Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX, EX, MX, PTX, QFX, NFX, SRX, VRR, vMX, vSRX
Alert Description
Junos Software Service Release version 20.3R3-S3 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 20.3R3-S3 is now available.
20.3R3-S3 - List of Fixed issues
PR Number
Synopsis
Category: EX4300 PFE
1630616
The ARP resolution may get failed on VRRP enabled interface
Product-Group=junos
On EX4300, ARP resolution against virtual IP on VRRP enabled interface may get fail with "no-arp-trap" is configured due to which service may get affected.
1630935
Application of firewall filters might break connectivity towards the hosts on EX4300
Product-Group=junos
On EX4300 platforms except EX4300-MP/EX4300-48MP, once input/output firewall filters are applied to the interfaces under family ethernet-switching, it might result in disrupting the connectivity towards few hosts connected to the device and thus impacts the related traffic.
PR Number
Synopsis
Category: EX4300 Virtual Chassis
1624850
Delay might be observed while establishing the virtual-chassis post upgrading or rebooting device
Product-Group=junos
On all EX4300 platforms except EX4300-48MP with virtual chassis ports using the DAC cables, there might be a delay in establishing the virtual-chassis post upgrading or rebooting the device.
PR Number
Synopsis
Category: EX2300/3400 PFE
1564941
The DHCP client might not obtain IP address when dhcp-security is configured
Product-Group=junos
On EX2300 platforms, if enterprise Style (EP) and service provider (SP) style configurations are mixed on a trunk interface, the DHCP client under SP style configuration might not obtain IP address when dhcp-security is enabled on one of the trunk VLANs.
1616646
PFE might crash due to deletion of storm control configuration for IFL in CLI which may lead to traffic loss
Product-Group=junos
On Junos EX and QFX platforms with storm control IFL entry, when deleting the storm control configuration in CLI PFE reboot might occur due to access of storm control IFL entry memory that was freed during deletion which might lead to traffic loss.
1627857
Packet drop might be observed when L2PT is configured on transit device
Product-Group=junos
On ACX/EX/QFX Junos platforms with Q-in-Q setup in SP(Service Provider) style configuration, when L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch, mac rewritten packets might get dropped on the transit device due to which protocol (for example, STP) convergence fails between the end nodes and thus L2PT breakage could be observed for service-VLANs included in the environment.
1632643
Unicast ARP packets with the first four bytes of its destination MAC matching to system macs of a transit system gets trapped by the system
Product-Group=junos
On EX2300 platforms as transit switches, when no-arp-trap is enabled, if the ARP packets are unicast of which the destination MAC has upper four bytes matching to the system MAC, the ARP packets are not forwarded but trapped.
PR Number
Synopsis
Category: IGP-Static, RIP, OSPF, ISIS
1634747
ISIS last transition time never increments
Product-Group=junos
On ACX710 platform ISIS last transition time never increments even though session remains stable for long time.
PR Number
Synopsis
Category: QFX PFE CoS
1631448
The uplink interface remains down for a longer duration due to VXLAN scaled configuration
Product-Group=junos
On all Junos QFX5K platforms, with Virtual Extensible LAN (VXLAN) and the filters applied on the VXLAN interface both having scaled configuration, if the device reboots, the uplink interface might remain down for a longer duration, resulting in service impact.
1633827
Unable to configure policer with "bandwidth-limit" more than 50G
Product-Group=junos
On EX4650 and on all QFX5k (except QFX5220 and QFX5770) platforms, a policer with a "bandwidth-limit" of more than 50G may not be configured for a 100G port.
PR Number
Synopsis
Category: ACX Interfaces IFD, IFL, vlans, and BRCM init
1614550
In ACX5448, at rates above 4GB, there might be mismatches in statistics between the physical and logical interfaces
Product-Group=junos
In ACX5448, at rates above 4GB, there might be mismatches in statistics between the physical and logical interfaces
PR Number
Synopsis
Category: ACX GE, 10GE, PoE, IDT framers
1633226
Speed 10m configuration error on ACX5048 and ACX5096 platforms
Product-Group=junos
On ACX5048 and ACX5096 platforms interface speed 10m is not supported on 1G interface. This issue was introduced due to a bug fix and it has been resolved with this PR.
PR Number
Synopsis
Category: ACX Services feature
1626058
Unicast packet loss might be observed due to control-word configuration
Product-Group=junos
On ACX5448/ACX710 platforms, enabling control-word for Virtual Private LAN Service (VPLS) instance might result in unicast packet loss.
PR Number
Synopsis
Category: BBE Autoconfigured DVLAN related issues
1626558
The autoconf might not work if the DHCPv4 Discover message has option 80 (rapid commit) ahead of option 82
Product-Group=junos
If in the client's DHCP discover packet there has option 80 ahead of option 82, the auto-configure feature can not extract the subscriber's ACI (Agent Circuit-ID) and ARI (Agent Remote-ID). This leads to authentication failure when creating the Dynamic VLAN interface where option 82 is requested.
