Alert Type

SRN - Software Release Notification
Low/NotificationSRN
Low/NotificationSRN

Product Affected

ACX EX MX NFX QFX SRX vSRX

Alert Description

Junos Software Service Release version 25.4R1-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 25.4R1-S2 is now available.

25.4R1-S2 - List of Fixed issues

PR NumberSynopsisCategory: "agentd" software daemon
1929823
Major
The sysd process crashes with error logs upon exceeding its memory limit
Product-Group=junos
Severity=Major
On Junos OS Evolved platforms with telemetry streaming configured, the sysd (System Daemon) process crashes on the backup RE (Routing Engine), and error logs are observed when sysd memory usage continues to grow over time, and the memory limit is exceeded. This issue is observed when the 64-bit sysd consumes more memory than the configured system limit when the device has been running for a long time (typically more than 100 days) in the dual RE scenario.
PR NumberSynopsisCategory: BBE routing
1922536
Major
Forwarding issues for an access DHCPv6-PD or access-internal DHCPv6-IA route or both may be seen on LNS due to an incorrect route programming of such route on PFE
Product-Group=junos
Severity=Major
Drop of traffic to subscriber DHCPv6 prefixes may be observed on LNS (L2TP network server) if CPE uses IPv6 address obtained via NDRA process as the source address for DHCPv6 negotiation instead of link-local address.
PR NumberSynopsisCategory: Border Gateway Protocol
1926835
Minor
AS path loop may not be detected with VPN route when autonomous-system independent-domain is configured with 'no-attrset' option
Product-Group=junos
Severity=Minor
AS path loop may not be detected with VPN route when autonomous-system independent-domain is configured with 'no-attrset' option under routing-options hierarchy
PR NumberSynopsisCategory: MX304 PSM issuues
1923135
Major
On MX304 platform repetitive logic fault alarm on both PEMs observed
Product-Group=junosvae
Severity=Major
On MX304 platforms, PEM Logic Fault alarms may intermittently appear due to I2C transaction timing limitations. PEMs require a delay between backtoback transactions; without this delay, alarms can be raised randomly on either PEM.
PR NumberSynopsisCategory: MX Platform SW - Power Management
1924872
Major
SFB-Redundant mode not applied after reboot when "event-options event-script file" is configured
Product-Group=junos
Severity=Major
On Junos MX2020 platforms with SFB3, when event script is configured on the device, the platform does not correctly apply the SFB power-redundant-mode configs (set chassis power sfb-redundant-mode) during a full chassis reboot, affecting the chassis resiliency.
PR NumberSynopsisCategory: Class of Service
1928420
Minor
Incorrect COS scheduler-map gets attached to an AE IFL after GRES or 'cosd' process restart
Product-Group=junos
Severity=Minor
On all Junos MX platforms with line cards (MPC1-11, MS-MPC, LC2101, LC2103, LC480, LC4800, LC4802, LC9600, JNP304-LMIC), when a scheduler-map is attached to an AE (Aggregated Ethernet) IFL (Logical Interface) directly or by 'traffic-control-profile' and when this AE is in 'replicate' mode, upon GRES (Graceful Routing Engine Switchover) or on 'cosd' process restart operation, configured scheduler-map gets removed from this AE IFL and a default (Incorrect) scheduler-map gets attached to it. This causes change in the traffic flow pattern via the COS (Class of Service) queues of the AE IFL and can impact service.
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1921796
Minor
Traffic dropped after priority change in VRRP with EVPN-VxLAN scenario
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, in Virtual Router Redundancy Protocol (VRRP) with Ethernet Virtual Private Network - Virtual Extensible Local Area Network (EVPN-VXLAN) scenario, when VRRP priority is changed, the VRRP virtual Media Access Control (MAC) address can remain pinned as a static entry on the remote device. As a result, MAC movement does not occur correctly, and VRRP packets are dropped on the leaf device. This impacts VRRP operation after priority changes.
PR NumberSynopsisCategory: OpenSSH and related subsystems
1922002
Major
Major alarms showing SPMB1 not online on MX2008 will be seen on 24.2R1 and later releases
Product-Group=junos
Severity=Major
On the Junos MX2008 VMhost platform with dual Routing Engines (REs), the backup SPMB {Switch Processor Mezzanine Board} (spmb1) fails to come online following a graceful switchover on releases starting when upgrading to releases starting from Junos 24.1. As a result, if the backup SPMB cannot boot, the traffic will be impacted during switchovers.
PR NumberSynopsisCategory: 1G/10G LC Timing software
1908234
Major
The time error performance degrades when PTP is configured with large number of master streams
Product-Group=junos
Severity=Major
On MX 10000 platforms, when PTP is configured with a large number of master streams (128 or 256), the time error performance degrades.
PR NumberSynopsisCategory: EVO Class of Services
1858634
Critical
Telemetry subscription to path /qos/interfaces/interface/output/ queues/queue/state/transmit-pkts showing incorrect result
Product-Group=junos
Severity=Critical
Telemetry subscription to path /qos/interfaces/interface/output/queues/queue/state/transmit-pkts showing incorrect result
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1906880
Major
Committing a scaled config may take time which can make other sessions appear hung.
Product-Group=junos
Severity=Major
