Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX

Alert Description

Junos Software Service Release version 23.2R2-S6 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 23.2R2-S6 is now available.

23.2R2-S6 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 Mutlicast implementation
1873129
Major
The PTP packets are dropped when IGMP snooping is enabled
Product-Group=junos
Severity=Major
On EX4400, EX4100, QFX5120 and EX4650 platforms running Junos Operation System (OS), when Internet Group Management Protocol (IGMP) snooping is enabled on Virtual Extensible Local Area Network (VXLAN) Virtual Local Area Network (VLAN), all unknown multicast packets will be dropped. As a result, PTP (Precision Time Protocol) packets that use reserved multicast addresses are also discarded affecting the synchronization of the device with the clock server.
PR NumberSynopsisCategory: EX2300/3400 PFE
1899441
Major
Traffic loss is observed on the CVLAN interfaces during the transition between SP and EP configuration style
Product-Group=junos
Severity=Major
On Junos OS EX2300, EX3400, EX4100, EX4400, EX4650, EX4000 and QFX5K platforms with software-based MAC (Media Access Control) address learning enabled through interface-level MAC-limit or MAC-move-limit, the traffic fails to traverse CVLAN interfaces when changing the configuration mode from Service Provider (SP) style to Enterprise (EP) style and vice versa.
PR NumberSynopsisCategory: SRX2000/50000 issue
1904267
Major
In SRX high availability cluster, RG0 failover to secondary node fails as srxpfe daemons failed to reconnect to routing-engine on secondary
Product-Group=junos
Severity=Major
On all Junos OS SRX except branch SRX platforms, in high availability scenario, during redundancy group (RG0) failover, all the FPC PICs need to reconnect to the new primary routing-engine on secondary node within 16 seconds timer. However, this is not happening which is causing a connection reset and impacting traffic.
PR NumberSynopsisCategory: chassisd related issues for high-end SRX platforms
1887000
Minor
SRX4600 node 1 enters hardware failure during upgrade
Product-Group=junos
Severity=Minor
On SRX4600 platforms running Junos OS and configured in High Availability (HA), a hardware alarm is triggered during Low Impact Cluster Upgrade (LICU) procedures due to incorrect alarm logic tied to control link status. This condition affects Node 1 and causes Redundancy Group 1 (RG1) to failover to Node 0, even if Node 0 interfaces are not yet active, resulting in a traffic outage.
PR NumberSynopsisCategory: A20/A40 IOC card
1883027
Minor
SRX Firewalls with IOC3 triggers a temperature alert on the FPC 2 PLX PCIe Switch Chip
Product-Group=junos
Severity=Minor
On SRX5400, SRX5600, and SRX5800 platform with MPC3-40G10G and MPC3-100G10G (IOC3) interface card, a temperature alarm is triggered when the Peripheral Component Interconnect Express (PCIe) switch chip temperature exceeds 75 Celsius degrees.
PR NumberSynopsisCategory: Border Gateway Protocol
1889749
Major
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=junos
Severity=Major
On MX480 and MX960 platforms, routes become hidden when the "accept-own" feature is enabled in environments configured with rib-sharding. This issue arises when the "vrf-table-label" is configured within a routing instance and route sharding is enabled, potentially leading to routing failures.
1914814
Major
BGP task replication will be stuck in 'InProgress' state following an RE switchover when two single hop EBGP sessions are configured on two different interfaces using the IP addresses from the same subnet
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms with NSR (Nonstop Active Routing), when two single hop EBGP (External Border Gateway Protocol) sessions are configured to run on two different interfaces using IP addresses from the same subnet (overlapping subnet), the BGP task replication process does not complete after an RE (Routing Engine) switchover for the EBGP session with a specified local-address. This results in one BGP peer being in the 'Idle' state on the Backup RE while remaining in the 'Established' state on the new Master RE, causing the BGP task replication process to remain stuck in the 'InProgress' state.
PR NumberSynopsisCategory: BBE Remote Access Server
1813456
Minor
Error message is observed after device is restarted
Product-Group=junos
Severity=Minor
On all Junos Evolved platforms, the error message "UI_SCHEMA_SEQUENCE_ERROR" is observed when device is restarted. There is no traffic impact due to this issue.
PR NumberSynopsisCategory: MX304 Chassis specific platform
1841098
Minor
The kernel trace messages will be seen on the logs in Junos OS Evolved based platforms and Linecards
Product-Group=junos
Severity=Minor
On MX platforms with MPC11, LC4800, LC9600 , MX304 and all Junos OS Evolved platforms, kernel trace will be seen in the log messages in a rare scenario due to a floating point unit register corruption. There is no known functional impact due to these traces.
1905954
Critical
memory leak caused by using the "show ccl statistic summary ... " command
Product-Group=junos
Severity=Critical
On Junos OS and Junos OS Evolved platforms, running the command "show ccl statistic summary ... " cause memory leaks in the Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: L2NG Access Security feature
1904091
Critical
During virtual chassis switchover causes default dead route creation
Product-Group=junos
Severity=Critical
On all Junos OS EX and QFX platforms in Virtual Chassis (VC) , during switchover, a race condition between the dcd (Device Control Daemon) and dhcpd (Dynamic Host Configuration Protocol Daemon) causes the dcd to delete Interface Address (IFA) objects that were previously configured by dhcpd. This results in the addition of a default dead route by rpd in the routing table of the new master switch after GRES, leading to services to be impacted.
PR NumberSynopsisCategory: Device Configuration Daemon
1916208
Major
Traffic drops due to VLAN configuration not updated for Ethernet-Switching Interfaces
Product-Group=junos
Severity=Major
On Junos OS platforms in which VLAN information can be given as a VLAN member name, if both VLAN (Virtual Local Area Network) IDs and VLAN member names are configured together on an interface within a routing instance, the VLAN membership does not update correctly on that interface, resulting in traffic impact associated with that VLAN.
PR NumberSynopsisCategory: Firewall Filter
1856854
Major
MIB2D will see 100% CPU utilization due to MIB2D walk fail
Product-Group=junos
Severity=Major
On PTX3000/PTX5000/PTX10008 /PTX10016/QFX10008 /PTX1000/PTX10002/ QFX10002 platforms, MIB2D will see 100% CPU utilization due to MIB2D walk failure.
1859894
Major
MIB2D stucked at 100% on MX10003
Product-Group=junos
Severity=Major
On all MX platforms, during interface flaps with interface-specific / list filters we may see an error "get_counter_list_async: failed in reading counter names (No such file or directory)" due to internal clean-up missing. Please, note that this error is also seen during the churn. This could result in MIB2D hitting at 100% CPU if error remains consistent. The best way to escape this 100% CPU is to restart MIB2d process as soon as the said error is noticed and keep repeating with same counter name.