PR Number
Synopsis
Category: BBE interface related issues
1629910
The egress traffic on non-targeted iflset of subscribers might not be forwarded correctly over targeted AE interface
Product-Group=junos
In subscriber traffic across links over an aggregated Ethernet (AE) interface scenario, the egress data of subscriber applications (e.g. PPPoE/L2TP/MPLS/DHCP) attached logical interface sets (iflset, e.g. pppoe-iflset/demux-iflset) are configured at Layer 3 to handle many sets of subscriber queues respectively over one targeted-distribution enabled Layer 2 ifl of AE interface (e.g. ae-x/y/z.1). In some rare cases, if the member link/FPC of AE are flapped, the underlying ifd of the AE bundle might not be attached to iflset again. Then the egress traffic forwarding function of subscribers over the AE interface (e.g. traffic redistribution/CoS scheduling resources) might be impacted.
1633392
The bbe-smgd process might crash after removing and adding a child link from AE interface
Product-Group=junos
On MX platforms enabled with dynamic-profiles for subscribers and the subscribers are configured over AE [Aggregate Ethernet] interface with targeted-distribution. When the child links of the AE interface are removed and then added, it could lead to bbe-smgd crash in the backup RE. This in-turn could affect the control plane subscriber services when the primary RE fails during such event.
PR Number
Synopsis
Category: Bi Directional Forwarding Detection (BFD)
1599431
Some BFD sessions stuck in Init state after FPC restart
Product-Group=junos
After a reboot or chassis restart, everything goes Up and is stable. However, after restarting FPC 3 a good number of BGP sessions never recover. The reason is BFD (see the piece of log below) show bfd session | except up Detect Transmit Address State Interface Time Interval Multiplier XX.XX.XX.XX Init ae-x/x/x 6.000 2.000 3 XX:XX Init xe-x/x/x 256.000 2.000 3 After restarting fpc(Flexible PIC Concentrators ), there is a delay of 12-15sec delay to receive the PIPE close message. Few sessions which are using AE interface may stuck in init state forever. Which may impact traffic.
PR Number
Synopsis
Category: Border Gateway Protocol
1599730
rpd crash might be seen when NSR is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms when nonstop routing (NSR) is enabled during route convergence then routing protocol daemon (rpd) might crash with a core there-by causing service impact on the device.
1600599
Kernel crash might be observed on platforms having BGP configured with family L2VPN
Product-Group=junos
On all Junos OS and Junos Evolved platforms running Border Gateway Protocol (BGP) with Layer 2 VPN (L2VPN) scenario, kernel crash might be observed.
1626756
Multipath route with List-NH which has Indirect-NH as members fails into BGP-LU
Product-Group=junos
"RT-multipath route with List-Next-hop which has Indirect-Next-hop as members" is unable to advertise into BGP-labeled-unicast address family. This scenario could happen in Carrier's Carrier (CsC) VRF which is also the reported case.
1630220
The BGP ECMP might not work and multipath route wont be created
Product-Group=junos
On all platforms, if BGP multipath is configured, if an active path that is not eligible for multipath and later gets deleted, the device might not calculate multipath for the other routes. This causes the ECMP (Equal Cost Multi Path) feature to fail and thereby causes route learning to fail.
PR Number
Synopsis
Category: MX Platform SW - FRU Management
1634164
Slow chassis memory leak may occur when chassisd related configuration change is committed
Product-Group=junos
On MX platforms, every commit routine may leak some memory in chassisd process. Over a long period of time if the total process heap memory usage goes above 3 GB approximately, chassisd may core and restart.
PR Number
Synopsis
Category: DNX VPLS
1626267
VPLS traffic loss might be observed post route flap
Product-Group=junos
On ACX5448 and ACX710 platforms, if route flap occurs, post which routes are re-learned and even if the Virtual private LAN service (VPLS) connection is up, VPLS traffic loss might still be observed.
PR Number
Synopsis
Category: Covers custom app
1628202
The error might be seen after configuring a unified security policy allowing some app categories
Product-Group=junos
On SRX platforms, after committing the configuration of a unified security policy with some app categories, an error might be seen. Due to this unified security policy configuration might get failed.
PR Number
Synopsis
Category: Lacp related problems and issues.
1636093
Some daemons might get stuck when snmpd is at 100% CPU utilization
Product-Group=junos
On all Junos and EVO platforms, when snmpd is at 100% CPU utilization and some daemons are trying to raise an SNMP trap, these daemons might get stuck which results in unbaling to handle any incoming corresponding packets and unbaling to response to any CLI commands.
PR Number
Synopsis
Category: eventd, syslog infra issues
1611885
Master-eventd process might go down when syslog configuration is misconfigured
Product-Group=junos
On all Junos Operating System Evolved(EVO) based platforms with misconfigured syslog, master-eventd process might go down.
PR Number
Synopsis
Category: EVPN control plane issues
1600310
Bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance
Product-Group=junos
When using the logical tunnel (lt-) interface to stitch EVPN-MPLS and EVPN-VxLAN, bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance. This is due to the AD (Auto-Discovery) route per ESI with VxLAN encapsulation community which is ignored on MPLS routing instance.
