Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification (SRN)

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Alert Description

Junos Software Service Release version 23.4R2-S8 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review.

Solution

Junos Software service Release version 23.4R2-S8 is now available.

23.4R2-S8 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 Platform implementation
1928087
Minor
The "set chassis config-button no-clear" command not available
Product-Group=junosvae
Severity=Minor
On Junos OS EX4300-48MP platform, the command "set chassis config-button no-clear" is missing.
PR NumberSynopsisCategory: NFX Series Platform Software
1903544
Major
QCOW2 images larger than 4GB cause VNF boot failures
Product-Group=junosvae
Severity=Major
On Junos NFX150, NFX250, and NFX350 network services platforms, Virtual Network Functions (VNFs) fail to boot after upgrading to Junos OS 23.4 or later versions as the QEMU Copy-On-Write version 2 (QCOW2) image size exceeds 4GB.
PR NumberSynopsisCategory: SPC3 HW and SW Issues
1922949
Critical
Executing unsupported pfe cli triggers chassis reset on srx5000 series
Product-Group=junos
Severity=Critical
On Junos SRX5000 series platforms with Services Processing Card 3 (SPC3), executing the unsupported operational command "show pfe statistics dma" causes loss of communication between the Packet Forwarding Engine (PFE) and the Routing Engine (RE), triggering a system-wide Flexible PIC Concentrator reset and resulting in a complete traffic outage.
PR NumberSynopsisCategory: SRX Fleming Platforms related issues
1927758
Critical
HA failover not triggered after PFE process crash in HA deployments (Chassis Cluster / MNHA) on SRX1600/2300/4300/4700
Product-Group=junosvae
Severity=Critical
On SRX1600/2300/4300/4700 platforms configured in HA mode (Chassis Cluster or MNHA), when a PFE (Packet Forwarding Engine) process crash occurs on the active node, HA failover is not triggered because the failure condition is not detected by the HA subsystem. This can lead to traffic disruption and service outage.
PR NumberSynopsisCategory: Accounting Profile
1914977
Minor
Whenever a client(eg lacp/ifinfo/snmp) requests statistics from PFE, the query is routed via the kernel and not through the use of the BULKGET protocol
Product-Group=junos
Severity=Minor
On specific VMHost platforms like MX204/MX304/MX10003/MX10008/MX10016/ PTX1000/PTX10008/PTX10016/ EX2300/EX3400/EX4650/ QFX5100/QFX5110/QFX5200/ QFX10002/QFX10008/QFX10016/ vSRX/SRX1500/SRX1600/SRX2300/SRX4100/SRX4200/SRX4300/SRX4600 platforms. Whenever a client (e.g., lacp/ifinfo/snmp) requests statistics from PFE, the query is routed via the kernel and not through the use of the BULKGET protocol.
PR NumberSynopsisCategory: "agentd" software daemon
1843184
Major
JSD core reported (backtrace truncated)
Product-Group=junos
Severity=Major
JSD utilizes the libaudit API to send accounting messages for gRPC RPCs to auditd. The libaudit library establishes a socket connection and writes accounting messages to auditd. This socket is intended to be shared across multiple threads within JSD. Upon a write failure, the existing socket is closed, and a new socket is created. However, in a multi-threaded environment, there is a race condition whereby multiple threads may simultaneously detect that the socket has been closed and attempt to create a new one. This can result in multiple sockets being opened concurrently, ultimately leading to a file descriptor (FD) leak. To address this issue, a mutex lock has been introduced around the function responsible for socket creation and message transmission via libaudit. With this fix in place, when a socket is closed due to a write failure, the same thread will recreate the socket while holding the lock, and the updated socket descriptor will then be safely shared across all threads within JSD.
1859761
Minor
Continuous AGENTD_PFE_SENSOR_INSTALL_FAILED error messages on backup RE
Product-Group=junos
Severity=Minor
On Junos OS platforms with dual Routing Engines, the backup Routing Engine may repeatedly log AGENTD_PFE_SENSOR_INSTALL_FAILED error messages related to telemetry sensor installation. This issue is cosmetic and does not impact traffic forwarding, control-plane operation, or system stability. The issue has been resolved by improving resiliency in telemetry-related components to prevent unnecessary retry attempts on the backup Routing Engine.
1902691
Major
The JSD server fails to start the local SSL certificate for the SSL-based telemetry services in the FIP mode
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when FIPS is enabled, the JSD server fails to start if a local SSL certificate is configured on telemetry; as a result, telemetry services using SSL certificates are unavailable.
1913260
Major
Discrepancy noticed in the interfaces when there is a reset in Linecard or PFE
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, with an established telemetry session with multiple collectors, there will be interface statistics discrepancy when there is a linecard OIR event or PFE offline/online sequence.
1919448
Major
Heavy traffic flow causing SWAN agent to disconnect from the clients
Product-Group=junos
Severity=Major
In all Junos and EVO platforms, a gRPC connection between the SWAN (Software Wide Area Network) agent and the device is being closed unexpectedly. While SWAN client/JET(Juniper Extension Toolkit) client is connecting and sending data close to 3K(3000) routes at 8KB Per RPC (Remote Procedure Call) over the connection, they can hit rare race condition which can cause the clients to disconnect.
1929823
Major
The sysd process crashes with error logs upon exceeding its memory limit
Product-Group=junos
Severity=Major
On Junos OS Evolved platforms with telemetry streaming configured, the sysd (System Daemon) process crashes on the backup RE (Routing Engine), and error logs are observed when sysd memory usage continues to grow over time, and the memory limit is exceeded. This issue is observed when the 64-bit sysd consumes more memory than the configured system limit when the device has been running for a long time (typically more than 100 days) in the dual RE scenario.
PR NumberSynopsisCategory: MX YT-ZF Linecards YT, MQSS, Pre-Classifier, HBM Driver Category
1948588
Minor
Intermittent fabric errors causing traffic loss due to line card PLL lock loss.
Product-Group=junos
Severity=Minor
On certain MX Series and SRX Series platforms running Junos, an intermittent PLL (Phase-Locked Loop) lock loss on certain line cards leads to fabric link errors. When the issue happens, forwarding plane traffic across the chassis fabric is impacted, resulting in partial or complete traffic loss.
PR NumberSynopsisCategory: BBE routing
1922536
Major
Forwarding issues for an access DHCPv6-PD or access-internal DHCPv6-IA route or both may be seen on LNS due to an incorrect route programming of such route on PFE
Product-Group=junos
Severity=Major
Drop of traffic to subscriber DHCPv6 prefixes may be observed on LNS (L2TP network server) if CPE uses IPv6 address obtained via NDRA process as the source address for DHCPv6 negotiation instead of link-local address.
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1856217
Major
Memory corruption in bbe-statsd due to double free for IP demux lite subscribers
Product-Group=junos
Severity=Major
On Junos MX platforms with bbe-statsd running, there is a rare timing issue that could cause memory corruption in the bbe-statsd process due to a double-free scenario for IP demux lite subscribers. The issue could result in bbe-statsd process crashes. but had no service impact. The bbe-statsd process may crash, but there is no service or network impact.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1846448
Major
The S-BFD responder session cannot be distributed to PFE and failing S-BFD session to establish
Product-Group=junos
Severity=Major
On al MX and PTX platforms, If S-BFD(Seamless-Bidirectional Forwarding Detection) responder is configured without the "lo0.0" on device and with any other "lo0.x " then this S-BFD responder session cannot be distributed to PFE(Packet Forwarding Engine) and fails to come up in distributed mode. Hence BFD service will be impacted.
PR NumberSynopsisCategory: Border Gateway Protocol
1854194
Major
Handling cores when always-compare-med is configured in BGP path selection
Product-Group=junos
Severity=Major
When using rib-groups, which copy inet.3 routes to inet.0 and inet6.3, configuring path-selection always-compare-med triggers a local RIB evaluation that will miss inet6.3 because inet6.3 tables are not initialized as a BGP RIB. As a result, Inet6.3 routes will not get updated.
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.
1880630
Major
Some BGP sessions remain in the Idle state after all interfaces are deactivated and rollback is issued
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, after all the interfaces are deactivated and the rolled back, some BGP sessions stay in Idle state. This will impact the traffic.
1889749
Critical
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=junos
Severity=Major
On MX480 and MX960 platforms, routes become hidden when the "accept-own" feature is enabled in environments configured with rib-sharding. This issue arises when the "vrf-table-label" is configured within a routing instance and route sharding is enabled, potentially leading to routing failures.
1915893
Major
The rpd process crash triggered by LLGR stale timer expiry and late reconnection of unconfigured BGP peer on helper node
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved, when Long-Lived Graceful Restart (LLGR) is configured and a Border Gateway Protocol (BGP) neighbor goes down and reconnects after the LLGR stale timer expires, the Routing Protocol Daemon (rpd) process crashes leading to service disruption.
1935730
Major
BGP session teardown due to incorrect 'prefix-limit maximum exceeded' error when RIB sharding is enabled
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when prefix-limit or accepted-prefix-limit is configured under family route-target with rib-sharding, prefix-limit will be incorrectly reported as 'prefix-limit maximum is exceeded'. This causes the BGP session to go down immediately. This occurs because the system incorrectly counts each received route multiple times (once for the main thread and once for each shard)
PR NumberSynopsisCategory: BGP BMP Software
1785723
Major
When BGP rib-sharding is enabled, show bgp bmp output hangs
Product-Group=junos
Severity=Major
On all Junos and Junos evolved platforms, the output of command show bgp bmp hangs when rib-sharding is enabled and rpd restarts
PR NumberSynopsisCategory: Track PRs in BGP Flow Spec area & is part of BGP inside RPD.
1945627
Minor
BGP IPv6 Flow Specification Session Flapping When inet6-flow Is Enabled
Product-Group=junos
Severity=Minor
In certain Junos OS releases, BGP sessions may repeatedly reset when IPv6 Flow Specification (inet6-flow) is enabled. This behavior occurs when the router receives specific IPv6 Flow Specification updates that include a default (wildcard) match. Earlier releases do not exhibit this behavior, leading to a difference in observed stability when upgrading.
PR NumberSynopsisCategory: bras licensing prs
1836179
Minor
The smid process restarts as BBE daemons and libraries use incorrect license
Product-Group=junos
Severity=Minor
On Junos MX OS platforms, the use of an incorrect license by BBE (Broadband Edge) daemons and libraries leads to the smid process consuming 100% CPU (Central Processing Unit), which causes the smid (Subscriber Management Infrastructure Daemon) to restart and results in memory corruption.
PR NumberSynopsisCategory: MX304 PSM issuues
1923135
Major
On MX304 platform repetitive logic fault alarm on both PEMs observed
Product-Group=junosvae
Severity=Major
On MX304 platforms, PEM Logic Fault alarms may intermittently appear due to I2C transaction timing limitations. PEMs require a delay between backtoback transactions; without this delay, alarms can be raised randomly on either PEM.
PR NumberSynopsisCategory: MX304 interface specific
1818120
Critical
