Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, EX, MX, PTX, QFX, NFX, SRX, VRR, vMX, vSRX

Alert Description

Junos Software Service Release version 20.4R3-S2 is now available for download from the Junos software download site

NOTE: For EX2300-MP, this release is not recommended due to PR1627673

Download Junos Software Service Release:
  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 20.4R3-S2 is now available.

20.4R3-S2 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 PFE
1630616The ARP resolution may get failed on VRRP enabled interface
Product-Group=junos
On EX4300, ARP resolution against virtual IP on VRRP enabled interface may get fail with "no-arp-trap" is configured due to which service may get affected.
  Category: EX4300 Platform
1580829Some interfaces might be down after the power outage or power cycle
Product-Group=junos
On EX4300-VC platforms, after a power outage, some of the interfaces might be down when configured with no-auto-negotiation, and speed is configured, which might impact the traffic.
1623215Verification of "LOCAL-FAULT" insertion might fail on 'xe' interface
Product-Group=junos
On all EX4300 platforms( Except EX4300-MP), Local fault insertion is failing when the fault is injected (through a traffic generator) and traffic loss is seen on the port.
  Category: EX4300 Virtual Chassis
1624850Delay might be observed while establishing the virtual-chassis post upgrading or rebooting device
Product-Group=junos
On all EX4300 platforms except EX4300-48MP with virtual chassis ports using the DAC cables, there might be a delay in establishing the virtual-chassis post upgrading or rebooting the device.
  Category: EX2300/3400 PFE
1616646PFE might crash due to deletion of storm control configuration for IFL in CLI which may lead to traffic loss
Product-Group=junos
On Junos EX and QFX platforms with storm control IFL entry, when deleting the storm control configuration in CLI PFE reboot might occur due to access of storm control IFL entry memory that was freed during deletion which might lead to traffic loss.
1627857Packet drop might be observed when L2PT is configured on transit device
Product-Group=junos
On ACX/EX/QFX Junos platforms with Q-in-Q setup in SP(Service Provider) style configuration, when L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch, mac rewritten packets might get dropped on the transit device due to which protocol (for example, STP) convergence fails between the end nodes and thus L2PT breakage could be observed for service-VLANs included in the environment.
1632643Unicast ARP packets with the first four bytes of its destination MAC matching to system macs of a transit system gets trapped by the system
Product-Group=junos
On EX2300 platforms as transit switches, when no-arp-trap is enabled, if the ARP packets are unicast of which the destination MAC has upper four bytes matching to the system MAC, the ARP packets are not forwarded but trapped.
1637784MAC address might not be learned on the new interface after MAC move
Product-Group=junos
On EX3400/EX4300/EX2300 platforms, when dot1x authentication is configured for a MAC-based VLAN (MBV) and if MAC move happens, the old MBV entry might not get cleared because of which MAC address might not be learned on the new interface and result in traffic loss.
  Category: Fireall support for ACX
1630280ACX5048 filters reporting TCAM errors are not installed in h/w after the upgrade from 17.4R2-S8 to 20.4R3
Product-Group=junos
This changes increase the number of family inet arp policers to 64 entries. TCAM resource shortage errors can be seen if there are more than 32 IFLs with configured arp policer.
  Category: "agentd" software daemon
1600412The gNMI Telemetry might stop working after RE switchover
Product-Group=junos
In a dual RE (Routing Engine) system with GRES (Graceful Routing Engine Switchover) NSR (Nonstop Active Routing) enabled telemetry might stop working after RE switchover.
  Category: a20a40 specific issue
1600216Traffic through one SPU may stop with potential packet drop issue with alarm as FPC Major Errors raised due to the PIC_CMERROR_TALUS_PKT_LOSS error
Product-Group=junos
On SRX5k series with SPC3 card, in rare cases an SPU may stop forwarding traffic. In this case, logs will show a "potential pkt drop issue" on all the cores of that SPU and an FPC Major Alarm would be raised due to the PIC_CMERROR_TALUS_PKT_LOSS error being reported.
