Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

SRX platforms running Junos software

Alert Description

Junos Software Service Release version 24.4R2-S4 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 24.4R2-S4 is now available.

24.4R2-S4 - List of Fixed issues

PR NumberSynopsisCategory: SRX Fleming Platforms related issues
1927758
Critical
HA failover not triggered after PFE process crash in HA deployments (Chassis Cluster / MNHA) on SRX1600/2300/4300/4700
Product-Group=junosvae
Severity=Critical
On SRX1600/2300/ 4300/4700 platforms configured in HA mode (Chassis Cluster or MNHA), when a PFE (Packet Forwarding Engine) process crash occurs on the active node, HA failover is not triggered because the failure condition is not detected by the HA subsystem. This can lead to traffic disruption and service outage.
PR NumberSynopsisCategory: Accounting Profile
1914977
Minor
Whenever a client(eg lacp/ifinfo/snmp) requests statistics from PFE, the query is routed via the kernel and not through the use of the BULKGET protocol
Product-Group=junos
Severity=Minor
On specific VMHost platforms. Whenever a client (e.g., lacp/ifinfo/snmp) requests statistics from PFE, the query is routed via the kernel and not through the use of the BULKGET protocol.
PR NumberSynopsisCategory: "agentd" software daemon
1779722
Minor
The interface fails to come up after FPC reboot if the streaming server and export profile are not configured correctly
Product-Group=junos
Severity=Minor
On all Junos and Junos evolved platforms with telemetry enabled, if the streaming server and export profile for reporting-rate are not properly configured in the analytics settings, rebooting the FPC would prevent any of the interfaces from coming up.
1913260
Major
Discrepancy noticed in the interfaces when there is a reset in Linecard or PFE
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, with an established telemetry session with multiple collectors, there will be interface statistics discrepancy when there is a linecard OIR event or PFE offline/online sequence.
1919448
Major
Heavy traffic flow causing SWAN agent to disconnect from the clients
Product-Group=junos
Severity=Major
In all Junos and EVO platforms, a gRPC connection between the SWAN (Software Wide Area Network) agent and the device is being closed unexpectedly. While SWAN client/JET(Juniper Extension Toolkit) client is connecting and sending data close to 3K(3000) routes at 8KB Per RPC (Remote Procedure Call) over the connection, they can hit rare race condition which can cause the clients to disconnect.
1923848
Major
Junos Evolved platfrom, when gNMI collecting data from "optics/lanediags/lane/ lane_laser_receiver_power_dbm" and "optics/lanediags/lane/ lane_laser_output_power_dbm" are unreadable
Product-Group=junos
Severity=Major
The JavaScript Object Notation (JSON) encoding of leafs of type "ieeefloat32"(https://github.com/openconfig/public/blob/ master/release/models/types/openconfig-types.yang#L127) is not correct, causing gRPC Network Management Interface (gNMI) data outputs unreadable.
1929823
Major
The sysd process crashes with error logs upon exceeding its memory limit
Product-Group=junos
Severity=Major
On Junos OS Evolved platforms with telemetry streaming configured, the sysd (System Daemon) process crashes on the backup RE (Routing Engine), and error logs are observed when sysd memory usage continues to grow over time, and the memory limit is exceeded. This issue is observed when the 64-bit sysd consumes more memory than the configured system limit when the device has been running for a long time (typically more than 100 days) in the dual RE scenario.
PR NumberSynopsisCategory: MX YT-ZF Linecards YT, MQSS, Pre-Classifier, HBM Driver Category
1948588
Minor
Intermittent fabric errors causing traffic loss due to line card PLL lock loss.
Product-Group=junos
Severity=Minor
On certain MX Series and SRX Series platforms running Junos, an intermittent PLL (Phase-Locked Loop) lock loss on certain line cards leads to fabric link errors. When the issue happens, forwarding plane traffic across the chassis fabric is impacted, resulting in partial or complete traffic loss.
PR NumberSynopsisCategory: BBE routing
1922536
Major
Forwarding issues for an access DHCPv6-PD or access-internal DHCPv6-IA route or both may be seen on LNS due to an incorrect route programming of such route on PFE
Product-Group=junos
Severity=Major
Drop of traffic to subscriber DHCPv6 prefixes may be observed on LNS (L2TP network server) if CPE uses IPv6 address obtained via NDRA process as the source address for DHCPv6 negotiation instead of link-local address.
PR NumberSynopsisCategory: Border Gateway Protocol
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
Severity=Major
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.
1880630
Major
Some BGP sessions remain in the Idle state after all interfaces are deactivated and rollback is issued
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, after all the interfaces are deactivated and the rolled back, some BGP sessions stay in Idle state. This will impact the traffic.
1889749
Critical
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.
1915893
Major
The rpd process crash triggered by LLGR stale timer expiry and late reconnection of unconfigured BGP peer on helper node
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved, when Long-Lived Graceful Restart (LLGR) is configured and a Border Gateway Protocol (BGP) neighbor goes down and reconnects after the LLGR stale timer expires, the Routing Protocol Daemon (rpd) process crashes leading to service disruption.
1935730
Major
BGP session teardown due to incorrect 'prefix-limit maximum exceeded' error when RIB sharding is enabled
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when prefix-limit or accepted-prefix-limit is configured under family route-target with rib-sharding, prefix-limit will be incorrectly reported as 'prefix-limit maximum is exceeded'. This causes the BGP session to go down immediately. This occurs because the system incorrectly counts each received route multiple times (once for the main thread and once for each shard)
PR NumberSynopsisCategory: BGP BMP Software
1908215
Minor
BMP traces continues to fill the trace file even after removing BMP traceoptions configuration
Product-Group=junos
Severity=Minor
On all Junos OS and Junos OS Evolved platforms, enabling BMP(BGP Monitoring Protocol) tracing with local-rib monitoring continues to fill the trace file even after removing BMP trace option Configuration it is still running this on a cRPD instance, this creates a risk of the space exhaustion on a host that contains other production cRPDs.
PR NumberSynopsisCategory: Track PRs in BGP Flow Spec area & is part of BGP inside RPD.
1945627
Minor
BGP IPv6 Flow Specification Session Flapping When inet6-flow Is Enabled
Product-Group=junos
Severity=Minor
In certain Junos OS releases, BGP sessions may repeatedly reset when IPv6 Flow Specification (inet6-flow) is enabled. This behavior occurs when the router receives specific IPv6 Flow Specification updates that include a default (wildcard) match. Earlier releases do not exhibit this behavior, leading to a difference in observed stability when upgrading.
PR NumberSynopsisCategory: bras licensing prs
1836179
Major
The smid process restarts as BBE daemons and libraries use incorrect license
Product-Group=junos
Severity=Major
On Junos MX OS platforms, the use of an incorrect license by BBE (Broadband Edge) daemons and libraries leads to the smid process consuming 100% CPU (Central Processing Unit), which causes the smid (Subscriber Management Infrastructure Daemon) to restart and results in memory corruption.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for cos
1933096
Major
smpc_re core crash is seen during PPPoE subscriber login when CoS is configured on AE interface
Product-Group=junos
Severity=Major
On all MX platforms with MS-MPC/MPC-3D and MPC1-MPC13E line cards, when Class of Service (CoS) is configured on an Aggregated Ethernet (AE) interface, a crash is observed in the smpc_re process during PPPoE subscriber login attempts. Subscriber management services will be impacted.
PR NumberSynopsisCategory: Device Configuration Daemon
1916208
Major
Traffic drops due to VLAN configuration not updated for Ethernet-Switching Interfaces
Product-Group=junos
Severity=Major
On Junos OS platforms in which VLAN information can be given as a VLAN member name, if both VLAN (Virtual Local Area Network) IDs and VLAN member names are configured together on an interface within a routing instance, the VLAN membership does not update correctly on that interface, resulting in traffic impact associated with that VLAN.
PR NumberSynopsisCategory: Firewall Filter
1903874
Major
[MX10008] cmd='ls -i /var/etc/filters/filter-define.conf' is logged every 1 second instead of every 30 seconds
Product-Group=junos
Severity=Major
An issue where client sessions were not cleared on a router/switch, leaving stale session data that triggered immediate timeout handling instead of the expected 30?second delay. This caused once?per?second master?data lookups and repeated log entries such as "ls -i /var/etc/filters/filter-define.conf", but had no functional impact.
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1903922
Minor
Latency and packet loss noted to inet circuits after upgrading to 24.4R1-S3.6
Product-Group=junos
Severity=Minor
When MTU set as 1500, transient packets were redirected to the host path instead of being forwarded directly. Thus causing ping latency.This issue was observed after the changes introduced in PR1775703 and the changes are committed in 24.1. All the releases after 24.1 will face the issue, previous releases will not have any issue.
PR NumberSynopsisCategory: Dynamic rendering infrastructure
1915225
Major
cli-pfe does not terminate immediately when user issues Ctrl-C
Product-Group=junos
Severity=Major
A cli-pfe show command may continue to gather data in the background after the user issues a Ctrl-C. Eventually the background command will complete. However, the CPU usage for the cli-pfe process will continue to be high while it is still running.
PR NumberSynopsisCategory: JUNOS Dynamic Profile Configuration Infrastructure
1930036
Major
High memory usage is showing, when we configure unsupported licensing feature
Product-Group=junos
Severity=Major
On all Junos EX and QFX platforms operating in an EVPN (Ethernet Virtual Private Network) environment, this issue occurs when the CLI command 'licensing hourly update' is executed on a device that does not support the licensing feature.
PR NumberSynopsisCategory: eventd, syslog infra issues
1919638
Major
Certain Junos EVO applications may become unresponsive during trace file rotation
Product-Group=junos
Severity=Major
On Junos EVO platforms, frequent trace file rotation may cause certain EVO applications to become unresponsive.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1954021
Minor
CLI session timeout clears terminal scroll back
Product-Group=junos
Severity=Minor
On all Junos OS Evolved platforms, when a CLI(Command Line Interface) session times out, it triggers a terminal reset which clears the visible screen and scrollback buffer. As a result, users are unable to view previous command outputs.