100G AOC cable with serial numbers starting with 1A will not get detected on all Junos OS Evolved based FPC
Product-Group=junos
Severity=Critical
On all Junos OS Evolved platforms, MX platforms with MPC10 and above, MX304 and EX9K with EX9200-15C, 100G AOC cable with serial numbers starting with 1A will not get detected. When this issue occurs, interface will go down which causes traffic loss.
PR NumberSynopsisCategory: MX Platform SW - UI management
1906927
Major
SNMP jnxDomCurrentLaneWarnings OID values are wrong due to other lane values are copied from lane 0
Product-Group=junos
Severity=Major
When a interface supports multiple lanes, the SNMP OID jnxDomCurrentLaneWarnings is incorrectly handled as a single lane, resulting in the value from lane 0 being replicated across all other lanes.
PR NumberSynopsisCategory: Class of Service
1928420
Minor
Incorrect COS scheduler-map gets attached to an AE IFL after GRES or 'cosd' process restart
Product-Group=junos
Severity=Minor
On all Junos MX platforms with line cards (MPC1-11, MS-MPC, LC2101, LC2103, LC480, LC4800, LC4802, LC9600, JNP304-LMIC), when a scheduler-map is attached to an AE (Aggregated Ethernet) IFL (Logical Interface) directly or by 'traffic-control-profile' and when this AE is in 'replicate' mode, upon GRES (Graceful Routing Engine Switchover) or on 'cosd' process restart operation, configured scheduler-map gets removed from this AE IFL and a default (Incorrect) scheduler-map gets attached to it. This causes change in the traffic flow pattern via the COS (Class of Service) queues of the AE IFL and can impact service.
PR NumberSynopsisCategory: QFX Access Control related
1934680
Major
The radius accounting interim updates is missing framed-ip-address when manually triggered
Product-Group=junos
Severity=Major
On platforms supporting dot1x authentication, when a Radius accounting Interim-Update is manually triggered from the switch (using a COA), the resulting accounting packet does not include the Framed-IP-Address attribute. However, when the same session generates an interim update via the periodic timer (10-minute interval), the Framed-IP-Address is included as expected.
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1921796
Minor
Traffic dropped after priority change in VRRP with EVPN-VxLAN scenario
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, in Virtual Router Redundancy Protocol (VRRP) with Ethernet Virtual Private Network - Virtual Extensible Local Area Network (EVPN-VXLAN) scenario, when VRRP priority is changed, the VRRP virtual Media Access Control (MAC) address can remain pinned as a static entry on the remote device. As a result, MAC movement does not occur correctly, and VRRP packets are dropped on the leaf device. This impacts VRRP operation after priority changes.
1926468
Major
EVPN-VXLAN: Duplicate Proxied Neighbor Advertisements Missing Router/Override Flags Disrupt IPv6 Connectivity
Product-Group=junos
Severity=Major
When Junos and Junos Evolved platform sends two proxied Neighbor Advertisement for default gateway, second one without Router flag and target Link-Layer address. The second Neighbor Advertisement can disrupt connectivity for end hosts. A proxied Neighbor Advertisement (NA) is an IPv6 mechanism where a network device responds to Neighbor Discovery requests on behalf of another device, instead of the actual endpoint replying itself.
PR NumberSynopsisCategory: ACX platform interface issues
1912165
Minor
[ACX5448] QSFP May Stop Functioning After Reboot-Related Operations Due to I2C Read Errors
Product-Group=junos
Severity=Minor
After performing operations that involve a reboot - such as system reboot, Junos upgrade/downgrade, or restart chassis-control - the QSFP module may detect I2C read errors and stop functioning. When this issue occurs, the following messages can be observed in the system log: Jan 11 11:11:11.111 20XX acx5448 fpc0 qsfp[RIO-MIC(0/1)(2)] I2C READ access reached max try qsfp_tk_i2c_rd_wr_access Jan 11 11:11:11.111 20XX acx5448 fpc0 RIO-MIC(0/1)(2): Reading the power-mode failed.
PR NumberSynopsisCategory: Dynamic rendering infrastructure
1915225
Major
cli-pfe does not terminate immediately when user issues Ctrl-C
Product-Group=junos
Severity=Major
A cli-pfe show command may continue to gather data in the background after the user issues a Ctrl-C. Eventually the background command will complete. However, the CPU usage for the cli-pfe process will continue to be high while it is still running.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1908408
Major
Interfaces fail to come up after port speed changes or system power cycle reboot events on MX platforms
Product-Group=junos
Severity=Major
On all Junos OS MX platforms, after port speed related configuration changes or on MX240, MX480, MX960, and MX10003 platforms in VC (Virtual Chassis) setup, after a powercycle reboot of any VC member, some interfaces which were previously operational fail to return to an operational state due to an internal timing issue during PIC (Physical Interface Card) reinitialization.
PR NumberSynopsisCategory: JUNOS Dynamic Profile Configuration Infrastructure
1930036
Major
High memory usage is showing, when we configure unsupported licensing feature
Product-Group=junos
Severity=Major
On all Junos EX and QFX platforms operating in an EVPN (Ethernet Virtual Private Network) environment, this issue occurs when the CLI command 'licensing hourly update' is executed on a device that does not support the licensing feature.
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1899711
Minor
Unexpected packet retransmissions and traffic drops observed on SFP-T interfaces on LC480 line cards
Product-Group=junos
Severity=Minor
On MX10004, MX10008, and MX10016 platforms with LC480 line cards using 1G SFP-T transceivers, an issue in the PHY caused frames to be transmitted too closely together, leading to packet loss or retransmissions.
PR NumberSynopsisCategory: eventd, syslog infra issues
1919638
Major
Certain Junos EVO applications may become unresponsive during trace file rotation
Product-Group=junos
Severity=Major
On Junos EVO platforms, frequent trace file rotation may cause certain EVO applications to become unresponsive.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1882996
Major
xnm-ssl feature fails without loopback interface configuration on Junos Evolved platforms.
Product-Group=junos
Severity=Major
On Junos Evolved platforms, the xnm-ssl feature does not function unless a loopback address (lo0.0) is explicitly configured. The feature is not applicable to Junos (non-EVO) platforms. To ensure proper operation, configure 127.0.0.1/32 on lo0.0.
PR NumberSynopsisCategory: EVPN control plane issues
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby) the ARP (Address Resolution Protocol) tables from Customer Edge (CE's) device may not update simultaneously on Provider Edge (PE) devices when an IP address moves between two different Ethernet Segments (ESIs) during a switchover, leading to temporary traffic disruption until the tables are refreshed.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1916646
Major
IRB interface state is observed incorrect on IFD events tracked by a Network Isolation group
Product-Group=junos
Severity=Major
On MX, EX9200, QFX, PTX platforms, Traffic forwarded over the IRB (Integrated Routing and Bridging) is impacted when isolation decisions rely on the state of a tracked interface, because the Network Isolation Group tracks the interface but processes only IFL (Interface Logical) events and does not process IFD (Interface Device) events.
1926818
Major
ARP resolution failure for /32 static host routes via IRB in EVPN virtual-switch routing instances
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms that support EVPN (Ethernet VPN) virtual-switch routing instances, ARP (Address Resolution Protocol) resolution fails for static host routes configured with a /32 mask when the next-hop interface is an IRB (Integrated Routing and Bridging) interface and the destination host resides in a different subnet. As a result, ARP entries are not installed, MAC (Media Access Control) addresses of destination hosts are not learned, and traffic destined to those hosts becomes unreachable, causing service impact.
1943641
Major
ARP and MAC/IP table for virtual IP mac is not installed in bridge domain which is part if EVPN instance
Product-Group=junos
Severity=Major
In any EVPN setups of MX , EX, QFX using Aggregated Ethernet across multiple FPCs, the VRRP virtual IP may fail to install ARP and destination route entries when the VRRP virtual MAC is learned on one FPC while the ARP response is received on another with a source MAC and SHA mismatch.
PR NumberSynopsisCategory: EX4100 PFE
1925850
Minor
High CPU utilization and dfwd crash when modifying firewall filter terms applied on lo0 interface of Junos-based EX and QFX platforms
Product-Group=junos
Severity=Minor
On Junos-based EX and QFX platforms, modifying any term of a firewall filter applied on the lo0 interface triggers repeated Dynamic Firewall Daemon (dfwd) restarts and causes the Routing Engine (RE) CPU to reach 100 percent. The condition persists until the filter is removed or the previous configuration is restored.
PR NumberSynopsisCategory: EX interfaces issues
1757034
Major
EX3400: "Error:tvp_optics_eeprom_read: Failed to read eeprom for link" syslog error message
Product-Group=junos
Severity=Major
"Error:tvp_optics_eeprom_read: Failed to read eeprom for link" logs might be seen for some time during system reboot or pfe restart in EX3400. There is no functional impact due to these logs.
1904884
Major
VCP link flap due to SYSPLD read failures
Product-Group=junos
Severity=Major
On EX4100 platform VCP link flap due to SYSPLD read failures and mark SFP as unplugged
1915222
Major
Interfaces down after Virtual Chassis reboot
Product-Group=junos
Severity=Major
On all Junos EX Series platforms, following a Virtual Chassis (VC) reboot, random interface links GE(Gigabit) and XE(10 Gigabit) intermittently appear in a down state at the Interface Descriptor (IFD) level, even though the physical link remains operational.
PR NumberSynopsisCategory: EX4400 PFE software
1908971
Major
DHCP Snooping drops due to misrouted server packets causing intermittent issues.
Product-Group=junos
Severity=Major
Intermittent performance issues observed across sites due to anomalous DHCP behavior, where DHCP server packets are incorrectly received on downstream switch interfaces, triggering snooping drops.
PR NumberSynopsisCategory: EX4400 platform
1932557
Major
Running 'request support information' command may result in disk I/O errors
Product-Group=junos
Severity=Major
On EX4400 platforms, running the command 'request support information' may result in disk I/O errors. This issue occurs because the RSI process runs an internal command that retrieves eMMC details using chipset vendor-specific operations. These commands were originally used during early platform development but can conflict with normal eMMC operations when executed concurrently. This causes service disruption.
1942085
Major
EX4400: Kernel panic and unexpected reboot on certain EX4400 platforms due to CPU erratum
Product-Group=junos
Severity=Major
On EX4400 product family platforms, device experienced an unexpected reboot and recovers automatically. The system logs indicate a kernel panic, and a VMcore file is generated. Traffic impact will be seen until the recovery. Bios version CDEN_P_EX1_00.22.01.00 fixes this issue.
PR NumberSynopsisCategory: EX POE
1814715
Minor
When PDs(power devices) are connected to all the PoE (power over ethernet) ports with LLDP enabled, the last port is not powered up
Product-Group=junos
Severity=Minor
On EX2300P and EX3400 platforms, when PDs are connected to all the PoE ports with LLDP enabled, the last port is not powered up.
1930080
Minor
PoE outage observed on EX4400 in a rare scenario
Product-Group=junos
Severity=Minor
On EX4400 platforms, loss of PoE (Power over Ethernet) power is seen on ports after port bounce or even during normal operation without specific external trigger . This causes outage on all PoE ports and devices connected to PoE port will not receive power causing service impact.