  Category: BBE Autoconfigured DVLAN related issues
1626558The autoconf might not work if the DHCPv4 Discover message has option 80 (rapid commit) ahead of option 82
Product-Group=junos
If in the client's DHCP discover packet there has option 80 ahead of option 82, the auto-configure feature can not extract the subscriber's ACI (Agent Circuit-ID) and ARI (Agent Remote-ID). This leads to authentication failure when creating the Dynamic VLAN interface where option 82 is requested.
  Category: BBE interface related issues
1633392The bbe-smgd process might crash after removing and adding a child link from AE interface
Product-Group=junos
On MX platforms enabled with dynamic-profiles for subscribers and the subscribers are configured over AE [Aggregate Ethernet] interface with targeted-distribution. When the child links of the AE interface are removed and then added, it could lead to bbe-smgd crash in the backup RE. This in-turn could affect the control plane subscriber services when the primary RE fails during such event.
  Category: Border Gateway Protocol
1620463The rpd may crash and restart when NSR is enabled
Product-Group=junos
On all Junos with NSR (nonstop routing) enabled the rpd crash and restart may occur when RPKI (Resource Public Key Infrastructure) records are being replicated between the primary and backup RE (Routing Engine) and some of the records are withdrawn over the RPKI session.
1626367Time delay to export prefixes to BGP neighbors might occur post applying peer-specific BGP export policies
Product-Group=junos
On all Junos and EVO Platforms, when BGP export policies were changed from deny all to the peer-specific export policies, it might take several hours for the RPD/BGP to finish the export evaluation.
1626756Multipath route with List-NH which has Indirect-NH as members fails into BGP-LU
Product-Group=junos
"RT-multipath route with List-Next-hop which has Indirect-Next-hop as members" is unable to advertise into BGP-labeled-unicast address family. This scenario could happen in Carrier's Carrier (CsC) VRF which is also the reported case.
1630220The BGP ECMP might not work and multipath route wont be created
Product-Group=junos
On all platforms, if BGP multipath is configured, if an active path that is not eligible for multipath and later gets deleted, the device might not calculate multipath for the other routes. This causes the ECMP (Equal Cost Multi Path) feature to fail and thereby causes route learning to fail.
  Category: BBE Remote Access Server
1625858Radius CoA (Change of Authorization) NAK may not be sent with the configured Source Address in a virtual-router environment
Product-Group=junos
On all Junos, when running a radius server in multiple routing instances, the CoA NAK messages uses the interface address instead of the configured source address for non-existent sessions. This issue happens when the Radius server is configured in different virtual routers with different settings.
1626718ESSM sessions may get terminated in Radius as class attribute has got corrupted after performing ISSU
Product-Group=junos
When the ESSM (Extensible Subscriber Services Manager) service is getting created on existing subscriber session, the class attribute is wrongly formed. This happens when Radius sends class attribute in access-accept messages after performing ISSU.
1629395Adding the new radius access configuration might fail
Product-Group=junos
On all Junos and Junos OS Evolved platforms deleting the old radius access configuration and adding the new radius access configuration with different dynamic request port values results in failure of commit of the new radius access configuration.
  Category: MX Platform SW - FRU Management
1634164Slow chassis memory leak may occur when chassisd related configuration change is committed
Product-Group=junos
On MX platforms, every commit routine may leak some memory in chassisd process. Over a long period of time if the total process heap memory usage goes above 3 GB approximately, chassisd may core and restart.
  Category: OpenSSL and related subsystems
1626704Memory leak in 'global data shm' process might lead to traffic outage
Product-Group=junos
On all SRX platforms, the traffic being matched/inspected at Layer 7 (ssl-proxy) on a security policy might get dropped as it moves from one trust zone to another. This is due to a memory leak and possible memory shortage of the 'global data shm' process.
  Category: Device Configuration Daemon
1630229The subscribers might be deleted when "host-prefix-only" knob is configured on the underlying-interface in GRES scenario
Product-Group=junos
On MX platforms, the subscribers might be removed while posting GRES, if "host-prefix-only" knob is configured on the underlying-interface (e.g. demux0). Due to this, the connected subscribers might be impacted until they reconnect again to the interface.