PR NumberSynopsisCategory: CoS support on DNX
1897336
Major
ARP resolution and device discovery failure is observed due to unexpected VLAN tags on ARP replies
Product-Group=junos
Severity=Major
On ACX710 and ACX5448 platforms, due to VLAN edit profile remapping and VLAN translation, all the packets are getting VLAN-tagged. The RE ( Routing Engine ) drops ARP ( Address Resolution Protocol ) reply packets that contain VLAN ( Virtual Local Area Network ) tags, if the interface encapsulation was set to ethernet-ccc and VLAN configuration was removed. As a result, ARP resolution fails, leading to ping and device discovery failure.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1908719
Major
On all mx platforms chassid gets stuck and becomes unresponsive it resumes only after restarting both control units
Product-Group=junos
Severity=Major
On MX devices, the sub-linecard feature with MPC11 cards. When this feature is used, the main system process can sometimes freeze, which may lead to system crashes and error logs.
PR NumberSynopsisCategory: EVO Netstack FIB Service Daemon
1785913
Critical
Junos OS Evolved: TCP session state is not always cleared on the Routing Engine leading to DoS (CVE-2024-47502)
Product-Group=junos
Severity=Critical
An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88132 [juniper.net] for more information.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1899530
Major
MAC learning failure when moving the AE interface from one VLAN to another VLAN in a single commit
Product-Group=junos
Severity=Major
On Junos OS Evolved platforms, when an Aggregated Ethernet (AE) logical interface (IFL) is moved from one Virtual LAN (VLAN) to another VLAN in a single commit, Layer 2 forwarding tables fail to update correctly. This causes Media Access Control (MAC) learning failure and traffic disruption.
PR NumberSynopsisCategory: Lacp related problems and issues.
1898531
Major
AE interfaces flap during GRES following an RE reboot on all Junos Evolved platforms
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, Aggregate Ethernet (AE) interfaces with LACP configured will experience a flap due to a timing issue when Graceful Routing Engine Switchover (GRES) is performed after a Routing Engine (RE) reboot, resulting in traffic loss during the flap.
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1750699
Major
Observing routes missing in few scale VRF configuration after doing "Interface Flap"
Product-Group=junos
Severity=Major
In scaled scenario (1 million BGP routes and 1000 VRF's), interface flap will impact relearning routes with few VRFs and the routes are missing. Clearing BGP neighbors should recover the issue. Issue is applicable to all EVO platforms.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1871272
Major
RPD coredump on PTX10002-36qdd after the any configuration commit
Product-Group=junos
Severity=Major
During configuration commits, management daemon(mgd) updates juniper database /var/rundb/juniper.data. The information about this file (such as path, size, etc) will be populated in junos daemon using a data structure called dbm_mmap_table. During configuration commits, management daemon(mgd) updates juniper database /var/rundb/juniper.data. The information about this file (such as path, size, etc) will be populated in junos daemon using a data structure Since RPD is multithreaded, every shard has its own copy of data. Upon every commit, the size of /var/rundb/juniper.data changes and when a particular size/limit is reached, mgd decides to resize the database to take it to a next higher size (say, from 1.5MB to 2MB). Now, upon this particular SIGHUP, the new information should be reflected in every shard thread of RPD.However, due to an initialization problem, the worker threads continue to look into stale data. causing the core-dump.
PR NumberSynopsisCategory: EVPN control plane issues
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby) the ARP (Address Resolution Protocol) tables from Customer Edge (CE's) device may not update simultaneously on Provider Edge (PE) devices when an IP address moves between two different Ethernet Segments (ESIs) during a switchover, leading to temporary traffic disruption until the tables are refreshed.
PR NumberSynopsisCategory: EX4100 PFE
1905783
Major
FXPC core dumps and crashes on EX switches during RA packet processing when SLAAC snooping is enabled
Product-Group=junos
Severity=Major
On EX switches, when SLAAC Snooping is enabled in certain IPv6 Router Advertisement (RA) packet, both PFE (Packet Forwarding Engine) and Routing Engine (RE) are used to free the same packet leading to double free scenario. This double packet free eventually might lead to FXPC cores and switch crashes caused by an invalid access or while freeing the packet. This impacts overall switch stability.
PR NumberSynopsisCategory: EX4100 RE, Platform Infra, Drivers
1833698
Major
On Junos EX4100 and EX4400 platforms, switch core dump when user commits a command to ignore a "power entry module" alarm
Product-Group=junos
Severity=Major
On Junos EX4100 and EX4400 platforms, at commit time to configure device to ignore a PEM (Power Entry Module) alarm, switch core dump due to an error on Chassis control process (chassisd).
PR NumberSynopsisCategory: EX POE
1876675
Major
On EX4100/EX4400s platforms PoE powered devices connected do not come up when adding a second power supply unit
Product-Group=junos
Severity=Major
On EX4100/EX4400s platforms using Perpetual PoE and Fast PoE, if power is lost due to one PSU (Power Supply Unit) being removed and the system shuts down, the PoE-powered devices will not automatically power back on when the system is restarted using the other PSU (e.g., switching from slot 0 to slot 1 or vice versa).
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1865354
Major
Traffic to anycast IPv6 destination addresses dropped when using ECMP routes
Product-Group=junos
Severity=Major
On QFX10002-60C platforms when ECMP is required to get multiple-path to multiple hosts connected, and with IPV6 address configured as a destination address, the destination MAC rewrite process fails, due to the unilist nexthop for IPv6 destination is getting overwritten. This leads the IPv6 packets to the host, to get dropped over the ECMP routes.
1884163
Major
IFL Memory Leak on QFX10K8/16 device
Product-Group=junos
Severity=Major
On QFX10K8/16 , IFL memory is not freed on non-local interface of FPC during configuration changes (eg: IFL delete/deactivate) for L3IFL/L2IFL on AE/Scalar interfaces. Fix is present in common code and risky. It is a day one issue and the per IFL leak is minimal (0.00016% of total Kernel heap size) .
PR NumberSynopsisCategory: FIPS related issues
1871858
Minor
The device is in a reboot loop when fips mode is enabled
Product-Group=junos
Severity=Minor
On all Junos platforms, after loading the image where FIPS (Federal Information Processing Standards) mode is already enabled, the FIPS self-test may fail and the device may encounter a reboot loop.