1626416
Multiple memory leaks might be seen leading to process rpd crash
Product-Group=junos
Multiple memory leaks might be seen, which might lead to the process rpd crash. Issue 1- On QFX platforms configured with EVPN-VxLAN memory leaks might be seen due to BGP communities. Issue 2- On all Junos and Junos OS Evolved platforms memory leaks might be seen due to MAC mobility.
PR Number
Synopsis
Category: EX driver issues
1600291
The SFP-T port might stop forwarding traffic on EX4600 platforms
Product-Group=junos
On EX4600, after performing an upgrade, the peer device is rebooted, the peer interface is disabled/enabled or rebooting EX4600, then the SFP-T port on EX4600 might remain in up state but could not forward traffic.
PR Number
Synopsis
Category: Express PFE including evpn, vxlan
1620924
EVPN-VXLAN Type5 traffic might get failed on the Spine device of QFX10K
Product-Group=junos
In the EVPN-VXLAN scenario on QFX10002/08/16/QFX10002-60C platforms, when a route destination is reachable over more than one type-5 tunnel, in transient cases traffic on the type-5 tunnels is dropped.
PR Number
Synopsis
Category: Fast Ethernet interfaces
1613430
Static route might not work on vSRX
Product-Group=junos
On vSRX instance instantiated in Google Cloud, static route might not work.
PR Number
Synopsis
Category: Integrated Routing & Bridging (IRB) module
1623262
Host generated IPv4 traffic sent over IPv6 next-hop with IRB interface might get dropped
Product-Group=junos
On all Junos platforms that support IRB(Integrated routing and bridging), when host originated IPv4 traffic is sent over IPv6 next-hop with IRB interface, the traffic might get dropped because of ether-type mismatch. This is because the ether-type field in L2 header is set to IPv6 (instead of IPv4) always due to the IPv6 next hop.
PR Number
Synopsis
Category: ISIS routing protocol
1633858
IS-IS database may not be synchronized in some multiple areas scenario
Product-Group=junos
On all platforms with IS-IS multiple areas scenario, if the knob "flood-group" is enabled, IS-IS Databases may not get synchronized between areas after clearing the IS-IS DB or making the DB change in any other way. This is because when link-state packet (LSP) is fragmented, only the first packet has the area ID list (for flood-group matching), while the rest of the fragmented LSPs do not have that list, which will result in these packets not being flooded, so that ISIS will not work properly. Note: Flood Group is a feature of IS-IS, used to limit link-state packet data unit (PDU) flooding over IS-IS interfaces. When a link-state packet (LSP) that is not self-originated will be flooded only through the interface belonging to the flood group that has the configured area ID in the LSP. This helps minimize the routes and topology information, thus ensuring optimal convergence.
PR Number
Synopsis
Category: jl2tpd daemon
1629104
L2TP tunnels may go down and not able to re-establish after restarting the bbe-smgd process
Product-Group=junos
On MX configured as L2TP access concentrator (LAC), if the bbe-smgd process is restarted when L2TP tunnels are getting down (e.g., L2TP tunnel will get down due to retransmission timed out caused by loss of IP connection between LAC and LNS) and later on the same tunnels are selected to tunnel new subscriber sessions, these L2TP tunnels may be stuck in down state and not be able to re-establish. The issue could cause the subscriber to lose connectivity. This is a timing issue.
1630150
Tunneled subscribers may be stuck in terminating state in L2TP subscriber scenario
Product-Group=junos
On all MX platforms that support enhanced subscriber management (Next Generation Subscriber Management) with Layer 2 Tunneling Protocol (L2TP) subscriber scenario, L2TP subscribers may be stuck in terminating state if the L2TP subscribers try to login.
PR Number
Synopsis
Category: Application aware Quality-of-Service
1640768
Configuration change during AppQoS session might result in PFE crash with flowd core
Product-Group=junos
On SRX/NFX platforms supporting Application Aware Quality Of Service (AppQoS), when the session is in process by AppQoS module and if any configuration change is pushed to PFE at the same time, PFE might crash with flowd core resulting in the traffic outage. Issue could be recovered by disabling AppQoS. It could be a rare timing issue.
PR Number
Synopsis
Category: Firewall Authentication
1626667
The authentication delay might occur upto 60 secs if same user authenticates
Product-Group=junos
UAC(Unified Access Control) authentication delay upto 60 sec will be seen to pass authenticated traffic if same source IP address authenticates.
PR Number
Synopsis
Category: Flow Module
1615765
vSRX Power Mode IPSEC (PMI) enabled, packets might be dropped for ipv6
Product-Group=junos
Packet drop might be seen while sending traffic across IPSec vpn ipv6 tunnel when Power Mode IPSEC (PMI) is enabled on vSRX platforms.
PR Number
Synopsis
Category: High Availability/NSRP/VRRP
1606724
Secondary node in a chassis cluster might go into reboot loop on SRX platforms
Product-Group=junos
On SRX1500/4100/4200, the secondary node in a chassis cluster might go into reboot loop after RG0 (redundancy-group 0) failover and secondary node is rebooted manually.