PR NumberSynopsisCategory: SRX1500 platform software
1905001
Minor
FPC stuck in network loop scenario
Product-Group=junos
Severity=Minor
On SRX1500 in network loop scenarios, FPC gets stuck and traffic drop happens. System can be recovered by rebooting the device.
PR NumberSynopsisCategory: Signature Database
1919218
Minor
Adding new CLI option to jist conversion command.
Product-Group=junos
Severity=Minor
Adding new CLI option to jist conversion command. > request security idp jist-conversion ? Possible completions: input-file Snort rules file output-file Redirect converted attacks-set commands to this file best-effort-conversion Best effort conversion, skip unsupported Snort modifiers
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1933452
Major
ICMP ping with higher MTU size fails in VPLS when IRB MTU exceeds MPLS core MTU
Product-Group=junos
Severity=Major
On all Junos OS platforms, configured with VPLS (Virtual Private LAN Service) and IRB (Integrated Routing and Bridging ) interfaces, when the MTU (Maximum Transmission Unit) configured on the IRB or CE interface is larger than the MPLS ( Multiprotocol Label Switching ) core interface MTU (including MPLS label overhead), ICMP Echo Request (ping) packets with higher packet sizes fail.
PR NumberSynopsisCategory: jdhcpd daemon
1911001
Major
On Junos devices supporting subscriber services acting as DHCPv6 relay randomly deletes IA_NA or IA_PD binding/route
Product-Group=junos
Severity=Major
On all Junos devices supporting subscriber services, in case of dual stack DHCP (Dynamic Host Configuration Protocol) subscribers with IA_NA (Identity Association for Non-temporary Address) and IA_PD (Identity Association for Prefix Delegation) bindings with lease times (For the assignment of IPv6 address to a client device), when a client initiates separate renew exchanges for the IA_NA and IA_PD, and once client and DHCP server are in sync with these timers, there can be a race condition at Junos device which is DHCPv6 relay, has not refreshed lease timer and can go out of sync. This can result in deleting IA_NA/IA_PD binding and route to get deleted for that subscriber only. This causes one of the leg for IA_PD or IA_NA to go down for that subscriber, which can result in traffic impact for that leg.
1916981
Minor
Core and context for jdhcpd saved in /var/tmp/jdhcpd.core-tarball.0.tgz
Product-Group=junos
Severity=Minor
When the jdhcpd process encounters an internal exception, the process may generate a core file and save the relevant diagnostic context in /var/tmp/jdhcpd.core-tarball.0.tgz. This data is intended to assist Juniper support in root-cause analysis. The impact is limited to the affected jdhcpd process instance and recovery follows the standard process restart behavior.
1927449
Major
Jdhcpd cores generated after upgrade
Product-Group=junos
Severity=Major
jdhcpd cores seen after upgrade with dhcpv6 for IANA/PD
PR NumberSynopsisCategory: SRX power-mode (PMI/PME)
1858490
Major
flowd crashes due to a timing issue during IPsec SA re-keying on certain SRX platforms
Product-Group=junos
Severity=Major
On certain SRX platforms, the flowd process crash is observed during Internet Protocol Security (IPsec) Security Association (SA) re-keying. This occurs due to an internal timing issue, leading to IPsec tunnel establishment failure, traffic loss during re-key events, and traffic switchover.
PR NumberSynopsisCategory: SRX Service-offload
1912204
Minor
When service offload is enabled on SRX4600/SRX4700, flow sessions might keep using backup route when active route is added back
Product-Group=junos
Severity=Minor
On SRX4600/SRX4700 with service offload is enabled, flow sessions might keep using backup route when active route is added back.
PR NumberSynopsisCategory: SRX Datapath Multicast Solution
1935897
Major
Multicast packets are getting dropped at the start of a multicast stream
Product-Group=junos
Severity=Major
On SRX345/SRX1500 and SRX1600 platforms , when set security flow strict-packet-order is enabled, a Protocol Independent Multicast (PIM) middle-hop router in a multicast network experience a multicast packet drop at the start of a multicast stream. The packet loss is transient and typically lasts for approximately one second.
1939258
Major
Multicast packet drop on SRX1600
Product-Group=junos
Severity=Major
Random multicast packets could be dropped by SRX1600. This is the special feature for a specific customer use case and needs a special configuration knob to turn on.
PR NumberSynopsisCategory: Firewall Network Address Translation
1920648
Minor
Configuration commit takes several minutes to complete on SRX platforms
Product-Group=junos
Severity=Minor
On SRX platforms, when destination NAT rules referencing addressrange objects are configured, commit and commit-check operations may take several minutes to complete. The delay affects only administrative commit workflows and does not impact packet forwarding or controlplane functions.
1933239
Critical
The FPC restarts on SRX series platforms when session-persistence-scan is configured
Product-Group=junos
Severity=Critical
On Junos OS SRX Series platforms with 'session-persistence-scan' and NAT46 or NAT64 configured, modification to source Network Address Translation (NAT) rule will cause Flexible PIC Concentrators (FPCs) to restart when there is live IPv6 traffic. This will cause all traffic to be dropped and cause service disruption.
PR NumberSynopsisCategory: Firewall Policy
1932245
Minor
NSD main thread delay during policy file serialization on SRX5K platforms leads to instability
Product-Group=junos
Severity=Minor
On SRX5K platforms, during policy configuration processing using the policy file serialization feature, the Network Security Daemon (NSD) main thread can stop yielding for more than one second. This results in warning messages in system logs and can impact protocol/FPC stability if the delay becomes excessive.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1890976
Major
The IKE process is repeatedly crashing on MNHA scenario with per-tunnel debugging enabled
Product-Group=junos
Severity=Major
On all Junos platforms with MNHA and IPsec configured, when peer-allocation failure is observed and per-tunnel debugging is enabled, the IKE process is cored, causing the VPN tunnel to go down and IKE process to core.
1912271
Major
State synchronization failure between SRX cluster nodes
Product-Group=junos
Severity=Major
On all SRX series platform in cluster with IKED package enabled, when the backup node becomes active, some tunnel configuration were missing. This occurs because, during cold synchronization, the IPC communication between IKED and SPU can have a chance to fail due to a kernl error which ultimately led to traffic disruption.
1913985
Minor
SRX fail to establish IKE / IPsec VPN when ChaCha20Poly1305 algorithm is negotiated and IKE fragmentation occurs
Product-Group=junos
Severity=Minor
On Junos SRX devices, if the IKE (Internet Key Exchange) proposal negotiates ChaCha20Poly1305 and IKE fragmentation occurs (commonly with large IKE_AUTH payloads such as certificate-based authentication), the VPN fails to establish. Logs may show checksum failure during decryption.
1918367
Major
The OSPF state remains down when st0 is moved from p2p to p2mp
Product-Group=junos
Severity=Major
On all SRX platforms, when interface st0 inet6 is initially configured as point-to-point, and later if st0 is modified to multi-point along with the configuration of IKE ( Internet Key Exchange)/IPsec (Internet Protocol Security), which uses this st0, the ikemd enters a timing issue where it can't re-read the LLA (Link-Local Address) information of this st0 while parsing ike/ipsec configuration. Thus, resulting in a situation where the NHTB (Next-Hop Tunnel Binding) table is not complete, and the OSPF(Open Shortest Path First) IPv6 neighbor discovery fails.
1943292
Major
Add IPsec vpn support with user TSYS
Product-Group=junos
Severity=Major
Like logical systems, tenent systems also support ipsec vpn st0 management part of user TSYS.
PR NumberSynopsisCategory: Security platform jweb support
1926242
Minor
When multiple users establish IPsec connection with the same source IP address, J-Web displays the same IPsec phase 1 information for all users
Product-Group=junos
Severity=Minor
On SRX platforms, J-Web displays the same IPsec phase1 information for all users, when multiple users establish IPsec connections with the same source IP address.
1931780
Major
The Captive Web Authentication might not be completed on specific Junos versions for EX Series switch
Product-Group=junos
Severity=Major
When a MAC-RADIUS authentication succeeds and the RADIUS server returns CWA redirect attributes (URL-Redirect), the EX switch should intercept client HTTP traffic and return an HTTP 302 redirect to the Captive Portal. The switch instead responded with HTTP 405 (Method Not Allowed), causing the client to bypass the CWA redirect workflow.
PR NumberSynopsisCategory: Software Junos/JunosEvolved lab product
1903528
Major
vJunos-switch and vJunos-router can now be deployed on AMD servers
Product-Group=junos
Severity=Major
vJunos-switch and vJunos-router could previously only be deployed on Intel CPU based servers. This fix allows them to be deployed on AMD CPU based servers as well.
PR NumberSynopsisCategory: Layer 2 Control Module
1930380
Major
The hash collision for storm control profile indices will result in an l2ald process crash
Product-Group=junos
Severity=Major
On all Junos OS platforms and Junos OS Evolved platforms which supports storm control, when a different storm-control profile is applied for interface where these profile have same profile index allocated then the storm control profile configuration and system state will not be in sync and a different profile will be applied for interface binding due to profile index collision which results into l2ald process crash.
PR NumberSynopsisCategory: Multicast for L3VPNs
1918004
Minor
Multicast traffic disruption in multi-homed networks
Product-Group=junos
Severity=Minor
On Junos and Junos OS Evolved platforms, blackholed traffic disruption can occur in multi-homed NGEN MVPN (Next Generation Multicast Virtual Private Network) setups when a PE(Provider Edge) acting as both multicast source and DR/RP (Designated Router/Rendezvous Point) experiences path changes or flaps, provided the source is local and multi-homed across two PEs.
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1876690
Major
ntp process may restart when issue the "show system ntp threshold" command
Product-Group=junos
Severity=Major
The ntp (or xntpd) process is initialized when the "show system ntp threshold" command is issued. This has no impact to system operation.
PR NumberSynopsisCategory: PFE Peer Infra
1883882
Minor
Junos EX series device reboots unexpectedly with VMcore
Product-Group=junos
Severity=Minor
The Junos EX platforms restart unexpectedly - leaving a vmcore after the reboot.
PR NumberSynopsisCategory: Path computation client daemon
1929225
Critical
The pccd process crashes when muliple LSP updates are received from PCE