When using ?load override?, committing a scaled configuration (on top of an already committed scaled config) may take longer to complete. During this time, other sessions cannot enter configure mode, which can make those sessions appear hung. It is advised to use 'load update' instead of 'load override' to load the configuration before committing.
PR NumberSynopsisCategory: EX interfaces issues
1904884
Critical
VCP link flap due to SYSPLD read failures
Product-Group=junos
Severity=Critical
On EX4100 platform VCP link flap due to SYSPLD read failures and mark SFP as unplugged
PR NumberSynopsisCategory: EX POE
1930080
Major
PoE outage observed on EX4400 in a rare scenario
Product-Group=junos
Severity=Major
On EX4400 platforms, loss of PoE (Power over Ethernet) power is seen on ports after port bounce or even during normal operation without specific external trigger . This causes outage on all PoE ports and devices connected to PoE port will not receive power causing service impact.
PR NumberSynopsisCategory: EX Entry Level Access VC platform
1919727
Minor
The dcpfe process crashes repeatedly with continuous error logs 'smb_transfer: SMBus ioctl failed'
Product-Group=junos
Severity=Minor
On EX4400 platforms, due to an internal communication issue within the CPU controller, the system triggers repeated fxpc panics which in turn lead to the dcpfe process (Dataplane Packet Forwarding Engine) to crash and restart continuously, resulting in service disruption.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1928462
Major
FPC crash occurs after configuration changes are made to a service-filter on specific MX platforms
Product-Group=junos
Severity=Major
FPC crash and aftd-trio core-dump will be observed on MX platforms supporting MPC10E, MPC11E, LC9600 line cards, and MX304 after configuration changes were made to a service-filter which was in use by BBE subscribers.
PR NumberSynopsisCategory: SRX power-mode (PMI/PME)
1858490
Major
flowd crashes due to a timing issue during IPsec SA re-keying on certain SRX platforms
Product-Group=junos
Severity=Major
On certain SRX platforms, the flowd process crash is observed during Internet Protocol Security (IPsec) Security Association (SA) re-keying. This occurs due to an internal timing issue, leading to IPsec tunnel establishment failure, traffic loss during re-key events, and traffic switchover.
PR NumberSynopsisCategory: Firewall Network Address Translation
1933239
Critical
The FPC restarts on SRX series platforms when session-persistence-scan is configured
Product-Group=junos
Severity=Critical
On Junos OS SRX Series platforms with 'session-persistence-scan' and NAT46 or NAT64 configured, modification to source Network Address Translation (NAT) rule will cause Flexible PIC Concentrators (FPCs) to restart when there is live IPv6 traffic. This will cause all traffic to be dropped and cause service disruption.
PR NumberSynopsisCategory: Layer 2 Control Module
1930380
Major
The hash collision for storm control profile indices will result in an l2ald process crash
Product-Group=junos
Severity=Major
On all Junos OS platforms and Junos OS Evolved platforms which supports storm control, when a different storm-control profile is applied for interface where these profile have same profile index allocated then the storm control profile configuration and system state will not be in sync and a different profile will be applied for interface binding due to profile index collision which results into l2ald process crash.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1912050
Minor
Broadcast and Multicast traffic is dropped in MH EVPN MPLS topology where Egress Link Protection is enabled on the PEs and restart l2-learning is executed
Product-Group=junos
Severity=Minor
On all Junos platform in MH (Multi homed) EVPN (Ethernet Virtual Private Network) MPLS (Multi Protocol Label Switching) topology where Egress Link Protection feature is enabled on the PEs (Provider Edge) routers and the PE - CE (Customer Edge) link is disabled on the one of the MH PEs and 'restart l2-learning' command is executed on another MH PE, this results in broadcast and Multicast traffic drop.
1928530
Critical
A buffer overflow during IPv6 NDP operations in an EVPN environment caused segmentation faults leading to FPC crash files and repeated reboots
Product-Group=junos
Severity=Critical
On JunOS MX240/MX480/MX960/MX2008/MX2010/MX2020 platforms with MPC10E/MPC11E line cards as well as the MX304 platform, an issue in IPv6 EVPN (Ethernet Virtual Private Network) during NDP (Neighbor Discovery Protocol) resolicitation of a link local target address causes the system to use the IRB link local address in outgoing packets. Stack corruption happens when handling the IRB link local address and resulting in continuous FPC (Flexible PIC Concentrator) reboots (around 3 or 4 times) and crash files generation.
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1914499
Major
MACsec session not coming up after multiple reboot of VC member or VC link flaps
Product-Group=junos
Severity=Major
On Junos OS EX series Virtual Chassis platforms, the MACsec interface fails to re-establish sessions after multiple reboots of a particular Virtual Chassis (VC) member or when a VC link flaps. This issue is observed between 4/5 reboots of the VC member. In these case, the MACsec daemon is not notified that the license is installed on the member, resulting in MACsec encryption being unavailable on that interface.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1921529
Minor
License Feature used is shown 0 for MACSec Bandwidth Usage (in gbps) although MACSec license is installed and used
Product-Group=junos
Severity=Minor
