Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX platforms running Junos Evolved Software

Alert Description

Junos Software Service Release version 24.4R2-S3-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 24.4R2-S3-EVO is now available.

24.4R2-S3-EVO - List of Fixed issues

PR NumberSynopsisCategory: Fabric for LC1300 and SIB3
1880275
Major
bf_crcv_x_intr_cru_err_pg_psc transient interrupt may occur during FPC offline.
Product-Group=evo
Severity=Major
During link detraining sometimes cru_err_pg_psc interrupt may be present for a very brief time in SIB. Its not a problem if its seen during offline. But should not occur during stable state.
PR NumberSynopsisCategory: Tracking interface specific issues for Aegon Line card
1913948
Minor
Interfaces take 14 seconds to come up for a short LOS event
Product-Group=evo
Severity=Minor
On all Junos OS Evolved PTX10008 with LC1301 line cards, interfaces exhibit a delayed link-up condition when a brief LOS (Loss of Signal) event occurs. This issue occur due to far end turns the laser off and back on, and local interface takes approximately 14 seconds to come up.
PR NumberSynopsisCategory: "agentd" software daemon
1885622
Major
The aaasd process stops responding for RPC calls
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms with gRPC configured, the aaasd process rejects incoming RPCs. This issue occurs in some rare cases, and aaasd will stop listening for authentication requests from reverse proxy. This issue does not cause a traffic impact.
PR NumberSynopsisCategory: EVO interface software
1878198
Major
Link flapping occurs on stable subinterfaces when using QDD400GZR optics if any one subinterface in the channelized group is down
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms that support the QDD-400G-ZR coherent optical transceiver modules (400G-ZR and 400G OpenZR+), when an interface is equipped with any of these optics and configured in breakout mode, if anyone of the sub-interfaces in the group is administratively up and operationally down, the remaining stable sub-interfaces in the same group experience the link flaps at a regular interval.
PR NumberSynopsisCategory: PTX10000s Platform software
1870875
Major
60A DIP switch setting on 3KW DC PSU limits output power capacity and system could shutdown based on system power usage
Product-Group=evo
Severity=Major
On PTX10002-36QDD platform, the 3KW DC PSUs output power is limited when the DIP switch is set to 60A. In older releases that do not include the fix for this PR, the system powered on in normal power mode with only one 3KW DC PSU in the 60A DIP switch setting may abruptly power off if the system is in normal power mode and the system power usage exceeds the PSUs limited output capacity. If the system is powered on with multiple 3KW DC PSUs in the 60A DIP switch setting, it will continue to function normally but will lose PSU redundancy. If the system is configured to operate in power-optimized mode, the 3KW DC PSU DIP switch setting does not affect system functionality. The DIP switch setting also has no effect on 2.2KW DC PSUs.
PR NumberSynopsisCategory: BBE UP Session Manager related issues
1916030
Major
L2TP subscriber session failure in BNG CUPS scenario
Product-Group=evo
Severity=Major
On Junos MX platforms and Junos OS Evolved ACX platforms that support BNG CUPS ( Broadband Network Gateway Control and User Plane Separation), L2TP (Layer 2 Tunneling Protocol) subscriber sessions will fail to come up. When this happens, the subscriber session does not bind correctly and no data traffic will pass for the affected subscribers.
PR NumberSynopsisCategory: Border Gateway Protocol
1880630
Major
Scaled BGP sessions remain in the Idle state after interface rollback.
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, after interface configuration rollback, sessions stay in Idle state when multiple BGP(Border Gateway Protocol) sessions exist.
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.
1903829
Major
On platforms supporting BGP RIB sharding the rpd process crash is observed on both REs
Product-Group=evo
Severity=Major
On platforms supporting where BGP (Border Gateway Protocol) RIB (Routing Information Base) Sharding is configured the rpd process crashes on both REs (Routing Engines) due to route churns. This timing issue is caused when a particular internal function is used by multiple threads.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1893165
Major
Micro BFD packets egress through incorrect queue on PTX platforms
Product-Group=evo
Severity=Major
On PTX platforms that support inline micro BFD ( Bidirectional Forwarding Detection), the BFD packets are sent through Q3 ( network-control queue) instead of Q5 (protocol queue). This can cause packet drops due to wrong queue selection.
PR NumberSynopsisCategory: MX304 Routing Engine issues
1877895
Major
Martian logs observed on the device.
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved OS, martian logs are observed on FPC (Flexible Physical Interface Card) and on Routing Engine 0.
PR NumberSynopsisCategory: EVPN ELAN/E-TREE
PR NumberSynopsisCategory: ACX EVO PFE IP Tunnel issue assignment alias
1896144
Major
Renaming a FTI tunnel causes all IPv6 traffic on the FTI tunnel to be dropped
Product-Group=evo
Severity=Major
On ACX-series platforms running Junos Evolved Operation System (OS), when renaming a Flexible Tunnel Interface (FTI) causes all Internet Protocol version 6 (IPv6) traffic on the FTI tunnel to be dropped.
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1908282
Major
Next hop is missing when ECMP uses an IRB interface in an EVPN-VXLAN scenario
Product-Group=evo
Severity=Major
On all Junos OS Evolved ACX7K Series platforms, the Next hop is wrongly programed when Equal Cost Multi Path (ECMP) is configured, and IRB (Integrated Routing and Bridging) interface is used as a Next hop. Since the Next hope is not being programed properly, routes are unable to have a next hop causing service disruption.