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with PCEP (Path Computation Element Protocol) configured, the pccd process crash is seen when multiple LSP (Label Switched Path) updates are received in a single PCE (Path Computation Element) message. The LSP update sent by the PCE will not get programmed into the forwarding plane and LSP states will not be updated till the pccd process restarts.
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.
PR NumberSynopsisCategory: Issues related to PKI daemon
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
Severity=Major
In stressful conditions, FPC crash observed and core file generated when PKI (Public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured, on all Junos platforms supporting PKI and SSL-Proxy services (MX, PTX, SRX).
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1931633
Major
PFE crash due to memory corruption when STP is enabled
Product-Group=junos
Severity=Major
On all Junos Platforms, a rare memory corruption condition may occur in the Packet Forwarding Engine (PFE) when Spanning Tree Protocol (STP) is enabled and operating in default (distributed) mode. When the issue is triggered, the PFE crashes and a dc-pfe core file is generated. The exact trigger for the memory corruption is currently unknown.
PR NumberSynopsisCategory: RPD Interfaces related issues
1913519
Major
EVPN routes are stuck in the KRT queue
Product-Group=junos
Severity=Major
When EVPN (Ethernet Virtual Private Network) routes attempt to transition between private (eg, management em1 - with IGP enabled) and public interfaces, it causes an error in next-hop resolution in the kernel, because the system deletes the old indirect next-hop and creates a new one. This happens as the kernel does not support changing an indirect next-hop between private and public interfaces directly.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1830588
Critical
The rpd process crashes on all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted, route churn will potentially lead to the rpd process crash.
1908681
Major
RIB and the FIB inconsistency results in traffic loss in IPsec scenario with st0 interface configured
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having IPsec (Internet Protocol Security) with st0 (Secure Tunnel Interface) interface configured, traffic loss will be observed if the "next-hop-tunnel" configuration is removed and added within a few seconds. This happens due to a inconsistency between the RIB (Routing Information Base) and the FIB (Forwarding Information Base).
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1907558
Major
The rpd process crashes in a vrf having EVPN-VXLAN routes with specific configuration.
Product-Group=junos
Severity=Major
In all Junos and Junos OS Evolved platforms, when EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible LAN) routes are present in a VRF (Virtual Routing and Forwarding), configuring a generate route in same vrf can cause rpd (Routing Protocol Daemon) to crash and restart. Generate route configuration has to be removed to recover from this behaviour.
PR NumberSynopsisCategory: Resource Reservation Protocol
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.
1913565
Major
The rpd process crashes during repeated RSVP session clear operations
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, the rpd process crashes when Resource Reservation Protocol (RSVP) sessions are repeatedly cleared under specific timing conditions. This issue occurs due to a timing window during RSVP processing on the standby Routing Engine (RE) while sessions are being re-established, which results in an invalid memory access and leads to an the rpd process crashes.
PR NumberSynopsisCategory: Segment routing traffic Engineering
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
Severity=Major
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.
PR NumberSynopsisCategory: SRX branch platforms
1904539
Major
On SRX3XX platforms the configured Link Speed or link mode or duplex does not reflect in the ge interface
Product-Group=junos
Severity=Major
On SRX3XX platforms when the speed or duplex or link mode is/are explicitly configured the same is not reflected in show interface command for ge interface. This will not bring the interface down. However the show interface command will not reflected to committed value. This symptom is also triggered when the peer device changes the speed/duplex or link mode. Additionally, for SFP ports, the link goes down.
1924464
Minor
Delay in commit time post upgrade
Product-Group=junos
Severity=Minor
On all branch SRX platforms (SRX300/320/340/345/380) running on FreeBSD12 OS, any upgrade post 24.4 release will cause a delay in every CLI (Command Line Interface) commit, with no impact to traffic forwarding or network services.
1927646
Minor
Ethernet interfaces with fiber SFPs and configured with 'family ethernet-switching' and 'no auto negotiation' don't come up after reboot
Product-Group=junos
Severity=Minor
After reboot on branch SRX300 Series platforms, interfaces using Small Formfactor Pluggable (SFP) SX/LX fiber transceivers and configured with 'family ethernet-switching' and 'no auto negotiation' might remain in a down state due to incorrect physical medium detection by the Ethernet physical layer (PHY). The issue is timing-dependent, it might happen with single or after several reboots.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1905768
Major
FPC crash triggered when a line card reboots with a large number of static subscribers
Product-Group=junos
Severity=Major
On all MX platforms with the MPCs/Line cards except MPC10E, MPC11E, LC9600 and MX304. When a line card hosting an AE ( Aggregate Ethernet ) interface with a large number of static subscribers (around 4000) reboots, excessive processing load across multiple subscriber interfaces will cause delays that trigger the watchdog timer and result in an FPC ( Flexible PIC Concentrator ) crash.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
Severity=Critical
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1863354
Minor
Command line freezes when Ctrl+Z is used
Product-Group=junos
Severity=Minor
In Junos OS Releases 24.2 and later(BSD 15), pressing Ctrl+Z in the Command Line Interface CLI suspends the process and causes it to become unresponsive. This behaviour is observed on systems using the and Berkeley Software Distribution BSD15 platform.
1902358
Minor
RPC crash when non-ASCII character is included in XML data result
Product-Group=junos
Severity=Minor
1947196
Minor
Commitd core dumps observed during specific config commits with "patch generation error - not syncing patch"
Product-Group=junos
Severity=Minor
Resolved an issue where configuration commits could intermittently fail when applying certain routing policy changes. The problem occurred only under specific conditions during commit processing and could result in the commit operation aborting unexpectedly. This fix improves commit stability when updating routing policies.
1948232
Major
The command test configuration fails in VC deployments
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms with virtual chassis (VC) deployments when the CLI command 'test configuration ' is executed it fails consistently and error messages are observed.
PR NumberSynopsisCategory: Issues related to NETCONF
1894296
Major
GNMI Get on openconfig returns not-found when only root-level openconfig metadata is configured
Product-Group=junos
Severity=Major
On Junos Evolved platforms, a gNMI Get request for the OpenConfig root (origin: openconfig, type CONFIG) returns a NOT_FOUND error when only root-level OpenConfig metadata is configured and no OpenConfig configuration data nodes are present. In this scenario, the configured OpenConfig metadata is not returned unless at least one OpenConfig configuration subtree exists.
1906621
Major
RPC reply delayed for commit during NETCONF over SSH session on Junos TVP-based VMhost platforms
Product-Group=junos
Severity=Major
On JUNOS VM Host-based platforms, when performing NetConf "", an internal script caused its PID to be displayed in the NETCONF session during commit.
PR NumberSynopsisCategory: content filtering bugs
1927484
Critical
Traffic loss occurs due to high memory utilisation in UTM pools
Product-Group=junos
Severity=Critical
On Junos OS SRX platforms, configuring cache preload in web filtering causes high memory utilization in the UTM (Unified Threat Management) pool, which results in traffic loss.
PR NumberSynopsisCategory: VMHOST platforms software
1924890
Major
During vmhost upgrade or downgrade livirtd.conf file was not updated correctly
Product-Group=junosvae
Severity=Major
During update and downgrade of vmhost images the livirtd.conf cleanup entries had not been performed properly. See TSB103739 [juniper.net]. https://kb.juniper.net/TSB103739 [juniper.net]
1927342
Minor
Junos VMhost platforms restart unexpectedly due to deadlock
Product-Group=junosvae
Severity=Minor
On all Junos VMhost platforms, when Junos performs disk access, a rare deadlock involving FreeBSD kernel processes will occur. This condition causes FreeBSD kernel panic, resulting in crash of vmcore and an unexpected device restart, leading to temporary system unavailability.
PR NumberSynopsisCategory: Virtual Private LAN Services
1885690
Major
rpd crash on backup RE during switchover due to VPLS Auto-Site mismatch
Product-Group=junos
Severity=Major
An rpd core triggered on the backup Routing Engine after a switchover due to an assertion failure in within the context of L2VPN VPLS auto-site processing, caused by a mismatch between the auto-site claim-id/site-id and the local site-id associated with interfaces in the VPLS IFL repository for a given instance, leading to stale interface entries being referenced during auto-site processing.
PR NumberSynopsisCategory: usf ams related issues
1913560
Major
Routing Engine restart on MX platforms with SPC3 line card could cause loss of traffic processing
Product-Group=junos
Severity=Major
On Junos MX960, MX240, and MX480 platforms using SPC3 service line cards, restarting the Routing Engine may result in the network security daemon (nsd) not starting or failing to program internal subsystems like service sets . When this occurs, the control plane becomes unavailable and traffic stops forwarding permanently. This is a timing related behavior observed during the boot sequence and does not appear on every restart.
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1925039
Major
Memory leak in ipv4-to-ipv6 session reuse trigger flowd crash
Product-Group=junos
Severity=Major
On Junos OS MX240/MX480/MX960 platforms with MX-SPC3 cards, the flowd process crash and reboots the service PIC when a stale IPv4 session is mistakenly reused for IPv6 due to a memory issue. During process restart the services remain down, session information is briefly lost and active traffic will drop, however the system recovers automatically.
PR NumberSynopsisCategory: usf ipsec related issues
1888205
Major
Change in the behaviour of configured lifesize kilobytes of ipsec proposal.
Product-Group=junos
Severity=Major
The lifesize parameter (in kilobytes) within the IPsec proposal is negotiated only when it is explicitly defined in the local device configuration.
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
Severity=Major
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

