Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

QFX5110 QFX5120 EX4400 EX4100

Alert Description

Junos Software Service Release version 23.4R2-S7 is now available for download from the Junos software download site for the following platforms: EX4100 EX4400 QFX5110 QFX5120

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as needed and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 23.4R2-S7 is now available.

23.4R2-S7 - List of Fixed issues

PR NumberSynopsisCategory: EX2300/3400 PFE
1899441
Major
Traffic loss is observed on the CVLAN interfaces during the transition between SP and EP configuration style
Product-Group=junos
Severity=Major
On Junos OS EX2300, EX3400, EX4100, EX4400, EX4650, EX4000 and QFX5K platforms with software-based MAC (Media Access Control) address learning enabled through interface-level MAC-limit or MAC-move-limit, the traffic fails to traverse CVLAN interfaces when changing the configuration mode from Service Provider (SP) style to Enterprise (EP) style and vice versa.
PR NumberSynopsisCategory: "agentd" software daemon
1805445
Major
Return Error for unsupported options with GNMI RPCs
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, the error message returned with unsupported encoding is changed for gnmi RPCs. It has no traffic impact.
PR NumberSynopsisCategory: Border Gateway Protocol
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.
1914814
Major
BGP task replication will be stuck in 'InProgress' state following an RE switchover when two single hop EBGP sessions are configured on two different interfaces using the IP addresses from the same subnet
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms with NSR (Nonstop Active Routing), when two single hop EBGP (External Border Gateway Protocol) sessions are configured to run on two different interfaces using IP addresses from the same subnet (overlapping subnet), the BGP task replication process does not complete after an RE (Routing Engine) switchover for the EBGP session with a specified local-address. This results in one BGP peer being in the 'Idle' state on the Backup RE while remaining in the 'Established' state on the new Master RE, causing the BGP task replication process to remain stuck in the 'InProgress' state.
PR NumberSynopsisCategory: QFX Access Control related
1923266
Major
Upgrade from release 23.4R2-S4 with persistent-cache enabled on VC can cause dot1xd to crash continuously
Product-Group=junos
Severity=Major
On all Junos devices with dual RE configured with dot1x, if the device is upgraded from release 23.4R2-S4 or there is a RE switchover and persistent-cache feature enabled it will cause dot1xd to crash. It is due to presence of some stale files on backup node.
PR NumberSynopsisCategory: Device Configuration Daemon
1916208
Major
Traffic drops due to VLAN configuration not updated for Ethernet-Switching Interfaces
Product-Group=junos
Severity=Major
On Junos OS platforms in which VLAN information can be given as a VLAN member name, if both VLAN (Virtual Local Area Network) IDs and VLAN member names are configured together on an interface within a routing instance, the VLAN membership does not update correctly on that interface, resulting in traffic impact associated with that VLAN.
PR NumberSynopsisCategory: EX4000 PFE issues
1847159
Major
Reachability issues are seen on interfaces that are aggregated without address-family
Product-Group=junos
Severity=Major
On Junos platforms, specifically on EX and QFX series aggregated interfaces configured without address-family results in reachability issues.
PR NumberSynopsisCategory: EX4100 PFE
1905783
Major
FXPC core dumps and crashes on EX switches during RA packet processing when SLAAC snooping is enabled
Product-Group=junos
Severity=Major
On EX switches, when Router Advertisement Guard is configured with slaac-snooping, both PFE (Packet Forwarding Engine) and Routing Engine (RE) are used to free the same packet leading to double free scenario. Over time, repeated occurrences of this condition can lead to FXPC cores and switch crashes due to invalid access or while freeing the packet. This impacts overall VC stability.
PR NumberSynopsisCategory: EX interfaces issues
1827595
Minor
Broadcom phy/EPDM SDK upgrade to version 2.3
Product-Group=junos
Severity=Minor
Broadcom PHY EPDM SDK has been upgraded to version 2.3 to address the port not coming up issue.