PR NumberSynopsisCategory: ACX IFL, IFF creation
1857014
Major
Interfaces on ACX7509 go down after reboot with any FPC in an offline state
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX7509 platforms, if any Flexible PIC Concentrator (FPC) is in an offline state, either due to manual offlining via CLI, a hardware fault, or insertion of an incompatible FPC, a subsequent system reboot will result in all interfaces on the remaining healthy FPCs going down.
PR NumberSynopsisCategory: Segment Routing PFE part for v4 + SR-TE
1869140
Major
PHP pop label operation is incorrectly pushing a label on an MPLS LSR
Product-Group=evo
Severity=Major
On all Junos Evolved ACX platforms, due to a PHP (Penultimate Hop Popping) pop label operation incorrectly pushing a label on an MPLS LSR (Label Switch Router) will cause an eBGP sessions not comming across the AS (Autonomous System).
PR NumberSynopsisCategory: EVO Netstack FIB Service Daemon
1785913
Critical
Junos OS Evolved: TCP session state is not always cleared on the Routing Engine leading to DoS (CVE-2024-47502)
Product-Group=evo
Severity=Critical
An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88132 [juniper.net] for more information.
PR NumberSynopsisCategory: System Management daemon and related issues
1890518
Minor
Commit sync will fail on standby RE
Product-Group=evo
Severity=Minor
On Junos OS Evolved ACX and PTX platforms with Dual RE, a configuration commit will not sync to the standby RE (Routing Engine). If a switchover happens during this time, traffic will be impacted because both REs are not in sync. This is a rare case.
PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1911684
Major
IFL installation failure with the same outer VLAN tag and distinct inner VLAN lists
Product-Group=evo
Severity=Major
On all Junos evolved platforms, the logical interface (IFL) installation fails in the Packet Forwarding Engine (PFE) when two or more double-tagged sub-interfaces are configured under the same aggregated ethernet interface with the same outer VLAN tag and distinct inner VLAN lists.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1914423
Major
On-change telemetry events dropped when l2ald telemetry queue memory limit is not configured
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, when l2-learning telemetry is enabled without explicitly configuring a memory limit for the l2ald (Layer 2 Address Learning Daemon) telemetry queue, the default memory limit is not applied. As a result, all on-change telemetry events are dropped.
PR NumberSynopsisCategory: N/A:sw-evo-re-firewall:
1896496
Minor
Traffic drop observed for two policer with same initial name and term names
Product-Group=evo
Severity=Minor
On all Junos OS Evolved platforms, when two policers with the same initial name(First 15 characters of rate estimator name) and term names are configured, since the rate estimator name (combination of filter term name and policer name) which gets truncated to 15 characters, the two policers start using the same rate estimator and it can lead to possible early drops by the policer, based on the current traffic rate of the two policers.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1916646
Major
IRB interface state is observed incorrect on IFD events tracked by a Network Isolation group
Product-Group=evo
Severity=Major
On MX, EX9200, QFX, PTX platforms, Traffic forwarded over the IRB (Integrated Routing and Bridging) is impacted when isolation decisions rely on the state of a tracked interface, because the Network Isolation Group tracks the interface but processes only IFL (Interface Logical) events and does not process IFD (Interface Device) events.
PR NumberSynopsisCategory: Express PFE CFM
1891363
Major
hardware-assisted-keepalives CFM transmit packets are queued into Q4 instead of Q3/Network-control
Product-Group=evo
Severity=Major
On EVO-based PTX platform, hardware-assisted-keepalives (aka inline) CFM transmit packets running on INET and CCC downmep topology are queued into Q4, instead of Q3/network-control. If no COS scheduler is configured on interface Q4, the CFM packets will be dropped in an interface burst scenario which will end up with protocol flap.
PR NumberSynopsisCategory: Express PFE FW Features
1882315
Minor
Firewall policy configured to match IP payloads fail matching on MPLS packets
Product-Group=evo
Severity=Minor
On Junos Evolved PTX platforms, when configuring a firewall policy, specifying family any, and matching on inner IP payload (IPv4 or IPv6), matching does not work on Multiprotocol Label Switching (MPLS) packets
1911372
Minor
The evo-aftmand process crashes when the prefix list is modified in scaled scenario
Product-Group=evo
Severity=Minor
On all Junos OS Evolved PTX platforms, a filter installation failure under high prefix utilization leaves the system in an inconsistent internal state, and subsequent modification of prefix lists or prefixes in the filter can further result in incorrect traffic matching and unpredictable packet handling, leading to inconsistent traffic behavior. In rare cases, this internal data corruption may also cause the evo-aftmand process to crash.
PR NumberSynopsisCategory: ACX7332 & ACX7348 Platform Software
1894824
Minor
ACX 7348 - Continuous log messages seen on backup routing engine after RE switchover
Product-Group=evo
Severity=Minor
OnJunos Evolved ACX 7348 platforms, continuous log messages are flooded in the backup routing engine during switchover of routing engine. This does not have any functional impact.
1914062
Major
[ACX] HWD_ALARM_CLEAR_NOTICE: ClearFault: Fault(Location: /Chassis[0]/Psm[0] Device: psm0 Error: psm_cml_pec_fault) cleared
Product-Group=evo
Severity=Major
[ACX] HWD_ALARM_CLEAR_NOTICE: ClearFault: Fault(Location: /Chassis[0]/Psm[0] Device: psm0 Error: psm_cml_pec_fault) cleared