PR Number
Synopsis
Category: Firewall Network Address Translation
1631815
New persistent NAT or normal source NAT sessions might fail due to noncleared aged out sessions
Product-Group=junos
On high end SRX platforms with Central Point (CP) architecture and Services Processing Units (SPUs), if configured with all these features "Port Block Allocation (PBA), persistent NAT, hairpin, source NAT", persistent NAT sessions might get stuck and aged out Persistent NAT sessions might not get cleared, due to which the new persistent NAT or normal source NAT session might fail.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1574409
The SRXPFE process might crash and generate a core file when IPsec VPN is used
Product-Group=junosvae
On SRX4000 and SRX5000 Series devices, the SRXPFE process might crash and generate a core file when IPsec VPN is configured.
1627557
Traffic over IPSec tunnels may be dropped post control link failure
Product-Group=junos
After control-link failure, the traffic over IPSec tunnels might be dropped.
1638437
The kmd process might crash if the IKE negotiation fragment packets are missed during initiating an IKE SA rekey
Product-Group=junos
If IPsec IKEv2 is used and IKE negotiation fragment packets are missed during initiating an IKE SA rekey, the kmd process might crash. There will be temporary IPSec traffic interruption until the issue is restored automatically.
PR Number
Synopsis
Category: Security platform jweb support
1629978
skip to jweb not working for srx300
Product-Group=junos
The J-Web setup wizard may not function correctly on SRX300 and SRX320 devices. The work around is to perform initial configuration manually.
PR Number
Synopsis
Category: Layer 2 Circuit issues
1626219
The rpd process might crash during ISSU if the auto-sensing knob is enabled for l2circuit
Product-Group=junos
On all platforms which support the In-Service Software Upgrade (ISSU) feature, if the auto-sensing knob is enabled for l2circuit, the routing protocol daemon (rpd) might crash while performing ISSU. Traffic loss might be seen when the rpd is down and service can recover after rpd comes back up.
PR Number
Synopsis
Category: Layer2 forwarding on EX/NTF/PTX/QFX
1626714
Broadcast traffic might not be forwarded to LT interface in VPLS routing instance after LT interface is deleted then added back
Product-Group=junos
On MX platforms, when Logical Tunnels (LT) interface is used for VPLS, VPLS broadcast traffic might not be forwarded to LT interface properly after deleting the LT interface adding it back, which might cause LT interface missing from VPLS flood topology and eventually affects VPLS communication.
1627617
The line card might crash and reload if the EVPN MAC entry is not deleted correctly
Product-Group=junos
On all Junos and EVO platforms, the line card might crash and reload in an EVPN-MPLS scenario when there is a MAC move from local to remote and the request to delete MAC entry is received from remote. Core files are generated and complete traffic loss might be observed until the line card reloads.
1629678
The l2ald might be stuck in "issu state" when ISSU is aborted
Product-Group=junos
On all Junos platforms, when Unified In-service Software Upgrade (ISSU) is aborted, Layer 2 Address Learning Daemon (l2ald) may not be able to read 'issu abort' notification and l2ald might be stuck in 'issu state' and l2ald will not process new events while in 'issu state'.
PR Number
Synopsis
Category: MX104 Software - Chassis Daemon
1626486
The chassisd might crash on MX104
Product-Group=junos
On the MX104 platform, when 'Invalid Chassis Model' occurs in the chassisd daemon, the chassisd might crash which might lead to interfaces down and automatic recovery. The fix is to solve avoid this chassisd core during 'Invalid Chassis Model' scenario.
PR Number
Synopsis
Category: Express Chip L3 software
1598309
The unilist nexthop might get stuck after interface flap on PTX/QFX10K
Product-Group=junos
On PTX/QFX10K platforms, some of the unilist nexthops might get stuck after interface flap, the issue might still exist even after FPC or rpd reboot.
PR Number
Synopsis
Category: vMX Data Plane Issues
1641119
IPv4 and v6 packet header corruption could happen with some sampling scenario
Product-Group=junos
On VMX/MX150/NFX150 platforms, when sampling is enabled on input WAN interfaces and the sampled packet go out through a GRE tunnel, IPv4/6 header corruption may happen. Due to IP header corruption, remote router reports L3 incompletes at receiving interface.
PR Number
Synopsis
Category: Protocol Independant Multicast
1630144
The multicast forwarding cache might not get updated after deactivating the scope-policy configuration
Product-Group=junos
On all Junos and EVO platforms with multicast setup, the multicast forwarding cache might not get updated after deactivating the scope-policy configuration. This could result in the PIM register process to be incomplete and further multicast traffic to be dropped.
PR Number
Synopsis
Category: VRR (Virtual Route Reflector) for MX
1629242
vRR: monitor traffic interface doesn't work on em2
Product-Group=junos
CLI operational command "monitor traffic interface" might not work on em2 on vRR with the error thrown as "error: interface: 'em2': Cannot monitor em2 interface".
