Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, EX, PTX, MX, QFX, vMX, vRR, SRX, vSRX

Alert Description

Junos Software Service Release version 18.1R3-S10 is now available for download from the Junos software download site
Download Junos Software Service Release:
  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 18.1R3-S10 is now available.

18.1R3-S10 - List of Fixed issues

PR NumberSynopsisCategory: Software build tools (packaging, makefiles, et. al.)
1417345The JSU package installation may fail
Product-Group=junos
In a specific scenario, the JSU (Junos OS selective upgrade) package installation on a router which has JET (Juniper Extension Toolkit) package installed may fail due to "Operation not permitted" error. This issue does not impact service and traffic.
  Category: DOT1X
1462479EX-4600-EX-4300: Mac entry missing in Ethernet-Switching table for Mac-radius client in server fail scenario when tagged is sent for 2 client
Product-Group=junos
In case of server_fail scenario, When tagged traffic is sent for first client MAC learning happen for both data and voice. But for second client on same interface learning happening only for voice. Because vlan is already added for an interface due to first client authentication process.
  Category: LLDP
1464553The LLDP packets might get discarded on all Junos platforms
Product-Group=junos
On all Junos platforms, the LLDP packet received from any other vendor might get discarded. The issue is seen when there are two location-id in the same packet and the Junos device considers the LLDP packet as duplicate and discards it. This might result in the PoE phone not coming up or neighborship information not getting exchanged.
  Category: EX4300 PFE
1428124VIP might not forward the traffic if VRRP is configured on an AE interface
Product-Group=junos
On EX4300 platform with VRRP configured on an AE interface, if the VIP address is different than the interface address, VIP address might not forward the traffic destined to the AE interface and not respond to ICMP request.
1491348The traffic destined to VRRP VIP might be dropped after the IRB interface is disabled on the initial VRRP primary
Product-Group=junos
On the EX4300 virtual-chassis scenario, the traffic destined to the VRRP Virtual IP Address (VIP) might be dropped on the Virtual-Chassis if the VRRP IRB interface is disabled on the initial VRRP primary. For details, please refer to the following topology and problem description.
  Category: EX9200 Platform
1467459The MAC move message may have an incorrect "from" interface when MAC moves rapidly
Product-Group=junos
On the EX2300/3400/4300/4600/9200 platform, in some cases, if MAC moves rapidly, traffic might be impacted and the MAC move message might have an incorrect "from" interface.
  Category: EX2300/3400 PFE
1369678Virtual Chassis split followed by fxpc core file might occur upon scaling VLAN members
Product-Group=junos
Virtual Chassis split followed by fxpc core might occur when configuring more than 4000 VLANs, with each VLAN having more than 16 members.
1434646Packet drop might be seen if native VLAN is configured along with flexible VLAN tagging
Product-Group=junos
When the native VLAN is configured along with the flexible VLAN tagging on a L3 subinterface, untagged packets might be dropped on that L3 subinterface.
  Category: EX2300/3400 platform
1452209The MAC Pause frames will be incrementing on Receive direction if half duplex mode on 10M or 100M speed is configured
Product-Group=junos
On EX3400 with half duplex mode on 10M or 100M speed at medium traffic rates, MAC pause frames will be seen on the port and egress traffic on the port will stop to flow.
1452209The MAC Pause frames will be incrementing on Receive direction if half duplex mode on 10M or 100M speed is configured
Product-Group=junosvae
On EX3400 with half duplex mode on 10M or 100M speed at medium traffic rates, MAC pause frames will be seen on the port and egress traffic on the port will stop to flow.
1467707FPCs might get disconnected from EX3400 VC briefly after reboot/upgrade
Product-Group=junos
On EX3400 Virtual Chassis, during reboot or upgrade, because of a high CPU load in slow path of fxpc, TCP keep alive message is not sent. Hence, it is observed that sometimes a few Virtual Chassis members might get disconnected from the Virtual Chassis briefly and join back in 3-6 minutes.
1477165EX3400 me0 interface might remain down
Product-Group=junos
The me0 interface of EX3400 does not come up when connected to 100m speed interface.
  Category: Hardware Escalation
1426910Drift messages in ACX2200 which is a PTP hybrid (PTP+syncE) device
Product-Group=junos
On ACX2200 configured with PTP+SyncE , backup devices might get impacted due to high PDVs. This is observed through drift messages in the router.
  Category: Platform-side analytics for QFX
1456282Telemetry traffic might not be sent out when telemetry server is reachable through different routing-instance
Product-Group=junos
On QFX Series switches (except for QFX10000) with Jvision enabled, the telemetry traffic might be locally dropped when the egress interface to the telemetry server is a part of non-default routing-instance.
  Category: DHCP related Issues
1467182Few of DHCP INFORM packets specific to particular VLAN might be taking the wrong resolve Queue
Product-Group=junos
On QFX5K/EX4600 with DHCP relay scenario, if DHCPv4/v6 packets are coming over irb interface, few of DHCP INFORM packets specific to particular VLAN might be taking the wrong resolve Queue which is not expected.
  Category: QFX Multichassis Link Aggregrate
1488681MClag consistency check for multiple irb's configured with same vrrp-group
Product-Group=junos
The MClag consistency check fails if the same vrrp-group is used for multiple irb configurations on Local and Remote REs of the MCLAG topology. This change corrects the defect and makes the MClag consistency check to pass.
  Category: QFX Access control list
1476708ARP packets are always sent to CPU regardless of whether the storm-control is activated
Product-Group=junos
On QFX5K platforms with VXLAN or VLAN scenario, ARP packets are not rate limited by the storm-control settings as the ARP packets will be copied to CPU by VLAN register settings and can be only rate limited by the CPU Queues rate-limit settings (ARP DDOS Queues).
  Category: QFX PFE L2
1467466Few MAC addresses might be missing from MAC table in software on QFX5k platform.
Product-Group=junos
On QFX5k platform, if Packet Forwarding Engine process is restarted manually or device reboot occurs, some MAC address(es) might not be seen on software MAC table but MAC address will be present in hardware table.
1481031Connectivity is broken through LAG due to members configured with hold-time and force-up
Product-Group=junos
Connectivity through link aggregation group bundle could break after there is a flap event on the physical ports when one physical member interface is configured with hold-time and the other member interface is having LACP force-up feature configured.