License Feature used is shown 0 for MACSec Bandwidth Usage (in gbps), although MACSec license is installed and used.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1932893
Major
vmhost upgrade may fail due to 'Validation failed' when upgrading to freebsd15 based Junos from older releases.
Product-Group=junos
Severity=Major
vmhost upgrade may fail due to 'Validation failed' when upgrading to freebsd15 based Junos from older releases. This does not apply to Junos-EVO.
PR NumberSynopsisCategory: Protocol Independant Multicast
PR NumberSynopsisCategory: L2NG PVLAN feature
1916610
Minor
Primary VLAN mapping causes MAC learning failure on PVLAN inner port
Product-Group=junos
Severity=Minor
On EX2300 platform, A Private VLAN (PVLAN) issue occurs where Media Access Control (MAC) learning works correctly for Isolated and Community Virtual Local Area Network (VLAN) access ports, but when the Primary VLAN is assigned to an inner VLAN port, the switch stops forwarding traffic and no Media Access Control addresses are learned after committing the configuration. This issue impacts services on interfaces configured with PVLAN.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1925996
Major
Intermittent uplink ports flaps events observed and syspld read failures on syslog messages were seen.
Product-Group=junos
Severity=Major
Intermittent uplink ports flaps events observed and log messages show continuous syspld read failures during the issue. After a power cycle, the devices recovered.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1933698
Major
PFE crash due to memory corruption in EVPN-VxLAN type5 overlay ECMP at high tunnel next hop scale
Product-Group=junosvae
Severity=Major
On Junos QFX5110, QFX5120, EX4650, EX4400, EX4100, and EX5200 platforms, when operating with EVPN-VxLAN type5 overlay ECMP at high tunnel next hop scale, the Packet Forwarding Engine (PFE) crash when a memory corruption issue is observed due to a buffer overflow that leads to corruption of heap management structures. This corrupted metadata is detected by the memory manager when later heap allocation or free operations are invoked, resulting in a reported heap corruption condition.
PR NumberSynopsisCategory: SW PRs for SCBE3 fabric
1911536
Minor
Ungraceful removal of SCB causes traffic loss
Product-Group=junos
Severity=Minor
On Junos OS, MX Series (MX240, MX480, MX960) devices that use a Switch Control Board (SCB), forwarding traffic may be interrupted for approximately one minute if an SCB is physically removed without first powering it off. The control plane remains operational, but forwarding is impacted until fabric manager and forwarding services selfrecover.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1934419
Major
Unexpected throughput reduction seen on AE bundle and physical interface when interface filter and policer are applied together
Product-Group=junos
Severity=Major
The issue is seen on all MX platforms with MPC10/MPC11/LC4800/LC9600 linecards and MX304, when the output filter and interface policer is applied to the egress AE (aggregated ethernet) and physical interface in the output direction and the interface policer runs first then the output filter. This kind of an incorrect policing issue leads to the exhaustion of the policer bandwidth and throughput reduction will be seen.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1922876
Major
Traffic loss observed, after device upgrade
Product-Group=junos
Severity=Major
On all Junos platforms that use the NodeSlice architecture like MPC10 and MPC11 FPCs, the issue involves traffic loss, specifically for traffic flowing from R2(Router 2) to R1 (Router 1), while traffic from R1 to R2 flows without issues. Due to this multicast traffic over EVPN(Ethernet Virtual Private Network) MPLS(Multiprotocol Label Switching) maybe blackholed.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1927194
Major
When a resolution for an IPv4/IPv6 address fails, NH IFL is throttled causing service impact
Product-Group=junos
Severity=Major
In MX uKern and AFT based cards, NH IFL throttling will be seen when resolution for an destination IPv4/IPv6 address fails.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1926050
Major
The auditd process crashes when the Radius server is configured but unreachable
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved having the Radius (Remote Authentication Dial-In User Service) server with accounting configured, the auditd crash is observed if the Radius server is unreachable for a long time and a large number of accounting records accumulate, which leads to memory exhaustion during accounting processing and results in a process crash.
PR NumberSynopsisCategory: Configuration management, ffp, load action
1860340
Critical
Junos OS and Junos OS Evolved: The Annotate configuration command can be used to change the configuration (CVE-2025-52989)
Product-Group=junos
Severity=Critical
An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. Please refer to https://supportportal.juniper.net/JSA100096 [juniper.net] for more information.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1902358
Minor
RPC crash when non-ASCII character is included in XML data result
Product-Group=junos
Severity=Minor
RPC calls fail when non-ASCII characters (i.e. UTF-8 encoded characters) are included in XML data results.
PR NumberSynopsisCategory: content filtering bugs
1927484
Critical
Traffic loss occurs due to high memory utilisation in UTM pools
Product-Group=junos
Severity=Critical
On Junos OS SRX platforms, configuring cache preload in web filtering causes high memory utilization in the UTM (Unified Threat Management) pool, which results in traffic loss.