1918410
Minor
ACX7348 - Minor alarm not clearing for "Host 0 Active Disk Usage Exceeded"
Product-Group=evo
Severity=Minor
When multiple partitions exceeded 90%, only one alarm was shown because all partitions shared the same descriptor and when any one partition dropped below 90%, the alarm was cleared globally, even if other partitions were still above the threshold. This caused incorrect alarm behavior in multi-partition scenarios.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1905196
Minor
Stale entry in MAC-IP table affects ARP resolution
Product-Group=evo
Severity=Minor
On all Junos OS platforms, when an IP address already exists in the MAC-IP table as a remote entry and then an IRB (Integrated Routing and Bridging) interface is configured with the same IP address but a different MAC address, then the L2ALD (Layer 2 Address Learning Daemon) does not handle the update correctly, leading to incorrect ARP (Address Resolution Protocol) resolution.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1897682
Major
Incorrect port bandwidth license usage is shown when VLAN tagging is enabled on ae interfaces.
Product-Group=evo
Severity=Major
On PTX platforms running Junos EVO, ae interfaces are excluded from bandwidth calculation when VLAN tagging is configured.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1911538
Major
Show command execution failure for show system macsec license on MX platforms
Product-Group=evo
Severity=Major
On all Junos MX10004, MX10008, MX304, MX301 platforms on executing the command "show system maces license" fails and doesn't fetch any information however it doesn't cause any service disruption. This is a Day-1 issue.
PR NumberSynopsisCategory: SW PRs for MPC10E PlatformD
1909455
Major
RADIUS interim accounting will not work for subscribers after GRES on MX platforms with MPC10 line card
Product-Group=evo
Severity=Major
On MX platforms with MPC10, RADIUS (Remote Authentication Dial-In User Service) interim accounting will not be working for subscribers after GRES (Graceful Routing Engine Switchover).
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=evo
Severity=Major
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1909719
Critical
Junos and Junos OS Evolved platforms experience high CPU after FPC reboot causing unpredictable issues with protocols (OSPF/ISIS/BGP, etc.) managed by PPMD
Product-Group=evo
Severity=Critical
After upgrading or rebooting Junos/Junos OS Evolved platforms, a CPU spike may be observed in the PPMD (Periodic Packet Management Daemon) process due to repeated internal message failures. This can lead to BFD (Bidirectional Forwarding Detection) authentication failures. Additionally, other protocols that rely on authentication and PPMD for packet distribution may also be affected, potentially resulting in traffic loss.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1830588
Critical
The rpd process crashes on all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted
Product-Group=evo
Severity=Critical
On all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted, route churn will potentially lead to the rpd process crash.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1896548
Major
Enhancement to increase the number of NHs that can fit in ASIC memory
Product-Group=evo
Severity=Major
On PTX10008 with LC1301 & PTX10002-36QDD, the nexthop memory allocation can get fragmented in scaled nexthop scenarios, leading to nexthop memory allocation failures even though memory is not completely exhausted. This is an enhancement to increase the number of NHs that can fit in ASIC memory.
PR NumberSynopsisCategory: PTX10K Line Card specific interface PRs
1914013
Major
Incorrect optics module fault triggered due to transient I2C read error
Product-Group=evo
Severity=Major
On all junos Evolved platforms and MX platforms with ULC cards, The system encountered a momentary I2C communication issue while reading information from the optics module. Instead of treating it as a brief, recoverable read problem, the software incorrectly classified it as a hardware failure and prematurely marked the optics module as faulty.
PR NumberSynopsisCategory: PRs related to PICd and associated lib WAN side PI code.
1914708
Minor
PICD fails to reuse or clean SNMP trap objects, causing memory leak
Product-Group=evo
Severity=Minor
On all Junos OS Evolved platforms, PICD repeatedly created new SNMP trap objects without removing old ones, causing distributord memory leaks over time.
PR NumberSynopsisCategory: ACX724 platform issues
1895749
Critical
System crashes due to a CPU glitch
Product-Group=evo
Severity=Critical
On Junos Evolved ACX7024 and ACX7024X platforms, the system crashes, and a kernel crash is generated due to a random CPU error.
PR NumberSynopsisCategory: MX10K linecard
1898825
Major
Timing defect in ukern thread handling causing LC reboot
Product-Group=evo
Severity=Major
On Junos platforms using line cards LC480 and LC2101, a timing defect in the embedded microkernel thread handling logic causes a panic when a thread attempts to yield execution while interrupt processing is still active. This panic results in a line card reboot.
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1914060
Major
Ipv4/ipv6 ingress filters are not applied for mpls explicit null traffic on PTX10003
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX10003 platforms, IPv4 or IPv6 ingress filters are not applied to Multiprotocol Label Switching (MPLS) packets carrying an explicit NULL label with IPv4 or IPv6 payloads. This occurs due to ingress packet classification, where MPLS explicit NULL packets are processed as MPLS traffic instead of native Internet Protocol (IP) traffic. As a result, configured IPv4/IPv6 ingress filter actions are not executed, leading to unexpected traffic handling and reduced effectiveness of configured policies

