Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX

Alert Description

Junos Software Service Release version 24.2R2-S4-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 24.2R2-S4-EVO is now available.

24.2R2-S4-EVO - List of Fixed issues

PR NumberSynopsisCategory: Issues with pluggable optics
1890558
Major
Mismatch between configured and reported wavelength for some optics
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms and MX paltforms with MPC11E / LC9600 line cards , the issue is seen with optics that doesn't support 6.25GHz spacing. There is a mismatch seen between the configured and the reported wavelength. The wavelength mismatch will lead to the loss of signal and thus result in impact on the traffic.
PR NumberSynopsisCategory: "agentd" software daemon
1885622
Major
The aaasd process stops responding for RPC calls
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms with gRPC configured, the aaasd process rejects incoming RPCs. This issue occurs in some rare cases, and aaasd will stop listening for authentication requests from reverse proxy. This issue does not cause a traffic impact.
PR NumberSynopsisCategory: Border Gateway Protocol
1838490
Minor
BGP_PREFIX_THRESH_EXCEEDED warning message keeps flooding after accepted max prefix limit is reached
Product-Group=evo
Severity=Minor
With this PR fix, BGP_PREFIX_THRESH_EXCEEDED warning message will be stopped after the max prefix limit is reached. The behavior is consitent with prefix-limit feature.
1880630
Major
Scaled BGP sessions remain in the Idle state after interface rollback.
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, after interface configuration rollback, sessions stay in Idle state when multiple BGP(Border Gateway Protocol) sessions exist.
1914814
Major
BGP task replication will be stuck in 'InProgress' state following an RE switchover when two single hop EBGP sessions are configured on two different interfaces using the IP addresses from the same subnet
Product-Group=evo
Severity=Major
On all Junos OS and Junos OS Evolved platforms with NSR (Nonstop Active Routing), when two single hop EBGP (External Border Gateway Protocol) sessions are configured to run on two different interfaces using IP addresses from the same subnet (overlapping subnet), the BGP task replication process does not complete after an RE (Routing Engine) switchover for the EBGP session with a specified local-address. This results in one BGP peer being in the 'Idle' state on the Backup RE while remaining in the 'Established' state on the new Master RE, causing the BGP task replication process to remain stuck in the 'InProgress' state.
1915893
Major
PTX10001-36MR - rpd crashed while stale route LLGR timer expired
Product-Group=evo
Severity=Major
PR NumberSynopsisCategory: BBE Remote Access Server
1813456
Minor
Error message is observed after device is restarted
Product-Group=evo
Severity=Minor
On all Junos Evolved platforms, the error message "UI_SCHEMA_SEQUENCE_ERROR" is observed when device is restarted. There is no traffic impact due to this issue.
PR NumberSynopsisCategory: PFE COS features on BT based platforms
1856528
Major
Missing traffic statistics via telemetry on PTX EVO platforms with MPC10E, MPC11E, and LC9600 line cards
Product-Group=evo
Severity=Major
On PTX EVO platforms equipped with MPC10E, MPC11E, or LC9600 line cards, when telemetry monitoring is enabled and the sensor /junos/system/linecard/interface/traffic/ is subscribed to, some entries for interface traffic statistics might be missing. This occurs due to an issue where the volume of telemetry data per interface can lead to message fragmentation, resulting in incomplete data export.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1871457
Minor
Input bytes counter on an ifl is displayed as zero on Junos Evolved platforms
Product-Group=evo
Severity=Minor
On all Junos Evolved platforms, the 'input bytes' counter in the 'show interfaces ' is always displayed as zero. There is no traffic impact due to this issue.
PR NumberSynopsisCategory: CoS support on DNX
1893395
Minor
Classification of traffic is not working due to Forwarding Class to Queue mapping configuration failure.
Product-Group=evo
Severity=Minor
Error Message "Failed to program the hardware with error table is full, during = jbcm_cosq_gport_queue_offset_mapping_set" can be seen while modifying the class-of-service configuration in a single commit involving both the addition and deletion of forwarding-class/queues on ACX7k platforms.
PR NumberSynopsisCategory: EVPN ELAN/E-TREE
PR NumberSynopsisCategory: Host path software for ACX platform
1821807
Minor
Excessive logging in various log files is observed on EVO ACX platforms
Product-Group=evo
Severity=Minor
On all Junos OS Evolved ACX platforms, the log message 'packetio[10514]: [t:17681] [Info] JUNIPER:: DevDb params are not needed for other platform productId:257' appears in the messages file and the JournalCtl. This message has no functional impact, but it should be logged only once during PFE initialization following a reboot and not continuously.
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=evo
Severity=Major
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.
PR NumberSynopsisCategory: ACX IRB specific issues
1900224
Minor
The egress traffic control profile configured under hierarchical QoS does not take effect when applied to an L2IFL interface that is associated with an IRB
Product-Group=evo
Severity=Minor