1833177
Major
Incorrect Green LED Indication on 4x10G SFP/SFP+ Uplink Module When Link Is Down
Product-Group=junos
Severity=Major
On EX2300 and EX3400 platforms, When running the 'show chassis led' command, the uplink port LED on the 4x10G SFP/SFP+ module consistently shows green even when the link is down. This behavior is cosmetic only and does not impact service.
PR NumberSynopsisCategory: EX4400 PFE software
1870016
Minor
Traffic will be dropped due to IPv4 header checksum mismatch on EX4400 platform
Product-Group=junos
Severity=Minor
On EX4400 platform, if the switch is acting as a routing transit device, and if the value of the IPv4 header checksum is 0xFFFF in the ingress traffic, the checksum of the IPv4 header will not be recalculated even though the TTL (time to live) value has been reduced. This will lead to traffic being dropped by the next transit-device due to the bad checksum.
PR NumberSynopsisCategory: EX optics issues
1858986
Major
EX4400: Error message 'Failed to read eeprom' intermittently on SFP-T
Product-Group=junos
Severity=Major
On EX4400, error message 'Failed to read eeprom' is seen intermittently on SFP-T.
PR NumberSynopsisCategory: EX POE
1906507
Minor
False "Device Manager Failure" Alarms Observed on PoE Subsystem
Product-Group=junos
Severity=Minor
On EX2300/EX3400 platforms, The system reports false Power over Ethernet (PoE) "Device Manager failure" alarms, typically triggered by older PoE controller chips. These are not port-level or hardware issues, and connected PoE devices operate normally with correct power levels. The PoE subsystem auto-recovers, and the alarms are safe to ignore.
PR NumberSynopsisCategory: Dynamic flow capture
1880090
Major
On-Box IPv6 packet capture support
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, IPv6 support was added for on-box packet capture. This is an enhancement request and has no service impact.
PR NumberSynopsisCategory: jdhcpd daemon
1911001
Major
On Junos devices supporting subscriber services acting as DHCPv6 relay randomly deletes IA_NA or IA_PD binding/route
Product-Group=junos
Severity=Major
On all Junos devices supporting subscriber services, in case of dual stack DHCP (Dynamic Host Configuration Protocol) subscribers with IA_NA (Identity Association for Non-temporary Address) and IA_PD (Identity Association for Prefix Delegation) bindings with lease times (For the assignment of IPv6 address to a client device), when a client initiates separate renew exchanges for the IA_NA and IA_PD, and once client and DHCP server are in sync with these timers, there can be a race condition at Junos device which is DHCPv6 relay, has not refreshed lease timer and can go out of sync. This can result in deleting IA_NA/IA_PD binding and route to get deleted for that subscriber only. This causes one of the leg for IA_PD or IA_NA to go down for that subscriber, which can result in traffic impact for that leg.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1905196
Minor
Stale entry in MAC-IP table affects ARP resolution
Product-Group=junos
Severity=Minor
On all Junos OS platforms, when an IP address already exists in the MAC-IP table as a remote entry and then an IRB (Integrated Routing and Bridging) interface is configured with the same IP address but a different MAC address, then the L2ALD (Layer 2 Address Learning Daemon) does not handle the update correctly, leading to incorrect ARP (Address Resolution Protocol) resolution.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1876690
Major
ntp process may restart when issue the "show system ntp threshold" command
Product-Group=junos
Severity=Major
The ntp (or xntpd) process is initialized when the "show system ntp threshold" command is issued. This has no impact to system operation.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1897240
Major
Chassis-Control restart triggers when configuring GRE interface across multiple routing-instances leading to kernel crash
Product-Group=junos
Severity=Major
On Junos series devices, the kernel crash occurs when creating and configuring a identical GRE(Generic Routing Encapsulation) interface across different routing-instances.
PR NumberSynopsisCategory: Issues related to PKI daemon
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
Severity=Major