PR NumberSynopsisCategory: EX Entry Level Access VC platform
1919727
Minor
The dcpfe process crashes repeatedly with continuous error logs 'smb_transfer: SMBus ioctl failed'
Product-Group=junos
Severity=Minor
On EX4400 platforms, due to an internal communication issue within the CPU controller, the system triggers repeated fxpc panics which in turn lead to the dcpfe process (Dataplane Packet Forwarding Engine) to crash and restart continuously, resulting in service disruption.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1928462
Major
FPC crash occurs after configuration changes are made to a service-filter on specific MX platforms
Product-Group=junos
Severity=Major
FPC crash and aftd-trio core-dump will be observed on MX platforms supporting MPC10E, MPC11E, LC9600 line cards, and MX304 after configuration changes were made to a service-filter which was in use by BBE subscribers.
PR NumberSynopsisCategory: SRX1500 platform software
1905001
Minor
FPC stuck in network loop scenario
Product-Group=junos
Severity=Minor
On SRX1500 in network loop scenarios, FPC gets stuck and traffic drop happens. System can be recovered by rebooting the device.
PR NumberSynopsisCategory: LC4800 specific Fabric software issues
1881595
Minor
When an FPC is ungracefully offlined it remains online for 12 minutes causing a service impact
Product-Group=junos
Severity=Minor
On all MX platforms with 2 or more FPCs (Flexible PIC Concentrators), a temporary service impact will be observed if a FPC is ungracefully offlined (for example, due to an ungraceful switchover, command to simulate ungraceful offline, or physical removal). The FPC that is being ungracefully offlined appears online for ~12 minutes before going offline. During this 12-minute period, the Fabric Manager remains in a stuck state and recovers automatically after the FPC goes offline.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1861810
Major
The rpd process crash is observed while adding and removing dynamic-tunnels with scaled tunnel configuration
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, the indexing of next hop while adding and deleting dynamic tunnels causes the rpd process to crash and restart. This is a timing issue.
PR NumberSynopsisCategory: jdhcpd daemon
1825998
Major
DHCP ALQ process crashes to recover from memory leak.
Product-Group=junos
Severity=Major
On all Junos platforms , In a rare scenario when memory leak happens the Dynamic Host Configuration Protocol (DHCP) active-leasequery (ALQ) process crashes automatically.
1927449
Major
Jdhcpd cores generated after upgrade
Product-Group=junos
Severity=Major
jdhcpd cores seen after upgrade with dhcpv6 for IANA/PD
1939685
Minor
Insert command not working for "dhcp-local-server group" hierarchy
Product-Group=junos
Severity=Minor
Insert command not working for "dhcp-local-server group" hierarchy, below error is seen: user@host# insert system services dhcp-local-server group servers-1 after syntax error, expecting `after' or `before'. user@host# insert system services dhcp-local-server group servers-1 bef syntax error, expecting `after' or `before'.
PR NumberSynopsisCategory: SRX power-mode (PMI/PME)
1858490
Major
flowd crashes due to a timing issue during IPsec SA re-keying on certain SRX platforms
Product-Group=junos
Severity=Major
On certain SRX platforms, the flowd process crash is observed during Internet Protocol Security (IPsec) Security Association (SA) re-keying. This occurs due to an internal timing issue, leading to IPsec tunnel establishment failure, traffic loss during re-key events, and traffic switchover.
PR NumberSynopsisCategory: IPSEC/IKE Key Management
1922670
Critical
KMD process crash during RG0 failover with ADVPN shortcuts in HA cluster
Product-Group=junos
Severity=Critical
On SRX and MX platforms using the IPsec Key Management Daemon (KMD), RG0 failover or failback while Auto Discovery VPN (ADVPN) shortcuts are active may cause the KMD process to crash, temporarily disrupting ADVPN sessions.
PR NumberSynopsisCategory: Firewall Network Address Translation
1920648
Minor
Configuration commit takes several minutes to complete on SRX platforms
Product-Group=junos
Severity=Minor
On SRX platforms, when destination NAT rules referencing addressrange objects are configured, commit and commit-check operations may take several minutes to complete. The delay affects only administrative commit workflows and does not impact packet forwarding or controlplane functions.
1933239
Critical
The FPC restarts on SRX series platforms when session-persistence-scan is configured
Product-Group=junos
Severity=Critical
On Junos OS SRX Series platforms with 'session-persistence-scan' and NAT46 or NAT64 configured, modification to source Network Address Translation (NAT) rule will cause Flexible PIC Concentrators (FPCs) to restart when there is live IPv6 traffic. This will cause all traffic to be dropped and cause service disruption.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1877966
Minor
Some new VPN tunnels are not coming up on SRX5K platforms with SPC3
Product-Group=junos
Severity=Minor
On SRX5K platforms with SPC3 installed, IPSec (Internet Protocol Security ) tunnels with iked which reuses the same IKE (Internet Key Exchange) gateway peer IP, could be observed not re-establishing.
1890872
Major
Packets are post-fragmented with DF=0
Product-Group=junos
Severity=Major
On all SRX platforms, due to PMTU wrong calculation packets are post-fragmented, even when DF=0 is configured. This adds processing overhead and can cause downstream forwarding issues.
1912271
Major
State synchronization failure between SRX cluster nodes
Product-Group=junos
Severity=Major
On all SRX series platform in cluster with IKED package enabled, when the backup node becomes active, some tunnel configuration were missing. This occurs because, during cold synchronization, the IPC communication between IKED and SPU can have a chance to fail due to a kernl error which ultimately led to traffic disruption.
PR NumberSynopsisCategory: Security platform jweb support
1931780
Major
The Captive Web Authentication might not be completed on specific Junos versions for EX Series switch
Product-Group=junos
Severity=Major
When a MAC-RADIUS authentication succeeds and the RADIUS server returns CWA redirect attributes (URL-Redirect), the EX switch should intercept client HTTP traffic and return an HTTP 302 redirect to the Captive Portal. The switch instead responded with HTTP 405 (Method Not Allowed), causing the client to bypass the CWA redirect workflow.
PR NumberSynopsisCategory: Platform infra to support jvision
1928253
Major
The sensord process crashes leading to PFE reboot on MPC10E supported MX platforms
Product-Group=junos
Severity=Major
On MX platforms supporting MPC10E line card, the sensord process crashes due to corrupted memory state on the FPC (Flexible PIC Concentrator). When the sensord process crashes, the PFE (Packet Forwarding Engine) reboots leading to interface flaps and consequent disruption to traffic flow.
PR NumberSynopsisCategory: Layer 2 Control Module
1930380
Major
The hash collision for storm control profile indices will result in an l2ald process crash
Product-Group=junos
Severity=Major
On all Junos OS platforms and Junos OS Evolved platforms which supports storm control, when a different storm-control profile is applied for interface where these profile have same profile index allocated then the storm control profile configuration and system state will not be in sync and a different profile will be applied for interface binding due to profile index collision which results into l2ald process crash.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1816344
Major
EVPN : Traffic failure after multiple link flaps of core facing interfaces on scaled setup
Product-Group=junos
Severity=Major
ARP resolution failure when there is quick flap of core facing interface on scaled setup
1928530
Critical
A buffer overflow during IPv6 NDP operations in an EVPN environment caused segmentation faults leading to FPC crash files and repeated reboots
Product-Group=junos
Severity=Critical
On JunOS MX240/MX480/MX960/MX2008/MX2010/MX2020 platforms with MPC10E/MPC11E line cards as well as the MX304 platform, an issue in IPv6 EVPN (Ethernet Virtual Private Network) during NDP (Neighbor Discovery Protocol) resolicitation of a link local target address causes the system to use the IRB link local address in outgoing packets. Stack corruption happens when handling the IRB link local address and resulting in continuous FPC (Flexible PIC Concentrator) reboots (around 3 or 4 times) and crash files generation.
1936648
Major
EVPN-VXLAN remote MAC IP programming is removed after a MAC move, resulting in missing ARP on a remote VTEP
Product-Group=junos
Severity=Major
In an Ethernet VPN (EVPN) Virtual Extensible LAN (VXLAN) deployment, a remote MAC move event can cause the remote MAC IP entry to be removed after it is initially installed, resulting in missing Address Resolution Protocol (ARP) state and incomplete hardware programming on the remote Virtual Tunnel Endpoint (VTEP), which can lead to traffic loss for the affected endpoint.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1881572
Minor
Logs are seen when unsupported feature license key is added
Product-Group=junos
Severity=Minor
Logs are seen when unsupported feature license key is added using "request system license add " command. It is a display issue.
1933553
Minor
License check process crashes due to mutex synchronization issue
Product-Group=junos
Severity=Minor
A software issue was identified in the license check process that could cause the process to crash due to a synchronization condition between internal threads. This behavior may occur when multiple threads access the LicenseMonitorEventNotify() function simultaneously, potentially leading to a mutex deadlock and generating a core dump. This issue has no impact on traffic forwarding or network services.
PR NumberSynopsisCategory: MPC11 ULC platform software related issues.
1881499
Minor
On MPC11E linecards, Periodic error messages are logged as "Temp sensor DDR4 A failed"
Product-Group=junos
Severity=Minor
DDR temp sensor is designed to be used periodically to get temps to send to chassisd. The temp sensors reside may have an intermittent contention that can cause these read failures resulting in DDR4 Temp Sensor Fail" logs on MPC11E linecards.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=junos
Severity=Major
This is a timing issue seen on all Junos and Junos OS Evolved platforms when the optimisation timer expires for a member LSP (Label-Switched Path) when normalisation is in progress for a container LSP, this generates an unrequired route update leading to the link protection route of the LSPs to flap. LSP flap will result in impact on the traffic.
1923867
Minor
The rpd process crash is observed after a graceful restart in the RSVP-TE scenario
Product-Group=junos
Severity=Minor
On Junos OS and Junos OS Evolved platforms with Graceful Restart and RSVP-TE (Resource Reservation Protocol - Traffic Engineering) configured, an rpd crash is observed, leading to traffic impact after a Graceful Restart if a PVC (Permanent Virtual Circuit) fails to allocate correctly during this recovery process, leaving it in an incomplete or unallocated state, and the system attempts to clean up or remove this unallocated PVC.
PR NumberSynopsisCategory: Multicast for L3VPNs
1918004
Minor
Multicast traffic disruption in multi-homed networks
Product-Group=junos
Severity=Minor
On Junos and Junos OS Evolved platforms, blackholed traffic disruption can occur in multi-homed NGEN MVPN (Next Generation Multicast Virtual Private Network) setups when a PE(Provider Edge) acting as both multicast source and DR/RP (Designated Router/Rendezvous Point) experiences path changes or flaps, provided the source is local and multi-homed across two PEs.
PR NumberSynopsisCategory: ACX Timing software
1810429
Major
ACX710 PTP ports marked 'passive' instead of 'master' during T-GM selection
Product-Group=junos
Severity=Major