1635950
vRR VM might establish its identity as "Olive" after a CLI s/w upgrade
Product-Group=junos
vRR VM might come up as Olive after a CLI sw upgrade using junos-install-mx* package if the XML used to spawn the VM didn't have SMBIOS entry "VRR".
PR Number
Synopsis
Category: Periodic Packet Management Daemon
1599751
rpd core might be observed due to memory corruption
Product-Group=junos
On all Junos and Evo devices, when connection between Internal Junos Modules (Routing Module & Periodic Packet Manager Module) resets, data structure representing that connection is not completely reset/freed. Due to this next time, when the connection is re-established, there is a possibility of re-using the old/stale data structure and this could lead to memory corruption and thereby rpd core.
PR Number
Synopsis
Category: QFX Platform related (SYSLOG/ALARMS/miscellaneous)
1598805
The interface on SFP-T or SFP-SX might stop forwarding traffic on EX4600
Product-Group=junos
On EX4600, the interfaces on SFP-T or SFP-SX might stop forwarding traffic when MACSec and auto-negotiation is enabled on the ports. The interfaces would still show as up and the transmit and receive counters will increase. However, the transmit counters on the port will not increase.
PR Number
Synopsis
Category: QFX L2 PFE
1628845
QFX5120VC : Restarting one of the FPCs may cause traffic loss in QFX VC scenario
Product-Group=junosvae
On QFX5120 with the Virtual Chassis (VC) scenario, when traffic coming in master FPC and going out from backup FPC, reboot the backup FPC, the master FPC still thinks the backup link is present, and show lacp interface also continues showing the backup link as collecting / distributing. Therefore, master FPC continues sending the echo reply through the backup link which fails since the backup is powered off, which might lead to traffic drop.
1633452
The FBF filtered VLAN traffic will not be passed properly to the forwarding routing instances over AE interfaces on QFX5K/EX4600/EX4650 platforms
Product-Group=junos
On QFX5K/EX4600/EX4650 platforms with IPv4 Filter-based forwarding (FBF) scenario, when IPv4 FBF is used with 802.1Q VLAN tag enabled layer-3 AE interfaces, the VLAN filtered configuration enabled by FBF filter will be stored in the VLAN filter processor (VFP) ternary content addressable memory (TCAM). But, in some cases of adding/deleting the configuration of the routing instances (then routing-instance) in FBF filter, the stale allocated entries in VFP TCAM might not be deleted from the system, the memory slices of VFP TCAM will be exhausted until it is run out. Finally, there are not enough memory slices left to store the VLAN filtered information for the forwarding routing instances, then the FBF filtered VLAN traffic will not be forwarded correctly since the FBF filters might not be programmed/processed on the system.
1637249
Configuring L2PT on a transit switch in a Q-in-Q environment breaks L2PT for other S-VLANs
Product-Group=junos
When L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch using SP style configuration, protocol convergence between end nodes might fail.
PR Number
Synopsis
Category: QFX L3 data-plane/forwarding
1608610
FPC might crash post firewall filter configuration changes in QFX platforms
Product-Group=junos
On QFX5110/5120 platforms with VXLAN routing scenarios, FPC might crash when there is a change in firewall filter configuration which is applied on IRB. This issue might not affect the 20.3R1 version.
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1624925
QFX5K log messages: fpc0 SRIRAM Tx VxLAN Ucast: ifd_out = vtep dst_gport is (c00000X) so do not process pkt further
Product-Group=junos
Log messages "fpc0 SRIRAM Tx VxLAN Ucast: ifd_out = vtep dst_gport is (c00000X) so do not process pkt further" can show up on QFX5K switches (where X = different values). These are harmless messages.
1635347
Data might not be exchanged via EVPN-VxLAN domain
Product-Group=junos
On QFX5000 series platforms (i.e., QFX5100 and QFX5200 etc) running Junos system ONLY, if VLAN ID configured on Leaf devices is different, traffic from different end-hosts might not be transported via Ethernet VPN and Virtual Extensible LAN (EVPN-VxLAN) domain. There is a service impact when this issue happens.
1636950
Traffic blackhole might be observed when STP is configured in VxLAN environment
Product-Group=junos
On QFX platforms in VxLAN scenario, if STP is enabled on all the interfaces of the switch, ethernet table might not get populated to locally connected devices resulting in traffic blackhole.
PR Number
Synopsis
Category: QFX VCCP
1628447
802.1p BA classification might not work on mixed VC when interface has a DSCP and 802.1p classifier
Product-Group=junos
In a mixed (QFX5K and EX4300) VC (Virtual-Chassis) scenario, when traffic enters the VC on an EX4300, the classification for IP traffic (DSCP classifier) is working fine, but MPLS traffic is not correctly classified (802.1p classifier is NOT working and all traffic is classified as Best Effort) that might lead to incorrect QoS treatment for MPLS traffic.