In stressful conditions, FPC crash observed and core file generated when PKI (Public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured, on all Junos platforms supporting PKI and SSL-Proxy services (MX, PTX, SRX).
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1909719
Critical
Junos and Junos OS Evolved platforms experience high CPU after FPC reboot causing unpredictable issues with protocols (OSPF/ISIS/BGP, etc.) managed by PPMD
Product-Group=junos
Severity=Critical
After upgrading or rebooting Junos/Junos OS Evolved platforms, a CPU spike may be observed in the PPMD (Periodic Packet Management Daemon) process due to repeated internal message failures. This can lead to BFD (Bidirectional Forwarding Detection) authentication failures. Additionally, other protocols that rely on authentication and PPMD for packet distribution may also be affected, potentially resulting in traffic loss.
1912250
Major
BFD sessions will not come up on Junos OS and Junos OS Evolved platforms due to keychain names overlapping
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms, where BFD with authentication key chain names are overlapping due to which BFD (Bidirectional Forwarding Detection) sessions will not come up in few scenarios like restart bfdd, restart ppmd, restart FPC.
PR NumberSynopsisCategory: QFX L2 PFE
1866016
Minor
Model: qfx5120-32c | Junos: 22.2R3-S4.10 | Management lost | JSD Coredumps observed
Product-Group=junos
Severity=Minor
A race in JSD When multiple clients connecting and disconnecting can cause JSD to crash.
PR NumberSynopsisCategory: QFX analyzer, sflow
1884080
Major
JTI telemetry data missing for nonmaster VC ports
Product-Group=junosvae
Severity=Major
On EX465048Y, EX430048MP, and all QFX5K platforms running Junos in Virtual Chassis (VC) mode, telemetry data from nonmaster VC members is not streamed to the collector. Telemetry packets from nonmaster members are dropped before reaching the master VC member. This affects all Packet Forwarding Engine (PFE) sensors on nonmaster VC members.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1897459
Minor
qfx5120-48y-8c/23.4R2-S3.9/Flooding back GARP BUM traffic towards source.
Product-Group=junos
Severity=Minor
When EVPN is configured on Broadcom-based platforms, GARP reply packets are flooded and may be sent back toward the source device. With this fix, GARP reply packets will be terminated rather than flooded.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1920870
Major
On QFX5120 platforms, QSFP?100GBASE?DR optics may fail to be recognized
Product-Group=junos
Severity=Major
In certain conditions, the FPGA component responsible for managing QSFP ports (FPGA Slave 3) may enter a stuck or reset state. When this occurs, the device may fail to detect QSFP?100GBASE?DR modules.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform issues
1796218
Major
The 100G VCP will go down upon restarting or upgrading the device
Product-Group=junos
Severity=Major
On Junos QFX5K platforms in a Virtual Chassis scenario, the 100G VCP (Virtual Chassis Port) will go down and remain in a down state after a device or VCP restart or device upgrade.
PR NumberSynopsisCategory: RPD Interfaces related issues
1831337
Major
When configuring router-advertisement on PS interfaces, the system sends router advertisement with invalid source link-address option
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platform, when router-advertisement is enabled on Pseudowire Subscriber(PS) interface configurations where Virtual Local Area Network (VLAN) tags are used, the system may incorrectly assign MAC (Media Access Control) addresses, causing routing and forwarding failures.
1913519
Major
EVPN routes are stuck in the KRT queue
Product-Group=junos
Severity=Major
When EVPN (Ethernet Virtual Private Network) routes attempt to transition between private (eg, management em1 - with IGP enabled) and public interfaces, it causes an error in next-hop resolution in the kernel, because the system deletes the old indirect next-hop and creates a new one. This happens as the kernel does not support changing an indirect next-hop between private and public interfaces directly.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1868085
Major
The rpd process crashes and asserts are seen due to memory leak
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, rpd process crashes and asserts are seen due to a memory leak when BGP sharding is enabled and 'show route' is performed continuously.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1796548