 


 

25.4R1-S2 - List of Known issues

PR NumberSynopsisCategory: "agentd" software daemon
1913260
Major
Discrepancy noticed in the interfaces when there is a reset in Linecard or PFE
Product-Group=junos
On all Junos and Junos Evolved platforms, with an established telemetry session with multiple collectors, there will be interface statistics discrepancy when there is a linecard OIR event or PFE offline/online sequence.

Resolved In: evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:26.1R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.4R2 junos:26.1R1 junos:26.2R1
1923848
Major
Junos Evolved platfrom, when gNMI collecting data from "optics/lanediags/lane/ lane_laser_receiver_power_dbm" and "optics/lanediags/lane/ lane_laser_output_power_dbm" are unreadable
Product-Group=junos
The JavaScript Object Notation (JSON) encoding of leafs of type "ieeefloat32" is not correct, causing gRPC Network Management Interface (gNMI) data outputs unreadable.

Resolved In: evo:24.4R2-S4-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: MX304 Routing Engine issues
1913540
Minor
[MX304] Certain 'cat' commands within the 'show vmhost support-info' command in RSI try to access files that are not present on the MX304, causing error messages to appear.
Product-Group=junos
As part of the RSI process, the command "show vmhost support-info" is executed, which comprehensively collects vmhost logs using various cat commands. Some of these commands attempt to access files that do not exist on the MX304, leading to the display of error messages.

Resolved In: junos:24.2R2-S5 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: L2NG Access Security feature
1911142
Major
Client IP assignment failure observed on EX4300 due to DHCPv6 snooping validation issue
Product-Group=junos
On EX4300, DHCPv6 ( Dynamic Host Configuration Protocol for IPv6 ) clients will fail to receive IP addresses due to improper client entry handling when DHCPv6 snooping is enabled.