  Category: QFX L3 data-plane/forwarding
1437943The IPv4 fragmented packets might be broken if PTP transparent clock is configured
Product-Group=junos
When Precision Time Protocol (PTP) transparent clock is enabled, PTP adds the residence time to the Correction Field of the PTP packets as they pass through the device. On QFX5K platforms with PTP transparent clock enabled, the IPv4 fragmented packets of UDP datagram might be broken by PTP in some rare scenario, and the corrupted packets will be discarded by system. This issue has traffic impact.
1460791JDI-RCT : QFX 5100 VC/VCF : Observing Error brcm_ipmc_route_counter_delete:3900Multicast stat destroy failed (-10:Operation still running) after ISSU with Mini-PDT base configurations
Product-Group=junos
"multicast stats related errors like " brcm_ipmc_route_counter_delete:3900Multicast stat destroy failed (-10:Operation still running)" will be observed during ISSU and these messages are harmless and does not affect multicast functionality".
1485612FPC may go to "NotPrsnt" state after upgrading with non-tvp image in VC/VCF setup
Product-Group=junos
On EX4600/QFX5100 platform, there are two types of PIC (Physical Interface Card). The first one is PIC with the integrated PHY capability (called PHYLESS). The second one is PIC with an external PHY capability (called PHY). If VCPs (Virtual Chassis Port) are configured on external PHY capability PIC(s), the FPC(s) might go to "NotPrsnt" state after upgrading with non-tvp image in VC/VCF setup. The affected FPC(s) cannot be used to forwarding traffic.
1487707CPU port queue gets full due to excessive pause frames being received on interfaces, this causes control packets from the CPU to all ports to be dropped
Product-Group=junos
On QFX5000 platforms (QFX5100/QFX5110/QFX5120/QFX5200/QFX5210) with point-to-point multi-link scenario, when the switch ingress buffer saturation happens, all interfaces on multi-link stop sending traffic at the same time.
  Category: QFX PFE MPLS
1475395Traffic blackhole might be seen on PE when CE sends traffic to PE and the destination is resolved with two LSPs through one upstream interface
Product-Group=junos
On QFX5K platforms with Layer3 VPN scenario, when CE sends traffic to PE and the destination is resolved with two LSPs through one upstream interface, the traffic blackhole might be seen on PE. It happens in ECMP scenario.
  Category: MPC Fusion SW
1463859The MPC2E-NG/MPC3E-NG card with specific MIC might crash after a high rate of interface flaps
Product-Group=junos
If any MIC of type MIC-3D-2XGE-XFP / MIC-3D-4XGE-XFP / MIC-3D-20GE-SFP-E / MIC-3D-20GE-SFP-EH / MIC-MACSEC-20GE is installed in MPC2E-NG/MPC3E-NG card, the Microkernel (uKern) might hog for CPU on Packet Forwarding Engine (PFE) when there is a high rate of interface flaps (~30/40 flaps per second). This will eventually trigger the MPC2E-NG/MPC3E-NG card crash with an NGMPC core file. Normally the excessive interface flapping won't happen frequently in the real-world and it may be caused due to the external environment. This fix will reduce the impact and prevent the uKern hog when having such conditions. The fix for this issue causes a regression as documented in TSB17782 [juniper.net] and PR1508794 which affects interfaces with "WAN-PHY" framing.
  Category: a2a10 specific issue
1471524The flowd and srxpfe process might stop immediately after you commit the jflowv9 configuration or after you upgrade Junos OS to affected releases.
Product-Group=junos
On all SRX platforms, if Jflow v9 is configured on the device, the flowd/srxpfe daemon might crash when committing the configuration or after upgrading to affected releases. It might show as a hung state for the device or the device will crash. Affected Releases are 12.3X48-D80 to D95 and 15.1X49-D160 to D200.
  Category: These are new categories in the areas of PFE
1460209Loop detection might not work on extended ports in Junos Fusion scenarios
Product-Group=junos
In Junos Fusion scenarios, if loop detection is enabled on extended ports, when a satellite device (SD) is rebooted, or when a satellite device is added or removed/re-added, the loop detection feature might not work.
  Category: BBE Resource monitoring related issues
1431566Subscribers coming from new IFDs might not login in due to 512 entries limit in the subscriber-limit table.
Product-Group=junos
On MX platforms, in subscriber management scenario, if the 512 entries are exhausted in the subscriber-limit table, the subscribers which come from new IFDs might not login in.
  Category: Bi Directional Forwarding Detection (BFD)
1470603The BFD client session might flap when removing BFD configuration from the peer end (from other vendor) of the BFD session
Product-Group=junos
Currently, when a BFD packet with session state set to "AdminDown" is received by Juniper Device, the Juniper device will check both the session state and the diagnostic code in the packet. If the session state is "AdminDown" and the diagnostic code is 7 (which means "diag AdminDown"), the BFD session will be set to "Down" and the BFD client (i.e. the service which is protected by BFD) will be notified with "AdminDown" and the BFD client session will not flap. But if the BFD packet with session state set to "AdminDown" along with diagnostic code other than 7 is received, the BFD client will be notified with "Down" and the BFD client session will flap.
  Category: Border Gateway Protocol
1403186All the BGP session flap after RE switchover
Product-Group=junos
With GRES and NSR enabled, if executing RE switchover, BGP session might flap in some scenario. When Junos version have the fix of PR-1440694, BGP session always flap after doing RE switchover.
1414121QFX5100 : BGP v4/v6 convergence & RIB install/delete time degraded in 19.1R1/19.2R1/19.3R1/19.4R1
Product-Group=junos
BGP IPv4 or IPv6 convergence and RIB install/delete time is degraded in Junos OS Releases 19.1R1, 19.2R1, 19.3R1, and 19.4R1.
1437837The rpd process crash might be observed if leaking multi-pathed BGP routes from routing-instance to another routing table
Product-Group=junos
This issue applies to Junos platforms with BGP multipath configured under a routing-instance and a RIB group is deployed to leak routes from that routing-instance to another routing table. "rpd" may restarts unexpectedly when performing multipath calculation operations for the secondary routes - (such as, removing the rib-groups/bouncing BGP neighbor under routing-instance.) The secondary routes refer to the second RIB in a RIB (Routing Information Base) group.
1461602The rpd scheduler slips might be seen on RPKI route validation enabled BGP peering router in a scaled setup
Product-Group=junos
In scaled BGP environment (e.g. global table ~3M routes or more) when there are a lot of (e.g 10k or more) more specific routes for a certain IPv4 or IPv6 prefix covered by some RV (route validation) record, a change in RV records database might lead to rpd (routing protocol daemon) scheduler slips, which could trigger routing protocol adjacency flap. The same could be triggered by executing "clear validation database" command or shortly after initial session RPKI (resource public key infrastructure) establishment event.