On Junos Evolved ACX 7K platforms, applying egress traffic control profile under HQoS (Hierarchical Quality of Service) on a L2IFL (Layer2 Logical Interface) that has active traffic flows and is associated with an IRB (Integrated Routing & Bridging), the flows continue to use the existing physical interface VOQ (Virtual Output Queue) flow entries mapped to that L2IFL.
PR NumberSynopsisCategory: DNX L2 related features
1742136
Minor
Traffic impact is seen on Junos OS Evolved ACX7K platforms due to an evo-pfemand process crash after the FPC restart or system reboot
Product-Group=evo
Severity=Minor
The FPC (Flexible PIC Concentrator) restart or system reboot causes evo-pfemand process crash on Junos OS Evolved ACX7K platforms. Forwarding traffic will be affected here.
PR NumberSynopsisCategory: VPWS, L2 CKT, EVPN-VPWS
1787689
Major
, After system reboot or RE switch over, syslog messages with "ddsType = "RouteCcc" tpName = "BrcmRtCcc"" are seen.
Product-Group=evo
Severity=Major
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1846150
Minor
EVO: ACX7024X - "Exception: [Errno -2] Name or service not known" outputs after issuing "show forwarding-options hash-key"
Product-Group=evo
Severity=Minor
Following command doesn't return result correctly. lab@ACX7024X> show forwarding-options hash-key Exception: [Errno -2] Name or service not known The error is because command support mapping was wrong for ACX7024X. The problem has been fixed as below. lab@ACX7024X> show forwarding-options hash-key SENT: Ukern command: show evo-pfemand hashkey Multiservice Hash Settings ---------------------------- Source MAC: disabled Destination MAC: disabled Inet Hash Settings -------------------- Layer3 Proto: disabled Layer4 Proto: disabled Inet6 Hash Settings ---------------------- Layer3 Proto: disabled Layer4 Proto: disabled Mpls Hash Settings --------------------- Label: disabled IpPayload: disabled EtherPayload: disabled ZeroCW: disabled
1866442
Minor
ACX7K is seeing an info level log from evo-pfemand tied to removeEcmpNhInHw
Product-Group=evo
Severity=Minor
ACX7K is seeing an info level log from evo-pfemand tied to removeEcmpNhInHw
1891016
Major
ACX7k sees a bcm_dnx_l3_egress_ecmp_delete error while deleting the last member of the group
Product-Group=evo
Severity=Major
ACX7k sees a bcm_dnx_l3_egress_ecmp_delete error while deleting the last member of the group
1908282
Major
Next hop is missing when ECMP uses an IRB interface in an EVPN-VXLAN scenario
Product-Group=evo
Severity=Major
On all Junos OS Evolved ACX7K Series platforms, the Next hop is wrongly programed when Equal Cost Multi Path (ECMP) is configured, and IRB (Integrated Routing and Bridging) interface is used as a Next hop. Since the Next hope is not being programed properly, routes are unable to have a next hop causing service disruption.
1924450
Major
L3VPN traffic drop due to incorrect destination MAC after MAC move in core
Product-Group=evo
Severity=Major
On all Junos OS Evolved ACK7K platforms, When a Media Access Control (MAC) address change or move occurs on the core side of the ingress Provider Edge (PE) node in a Layer 3 Virtual Private Network (L3VPN) topology, the ingress PE correctly updates the unicast Internet Protocol version 4 (IPv4) next-hop via Address Resolution Protocol (ARP); however, the dependent IPv4 to Multiprotocol Label Switching (MPLS) (indirect) L3VPN next-hop fails to update its destination MAC address. As a result, L3VPN MPLS traffic is forwarded with a stale destination MAC address, leading to incorrect packet forwarding and service impact.
PR NumberSynopsisCategory: ACX IFL, IFF creation
1857014
Major
Interfaces on ACX7509 go down after reboot with any FPC in an offline state
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX7509 platforms, if any Flexible PIC Concentrator (FPC) is in an offline state, either due to manual offlining via CLI, a hardware fault, or insertion of an incompatible FPC, a subsequent system reboot will result in all interfaces on the remaining healthy FPCs going down.
PR NumberSynopsisCategory: DNX VPLS
1861642
Major
VPLS traffic reports - Failed to program the hardware with an error - = invalid configuration specified, during = jbcm_multicast_add
Product-Group=evo
Severity=Major
In correct use of internal API was giving a different Gport number while deleting entry from Mcast group. With HQOS enabled on core interface, when 1st member in the MC grp is flapped, stale entries are created in VPLS VSI mcgroup
PR NumberSynopsisCategory: Firewall related development
1843116
Major
Routing policy with next hop set to default route 0.0.0.0/0 is not supported
Product-Group=evo
Severity=Major
On all Junos Evolved ACX platforms, when routing policy is configured to forward traffic to default route 0.0.0.0/0, configuration is committed but fails to work since knob is not supported.
1875725
Minor
The firewalld process crashes post specific set of filter related modifications performed in single commit
Product-Group=evo
Severity=Minor
On Junos EVO platforms, When Firewall Filter change involved both delete and change to new filter on an interface in a single commit resulted in Firewalld coredump.
PR NumberSynopsisCategory: Binding Queue
1885455
Major
application rpd-agent may restart with a coredump after interface related event changes.
Product-Group=evo
Severity=Major
The rpd-agen application may restart either immediately or latently - after interface are activate, deactivated, created, or removed.via.
PR NumberSynopsisCategory: software upgrade infra issues