 


 

24.4R2-S3-EVO - List of Known issues

PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1846448
Major
The S-BFD responder session cannot be distributed to PFE and failing S-BFD session to establish
Product-Group=evo
On al MX and PTX platforms, If S-BFD(Seamless-Bidirectional Forwarding Detection) responder is configured without the "lo0.0" on device and with any other "lo0.x " then this S-BFD responder session cannot be distributed to PFE(Packet Forwarding Engine) and fails to come up in distributed mode. Hence BFD service will be impacted.

Resolved In: evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S8 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Express BT PFE L3 Features
PR NumberSynopsisCategory: Host path software for ACX platform
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=evo
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1924450
Major
L3VPN traffic drop due to incorrect destination MAC after MAC move in core
Product-Group=evo
On all Junos OS Evolved ACK7K platforms, When a Media Access Control (MAC) address change or move occurs on the core side of the ingress Provider Edge (PE) node in a Layer 3 Virtual Private Network (L3VPN) topology, the ingress PE correctly updates the unicast Internet Protocol version 4 (IPv4) next-hop via Address Resolution Protocol (ARP); however, the dependent IPv4 to Multiprotocol Label Switching (MPLS) (indirect) L3VPN next-hop fails to update its destination MAC address. As a result, L3VPN MPLS traffic is forwarded with a stale destination MAC address, leading to incorrect packet forwarding and service impact.