Resolved In: junos:21.4R3-S12
PR NumberSynopsisCategory: OpenSSL and related subsystems
1939872
Major
xnm-ssl: TLS connection fails with RSA cert and key size of 1024
Product-Group=junos
Starting with stunnel version 5.75, the application operates with OpenSSL Security Level 2 by default when linked with OpenSSL versions that enforce modern security policies. At Security Level 2, OpenSSL requires a minimum RSA key size of 2048 bits. As a result, certificates using RSA 1024-bit keys are no longer accepted. If a service is configured with a certificate using a 1024-bit RSA key, stunnel will fail to load the certificate and the service may fail to start, typically producing an error similar to: SSL_CTX_use_certificate: ee key too small. Impact Systems using 1024-bit RSA certificates for TLS authentication with stunnel may experience service startup failures or TLS handshake failures after upgrading to stunnel 5.75. Recommended Action It is recommended to replace existing 1024-bit RSA certificates with certificates using RSA 2048-bit or stronger keys to comply with modern cryptographic security standards.

Resolved In:
PR NumberSynopsisCategory: JNU issues in CSDS solution
1906055
Major
mgd core is seen after upgrading the Dual MX setup (mx304) in a JNU CSDS topology
Product-Group=junos
mgd core is seen after upgrading the Dual MX setup (mx304) in a JNU CSDS topology. When the user is in the controller's config mode, after the satellite is upgraded and rejoins the controller, the satellite will send its new schema, which is merged with the controller's schema. As part of that, the new controller merged schema would be created. Also, the satellite would be remapped to use the new version of the schema to which the satellite is upgraded.

Resolved In:
PR NumberSynopsisCategory: DNX VPLS
1911208
Major
VPLS drop seen post Clear OSPF Neighbors .
Product-Group=junos
Traffic drop seen in VPLS stream post "clear ospf neighbor" command.

Resolved In: junos:23.2R2-S7 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: JUNOS Dynamic Profile Configuration Infrastructure
1930036
Major
High memory usage is showing, when we configure unsupported licensing feature
Product-Group=junos
On all Junos EX and QFX platforms operating in an EVPN (Ethernet Virtual Private Network) environment, this issue occurs when the CLI command 'licensing hourly update' is executed on a device that does not support the licensing feature.

Resolved In: evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R1-S2-J4 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1926818
Major
ARP resolution failure for /32 static host routes via IRB in EVPN virtual-switch routing instances
Product-Group=junos
On all Junos and Junos Evolved platforms that support EVPN (Ethernet VPN) virtual-switch routing instances, ARP (Address Resolution Protocol) resolution fails for static host routes configured with a /32 mask when the next-hop interface is an IRB (Integrated Routing and Bridging) interface and the destination host resides in a different subnet. As a result, ARP entries are not installed, MAC (Media Access Control) addresses of destination hosts are not learned, and traffic destined to those hosts becomes unreachable, causing service impact.

Resolved In: evo:23.4R2-S8-EVO evo:24.2R2-S4-EVO evo:25.2R2-S1-EVO evo:25.4R1-S1-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: EX4100 RE, Platform Infra, Drivers
1942521
Major
request system firmware upgrade jfirmware allfw only upgrading CPLD not upgrading Uboot
Product-Group=junos
request system firmware upgrade jfirmware allfw only upgrading CPLD not upgrading Uboot

Resolved In:
PR NumberSynopsisCategory: EX interfaces issues
1870962
Major
The CPU high utilization is observed after PIC offline/online
Product-Group=junos
On EX4400 platforms with 4x25G or 1x100G ULM (Universal Link Module), the CPU hogs by CMQFX thread for as much as 3.7 secs when Firmware download occurs during PIC offline/online and PFE restart time / Device reboot. To speed up the firmware download operation, the MDIO clock (MDC) frequency is increased from 2.6 MHz to 9 MHz which reduced firmware download time from ~3.8 s to ~2.2 s. This is an enhancement PR.

Resolved In: junos:26.2R1
PR NumberSynopsisCategory: EX POE
1930080
Major
PoE outage observed on EX4400 in a rare scenario
Product-Group=junosvae
On EX4400 platforms, loss of PoE (Power over Ethernet) power is seen on ports after port bounce or even during normal operation without specific external trigger . This causes outage on all PoE ports and devices connected to PoE port will not receive power causing service impact.

Resolved In: evo:26.2R1-EVO evo:26.3R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1933452
Major
ICMP ping with higher MTU size fails in VPLS when IRB MTU exceeds MPLS core MTU
Product-Group=junos
On all Junos OS platforms, configured with VPLS (Virtual Private LAN Service) and IRB (Integrated Routing and Bridging ) interfaces, when the MTU (Maximum Transmission Unit) configured on the IRB or CE interface is larger than the MPLS ( Multiprotocol Label Switching ) core interface MTU (including MPLS label overhead), ICMP Echo Request (ping) packets with higher packet sizes fail.