PR NumberSynopsisCategory: SRX1500 platform software
1896794
Major
On SRX1500 platforms, after PFE crash, FPC cannot come online
Product-Group=junosvae
Severity=Major
On SRX1500 platforms, when transit packets get stuck, PFE crash and PFE core-dump is generated. FPC remains 'present' state until reboot, all the services running on that FPC will be impacted.
1910445
Major
Link status of disabled SFP-T port becomes up after rebooting on SRX1500
Product-Group=junos
Severity=Major
When an SFP-T port is disabled, it shows admin down but can be in a physical up state after a reboot.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1706125
Major
ifHCOutOctets unexpected spikes in value
Product-Group=junos
Severity=Major
On SRX4100 and SRX4200 platforms, the ifHCOutOctets interface counter values may sometimes incorrectly spike and exceed interface speed.
PR NumberSynopsisCategory: jdhcpd daemon
1911001
Major
On Junos devices supporting subscriber services acting as DHCPv6 relay randomly deletes IA_NA or IA_PD binding/route
Product-Group=junos
Severity=Major
On all Junos devices supporting subscriber services, in case of dual stack DHCP (Dynamic Host Configuration Protocol) subscribers with IA_NA (Identity Association for Non-temporary Address) and IA_PD (Identity Association for Prefix Delegation) bindings with lease times (For the assignment of IPv6 address to a client device), when a client initiates separate renew exchanges for the IA_NA and IA_PD, and once client and DHCP server are in sync with these timers, there can be a race condition at Junos device which is DHCPv6 relay, has not refreshed lease timer and can go out of sync. This can result in deleting IA_NA/IA_PD binding and route to get deleted for that subscriber only. This causes one of the leg for IA_PD or IA_NA to go down for that subscriber, which can result in traffic impact for that leg.
PR NumberSynopsisCategory: Flow Module
1892015
Major
Junos MX/SRX flowd Crash After Tunnel Removal Leaves Stale Flows, Causing FPC Reboot
Product-Group=junos
Severity=Major
On Junos OS SRX and MX platforms, any tunnels such as GRE, IPIP, DS-Lite, or IPSEC tunnel has its configuration removed, the IKE SAs can go down causing invalid entires. These can later cause the flowd process to crash
1903515
Major
On the SRX platform the FPC reboots when traffic reaches the FAT IPSec tunnel
Product-Group=junos
Severity=Major
All Junos SRX platforms that support PMI (Power Mode IPsec) experiences FPC reboot due to traffic hitting the FAT (flow aware transport) IPSec tunnel configuration.
PR NumberSynopsisCategory: flow ha module
1895134
Minor
ISSU failure and process crash on primary node during HA upgrade
Product-Group=junos
Severity=Minor
On all Junos SRX platforms, performing ISSU (In-Service Software Upgrade) with the no-validate option in HA ( (High availability ) setups can cause ISSU failure and a process crash on the primary node.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1895790
Major
Backup node stuck in cold sync failure after all FPCs reset due to SPC crash files in SRX chassis cluster
Product-Group=junos
Severity=Major
On all SRX platforms, in a chassis cluster scenario, the PFE crashes on the backup node. After the crash files are fully generated, this triggers a reset of all FPCs. Following the crash and FPC resets, the backup node enters a cold sync failure state and remains in that state until it is manually rebooted.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1864322
Major
On rare circumstances the kmd or iked process crash will be observed on using the third-party library API
Product-Group=junos
Severity=Major
On all Junos platforms using ipsec-key-management (daemon name kmd) or the ike-key-management (daemon name iked) service for the IPSec VPN functionality, under very rare scenarios the device can be extremely overloaded so that it cannot generate a random number required for the VPN negotiation after repeated attempts. When this occurs, the VPN negotiation daemon kmd or iked can crash. The VPN operation may or may not be temporarily impacted and will recover automatically.
1901732
Major
VPN traffic stops flowing intermittently on the st0 interface on SRX platforms
Product-Group=junos
Severity=Major
On Junos SRX platforms, Virtual Private Network (VPN) traffic stops even though the IPsec tunnel remains UP. This issue occurs when Class of Service (CoS) is configured on the secure tunnel (st0) interface. IPsec packet processing fails, and memory buffer (mbuff) resources are not freed, leading to resource exhaustion. As a result, encrypted traffic cannot be transmitted through the tunnel. The problem does not impact tunnel status or Internet Key Exchange (IKE) negotiation, but impacts the interface traffic.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1909786
Critical
EVPN traffic blackholing occurs due to incorrect ARP binding when VGA IP is used as re-ARP source
Product-Group=junos
Severity=Critical
On all Junos platforms, In Ethernet VPN (EVPN) Virtual Extensible LAN (VXLAN) deployments using Integrated Routing and Bridging (IRB) interfaces with a virtual gateway IP address and virtual gateway Media Access Control (MAC) configuration, re-ARP packets may use the virtual gateway IP as the source IP while using the IRB MAC as the source MAC. This behavior can cause connected hosts to overwrite their Address Resolution Protocol (ARP) entries, resulting in traffic being forwarded to an incorrect leaf switch in all-active Link Aggregation Group (LAG) multihoming scenarios. This may lead to intermittent or complete traffic loss for hosts connected via LAG to dual-homed leaf devices.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1911538
Major
Show command execution failure for show system macsec license on MX platforms
Product-Group=junos
Severity=Major
On all Junos MX10004, MX10008, MX304, MX301 platforms on executing the command "show system maces license" fails and doesn't fetch any information however it doesn't cause any service disruption. This is a Day-1 issue.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=junos
Severity=Major
This is a timing issue seen on all Junos and Junos OS Evolved platforms when the optimisation timer expires for a member LSP (Label-Switched Path) when normalisation is in progress for a container LSP, this generates an unrequired route update leading to the link protection route of the LSPs to flap. LSP flap will result in impact on the traffic.
PR NumberSynopsisCategory: MX10K platform
1846557
Critical
When "set chassis redundancy failover on-re-to-fpc-stale" is configured unexpected master RE switchover will be seen if backup RE reboots resulting in traffic disruption
Product-Group=junos
Severity=Critical
On Junos OS MX10008/MX10016/MX10004 platforms, When "set chassis redundancy failover on-re-fpc-stale" is configured and the backup Routing Engine (RE) is rebooted, traffic disruption will be observed. This is due to a brief loss of internal system connectivity particularly the control link between the master RE and the FPCs (Flexible PIC Concentrators). During this time, the FPC reboots and interface will go down. This issue happens while the backup RE reboots, missed keepalives cause the master RE to mistakenly assume a communication failure and briefly step down, triggering a mastership re-election and re-elects itself as master that results in a traffic disruption as FPCs reboots before recovering.