1472671The rpd process might crash with BGP multipath and damping configured
Product-Group=junos
On all Junos platforms running with Border Gateway Protocol (BGP), if both BGP multipath and BGP damping are configured, it might happen that, when the active route, for example r1, is withdrawn but it is not really deleted due to damping, then BGP might be unable to find its original gateway when the route r1 is relearned and becomes the best route again. It will lead to the rpd process crash.
1473351Removing cluster from BGP group might cause prolonged convergence time
Product-Group=junos
Cluster removal from BGP group might lead to a state where each subsequent change to BGP configuration will trigger import policy reevaluation causing prolonged convergence time of several minutes. This might result in a traffic loss.
1482551The rpd might be crashed after BGP peer flapping
Product-Group=junos
On all Junos platforms, with BGP long-lived graceful restart (LLGR) or BGP route dampening configuration, The rpd might be cored after BGP peer flapping. This is a day-1 issue.
1487691High CPU utilization might be observed when the outgoing BGP updates are sending slowly
Product-Group=junos
On all Junos platforms with the BGP routing protocols, the rpd process might go into a high CPU utilization causing slow network convergence. If a BGP peer is receiving and processing BGP updates slowly, this may cause the BGP output queue of the sending BGP peer to be full. When the queue is full it causes high CPU utilization of the BGP IO thread (bgpio, it is part of the rpd daemon) on the sending BGP peer. This defect could cause network-wide slow BGP network convergence. (See also https://kb.juniper.net/TSB17725 [juniper.net])
1487893The process rpd may generate soft cores after "always-compare-med" is configured for BGP path-selection
Product-Group=junos
If a manually configured rib-group or automatically generated rib-group (via "family inet labeled-unicast resolve-vpn") is used to copy inet.0 (IP routing table) routes to inet.3 (MPLS routing table), the process rpd may continuously generate soft cores after "protocols bgp path-selection always-compare-med" is configured.
  Category: BBE Remote Access Server
1479697The CoA request may not be processed if it includes "proxy-state" attribute
Product-Group=junos
In a subscriber management environment, the CoA requests (such as deactivating/activating subscribers) sent from Radius server will fail if the "proxy-state" attribute is present. This attribute is still unsupported but will now be ignored if it's present in CoA requests.
  Category: Captive Portal, Content Delivery Daemon, and Service Plugin
1445382The cpcdd process might crash continuously if the captive-portal-content-delivery service is activated for dual-stack PPPoE/DHCPv6 subscriber. Basically issue can occur when multiple add request for same subscriber and same IFL.
Product-Group=junos
On MX platforms running with subscriber-management enabled, if the single client connection of Point-to-Point Protocol over Ethernet (PPPoE) dual-stacked with Dynamic Host Configuration Protocol version 6 (DHCPv6) is established, and then the captive-portal-content-delivery (CPCD) service is activated for both PPPoE and DHCPv6 sessions, the cpcdd process might crash continuously and stop working due to this issue. Basically issue can occur when multiple add request for same subscriber and same IFL.
  Category: L2NG Access Security feature
1478375The process dhcpd may crash in a Junos Fusion environment
Product-Group=junos
On EX92XX platforms with the DHCP snooping configured, if a peer receives DHCPv6 packets from the server without the "client-id" option present, and it is syncing packets to the other side at that time, then the process dhcpd crash may be observed.
  Category: OpenSSH and related subsystems
1454177SSH login might fail if a user account exists in both local database and RADIUS/TACACS+.
Product-Group=junos
SSH login from an automation tool to the Junos device might not be successful if the username is configured both as a local user and on remote RADIUS/TACACS server, and using authentication method 'password'.
  Category: Device Configuration Daemon
1457460Mismatched MTU value causes the RLT interface to flap
Product-Group=junos
In Redundant Logical Tunnel (RLT) with any dynamic protocols that rely on this interface scenario, when performing a "commit full" operation, which might cause the protocol to get flapping if MTU is configured at IFD level of the RLT. Due to the mismatch MTU value calculated by DCD and Kernel that triggers the IFD flapping, and then the protocols flapping.
  Category: dhcpd daemon
1471161DHCP relay with forward-only might fail to send OFFER messages when DHCP client is terminated on logical tunnel interface
Product-Group=junos
On all Junos platforms, when DHCP relay is configured with forward-only, and DHCP client is terminated on logical tunnel interface that multiple IFLs under this lt- interface have a same VLAN, DHCP relay might fail to send OFFER messages.
  Category: Covers Application classification workflows apart from custo
1455465The traffic loss might occur when application service is configured
Product-Group=junos
On vSRX3.0 platform, traffic loss might occur when application service is configured.
1455465The traffic loss might occur when application service is configured
Product-Group=junosvae
On vSRX3.0 platform, traffic loss might occur when application service is configured.
  Category: JUNOS Dynamic Profile Configuration Infrastructure
1421589bbemg_smgd_lock_cli_instance_db should not log as error messages
Product-Group=junos
The "bbemg_smgd_lock_cli_instance_db: lock/unlock failed" messages are harmless and should not be considered as error:
  Category: Ethernet OAM (LFM)
1396540V44-CFM: NPC crash @ rt_nh_install (rnh=0x618123d8, rnh_src=0x0, rt=< optimized out>, p_rtt=0x74f886c0) at ../../../../src/pfe/common/pfe-arch/trinity/applications/route/rt_nh.c:631
Product-Group=junos
As part of the EOAM programming the LM counters are allocated. When an interface is deleted, the EOAM LM counters needs to be cleared. This is done as part of EOAM punt deletion. But there are scenarios where the prog punt delete processing is received, the IFL is deleted in ukern. In this case the EOAM NHs are cleared but the LM counters are not freed. this can cause memory leak in jnh. This issue is seen for a scaled config, repeated addition and deletion of the interface configs when EOAM config is present
  Category: EVPN control plane issues
1399371When committing a configuration for a VLAN adding to an EVPN instance and an AE interface respectively the newly added VLAN interface count might be zero (0) in that bridge domain
Product-Group=junos
On all MX-Series platforms with EVPN supported, when committing a configuration for a VLAN adding to an EVPN instance and an AE interface respectively the newly added VLAN interface count might be zero (0) in that bridge domain and causes all the traffic in that VLAN to be blocked. However, if the two configurations are committed all together in one time, the interface count will be the correct number right after the committing.