  Category: dhcpd daemon
1620544DHCP subscribers might not be synchronized to backup BNG when DHCP ALQ is configured without topology-discover
Product-Group=junos
On MX platforms with Subscriber Management redundancy scenario, if DHCP Active Lease Query (ALQ) is configured without topology-discover and the knob "no-advertise-routes-on-backup" is configured, DHCP ALQ connection might not be established and DHCP subscribers might not be synchronized to backup Broadband Network Gateway (BNG).
  Category: Host path software for ACX platform
1584509IPv4 Traffic loss with packet size more than 1410 on ACX5448
Product-Group=junos
On ACX5400 series platform when there is traffic surge, due to packet reassembly failures in the VMHOST, traffic loss might be seen. The ACX5400 software consists of Windriver Linux (WRL) 64-bit kernel with KVM hypervisor support providing the host operating system environment. The JUNOS runs as a VM on top of WRL host (VMHOST). As per the architecture the traffic from the Junos control plane will pass through the VMHOST and further to PFE to exit via the WAN interface. The internal interface between the Junos and VMHOST is of MTU 1500 due to which control packets exceeding 1500 MTU are to be fragmented and sent to VMHOST but it fails.
  Category: ACX platform interface issues
1621894SNMP interface reporting temperature instead of RX alarms
Product-Group=junos
The jnxDomCurrentAlarms value is incorrectly set which could indicate a temperature alarm.
  Category: BGP MPLS VPN specific issues
1611651Traffic towards CE via default route might be dropped in VRF on ACX5448/ACX710
Product-Group=junos
On ACX5448/ACX710 PE in L3VPN, if default route is present in the VRF with next-hop via CE, the traffic towards CE via the default route might be dropped.
  Category: DNX VPLS
1626267VPLS traffic loss might be observed post route flap
Product-Group=junos
On ACX5448 and ACX710 platforms, if route flap occurs, post which routes are re-learned and even if the Virtual private LAN service (VPLS) connection is up, VPLS traffic loss might still be observed.
  Category: Covers Application classification workflows apart from custo
1613516For apps getting classified on first packet, the volume update syslog is not getting generated.
Product-Group=junos
On Junos 21.3R1 release, due to the default enablement of PMI(Power Mode IPSec) express path at FLOW end, for apps getting classified on first packet, the volume update log is not getting triggered. Workaround is to disable PMI using config : "set security flow power-mode-disable".
1625364Coredumps might be reported on installing IDP security package
Product-Group=junos
On SRX platforms, when installing IDP sigpack, it might impact SRXPFE core file generation. It is a memory corruption issue.
  Category: Covers custom app
1628202The error might be seen after configuring a unified security policy allowing some app categories
Product-Group=junos
On SRX platforms, after committing the configuration of a unified security policy with some app categories, an error might be seen. Due to this unified security policy configuration might get failed.
  Category: EA chip ( MQSS SW issues )
1551353The Packet Forwarding Engine might get disabled when major CMERROR occurs due to parity errors
Product-Group=junos
On MX Series routers and the EX9200 line of switches, the Packet Forwarding Engine might get disabled when a major CMERROR occurs due to a parity error in the DRD memory block's SRAM.
  Category: System Management daemon and related issues
1606839Around 500ms to 800ms of traffic loss might be seen with one of AE member links of p2mp LSP branches is down on Junos Evolved PTX10008 platform
Product-Group=junos
On Junos Evolved PTX10008 platform in FMBB (Fast Make-Before-Break) scenario, around 500ms to 800ms of traffic loss might be seen if the member link of AE bundle of the p2mp LSP branches is down.
  Category: Lacp related problems and issues.
1636093Some daemons might get stuck when snmpd is at 100% CPU utilization
Product-Group=junos
On all Junos and EVO platforms, when snmpd is at 100% CPU utilization and some daemons are trying to raise an SNMP trap, these daemons might get stuck which results in unbaling to handle any incoming corresponding packets and unbaling to response to any CLI commands.
  Category: EVPN control plane issues
1600310Bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance
Product-Group=junos
When using the logical tunnel (lt-) interface to stitch EVPN-MPLS and EVPN-VxLAN, bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance. This is due to the AD (Auto-Discovery) route per ESI with VxLAN encapsulation community which is ignored on MPLS routing instance.