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=junos
Severity=Major
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.
1910534
Major
SPC3 crashes when three-color policer is attached to firewall filter
Product-Group=junos
Severity=Major
On MX platforms with SPC3, when three-color policer is configured and attached to firewall filter SPC3 crashes and flowd crash files are seen. This will cause service impact since SPC3 keeps crashing and may not come up if the configuration leading to crash is not deleted.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1795218
Minor
JUNOS_REG: MX : With the GR interface configured, ASIC error at PFE can trigger vmcore on backup.
Product-Group=junos
Severity=Minor
With the GR interface configured, ASIC error at PFE can trigger vmcore on backup.
1897240
Major
Chassis-Control restart triggers when configuring GRE interface across multiple routing-instances leading to kernel crash
Product-Group=junos
Severity=Major
On Junos series devices, the kernel crash occurs when creating and configuring a identical GRE(Generic Routing Encapsulation) interface across different routing-instances.
PR NumberSynopsisCategory: Issues related to PKI daemon
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
Severity=Major
In stressful conditions, FPC crash observed and core file generated when PKI (Public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured, on all Junos platforms supporting PKI and SSL-Proxy services (MX, PTX, SRX).
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
Severity=Major
On Junos QFX5k and EX4k platforms, if VPLAG(Virtual Private Link Aggregation group) is configured and if there is event change which could make ECMP(Equal Cost Monitoring Protocol) programming to change like ECMP link flap, dcpfe restart, system reboot etc which causes traffic loss.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1810740
Major
Link wont come up on bounce of fec91 on QFX5120 platform
Product-Group=junos
Severity=Major
On QFX5120-48T, Interface links are not coming up at DUT after restoring the FEC configuration from mistmatched FEC configuration at non-dut.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1758400
Major
JUNOS_REG: QFX51200-48YM: Fan status output was not same after/before device vc-switch over.
Product-Group=junos
Severity=Major
In a QFX51200-48YM-8C VC setup, after a a mastership switch over fan tray of linecard may not be displayed in show chassis hardware and show chassis environment. There is no functional impact
PR NumberSynopsisCategory: KRT Queue issues within RPD
1908681
Major
RIB and the FIB inconsistency results in traffic loss in IPsec scenario with st0 interface configured
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having IPsec (Internet Protocol Security) with st0 (Secure Tunnel Interface) interface configured, traffic loss will be observed if the "next-hop-tunnel" configuration is removed and added within a few seconds. This happens due to a inconsistency between the RIB (Routing Information Base) and the FIB (Forwarding Information Base).
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1807037
Major
BGP backup routes are installed as primary routes after enabling 'protect core' feature
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms when Border Gateway Protocol (BGP) multipath is enabled for Layer 3 Virtual Private Network (L3VPN) routes and 'protect core' is enabled on the Virtual Routing and Forwarding (VRF) instance, the backup BGP path is installed as primary path. The Next hop weight value is not updated correctly, it is weight 0x1 instead of weight 0x4000 for the backup.
1812124
Minor
The rpd process crash is observed when the label received exceeds the configured maximum-labels 16
Product-Group=junos
Severity=Minor
On Junos and Junos Evolved platforms, the rpd process crash is observed on both REs (Routing Engines) and RE switchover was triggered when maximum-labels under MPLS(Multi Protocol Label System) address family is configured as 16 and an extra label is received.
1907558
Major
The rpd process crashes in a vrf having EVPN-VXLAN routes with specific configuration.
Product-Group=junos
Severity=Major
In all Junos and Junos OS Evolved platforms, when EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible LAN) routes are present in a VRF (Virtual Routing and Forwarding), configuring a generate route in same vrf can cause rpd (Routing Protocol Daemon) to crash and restart. Generate route configuration has to be removed to recover from this behaviour.
PR NumberSynopsisCategory: Resource Reservation Protocol
1896022
Major
More bandwidth admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
Severity=Major
On all Junos and Junos evolved platforms with Point of Local Repair Router, in a Multiprotocol Label Switching(MPLS) Label Switched Paths (LSPs) set-up if the ingress router is configured with link-protection , if Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1906065
Major
ifStackStatus is not reported correctly for one or more AE bundles
Product-Group=junos
Severity=Major
On all Junos, the ifStackStatus query is executed after the system reboot, the member link status is not reported correctly for one or more AE (Aggregated Ethernet) bundles and thus the relation between AE IFL (Logical Interface) and corresponding member link IFL's cant be fetched from ifStackTable. This is an error message and no traffic impact will be observed.
1913131
Major
On MX301 snmd may core in certain scenarios.
Product-Group=junos
Severity=Major
On MX301 snmd may core in certain scenarios.
PR NumberSynopsisCategory: SRX branch platforms
1893957
Minor
SRX configured with a native VLAN ID other than 1 experienced DHCP assignment issues and ARP resolution failures to the default gateway
Product-Group=junos
Severity=Minor
In SRX configured with a native VLAN ID other than 1, connected devices successfully obtain DHCP IP addresses but are unable to resolve ARP for the default gateway. Although the SRX sends ARP replies, these responses do not reach the connected devices. Corresponding packet discards are observed in the Packet Forwarding Engine (PFE), indicating that the ARP replies are being dropped before reaching the endpoints.
1895179
Major
The kern.maxfiles limit exceeded observed due to log rotation resulting in unresponsive SSH
Product-Group=junos
Severity=Major
On all Junos OS platforms, Configuring multiple syslog servers causes duplicate routing-instance map entries, leading to an eventd file descriptor leak during log rotations. Once the threshold is exceeded, the SSH connection becomes unresponsive.
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1869285
Major
Speed conversion from 10G to 1G on MX routers with MPC7E-10G does not synchronise across PFE and Kernel when adding the interface to Aggregate Ethernet (AE)
Product-Group=junos
Severity=Major