Major
Truncated RPD core-dump seen after routing restart
Product-Group=junos
Severity=Major
After restarting rpd process. System truncates the core-dump.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1907558
Major
The rpd process crashes in a vrf having EVPN-VXLAN routes with specific configuration.
Product-Group=junos
Severity=Major
In all Junos and Junos OS Evolved platforms, when EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible LAN) routes are present in a VRF (Virtual Routing and Forwarding), configuring a generate route in same vrf can cause rpd (Routing Protocol Daemon) to crash and restart. Generate route configuration has to be removed to recover from this behaviour.
PR NumberSynopsisCategory: Resource Reservation Protocol
1792192
Major
Missing HELLO object in RSVP Hello messages after RE failovers in the NSR mode
Product-Group=junos
Severity=Major
In rare unknown condition after RE switchover, rsvp hello can have local instance to be zero due to wrong information synced from master RE by mirroring process. When rsvp neighbor is created and never received hello exchange with neighbor, the replication entry which is synced to standby RE will have most of the information as zero, including the local instance, which is used to generate hello object. After RE switchover, rsvp hello will have local instance to be zero due to the wrong information synced from master RE by mirroring process. This is addressed by update the replication entry once all the parameters of the rsvp neighbor is filled, so standby RE will receive the right info, also for future protection, backup RE will avoid creating neighbor until after switchover and setting a new local instance if it is zero.
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
Severity=Major
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated
1896022
Major
More bandwidth admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
Severity=Major
On all Junos and Junos evolved platforms with Point of Local Repair Router, in a Multiprotocol Label Switching(MPLS) Label Switched Paths (LSPs) set-up if the ingress router is configured with link-protection , if Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.
PR NumberSynopsisCategory: MX SCBE3 specific timing and synchronization issues
1902478
Major
After the deactivation of the PTP protocol in the G.8275.1 profile configuration, SyncE remained in Holdover mode.
Product-Group=junos
Severity=Major
In G.8275.1 Hybrid mode of operation, when PTP only is deactivated, SyncE shall not lock to the SyncE source and DPLL shall remain in Holdover state.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1906065
Major
ifStackStatus is not reported correctly for one or more AE bundles
Product-Group=junos
Severity=Major
On all Junos, the ifStackStatus query is executed after the system reboot, the member link status is not reported correctly for one or more AE (Aggregated Ethernet) bundles and thus the relation between AE IFL (Logical Interface) and corresponding member link IFL's cant be fetched from ifStackTable. This is an error message and no traffic impact will be observed.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1881989
Major
Tactical Traffic Engineering does not work on aggregated-ethernet interfaces
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, Segment Routing Tactical Traffic Engineering (TTE) does not work as expected for aggregated-ethernet interfaces. As a result, congestion is not alleviated or sent over TI-LFA paths.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1902713
Minor
The mgd process crash observed on running commit check after replace operation of groups name for apply-groups-except
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, when replace operation was done on apply-groups-except object it was not clearing the entry of that object from apply-groups-info-tree, as a result 'mgd' process crash observed on commit check. There is no service impact due to this issue.
PR NumberSynopsisCategory: Issues related to NETCONF
1906621
Major
RPC reply delayed for commit during NETCONF over SSH session on Junos TVP-based VMhost platforms
Product-Group=junos
Severity=Major
On JUNOS VM Host-based platforms, when performing NetConf "", an internal script caused its PID to be displayed in the NETCONF session during commit.