PR Number
Synopsis
Category: QFX5100 Interface related issues
1633998
The VCPs connected with the AOC cable might not come up after upgrading to 17.3 or later releases
Product-Group=junos
On QFX5100/EX4600 platforms with the Virtual Chassis (VC) scenario, if the Virtual Chassis Ports (VCPs) are connected through QSFP+40GE-AOC cable, post upgrading to 17.3 or later releases, VCPs might not come up or flap impacting VC functionality and services.
1638045
Delay might be observed for the interfaces to come up after reboot/transceiver replacement
Product-Group=junos
On QFX5100/EX4600 Junos platforms with 2-member VC(Virtual Chassis) setup, after the device reboot or QSFP+-40G-SR4 SFP (small form-factor pluggable) replacement, the VC port might remain down and takes longer time (approximately 5-20min) to come up even if the cable is connected properly to the interface.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Platfom issues
1630380
QFX5k : Chassis Status LED doesn't work as document described
Product-Group=junosvae
On QFX5k series switch which is woking on 5e image, chassis status LED does not work properly. You may see unexpected state of SYS or MST LED on master or backup FPC.
PR Number
Synopsis
Category: RPD route tables, resolver, routing instances, static routes
1629437
The contributing routes might not be advertised properly if "from aggregate-contributor" is used
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, if a aggregate route is configured under routing-options, and if "from aggregate-contributor" is used for many contributing routes (e.g. more than 250-300 routes), the policy for these contributing routes might not work properly when the policy is exported. Due to this issue, the contributing routes might not be advertised properly.
1635009
Multipath route getting formed for a VPN prefix due to incorrect BGP route selection logic
Product-Group=junos
On all Junos and EVO platforms running BGP, when a specific route is received from multiple places under a VRF, multipath route is getting formed even though the BGP route selection algorithm has the active route with higher local preference. Once multipath is formed, the traffic forwarding is happening based on that, and it may result in some traffic going to an unwanted path. Please refer to
KB37775
[juniper.net]
for more details.
PR Number
Synopsis
Category: Resource Reservation Protocol
1603613
RSVP detour LSP might fail to come up when an LSR in the detour path goes down
Product-Group=junos
In a RSVP environment with fast-reroute enabled, when an LSR in a detour LSP goes down in particular scenario, the newly signaled detour path might be brought down and remain in incomplete state. This is due to a defect in RSVP-IO thread where it continues sending incorrect Path Refresh, which brings down the detour path.
PR Number
Synopsis
Category: SRX branch platforms
1630886
LLDP packets may be sent with incorrect source MAC for RETH/LAG child members
Product-Group=junos
On all platforms, when LLDP is run on child members of LAG/Redundant Ethernet (RETH) interfaces, LLDP packets may not be sent out with interface hardware address as source MAC. Instead, packets will be sent out using LAG/RETH interfaces MAC address. So, in case if the RETH/LAG interface MAC address changes, the source MAC address of LLDP packets will also change dynamically. Which will affect any service that relays on LLDP.
PR Number
Synopsis
Category: Stout cards (MPC8, MPC9) fabric issues
1617469
MPC8E in 1.6T bandwidth mode may not work correctly
Product-Group=junos
If MPC8E is set in 1.6T bandwidth mode, it may not work correctly and the end result is that the MPC8E will not be able to see 1.6T throughput (as configured) and will see fabric drops at higher traffic rates. The 1.6T bandwidth fabric parameters are not getting applied to SFBs.
PR Number
Synopsis
Category: SRX-1RU platfom related protocol, QoS, filtering features et
1630990
The srxpfe process might crash on SRX4600
Product-Group=junosvae
On SRX4600, a corruption in memory buffer (m_buf) might lead to srxpfe crash. Core files are generated and hardware monitoring failures might be observed when the process crashes.
PR Number
Synopsis
Category: ZT/YT pfe infra issues
1595663
The control packet doesn't get dropped after disabling IFL interface
Product-Group=junos
On MPC10/MPC11 line card, even if the IFL (logical interface) is disabled, the data packets will be dropped, while the unexpected incoming control packets destined for local host will not be dropped.
PR Number
Synopsis
Category: ZT/YT pfe firewall software
1627986
FPC might restart with syslog filter action configured
Product-Group=junos
On EVO-based PTX platforms and all MX series platforms with MPC10+, configuring syslog as a filter action may cause the FPC to restart.
PR Number
Synopsis
Category: ZT/YTpfe bridging, learning, stp, oam, irb software
1628270
EVPN flood filter might not work for MPC10/MPC11 line cards
Product-Group=junos
On all MX platforms equipped with MPC10/MPC11 line cards, when the flood filter is configured in EVPN(Ethernet Virtual Private Network) family on the PFE(Packet Forwarding Engine), the line card might fail to program the filter.
PR Number
Synopsis
Category: ZT/YT pfe l3 forwarding issues
1629100
Packet loss might be seen intermittently if IPv6 Neighbor Discovery Protocol (NDP) entry is updated
Product-Group=junos
On EX9200 and MX240/480/960/2010/2020 platforms using MPC10 onwards with IPV6 is configured, packet loss might be seen intermittently if IPv6 Neighbor Discovery Protocol (NDP) entry is updated.