1626416Multiple memory leaks might be seen leading to process rpd crash
Product-Group=junos
Multiple memory leaks might be seen, which might lead to the process rpd crash. Issue 1- On QFX platforms configured with EVPN-VxLAN memory leaks might be seen due to BGP communities. Issue 2- On all Junos and Junos OS Evolved platforms memory leaks might be seen due to MAC mobility.
1629953Removing knob "es-label-oldstyle" does not take effect if it is the only knob configured under the protocol EVPN
Product-Group=junos
On MX, QFX, and EX series platforms with EVPN enabled, removing knob "es-label-oldstyle" does not take effect if it is the only knob configured under the protocol EVPN.
  Category: EVPN Layer-2 Forwarding
1629426The l2ald crash might be seen after performing restart routing on EVPN PE
Product-Group=junos
On all Junos and Evo platforms, when restart routing performed on EVPN PE in the network, l2ald crash might be seen on EVPN PE where restart routing was done. Furthermore, its peering PEs may see l2ald crash due to protocol flap following to restart routing. In both case, l2ald crash would be seen in a few minutes (~ 10 min) after restart routing was done.
  Category: EX driver issues
1600291The SFP-T port might stop forwarding traffic on EX4600 platforms
Product-Group=junos
On EX4600, after performing an upgrade, the peer device is rebooted, the peer interface is disabled/enabled or rebooting EX4600, then the SFP-T port on EX4600 might remain in up state but could not forward traffic.
  Category: Express PFE including evpn, vxlan
1620924EVPN-VXLAN Type5 traffic might get failed on the Spine device of QFX10K
Product-Group=junos
In the EVPN-VXLAN scenario on QFX10002/08/16/QFX10002-60C platforms, when a route destination is reachable over more than one type-5 tunnel, in transient cases traffic on the type-5 tunnels is dropped.
  Category: ISIS routing protocol
1631738The rpd might crash after clearing isis database
Product-Group=junos
When ISIS database is cleaned, rpd crash might be observed.
1633858IS-IS database may not be synchronized in some multiple areas scenario
Product-Group=junos
On all platforms with IS-IS multiple areas scenario, if the knob "flood-group" is enabled, IS-IS Databases may not get synchronized between areas after clearing the IS-IS DB or making the DB change in any other way. This is because when link-state packet (LSP) is fragmented, only the first packet has the area ID list (for flood-group matching), while the rest of the fragmented LSPs do not have that list, which will result in these packets not being flooded, so that ISIS will not work properly. Note: Flood Group is a feature of IS-IS, used to limit link-state packet data unit (PDU) flooding over IS-IS interfaces. When a link-state packet (LSP) that is not self-originated will be flooded only through the interface belonging to the flood group that has the configured area ID in the LSP. This helps minimize the routes and topology information, thus ensuring optimal convergence.
  Category: jdhcpd daemon
1625011The jdhcpd process crashes in DHCP/DHCPv6 environment
Product-Group=junos
On MX platforms, the jdhcpd process(DHCP daemon) might crash and dump core files in a DHCP/DHCPv6 (Dynamic Host Control Protocol) environment when the device is configured as a relay agent or server with 'active-leasequery. This might lead to subscriber termination and DHCP relay binding state of the terminating subscriber shows as 'Release' state.
1629172Non-DHCPv4 BOOTP protocol packets might not be processed if enhanced subscriber management is enabled
Product-Group=junos
On all MX platforms, if enhanced subscriber management is enabled, non Dynamic Host Configuration Protocol version 4 (non-DHCPv4) Bootstrap Protocol (BOOTP) packets might not be processed even though the DHCP relay/server "overrides bootp-support" knob is configured. Post the PR fix, the "show system subscriber-management statistics dhcp extensive" CLI operational command can display BOOTP boot request/reply received/transmitted statistics.