1467309The rpd might crash after changing EVPN related configuration
Product-Group=junos
In EVPN scenario without encapsulation type specified (the default EVPN encapsulation type is set to MPLS), if "vlan-id none" and "vni " is configured in EVPN instance, the rpd might crash after changing EVPN related configuration (such as set the encapsulation as vxlan or delete label-allocation scheme).
1482790The ESI of IRB interfaces does not update after autonomous-system number change if the interface is down
Product-Group=junos
On EX, QFX and MX platforms, Ethernet Segment Identifier (ESI) of IRB interfaces does not update after autonomous-system number change when IRB interface is in DOWN state.
1490953The rpd core might be seen when doing RE switchover after disabling BGP protocol globally
Product-Group=junos
On EVPN scenario with BGP and routing-instance configured, if BGP protocol is disabled globally and then doing RE switchover, multiple rpd core might be seen. And the rpd does not run on new primary RE. Hence it would affect the traffic and service.
  Category: EVPN Layer-2 Forwarding
1498023The l2ald memory leak may be observed in any EVPN scenario
Product-Group=junos
In any EVPN scenario (e.g. active-active multi-homing mode, active-standby multi-homing mode, EVPN-VxLAN, or EVPN-MPLS), the l2ald (Layer 2 Address Learning Daemon) memory may slowly come up when the local CE or core face interfaces continuously flap. If the memory of l2ald is exhausted, it will cause the l2ald to crash.
  Category: Issues related to EX MACsec
1469663Traffic loss might be seen with framing errors or runts if MACsec is configured on EX4600/QFX5100 platforms
Product-Group=junos
On EX4600/QFX5100 platforms with Media Access Control Security (MACsec) configured, if there is traffic flowing through the MACsec enabled link, increasing framing errors or runts statistics might be seen in the output of "show interfaces extensive <>" for the affected interface. Traffic loss might also happen due to this issue.
  Category: Express PFE FW Features
1462634The sample/syslog/log action in output firewall filter with packet of size less than 128 might cause ASIC wedge (all packet loss) on PTX platforms
Product-Group=junos
On PTX platforms, if output firewall filter is configured with sample/syslog/log action, the host interface might get wedged for packets with lengths 0-128 including Layer 3 headers.
1470385Incorrect counter value for "Arrival rate" and "Peak rate" for ddos commands
Product-Group=junos
On PTX1000/PTX3000/PTX5000/PTX10000/PTX9000/QFX10000, sending hostpath traffic and check the ddos statistics might lead to incorrect counter value for "Arrival rate" and "Peak rate" for ddos commands
1491575BFD sessions start to flap when the firewall filter in the loopback0 is changed
Product-Group=junos
On all Junos based PTX/QFX10000 series platforms with large filter configuration (e.g. one filter has more than 500 terms or one term has more than 500 filters) scenario, during the change operation of loopback0 filter, the bfd sessions start to flap.
  Category: SRX1500 platform software
1402242Unable to access to SRX Series devices if messages kern.maxfiles limit exceeded by uid 65534, please see tuning(7) are seen.
Product-Group=junos
On SRX platforms (except SRX5400,SRX5600,SRX5800) the messages "kern.maxfiles limit exceeded by uid 65534, please see tuning(7)" may appear on console or on messages log, then management access to the device is impossible.
1403727Throughput or latency performance of all traffic drops when TCP traffic is passing through the device.
Product-Group=junos
On vSRX, SRX1500, SRX4100,SRX4200 and SRX4600 platforms, when TCP Traffic is passing through the device for a certain period, throughput performance of all traffic is dropped about two thirds and latency performance of all traffic is increased up to around 20 ms.
1438445The flowd process stops and generates core files.
Product-Group=junos
On vSRX, SRX100, SRX110, SRX210, SRX220, SRX240, SRX300, SRX320, SRX340, SRX345, SRX550, SRX650, and SRX1500 devices, and the SRX4000 line of devices, in a rare condition, the flowd process goes into a dead loop and then stops. This might cause traffic loss.
  Category: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1472643Performing back-to-back rpd restarts might cause rpd to crash
Product-Group=junos
On all Junos platforms, after performing back-to-back rpd restarts, rpd might crash. The rpd core may be observed after a timeout of 10 mins.
  Category: Kernel software for AE/AS/Container
1390367Traffic destined to VRRP VIP gets dropped as filter is not updated to related logical interface
Product-Group=junos
On MX platform with enhanced-ip and VRRP configured, if remove/add a child link from AE bundles, traffic destined to VRRP VIP might be dropped.
1474300A newly added LAG member interface might forward traffic even though its micro BFD session is down
Product-Group=junos
On all Junos platforms, if a static Link Aggregate Group (LAG) is configured, and Bidirectional Forwarding Detection (BFD) is enabled on the LAG which is also called as micro BFD, a newly added member link might start to forward traffic immediately when the configuration change commits even though its micro BFD session is still down, for example, add a new member interface only on single end, and the remote member interface is disabled or not added. Therefore, traffic loss might be seen due to this issue.
  Category: Optical Transport Interface
1429279After member interface flapping AE remains down on 5X100GE DWDM CFP2-ACO PIC.
Product-Group=junos
On 5X100GE DWDM CFP2-ACO PIC on PTX series platforms, if any AE member interface flaps, the AE interface might stop receiving the LACP RX packets and fail to come up. It can be recovered by disabling/enabling the AE interface.
  Category: Integrated Routing & Bridging (IRB) module
1484721ARP entry may not be created in the EVPN-MPLS environment
Product-Group=junos
In the EVPN-MPLS environment, if a VLAN is created without having it in "protocols evpn extended-vlan-list", then adding it, the ARP entry may not be created on the device even it receives the ARP packets through the newly added VLAN.
  Category: jdhcpd daemon
1431201The jdhcpd_era log files constantly consume 121M of space out of 170M, resulting into file system full and traffic impact
Product-Group=junos
On EX platforms with service dhcp enabled, the jdhcpd_era log files constantly consume 121M of space out of 170M, resulting into file system full and traffic impact. Memory usage of /var/log/ will reach 100%.