PR Number
Synopsis
Category: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1626041
Trio-based line cards might crash when PFE memory is hot-banking
Product-Group=junos
Trio-based line cards crash might be seen when Packet Forwarding Engine (PFE) memory is hot-banking. It is a rare issue.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1608718
In an SRX cluster with VPN configuration, primary node in cluster may generate kmd core files in a loop when a commit fails with "lock can not be taken on other node" followed by another commit.
Product-Group=junos
When a commit is failed due to "lock can not be taken on other node", "/var/etc/vpn_tunnel.id+" and other ffp(foreign file propagation) files are not getting cleaned up on srx cluster. In next commit, these stale ffp files are activated for use, it is resulting in discrepancy and resulting in assert failure in applications/KMD daemons. The problem moves to the secondary node if the failover is executed.
PR Number
Synopsis
Category: VMHOST platforms software
1605971
VM host platforms might boot exactly 30 minutes after executing 'request vmhost halt' command
Product-Group=junos
On all VM host platforms running Junos OS Release 19.3R1 onwards, when 'request vmhost halt' is executed, the system reboots after exactly 30 minutes instead of maintaining the halt condition.
PR Number
Synopsis
Category: Virtual Router Redundancy Protocol
1635351
VRRP route tracking for routes in VRF might not work if "chained-composite-next-hop ingress l3vpn" is used
Product-Group=junos
In L3VPN scenario with configured "routing-options forwarding-table chained-composite-next-hop ingress l3vpn" knob, if VRRP route tracking is used to track routes inside a VRF, and if such routes are with composite next hop, they might be marked as down even they are present in the VRF, hence the VRRP route tracking might not work properly.
1637735
"show vrrp extensive" doesn't show the next IFL "Interface VRRP PDU statistics"
Product-Group=junos
"show vrrp extensive" only shows "Interface VRRP PDU statistics" for the first IFL. labroot@jtac-MX80-r113# run show vrrp extensive Interface: ae0.1025, Interface index :328, Groups: 1, Active :1 Interface VRRP PDU statistics Advertisement sent :6 Advertisement received :4649 Packets received :4649 No group match received :0 Interface VRRP PDU error statistics Invalid IPAH next type received :0 Invalid VRRP TTL value received :0 Invalid VRRP version received :0 Invalid VRRP PDU type received :0 Invalid VRRP authentication type received:0 Invalid VRRP IP count received :0 Invalid VRRP checksum received :0 Physical interface: ae0, Unit: 1025, Vlan-id: 1025, Address: 172.16.0.3/24 Index: 328, SNMP ifIndex: 719, VRRP-Traps: disabled, VRRP-Version: 2 Interface state: up, Group: 1, State: backup, VRRP Mode: Active Priority: 100, Advertisement interval: 1, Authentication type: none Advertisement threshold: 3, Computed send rate: 0 Preempt: yes, Accept-data mode: no, VIP count: 1, VIP: 172.16.0.1 Dead timer: 3.208s, Master priority: 105, Master router: 172.16.0.2 Virtual router uptime: 01:08:09 Preferred: yes Tracking: disabled Group VRRP PDU statistics Advertisement sent :6 Advertisement received :4649 Group VRRP PDU error statistics Bad authentication Type received :0 Bad password received :0 Bad MD5 digest received :0 Bad advertisement timer received :0 Bad VIP count received :0 Bad VIPADDR received :0 Group state transition statistics Idle to master transitions :0 Idle to backup transitions :1 Backup to master transitions :1 Master to backup transitions :1 Interface: ae0.1026, Interface index :329, Groups: 1, Active :1 <-------------------No "Interface VRRP PDU statistics" Interface VRRP PDU statistics Advertisement sent :6 Advertisement received :4662 Packets received :4662 No group match received :0 Interface VRRP PDU error statistics Invalid IPAH next type received :0 Invalid VRRP TTL value received :0 Invalid VRRP version received :0 Invalid VRRP PDU type received :0 Invalid VRRP authentication type received:0 Invalid VRRP IP count received :0 Invalid VRRP checksum received :0
20.3R3-S3 - List of Known issues
PR Number
Synopsis
Category: CoS support on ACX
1633427
The storm-control rate-limit might not work with VPLS policer under IFL
Product-Group=junos
On ACX5448 platforms, when storm-control rate-limit is configured on the physical interface along with the VPLS(Virtual Private LAN Service) filter and policer configured under attached IFL(logical interface), storm-control rate-limit might not get applied to the ingress traffic and hence entire traffic might get forwarded further unexpectedly.
PR Number
Synopsis
Category: This category is for Broadband Edge accounting related issue
1628139
Memory leak may occur on PFED process when the flat-file-profile is configured with knob 'use-fc-ingress-stats'
Product-Group=junos
In a scaled Subscriber Service Accounting scenario(~32K IFLs), if flat-file-profile is configured with 'use-fc-ingress-stats' knob, the memory leak on PFED(Packet Forwarding Engine Daemon) process may occur and if it crosses 80% of the total allocated memory of the process, it may crash.