In a scenario where two T-GM devices (Telecom Grandmaster clocks) have identical BMCA (Best Master Clock Algorithm) parameters, except for steps removed or grandmaster ID, the ACX710 running the G.8275.1 profile can experience a failure in proper PTP (Precision Time Protocol) clock synchronization. This issue arises because the default BMCA is used instead of the expected Alternate BMCA profile in G.8275.1. This mismatch leads to incorrect PTP clock states, with master ports being marked as 'Passive' instead of 'Master'.
1900889
Major
High CPU utilization of the acx-arm-feb process on ACX710 platforms after upgrade or reboot when Precision Time Protocol (PTP) or Synchronous Ethernet (SyncE) is configured
Product-Group=junos
Severity=Major
On ACX710 platforms running Junos OS, the acx-arm-feb process reaches 100 percent CPU utilization after a system upgrade or reboot when Precision Time Protocol (PTP) or Synchronous Ethernet (SyncE) is configured and the associated interfaces are enabled. This condition results in control plane degradation and traffic impact.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1821268
Major
Mist-managed Junos devices experience excessive logging due to execution of snapshot command resulting in an error
Product-Group=junos
Severity=Major
On all Junos platforms managed by Mist, Mist will push the snapshot command periodically to the Junos devices. However, the exit status returned is an error due to this issue and there will be a constant logging for snapshots running. There is no service impacts due to this issue.
PR NumberSynopsisCategory: PFE Peer Infra
1883882
Minor
Junos EX series device reboots unexpectedly with VMcore
Product-Group=junos
Severity=Minor
The Junos EX platforms restart unexpectedly - leaving a vmcore after the reboot.
PR NumberSynopsisCategory: TCP/UDP transport layer
1893210
Minor
Master RE crashed and triggered unexpected switchover due to memory corruption
Product-Group=junos
Severity=Minor
On all Junos OS platforms, In Nonstop active routing (NSR) enabled system Routing Engine (RE) crash can occur due to a double free of a memory buffer (mbuf) was not handled properly leading to memory corruption causing synchronization issue and triggers unexpected switchover.
PR NumberSynopsisCategory: Path computation client daemon
1929225
Critical
The pccd process crashes when muliple LSP updates are received from PCE
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with PCEP (Path Computation Element Protocol) configured, the pccd process crash is seen when multiple LSP (Label Switched Path) updates are received in a single PCE (Path Computation Element) message. The LSP update sent by the PCE will not get programmed into the forwarding plane and LSP states will not be updated till the pccd process restarts.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1931633
Major
PFE crash due to memory corruption when STP is enabled
Product-Group=junos
Severity=Major
On all Junos Platforms, a rare memory corruption condition may occur in the Packet Forwarding Engine (PFE) when Spanning Tree Protocol (STP) is enabled and operating in default (distributed) mode. When the issue is triggered, the PFE crashes and a dc-pfe core file is generated. The exact trigger for the memory corruption is currently unknown.
PR NumberSynopsisCategory: QFX5K hostpath
1921455
Major
The dcpfe process crashes when adding or removing classifier configuration on QFX5210
Product-Group=junos
Severity=Major
On QFX5210 platform with Class of Service (CoS), the dcpfe process crashes when classifier is configured or removed on interface with active traffic. This can affect traffic forwarding till dcpfe process restarts post crash.
1932314
Minor
Errors "fpc0 ifd null, port X and TD3:ifd null, port X" are seen on QFX5k platforms
Product-Group=junos
Severity=Minor
On QFX5k platforms, if sflow is configured without multicast and BUM traffic is sampled, then the errors "fpc0 ifd null, port X and TD3:ifd null, port X" are observed.
PR NumberSynopsisCategory: for all ipv6 related issues
1922278
Major
IPV6 auto negotiation Router Advertisement packet is missed over configured L2 circuit
Product-Group=junos
Severity=Major
On Junos OS QFX5120 and EX4650, when a L2 circuit is configured between two Customer Premises Equipment (CPE) , IPv6 Router Advertisement packets will not be sent to peer. This will cause devices to not exchange IPv6 messages so they cannot automatically be configured with an IPv6 address, therefore IPv6 connectivity won't be established.
PR NumberSynopsisCategory: QFX L2 PFE
1852186
Minor
vlan-mac-in-tcam knob is not working
Product-Group=junos
Severity=Minor
On all Junos QFX5k and EX4k platforms, traffic will be affected by incorrect handling and programming of associated MAC (Media Access Control) addresses for IRB (Integrated Routing and Bridging) in the PFE (Packet Forwarding Engine) when this knob is used.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1905607
Major
Hardware MTU stuck at default value, causing packet drops on VXLAN Interfaces
Product-Group=junos
Severity=Major
On QFX5K and EX4K platforms which are running Junos release, when new VxLAN (Virtual Extensible LAN) vlans with IRBs (Integrated Routing & Bridging) are added, the L3 (Layer 3) interface values overwrite the MTU (Maximum Transmission Unit) entries previously programmed for non-VxLAN vlans that use the same hardware token internally. The VxLAN L3 interface is created with default MTU (1514) because L3 interface MTU value is still 1514 as it is not update by RE (Routing Engine).
1925996
Major
Intermittent uplink ports flaps events observed and syspld read failures on syslog messages were seen.
Product-Group=junos
Severity=Major
Intermittent uplink ports flaps events observed and log messages show continuous syspld read failures during the issue. After a power cycle, the devices recovered.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1924654
Minor
DC-PFE Core due to Concurrent Filter Reprogramming and VTY Command Execution
Product-Group=junos
Severity=Minor
While a filter with a routing-instance action was being reprogrammed as part of a CLI commit, a firewall VTY command to dump this filter was executed concurrently. This concurrent access resulted in a DC-PFE core, as filter-related data structures were modified during reprogramming.
1933698
Major
PFE crash due to memory corruption in EVPN-VxLAN type5 overlay ECMP at high tunnel next hop scale
Product-Group=junosvae
Severity=Major
On Junos QFX5110, QFX5120, EX4650, EX4400, EX4100, and EX5200 platforms, when operating with EVPN-VxLAN type5 overlay ECMP at high tunnel next hop scale, the Packet Forwarding Engine (PFE) crash when a memory corruption issue is observed due to a buffer overflow that leads to corruption of heap management structures. This corrupted metadata is detected by the memory manager when later heap allocation or free operations are invoked, resulting in a reported heap corruption condition.
1948146
Minor
BFD distributed mode not coming up on IRB with CRB in EVPN-VXLAN
Product-Group=junos
Severity=Minor
On Junos OS platforms, when the device is operating as a spine, with EVPN-VXLAN (Ethernet VPN Virtual Extensible LAN) in CRB (centrally routed bridging), enabling BFD (Bidirectional Forwarding Detection) as distributed mode on IRB (Integrated Routing and Bridging) interfaces, causes the BFD destination process to not to set the output interface correctly, preventing the BFD session from coming up.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1810740
Major
Link wont come up on bounce of fec91 on QFX5120 platform
Product-Group=junos
Severity=Major
On QFX5120-48T, Interface links are not coming up at DUT after restoring the FEC configuration from mistmatched FEC configuration at non-dut.
1920870
Minor
QSFP optical modules go undetected on certain QFX5100 platforms
Product-Group=junos
Severity=Minor
On QFX5120-48Y, QFX5110-32q, QFX5110-48s platforms, running on 23.4R2-S4 release and multiple configurations are committed at the same time, the FPGA (Field-Programmable Gate Array) component responsible for managing QSFP (Quad Small Form Factor Pluggable) ports get into a hung state or reset state and the QSFP modules go undetected leading to loss of connectivity.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1758400
Major
JUNOS_REG: QFX51200-48YM: Fan status output was not same after/before device vc-switch over.
Product-Group=junos
Severity=Major
In a QFX51200-48YM-8C VC setup, after a a mastership switch over fan tray of linecard may not be displayed in show chassis hardware and show chassis environment. There is no functional impact
1864591
Major
The cpu-utilization-idle and temperature-cpu properties for FPC are not present on QFX-Series devices.
Product-Group=junos
Severity=Major
On QFX Series platforms running Junos OS, the cpu-utilization-idle and temperature-cpu properties for the Flexible PIC Concentrator (FPC) are not being streamed in the telemetry data. However, this issue doesn't impact traffic or performance of the device.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1908681
Major
RIB and the FIB inconsistency results in traffic loss in IPsec scenario with st0 interface configured
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having IPsec (Internet Protocol Security) with st0 (Secure Tunnel Interface) interface configured, traffic loss will be observed if the "next-hop-tunnel" configuration is removed and added within a few seconds. This happens due to a inconsistency between the RIB (Routing Information Base) and the FIB (Forwarding Information Base).
1931875
Major
The L2Circuit traffic which are resolving over BGP-LU get drop when 'chained-composite-next-hop' for BGP-LU and 'preserve-nexthop-hierarchy' is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms supporting 'chained-composite-next-hop' for BGP-LU (Border Gateway Protocol - Labeled Unicast), when having L2Circuit (Layer 2 Circuit) links configured, with indirect next-hop resolving on BGP-LU prefix, if 'chained-composite-next-hop' enabled for BGP-LU and with 'preserve-nexthop-hierarchy' configured, L2Circuit traffic will get dropped due to failure in installing the forwarding next-hop with labels for L2Circuit service.
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
Severity=Major
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1757389
Minor
"show route detail" shows "State: " for routes when route-record is enabled
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms with route-record enabled, some routes will be seen in State: due to race condition. There is no functionality issue, this is a display issue.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1906718
Critical
Junos OS and Junos OS Evolved: CVE-2022-24805 resolved in net-SNMP
Product-Group=junos
Severity=Critical
CVE-2022-24805 has been resolved in net-SNMP software included with Juniper Networks Junos OS and Junos OS Evolved. Please refer to https://supportportal.juniper.net/JSA107822 [juniper.net] for more information.
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1903211
Minor
Vmcore triggers while configuring new members into an existing AMS interface on all MX platforms with specific linecard
Product-Group=junos
Severity=Minor
On all MX platforms with MS-MPC(Multiservices Modular PIC Concentrator) card, When new members are configured into an existing AMS (Aggregated Multiservices) interface, it causes all the PICs (Physical Interface Cards) to bounce, which triggers a vmcore and RE(Routing Engine) reboot due to a timing rare-issue.
PR NumberSynopsisCategory: Segment routing traffic Engineering
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
Severity=Major
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.
PR NumberSynopsisCategory: SRX branch platforms
1845997
Major
Packet drops are observed in the VPLS environment on SRX380 platforms in packet mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms in packet mode, when VLAN (Virtual Local Area Network)-VPLS (Virtual Private LAN Service) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 (Layer 2) unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.
1889549
Major
The XE interfaces of SRX380 platform with 1G SFP (fiber) are flapping continuously when LACP is enabled
Product-Group=junos