1878365
Major
Log messages getting disappeared after upgrade
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, log messages disappear when an upgrade without the "no-validate" option is performed. This issue has no impact on traffic.
PR NumberSynopsisCategory: Issues related to debug utilties - objmon, objshell/Dashboard
1835388
Major
The Netconf output for xml format shows tag under ping failure situation
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms, the Netconf output for xml format shows tag under ping failure situation. It is only an XML display output issue and has no impact to network traffic.
PR NumberSynopsisCategory: Ztp related issues
1740989
Major
Ultron sZTP: System not bootable after request system zeroize
Product-Group=evo
Severity=Major
zeroize does secure erase of disk on available platforms. However, few platforms do not support secure erase and hence "dd" is used to erase contents of disk. In ACX based platforms, "dd" of 40GiB disk was taking more time which raised watchdog timeout resulting in kernel panic. The solution was to reset watchdog timer to 500s just before "dd" procedure starts
PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1859501
Minor
Interfaces with the same outer VLAN ID but different inner vlans or inner-lists/ranges are reporting a commit error
Product-Group=evo
Severity=Minor
On all Junos OS Evolved platforms, When an interface configured with the same outer VLAN ID but with different inner vlans or inner-lists/ranges, reports a commit error.
1911684
Major
IFL installation failure with the same outer VLAN tag and distinct inner VLAN lists
Product-Group=evo
Severity=Major
On all Junos evolved platforms, the logical interface (IFL) installation fails in the Packet Forwarding Engine (PFE) when two or more double-tagged sub-interfaces are configured under the same aggregated ethernet interface with the same outer VLAN tag and distinct inner VLAN lists.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1756208
Critical
Junos OS Evolved: MAC table changes cause a memory leak (CVE-2024-39557)
Product-Group=evo
Severity=Critical
An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a memory leak, eventually exhausting all system memory, leading to a system crash and Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83017 [juniper.net] for more information.
1889335
Minor
Traffic drop is observed in an EVPN multihoming as the MAC route points to the ESI interface when the CE (ESI) IFD flaps
Product-Group=evo
Severity=Minor
On all Junos and Junos Evolved platforms, in an Ethernet Virtual Private Network (EVPN) MultiHoming setup with Ethernet Segment Identifier (ESI) configured under logical Interface (IFL) (CE-facing), when the corresponding IFD (Physical Interface) flaps, the MAC route will point to the ESI interface, while it should point to the Multihoming CE (Customer Edge) interface. This results in traffic loss.
1899530
Major
MAC learning failure when moving the AE interface from one VLAN to another VLAN in a single commit
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, when an Aggregated Ethernet (AE) logical interface (IFL) is moved from one Virtual LAN (VLAN) to another VLAN in a single commit, Layer 2 forwarding tables fail to update correctly. This causes Media Access Control (MAC) learning failure and traffic disruption.
PR NumberSynopsisCategory: Configd, ffp issues
1900883
Major
Traffic loss occurs due to missing apply-path handling during reboot or configd restart
Product-Group=evo
Severity=Major
On platforms running Junos OS Evolved 20.2R1-EVO and later releases, apply-path configurations with wildcards after leaf nodes are not evaluated correctly during reboot or configd restart. This is due to missing special handling required for evaluating such configurations during reboot and configd restart, this causes failure of routing and forwarding functions that rely on apply-paths, leading to traffic loss post reboot or configd restart.
PR NumberSynopsisCategory: SNMP, mib2d issues
1792360
Major
The SNMPv3 Authentication error is observed
Product-Group=evo
Severity=Major
On All Junos Evolved platforms, the Simple Network Management Protocol version 3 (SNMPv3) Authentication error is observed at Network Management System (NMS) side as routing engine switch over causes change in engine-id and SNMPv3 requests sent to the server will fail.
PR NumberSynopsisCategory: EVPN control plane issues
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=evo
Severity=Critical
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=evo
Severity=Major
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby) the ARP (Address Resolution Protocol) tables from Customer Edge (CE's) device may not update simultaneously on Provider Edge (PE) devices when an IP address moves between two different Ethernet Segments (ESIs) during a switchover, leading to temporary traffic disruption until the tables are refreshed.
1916656
Major
Incorrect CCC state displayed when IFL or interface status is absent
Product-Group=evo
Severity=Major
On all Junos OS and Junos OS Evolved platforms, When the logical interface (IFL) is not present, the system incorrectly reports the Circuit Cross-Connect (CCC) state as CCC Up. Similarly, when the interface status itself is not available, the pseudowire state is shown as CCC_Up or CCC_Down. The pseudowire state should instead be reported as Not Applicable, since the underlying interface or IFL required to determine a valid CCC state does not exist. Displaying CCC Up/Down incorrectly in the absence of interface.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1916646