 

Extended Solution

23.4R2-S7 - List of Known issues

PR NumberSynopsisCategory: Software build tools (packaging, makefiles, et. al.)
1900881
Major
EX2300/EX3400: TFTP installation failure
Product-Group=junos
EX2300/EX3400 : TFTP install can fail with a "No device tree blob found" error

Resolved In: junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: EX4000 HW issues
1902609
Minor
Intermittent kernel panic results in device reboot or fxpc crash
Product-Group=junosvae
On all EX4000-48MP/EX4000-48P/EX4000-48T platforms, false ECC (Error-Correcting Code) alarms are observed due to the usage of un-initialised memory on the chip and intermittent kernel panic might result in vm core dump causing device reboot or fxpc crash. This results in impact on the traffic.

Resolved In: junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4B1 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: "agentd" software daemon
1859761
Minor
Continuous AGENTD_PFE_SENSOR_INSTALL_FAILED error messages on backup RE
Product-Group=junos
On Junos OS platforms with dual Routing Engines, the backup Routing Engine may repeatedly log AGENTD_PFE_SENSOR_INSTALL_FAILED error messages related to telemetry sensor installation. This issue is cosmetic and does not impact traffic forwarding, control-plane operation, or system stability. The issue has been resolved by improving resiliency in telemetry-related components to prevent unnecessary retry attempts on the backup Routing Engine.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Border Gateway Protocol
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP (Border Gateway Protocol) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.

Resolved In: evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-J6 junos:24.2R2-S1-J4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned on a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB (Segment Routing Global Block), this mismatch can result in incorrect label forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Alias for DHCP issue on DNX based platform.
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:24.1B1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4X30-D30 junos:23.4X9 junos:24.1B1 junos:24.1R1 junos:24.2R1 junos:24.4R2-S3
PR NumberSynopsisCategory: EVPN control plane issues
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: EX interfaces issues
1771119
Major
Mixed speed support in PIC2 phyless 4x10G uplink module
Product-Group=junos
1G and 10G are now default speeds in 10G ULM.

Resolved In: junos:24.2R1-S1-J4 junos:24.2R1-S2-J1 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
1886889
Minor
snmp mib walk DomCurrentLaneAlarms does not show proper lanes Values in the latest builds
Product-Group=junos


Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1909608
Minor
Auto-negotiation is not displayed in 'show interfaces' command output
Product-Group=junos
On EX3400 and EX4400-48F, when using 1G optics, the auto-negotiation information does not appear in the output of the "show interfaces" command.

Resolved In: junos:24.2R2-S4 junos:24.4R2-S3 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: EX optics issues
1887303
Minor
[EX4400-48F] One of the 10gBase-T transceiver is not detected - showing as "Partial" Unknown in PFE
Product-Group=junos
In the EX4400-48F systems, a 10G-BaseT transceiver that was earlier up may not come up post a reboot/image upgrade event; The transceiver may go undetected causing the interface to not be created in the system.

Resolved In:
PR NumberSynopsisCategory: ISIS routing protocol
1892136
Minor
Primary path temporarily disappear until the MLA timer expires for IPv6 SRv6 routes
Product-Group=junos
On Junos and Junos EVO platforms having Segment Routing over IPv6 (SRv6) with the Intermediate System to Intermediate System (IS-IS) routing protocol and with the Microloop Avoidance (MLA) feature enabled, primary path for IPv6 SRv6 routes disappear until the MLA delay timer expires if Multiprotocol Label Switching (MPLS) is configured only at the global level. Traffic loss occur if network topology changes during this period.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Issues related to JMRT and other Malware found by customers
1889037
Major
Temporary file /tmp/veriexec_test is not cleaning up on all platforms after "request system malware-scan integrity-check"
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, temporary binary file /tmp/veriexec_test is created to test if veriexec (Verified Exec) is running as expected or not while running "request system malware-scan integrity-check". This temporary file isn't getting removed after the test execution.

Resolved In: evo:26.1R1-EVO junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1816344
Major
EVPN : Traffic failure after multiple link flaps of core facing interfaces on scaled setup
Product-Group=junos
ARP resolution failure when there is quick flap of core facing interface on scaled setup

Resolved In: evo:23.2R2-S7-EVO evo:23.4R2-S8-EVO evo:23.4X100-D43-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Label Distribution Protocol
1906611
Major
Crash in the rpd process after LDP P2MP LSP Identifier reaches its maximum value and rolls over, due to duplicate identifier allocation
Product-Group=junos
On all Junos OS and Junos OS Evolved versions that support Label Distribution Protocol Point-to-Multipoint Label Switched Paths (LDP P2MP LSPs), the rpd process (routing protocol daemon) crashes when an LSP Identifier reaches its 24-bit maximum value (224 1 = 16, 777, 215) and rolls over to the starting value because a duplicate identifier is incorrectly allocated. This condition occurs only after prolonged tunnel flapping (typically more than 16 million flaps). When the rpd process crashes, routing convergence is briefly disrupted, and services relying on label-switched traffic are impacted until the process automatically restarts.