Severity=Major
When LACP (Link Aggregation Control Protocol) is enabled using 1G SFP(Small Form-factor Pluggable)-fiber (such as SFP-SX, SFP-LX etc) over XE interfaces, frequent state transitions will repeatedly trigger configuration updates. Due to LACP instability, the interfaces will continuously flap. As a result, the port configuration will be re-applied automatically which leads to a loop of re-configurations until the LACP state stabilizes.
1897579
Minor
Packet drops are observed on SRX380 platforms in packet mode
Product-Group=junos
Severity=Minor
On Junos OS SRX380 (cluster/standalone) platforms in packet mode, when L2 (Layer 2) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.
1927646
Minor
Ethernet interfaces with fiber SFPs and configured with 'family ethernet-switching' and 'no auto negotiation' don't come up after reboot
Product-Group=junos
Severity=Minor
After reboot on branch SRX300 Series platforms, interfaces using Small Formfactor Pluggable (SFP) SX/LX fiber transceivers and configured with 'family ethernet-switching' and 'no auto negotiation' might remain in a down state due to incorrect physical medium detection by the Ethernet physical layer (PHY). The issue is timing-dependent, it might happen with single or after several reboots.
1934517
Major
SRX380 XE interface flap on every configuration commit with 1G SFP transceivers
Product-Group=junos
Severity=Major
On the SRX380 platforms, in both cluster and standalone modes, the XE interfaces with 1G SFP fiber transceivers flap once after every configuration commit, causing the device to temporarily lose upstream reachability.
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1916367
Minor
High CPU utilization in packet forwarding engine caused by firewall filter count action
Product-Group=junos
Severity=Minor
On all SRX, vSRX and MX platforms with MX-SPC3, configuring a firewall filter term with the count action will cause high CPU utilization in the Packet Forwarding Engine (pfe) process. Frequent packet matches to a 'count' introduce additional packet-processing overhead in the forwarding data plane and under high-rate traffic this will lead to performance degradation, reduced throughput, and potential traffic loss.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1934419
Major
Unexpected throughput reduction seen on AE bundle and physical interface when interface filter and policer are applied together
Product-Group=junos
Severity=Major
The issue is seen on all MX platforms with MPC10/MPC11/LC4800/LC9600 linecards and MX304, when the output filter and interface policer is applied to the egress AE (aggregated ethernet) and physical interface in the output direction and the interface policer runs first then the output filter. This kind of an incorrect policing issue leads to the exhaustion of the policer bandwidth and throughput reduction will be seen.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1855624
Major
IPv6 neighbor discovery with DHCP packet getting dropped when no-snoop option is enabled for DHCP Relay
Product-Group=junos
Severity=Major
On Junos OS MX platforms with DHCP (Dynamic Host Configuration Protocol) Relay configured using the "no-snoop" option, DHCP packets are not being processed correctly. This prevents next-hop resolution for the DHCP packets, causing IPv6 (Internet Protocol version 6) Neighbor Discovery with DHCP packet to be dropped by an intermediate device. As a result, the client fails to obtain an IP address, leading to traffic impact.
1921361
Major
Slow memory leak triggered by subscribing to the pipeline sensor for a long duration
Product-Group=junos
Severity=Major
On Junos platforms with MPC 1-9, LC2101, LC480, LC2103 line-cards and MX204, a slow memory is observed when subscribing to the pipeline sensor ( path is /components/component/integrated-circuit/pipeline-counters/). Over time, this causes a gradual increase in heap memory usage. Increase in heap memory usage beyond a certain threshold will lead to FPC crash resulting in loss of services and traffic over that FPC.
1922741
Minor
FPC heap memory will be leaked when CCNHs are recreated due to VPLS PNH are getting deleted and re-added
Product-Group=junos
Severity=Minor
On Junos MX platforms with MPC1-9/LC480/LC2101 (including MX204 and MX10003 platforms) when "set protocols l2circuit resolution preserve-nexthop-hierarchy" is enabled, FPC heap memory will leak when CCNHs (Chained Composite Next Hops) are recreated because of the VPLS (Virtual Private LAN Service) PNH (Preserve Nexthop Hierarchy) are getting deleted and re-added.
PR NumberSynopsisCategory: DDos Support on MX
1897237
Major
Traffic flow display not accurate when SCFD is enabled
Product-Group=junos
Severity=Major
On MX platforms with MPC10/MPC11/LC9600/LC4800 linecards and MX304/MX301 platforms, if SCFD (Suspicious Control Flow Detection) is enabled and lot of flow are tracked on the device, error logs may be reported when the table overflows. This is purely a display issue.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
Severity=Critical
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
1926050
Major
The auditd process crashes when the Radius server is configured but unreachable
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved having the Radius (Remote Authentication Dial-In User Service) server with accounting configured, the auditd crash is observed if the Radius server is unreachable for a long time and a large number of accounting records accumulate, which leads to memory exhaustion during accounting processing and results in a process crash.
PR NumberSynopsisCategory: Configuration management, ffp, load action
1854461
Major
Configured TFTP server connection and rate limits are not applied
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms configured as Trivial File Transfer Protocol (TFTP) server , "connection-limit" or "rate-limit" values are not updated as per configured values.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1872703
Major
Junos OS: Privileged local user can gain access to a Linux-based FPC as root (CVE-2025-30650)
Product-Group=junos
Severity=Major
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. Please refer to https://supportportal.juniper.net/JSA107863 [juniper.net] for more information.
1902358
Minor
RPC crash when non-ASCII character is included in XML data result
Product-Group=junos
Severity=Minor
1947196
Minor
Commitd core dumps observed during specific config commits with "patch generation error - not syncing patch"
Product-Group=junos
Severity=Minor
Resolved an issue where configuration commits could intermittently fail when applying certain routing policy changes. The problem occurred only under specific conditions during commit processing and could result in the commit operation aborting unexpectedly. This fix improves commit stability when updating routing policies.
PR NumberSynopsisCategory: Issues related to NETCONF
1858635
Critical
ACX Series vmcore crash when netconf notifications are enabled
Product-Group=junos
Severity=Critical
On ACX7024, ACX710032C, and ACX7348 platforms running Junos OS Evolved, enabling netconf notifications with the command "set system services netconf notification" may cause a memory leak. This results in a control plane crash (vmcore). Forwarding plane remains unaffected.
1879816
Major
GNMI get native configuration garbage reply when there is no configuration related to openconfig
Product-Group=junos
Severity=Major
The native configuration is observed when there is no configuration related to openconfig but if there are configuration related to openconfig, the native config is not seen. This is just a corner case and no service impact is observed.
PR NumberSynopsisCategory: content filtering bugs
1927484
Critical
Traffic loss occurs due to high memory utilisation in UTM pools
Product-Group=junos
Severity=Critical
On Junos OS SRX platforms, configuring cache preload in web filtering causes high memory utilization in the UTM (Unified Threat Management) pool, which results in traffic loss.
PR NumberSynopsisCategory: MX10K linecard
1898825
Major
Unexpected line card restart due to timing condition
Product-Group=junos
Severity=Major
On Junos platforms using line cards LC480 and LC2101, a timing defect in the embedded microkernel thread handling logic causes a panic when a thread attempts to yield execution while interrupt processing is still active. This panic results in a line card reboot.
PR NumberSynopsisCategory: MX10K platform
1819263
Minor
The SNMP jnxFruRemoval/insertion trap OID is not being sent correctly when the FTC module or the fan tray module is inserted or removed
Product-Group=junos
Severity=Minor
On the MX10008 and PTX10008 platforms, when the Fan Tray Controller (FTC) or the fan tray is either removed or inserted, the device sends out SNMP traps with incorrect values (34 and 35) for the jnxFruRemoval and jnxFruInsertion OIDs. These values are not listed in Juniper's Management Information Base (MIB). This is a minor cosmetic issue.
PR NumberSynopsisCategory: VMHOST platforms software
1924890
Major
During vmhost upgrade or downgrade livirtd.conf file was not updated correctly
Product-Group=junosvae
Severity=Major
During update and downgrade of vmhost images the livirtd.conf cleanup entries had not been performed properly. See TSB103739 [juniper.net]. https://supportportal.juniper.net/s/article/VM-Host-system-will-fail-to-start-after-a-system-reboot-due-to-expired-Vcertificate
1927342
Minor
Junos VMhost platforms restart unexpectedly due to deadlock
Product-Group=junos
Severity=Minor
On all Junos VMhost platforms, when Junos performs disk access, a rare deadlock involving FreeBSD kernel processes will occur. This condition causes FreeBSD kernel panic, resulting in crash of vmcore and an unexpected device restart, leading to temporary system unavailability.
PR NumberSynopsisCategory: Virtual Private LAN Services
1806424
Major
The snmp mib walk on jnxVplsPwBindTable fails with vpls routing-instances having multiple mesh-groups
Product-Group=junos
Severity=Major
If VPLS mesh-groups are configured with different neighbours having different vpls-id the SNMP mib walk over jnxVplsPwBindTable might fail with the error Request failed: OID not increasing. No functional impact is seen due to this issue.
PR NumberSynopsisCategory: usf ams related issues
1913560
Major
Routing Engine restart on MX platforms with SPC3 line card could cause loss of traffic processing
Product-Group=junos
Severity=Major
On Junos MX960, MX240, and MX480 platforms using SPC3 service line cards, restarting the Routing Engine may result in the network security daemon (nsd) not starting or failing to program internal subsystems like service sets . When this occurs, the control plane becomes unavailable and traffic stops forwarding permanently. This is a timing related behavior observed during the boot sequence and does not appear on every restart.
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1925039
Major
Memory leak in ipv4-to-ipv6 session reuse trigger flowd crash
Product-Group=junos
Severity=Major
On Junos OS MX240/MX480/MX960 platforms with MX-SPC3 cards, the flowd process crash and reboots the service PIC when a stale IPv4 session is mistakenly reused for IPv6 due to a memory issue. During process restart the services remain down, session information is briefly lost and active traffic will drop, however the system recovers automatically.
PR NumberSynopsisCategory: PTX10016 platform software
1935026
Minor
IPv4 & BGP failure on AE interfaces when group-based static MAC is configured in dual-stack environment
Product-Group=junosvae
Severity=Minor
On Junos PTX1000, PTX1000260C, and QFX1000260C platforms, configuring a groupbased static MAC (Media Access Control) address on AE (Aggregated Ethernet) interfaces in a dualstack (IPv4 + IPv6) setup can result in IPv4 traffic forwarding failure following unexpected FPC (Flexible PIC Concentrator) events such as FPC crash, connection drop, or silent reboot. Because the static MAC is not correctly applied to the AE interface, the system continues to use a derived MAC address. This misconfiguration disrupts IPv4 forwarding and impacts routing protocol sessions.