PR Number
Synopsis
Category: Device Configuration Daemon
1609838
SNMP_TRAP_LINK_UP & SNMP_TRAP_LINK_DOWN trap might be seen while activating and deactivating firewall filters
Product-Group=junos
Unexpected LINK_UP/LINK_DOWN messages on vme interface might be seen in the syslog as part of config update on firewall filter. This issue is ONLY seen when vme interface is not configured, but not seen when vme interface is configured. And This issue only happens when virtual chassis is configured on the platform like EX Series or QFX Series Virtual Chassis.
PR Number
Synopsis
Category: DNX platform MPLS FRR features
1635801
ACX710/5448 working as PE stops forwarding L3VPN traffic after core-facing link flapping
Product-Group=junos
When ACX710/5448 series platforms work as PE nodes in L3VPN environment, it might stop forwarding L3VPN traffic after core-facing link flaps, due to a race condition that happens during L3VPN NH programming in PFE.
PR Number
Synopsis
Category: ACX IFL, IFF creation
1638581
L3 interface creation may fail on the ACX5448 and ACX710 platforms
Product-Group=junos
On the ACX5448 and ACX710 platforms, Layer 3 interface creation may fail due to a base MAC address programmed on the PFE. As a result, the simplest symptom is ping failure.
PR Number
Synopsis
Category: Express PFE MPLS Features
1590387
ISIS adjacency is not coming up through TCC l2circuit
Product-Group=junos
On ACX/PTX/QFX platforms(PTX10002/10003/10008/10016/QFX10002/10003/10008/10016/ACX6360) if protocols l2circuit and channel tcc is enabled for providing layer 2 transaction, ISIS connection through the layer 2 domain might get failed and traffic loss might be seen.
1618507
Traffic loss might be observed with some MPLS labels in multipath BGP scenarios
Product-Group=junos
On all PTX platforms, when a Provider Edge (PE) router is configured with multipath, traffic loss might be seen even though the link is up. After this PR, a new knob "no-ifl-based-frr-for-inh-primary" can be applied under "forwarding-options" to avoid such issues.
PR Number
Synopsis
Category: Flow-tap software
1647179
DTCP radius-flow-tap fails to program PFE when trigger X-NAS-Port-Id exceeds 48 character length.
Product-Group=junos
DTCP radius-flow-tap fails to program PFE when trigger X-NAS-Port-Id exceeds 48 character length.
PR Number
Synopsis
Category: Layer 2 Control Module
1629011
Traffic drop might be reported on the interface after reboot or power cycle
Product-Group=junos
On Junos and EVO platforms, after reboot or power cycle, aggregated ethernet (AE) interfaces will have spanning tree protocol (STP) state discarding after the box comes up. It might cause traffic drop on the interface.
PR Number
Synopsis
Category: Multicast for L3VPNs
1536903
Stale PIM (S, G) entry might be seen in certain conditions under MVPN scenario
Product-Group=junos
On all Junos platforms with MVPN scenario, stale PIM (S, G) state might be seen when there are no local/remote receivers and the multicast source is inactive. Only stale PIM entry will be seen, and it doesn't impact MVPN service or functionalities.
PR Number
Synopsis
Category: IPv6/ND/ICMPv6 issues
1631607
ipv6 host route prefix match disappear from 'forwarding-table' after a ping test, ping continues to work, forwarding table entry is not shown. No impact in traffic.
Product-Group=junos
IPv6 route resolutions for ipv6 hosts is missing from the 'route forwarding-table' after pinging hosts within the ip prefix.
PR Number
Synopsis
Category: OSPF routing protocol
1636028
RPD memory leak on OSPF SR routers when deploy in a network with mixed OSPF SR/Non-SR router
Product-Group=junos
When mixing OSPF Segment Routing (SR) routers with non-SR routers, you may see memory leak on the SR routers.
PR Number
Synopsis
Category: QFX5100 Platform optics
1606003
QFX5100 : Generate an optical power after detached and attached QSFP on disabled interface.
Product-Group=junos
On QFX5100, optical power is seen after detached and attached QSFP on disable interface.
PR Number
Synopsis
Category: RPD policy options
1616167
The rpd process might get stuck at 100% when EVPN vrf-target is enabled and after any configuration change
Product-Group=junos
On all Junos and EVO platforms with EVPN (Ethernet VPN)/EVPN-VXLAN (Virtual Extensible LAN Protocol) implemented, any configuration (related/unrelated) change with the knobs 'vrf-target auto' and/or 'protocols evpn vni-options vni vrf-target ' being enabled might result in CPU spike and thus, rpd (routing protocol process) gets stuck at 100%. Traffic could be blackholed during the incident happening and could be back to normal once CPU usage is decremented after an interval.
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1607767
FPC crash might be seen due to mac-move between two interfaces under same bridge domain
Product-Group=junos
On all Trio based platforms, continuous mac-move between interfaces under same bridge domain can lead to memory corruption there by crashing the FPC.
Modification History
First publication 2022-02-18
20.3R3-S3: Software Release Notification for JUNOS Software Version 20.3R3-S3