Resolved In: junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: jdhcpd daemon
1939685
Minor
Insert command not working for "dhcp-local-server group" hierarchy
Product-Group=junos
Insert command not working for "dhcp-local-server group" hierarchy, below error is seen: user@host# insert system services dhcp-local-server group servers-1 after syntax error, expecting `after' or `before'. user@host# insert system services dhcp-local-server group servers-1 bef syntax error, expecting `after' or `before'.

Resolved In: evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:25.2R2-S1-EVO evo:26.2R1-EVO evo:26.3R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:25.2R2-S1 junos:26.2R1
PR NumberSynopsisCategory: Firewall Policy
1939433
Major
Flow sessions not synchronizing from primary to backup in SRX High Availability clusters
Product-Group=junos
On SRX devices operating in a High Availability cluster with logical-systems enabled, the backup node may display fewer flow sessions than the primary node due to incomplete flow session synchronization. Sessions that do not synchronize to the backup node are lost during a failover, resulting in service interruption for the affected flows.

Resolved In: junos:23.4R2-S7-J9 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Security platform jweb support
1931780
Major
The Captive Web Authentication might not be completed on specific Junos versions for EX Series switch
Product-Group=junos
When a MAC-RADIUS authentication succeeds and the RADIUS server returns CWA redirect attributes (URL-Redirect), the EX switch should intercept client HTTP traffic and return an HTTP 302 redirect to the Captive Portal. The switch instead responded with HTTP 405 (Method Not Allowed), causing the client to bypass the CWA redirect workflow.

Resolved In: evo:25.4R2-EVO evo:26.2R1-EVO junos:23.2R2-S7 junos:23.4R2-S8 junos:24.4R2-S4 junos:25.2R2 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Layer 2 Control Module
1938991
Minor
VSTP bridge-priority configuration not taking effect for VLAN group
Product-Group=junos
The VSTP (VLAN Spanning Tree Protocol) bridge-priority configuration does not apply to VLAN (Virtual LAN) groups as expected. This issue results in VLAN groups not reflecting the intended bridge priority. This configuration issue can affect the network's root bridge election process, causing potential inconsistencies in network behavior and performance.

Resolved In: evo:26.1R1-EVO evo:26.2R1-EVO evo:26.3R1-EVO junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1932925
Critical
MACsec traffic encryption/decryption failure post SFP OIR with interface and session in up state
Product-Group=junos
On MX301 platform, After SFP (Small Form-factor Pluggable transceiver) Online Insertion and Removal (OIR) on a MACsec (Media Access Control Security) enabled interface, the link and MACsec session remain UP, but MACsec encryption and decryption stop functioning. This results in traffic loss and causes service impact.

Resolved In:
PR NumberSynopsisCategory: Multiprotocol Label Switching
1923867
Minor
The rpd process crash is observed after a graceful restart in the RSVP-TE scenario
Product-Group=junos
On Junos OS and Junos OS Evolved platforms with Graceful Restart and RSVP-TE (Resource Reservation Protocol - Traffic Engineering) configured, an rpd crash is observed, leading to traffic impact after a Graceful Restart if a PVC (Permanent Virtual Circuit) fails to allocate correctly during this recovery process, leaving it in an incomplete or unallocated state, and the system attempts to clean up or remove this unallocated PVC.

Resolved In: evo:24.4R2-S4-EVO evo:25.2R2-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.4R2-S1-C1 junos:24.4R2-S1-J8 junos:24.4R2-S3 junos:25.2R2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1908581
Major
Significant multicast traffic loss observed during ISSU in Next-Generation Multicast VPN (NGMVPN) deployments
Product-Group=junos
On all Junos platforms that support both InService Software Upgrade (ISSU) and NextGeneration Multicast VPN (NGMVPN), multicast traffic loss can occur during an ISSU operation when NGMVPN deployments use both the Inclusive Provider Multicast Service Interface (IPMSI) and the Selective Provider Multicast Service Interface (SPMSI) with a nonzero threshold. During the ISSU process, Flexible PIC Concentrators (FPCs) upgrade and synchronize, and multicast statistics may briefly report zero. This event causes withdrawal of the SPMSI and a fallback to the IPMSI. If the IPMSI next hops are not fully programmed at that moment, a temporary interruption of SPMSI flows occurs, while IPMSI flows continue forwarding normally. The traffic loss duration is short and typically limited to a few seconds to a few minutes during FPC upgrade cycles, not exceeding the expected ISSU convergence window. Both IPv4 and IPv6 multicast traffic are affected.