On MX Series routers with MPC7E-10G line cards when interface speed is converted to 1G and the interface is added to AE, speed change is not getting synchronised across Packet Forwarding Engine (PFE) and Kernel, leading to inconsistencies in bandwidth reporting and Class of Service (CoS) behaviour. Using 'set interfaces speed 1g', ensures proper synchronisation across all modules.
PR NumberSynopsisCategory: MX10003/MX204 Platform SW - Chassisd s/w defects
1818517
Minor
Fan Tray Outer Fan running at over speed alarm is reporting after upgrade
Product-Group=junos
Severity=Minor
For MX10003 fan min and max threshold were -40 and +20 set. If fan RPM goes below/beyond those RPM, s/w start raising alarms. Similarly for MX204 fan min and max threshold were -20 and +20 set. On log analyzing, its seen FAN RPM was running +34% , that was beyond ma threshold. After discussing with h/w team, min & max threshold values are now decided -40 and +40. Due to this FAN RPM will be in bandwidth and no alarm will be seen.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1846340
Major
FPC0 will not transition to Online and may generate chassis alarm "FPC 0 Hard errors" in SRXTVP devices deployed in chassis cluster
Product-Group=junos
Severity=Major
On SRX TVP platform devices (SRX1500, SRX1600, SRX2300, SRX4100, SRX4120, SRX4200, SRX4300, SRX4600, SRX4700, SRX5k-SPC3) deployed in a chassis cluster, after rebooting the Secondary node, if count of RIB (Routing Information Base) /FIB (Forwarding Information Base) is above 15000, FPC0 will not transition to Online, and a "FPC 0 Hard errors" chassis alarm may be generated.
1886757
Minor
Alarms for high usage in /var partition are not generated
Product-Group=junos
Severity=Minor
On Junos SRX4600/SRX4700/SRX1600/SRX2300/SRX4300 platforms, alarms for high usage at /var partition storage is not reported.
1904696
Major
FPC flaps and the Ukern process will crash on certain SRX platforms when the policer action is changed from 'discard' to 'loss-priority'
Product-Group=junos
Severity=Major
On SRX4600, SRX4700, and SRX5K platforms, the Flexible PIC Concentrator (FPC) flaps and Ukern process will crash when the policer action is changed from 'discard' to 'loss-priority'. Traffic will be impacted when the FPC flaps.
1911845
Critical
SRX PFE crash is observed if nexthop limit is reached
Product-Group=junos
Severity=Critical
On all SRX platforms, SRX PFE ( Packet Forwarding Engine ) crash is observed if next-hops in the PFE next-hop table exceeds the limit 64k.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1897464
Major
Memory allocation failure in all the FPCs inside the NH partition
Product-Group=junos
Severity=Major
On all affected platforms, under rare conditions involving heavy control-plane churn and a large number of interfaces within a routing instance, memory allocation failures related to Next-Hop processing will occur. This can lead to traffic drops and, in severe cases, complete service disruption across multiple FPCs.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1905768
Major
FPC crash triggered when a line card reboots with a large number of static subscribers
Product-Group=junos
Severity=Major
On all MX platforms with the MPCs/Line cards except MPC10E, MPC11E, LC9600 and MX304. When a line card hosting an AE ( Aggregate Ethernet ) interface with a large number of static subscribers (around 4000) reboots, excessive processing load across multiple subscriber interfaces will cause delays that trigger the watchdog timer and result in an FPC ( Flexible PIC Concentrator ) crash.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1908413
Minor
On MX150 platform system crash or interface/protocol flaps when sampling or jFlow or firewall features are present
Product-Group=junos
Severity=Minor
On MX150 platforms, enabling sampling, jFlow, or firewall features causes continuous mbuf pool leaks, leading to system crash or interface/protocol flaps. The issue can occur after loading the configuration or sending traffic related to the said features.
1913870
Major
GRE-over-GRE tunnel is down due to keepalive packets dropped
Product-Group=junos
Severity=Major
On Junos MX204, MX240, MX480, MX960, MX2008, MX2010, MX2020 and MX10003 platforms using a version of line cards MX2K-MPC(6/9)E, MX-MPC(2/3)E or MPC(3/5/7)E; when Generic Routing Encapsulation (GRE)-over-GRE is configured, end-to-end keepalive packets in the outer tunnel are dropped, and tunnel interface cannot pass traffic
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1872820
Major
The dcd process crashes when deactivating only 'swap' under ' interfaces <> unit <> output-vlan-map' with no other attributes present
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, this issue affects configurations where Virtual Local Area Network (VLAN) mapping is used, particularly in scenarios where only the swap attribute is applied under 'interfaces <> unit <> output-vlan-map'. Sequence of 'Deactivate -> Activate -> Commit' of the config hieararchy leads to crash of the device control daemon (dcd) process, potentially causing service disruption.
1914952
Minor
The error message will be seen on CLI when 'clear log messages' command is issued
Product-Group=junos
Severity=Minor
On Junos platforms with BSD6 image, Error message will be seen on CLI when clear log messages command is issued.
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1913169
Major
The smdp process crash is observed on MX Aggregation Device during Junos upgrade in a Junos Fusion Deployment
Product-Group=junos
Severity=Major
In all Junos MX platforms acting as the AD (Aggregation Device) in a Junos Fusion deployment, a Junos software upgrade causes the smdp (Satellite Platform and Management Daemon) process to crash impacting forwarding plane services. This issue is observed when AD nodes are moved to a higher Junos version while the SD (Satellite nodes) are still running a lower version.
PR NumberSynopsisCategory: ACX7000 hwd/chassisd software related issues.
1700839
Minor
ACX7100-32C/ACX7100-48L reports "/psm/0/ hwdre/0/cm/0/ psm_mcu /psm0/psm_cml_cmd_fault" even though the PSM is in working order
Product-Group=junos
Severity=Minor
On ACX7100-32C/ACX7100-48L platforms, "/psm/0 /hwdre/0 /cm/0 /psm_mcu/ psm0/psm_cml_cmd_fault" error is observed even though the PSM is in working order.
PR NumberSynopsisCategory: usf ipsec related issues
1869198
Major
After IPv6 tunnel is up and the iked daemon is restarted, post clearing of the IKE SA, ping from one end to the other end is not working as expected
Product-Group=junos
Severity=Major
If st0 IFL is configured with inet6 family alone, then it is observed that after IKED daemon is restarted and whenever the new IPSec tunnel is formed over that st0 IFL, the traffic over the tunnel will not work as the st0 metadata will not get programmed properly over the st0 IFL.
PR NumberSynopsisCategory: Unified Services Framework
1912459
Critical
The nsd process crash will be seen on MX platforms when configuration change is commited using ephemeral database
Product-Group=junos
Severity=Critical
On MX platforms with SPC3 line cards, when the ephemeral configuration-database is configured, parsing of the respective hierarchies by nsd (Network Security Domain) was faulty and leads to the daemon crash.