Major
IRB interface state is observed incorrect on IFD events tracked by a Network Isolation group
Product-Group=evo
Severity=Major
On MX, EX9200, QFX, PTX platforms, Traffic forwarded over the IRB (Integrated Routing and Bridging) is impacted when isolation decisions rely on the state of a tracked interface, because the Network Isolation Group tracks the interface but processes only IFL (Interface Logical) events and does not process IFD (Interface Device) events.
1926818
Major
ARP resolution failure for /32 static host routes via IRB in EVPN virtual-switch routing instances
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms that support EVPN (Ethernet VPN) virtual-switch routing instances, ARP (Address Resolution Protocol) resolution fails for static host routes configured with a /32 mask when the next-hop interface is an IRB (Integrated Routing and Bridging) interface and the destination host resides in a different subnet. As a result, ARP entries are not installed, MAC (Media Access Control) addresses of destination hosts are not learned, and traffic destined to those hosts becomes unreachable, causing service impact.
PR NumberSynopsisCategory: Express PFE FW Features
1911372
Minor
The evo-aftmand process crashes when the prefix list is modified in scaled scenario
Product-Group=evo
Severity=Minor
On all Junos OS Evolved PTX platforms, a filter installation failure under high prefix utilization leaves the system in an inconsistent internal state, and subsequent modification of prefix lists or prefixes in the filter can further result in incorrect traffic matching and unpredictable packet handling, leading to inconsistent traffic behavior. In rare cases, this internal data corruption may also cause the evo-aftmand process to crash.
PR NumberSynopsisCategory: ACX7332 & ACX7348 Platform Software
1820783
Minor
Configuring the port to 400G without inserting an optical transceiver causes the interface to disappear
Product-Group=evo
Severity=Minor
When interface speed is configured as 400G and other relevant ports are marked as unused so that port can support 400G, the interface disappears and is not visible in the show interface terse output. Issue is observed on FPC: ACX7300-2CD4C without a 400G optics present on the device
1894824
Minor
ACX 7348 - Continuous log messages seen on backup routing engine after RE switchover
Product-Group=evo
Severity=Minor
OnJunos Evolved ACX 7348 platforms, continuous log messages are flooded in the backup routing engine during switchover of routing engine. This does not have any functional impact.
1914062
Major
[ACX] HWD_ALARM_CLEAR_NOTICE: ClearFault: Fault(Location: /Chassis[0]/Psm[0] Device: psm0 Error: psm_cml_pec_fault) cleared
Product-Group=evo
Severity=Major
[ACX] HWD_ALARM_CLEAR_NOTICE: ClearFault: Fault(Location: /Chassis[0]/Psm[0] Device: psm0 Error: psm_cml_pec_fault) cleared
1918410
Minor
ACX7348 - Minor alarm not clearing for "Host 0 Active Disk Usage Exceeded"
Product-Group=evo
Severity=Minor
When multiple partitions exceeded 90%, only one alarm was shown because all partitions shared the same descriptor and when any one partition dropped below 90%, the alarm was cleared globally, even if other partitions were still above the threshold. This caused incorrect alarm behavior in multi-partition scenarios.
PR NumberSynopsisCategory: ACX PTP Timing:
1855379
Major
After GRES ptp-spll-lock-state is stuck in ACQUIRING instead of phase aligned. timingd re core is also observed which is not seen in rerun
Product-Group=evo
Severity=Major
After GRES ptp-spll-lock-state is stuck in ACQUIRING instead of phase aligned. timingd re core is also observed which is not seen in rerun
PR NumberSynopsisCategory: ACX7509 Platform related issues
1907310
Major
After RE switchover on the device, the capacity of DC PSM is observed to be zero after toggling the input power
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms, whenever a Routing Engine (RE) switchover occurs and the DC input supply to one of the Power Supply Modules (PSMs) is toggled or flapped, the output capacity of that PSM becomes zero. If the remaining PSMs are unable to provide sufficient power to the chassis, all Flexible PIC Concentrators (FPCs) go offline, resulting in traffic impact.
PR NumberSynopsisCategory: ACX7509 timing related issues
1892751
Minor
On Junos OS Evolved ACX7509 system's clock break synchronization
Product-Group=evo
Severity=Minor
On Junos OS Evolved ACX7509 platforms, clockd uses an older API to communicate with the Zarlink DPLL (Digital Phase-Locked Loop) timing registers, and because this API lacks proper locking, it can impact Zarlink register synchronization and lead to time-synchronization issues for PTP (Precision Time Protocol) and SyncE (Synchronous Ethernet).
PR NumberSynopsisCategory: ISIS routing protocol
1859099
Minor
Memory leak is observed for certain topologies when TI-LFA is configured
Product-Group=evo
Severity=Minor
On all Junos and Junos OS Evolved platforms , where IS-IS/OSPF is enabled and TI-LFA (post-convergence-lfa) is configured in a SR (Segment Routing) environment. In a scenario where the computed backup paths to reach a destination is fetched from the more than one originator, duplicate paths gets computed for certain topology combinations and the clean-up of infosid list doesn't happen this leads to memory leak that might eventually lead to high memory usage and result in rpd crash and thus impacting traffic.