Resolved In: evo:26.1R1-EVO junos:26.1R1
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1885185
Major
AE interface going down on specific MX platform with exclude-protocol being re-configured under MACsec.
Product-Group=junos
When exclude protocol is configured with MACsec(Media Access Control Security) on IFD (Interface Device), a delete AE(Aggregated Ethernet) interface can cause the exclude protocol filters to not clean up on MX platforms with MPC10 and MPC11 linecards . When MACsec is reconfigured on the same link with AE, AE interface goes down.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1908238
Minor
MPC10 reports "ifd 340; does not exist " after configuring an interface
Product-Group=junos
MPC10 reports "ifd 340; does not exist " after configuring an interface

Resolved In: junos:26.1R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1902405
Major
The rpd process crash is observed with MVPN and RIB sharding enabled
Product-Group=junos
On Junos MX and Junos Evolved PTX platforms , with RIB sharding enabled and if either IPv4 or IPv6 address family is disabled in MVPN (multicast virtual private network), the unicast route flow from shard tries to access MVPN data structures without validation leading to rpd (Routing Protocol Daemon) process crash.

Resolved In: evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2-J2 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1801129
Major
IP routes can get added to a deleted routing table
Product-Group=junos
On all Junos platforms routes can get added to deleted routing tables.

Resolved In: junos:24.2R2 junos:24.3R1
1918788
Major
[QFX5120] 23.4R2-S5 - PROXY-ARP not replying ARP-REQUEST from client.
Product-Group=junos
PROXY-ARP not replying ARP-REQUEST from client. Working as designed.

Resolved In:
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
The management interface is unreachable post switchover/RPD restart events
Product-Group=junos
On all Junos platforms with management interface like em0/me0/fxp0 disabled, the management port remains unreachable after performing RE switchover or rpd restart events and re-enabling the management port.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: IPv6/ND/ICMPv6 issues
1920718
Minor
Ksyncd core seen : "ROUTE subtype 18 : Can't assign requested address" due to a misconfiguration
Product-Group=junos
Ksyncd core seen : " ROUTE subtype 18 : Can't assign requested address" due to a misconfiguration i.e giving subnet route as nexthop in below configuration which is incorrect.A valid nexthop has to be given. set protocols mpls static-label-switched-path ae131.0-v6 transit 1004040 next-hop fc00:: 220. This is applicable to all JUNOS platforms.

Resolved In:
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1924159
Major
Fetch command output format changed and completion percentage not displayed
Product-Group=junos
On Junos and Junos OS Evolved platforms, the output format of the fetch command changed after upgrading to a newer upstream version of the utility. The earlier format displayed an explicit completion indicator (for example, 100%). The upgraded version removed this indicator.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:25.4R1-S1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1876497
Minor
Wrong digest algorithm is used for ECDSA key based certificate requests using PKI
Product-Group=junos
On all Junos and Junos Evolved platforms, when generating Elliptic Curve Digital Signature Algorithm (ECDSA) based Certificate Signing Request (CSR) using Public Key Infrastructure (PKI), SHA-384 digest is used even when other digest algorithm is specified in Command Line Interface (CLI). This issue will impact services that are based on these certificates when the services are configured for specific digest algorithm.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
On Junos MX platform with subscriber management enabled, interface flapping causes PPPoE subscriber login failures, resulting in AC (Access Concentrator)System errors.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R2-S1-J6 junos:22.4R3-S7 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: QFX5K hostpath
1921455
Major
The dcpfe process crashes when adding or removing classifier configuration
Product-Group=junos
On QFX5210 platform with Class of Service (CoS), the dcpfe process crashes when classifier is configured or removed on interface with active traffic. This can affect traffic forwarding till dcpfe process restarts post crash.

Resolved In: junos:24.2R2-S4 junos:25.4R1-S1 junos:25.4R2
PR NumberSynopsisCategory: QFX L2 PFE
1912846
Critical
LLDP neighborship will not be displayed post reboot of VXLAN VC devices.
Product-Group=junos
In VXLAN VC environment, with Leaf multi-homed to CE devices via AE link, LLDP neighbors will not be successful post reboot of the devices.