 


 

23.2R2-S6 - List of Known issues

PR NumberSynopsisCategory: EX4000 HW issues
1902609
Minor
Intermittent kernel panic results in device reboot or fxpc crash
Product-Group=junos
On all EX4000-48MP/EX4000-48P/EX4000-48T platforms, false ECC (Error-Correcting Code) alarms are observed due to the usage of un-initialised memory on the chip and intermittent kernel panic might result in vm core dump causing device reboot or fxpc crash. This results in impact on the traffic.

Resolved In: junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4B1 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: NFX Layer 3 Features Software
1776216
Major
IPsec Tunnel behind NAT stops passing traffic when the NAT port Number or IP address changes
Product-Group=junos
On Junos SRX and NFX series platforms, when the peer device located behind a Network address translation (NAT) device, experiences a change in the NAT port number or Internet Protocol (IP) address, the next Dead Peer Detection (DPD) or rekey process fails to update the port number in the existing tunnel NAT Traversal (NAT-T) flow session if the DPD "always-send" is being configured. This leads to communication failure over the Internet Protocol Security (IPsec) tunnel.

Resolved In: junos:22.4R3-S2 junos:23.4R2 junos:24.1R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: NFX Series Platform Software
1858495
Major
The auto-negotiation is not working properly on NFX350 platform using 1 Gigabit Ethernet SFP
Product-Group=junos
On NFX350 platforms connected to certain peer devices over SFP 1 Gigabit Ethernet (GE) with auto-negotiation enabled at both ends, a communication issue occur during the initial connection between devices, causing a mismatch in their status. As a result, the port status on the peer device appear as up/down affecting the traffic.

Resolved In: junos:24.2R2-S2 junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: BBE routing
1922536
Major
Forwarding issues for an access DHCPv6-PD or access-internal DHCPv6-IA route or both may be seen on LNS due to an incorrect route programming of such route on PFE
Product-Group=junos
Drop of traffic to subscriber DHCPv6 prefixes may be observed on LNS (L2TP network server) if CPE uses IPv6 address obtained via NDRA process as the source address for DHCPv6 negotiation instead of link-local address.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Firewall Filter
1903047
Minor
Intermittent traffic loss after pfe reset due to FLT filters
Product-Group=junos
On all Junos MX platforms with line cards MPC7/8/9 (EA Asic) , if any PFE restarts as part of any encountered CM Error defects, then fast-lookup-table filters will not work properly and traffic black holing will be seen.

Resolved In: evo:25.2R2-EVO evo:26.1R1-EVO junos:23.2R2-J22 junos:24.2R2-J11 junos:24.2R2-S2-J12 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
1903874
Minor
[MX10008] cmd='ls -i /var/etc/filters/filter-define.conf' is logged every 1 second instead of every 30 seconds
Product-Group=junos
An issue where client sessions were not cleared on a router/switch, leaving stale session data that triggered immediate timeout handling instead of the expected 30?second delay. This caused once?per?second master?data lookups and repeated log entries such as "ls -i /var/etc/filters/filter-define.conf", but had no functional impact.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S7 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: DNS software support.
1851909
Major
Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash (CVE-2026-21920)
Product-Group=junos
An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA106020 [juniper.net] for more information.

Resolved In: junos:22.4R3-S7 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:26.1DCB
PR NumberSynopsisCategory: Alias for DHCP issue on DNX based platform.
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:24.1B1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4X30-D30 junos:23.4X9 junos:24.1B1 junos:24.1R1 junos:24.2R1 junos:24.4R2-S3
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: EX interfaces issues
1909608
Minor
Auto-negotiation is not displayed in 'show interfaces' command output
Product-Group=junos
On EX3400 and EX4400-48F, when using 1G optics, the auto-negotiation information does not appear in the output of the "show interfaces" command.

Resolved In: junos:24.2R2-S4 junos:24.4R2-S3 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: EX4400 platform
1814463
Minor
EX4400: MIST: Wrong PSU state is updating in the mist
Product-Group=junos
Unsupported PEM/PSU is shown as online (green)in the MIST Dashboard and the output of "show chassis environment" for that PSU shows the status as present/OK. No functional impact.

Resolved In: junos:23.4R2-S6 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: EX POE
1879702
Major
There is a PoE short circuit alarm after upgrading the device
Product-Group=junos
On all Junos EX2300, EX3400, EX4400, EX4300 platforms running in Virtual Chassis or Standalone and during normal operation of the switch when POE (Power Over Ethernet) get port status command fails to read then software reads the garbage value from the response buffer and sends to chassisd due to which it results in PoE short Circuit alarm. However, this is a non-existent PoE alarm and non-impacting issue.

Resolved In: junos:22.4R3-S8 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Express ASIC interface
1793344
Major
The 10g channelized Interface doesn't come up after router reboot on the PTX5000 platform
Product-Group=junos
On Junos PTX5K platforms running 22.3X60 configured with FPC3-PTX-U2 and FPC3-PTX-U3, the 10g channelized Interface port doesn't come up after router reboot. In rare conditions, the interface might remain down when firmware attempts to configure the line-side lane configuration during the firmware mode set process.

Resolved In: junos:22.3X60 junos:22.4R3-S5
PR NumberSynopsisCategory: MX MIC-3D-10GE-SFP-X driver
1906675
Major
Link failure due to auto-negotiation state getting stuck on MX platforms having Junos OS
Product-Group=junos
On all Junos OS MX platforms that support MPC2E-NG, MPC2E-3D-NG-Q, MPC3E-NG and MPC3E-3D-NG-Q, the Auto-Negotiation (AN) process on certain PHY interfaces of the MIC (MIC-3D-10GE-SFP-E) may intermittently get stuck, preventing link establishment and causing traffic loss. This issue can be triggered by reinserting an SFP-T module, multiple times restarting the mic or by interface driver resets, which lead to inconsistent enable/disable sequences during Auto-Negotiation.