1925611
Minor
Telemetry sensors on ACX EVO to pull /network-instances/network-instance/protocols/protocol/isis/interfaces only report the first ISIS interface
Product-Group=evo
Severity=Minor
Telemetry sensors on ACX EVO to pull /network-instances/network-instance/protocols/protocol/isis/interfaces only report the first ISIS interface
PR NumberSynopsisCategory: Key Management
1864322
Major
On rare circumstances the kmd or iked process crash will be observed on using the third-party library API
Product-Group=evo
Severity=Major
On all Junos platforms using ipsec-key-management (daemon name kmd) or the ike-key-management (daemon name iked) service for the IPSec VPN functionality, under very rare scenarios the device can be extremely overloaded so that it cannot generate a random number required for the VPN negotiation after repeated attempts. When this occurs, the VPN negotiation daemon kmd or iked can crash. The VPN operation may or may not be temporarily impacted and will recover automatically.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1911538
Major
Show command execution failure for show system macsec license on MX platforms
Product-Group=evo
Severity=Major
On all Junos MX10004, MX10008, MX304, MX301 platforms on executing the command "show system maces license" fails and doesn't fetch any information however it doesn't cause any service disruption. This is a Day-1 issue.
PR NumberSynopsisCategory: SW PRs for MPC10E PlatformD
1909455
Major
RADIUS interim accounting will not work for subscribers after GRES on MX platforms with MPC10 line card
Product-Group=evo
Severity=Major
On MX platforms with MPC10, RADIUS (Remote Authentication Dial-In User Service) interim accounting will not be working for subscribers after GRES (Graceful Routing Engine Switchover).
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=evo
Severity=Major
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.
PR NumberSynopsisCategory: OSPF routing protocol
1867120
Major
OSPFv3 Adjacencies Fail Across Realms When Shared Interface with IPsec-SA Experiences State Changes
Product-Group=evo
Severity=Major
On Junos Evolved , IPsec OSPFv3 realm sessions do not stay up when the same interface had been used for both realm and nonrealm OSPFv3 configurations. After an aggregate interface flap occurs, the realm session will not come back online.
PR NumberSynopsisCategory: RPD Interfaces related issues
1913519
Major
EVPN routes are stuck in the KRT queue
Product-Group=evo
Severity=Major
When EVPN (Ethernet Virtual Private Network) routes attempt to transition between private (eg, management em1 - with IGP enabled) and public interfaces, it causes an error in next-hop resolution in the kernel, because the system deletes the old indirect next-hop and creates a new one. This happens as the kernel does not support changing an indirect next-hop between private and public interfaces directly.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1853521
Major
BGP keeps trying to retrieve VPLS table info from the kernel even after the Layer2 instance is deactivated
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, when a Layer2 instance configuration is deactivated, the Kernel Routing Table (krt) continues attempting to retrieve VPLS table information from the kernel, even though the table has already been deleted. This results in repeated retries by krt.
1908681
Major
RIB and the FIB inconsistency results in traffic loss in IPsec scenario with st0 interface configured
Product-Group=evo
Severity=Major
On Junos OS SRX platforms having IPsec (Internet Protocol Security) with st0 (Secure Tunnel Interface) interface configured, traffic loss will be observed if the "next-hop-tunnel" configuration is removed and added within a few seconds. This happens due to a inconsistency between the RIB (Routing Information Base) and the FIB (Forwarding Information Base).
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=evo
Severity=Major
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1849202
Major
BGP route still seen in routing table when route not available
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms , the router learns routes through the BGP (Border Gateway Protocol) and has the feature: "BGP RIB Sharding" enabled for IPv4. These routes are stored in the Inet.0 routing table. Later, if the neighbor that announced this route or the protocols associated with the routing table of the used VRF (Virtual Routing and Forwarding) are removed, the route remains in the routing table, and hence traffic is forwarded to the stale routes.
1907558
Major
The rpd process crashes in a vrf having EVPN-VXLAN routes with specific configuration.
Product-Group=evo
Severity=Major
In all Junos and Junos OS Evolved platforms, when EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible LAN) routes are present in a VRF (Virtual Routing and Forwarding), configuring a generate route in same vrf can cause rpd (Routing Protocol Daemon) to crash and restart. Generate route configuration has to be removed to recover from this behaviour.
PR NumberSynopsisCategory: Resource Reservation Protocol
1792192
Major
Missing HELLO object in RSVP Hello messages after RE failovers in the NSR mode
Product-Group=evo
Severity=Major
