MX Series platforms equipped with Services Processing Card version 3 (SPC3), Bidirectional Forwarding Detection (BFD) session establishment over an Internet Protocol Security (IPsec) tunnel may fail due to an unintended Time to Live (TTL) decrement on self-generated BFD traffic.

Resolved In: junos:21.4R3-S13 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: usf ipsec related issues
1851840
Major
USF-SPC3 : with ipsec PMI/fat-core enabled, "show services sessions utilization" cli not displaying right CPU utilization with possible workaround Use VTY instead of CLI as CLI fix will cause leak this has its own procedural risk so work around is good
Product-Group=junos
Use VTY instead of CLI as CLI fix will cause leak

Resolved In:
1884595
Minor
Allow default route to be created provided st0 IFL is in a non-default routing instance.
Product-Group=junos
ARI now allows default route to be pushed if the corresponding st0 interface is configured in a specific routing instance.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

Resolved In: evo:25.4R1-EVO junos:20.2R3-S11 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1

 

Modification History

2026-02-09 Update to include VMHOST image recalled for TSB103739 [juniper.net]

First publication 2025-12-01