 


 

Extended Solution

24.4R2-S4 - List of Known Issues

PR NumberSynopsisCategory: "agentd" software daemon
1923848
Major
Junos Evolved platfrom, when gNMI collecting data from "optics/lanediags/lane/lane_laser_receiver_power_dbm" and "optics/lanediags/lane/lane_laser_output_power_dbm" are unreadable
Product-Group=junos
The JavaScript Object Notation (JSON) encoding of leafs of type "ieeefloat32"(https://github.com/openconfig/public/blob/master/release/models/types/openconfig-types.yang#L127) is not correct, causing gRPC Network Management Interface (gNMI) data outputs unreadable.

Resolved In: evo:22.3X80-D49-EVO evo:24.4R2-S4-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:24.2R2-S6 junos:25.2R2-S2 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: BBE database related issues
1894192
Minor
EX/QFX : Message 'shmlog: argcnt 166 not enough memory for argtype' appears
Product-Group=junos
The memory allocation issue persists on EX and QFX devices. As a result, you may observe the message 'shmlog: argcnt 166 not enough memory for argtype' when executing command, show version detail.

Resolved In: junos:23.4R2-S6
PR NumberSynopsisCategory: BBE Resource monitoring related issues
1942159
Major
New subscriber login request failure is seen due to missing PFE readiness update after boot
Product-Group=junos
On MX240, MX480, MX960, MX2008, MX2010, MX2020 platforms with MPC2/3/4/5/6/7/8/9 line cards, the new subscriber login request will fail if subscriber login request is initiated when PFE (Packet Forwarding Engine) is booting.

Resolved In: evo:25.4R2-EVO evo:26.2R1-EVO evo:26.3R1-EVO junos:23.2R2-S8 junos:24.2R2-S6 junos:25.2R2-S2 junos:25.4R2 junos:26.2R1 junos:26.3R1
PR NumberSynopsisCategory: Border Gateway Protocol
1914814
Major
BGP task replication will be stuck in 'InProgress' state following an RE switchover when two single hop EBGP sessions are configured on two different interfaces using the IP addresses from the same subnet
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms with NSR (Nonstop Active Routing), when two single hop EBGP (External Border Gateway Protocol) sessions are configured to run on two different interfaces using IP addresses from the same subnet (overlapping subnet), the BGP task replication process does not complete after an RE (Routing Engine) switchover for the EBGP session with a specified local-address. This results in one BGP peer being in the 'Idle' state on the Backup RE while remaining in the 'Established' state on the new Master RE, causing the BGP task replication process to remain stuck in the 'InProgress' state.

Resolved In: evo:22.4R3-S9-EVO evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: BGP Segment Routing
PR NumberSynopsisCategory: MX304 Chassis specific platform
1882470
Major
MX304/MPC10E - When an st0 interface is part of an ECMP next hop, it does not get considered for traffic forwarding
Product-Group=junos
The st0 interface is a pseudo interface and that is used for IPSec. It was created as "down". This does not affect IPSec traffic forwarding for interface-units over the st0 interface, but if the st0 interface is part of an ECMP next hop, the st0 interface is not considered for traffic forwarding.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.2R2-S2 junos:25.3R1 junos:25.4R1-S3 junos:25.4R2
PR NumberSynopsisCategory: MX304 line card platform software
1843577
Major
Brief transient Temp Sensor Hot alarm observed on MX304 during reboot
Product-Group=junosvae
On MX304 platforms, a transient FPC xcvr Temp Sensor Hot alarm may briefly appear and then clear automatically during MIC power cycling or line card reboot operations. This condition occurs when temperature data has not yet been fully updated by the line card management daemon (lcmd). The alarm clears on its own and has no functional impact on the system or the hardware.

Resolved In: junos:24.2R2-S4 junos:25.1R1 junos:25.2R1 junos:25.2R2-S1 junos:25.4R2
PR NumberSynopsisCategory: MX304 Routing Engine issues
1886633
Major
Logs from internal ethernet links monitoring script keep repetitively logged to /var/log/messages file if "set system syslog file messages user any" config is used.
Product-Group=junos
Logs from internal ethernet links monitoring script keep repetitively logged to /var/log/messages file if "set system syslog file messages user any" config is used.