In rare unknown condition after RE switchover, rsvp hello can have local instance to be zero due to wrong information synced from master RE by mirroring process. When rsvp neighbor is created and never received hello exchange with neighbor, the replication entry which is synced to standby RE will have most of the information as zero, including the local instance, which is used to generate hello object. After RE switchover, rsvp hello will have local instance to be zero due to the wrong information synced from master RE by mirroring process. This is addressed by update the replication entry once all the parameters of the rsvp neighbor is filled, so standby RE will receive the right info, also for future protection, backup RE will avoid creating neighbor until after switchover and setting a new local instance if it is zero.
1864949
Major
User traffic dropped after ISIS went down on one side with trapcode observed
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms if a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in unexpected traffic blackholing on the router at the downstream end of the flapping link.
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.
PR NumberSynopsisCategory: Segment routing traffic Engineering
1911821
Minor
(SPRING-TE Entropy-label is not supported for segment-list with single label for tunnel) is reported in messages logs even if the entropy label feature is not configured
Product-Group=evo
Severity=Minor
On Junos and Junos Evolved where Segment Routing Traffic Engineering (SRTE) Tunnel is supported, the log message (RPD_SPRING_TE_ENTROPY_UNSUPPORTED_FOR_ONE_LBL: SPRING-TE Entropy-label is not supported for segment-list with single label for tunnel) is observed even when entropy label feature is not configured.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1862500
Major
MX304 or MPC10/11/LC9600 aftd-trio process memory leak when polling NPU sensor data
Product-Group=evo
Severity=Major
On Linux-based PFE platforms like MX304, MPC10, MPC11, and LC9600, streaming NPU sensor data via Telemetry may leak memory
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1921361
Major
Slow memory leak triggered by subscribing to the pipeline sensor for a long duration
Product-Group=evo
Severity=Major
On Junos platforms with MPC 1-9, LC2101, LC480, LC2103 line-cards and MX204, a slow memory is observed when subscribing to the pipeline sensor ( path is /components/component/integrated-circuit/pipeline-counters/). Over time, this causes a gradual increase in heap memory usage. Increase in heap memory usage beyond a certain threshold will lead to FPC crash resulting in loss of services and traffic over that FPC.
PR NumberSynopsisCategory: DDos Support on MX
1848317
Major
SCFD flow variation leads to error messages or process crash
Product-Group=evo
Severity=Major
On all Junos MX platforms with line cards MPC10/11/LC9600/LC4800, this includes the MX304 and SCFD (Suspicious Control Flow Detection) enabled, when there are numerous flows being added, deleted, or modified simultaneously, the system experiences error messages or process crashes due to thread synchronization issues. The process crash will cause the FPC to restart.
PR NumberSynopsisCategory: Issues related to NETCONF
1858635
Critical
ACX Series vmcore crash when netconf notifications are enabled
Product-Group=evo
Severity=Critical
On ACX7024, ACX710032C, and ACX7348 platforms running Junos OS Evolved, enabling netconf notifications with the command "set system services netconf notification" may cause a memory leak. This results in a control plane crash (vmcore). Forwarding plane remains unaffected.
PR NumberSynopsisCategory: Issues related to XML, JSON handling
1843789
Critical
Management Daemon (MGD) when executing certain configuration display commands with the display json option in the CLI
Product-Group=evo
Severity=Critical
A core-dump issue has been identified in the Management Daemon (MGD) when executing certain configuration display commands with the display json option in the CLI. This may lead to an abrupt session termination and CLI disruption.
PR NumberSynopsisCategory: Virtual Private LAN Services
1882938
Major
In VPLS scenario due to ungraceful switchover rpd process crash is observed
Product-Group=evo
Severity=Major
On Junos OS and Junos OS Evolved platforms with VPLS (Virtual Private LAN Service) configured, during an ungraceful GRES (Graceful Switchover) switchover with NSR enabled, an issue with VPLS label replication will cause a mismatch, resulting in an rpd (Routing Protocol Process) crash.
PR NumberSynopsisCategory: ACX7000 interface software related issues.
1885817
Major
ACX7k DWDM optics wavelength not applied after reboot
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX7K platforms, the DWDM (Dense Wavelength Division Multiplexing) optics wavelength is not applied after reboot. Hence, the system defaulted to the standard wavelength mode rather than the explicitly configured wavelength. When the wavelength is defaulted to the standard wavelength mode, the link will be up and with no data traffic impact, and it's a corner case, and is specific to DWDM optics only.
PR NumberSynopsisCategory: ACX7000 platform software related issues.
1885345
Minor
Fan Tray X Incompatible alarm was raised when the fan unit was removed
Product-Group=evo
Severity=Minor
On all ACX7100-32C, when the fan unit was removed, the "Fan Tray X Incompatible" alarm was raised upon removal of the fan unit. This issue has no impact on traffic.
1889258
Minor
SSD firmware for both primary & secondary SSD is not displayed
Product-Group=evo
Severity=Minor
SSD firmware for both primary & secondary SSD is not displayed