Resolved In: evo:25.2R2-EVO evo:26.1R1-EVO junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:26.1R1
PR NumberSynopsisCategory: Juniper Device Manager VM Mgmt and infrastructure function
1675919
Critical
NFX350 :: JDI_REGRESSION:PLATFORM:SWITCHING:JDM:: Core "localhost.libvirtMib_suba.15909.1656455866.core.tgz" is seen on NFX-350 boxes
Product-Group=junos
NFX350 :: JDI_REGRESSION:PLATFORM:SWITCHING:JDM:: Core "localhost.libvirtMib_suba.15909.1656455866.core.tgz" is seen on NFX-350 boxes

Resolved In:
PR NumberSynopsisCategory: Flow Module
1892890
Minor
SRX drops to-the-box ICMPv6 echo request with sequence number 3503 and 35000 through 35999
Product-Group=junos
On all SRX platforms, to-the-box ICMPv6 echo request with sequence number 3503 and 35000 through 35999 will be dropped

Resolved In: junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: SRX PFE side GRE/IPIP/DS-Lite/IPSec/PIM/VXLAN tunnel
1884150
Major
Policy match failure for VXLAN EVPN type-5 cross vrf traffic
Product-Group=junos
On all SRX platforms, Ethernet Virtual Private Network (EVPN) Type-5 Virtual Extensible LAN (VXLAN) cross-Virtual Routing and Forwarding (VRF) traffic fails to match security policies when the ingress and egress VRFs are mapped to different VRF groups.

Resolved In: junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Firewall Policy
1882193
Critical
On SRX platform flowd process is generating crash files.
Product-Group=junos
On Junos OS SRX platforms, a crash in the flowd process occurs when the system attempts to retrieve interface information. During this process, an invalid memory address is accessed while copying the interface memory address from the database. This issue typically arises when accessing interface details to check session status on the backup device.

Resolved In: junos:19.4R3-S16 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1912271
Major
State synchronization failure between SRX cluster nodes
Product-Group=junos
On all SRX series platform in cluster with IKED package enabled, when the backup node becomes active, some tunnel configuration were missing. This occurs because, during cold synchronization, the IPC communication between IKED and SPU can have a chance to fail due to a kernl error which ultimately led to traffic disruption.

Resolved In: junos:24.4R2-S2-J1 junos:24.4R2-S3 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1816344
Major
EVPN : Traffic failure after multiple link flaps of core facing interfaces on scaled setup
Product-Group=junos
ARP resolution failure when there is quick flap of core facing interface on scaled setup

Resolved In: evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Label Distribution Protocol
1906611
Major
Crash in the rpd process after LDP P2MP LSP Identifier reaches its maximum value and rolls over, due to duplicate identifier allocation
Product-Group=junos
On all Junos OS and Junos OS Evolved versions that support Label Distribution Protocol Point-to-Multipoint Label Switched Paths (LDP P2MP LSPs), the rpd process (routing protocol daemon) crashes when an LSP Identifier reaches its 24-bit maximum value (224 1 = 16, 777, 215) and rolls over to the starting value because a duplicate identifier is incorrectly allocated. This condition occurs only after prolonged tunnel flapping (typically more than 16 million flaps). When the rpd process crashes, routing convergence is briefly disrupted, and services relying on label-switched traffic are impacted until the process automatically restarts.

Resolved In: evo:26.1R1-EVO junos:26.1R1
PR NumberSynopsisCategory: PTX1000 platform
1770739
Critical
Reboot on PTX1k with image 22.3x60 causes fpc to reboot with "Fatal ASIC initialization error, Offlining FPC" Error message
Product-Group=junosvae
Reboot on PTX1k with image 22.3x60 causes fpc to reboot with "Fatal ASIC initialization error, Offlining FPC" Error message times

Resolved In: junos:22.2R3-S3 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.3X60 junos:22.4R3-S2 junos:22.4R3-S8 junos:22.4X3 junos:22.4X4
PR NumberSynopsisCategory: Multiprotocol Label Switching
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.4R2-S7 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1902405
Major
The rpd process crash is observed with MVPN and RIB sharding enabled
Product-Group=junos
On Junos MX and Junos Evolved PTX platforms , with RIB sharding enabled and if either IPv4 or IPv6 address family is disabled in MVPN (multicast virtual private network), the unicast route flow from shard tries to access MVPN data structures without validation leading to rpd (Routing Protocol Daemon) process crash.

Resolved In: evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2-J2 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Odin Timing software
1900889
Major
[ACX710] acx-arm-feb process is 100% utilised after upgrading Junos to 23.2R2-Sx releases and enabling interfaces with PTP/ SyncE configuration.
Product-Group=junos
After upgrading Junos on ACX710 to a 23.2R2-Sx release, the acx-arm-feb process may run at 100 percent utilization if PTP/SyncE is operational and the associated interfaces are up. The condition persists even when the affected interfaces are disabled and the system is rebooted.

Resolved In: junos:23.2R2-S5 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1801129
Major
IP routes can get added to a deleted routing table
Product-Group=junos
On all Junos platforms routes can get added to deleted routing tables.

Resolved In: junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
The management interface is unreachable post switchover/RPD restart events
Product-Group=junos
On all Junos platforms with management interface like em0/me0/fxp0 disabled, the management port remains unreachable after performing RE switchover or rpd restart events and re-enabling the management port.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: TCP/UDP transport layer
1864027
Minor
TCP listening sockets are not displayed correctly
Product-Group=junos
On Junos OS platforms, TCP (Transmission Control Protocol) listening sockets may be absent from command outputs due to NULL values in netstat application.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1839090
Major
Traffic loss due to tunnel establishment failure in HA setup
Product-Group=junos
On Junos platforms, during PKI (Public Key Infrastructure) certificate renewal in an HA (High Availability) setup, if the PKI daemon on the secondary node is busy, mismatched certificates will occur. If a failover happens, the mismatched certificates are used for IKE (Internet Key Exchange) tunnel establishment, causing tunnel failure and resulting in traffic loss.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1
PR NumberSynopsisCategory: QFX L2 PFE
1912846
Critical
LLDP neighborship will not be displayed post reboot of VXLAN VC devices.
Product-Group=junos
In VXLAN VC environment, with Leaf multi-homed to CE devices via AE link, LLDP neighbors will not be successful post reboot of the devices.

Resolved In: junos:24.4R2-S3 junos:25.4R1-S1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1888543
Minor
SNMP trap on Junos QFX5100 and EX4600 platforms report incorrect jnxOperatingState after PEM reinsertion on master switch
Product-Group=junos
On Junos QFX5100 and EX4600 platforms with releases 21.4R3-S3, 21.4R3-S10, and 21.4R3-S11, the SNMP trap generated after reinserting a PEM on the master switch incorrectly reports the jnxOperatingState as 6 (down) instead of the expected value 2 (running). This behaviour is consistently reproducible across multiple versions and persists even after performing a mastership switchover.