Resolved In: junos:26.2R1
1913540
Minor
[MX304] Certain 'cat' commands within the 'show vmhost support-info' command in RSI try to access files that are not present on the MX304, causing error messages to appear.
Product-Group=junos
As part of the RSI process, execute the "show vmhost support-info" command to comprehensively collect the vmhost logs using various cat commands. Some of these commands attempt to access files that do not exist on the MX304, leading to error messages.

Resolved In: junos:24.2R2-S5 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: CoS support on DNX
1897336
Major
ARP resolution and device discovery failure is observed due to unexpected VLAN tags on ARP replies
Product-Group=junos
On ACX710 and ACX5448 platforms, due to VLAN edit profile remapping and VLAN translation, all the packets are getting VLAN-tagged. The RE ( Routing Engine ) drops ARP ( Address Resolution Protocol ) reply packets that contain VLAN ( Virtual Local Area Network ) tags, if the interface encapsulation was set to ethernet-ccc and VLAN configuration was removed. As a result, ARP resolution fails, leading to ping and device discovery failure.

Resolved In: junos:23.2R2-S6 junos:24.2R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:25.4R2-S1
PR NumberSynopsisCategory: EVPN ELAN/E-TREE
1901224
Major
Traffic drop seen in EVPN VPWS FXC stream post clear bfd session all.
Product-Group=junos
Traffic drop seen in EVPN VPWS FXC stream post "clear bfd session all" command.

Resolved In: junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1890791
Major
IDP installation update fails on secondary node in SRX chassis cluster
Product-Group=junos
On SRX devices running in a chassis cluster, when installing IDP (Intrusion Detection and Prevention) updates using the offline method, the secondary node may fail the installation. As a result, the update completes successfully on the primary node but fails on the secondary node.

Resolved In: junos:24.2R2-S3 junos:25.2R2 junos:25.3R1 junos:25.4R1
1901835
Major
AppID Reports Generic Error for Signature Download Failures via Proxy
Product-Group=junos
On SRX platforms, in the scenario where incorrect proxy authentication credentials are configured in the proxy profile. The functional behavior is partially correct (download failure and proxy denial), the error message presented to the user is misleading and generic, and does not accurately reflect the real cause of failure

Resolved In: junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1908196
Major
All Marvell(MX, ACX): LLDP protocol goes down when 'exclude protocol LLDP' is deleted from MACsec policy attached to IFD
Product-Group=junos
With IFD MACsec configured with exclude-protocol LLDP and LLDP protocol enabled, LLDP protocol goes down when 'exclude-protocol LLDP' is deleted from MACsec connectivity association.

Resolved In: evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: EVPN control plane issues
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby) the ARP (Address Resolution Protocol) tables from Customer Edge (CE's) device may not update simultaneously on Provider Edge (PE) devices when an IP address moves between two different Ethernet Segments (ESIs) during a switchover, leading to temporary traffic disruption until the tables are refreshed.

Resolved In: evo:23.4R2-S5-J28-EVO evo:23.4R2-S8-EVO evo:24.2R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:23.4R2-S8 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
1912156
Minor
Enhancement to retain route-target community after auto-import VRF routes
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, an enhancement added to retain the route-target community after auto-importing Virtual Routing and Forwarding (VRF) routes from an Ethernet Virtual Private Network (EVPN) route to an IP Virtual Private Network (IPVPN) route.

Resolved In: evo:24.4R2-S4-EVO evo:26.1R1-EVO junos:26.1R1
1924472
Minor
EVPN all-active not working in multi-homed setup when router-id not explicitly configured
Product-Group=junos
On Junos OS, if the router-id is not explicitly configured, the device dynamically selects a router-id during bootup. In this scenario, the device advertises EVPN Type1 AutoDiscovery/Ethernet Segment Identifier (AD/ESI) and Type4 Ethernet Segment Route Target (ES RT) routes with a Route Distinguisher (RD) of 0:0. As a result, Route Targets (RTs) advertised by different Provider Edge (PE) routers end up having identical prefixes. Consequently, only one PE routers RT is advertised and learned. This behavior prevents EVPN all-active redundancy resulting in the loss of multi-homing.

Resolved In: evo:26.3R1-EVO junos:26.3R1
PR NumberSynopsisCategory: EX interfaces issues
1492605
Minor
runt, fragment and jabber counters are not incrementing on EX4300-MPs
Product-Group=junos
runt, fragment and jabber counters are not incrementing on EX4300-MPs

Resolved In:
1870962
Major
The CPU high utilization is observed after PIC offline/online
Product-Group=junos
On EX4400 platforms with 4x25G or 1x100G ULM (Universal Link Module), the CPU hogs by CMQFX thread for as much as 3.7 secs when Firmware download occurs during PIC offline/online and PFE restart time / Device reboot. To speed up the firmware download operation, the MDIO clock (MDC) frequency is increased from 2.6 MHz to 9 MHz which reduced firmware download time from ~3.8 s to ~2.2 s. This is an enhancement PR.

Resolved In: junos:26.2R1
1923212
Major
PFE process crash occurs during EX4k boot-up
Product-Group=junos
On EX4400/4100 platforms, PFE process (fxpc) crash occurs with a segmentation fault (SIGSEGV) during device boot-up. The crash occurs during the Broadcom PHY firmware broadcast download sequence when initializing the external PHY. No service impact as this crash happens at initial boot cycle.

Resolved In: junos:24.2R2-S6 junos:25.4R2 junos:26.2R1 junos:26.2R2 junos:26.3R1
PR NumberSynopsisCategory: EX4400 PFE software
1930323
Major
[ECU CUC-3574] Multicast traffic sent upstream by MC receiver-side access switch (ACCESS.1), in addition to being sent upstream by MC source-side access switch, when PEG is configured on BLs, in EVPN VXLAN IP Clos with Enhanced OISM, SMET and GBP
Product-Group=junos
If there is only a single receiver for a TTL-1 stream in an EVPN fabric with source bd forward policy(https://www.juniper.net/documentation/us/en/software/junos/cli-reference/topics/ref/statement/forward-on-source-bridge-domain-edit-protocols-evpn-oism-enhanced.html) applied for such a stream throughout the EVPN fabric, that stream could be sent upstream again to the BLs from the receiver leaf , in addition to being sent sent by src leaf(EVPN PE directly attached to the source) as well.

Resolved In: junos:26.3R1
PR NumberSynopsisCategory: EX4400 platform
1956927
Major
chassisd crashes on EX4400 when set chassis alarm fru-absence ignore fpc pem configuration is applied
Product-Group=junos
On EX4400 platforms , the chassis daemon (chassisd) crashes when the configuration statement set chassis alarm fru-absence ignore fpc pem is committed.

Resolved In:
PR NumberSynopsisCategory: EX optics issues
1864715
Major
EX4100: 10g-BASE-T didn't come up after dc-pfe restart
Product-Group=junos
After multiple iterations of dc-pfe process restart, we may see interface with 10g-base-t transceiver (part# 740-123734) will not come up.

Resolved In:
1887303
Minor
[EX4400-48F] One of the 10gBase-T transceiver is not detected - showing as "Partial" Unknown in PFE
Product-Group=junos
In the EX4400-48F systems, a 10G-BaseT transceiver that was earlier up may not come up post a reboot/image upgrade event; The transceiver may go undetected causing the interface to not be created in the system.

Resolved In:
1899248
Major
EX4400-48F: When we have SFP-SX optics plugged in EX4400-48F device in the ports 0 to 35 and it is rebooted, the activity LED remains on
Product-Group=junos
EX4400-48F: When we have SFP-SX optics plugged in EX4400-48F device in the ports 0 to 35 and it is rebooted, the activity LED remains on.

Resolved In:
PR NumberSynopsisCategory: to track infrastructure replication bugs
1754351
Critical
vmcore on device with evpn-vxlan configs
Product-Group=junos
Graceful Routing Engine Switchover (GRES) not supporting the configuration of a private route, such as fxp0 , when imported into a non-default instance or logical system.Please see KB https://kb.juniper.net/InfoCenter/index?page=content&id=KB26616resolution rib policy is required to apply as a work-around.