 


 

24.2R2-S4-EVO - List of Known issues

PR NumberSynopsisCategory: Express BX PFE L3 Features
1886060
Major
PFEs will enter FAULT state when multiple PFEs are on-lined / off-lined / restarted at the same time
Product-Group=evo
On all Junos-Evolved PTX platforms, If multiple PFEs ( packet forwarding engine ) are on-lined / off-lined / restarted at the same time, without any delay in between the PFE activities ( on-lined / off-lined / restarted ) then one or more PFE will go fault state and all ports belonging to those PFEs become unusable.

Resolved In: evo:23.4R2-S7-EVO evo:24.4R2-S1-EVO evo:24.4X200-D20-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO
PR NumberSynopsisCategory: ACX EVO PFE IP Tunnel issue assignment alias
1896144
Major
Renaming a FTI tunnel causes all IPv6 traffic on the FTI tunnel to be dropped
Product-Group=evo
On ACX-series platforms running Junos Evolved Operation System (OS), when renaming a Flexible Tunnel Interface (FTI) causes all Internet Protocol version 6 (IPv6) traffic on the FTI tunnel to be dropped.

Resolved In: evo:24.4R2-S3-EVO
PR NumberSynopsisCategory: DNX L2 related features
1855040
Minor
Hardware programming failed due to invalid parameters being specified
Product-Group=evo
On ACX platforms running Junos OS Evolved, on walkthrough Bulk flush DB for re-Enable learning, we are getting the invalid port since the port/ifl (Interface Logical) is already deleted. It is a timing issue. Mainly occur when any catastrophic event on ifd (Interface Device), pfe (Packet Forwarding Engine) restart or feb (Forwarding Engine Board) restart.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO
PR NumberSynopsisCategory: System Management daemon and related issues
1852221
Minor
The l2cpd-agent crashes due to its state cleaned up during shutdown
Product-Group=evo
On all Junos Evolved platforms, due to a timing issue, it is observed that the l2cpd agent crashes when the app's state is being cleaned by external garbage collection as app is about to shutdown. But there is no traffic impact due to this issue.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO evo:25.4R2-EVO
PR NumberSynopsisCategory: EVO RPD agent PRs
1739567
Major
Forwarding issues observed on ACX7509 with NG-MVPN configuration
Product-Group=evo
On Junos Evolved ACX7509, with NGMVPN (Next-Generation Multicast Virtual Private Network) configuration, failures in local ping and LAG (Link Aggregation Group) bring up issues are observed resulting in forwarding traffic drop.

Resolved In: evo:23.2R2-S3-EVO evo:23.3R1-EVO evo:23.4R1-EVO
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1867821
Major
The "ui-gnmi-pubd.log" file growth may cause disk space issues on all Junos OS Evolved platforms
Product-Group=evo
On all Junos OS Evolved platforms, when telemetry is enabled and an active gNMI subscription includes a configuration path, the "ui-gnmi-pubd.log" file will grow continuously without log rotation or archival. This behaviour will lead to potential disk space exhaustion over time, however, there is no traffic impact due to this issue.

Resolved In: evo:23.4R2-S7-EVO evo:24.4R2-S1-EVO evo:24.4R2-S1-J1-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.4R1
1884781
Major
Slow configuration commit observed on devices with a single Routing Engine (RE)
Product-Group=evo
On all Junos OS Evolved platforms with single RE and the system type is cluster, a commit delay is observed when operating with a single RE. This occurs because the system attempts to synchronize with the second RE by default, but since it's not present, the process waits and causes the delay in commit.