Resolved In: evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO
PR NumberSynopsisCategory: ACX VxLAN Issue
1860489
Minor
Harmless error logs seen when EVPN Type-5 or IRB configured
Product-Group=evo
On all Junos Evolved ACX platforms, harmless error messages are seen in logs when EVPN Type-5/IRB-NDP routes are configured, this issue does not cause any service impact.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO
PR NumberSynopsisCategory: System Management daemon and related issues
1905807
Minor
System stops responding to "show system applications app ndp detail" command or prevents applications from start/stop/restart
Product-Group=evo
On all Junos OS Evolved platforms with release >=24.1R1, a failure in internal process communication will cause the system to stop responding to the "show system applications app ndp detail" CLI command or prevent applications from start/stop/restart. This issue occurs when systemd becomes unresponsive to requests initiated by sysman. There is no impact to traffic forwarding.

Resolved In: evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:24.4R2-S1-J1-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: EVO Services Jflow PRs for defect & enhancement requests
1874737
Minor
[ptx-10008-evo] ingress mpls IPFIX flows have TopLabelAddr V6: ::
Product-Group=evo
Root Cause: In this issue, there can be two routes published for the same MPLS label (one each for BOS=0 and BOS=1). So, in JFLOW, it learns both of them as a single route, resulting in overwriting the routes based on the sequence of updates. Fix Details: On route update in the onModify routine, if the route is present, then update the Prefix & fec PrefixLen only if the FEC prefix is not NULL. No workaround is available.

Resolved In: evo:23.4R2-S7-EVO evo:24.4R2-S1-J1-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1924455
Major
Junos Evolved RE name resolution requires local communication to dnsmasq
Product-Group=evo
From Junos Evolved release 24.1R1 and later, domain name resolution for host traffic on a routing engine relies on a local dnsmasq server. If an administrator applies firewall or filtering rules that affect local traffic on the RE, they should ensure that DNS traffic is not dropped in order to avoid name resolution failures. With the default dnsmasq configuration, local communication will take place over the :: 1 IPv6 loopback address using the standard port 53.

Resolved In:
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1908196
Major
All Marvell(MX, ACX): LLDP protocol goes down when 'exclude protocol LLDP' is deleted from MACsec policy attached to IFD
Product-Group=evo
With IFD MACsec configured with exclude-protocol LLDP and LLDP protocol enabled, LLDP protocol goes down when 'exclude-protocol LLDP' is deleted from MACsec connectivity association.

Resolved In: evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Paragon Active Assurance
1886928
Major
PAA installation failure on reboot due to "Not found default vrf" error
Product-Group=evo
When a device is rebooted with PAA installed in 25.2R1 , PAA installation on reboot may fail due to "Not found default vrf" error. This can be resolved by deactivating and activating or freshly installing the PAA configuration

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:25.4R1
PR NumberSynopsisCategory: Express ptx-evo PFE L3 Features
1883158
Major
Issue while connecting boot server with 1st iteration while in 2nd iteration it will go fine.
Product-Group=evo
In JUNOS evolved, ARP resolution requests are throttled on FPC per logical interface level i.e if resolution request on a logical interface expires then a throttle timer is started on that logical interface and no other resolution request could be generated on that logical interface when throttle timer is running. In this issue RE netstack is sending packets to FPC with hint to resolution request for already resolved IP address and triggering throttle timer. So resolution request for second IP address on same logical interface could not be generated for some time which is triggering phone-home application 10 seconds time out.

Resolved In:
PR NumberSynopsisCategory: EVO TCP AO module
1924030
Major
BGP/LDP sessions flap due to TCP sequence number wraparound when TCP-AO is enabled
Product-Group=evo
On all Junos OS Evolved platforms, Border Gateway Protocol (BGP) or Label Distribution Protocol (LDP) sessions will intermittently flap when Transmission Control Protocol-Authentication Option (TCP-AO) is enabled under high traffic or long-lived connections due to TCP sequence number rollover, leading to TCP authentication failures. The issue is primarily observed in interoperability scenarios and does not cause system crashes.

Resolved In: evo:25.2R2-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO
PR NumberSynopsisCategory: Configd, ffp issues
1907238
Minor
Rescue Configuration Check Fails
Product-Group=evo
On all ACX platforms, Junos Evolved cannot verify the syntax and integrity of the saved rescue configuration file when performing a configuration check.

Resolved In: evo:26.1R1-EVO
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1867821
Major
The "ui-gnmi-pubd.log" file growth may cause disk space issues on all Junos OS Evolved platforms
Product-Group=evo
On all Junos OS Evolved platforms, when telemetry is enabled and an active gNMI subscription includes a configuration path, the "ui-gnmi-pubd.log" file will grow continuously without log rotation or archival. This behaviour will lead to potential disk space exhaustion over time, however, there is no traffic impact due to this issue.