Resolved In:
PR NumberSynopsisCategory: Interface Information Display
1840142
Minor
The ODL execution failure observed for cli 'get-interface-information'
Product-Group=junos
On Junos and Junos OS Evolved platforms, the command 'get-interface-information' returns an error when called via RPC (Remote Procedure Call) and the XML (Extended Markup Language) response is validated against the YANG( (Yet Another Next Generation) model by the OpenDaylight (ODL) controller. There is no traffic impact because of this issue.

Resolved In: evo:24.2R2-S3-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:25.1R1 junos:25.2R1 junos:25.2R2 junos:25.3R1 junos:25.4R2
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
PR NumberSynopsisCategory: jdhcpd daemon
1939685
Minor
Insert command not working for "dhcp-local-server group" hierarchy
Product-Group=junos
Insert command not working for "dhcp-local-server group" hierarchy, below error is seen: user@host# insert system services dhcp-local-server group servers-1 after syntax error, expecting `after' or `before'. user@host# insert system services dhcp-local-server group servers-1 bef syntax error, expecting `after' or `before'.

Resolved In: evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:25.2R2-S1-EVO evo:26.2R1-EVO evo:26.3R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:25.2R2-S1 junos:26.2R1 junos:26.3R1
PR NumberSynopsisCategory: Category for JET(JUNOS Extension Toolkit) related issues
1961463
Critical
Telemetry fails as gRPC port does not come up after reboot
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, this issue is seen in SSL (Secure Sockets Layer)-based gRPC (Remote Procedure Call) dial-in telemetry configurations. When the device reboots, the configured IP (Internet Protocol) is not active during initialization. As a result, the gRPC port fails to come up. This causes telemetry sessions to fail and leads to complete loss of telemetry data.

Resolved In: evo:25.4R2-EVO evo:26.2R2-EVO evo:26.3R1-EVO junos:23.4R2-S8-J1 junos:25.4R2 junos:26.2R2 junos:26.3R1
PR NumberSynopsisCategory: Health-Monitoring related issues
1935089
Minor
The jinsightd process crashes on Junos platforms in a rare scenario
Product-Group=junos
On Junos platform in an extremely rare circumstances due to internal race conditions the jinsightd process crash is observed. J-insight Monitor will not function until the jinsightd process recovers. However, there will be no traffic impact due to this issue.

Resolved In: junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Firewall Policy
1904561
Major
Types of address book featured supported in IDP
Product-Group=junos
address book support below listed types of address root@device# set security address-book global address abc ? Possible completions: Numeric IPv4 or IPv6 address with prefix > dns-name DNS address name > range-address Address range > wildcard-address Numeric IPv4 wildcard address with in the form of a.d.d.r/netmask IDP support only and dns-name types of address in side IPS rule, range-address and wildcard-address is not supported by IDP IPS rule. so if any address of address book of type range-address or wildcard-address configured inside IPS rule that will result into commit failure. As IDP policy is configured in security policy and security policy already supports address book for the source and destination IP addresses so inorder to use range-address or wildcard-address type address feature please apply those address at firewall level and let fire wall to filter that traffic.

Resolved In:
1939433
Major
Flow sessions not synchronizing from primary to backup in SRX High Availability clusters
Product-Group=junos
On SRX devices operating in a High Availability cluster with logical-systems enabled, the backup node may display fewer flow sessions than the primary node due to incomplete flow session synchronization. Sessions that do not synchronize to the backup node are lost during a failover, resulting in service interruption for the affected flows.

Resolved In: junos:23.4R2-S7-J20 junos:23.4R2-S7-J9 junos:25.2R2-S1 junos:25.4R1-S3 junos:25.4R2 junos:26.2R1 junos:26.3R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1933443
Major
The st0 interface keeps up state during VPN down
Product-Group=junos
On all SRX platforms except branch series and SRX5K systems equipped only with SPC2 the st0 interface may remain in an up state after a VPN tunnel goes down when the SRX is configured with a dynamic IKE peer (dynamic IKEID) on iked. When traffic is routed through st0 using a static route, the static route is not removed upon VPN failure, causing traffic to continue being forwarded toward a tunnel that is no longer active.

Resolved In: junos:25.4R2 junos:26.2R1 junos:26.3R1
1937239
Major
Srxpfe process crash due to memory allocation errors triggered by IPsec processing
Product-Group=junos
On all SRX platforms with Internet Protocol Security (IPsec) Virtual Private Network (VPN) tunnel configuration, the srxpfe (SRX Packet Forwarding Engine) process leaks memory during internal IPsec operation failures, where allocated memory is not freed in the error handling path. Over time, this results in excessive growth of virtual memory usage, eventually leading to memory allocation failures and a crash of the srxpfe process. This condition causes a temporary IPsec VPN service disruption and impacts traffic.

Resolved In: junos:23.2R2-S8 junos:24.2R2-S6 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1 junos:26.3R1
PR NumberSynopsisCategory: Platform infra to support jvision
1928253
Major
The sensord process crashes leading to PFE reboot on MPC10E supported MX platforms
Product-Group=junos
On MX platforms supporting MPC10E line card, the sensord process crashes due to corrupted memory state on the FPC (Flexible PIC Concentrator). When the sensord process crashes, the PFE (Packet Forwarding Engine) reboots leading to interface flaps and consequent disruption to traffic flow.

Resolved In: evo:25.4R2-EVO evo:26.2R1-EVO evo:26.3R1-EVO junos:23.4R2-S8 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1 junos:26.3R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1912050
Minor
Broadcast and Multicast traffic is dropped in MH EVPN MPLS topology where Egress Link Protection is enabled on the PEs and restart l2-learning is executed
Product-Group=junos
On all Junos platform in MH (Multi homed) EVPN (Ethernet Virtual Private Network) MPLS (Multi Protocol Label Switching) topology where Egress Link Protection feature is enabled on the PEs (Provider Edge) routers and the PE - CE (Customer Edge) link is disabled on the one of the MH PEs and 'restart l2-learning' command is executed on another MH PE, this results in broadcast and Multicast traffic drop.

Resolved In: evo:25.2R2-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:25.2R2 junos:25.4R1-S2 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Label Distribution Protocol
1906611
Major
Crash in the rpd process after LDP P2MP LSP Identifier reaches its maximum value and rolls over, due to duplicate identifier allocation
Product-Group=junos
On all Junos OS and Junos OS Evolved versions that support Label Distribution Protocol Point-to-Multipoint Label Switched Paths (LDP P2MP LSPs), the rpd process (routing protocol daemon) crashes when an LSP Identifier reaches its 24-bit maximum value (224 1 = 16, 777, 215) and rolls over to the starting value because a duplicate identifier is incorrectly allocated. This condition occurs only after prolonged tunnel flapping (typically more than 16 million flaps). When the rpd process crashes, routing convergence is briefly disrupted, and services relying on label-switched traffic are impacted until the process automatically restarts.

Resolved In: evo:26.1R1-EVO junos:26.1R1
PR NumberSynopsisCategory: MPC11 ULC platform software related issues.
1809351
Major
JDI-RCT:M/Mx: ISIS session over MPC11 cards flapped due to "3-Way handshake failed" during ISSU (FRU upgrade stage - reboot phase)
Product-Group=junos
JDI-RCT:M/Mx: ISIS session over MPC11 cards flapped due to "3-Way handshake failed" during ISSU (FRU upgrade stage - reboot phase)

Resolved In:
PR NumberSynopsisCategory: Multiprotocol Label Switching
PR NumberSynopsisCategory: Multicast for L3VPNs
1908581
Major
Significant multicast traffic loss observed during ISSU in Next-Generation Multicast VPN (NGMVPN) deployments
Product-Group=junos
On all Junos platforms that support both InService Software Upgrade (ISSU) and NextGeneration Multicast VPN (NGMVPN), multicast traffic loss can occur during an ISSU operation when NGMVPN deployments use both the Inclusive Provider Multicast Service Interface (IPMSI) and the Selective Provider Multicast Service Interface (SPMSI) with a nonzero threshold. During the ISSU process, Flexible PIC Concentrators (FPCs) upgrade and synchronize, and multicast statistics may briefly report zero. This event causes withdrawal of the SPMSI and a fallback to the IPMSI. If the IPMSI next hops are not fully programmed at that moment, a temporary interruption of SPMSI flows occurs, while IPMSI flows continue forwarding normally. The traffic loss duration is short and typically limited to a few seconds to a few minutes during FPC upgrade cycles, not exceeding the expected ISSU convergence window. Both IPv4 and IPv6 multicast traffic are affected.