1435039DHCP request might get dropped in a DHCP relay scenario
Product-Group=junos
In DHCP relay scenario, if the device (DHCP relay) receives a request packet with option 50 where the requested IP address matches the IP address of an existing subscriber session, such request packet would be dropped. In such a case the subscriber may need more time to get IP address assigned. The subscriber may remain in this state until it's lease expires if it has previously bound with the address in the option 50.
1496220Issues with DHCPv6 Relay processing Confirm and Reply packets
Product-Group=junos
When wired DHCPv6 clients change VLAN and an existing DHCPV6 relay binding exists on another VLAN, the DHCPv6 CONFIRM packets from the client may not get processed correctly on the relay resulting in connectivity issues
  Category: Adresses ALG issues found in JSF
1483834FTPS traffic might get dropped on SRX Series or MX Series platforms if FTP ALG is used
Product-Group=junos
On SRX Series or MX Series platforms with FTP ALG enabled, if there are more than one FTPS connection between a pair of FTP client and server, the closure of one connection might cause other connections between that pair of FTP client and server to be affected, hence there might be traffic impact. It is a rare timing issue.
  Category: Firewall Authentication
1475435SRX Series: Unified Access Control (UAC) bypass vulnerability (CVE-2020-1637)
Product-Group=junos
A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are not permitted by a UAC policy; Refer to https://kb.juniper.net/JSA11018 [juniper.net] for more information.
  Category: Flow Module
1406210The flowd process stops and all cards are brought offline.
Product-Group=junos
On all SRX platforms, in a rare condition, the flowd process might crash if there is a route change for IPSec tunnel traffic and the traffic does not go through the tunnel after reroute. This issue might cause all cards off.
  Category: Firewall Network Address Translation
1479824Issuing the show security nat source paired-address command might return an error
Product-Group=junos
On the SRX series platforms with source NAT configuration, issuing the command "show security nat source paired-address ..." may return an error, which is not expected. It's a corner case, and not reproduced all the time.
  Category: Firewall Policy
1414319Memory leak in nsd prevents change from taking effect.
Product-Group=junos
In some case, changing configuration might trigger memory leak in the nsd daemon. It is possible committed configuration change will not take effect.
  Category: User Firewall related issues
1499090Don't use capital characters for source-identity when using "show security match-policies" cmd.
Product-Group=junos
When using "show security match-policies" cmd to match a policy with source-identity configured, only the non-capital source-identity name can be matched by policy.
  Category: Security platform jweb support
1499280Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services
Product-Group=junos
Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services (CVE-2020-1631). Refer to https://kb.juniper.net/JSA11021 [juniper.net] for more information.
  Category: Layer 2 Circuit issues
1498040The l2circuit neighbor might be stuck in RD state at one end of MG-LAG peer
Product-Group=junos
In MC-LAG scenario, if the l2circuit is configured with primary-neighbor/backup-neighbor over the MC-LAG link and the l2ckt (l2ciruits control daemon for pseudowire) session of the primary-neighbor/backup-neighbor is flapped continuously (such as clear neighbor ldp and ospf etc), one of the remote neighbors may be stuck in RD (the remote pseudowire neighbor is down) state due to race condition between VC (virtual circuit) state update timer and L2ckt intf state change timer. Then, that pseudowire might be down, the traffic might be impacted if the RD pseudowire is not up.
  Category: Layer2 forwarding on EX/NTF/PTX/QFX
1406691Some interfaces of AE bundle might go to the detached state after the bulk configurations change on QFX5K platforms
Product-Group=junos
On QFX5000 platforms with scaled setup of the aggregated Ethernet (ae) bundles and VLANs, if Link Aggregation Control Protocol (LACP) is enabled, and there are scaled configuration changes, for example, delete 4000 VLANS/VXLANs and reapply them again, some interfaces of ae bundle might go to the detached state. Due to this issue, the running routing protocols (for example, LACP and BGP) will go down over the affected ae bundles.
1484468Packet loss might be observed after device rebooted or l2ald restarted in EVPN-MPLS scenario
Product-Group=junos
In EVPN-MPLS scenario, if the core-facing interface (mpls interface) and the CE-facing interface are on different PEs, and the traffic from core is not continuous and DMAC (Dynamic MAC) ages out, due to an incorrect flood next-hop programming across different PFEs, packet loss might be observed after device rebooted or l2ald restarted.
  Category: mc-ae interface
1447693The l2ald might fail to update composite NH
Product-Group=junos
This is a timing issue where the l2ald receive underlay NH from rpd as part of LSI IFF ADD (VPLS core NH) and creates flood NH. Due to a flap at local IFL or core (VPLS etc.), the l2ald receives multiple LSI IFF Add and Delete in some order. In some sequence where rpd delete underlay NH from Kernel Forwarding table but the l2ald still create flood NH with this underlay NH, because IFF delete is yet to be received at the l2ald, so l2ald might fail to update Composite NH. This is generic L2 issue and can happen without mc-ae.
  Category: Application specific PRs (cos/snmp/time-sync/routing/BRAS)
1429797Extended Ukern thread(PFEBM task) priority to support BBE performance tuning
Product-Group=junos
Original PFEBM task, which is system-critical for internal network performance/resilience, was running a medium priority; Can see tnp queue errrors by 'show pfebm all' on VCP-bearing FPC when high rate of punt traffic (like ARPs or BGP route updates, etc.) which go through VC links. It needs to run at high priority to assure timely packet handling.
1493699[subscriber_services] [all] JDI_BBE_REGRESSIONS: DHCP subscribers not coming up as expected after deactivating vcp port
Product-Group=junos
In 20.1R1, for MX-VC platforms, setting or deleting a VC port causes other VC ports on the same FPC/MIC slot to bring link state down for a few seconds, possibly interrupting communication with the other member chassis.
  Category: Multiprotocol Label Switching
1465902The device may use the local-computed path for the PCE-controlled LSPs after link/node failure
Product-Group=junos
In a Path Computation Element Communication Protocol (PCEP) scenario where the link/node protection is enabled, the PCE-controlled LSPs may shift to the local-computed path after link/node failure upon path retry processing.
1497641The rpd might crash when SNMP polling is done using OID "jnxMplsTeP2mpTunnelDestTable"
Product-Group=junos
In a very rare P2MP with SNMP scenario, if the OID "jnxMplsTeP2mpTunnelDestTable" is polled by SNMP, the rpd (Routing Protocol Daemon) might crash since the relevant value is empty on the device and SNMP can not walk it at that time.