Resolved In: evo:23.4R2-S7-EVO evo:24.4R2-S1-EVO evo:24.4R2-S1-J1-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.4R1
PR NumberSynopsisCategory: EVPN control plane issues
1893671
Minor
EVPN routes take longer to install into the FIB after being learned via BGP
Product-Group=evo
In large-scale Junos and Junos EVO deployments, within high-scale BGP route scenarios, EVPN routes may take up to 7 minutes to be installed into the FIB. This delay can temporarily impact traffic until the routes are fully installed.

Resolved In: evo:24.2R2-S3-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:24.2R2-J8 junos:24.2R2-S3 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Express AFT Common FW issues
1934506
Major
The FPC crashes on all Junos OS Evolved PTX Series platforms when VLANs on an AE interface are updated or deleted
Product-Group=evo
On all Junos OS Evolved PTX Series platforms with multiple VLANs on an Aggregate Ethernet (AE) interface and an Firewall filter with family ethernet switching and bandwith policer attached to both the AE interface and its associated VLAN interfaces, a modification or deletion of the VLANs will lead to a FPC crash. All the traffic over the afeccted FPC will be droped.

Resolved In: evo:23.4R2-S8-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:25.4R2
PR NumberSynopsisCategory: Express PFE FW Features
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
The management interface is unreachable post switchover/RPD restart events
Product-Group=evo
On all Junos platforms with management interface em0 disabled, the management port remains unreachable after performing RE switchover or rpd restart events and re-enabling the management port.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=evo
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Indirect nexthop routing infrastructure
1928880
Major
traffic shifted and spiked to certain nh in unilist nh during transient state after interface flapped among ecmp
Product-Group=evo
Under scaled scenario, if a new best active lead path in a BGP multipath is coming up, BGP will first tear down the existing multipath, and temporary make the multipath route use the new best path unicast next hop, and also schedule a background job to re-calculate and form the new multpath route, finally make route change to newly formed multipath next hop. During that re-convergence period, transitional traffic spike may be observed in the active path, until all the service routes over the underlay BGP multipath next hop are updated in PFE data path. In the PR test case, AE11 corresponds to the multipath best path egress interface.

Resolved In:
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1815837
Minor
Configure low file size in traceoptions while logging volume is high will lead to high CPU and RPD scheduler slips causing operational impact
Product-Group=evo
If the file size is too small and the amount of traceoptions volume is too high it can cause scheduler slips and operational impact.

Resolved In: evo:22.3X80-D49-EVO evo:23.4R2-S6-EVO evo:24.2R2-S1-EVO evo:24.4R2-S1-J1-EVO evo:24.4R2-S2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S7 junos:23.4R2-S6 junos:24.2R2-S1 junos:24.4R2-S2 junos:25.2R1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1881609
Minor
RSVP hello messages uses secondary address when primary/preferred address are present for same interface
Product-Group=evo
On all Junos and Junos OS Evolved platforms where RSVP (Resource Reservation Protocol) configuration is present and a RSVP enabled interface has 2 IP address of which one is configured as primary/preferred in that case the RSVP Hello message uses the secondary IP address to form neighborship.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Issues related to control plane security
1860970
Minor
SIB HA wait timeout error upon graceful RE switchover
Product-Group=evo
SSH issue from the Routing Engine to the FPC causes SIB HA timeout error upon RE switchover. All the SIBs will be reset as a result of that.

Resolved In:
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1899826
Major
Macsec traffic stops working after performing a LMIC reboot
Product-Group=evo
On MX304 when performing an OFFLINE/ONLINE operation on the LMIC (Line-Card Module Interface Card), in scale scenarios the MACsec traffic becomes stuck, resulting in traffic impact.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:24.4R2-S3 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1853209
Major
Syslog forwarding intermittently stops post DUT reboot on virtual devices.
Product-Group=evo
On virtual devices, on reboot, vpn may take time to come up. Meanwhile since mgmt_junos is first in the routing table, syslog gets bound to mgmt_junos and hence forwarding stops.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.3X60 junos:23.4R2-S6 junos:24.4R2-S3 junos:25.2R2 junos:25.3R1 junos:25.4R1

 


 

Modification History

First publication 2026-02-10