 

Extended Solution

23.4R2-S8 - List of Known issues

PR NumberSynopsisCategory: "agentd" software daemon
1634372
Minor
[Platform] : Bugatti :Fabric : jnxFabricMib - Not updating Fabric Counts
Product-Group=junos
The fabric statistics counters are not displayed in the output of "show snmp mib walk ascii jnxFabricMib".

Resolved In:
1885622
Major
The aaasd process stops responding for RPC calls
Product-Group=junos
On all Junos and Junos Evolved platforms with gRPC configured, the aaasd process rejects incoming RPCs. This issue occurs in some rare cases, and aaasd will stop listening for authentication requests from reverse proxy. This issue does not cause a traffic impact.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:24.4X200-D10-EVO evo:24.4X200-D20-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO junos:24.2R2-S4 junos:24.2X1 junos:24.4R2-S3 junos:25.2R1-S1 junos:25.2R2
1886043
Major
Few telemetry paths are not exported after router reboot
Product-Group=junos
Following a router reboot, the router management socket, telemetry infrastructure, and RE daemons (such as mib2d and rpd) become operational before telemetry producers. Consequently, the external telemetry collector can establish a connection (e.g. sensor: "/interfaces" ; sample-mode) with the device as soon as the telemetry infrastructure and management interface are up and running. Since producers require several minutes to come up. Therefore, na-grpcd sends a consolidated initial sync completion message to the external collector based on the local init-sync responses from the telemetry producers present at telemetry subscription time (mostly RE based producers). When an application (evo-aftman-bt) becomes operational, a sensor is installed within it (if applicable).However, it is possible that the application has not consumed, thus not exported the interfaces data at the initial sync time (local to the application). As zero-suppression is activated after initial sync, a few statistics with a zero value will not be exported by the device.

Resolved In: evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:24.4R2-EVO evo:24.4X200-D20-EVO evo:24.4X200-D30-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.3R1 junos:25.4R1
1923848
Major
Junos Evolved platfrom, when gNMI collecting data from "optics/lanediags/lane/lane_laser_receiver_power_dbm" and "optics/lanediags/lane/lane_laser_output_power_dbm" are unreadable
Product-Group=junos
The JavaScript Object Notation (JSON) encoding of leafs of type "ieeefloat32"(https://github.com/openconfig/public/blob/master/release/models/types/openconfig-types.yang#L127) is not correct, causing gRPC Network Management Interface (gNMI) data outputs unreadable.

Resolved In: evo:22.3X80-D49-EVO evo:24.4R2-S4-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:24.2R2-S6 junos:25.2R2-S2 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: MX YT-ZF Linecards YT, MQSS, Pre-Classifier, HBM Driver Category
1839265
Minor
Resource Errors observed on PFE slices when egress is logical tunnel
Product-Group=junos
On all MX platforms, the Logical Tunnel (LT) back pressures the ingress interface with store resource errors if throughput exceeds 400Gbps per Packet Forwarding Engine (PFE) slice (200Gbps per LT interface).

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Border Gateway Protocol
1696328
Major
The rpd process will crash on all Junos and Junos OS Evolved platforms when BGP multipath is enabled
Product-Group=junos
The rpd process crash is observed on all Junos and Junos OS Evolved platforms with BGP multipath configuration.

Resolved In: evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S2-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:21.2R3-S7-J13 junos:21.2R3-S8 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3 junos:22.3X60 junos:22.4R2 junos:23.1R1 junos:24.2R2
PR NumberSynopsisCategory: MX Platform SW - UI management
1898722
Major
The craft-control process is unable to start on MX10004/MX10008 platforms
Product-Group=junos
On all Junos MX10004 and MX10008 platforms with FPM/craft interface, the craftd (craft control daemon) is unable to run, it causes the craft-control process does not start properly, leading the jnxAlarmRelayMode unable to retrieve data when an alarm condition is triggered. The issue does not cause traffic impact and only may affects monitoring traffic.

Resolved In: junos:24.4R2-S1 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: L2NG Access Security feature
1911142
Major
Client IP assignment failure observed on EX4300 due to DHCPv6 snooping validation issue
Product-Group=junos
On EX4300, DHCPv6 ( Dynamic Host Configuration Protocol for IPv6 ) clients will fail to receive IP addresses due to improper client entry handling when DHCPv6 snooping is enabled.

Resolved In: junos:21.4R3-S12
PR NumberSynopsisCategory: OpenSSH and related subsystems
1922002
Major
Major alarms showing SPMB1 not online on MX2008 will be seen on 24.2R1 and later releases
Product-Group=junos
On the Junos MX2008 VMhost platform with dual Routing Engines (REs), the backup SPMB {Switch Processor Mezzanine Board} (spmb1) fails to come online following a graceful switchover on releases starting when upgrading to releases starting from Junos 24.1. As a result, if the backup SPMB cannot boot, the traffic will be impacted during switchovers.

Resolved In: junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: EVPN ELAN/E-TREE
1882561
Major
EVPN-MPLS BUM Traffic Disruption Due to Incorrect QinQ STag Insertion
Product-Group=junos
On Junos OS ACX5448/ACX710 platforms, the traffic towards the MPLS (Multiprotocol Label Switching) core Provider Edge (PE), specifically BUM (Broadcast, Unknown Unicast, and Multicast) traffic, has a QinQ (802.1ad) Service Tag (STag) added to the Customer (CTag). This insertion can disrupt traffic forwarding, leading to malformed packets or corruption of the destination MAC address in the inner Ethernet header.

Resolved In: junos:24.4R2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Host path software for ACX platform
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1952112
Major
PICs fail to come online when multiple FPCs are repeatedly deleted and reassigned across GNFs due to an internal race condition
Product-Group=junos
On Junos OS MX Series platforms supporting Junos node slicing, when multiple FPCs are repeatedly deleted and reassigned across the same or different GNFs, an internal race condition will prevent system events related to FPC deletion and reassignment operations from being processed. As a result, PICs on the affected FPCs fail to come online and remain down, impacting traffic forwarding on interfaces hosted on those PICs.

Resolved In: junos:23.2R2-S7 junos:24.2R2-S6 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1919313
Major
The LDP session does not come up when an IPsec SA is configured under OSPFv3
Product-Group=junos
On Junos Evolved platforms, when Open Shortest Path First version 3 (OSPFv3) Internet Protocol Security (IPsec) SA is applied at the interface (IFD/IFL) level, Label Distribution Protocol (LDP) is able to discover the neighbor via User Datagram Protocol (UDP) Hellos, but fails to bring up the Transmission Control Protocol (TCP) session, preventing the LDP session from becoming operational. Disabling the OSPFv3 IPsec SA immediately restores normal LDP operation. During the service impact, the session will be down and traffic will not be send. Once the LDP session comes up, traffic can be routed through it.

Resolved In: evo:23.2R2-S7-EVO evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.2R2-S1-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO
PR NumberSynopsisCategory: EVPN control plane issues
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1924472
Minor
EVPN all-active not working in multi-homed setup when router-id not explicitly configured
Product-Group=junos
On Junos OS and Junos OS Evolved platforms, if the router-id is not explicitly configured, the device dynamically selects a router-id during bootup. In this scenario, the device advertises EVPN (Ethernet Virtual Private Network) Type1 AD/ESI (AutoDiscovery/Ethernet Segment Identifier) and Type4 ES RT (Ethernet Segment Route Target) routes with a Route Distinguisher (RD) of 0:0. As a result, Route Targets (RTs) advertised by different Provider Edge (PE) routers end up having identical prefixes. Consequently, only one PE routers RT is advertised and learned. This behavior prevents EVPN all-active redundancy resulting in the loss of multihoming.

Resolved In: evo:26.3R1-EVO
PR NumberSynopsisCategory: EX interfaces issues
1923212
Major
PFE process crash occurs during EX4k boot-up
Product-Group=junos
On EX4400/4100 platforms, PFE process (fxpc) crash occurs with a segmentation fault (SIGSEGV) during device boot-up. The crash occurs during the Broadcom PHY firmware broadcast download sequence when initializing the external PHY. No service impact as this crash happens at initial boot cycle.

Resolved In: junos:24.2R2-S6 junos:25.4R2 junos:26.2R1 junos:26.2R2
PR NumberSynopsisCategory: FIPS related issues
1905490
Major
On MX10003 with FIPS enabled, KATs failure in SMIC_QSFP28_MACSEC_TIC causes system halt
Product-Group=junos
In Junos, MX10003 platforms with Federal Information Processing Standards (FIPS) enabled experience repeated halts due to Known Answer Test (KATs) failures in the SMIC_QSFP28_MACSEC_TIC crypto path.

Resolved In: junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1762490
Minor
JDI-RCT-MPC10E: Ksyncd crash on backup RE after fpc reboot
Product-Group=junos
On MX series, when PS over RLT is configured where all member LTs are hosted on the same FPC and user restarts this FPC then on rare occasion, ksyncd crash can occur on backup RE. However, there is no impact on the master and only backup RE is affected. This issue is not consistent and seen only once out of ~10 or 15 fpc restart operations.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1933452
Major
ICMP ping with higher MTU size fails in VPLS when IRB MTU exceeds MPLS core MTU
Product-Group=junos
On all Junos OS platforms, configured with VPLS (Virtual Private LAN Service) and IRB (Integrated Routing and Bridging ) interfaces, when the MTU (Maximum Transmission Unit) configured on the IRB or CE interface is larger than the MPLS ( Multiprotocol Label Switching ) core interface MTU (including MPLS label overhead), ICMP Echo Request (ping) packets with higher packet sizes fail.

Resolved In: junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: jdhcpd daemon
1776072
Major
Device fails to resolve names due to Domain Name Resolution entries are deleted when applying commit command
Product-Group=junos
On all Junos platforms with Dynamic Host Configuration Protocol (DHCP) client configured, when ephemeral database commit or commit is applied, Domain Name System (DNS) entries previously received from the DHCP server are deleted, causing device to fail DNS resolution.

Resolved In: evo:22.2R3-S3-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:22.4R3-S1-EVO evo:24.1R1-EVO junos:21.4R3-S6 junos:21.4R3-S6-X1 junos:21.4X7 junos:22.1R3-S6 junos:22.2R3-S3 junos:22.2R3-S7 junos:22.3R3-S3 junos:22.3X60 junos:22.4R3 junos:22.4R3-S1 junos:22.4X3 junos:23.2R2 junos:23.4R1-S1 junos:23.4R2 junos:24.1R1
1934742
Major
DHCPv6 Relay Active Leasequery not able to establish TCP session to peer
Product-Group=junos
On all MX platforms, when configuring Dual Stack DHCPv6 ALQ without configuring DHCPv4 ALQ (active-leasequery), the ALQ will not be able to establish the TCP (Transmission Control Protocol) session for the ALQ peer due to XID (Exchange Identification) mismatch. This can lead to DHCPv6 subscriber bindings sync issue and server ALQ, resulting in compromising the redundancy functionality.

Resolved In: junos:23.4R2-S7-J21 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1930403
Major
SIP calls may not function properly in the SIP ALG application on MX-SPC3 and SRX platforms
Product-Group=junos
On MX platforms with SPC3 line-cards/ SRX platforms, when there are bandwidth attributes carried in SDP(Session Description Protocol) messages inside SIP(Session Initiation Protocol) packets, SIP application traffic and SIP calls get impacted.

Resolved In: junos:19.2R3-S12 junos:19.3R3-S13 junos:23.2R2-S8 junos:24.2R2-S6 junos:24.4R2-S4 junos:24.4R2-S5 junos:25.2R2 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Flow Module
1834338
Major
GRE traffic is getting blocked due to a software programming issue and MTU going below minimum value
Product-Group=junos
On Junos OS SRX platforms with GRE (Generic Routing Encapsulation) configured, due to a software programming issue, some threads have incomplete information while processing the data and even if "no-path-mtu-discovery" or "no-gre-path-mtu-discovery" is configured, the MTU going below minimum value (IPv4- 578, IPv6 1280) resulting in the GRE traffic being blocked i.e. complete traffic impact.