Resolved In: evo:26.2R1-EVO junos:26.2R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1932893
Major
vmhost upgrade may fail due to 'Validation failed' when upgrading to freebsd15 based Junos from older releases.
Product-Group=junos
vmhost upgrade may fail due to 'Validation failed' when upgrading to freebsd15 based Junos from older releases. This does not apply to Junos-EVO.

Resolved In: junos:23.2R2-S8 junos:23.4R2-S9 junos:24.2R2-S5 junos:24.4R2-S5 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1863814
Critical
JDI-RCT:AlfaRomeo:: Observing rpd core @ rt_stats_id_grp_set_kernid , krt_stats_id_grp_resp_from_kernel , libsock_build_and_send_rtsock_msg
Product-Group=junos
Release note is added for 25.2R2-S1? RPD core might be seen after GRES. This is a corner case scenario. This issue is not reproduced always.?This is the day-1 behaviour in the rtsock filtering logic. This is a corner case where RPD have filters installed on master and no filters installed on backup. RPD core is seen if gencfg deletes are sent on new master after GRES.??Workaround: RPD restart can help to recover from the issue. The fix is already committed in 25.4DCB and the fix will be committed to 25.2R2-S2.

Resolved In: junos:25.2R2-S2 junos:25.4R1
PR NumberSynopsisCategory: TCP/UDP transport layer
1893210
Minor
Master RE crashed and triggered unexpected switchover due to memory corruption
Product-Group=junos
On all Junos OS platforms, In Nonstop active routing (NSR) enabled system Routing Engine (RE) crash can occur due to a double free of a memory buffer (mbuf) was not handled properly leading to memory corruption causing synchronization issue and triggers unexpected switchover.

Resolved In: junos:23.4R2-S8 junos:24.2R2-S5 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Protocol Independant Multicast
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1937254
Minor
PPPoE clients are ignoring the service-name-table configuration and attempting to connect subscribers into default routing-instance.
Product-Group=junos
PPPoE clients are ignoring the service-name-table configuration and attempting to connect subscribers into default routing-instance. In this scenario customer has static VLAN configured on DEMUX0 and uses service-name-table to ensure PPPoE client is terminated within desired routing-instance. demux0 { unit 200 { vlan-id 200; demux-options { underlying-interface ae4; } family pppoe { dynamic-profile PPPoE_DUALSTACK; service-name-table PPPOE-TO-VRF200; } } } pppoe { service-name-tables PPPOE-TO-VRF200 { service any { routing-instance VRF200; } service empty { routing-instance VRF200; } } } }

Resolved In:
1939233
Major
Repeated bbe-smgd crashes caused when the system issues a dynamic profile add request during PPPoE session creation, but receives a delete event before the add completes on MX platforms.
Product-Group=junos
On all MX platforms where Enhanced Subscriber Management (bbesmgd) is enabled, activating PPPoE (PointtoPoint Protocol over Ethernet) over L2TP (Layer 2 Tunneling Protocol) triggers repeated crashes of the bbesmgd process, resulting in core dump generation. This issue affects both Junos and Junos EVO platforms.

Resolved In: evo:25.2R2-S1-EVO evo:25.4R2-EVO evo:26.2R1-EVO evo:26.3R1-EVO junos:23.2R2-S8 junos:24.2R2-S5 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1 junos:26.3R1
PR NumberSynopsisCategory: PTX10K Routing Engine
1915464
Major
The VMhost memory exhaustion causes RE hang when doing upgrade
Product-Group=junos
On VMhost platforms with RE that have two or more management interfaces, when only one management port is connected, it will cause VMhost memory over consumption and when the VMhost upgrade command is triggered leading to higher memory need and due to less availability leading to RE hang.

Resolved In: junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4R3-S9 junos:22.4X50 junos:26.1R1
PR NumberSynopsisCategory: QFX5K hostpath
1932314
Minor
Errors "fpc0 ifd null, port X and TD3:ifd null, port X" are seen on QFX5k platforms
Product-Group=junos
On QFX5k platforms, if sflow is configured without multicast and BUM traffic is sampled, then the errors "fpc0 ifd null, port X and TD3:ifd null, port X" are observed.

Resolved In: junos:23.4R2-S8 junos:24.2R2-S5 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX L2 PFE
1958247
Major
NPAT-REG: QFX5120-32C: Expected RX traffic count not observed during end-to-end validation due to CCC reverse path failure.
Product-Group=junos
RLI 55202: QFX5K/EX: L2 Circuit Support on AE with loadbalancing" is introduced in 25.2. Prior to this RLI, we did not claim support for L2 Circuit on AE interfaces. It is not supported in older releases including 24.4R2-Sx. FS of RLI 55202 mentions the following: QFX5K/EX platforms currently support L2 Circuit on non-aggregated interfaces. The scope of this RLI is to extend this L2Circuit functionality over Aggregated Ethernet (AE) interface / LAG bundle. In addition, through this RLI, the load balancing functionality for the L2 traffic over the AE interface from the decapsulated L3 MPLS traffic at the egress PE node would be implemented.

Resolved In:
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1934076
Major
JUNOS_REG: QFX5120-48T : After loading the baseline config, while checking the interfaces status on the devices interfaces are not coming up.
Product-Group=junosvae
NA

Resolved In:
PR NumberSynopsisCategory: KRT Queue issues within RPD
1931875
Major
The L2Circuit traffic which are resolving over BGP-LU get drop when 'chained-composite-next-hop' for BGP-LU and 'preserve-nexthop-hierarchy' is configured
Product-Group=junos
On all Junos and Junos Evolved platforms supporting 'chained-composite-next-hop' for BGP-LU (Border Gateway Protocol - Labeled Unicast), when having L2Circuit (Layer 2 Circuit) links configured, with indirect next-hop resolving on BGP-LU prefix, if 'chained-composite-next-hop' enabled for BGP-LU and with 'preserve-nexthop-hierarchy' configured, L2Circuit traffic will get dropped due to failure in installing the forwarding next-hop with labels for L2Circuit service.

Resolved In: evo:24.2R2-S5-EVO evo:25.2R2-S1-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:23.4R2-S8-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:26.2R1-EVO junos:23.4R2-S8 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
PR NumberSynopsisCategory: Resource Reservation Protocol
PR NumberSynopsisCategory: Sangria Platform including chassisd, RE, CB, power managemen
1913580
Major
Chassisd crash will happen when shutting down the FPC of PTX5000 and PTX3000 using online/offline button
Product-Group=junos
When the FPC(Flexible PIC Concentrator)online/offline button is pressed on PTX5000 and PTX3000 twice in a short period, chassisd crash will happen. it is causing all FPCs to lose connectivity with the Routing Engine while remaining in an online state. As a result, service impact happened till all FPCs become online.

Resolved In: junos:22.3X60 junos:22.4R3-S9
PR NumberSynopsisCategory: Issues related to control plane security
1897046
Major
CSDS: JNU : SSH/SCP : After downgrading from 25.X to 24.X release, SSH/SCP access via SSH keys is fails between controller and satellite
Product-Group=junos
This issue is caused by a behavior change(introduced through PR#1863588) that blocked non-root users from modifying the authorized_keys file by including "Strict Modes no" to the sshd config. Since this knob is not present before 25.3, it is not a backward compatible change. Hence the failure and the error "Authentication refused: bad ownership or modes for directory /var/home/jnuadmin/.ssh". As a workaround, users have to reconfigure the SSH keys(on both MX and SRX) after downgrading to 24.4 for the SSH/SCP passwordless login to work. Generate SSH keys using the below from shell mode in both MX/SRX: ssh-keygen -t rsa -f /var/db/jnu/.ssh/id_rsa -N "" -b 2048 Configure the SSH keys in both devices (MX & SRX) for passwordless access using SSH/SCP Try SSH/SCP in 24.4, it works Upgrade the setup (MX & SRX) to 25.4, SSH/SCP works Downgrade the setup (MX & SRX) back to 24.4, SSH/SCP fails

Resolved In:
PR NumberSynopsisCategory: Segment routing traffic Engineering
1927655
Major
BGP-LS advertises the default Instance Identifier instead of the configured value
Product-Group=junos
On routers running Junos OS 24.4 and later, including Junos Evolved, when the Traffic Engineering database import identifier is configured using "set protocols mpls traffic-engineering database import identifier ", the Border Gateway Protocol Link State advertisements in the "lsdist.0" table continue to use Instance Identifier 0 instead of the configured value. This results in BGP-LS exporting an incorrect Instance Identifier toward the route reflector or controllers, displaying mismatched or incorrect instance IDs for what should be a single shared topology. No traffic impact, but controlplane information is inaccurate.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1876314
Minor
Intermittent link-up failure on MX10003 after peer device reboot
Product-Group=junos
On Juniper MX10003 platforms equipped with MIC1, interfaces using QSFP optics fail to come up or remain down after a connected third-party device is rebooted. This behavior results from a timing mismatch, where the software delays link initialization while waiting for a stable optical signal, potentially missing the brief window when the remote device restarts its transmit signal. This is an interoperability issue and may require manual intervention for service restoration.