Resolved In: evo:23.4R2-S7-EVO evo:24.4R2-EVO evo:24.4X200-D20-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.4R2-S7 junos:23.4X30 junos:23.4X30-D30 junos:24.2R2-S4 junos:24.2X1 junos:24.2X4 junos:24.4R2 junos:25.2R1-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Port Mirroring feature on express PFE
1916382
Minor
Network packets on the self-mirrored file shows the same timestamp on every packet with self-mirroring function enabled
Product-Group=evo
On all Junos Evolved platforms, with On-device packet capture or self-mirroring function enabled, the copied packets into the PCAP (Packet Capture) file shows the same timestamps for every packet. This issue has no service impact.

Resolved In: evo:25.2R2-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: ACX7348 PTP Timing
1775585
Major
[Clocking Solution]:ACX7348:PTP and SyncE not working properly after RE switch over
Product-Group=evo
In Re switchover case, there is sxe ifl mapping with front end port in filters not going as expected . Due to this , the interface associated with slave port sends announce/sync captured from adjacent router mx480 . this behaviour not seen if I deactivate all other master ports in the router. This is evident that filter mapping are going incorrect after the RE switchover .

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO evo:24.3R1-EVO
PR NumberSynopsisCategory: ACX7509 Linecard (FPC) related issues
1791632
Major
"BrcmPlusPfe: Phy Time Clear Config Set Failed. Invalid configuration" error seen with evo-pfemand restart
Product-Group=evo
On Junos Evolved platforms, "[Error] BrcmPlusPfe: Phy Time Clear Config Set Failed. Invalid configuration" error is seen with evo-pfemand restart.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO
PR NumberSynopsisCategory: Layer 2 Circuit issues
1863228
Major
IFL configured on the LAG interface goes down when the VLAN operation is changed
Product-Group=evo
On all Junos OS and Junos OS Evolved platforms, when EVPN is configured with the 'df-election-granularity per-esi' feature, any change in VLAN operation causes the IFL (logical interface) configured on the LAG (Link Aggregation Group) interface to go down, impacting all services associated with that interface.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S1-J15 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1793598
Critical
Multicast Traffic loss (20s - 30s) is seen during the reconvergence after link flap
Product-Group=evo
On Junos and Junos Evolved platforms, When device is configured with MoFRR(Multicast-Only Fast Reroute) and PIM(Protocol Independent Multicast) and also when the upstream links to the source of the multicast traffic flow is made down and then up . Traffic loss is seen for around 20 to 30 seconds until the link comes up.

Resolved In: evo:21.4X6-J1-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-S2-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.4R3-S5-J7 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: QFX5K EVO MACSec
1903384
Major
QFX5700:MACsec traffic loss might occur on specific traffic streams inspite of successful SAK rekeying and MACsec session establishment
Product-Group=evo
QFX5700:MACsec traffic loss might occur on specific traffic streams inspite of successful SAK rekeying and MACsec session establishment

Resolved In:
PR NumberSynopsisCategory: PTX10K specific platform PRs
1749781
Minor
The Switch Interface Board (SIB) PWR and STAT LEDs will be unlit on PTX10K4/8/16 EVO platforms
Product-Group=evo
On Junos OS Evolved PTX10004/PTX10008/PTX10016 platforms with dual Routing Engines, the Switch Interface Board (SIB) PWR and STAT LEDs will be unlit state after an RE Switchover. This will not have any functional impact.

Resolved In: evo:21.4R3-S6-EVO junos:24.1R1
1900735
Major
Evo PTX PFE instance stuck in fault state after restart
Product-Group=evo
One or more PFEs may transition to fault state if multiple PFEs are restarted rapidly.

Resolved In: evo:23.4R2-S7-EVO evo:24.4R2-S1-EVO evo:24.4X200-D20-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4X200-D20-JUNOS-TO-EVO-HELPER junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Issues related to control plane security
1860970
Minor
SIB HA wait timeout error upon graceful RE switchover
Product-Group=evo
SSH issue from the Routing Engine to the FPC causes SIB HA timeout error upon RE switchover. All the SIBs will be reset as a result of that.

Resolved In:
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=evo
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1899597
Major
Getting validation error for get-interface-information rpc execution through ODL controller
Product-Group=evo
Getting validation error for get-interface-information rpc execution through ODL controller

Resolved In:
PR NumberSynopsisCategory: Issues related to NETCONF
1792554
Minor
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241
Product-Group=evo
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241

Resolved In:
PR NumberSynopsisCategory: Virtual Private LAN Services
1806424
Major
The snmp mib walk on jnxVplsPwBindTable fails with vpls routing-instances having multiple mesh-groups
Product-Group=evo
If VPLS mesh-groups are configured with different neighbours having different vpls-id the SNMP mib walk over jnxVplsPwBindTable might fail with the error Request failed: OID not increasing. No functional impact is seen due to this issue.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S8 junos:24.4R2 junos:25.1R1 junos:25.2R1

 

Modification History

First publication 2026-02-17