Resolved In: junos:24.4R2-S3 junos:25.4R1-S1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1888543
Minor
SNMP trap on Junos QFX5100 and EX4600 platforms report incorrect jnxOperatingState after PEM reinsertion on master switch
Product-Group=junos
On Junos QFX5100 and EX4600 platforms with releases 21.4R3-S3, 21.4R3-S10, and 21.4R3-S11, the SNMP trap generated after reinserting a PEM on the master switch incorrectly reports the jnxOperatingState as 6 (down) instead of the expected value 2 (running). This behaviour is consistently reproducible across multiple versions and persists even after performing a mastership switchover.

Resolved In: junos:21.4R3-S12 junos:26.1R1
PR NumberSynopsisCategory: RPD Interfaces related issues
1741485
Major
Unnecessary rsync messages causing issues
Product-Group=junos


Resolved In: evo:24.1R1-EVO junos:24.1R1
1905553
Minor
Redundant prefix information is included within one router-advertisement packet when configuring accept-data in VRRPv6
Product-Group=junos
When configuring accept-data in VRRPv6, two entries for the same prefix value are included within one router-advertisement packet on all Junos platforms.

Resolved In: evo:25.4R1-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1908681
Major
RIB and the FIB inconsistency results in traffic loss in IPsec scenario with st0 interface configured
Product-Group=junos
On Junos OS SRX platforms having IPsec (Internet Protocol Security) with st0 (Secure Tunnel Interface) interface configured, traffic loss will be observed if the "next-hop-tunnel" configuration is removed and added within a few seconds. This happens due to a inconsistency between the RIB (Routing Information Base) and the FIB (Forwarding Information Base).

Resolved In: evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1851629
Minor
Next-hop APIs to support LDP stitching cases over BGP routes pointing to list of indirects
Product-Group=junos
On all Junos and Junos Evolved platforms this is an enhancement for Nexthop APIs to support LDP stitching cases over BGP routes pointing to list of indirects next-hops.

Resolved In: evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.4DCB
PR NumberSynopsisCategory: Resource Reservation Protocol
1881609
Minor
RSVP hello messages uses secondary address when primary/preferred address are present for same interface
Product-Group=junos
On all Junos and Junos OS Evolved platforms where RSVP (Resource Reservation Protocol) configuration is present and a RSVP enabled interface has 2 IP address of which one is configured as primary/preferred in that case the RSVP Hello message uses the secondary IP address to form neighborship.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1845657
Major
Baseline configuration commit takes more time with 256000 MAC configurations
Product-Group=junos
On all Junos and Junos OS Evolved platforms with dual RE (Routing Engine), the baseline configuration commit takes more time when the device has 256000 MAC (Media Access Control) configurations configured under groups. It is a scaling issue, and occurs when a large number (256000 or more) of MAC configurations are configured. This has no impact to network traffic.

Resolved In: evo:24.4R1-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R1-S2 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
PR NumberSynopsisCategory: MX10K linecard
PR NumberSynopsisCategory: VMHOST platforms software
1795506
Minor
A non service impacting warning message 'Failed to set 'memory.limit' will be observed
Product-Group=junos
On all Junos OS Evolved platforms a warning message "Failed to set 'memory.limit_in_bytes' attribute on '/user.slice' to '-1': Invalid argument" would be observed.

Resolved In: evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:24.2R1-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2X1 junos:24.4R1
PR NumberSynopsisCategory: Virtual Private LAN Services
1806424
Major
The snmp mib walk on jnxVplsPwBindTable fails with vpls routing-instances having multiple mesh-groups
Product-Group=junos
If VPLS mesh-groups are configured with different neighbours having different vpls-id the SNMP mib walk over jnxVplsPwBindTable might fail with the error Request failed: OID not increasing. No functional impact is seen due to this issue.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: QFX10002 Platform
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3

 

Modification History

Release on 2026-02-04