Resolved In: evo:25.2R2-EVO junos:22.4R3-S8 junos:23.4R2-J2 junos:23.4R2-S5 junos:24.2R2-S3 junos:24.2X1 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1900773
Minor
Firewall terms in the Segmented Filter doesn't work as expected
Product-Group=junos
On MX platforms with MPC10/MPC11/LC4800/LC9600 or MX304, when the Segmented Filter is misconfigured, it can skip a segment that has a valid (possibly the first) matching term. As a result, the terms within the filter that satisfy the error conditions will not match, and the filter will not work as expected.

Resolved In: evo:25.4R1-EVO junos:25.4R1
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1924812
Minor
Dual stack PPPoE/DHCPv6 syslog reports PFE_ERROR_INVALID_STATE fd01:3333:b205:44f1:: /64 => source lookup is not enabled for flow 18558885
Product-Group=junos
Dual stack PPPoE/DHCPv6 syslog reports PFE_ERROR_INVALID_STATE fd01:3333:b205:44f1:: /64 => source lookup is not enabled for flow 18558885

Resolved In: evo:25.4R2-EVO evo:26.2R1-EVO evo:26.3R1-EVO junos:25.4R2 junos:26.2R1 junos:26.3R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1902144
Major
[MFT2.0] : 100% traffic loss for l3vpn resolving over BGP-CT routes
Product-Group=junos
In BGP-CT scenario at ASBR instead of swap operation, we have a pop and push NH programmed which results in pops the transport and service label and then pushes only transport label. Due to this service label is lost and once it reaches Penultimate Hop Router we pops (PHP) the transport label and sends plain IP packet and because service label is lost the DUT is unable to identify the VRF and results in default route reject.

Resolved In:
1913870
Major
Traffic is not passing through GRE-over-GRE tunnel due to keepalive packets are dropped in the outer tunnel
Product-Group=junos
On Junos MX platforms with MPC ( 1 to 9 ) or LC2103 linecards and platforms ( MX5- MX80 ) / MX104 / MX150 / MX204; when Generic Routing Encapsulation (GRE)-over-GRE is configured, end-to-end keepalive packets in the outer tunnel are dropped, and tunnel interface cannot pass traffic.

Resolved In: evo:25.4R1-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1 junos:26.1R1
1924105
Minor
The pfe process crash is observed under rare conditions with sensor-based statistics on MX platforms
Product-Group=junos
On MX platforms with LC2101, LC2103, LC480, MPC1, MPC1E, MPC2, MPC2E, MPC3E, MPC4E, MPC5E, MPC6E, MPC7E, MPC8E, and MPC9E line cards, a Packet Forwarding Engine (PFE) restart is observed when sensor-based statistics are enabled (for example, using set protocols mpls sensor-based-stats) and a rare internal timing condition is encountered during sensor processing.

Resolved In: junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1704406
Major
XML validation failure may be seen with the "show host | display xml validate" command
Product-Group=junos
The XML output of "show host| display xml validate" command results in the "WARNING: Received the tag , the output may not have been properly xmlized." error.

Resolved In:
1735584
Minor
Execution of get-directory-usage-information RPC on yang based client or controller fails with validation error
Product-Group=junos
Execution of get-directory-usage-information RPC on yang based client or controller fails with validation error

Resolved In:
1851232
Major
JUNOS_REG:QFX10008: While performing ZTP from 24.4 "24.4I-20241124.0.2259" to "24.2R1.17", ZTP upgrade fails and unable to connect device.
Product-Group=junos
ZTP upgrade in dual RE fails if the image name has special characters.

Resolved In:
1899597
Major
Getting validation error for get-interface-information rpc execution through ODL controller
Product-Group=junos
Getting validation error for get-interface-information rpc execution through ODL controller

Resolved In: evo:26.2R1-EVO
PR NumberSynopsisCategory: Issues related to NETCONF
1792554
Minor
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241
Product-Group=junos
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241

Resolved In:
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
1803967
Major
While validation XML response for CLI "show system storage" we see ODL validation failure
Product-Group=junos


Resolved In: junos:23.2R2-S5 junos:24.2R2-S3 junos:25.2R2 junos:25.3R1 junos:25.4R1
1815644
Minor
Few of the yang package are unvailable in GNMI capability response
Product-Group=junos
Few of the yang package are unvailable in GNMI capability response

Resolved In:
PR NumberSynopsisCategory: PRs related to PICd and associated lib WAN side PI code.
1914708
Minor
PICD fails to reuse or clean SNMP trap objects, causing memory leak
Product-Group=junos
On all Junos OS Evolved platforms, PICD repeatedly created new SNMP trap objects without removing old ones, causing distributord memory leaks over time. This is tracked under TSB107540 [juniper.net]

Resolved In: evo:24.4R2-S2-J20-EVO evo:24.4R2-S2-J22-EVO evo:24.4R2-S2-J23-EVO evo:24.4R2-S2-J25-EVO evo:24.4R2-S2-J27-EVO evo:24.4R2-S3-EVO evo:24.4R2-S3-J1-EVO evo:25.2R2-EVO evo:25.2X100-D20-EVO evo:25.2X100-EVO evo:25.4R1-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1913169
Major
The smdp process crash is observed on MX Aggregation Device during Junos upgrade in a Junos Fusion Deployment
Product-Group=junos
In all Junos MX platforms acting as the AD (Aggregation Device) in a Junos Fusion deployment, a Junos software upgrade causes the smdp (Satellite Platform and Management Daemon) process to crash impacting forwarding plane services. This issue is observed when AD nodes are moved to a higher Junos version while the SD (Satellite nodes) are still running a lower version.

Resolved In: evo:25.4R2-EVO junos:22.4R3-S7-J7 junos:22.4R3-S9 junos:23.2R2-S6 junos:24.2R2-S6 junos:25.4R2
PR NumberSynopsisCategory: Virtual Private LAN Services
1885690
Major
rpd crash on backup RE during switchover due to VPLS Auto-Site mismatch
Product-Group=junos
An rpd core triggered on the backup Routing Engine after a switchover due to an assertion failure in within the context of L2VPN VPLS auto-site processing, caused by a mismatch between the auto-site claim-id/site-id and the local site-id associated with interfaces in the VPLS IFL repository for a given instance, leading to stale interface entries being referenced during auto-site processing.

Resolved In: evo:24.4R2-S4-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: VSRX platform software
1922165
Major
ED25519 ssh key now supported from AWS and GCP upon vSRX 3.0 instance creation
Product-Group=junos
Starting in 25.4R2, customers can use ed25519 ssh keys from either the web console or CLI of AWS and GCP as well as rsa ssh keys when selecting an SSH key to be able to log into the system with at launch. Configuring the keys through cloud-init config was already supported.

Resolved In: junos:25.4R2 junos:26.1R1 junos:26.2R1
1945668
Minor
Upgrading vSRX to Junos 24.4R2-S3 and above causes AE bundling issues and traffic loss
Product-Group=junos
Upon booting up a Junos vSRX platform following an upgrade to Junos 24.4R2-S3 and above, one or more interfaces may not be seen within the interfaces list from running a "show interfaces terse" for aggregate ethernet (AE) interfaces. Due to this it causes AE bundling issue and interfaces don't come up leading to traffic loss.

Resolved In: junos:25.4R2 junos:26.2R1 junos:26.3R1
PR NumberSynopsisCategory: QFX10002 Platform
1869232
Major
CRC errors increase continuously after interface flap on some 100G transceivers with Rx CDR LOL support
Product-Group=junos
On Junos PTX10002-60C, and QFX10002-60C platforms, when using 100G QSFP modules with Clock and Data Recovery Loss of Lock (CDR LOL) support, CRC errors have been observed on odd-numbered ports, leading to traffic disruptions.

Resolved In: junos:22.4R3-S7-J1 junos:22.4R3-S9