  Category: Multicast for L3VPNs
1460625The rpd process might crash due to memory leak in "MVPN RPF Src PE" block
Product-Group=junos
In NG-MVPN scenario with multiple multicast sources, the rpd process might crash due to memory leak in "MVPN RPF Src PE" block.
  Category: build tools
1290089jcrypto syslog help package and events are not packaged even when errmsg is compiled
Product-Group=junos
jcrypto syslog help package and events are not packaged even when errmsg is compiled properly. Several of the KMD help syslog entries are missing
  Category: FreeBSD Kernel Infrastructure
1439906FPC might reboot if jlock hog occurs on all Junos VM based platforms
Product-Group=junos
On a JUNOS VM using TSC clocking from the host system, "jlock hog" messages may be seen. This may lead to FPCs reboot.
  Category: "ifstate" infrastructure
1486161Kernel core might be seen if deleting an ifstate
Product-Group=junos
On all Junos platforms, some operations such as configuration change may cause state information to change and eventually cause the ifstate to be deleted. In a very rare case, deleting an ifstate (kernel state) might cause kernel core and RE (Routing Engine) restart. There is no specific trigger, this issue is reported by the configuration change.
  Category: Kernel MPLS / Tag / P2MP Infrastructure
1478806Kernel crash and device restart might happen
Product-Group=junos
In a corner case on Junos platform, where the family ccc is configured along with any other existing family within the same interface, like inet, inet6, etc. (basically, Junos never allows to do so, but somehow a customer did it ). And if the family ccc is deleted from the interface, which might cause kernel crash and the device reboot automatically, so all the traffic will be interrupted.
1493053Backup RE might crash unexpectedly due to a rare timing issue
Product-Group=junos
The backup Routing Engine might crash unexpectedly due to a rare timing issue during a route churn in the network.
1493431BGP session might keep flapping between two directly connected BGP peers because of the wrong TCP-MSS in use
Product-Group=junos
In case the two directly connected BGP peers are established over a one-hop LSP, if the IP layer's MTU is smaller than the MPLS layer's MTU, plus the BGP packets from the host have the DF bit set, the BGP session might keep flapping because of the wrong TCP-MSS in use.
  Category: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1484689Show system buffer command display's all zero in the MX104 chassis and it looks like cosmetic issue as there is no service impact reported
Product-Group=junos
Corrected the odl tags and buffer data handling while xmlizing the output.
  Category: PTX Broadway based PFE MPLS-LSPs RSVP VPNs tcc ccc software
1484255FPC might crash when dealing with invalid next-hops
Product-Group=junos
On PTX3000/PTX5000 platform with some specific FPCs, if the weights of links are set to an invalid value on an AE bundle interface or unilist (an unilist next-hop composed of several unicast next-hops), the FPC crash might be observed. It is a rare issue and the FPC will try to reload to resolve this problem. Traffic loss might be seen before the FPC completes the reload period.
  Category: PTX5KBroadway based PFE IPv4, IPv6 software
1479789Multicast routes add/delete events might cause adjacency and LSPs to go down
Product-Group=junos
In PTX5000 platform with (FPC2-PTX-P1A | FPC-PTX-P1A), or PTX3000 with FPC-SFF-PTX-P1-A, with PIM scenario, The adjacency relationships of routing protocols and LSPs might go down if add/delete some multicast routes (which can be achieved by flapping interface or protocol) ). It is because that though the routes are deleted, its counter for statistic will not be removed from Junos resulting in memory block for counter exhaustion. And due to the exhaustion, any protocols that are sharing the same memory scope might fail to allocate its own counter, which eventually causes protocol adjacency and LSPs to go down. [TSB17747 [juniper.net]]
  Category: PTP related issues.
1421811PTP might not work on MX104 if phy-timestamping is enabled
Product-Group=junos
On MX104 platform with any 2-port license installed on 10G interfaces and phy-timestamping enabled in PTP, PTP might not work.
  Category: Chassis mgmt for all QFX systems - chassis MIB, alarms, CLI
1455201In a 16+ member QFX5100 VCF, the "FROM" column under the "show system users" shows wrong information
Product-Group=junos
In a 16+ member QFX5100 VCF, the "FROM" column under the "show system users" output reports "feb0/1/2/3" instead of showing "fpc16/17/18/19" respectively.
1456742The laser from the 10G SFP+ interface is still on when the interface is disabled or the device is rebooted
Product-Group=junos
On the QFX5210/QFX5110/QFX5100 platform, the laser is still emitting from 10G SFP+ port even though the interface is disabled or the device is rebooted. It will cause the peer's interface is still up and might impact traffic.
1458514QFX5210 : LED does not light on port 64 and 65 after upgraded to 19.2R1.
Product-Group=junosvae
On QFX5210, physical LED does not light on port 64 and 65 though traffic is passing through.
  Category: Interface related issues. Port up/down, stats, CMLC , serdes
1465302The physical interface of AE (Aggregated Ethernet) might take time to come up after disable/enable
Product-Group=junos
On Junos platforms, the physical interface of AE might come up after a long delay (4 mins) if there are millions of bgp routes learnt on the device. This delay is happening because PFE Manager thread is busy processing the routing updates from RE. These routing updates are the result of AE interface going down at the first step of disabling the interface.
  Category: QFX Control Plane Kernel related
1421250A vmcore is seen on QFX VC
Product-Group=junos
On QFX Series Virtual Chassis during shutdown, if an interrupt is received, the system gets into this state and vmcore is observed.
1421250A vmcore is seen on QFX VC
Product-Group=junosvae
On QFX Series Virtual Chassis during shutdown, if an interrupt is received, the system gets into this state and vmcore is observed.
  Category: QFX Platform related (SYSLOG/ALARMS/miscellaneous)
1449977FPC does not restart immediately after rebooting the system. That might cause packet loss
Product-Group=junosvae
On QFX10008 and QFX100016 switches, the traffic drop occurs after rebooting the system due to the time delay in rebooting the FPC.
1471216The speed 10m might not be configured on the GE interface
Product-Group=junos
On QFX5100 and EX4300 mixed-mode Virtual Chassis, the speed 10m might not be configured on the GE interface.
1498175QFX5210: Unexpected behaviour see for Port LEDs lights post Upgrade
Product-Group=junosvae
After upgrading QFX5210 to the affected releases, Port LED lights misbehaviour could be seen as follow. i. 40G port LED show amber instead of green ii. 2x50g port LED not lit. iii. 2x25g port LED shows white instead of green. There is no impact to packet forwarding on the port. The issue is cosmetic and only LED colour is affected. It can be resolved after doing a Junos upgrade to one of the fix releases. With the fix, Port LEDs glow green as expected
  Category: QFX platform optics related issues
1382803FEC error counts not updating for QFX5110
Product-Group=junos
On QFX5110, interface FEC counter does not work though FEC function has been supported. Added stats counter support through this PR.