Resolved In: junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1873580
Major
The TCP session is not closing properly on the SRX4600 and SRX5K platforms after receiving the FIN-ACK message causing packets to drop for new session if reusing same source port
Product-Group=junos
On SRX4600 and SRX5K platforms, when IDP (Intrusion Detection and Prevention) is configured in global policy, TCP (Transmission Control Protocol) sessions are not closing immediately after receiving the final FIN-ACK (finish-acknowledgement) message. If one end has initiated TCP session close by sending FIN packet and other end has sent an acknowledgement of FIN, IDP ignores the TCP session during processing of ACK packet as policy which accepts TCP packet is not configured with IDP application service. If other end device is reusing the same source port to initiate new connections, device drops because the existing session is still active.

Resolved In: junos:24.2R2-S4 junos:24.4R2 junos:25.2R1 junos:25.3R1
1892890
Minor
SRX drops to-the-box ICMPv6 echo request with sequence number 3503 and 35000 through 35999
Product-Group=junos
On all SRX platforms, to-the-box ICMPv6 echo request with sequence number 3503 and 35000 through 35999 will be dropped

Resolved In: junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: SRX Datapath Multicast Solution
1899131
Major
Multicast packets are getting dropped when multicast is configured in strict-ordering mode
Product-Group=junos
On Junos OS SRX1600 platforms, when multicast is configured in strict-ordering mode, and certain threads are dedicated to processing multicast traffic, some multicast packets get dropped. This occurs due to the way the system handles message processing in this configuration, which can impact multicast traffic forwarding.

Resolved In: junos:24.4R2-S3 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Firewall Policy
1939433
Major
Flow sessions not synchronizing from primary to backup in SRX High Availability clusters
Product-Group=junos
On SRX devices operating in a High Availability cluster with logical-systems enabled, the backup node may display fewer flow sessions than the primary node due to incomplete flow session synchronization. Sessions that do not synchronize to the backup node are lost during a failover, resulting in service interruption for the affected flows.

Resolved In: junos:23.4R2-S7-J20 junos:23.4R2-S7-J9 junos:25.2R2-S1 junos:25.4R1-S3 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1850526
Major
IPSEC tunnel distribution table on the RE is not cleaned up hitting SRXPFE coredump eventhough DPD is configured.
Product-Group=junos
Generic MNHA issue not specific to CSDS

Resolved In: junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1864758
Major
Post reboot , IPSec VPN is not coming up over MNHA active/active deployment
Product-Group=junos
On all SRX platforms with the new IKE daemon (iked) enabled in an MNHA (Multinode High Availability) active active setup, with the IKE gateway is configured to use the loopback (lo0) interface with the node-local knob enabled, Internet Protocol Security (IPsec) VPN will not come up after a reboot.

Resolved In: junos:23.2R2-S4 junos:24.2R2-S6 junos:24.4R1-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Label Distribution Protocol
1852934
Major
The rpd process crash is seen during RE switchover
Product-Group=junos
On Junos and Junos OS Evolved dual RE (Routing-Engine) platforms with LDP (Label Distribution Protocol) configuration, an rpd process crash in the new master RE is observed during a RE switchover.

Resolved In: evo:25.3R1-EVO junos:25.3R1
1906611
Major
Crash in the rpd process after LDP P2MP LSP Identifier reaches its maximum value and rolls over, due to duplicate identifier allocation
Product-Group=junos
On all Junos OS and Junos OS Evolved versions that support Label Distribution Protocol Point-to-Multipoint Label Switched Paths (LDP P2MP LSPs), the rpd process (routing protocol daemon) crashes when an LSP Identifier reaches its 24-bit maximum value (224 1 = 16, 777, 215) and rolls over to the starting value because a duplicate identifier is incorrectly allocated. This condition occurs only after prolonged tunnel flapping (typically more than 16 million flaps). When the rpd process crashes, routing convergence is briefly disrupted, and services relying on label-switched traffic are impacted until the process automatically restarts.

Resolved In: evo:26.1R1-EVO junos:26.1R1
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1805723
Major
The system doesn't become GRES ready after performing GRES
Product-Group=junos
On all Junos platforms during GRES the CPU utilization might reach 100% for smid & alarmd processes and the system is not becoming GRES ready with error "the replication-process subsystem is not responding to management requests". Every GRES requires the license-check daemon to establish a new connection with the feature daemon. The gRPC client (feature daemon) was sending RPC requests and waiting for responses while the gRPC server (license-check daemon) was down during GRES. If the client doesn't receive a response within the specified deadline (30 seconds), it should return a gRPC queue timeout type and success value as 0, but it got stuck in getting the "grpc_core:: Timestamp:: Now ()" API.

Resolved In: junos:23.2R2-S7 junos:24.2R2 junos:24.4R1
1925706
Minor
Snmp license polling cause license-check service crash
Product-Group=junos
On Junos platforms, a race condition occurs when the Simple Network Management Protocol (SNMP) poller attempts to retrieve device license information while subscriber management and SNMP policing features are in use. This condition causes the license-check process to encounter a null pointer and generate a core dump. There is no traffic or service impact. However, license information retrieval through SNMP polling fail until the license-check service recovers.

Resolved In: evo:24.2R2-S5-EVO evo:25.2R2-S1-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: MPC11 ULC platform software related issues.
1809351
Major
JDI-RCT:M/Mx: ISIS session over MPC11 cards flapped due to "3-Way handshake failed" during ISSU (FRU upgrade stage - reboot phase)
Product-Group=junos
JDI-RCT:M/Mx: ISIS session over MPC11 cards flapped due to "3-Way handshake failed" during ISSU (FRU upgrade stage - reboot phase)

Resolved In:
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1902405
Major
The rpd process crash is observed with MVPN and RIB sharding enabled
Product-Group=junos
On Junos MX and Junos Evolved PTX platforms , with RIB sharding enabled and if either IPv4 or IPv6 address family is disabled in MVPN (multicast virtual private network), the unicast route flow from shard tries to access MVPN data structures without validation leading to rpd (Routing Protocol Daemon) process crash.

Resolved In: evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2-J2 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1908581
Major
Significant multicast traffic loss observed during ISSU in Next-Generation Multicast VPN (NGMVPN) deployments
Product-Group=junos
On all Junos platforms that support both InService Software Upgrade (ISSU) and NextGeneration Multicast VPN (NGMVPN), multicast traffic loss can occur during an ISSU operation when NGMVPN deployments use both the Inclusive Provider Multicast Service Interface (IPMSI) and the Selective Provider Multicast Service Interface (SPMSI) with a nonzero threshold. During the ISSU process, Flexible PIC Concentrators (FPCs) upgrade and synchronize, and multicast statistics may briefly report zero. This event causes withdrawal of the SPMSI and a fallback to the IPMSI. If the IPMSI next hops are not fully programmed at that moment, a temporary interruption of SPMSI flows occurs, while IPMSI flows continue forwarding normally. The traffic loss duration is short and typically limited to a few seconds to a few minutes during FPC upgrade cycles, not exceeding the expected ISSU convergence window. Both IPv4 and IPv6 multicast traffic are affected.

Resolved In: evo:26.2R1-EVO junos:26.2R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
The management interface is unreachable post switchover/RPD restart events
Product-Group=junos
On all Junos platforms with management interface em0/fxp0 disabled, the management port remains unreachable after performing RE switchover or rpd restart events and re-enabling the management port.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: Wind River Linux Distribution issues in NG-RE
1911820
Major
Device getting stuck in boot phase during upgrade because of expired libvirt certificate
Product-Group=junos
On Junos platforms running the VMHOST system, devices are getting stuck in the boot phase during an upgrade because of expired libvirt certificate. See https://kb.juniper.net/TSB103739 [juniper.net]

Resolved In: junos:20.3X75-D442 junos:20.3X75-D46 junos:20.3X75-D52 junos:22.3X60 junos:22.3X60-J3 junos:22.3X60-J4 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4R3-S9 junos:22.4X50 junos:22.4X8
PR NumberSynopsisCategory: Protocol Independant Multicast
PR NumberSynopsisCategory: Issues related to PKI daemon
1919729
Major
SRX 2300 SRX 4700 SRX4300 and SRX1600 Enter System Halt or Amnesiac State After Reboot When TPM/MEK is Enabled
Product-Group=junos
On SRX4300, SRX 4700, SRX2300 , SRX1600 platforms When Master password and Master Encryption Key is set on the device and rebooted , the system was getting into amnesiac state.

Resolved In: junos:24.2R2-S5 junos:24.4R2-S4 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: QFX analyzer, sflow
1850213
Minor
L3 multicast traffic not forwarded when multi-homing node is acting as source in VXLAN
Product-Group=junos
When Group Based Policy (GBP) is enabled on Junos OS and Junos OS Evolved, Layer 3 multicast traffic originating from a Multi-homing (MH) source node is not forwarded.

Resolved In: junos:24.2R2-S1 junos:24.4R2-S1 junos:25.2R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1783397
Major
The fxpc process crash and the device reboots after deleting Aggregated Ethernet (AE) Interface along with its associated physical interface and then applying new interface configuration on the associated physical interface in an EVPN-VXLAN scenario
Product-Group=junos
On an Ethernet Virtual Private Network (EVPN) / Virtual eXtensible Local-Area Network (VXLAN) scenario, after removing an Aggregated Ethernet (AE) Interface along with its associated physical interface on a QFX5k series device and then applying any configuration to the physical interface, the fxpc process crashes and the device undergoes an automatic reboot.

Resolved In: junos:21.4R3-S7 junos:22.1R3-S6 junos:22.2R3-S3 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R2 junos:23.4R1-S1 junos:24.1R1 junos:24.2R1 junos:24.2R2
1939298
Major
Traffic drop is seen due to tagged IRB L3 interface with native-vlan and vlan members
Product-Group=junos
On all Junos OS QFX5K and EX4k platforms, configuring a native VLAN along with VLAN members on an underlay Integrated Routing and Bridging (IRB) Network-to-Network Interface (NNI) that carries VxLAN (Virtual Extensible LAN) traffic results in the VLAN tag not being stripped as expected. Instead of treating the native VLAN traffic as untagged, the interface adds the VLAN tag, leading to packet drops at the remote end.

Resolved In: junos:21.4R3-S13 junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
1950531
Major
VXLAN Traffic Loss Can Occur When Multiple OSPF Underlay Peerings Are Configured on Logical Interfaces Over the Same Physical Port
Product-Group=junos
On JUNOS-based QFX5K and EX4K platforms, configuring multiple OSPF underlay peerings using separate logical interfaces (IFLs) over the same physical interface (IFD) may lead to VXLAN traffic loss when one of the peerings goes down. Due to a hardware limitation, the platform maintains a single active next-hop per physical interface. If one OSPF adjacency fails and its forwarding entry is removed, forwarding information associated with the physical interface may also be cleared, potentially impacting VXLAN traffic forwarding.

Resolved In:
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1938876
Major
Incorrect interface mode leading to 100G Link Flaps on QFX5210-64C
Product-Group=junos
On Junos OS QFX5210-64C platform, 100G optics inherently operate in CAUI-4 (Chip-to-Module 100 Gb/s Four-Lane Attachment Unit Interface) mode, which is automatically selected by the system and not user-configurable; mismatches due to software versions leading to link instability or flapping.