  Category: jl2tpd daemon
1629104L2TP tunnels may go down and not able to re-establish after restarting the bbe-smgd process
Product-Group=junos
On MX configured as L2TP access concentrator (LAC), if the bbe-smgd process is restarted when L2TP tunnels are getting down (e.g., L2TP tunnel will get down due to retransmission timed out caused by loss of IP connection between LAC and LNS) and later on the same tunnels are selected to tunnel new subscriber sessions, these L2TP tunnels may be stuck in down state and not be able to re-establish. The issue could cause the subscriber to lose connectivity. This is a timing issue.
  Category: Adresses ALG issues found in JSF
1615438Junos OS: Flowd core observed if the SIP ALG is enabled and a specific Session Initiation Protocol (SIP) packet is received (CVE-2022-22178)
Product-Group=junos
A Stack-based Buffer Overflow vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on MX Series and SRX series allows an unauthenticated networked attacker to cause a flowd crash and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11284 [juniper.net] for more information.
  Category: Application aware Quality-of-Service
1640768Configuration change during AppQoS session might result in PFE crash with flowd core
Product-Group=junos
On SRX/NFX platforms supporting Application Aware Quality Of Service (AppQoS), when the session is in process by AppQoS module and if any configuration change is pushed to PFE at the same time, PFE might crash with flowd core resulting in the traffic outage. Issue could be recovered by disabling AppQoS. It could be a rare timing issue.
  Category: Firewall Authentication
1626667The authentication delay might occur upto 60 secs if same user authenticates
Product-Group=junos
UAC(Unified Access Control) authentication delay upto 60 sec will be seen to pass authenticated traffic if same source IP address authenticates.
  Category: Flow Module
1615765vSRX Power Mode IPSEC (PMI) enabled, packets might be dropped for ipv6
Product-Group=junos
Packet drop might be seen while sending traffic across IPSec vpn ipv6 tunnel when Power Mode IPSEC (PMI) is enabled on vSRX platforms.
1619321Security traffic log display service-name="None" for some application
Product-Group=junos
On SRX series devices, the expected service name for some application does not display in security traffic log, however service-name="None" is displayed.
1624041VLAN tagged packets might be dropped at TAP mode enabled interface
Product-Group=junos
On SRX4600 and SRX5000 (like SRX5400, SRX5600 and SRX5800) series platforms, if the interface is enabled with Terminal Access Point (TAP) mode, VLAN tagged packets from a mirror interface of switch might be dropped. When this issue happens, transit traffic going through the switch might not be analyzed.
  Category: flow ha module
1624262SPU might become offline on standby node after failover in SRX cluster
Product-Group=junos
On SRX5400, SRX5600 and SRX5800 platforms configured in chassis cluster, when the primary node is rebooted, it triggers a failover. Services Processing Unit Central Point(SPU CP) on the new standby node becomes offline which causes HA in abnormal state. Core files are generated on the new standby node.
  Category: all logging related bugs on srx platforms
1620018On SRX Series devices using On-Box Logging, LLMD write failures may be seen under high load. The output of 'show security log llmd counters' can be used to view LLMD behaviour.
Product-Group=junos
On SRX Series devices using On-Box Logging, LLMD write failures may be seen under high load. The output of 'show security log llmd counters' can be used to view LLMD behaviour.
1630123Depending on the configuration of the SRX, duplicate events may have been written to the on-box logging database. This fix improves LLMD performance by eliminating these duplicate write events
Product-Group=junos
Depending on the configuration of the SRX, duplicate events may have been written to the on-box logging database. This fix improves LLMD performance by eliminating these duplicate write events
  Category: Firewall Policy
1608029SSL proxy might not be performed when SSL Proxy profile is referenced in the zone/global policy
Product-Group=junos
On SRX platforms, SSL proxy might not be performed and sessions might get ignored when a SSL proxy profile is referenced in the zone/global security policy and URL-category is enabled in the policy zone context.
1618025Redundancy might get affected in SRX Chassis Cluster scenario
Product-Group=junos
On SRX5000-Series with Chassis Cluster configured, there might be a redundancy issue observed. This happens when node master-ship changes, Network Security Daemon (NSD) reconnects to other node's Packet Forwarding Engine (PFE). An error in re-connection leads to this issue.
  Category: IPSEC/IKE VPN
1627557Traffic over IPSec tunnels may be dropped post control link failure
Product-Group=junos
After control-link failure, the traffic over IPSec tunnels might be dropped.