Resolved In: evo:26.2R1-EVO junos:26.2R1
PR NumberSynopsisCategory: NGPE Chassis platform
1932385
Major
The license add using 'terminal' option fails in a controller setup
Product-Group=junos
On Junos MX304 and MX10K platforms, the 'terminal' option is not supported in controller satellite setup along with device-list option since terminal is local to controller and cannot be used to install license in satellite. The user can use the 'file' option and the file needs to be copied to the device and later user can use the same command with the file option to add the license.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:25.4R1-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1918590
Minor
On MX301, IGMP may not get enabled by default when PIM is enabled
Product-Group=junos
On MX301, IGMP may not get enabled by default when PIM is enabled. Use "set protocols igmp interface" to explicitly enable IGMP

Resolved In:
PR NumberSynopsisCategory: Issues related to PKI daemon
1919729
Major
SRX4300 and SRX1600 Enter System Halt or Amnesiac State After Reboot When TPM/MEK is Enabled
Product-Group=junos
On SRX4300 and SRX 1600 platforms When Master password and Master Encryption Key is set on the device and rebooted , the system was getting into amnesiac state.

Resolved In: junos:24.2R2-S5 junos:24.4R2-S4 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1931633
Major
PFE crash due to memory corruption when STP is enabled
Product-Group=junos
On all Junos Platforms, a rare memory corruption condition may occur in the Packet Forwarding Engine (PFE) when Spanning Tree Protocol (STP) is enabled and operating in default (distributed) mode. When the issue is triggered, the PFE crashes and a dc-pfe core file is generated. The exact trigger for the memory corruption is currently unknown.

Resolved In: evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.2R2-S1-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX access control list
1936556
Major
Removal of the flexible-match-range from CLI, as it is not supported
Product-Group=junosvae
On Junos QFX5100, QFX5200, and QFX5210, the unsupported knob "flexible-match-range" under "ethernet-switching"is hidden from the CLI.

Resolved In: junos:25.4R2 junos:26.2R1
1940595
Major
UDF filter is not working with user-vlan-id
Product-Group=junosvae
On Junos QFX5200 platform, traffic counting is lost when user-vlan-id and flex-offset-mask are used together in the same term of an Ethernet-switching firewall filter.

Resolved In: junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX L2 PFE
1938291
Major
Deactivating sub-interfaces on flexible ethernet ports leads to VLAN traffic loss
Product-Group=junos
On Junos platforms having QFX and EX, VLAN(Virtual Local Area Network) traffic loss occur on interfaces configured with flexible-vlan-tagging when an L3 (SP style) sub-interface is deactivated on a port that also carries L2 (enterprise style) VLAN units.

Resolved In: junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1905607
Major
Hardware MTU stuck at default value, causing packet drops on VXLAN Interfaces
Product-Group=junos
On QFX5K and EX4K platforms which are running Junos release, when new VxLAN (Virtual Extensible LAN) vlans with IRBs (Integrated Routing & Bridging) are added, the L3 (Layer 3) interface values overwrite the MTU (Maximum Transmission Unit) entries previously programmed for non-VxLAN vlans that use the same hardware token internally. The VxLAN L3 interface is created with default MTU (1514) because L3 interface MTU value is still 1514 as it is not update by RE (Routing Engine).

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1877194
Major
Traffic drop is seen in a scaled scenario on certain EX platforms
Product-Group=junosvae
On Junos EX4400, EX4400-24T, EX4400-24X, EX4400-48T, EX4400-48F, EX4400-24MP, EX4400-48MP, EX4300-MP platforms, it is observed that in a scaled scenario with more than three thousand next hops configured, further next hop installation fails which in turn causes routes to fail leading to traffic drop.