Resolved In: junos:21.4R3-S12 junos:26.1R1
PR NumberSynopsisCategory: RPD Interfaces related issues
1831337
Major
When configuring router-advertisement on PS interfaces, the system sends router advertisement with invalid source link-address option
Product-Group=junos
On Junos OS and Junos OS Evolved platform, when router-advertisement is enabled on Pseudowire Subscriber(PS) interface configurations where Virtual Local Area Network (VLAN) tags are used, the system may incorrectly assign MAC (Media Access Control) addresses, causing routing and forwarding failures.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S9 junos:23.4R2-S7 junos:24.2R2 junos:24.4R1 junos:25.1R1
1913519
Major
EVPN routes are stuck in the KRT queue
Product-Group=junos
When EVPN (Ethernet Virtual Private Network) routes attempt to transition between private (eg, management em1 - with IGP enabled) and public interfaces, it causes an error in next-hop resolution in the kernel, because the system deletes the old indirect next-hop and creates a new one. This happens as the kernel does not support changing an indirect next-hop between private and public interfaces directly.

Resolved In: evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issue related to mcnh routing infrastructure within RPD
1732258
Minor
rpd process crashes on Junos and Junos Evolved platforms when ingress replication creates duplicate multicast next-hops
Product-Group=junos
On all Junos and Junos Evolved platforms with MVPN environments, the RPD process crashes when the Ingress Replication (IR) module modifies multicast next hops in such a way that multiple multicast next hops are created with the same member or branch list. When such a duplicate next hop is being installed in the Forwarding Information Base (FIB), the kernel returns an EEXIST error. Because this error cannot be handled by RPD, the process crashes and traffic can be impacted.

Resolved In: evo:23.4R1-EVO junos:23.4R1 junos:24.2R2-S3
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:24.4R2-S3 junos:25.2R2 junos:25.3R1 junos:25.4R1 junos:25.4R2 junos:26.1DCB
PR NumberSynopsisCategory: Sangria Platform including chassisd, RE, CB, power managemen
1913580
Major
Chassisd crash will happen when shutting down the FPC of PTX5000 and PTX3000 using online/offline button
Product-Group=junos
When the FPC(Flexible PIC Concentrator)online/offline button is pressed on PTX5000 and PTX3000 twice in a short period, chassisd crash will happen. it is causing all FPCs to lose connectivity with the Routing Engine while remaining in an online state. As a result, service impact happened till all FPCs become online.

Resolved In: junos:22.4R3-S9
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1899178
Critical
Service session drops are observed when CPU throttling is configured on platforms with service cards installed
Product-Group=junos
On all Junos MX platforms that have MS-MPC or MS-MIC service cards installed, the use of the CPU throttling can cause the production service sessions to be dropped.

Resolved In: junos:21.2R3-S10 junos:21.2R3-S6-J16 junos:22.4R3-S7-J5 junos:22.4R3-S9
1901021
Major
Service-Set Configuration Bug Leading to Kernel Panic on Junos MX
Product-Group=junos
On Junos MX platforms with MS-MPC, when new rules are added to a service-set, the configuration size increases incrementally. This growth will cause failures during the commit process, potentially leading to a kernel panic. As a result, new configurations may not be successfully applied.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: SRX branch platforms
1889549
Major
The XE interfaces of SRX380 platform with 1G SFP (fiber) are flapping continuously when LACP is enabled
Product-Group=junos
When LACP (Link Aggregation Control Protocol) is enabled using 1G SFP(Small Form-factor Pluggable)-fiber (such as SFP-SX, SFP-LX etc) over XE interfaces, frequent state transitions will repeatedly trigger configuration updates. Due to LACP instability, the interfaces will continuously flap. As a result, the port configuration will be re-applied automatically which leads to a loop of re-configurations until the LACP state stabilizes.

Resolved In: junos:24.2R2-S3 junos:24.4R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1803105
Major
PTP attribute changes on upstream device causes best clock master slot switchover
Product-Group=junos
On all MX platforms(except MX80) with multi line card chassis, when PTP slave or stateful streams are configured across multiple linecards with clock from same PTP time provider and the announce msg parameters changes from the upstream device, the best master clock (BMC) slot switchover is observed and is restored back within few seconds. Although the slot time interval is very less, it can still lead to major impact as the active PTP slot and clock path is switched over and results in re-routing of the clocks.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:23.4R2-S6 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: SRX-1RU platfom chassisd SW defects
1802158
Major
CTL link down observed after rebooting one of cluster node at SRX4600HA
Product-Group=junos
Right after rebooting one of SRX4600 at HA setup, CTL link might keep down.

Resolved In:
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1766307
Major
JDI-RCT:M/Mx: during ISSU , observed aftd-trio core in MPC10 card @ boost:: throw_exception
Product-Group=junos
For certain releases, performing ISSU on MPC10 or MPC11 can cause an FPC core.

Resolved In:
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1886395
Major
FPC crash is seen on Junos platforms in a rare scenario
Product-Group=junos
On all Junos platforms, FPC (Flexible PIC Concentrator) crashes due to panic caused by incorrect handling of an application. This causes service impact since the card restarts after crash.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S4-J23 junos:23.4R2-S4-J30 junos:23.4R2-S6 junos:25.2R2
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1661128
Minor
Junos MX routers with VPN Localization generates crash files under high VPN scale conditions
Product-Group=junos
On Junos MX series routers with VPN Localization enabled for VRF, a PFE crash files may generate under high VPN and large FIB scale (~2M prefixes) during route churn, such as router configuration reloads.

Resolved In: junos:21.2R3-S9 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
1917066
Major
MX150 - Sflow unsupported feature
Product-Group=junos
Sflow is an unsupported feature on MX150 and should not be enabled or configured on an Junos version + MX150 platforms

Resolved In:
PR NumberSynopsisCategory: MX10K linecard
1898825
Major
Timing defect in ukern thread handling causing LC reboot
Product-Group=junos
On Junos platforms using line cards LC480 and LC2101, a timing defect in the embedded microkernel thread handling logic causes a panic when a thread attempts to yield execution while interrupt processing is still active. This panic results in a line card reboot.

Resolved In: evo:24.4R2-S3-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S4 junos:24.4R2-S3 junos:24.4R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: QFX10002 Platform
1869232
Major
CRC errors increase continuously after interface flap on some 100G transceivers with Rx CDR LOL support
Product-Group=junos
On Junos PTX10002-60C, and QFX10002-60C platforms, when using 100G QSFP modules with CDR LOL support, CRC errors have been observed on odd-numbered ports, leading to traffic disruptions.

Resolved In: junos:22.4R3-S7-J1 junos:22.4R3-S9

 

Modification History

First publication 2026-01-16