1628947SRX devices generates core dump after upgrading to any release
Product-Group=junos
On SRX devices, flowd process generates core dump after upgrading to any release
1638437The kmd process might crash if the IKE negotiation fragment packets are missed during initiating an IKE SA rekey
Product-Group=junos
If IPsec IKEv2 is used and IKE negotiation fragment packets are missed during initiating an IKE SA rekey, the kmd process might crash. There will be temporary IPSec traffic interruption until the issue is restored automatically.
  Category: Security platform jweb support
1629978skip to jweb not working for srx300
Product-Group=junos
The J-Web setup wizard may not function correctly on SRX300 and SRX320 devices. The work around is to perform initial configuration manually.
  Category: Layer 2 Control Module
1602588Junos OS and Junos OS Evolved: An l2cpd memory leak can occur when specific LLDP packets are received leading to a DoS (CVE-2022-22172)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a memory leak. Continued exploitation can lead to memory exhaustion and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11278 [juniper.net] for more information.
  Category: Layer2 forwarding on EX/NTF/PTX/QFX
1626710When clients connected to isolated vlan(Virtual Local Area Network) via trunk port can't communicate to the network
Product-Group=junos
When interface vlan membership is changed from secondary->primary or Vice-Versa, and The traffic might be impacted in primary and secondary VLAN due to this.
1626714Broadcast traffic might not be forwarded to LT interface in VPLS routing instance after LT interface is deleted then added back
Product-Group=junos
On MX platforms, when Logical Tunnels (LT) interface is used for VPLS, VPLS broadcast traffic might not be forwarded to LT interface properly after deleting the LT interface adding it back, which might cause LT interface missing from VPLS flood topology and eventually affects VPLS communication.
  Category: lldp sw on MX platform
1617151L2 cpd Memory leak may lead to l2cpd process crash
Product-Group=junos
On all Junos and Evo platforms, there is a one-shot timer created for LLDP (Link Layer Discovery Protocol) regardless of whether LLDP is configured or not, which may not get freed before creating the new one-shot timer because of which there is 160 bytes of leak every minute. This gradual memory leak in l2cpd may lead to l2cpd process crash. This may impact traffic only if protocols other than LLDP (example xSTP) are running.
  Category: Port-based link layer security services and protocols that a
1624524MACsec session might flap if multiple logical interfaces are created on single physical interface
Product-Group=junos
On all Junos and Evo platforms with MACsec enabled, when multiple ifls (logical interfaces) are created on single ifd (physical interface), deleting one/few ifls might flap MACsec session and traffic drop might be seen during the issue.
  Category: Multiprotocol Label Switching
1615001The RPD crash may happen due to refcount leak in routing table metrics
Product-Group=junos
On all Junos and Junos OS Evolved platforms with BGP-LS configured, addition of routes via TED_LS module might cause refcount leak and could lead to RPD crash on the device.
  Category: MX Timing software
1634569PTP clock class might incorrectly be downgraded to 248 when PTP is enabled on Linecard/MIC which does not support phy-timestamping
Product-Group=junos
When PTP slave is configured on MICs (MPC2E-3D-NG-Q, MPC3E-3D-NG-Q and MIC3-3D-10XGE-SFPP) that does not support phy-timestamping, the PTP TX clock class might incorrectly be degraded to 248 causing the downstream PTP nodes to look for another best master clock.
  Category: Neo Interface
1621286Flapping of all ports in the same PFE may cause PFE to be disabled
Product-Group=junos
On MPC1, MPC1E, MPC2, MPC2E, MPC-3D-16, EX9200-40T, EX9200-40F, and EX9200-40F-M line cards and in a very rare situation, all ports from the same Packet Forwarding Engine going down may cause error of mqchip_disable_ostream timeout. When this error is seen, a temporary host loopback path wedge error may occur and trigger disable-pfe. The wedge can be cleared by itself, but the disable-pfe needs a FPC reboot to recover.
  Category: OS IPv4/ARP/ICMPv4
1616775The SNMP packet (traps or polls) will be dropped if it crosses multiple routing-instances on SRX Series devices
Product-Group=junos
On SRX Series devices, if the SNMP packet (traps or polls) has to cross multiple routing-instances, it will cause the packet to be dropped due to incorrect routing-instance ID added by SRX.