1457266QFX5110 QSFP-100GBASE-SR4 made by Avago cannot linkup
Product-Group=junos
On QFX5110, interface on QSFP-100GBASE-SR4 whose Xcvr vendor is Avago on the QFX side cannot linkup, FEC errors might be seen on the other side. Note : Do not use 19.3R2-S2, 18.2R3-S3 and 18.2R3-S4 for this fix. The fix causes that FPC will go down when 100G link comes up and this leads FPC up and down every 90 seconds. The fix will work on 19.3R2-S3 and 18.2R3-S5 properly.
  Category: Filters
1480776ARP request packets for unknown host might get dropped in remote PE in EVPN-VXLAN scenario
Product-Group=junos
In EVPN-VXLAN environment, when local CE sends ARP request packets for unknown host, the packets will hit firewall-host queue in remote PE. It might trigger DDoS protection policer violations for firewall-host queue hence the ARP request packets might get dropped.
  Category: QFX L2 PFE
1385954"CMQFX: Error requesting SET BOOLEAN, illegal setting 66" is generated at booting up
Product-Group=junos
The following log may be generated at booting up. >> Feb 10 02:15:26 jtac-qfx5100-48s-6q-r2373 : %PFE-3: fpc0 CMQFX: Error requesting SET BOOLEAN, illegal setting 66. This is a cosmetic log and you can ignore the log safely.
1473685The RIPv2 packets forwarded across a L2circuit connection might be dropped
Product-Group=junos
When RIPv2 routes are received on a QFX5100/EX4600 platforms, either to or from an L2 circuit connection, such packets are not propagated. This includes directed unicast RIPv2 packets.
  Category: QFX MPLS PFE
1474935L2circuit might fail to communicate via VLAN 2 on QFX5K platforms
Product-Group=junos
On QFX5K platforms acting as L2circuit PE (tunnel terminating node), if VLAN 2 is used for L2circuit communication with CE node, the VLAN 2 packets might be dropped on PE.
  Category: QFX VC Infrastructure
1414492VC Ports using DAC may not establish link on QFX5200
Product-Group=junos
On QFX5200, when virtual-chassis is configured, if the QSFP configured as VCP is removed and then inserted, VC Ports using direct attach copper (DAC) may not establish link.
1478905The default VC MAC persistence timer is incorrectly set to 20 seconds instead of 20 minutes
Product-Group=junos
In QFX5200-32C, QFX5110 VC (Virtual Chassis) scenario, the default VC MAC (Media Access Control) persistence timer is incorrectly set to 20 seconds instead of 20 minutes. If the primary VC member is rebooted, the new primary member starts using its own MAC address as the system's MAC base address after only 20 seconds instead of 20 minutes. This results in issues like OSPF (Open Shortest Path First) stuck in "init" state after the primary VC member reboot.
  Category: Routing Information Protocol
1485009The rpd crashes if the same neighbor is set in different RIP groups
Product-Group=junos
If the same neighbor is configured under different RIP groups, the commit check fails to capture this invalid configuration and commit can be done successfully. However the rpd will crash.
  Category: rosen-6 and rosen-7 mvpn bugs
1405887The CLI command "show pim mdt data-mdt-limit instance " with family option might cause CPU usage of rpd high
Product-Group=junos
In draft-rosen MVPN scenario with data-mdt, if performing the CLI command "show pim mdt data-mdt-limit instance ", The output might go in loop and the rpd process might use high CPU.
  Category: RPD Interfaces related issues
1478523The FPC with 'vpn-localization vpn-core-facing-only' configured might be stuck in ready state
Product-Group=junos
On all Junos platform with MVPN scenario, when 'vpn-localization vpn-core-facing-only' is configured, the FPC should be restart when MVPN configuration is changed. But if there is a large-scale configuration that includes "vpn-localization vpn-core-facing-only" and vt-ifl under mvpn instance, when performing configuration removal/restoration(load baseline, commit, rollback 1, commit again), the FPC might be stuck in ready state due to cleanup failure of vt-ifl under MVPN instance.
  Category: RPD policy options
1450123The rib-group might not process the exported route correctly
Product-Group=junos
The rib-group with a policy that matches route next-hop can fail to add the route to the secondary routing table when matched route next-hop is changed to another one and then referred back again after some time. This issue has traffic impact as the exported route will lose in the secondary routing table.
  Category: show route table commands, tracing, and syslog facilities
1421076RPD crash might occur when changing prefix list address from IPv4 to IPv6
Product-Group=junos
RPD crash might occur when changing a prefix-list address from IPv4 to IPv6 with "replace-pattern"
  Category: Resource Reservation Protocol
1359087The FPC might be stuck in 'Ready' state after applying a configuration change that will remove RSVP and trigger FPC restart
Product-Group=junos
When 'tunnel-services' is configured under 'chassis fpc <> pic <>', the vt-x/y/z physical interface (IFD) is created for the corresponding FPC. If 'protocols rsvp' is configured, RSVP will create a default vt-x/y/z.u logical interface (IFL) under the corresponding vt-x/y/z IFD. After applying a configuration change that will remove RSVP and trigger FPC restart, the vt-x/y/z.u IFL is not cleaned up due to a code issue. Hence the corresponding vt-x/y/z IFD cannot be cleaned up during the corresponding FPC coming up. The IFD cleaning keeps retrying which cause the corresponding FPC to be stuck in 'Ready' state.
1490163High CPU utilization for rpd might be seen if RSVP is implemented
Product-Group=junos
On all Junos platforms, when Multiprotocol Label Switching (MPLS) is configured with Resource Reservation Protocol (RSVP) as signaling layer, CPU utilization for rpd might be high (more than 20%) if the MPLS ingress route has more than 32 equal-cost multipath (ECMP) next-hops. As a result, performance of the device might be affected.
  Category: jflow/monitoring services
1439630Sampling might return incorrect ASN for BGP traffic
Product-Group=junos
In a BGP scenario with sampling enabled, incorrect ASN (autonomous system number) might be returned for the traffic originated from an internal prefix. This is because some AS paths and routes don't hold the latest information in the message buffers that srrd (sampling route-record daemon) uses to send to the clients.