Resolved In: junos:23.2R2-S7 junos:23.2R2-S8 junos:23.2R2-S9 junos:23.4R2-S10 junos:23.4R2-S11 junos:23.4R2-S8 junos:23.4R2-S9 junos:24.2R2-S4 junos:24.2R2-S5 junos:24.2R2-S7 junos:24.2R2-S8 junos:24.4R2-S4 junos:24.4R2-S5 junos:24.4R2-S6 junos:24.4R2-S7 junos:25.2R1 junos:25.3R1
1939298
Major
Traffic drop is seen due to tagged IRB L3 interface with native-vlan and vlan members
Product-Group=junos
On all Junos OS QFX5K and EX4k platforms, configuring a native VLAN along with VLAN members on an underlay Integrated Routing and Bridging (IRB) Network-to-Network Interface (NNI) that carries VxLAN (Virtual Extensible LAN) traffic results in the VLAN tag not being stripped as expected. Instead of treating the native VLAN traffic as untagged, the interface adds the VLAN tag, leading to packet drops at the remote end.

Resolved In: junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1938876
Major
Incorrect interface mode leading to 100G Link Flaps on QFX5210-64C
Product-Group=junos
On Junos OS QFX5210-64C platform, 100G optics inherently operate in CAUI-4 (Chip-to-Module 100 Gb/s Four-Lane Attachment Unit Interface) mode, which is automatically selected by the system and not user-configurable; mismatches due to software versions leading to link instability or flapping.

Resolved In: junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1931875
Major
The L2Circuit traffic which are resolving over BGP-LU get drop when 'chained-composite-next-hop' for BGP-LU and 'preserve-nexthop-hierarchy' is configured
Product-Group=junos
On all Junos and Junos Evolved platforms supporting 'chained-composite-next-hop' for BGP-LU (Border Gateway Protocol - Labeled Unicast), when having L2Circuit (Layer 2 Circuit) links configured, with indirect next-hop resolving on BGP-LU prefix, if 'chained-composite-next-hop' enabled for BGP-LU and with 'preserve-nexthop-hierarchy' configured, L2Circuit traffic will get dropped due to failure in installing the forwarding next-hop with labels for L2Circuit service.

Resolved In: evo:24.2R2-S5-EVO evo:25.2R2-S1-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Segment routing traffic Engineering
1927655
Major
BGP-LS advertises the default Instance Identifier instead of the configured value
Product-Group=junos
On routers running Junos OS 24.4 and later, including Junos Evolved, when the Traffic Engineering database import identifier is configured using "set protocols mpls traffic-engineering database import identifier ", the Border Gateway Protocol Link State advertisements in the "lsdist.0" table continue to use Instance Identifier 0 instead of the configured value. This results in BGP-LS exporting an incorrect Instance Identifier toward the route reflector or controllers, displaying mismatched or incorrect instance IDs for what should be a single shared topology. No traffic impact, but controlplane information is inaccurate.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1907722
Major
MX/EX92K PFE3 YT Chip Errors Seen During EVPN SLM Multicast Traffic
Product-Group=junos
PFE error messages are observed on MX304 and EX92K when certain kind of L3 unicast and L3 multicast traffic are transmitted

Resolved In: evo:25.4R2-EVO evo:26.2R1-EVO evo:26.3R1-EVO junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:19.2R3-S12 junos:19.2R3-S13 junos:19.3R3-S13 junos:21.2R3-S11 junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: VSRX platform software
1922165
Major
ED25519 ssh key now supported from AWS and GCP upon vSRX 3.0 instance creation
Product-Group=junos
Starting in 25.4R2, customers can use ed25519 ssh keys from either the web console or CLI of AWS and GCP as well as rsa ssh keys when selecting an SSH key to be able to log into the system with at launch. Configuring the keys through cloud-init config was already supported.

Resolved In: junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1614358
Major
21.3R1:USF-NAT: Duplicate syslog messages are displayed for V4 and v6 session close after Configure NAT Services with 2 Service sets (next-hop style) one for NAPT44 and another for NAPT64.
Product-Group=junos
In some NAPT44 and NAT64 scenarios, Duplicate SESSION_CLOSE Syslog will be seen.

Resolved In:
1925039
Major
Memory leak in ipv4-to-ipv6 session reuse trigger flowd crash
Product-Group=junos
On Junos OS MX240/MX480/MX960 platforms with MX-SPC3 cards, the flowd process crash and reboots the service PIC when a stale IPv4 session is mistakenly reused for IPv6 due to a memory issue. During process restart the services remain down, session information is briefly lost and active traffic will drop, however the system recovers automatically.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1