Resolved In: junos:21.4R3-S13 junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1938921
Major
Software rollback may cause device to become unresponsive on Junos platforms with qfx-5e image
Product-Group=junosvae
On Junos platforms running qfx-5e image, the device fails to boot after issuing the command "request system software rollback". Once the issue occurred, the system gets hung and the CLI becomes unresponsive, as a result both control plane and forwarding plane traffic will be impacted.

Resolved In: junos:21.4R3-S13 junos:24.2R2-S5 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: RPD Interfaces related issues
1741485
Major
Unnecessary rsync messages causing issues
Product-Group=junos


Resolved In: evo:24.1R1-EVO junos:24.1R1
1905553
Minor
Redundant prefix information is included within one router-advertisement packet when configuring accept-data in VRRPv6
Product-Group=junos
When configuring accept-data in VRRPv6, two entries for the same prefix value are included within one router-advertisement packet on all Junos platforms.

Resolved In: evo:25.4R1-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1851629
Minor
Next-hop APIs to support LDP stitching cases over BGP routes pointing to list of indirects
Product-Group=junos
On all Junos and Junos Evolved platforms this is an enhancement for Nexthop APIs to support LDP stitching cases over BGP routes pointing to list of indirects next-hops.

Resolved In: evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.4DCB
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:24.4R2-S2-J8 junos:24.4R2-S3 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1 junos:25.4R2 junos:26.1DCB
PR NumberSynopsisCategory: Resource Reservation Protocol
1881609
Minor
RSVP hello messages uses secondary address when primary/preferred address are present for same interface
Product-Group=junos
On all Junos and Junos OS Evolved platforms where RSVP (Resource Reservation Protocol) configuration is present and a RSVP enabled interface has 2 IP address of which one is configured as primary/preferred in that case the RSVP Hello message uses the secondary IP address to form neighborship.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Scuba interfaces software
1816148
Major
PFE crash is observed due to PCIE link was down
Product-Group=junos
The core dump was seen while PIC was going down.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2 junos:24.4R1 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: SRX branch platforms
1913911
Major
ARP reply packets may be sent out from the STP blocked port
Product-Group=junos
On SRX300-series devices, when ethernet-switching is used with spanning-tree protocol enabled, in some cases ARP reply packets may be sent out from a spanning-tree blocked port.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S7 junos:23.4X11 junos:24.2R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1848740
Critical
Support FW_Continue with HW Segmented Filters on AFT TRIO platform
Product-Group=junos
This PR is a performance optimization PR for AFT Trio-based systems. Software Segmented Firewall enables FLT support for a maximum of 3584 terms, this PR adds support for HW segmented filter with support to up to a maximum of 8192 terms and better performance than the software segmented filters.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1874097
Minor
Telemetry is not reporting statistics for an IRB interfaces
Product-Group=junos
On Junos OS Evolved and MX platforms with MPC10E/MPC11E/LC9600 line cards, MX304 and EX9k with EX9200-15C line cards , telemetry is not reporting statistics for the IRB (Integrated Routing and Bridging) interfaces, even though they are up and running.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J15 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1887866
Minor
Incorrect uSID handling in SRv6-TE will impact the traffic path
Product-Group=junos
On MXxxx platforms with FPCs such as MPC7E/MPC8E/MPC9E/MPC10E/MPC11E/LC9600/LC480/LC4800/LC2101/LC2103 and with SRv6-TE (Segment Routing IPv6-Traffic Engineering) configured, the uSID (micro SID(Segment Identifier)) will incorrectly replace the entire last container segment instead of only the last SID. When this happens, packets will not follow the configured SRv6-TE path, which will lead to issues like missing hops in the path or packet loss.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2-S4 junos:25.2R2 junos:25.3R1 junos:25.4R1
1902144
Major
[MFT2.0] : 100% traffic loss for l3vpn resolving over BGP-CT routes
Product-Group=junos
In BGP-CT scenario at ASBR instead of swap operation, we have a pop and push NH programmed which results in pops the transport and service label and then pushes only transport label. Due to this service label is lost and once it reaches Penultimate Hop Router we pops (PHP) the transport label and sends plain IP packet and because service label is lost the DUT is unable to identify the VRF and results in default route reject.

Resolved In:
1927194
Major
When a resolution for an IPv4/IPv6 address fails, NH IFL is throttled causing service impact
Product-Group=junos
In MX uKern and AFT based cards, NH IFL throttling will be seen when resolution for an destination IPv4/IPv6 address fails.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:22.3R3-S5 junos:23.2R2-S7 junos:23.4R2-S7-J16 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1798178
Minor
IS-IS Level 2 disabled after upgrade due to OpenConfig YANG model change
Product-Group=junos
On Junos and Junos Evolved platforms that support OpenConfig IS-IS configuration, upgrading to a release where the enabled leaf under the IS-IS levels hierarchy (levels/level/config/enabled) has been deprecated may cause IS-IS Level 2 adjacencies to be disabled during configuration load via load override. This behavior is due to the deprecated YANG model leaf being processed incorrectly during load operations, resulting in Level 2 being automatically disabled and impacting inter-area routing. Configurations applied using manual set commands are not affected.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1818692
Major
Configuration commit fails due to mustd process crash
Product-Group=junos
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP

Resolved In: evo:21.4R3-S9-EVO evo:22.2R3-S6-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:23.4X100-D21-EVO evo:23.4X100-D30-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.2X32-D30 junos:21.2X33 junos:21.2X35 junos:21.2X40 junos:21.2X9 junos:21.4R3-S9 junos:21.4X30 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.3X60 junos:22.4R3-S5 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S3 junos:23.4X30-D30 junos:24.2R1-S1 junos:24.2R2 junos:24.2X1 junos:24.4R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1735584
Minor
Execution of get-directory-usage-information RPC on yang based client or controller fails with validation error
Product-Group=junos
Execution of get-directory-usage-information RPC on yang based client or controller fails with validation error

Resolved In:
1914952
Minor
The error message will be seen on CLI when 'clear log messages' command is issued
Product-Group=junos
On Junos platforms with BSD6 image, Error message will be seen on CLI when clear log messages command is issued.

Resolved In: evo:25.2R2-EVO evo:26.1R1-EVO junos:21.4R3-S13 junos:22.3X60 junos:23.2R2-S6 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:26.1R1
PR NumberSynopsisCategory: Issues related to NETCONF
1800859
Minor
Configuration push to device using RPC resulted in incorrect policy order
Product-Group=junos
On all Junos and Junos OS Evolved platforms, RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.

Resolved In: evo:21.4R3-S9-EVO evo:22.2R3-S7-EVO evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:22.4R0-J0-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R1-S1-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.2X32-D30 junos:21.2X33 junos:21.2X35 junos:21.2X40 junos:21.2X9 junos:21.4R3-S9 junos:21.4X30 junos:22.2R3-S7 junos:22.3R3-S5 junos:22.3X60 junos:22.4R3-S5 junos:22.4R3-S7 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S3 junos:23.4X30-D30 junos:24.2R1-S1 junos:24.2R2 junos:24.2X1 junos:24.3R1 junos:25.1R1
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
1803967
Major
While validation XML response for CLI "show system storage" we see ODL validation failure
Product-Group=junos


Resolved In: junos:23.2R2-S5 junos:24.2R2-S3 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: QFX RCB issues
1763588
Major
Warn if insufficient space to save unbundled packages during vm image upgrade
Product-Group=junos
If while preparing for replacement of a vm image, there is insufficient space to save copies of unbundled packages, issue a warning.

Resolved In: junos:19.1R3-S11 junos:19.2R3-S8 junos:19.3R3-S9 junos:19.4R3-S13 junos:20.2R3-S9 junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S8 junos:21.2X33 junos:21.2X34 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.3X60 junos:22.4R3-S1 junos:23.2R1-S2 junos:23.2R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: PTX/QFX10002/8/16 specific software components
1882584
Minor
SIB FPC link errors observed on platforms using JNP10008-SF modules due to power rail instability
Product-Group=junos
On Junos OS PTX10008/QFX10008/MX10008 platforms with JNP10008-SF cards , the systems experience Cycle Redundancy Check (CRC) errors on fabric links between the Switch Interface Board (SIB) and the FPC (Flexible PIC Concentrator). In some cases, these errors are attributed to electrical noise on an internal power rail within the SIB. This condition will lead to multiple FPC-to-SIB link failures, affecting traffic forwarding and overall fabric stability.

Resolved In: junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4X50
PR NumberSynopsisCategory: VMHOST platforms software
1795506
Minor
A non service impacting warning message 'Failed to set 'memory.limit' will be observed
Product-Group=junos
On all Junos OS Evolved platforms a warning message "Failed to set 'memory.limit_in_bytes' attribute on '/user.slice' to '-1': Invalid argument" would be observed.

Resolved In: evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:24.2R1-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2X1 junos:24.4R1
PR NumberSynopsisCategory: Virtual Private LAN Services
1882938
Major
In VPLS scenario due to ungraceful switchover rpd process crash is observed
Product-Group=junos
On Junos OS and Junos OS Evolved platforms with VPLS (Virtual Private LAN Service) configured, during an ungraceful GRES (Graceful Switchover) switchover with NSR enabled, an issue with VPLS label replication will cause a mismatch, resulting in an rpd (Routing Protocol Process) crash.

Resolved In: evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S2-J17 junos:24.2R2-S4 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Windsurf fabric software
1835860
Major
Fabric plane goes into check state and alarm is consistently seen along with traffic drop when ADC based line cards are restarted on certain MX platforms
Product-Group=junos
On MX2010/MX2020 platforms having adapter cards MPC7E and MPC5E with SFB3 (Switch Fabric Boards), the alarm "Check plane * Fabric Chip" is seen when both the ADC cards are restarted, which then causes a fabric link error on the adjacent ADC slot. As a result, traffic drop is observed for FPC (Flexible Physical Interface Cards Concentrators)/PFE (Packet Forwarding Engine) plane combination for which the error is reported.

Resolved In: junos:21.2R3-S8-J6 junos:21.2R3-S9 junos:21.2X35 junos:23.2R2-S3 junos:23.4R2-S3-J6 junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

Resolved In: evo:25.4R1-EVO junos:19.1R3-S15 junos:19.2R3-S12 junos:19.3R3-S13 junos:20.2R3-S11 junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: PTX10016 platform software
1935026
Minor
IPv4 & BGP failure on AE interfaces when group-based static MAC is configured in dual-stack environment
Product-Group=junos
On Junos PTX1000, PTX1000260C, and QFX1000260C platforms, configuring a groupbased static MAC (Media Access Control) address on AE (Aggregated Ethernet) interfaces in a dualstack (IPv4 + IPv6) setup can result in IPv4 traffic forwarding failure following unexpected FPC (Flexible PIC Concentrator) events such as FPC crash, connection drop, or silent reboot. Because the static MAC is not correctly applied to the AE interface, the system continues to use a derived MAC address. This misconfiguration disrupts IPv4 forwarding and impacts routing protocol sessions.

Resolved In: junos:22.4R3-S10 junos:23.4R2-S8