  Category: SNMP Infrastructure (snmpd, mib2d)
1392616The snmpd process might crash and cause a core dump
Product-Group=junos
The snmpd process leaks memory in snmpv3 query path and crashes. The issue is caused by a memory leak when the request PDU is dropped by SNMP when the snmp filter-duplicates configuration is enabled. Each request PDU has a structure pointer for the SNMPv3 security details. This is allocated when the PDU is created or cloned. But while dropping the duplicate requests, the corresponding structure is not freed, which causes the memory leak.
  Category: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1464020The mspmand might crash when stateful firewall and RPC ALG used on MX platforms with MS-MIC/MS-MPC
Product-Group=junos
On MX platforms with MS-MIC/MS-MPC, when stateful firewall is configured with "application junos-dce-rpc-portmap" and RPC ALG is enabled (both Sun RPC and MS-RPC), the mspmand might crash continuously (about every 15 or 20 minutes).
  Category: MS-MPC Logging on MX
1478972TCP-log sessions might be in Established state but no logs get sent out to the syslog server
Product-Group=junos
When TCP-based syslog is configured under the service-set, the Services PICs will establish the TCP sessions with syslog server. When the networks between the syslog server and the MX/SRX are not stable, TCP retransmit may not work properly and cause the TCP sessions to hang. When issuing "show services tcp-log connections", the TCP sessions are still shown in "Established" state, however, no syslog messages are sent to the syslog server.
  Category: platform related PRs on SRX branch platforms
1473456Supports LLDP on reth interfaces.
Product-Group=junos
On all SRX chassis cluster with LLDP supported, the "set protocols lldp interface reth*" is supported since this release, please configure LLDP on reth interface not on reth's child interfaces.
  Category: MPC7/8/9 Interface Issues
1463015The EA WAN SerDes gets into a stuck state, leading to continuous DFE tuning timeout errors and link staying down.
Product-Group=junos
The interfaces on certain MX platforms might get stuck in a down state, if the remote interface sends invalid code to the local interface. Link might not come up even after the remote peer has begun sending a good signal.
  Category: MX10002 Platform SW - Platform s/w defects
1426120MPC reboot or RE mastership switchover might occur on MX204/MX10003
Product-Group=junos
On MX204/MX10003, if there's high rate of fragmented traffic received on em3 interface, em3 watchdog timeout might occur. It could cause MPC reboot or RE mastership switchover.
1426120MPC reboot or RE mastership switchover might occur on MX204/MX10003
Product-Group=junosvae
On MX204/MX10003, if there's high rate of fragmented traffic received on em3 interface, em3 watchdog timeout might occur. It could cause MPC reboot or RE mastership switchover.
  Category: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1402345The MPC might crash due to CPU overuse by dfw thread.
Product-Group=junos
When a large amount of packets hit the firewall filter term action 'syslog' and a thread hogs CPU for more than 4 minutes, the MPC might crash.
1476786Traffic loss may be observed to the LNS subscribers in case the "routing-service" knob is enabled under the dynamic-profile
Product-Group=junos
On the MX platforms working in an enhanced subscriber environment, if the "routing-service" knob is enabled under the dynamic-profile for the LNS subscribers, l2tp services may not be programmed properly in the PFE due to timing, which causes forwarding issue to the affected subscribers.
  Category: Trio pfe stateless firewall software
1427936The policer bandwidth might be incorrect for the aggregate interface after activating the command 'shared-bandwidth-policer'.
Product-Group=junos
On MX Series with MPC, if an AE interface is with the filter of 'shared-bandwidth-policer' and the knob 'shared-bandwidth-policer' is deactivated, after activating the knob 'shared-bandwidth-policer', the policer bandwidth might be calculated as 0 and all traffic might be dropped for the AE interface.
  Category: Trio pfe bridging, learning, stp, oam, irb software
1468663JNH memory leaks might be seen after CFM session flap for LSI/VT interfaces
Product-Group=junos
JNH memory leak may be seen when CFM session over the VPLS LSI interface/VT interface flaps if mip-half-function is used.
1491091MAC malformation might happen in a rare scenario under MX-VC setup
Product-Group=junos
On MX-VC setup, if traffic is going through a VCP (virtual chassis port) port and forwarding to an egress port to the destination, while the traffic is handled entirely by the same PFE, MAC malformation might happen.
  Category: Junos Automation, Commit/Op/Event and SLAX
1436773The /var/db/scripts directory might be deleted after executing "request system zeroize"
Product-Group=junos
On all platforms which support ZTP (Zero Touch Provisioning), the /var/db/scripts directory might get deleted after executing "request system zeroize", and it won't be recreated automatically.
  Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1480348TFTP installation from loader prompt may not succeed on the EX series devices
Product-Group=junos
On the EX series platforms with 17.1R1 onwards, software installation from loader prompt may not succeed by using TFTP.
  Category: V44 Satellite Device Infra
1460607The dpd crash might be observed on satellite devices in junos fusion enterprise
Product-Group=junosvae
In junos fusion dpd might crash on satellite devices running SNOS.
  Category: PTX/QFX100002/8/16 platform software
1464119FPC might restart during run time on PTX10K/QFX10K platforms
Product-Group=junosvae
On PTX10K/QFX10K platforms, FPC might restart if there is some corruption in BCM (Broadcom) switch (a small internal ethernet switch, instead of PFE engine) inside the FPC. It is a timing issue. The reason is that the PCIe speed configuration for BCM switch is not correct. And this issue is resolved in some FPC U-boot versions.
  Category: Virtual Router Redundancy Protocol
1450652Dual VRRP mastership might be seen after RE switchover ungracefully
Product-Group=junos
When VRRP works in distributed mode (ie. delegate-processing is enabled under VRRP) with more than 250 VRRP sessions, dual VRRP mastership might be observed after RE switchover ungracefully (e.g. primary RE failure).
1454895The VRRP traffic loss is longer than one second for some backup groups after performing GRES
Product-Group=junos
On all Junos OS platforms, configuring VRRP over the AE interface whose member physical interfaces belong to different PFE (packet forwarding engine), some backup VRRP groups traffic loss are observed longer than one second after performing GRES (graceful Routing Engine switchover). As the expectation is that the outage is subsecond.

View TSB17792 Known Issues [juniper.net] for additional information

 

Modification History

2022-03-23: non-technical changes; corrected formatting issue
2020-05-26: First publication