  Category: FreeBSD Kernel Infrastructure
1570148A false error related to insufficient space might appear while installing a Junos image that is corrupted
Product-Group=junos
On all Junos platforms, the upgrade might fail with a false error related to insufficient space when trying to install Junos from a corrupted package.
1601904The process rpd may slip due to a FreeBSD defect
Product-Group=junos
The process rpd may slip due to a FreeBSD defect. See [FreeBSD id=227689](https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=227689) for more information.
  Category: Kernel Multicast Infrastructure
1608311Intermittent p2mp traffic drop might be seen in MVPN scenario
Product-Group=junos
On MX platforms that support enhanced IP, intermittent p2mp traffic drop might be seen in the case of MVPN with p2mp. When the multicast composite NH involves unicast NH pointing to pseudo interfaces like interface vt-, irb or lsi and the other unicast next-hop is spread across multiple line cards/PFEs, if a new member joins or an existing member leaves the multicast stream traffic drop might be seen.
  Category: Kernel Tunnel Interface Infrastructure
1621696Traffic loss can be seen on the new master RE post GRES
Product-Group=junos
On all Junos platforms with GRE (Generic Routing Encapsulation) configuration, when we disable the gr interface on master RE and enable it on new master RE post GRES, traffic loss can be seen on the new master RE.
  Category: Express Chip L3 software
1625988The knob "no-incoming-port" is not applied after reboot on QFX10002/QFX10008 platforms
Product-Group=junos
On QFX10002/QFX10008 platforms, "set forwarding-options enhanced-hash-key inet no-incoming-port" is not applied after rebooting system. The "no-incoming-port" knob is still present in configuration but it is not active when looking at the output of show commands.
1629200The vmhost crash might be seen in a rare condition when route addition and change
Product-Group=junos
On some QFX/PTX platforms, when route addition and change, in a rare condition, an invalid hash index value might be calculated and cause vmhost crash.
  Category: vMX Data Plane Issues
1641119IPv4 and v6 packet header corruption could happen with some sampling scenario
Product-Group=junos
On VMX/MX150/NFX150 platforms, when sampling is enabled on input WAN interfaces and the sampled packet go out through a GRE tunnel, IPv4/6 header corruption may happen. Due to IP header corruption, remote router reports L3 incompletes at receiving interface.
  Category: Protocol Independant Multicast
1630144The multicast forwarding cache might not get updated after deactivating the scope-policy configuration
Product-Group=junos
On all Junos and EVO platforms with multicast setup, the multicast forwarding cache might not get updated after deactivating the scope-policy configuration. This could result in the PIM register process to be incomplete and further multicast traffic to be dropped.
  Category: vMX Platform Infrastructure related issue tracking
1643932VRRP and ISIS fails to converge after interface flap
Product-Group=junos
On VMX platforms with i40e drivers, VRRP and ISIS might fail to converge after the interface flaps which might affect multicast services.
  Category: VRR (Virtual Route Reflector) for MX
1635950vRR VM might establish its identity as "Olive" after a CLI s/w upgrade
Product-Group=junos
vRR VM might come up as Olive after a CLI sw upgrade using junos-install-mx* package if the XML used to spawn the VM didn't have SMBIOS entry "VRR".
  Category: QFX Platform related (SYSLOG/ALARMS/miscellaneous)
1598805The interface on SFP-T or SFP-SX might stop forwarding traffic on EX4600
Product-Group=junos
On EX4600, the interfaces on SFP-T or SFP-SX might stop forwarding traffic when MACSec and auto-negotiation is enabled on the ports. The interfaces would still show as up and the transmit and receive counters will increase. However, the transmit counters on the port will not increase.
  Category: QFX L2 PFE
1603979l2ald might crash when ESI with local interface goes down in EVPN-VXLAN scenario
Product-Group=junos
On all Junos platforms, in the EVPN-VxLAN scenario with multihoming mode, l2ald might crash when ESI (Ethernet Segment Identifier) with the local interface goes down.
1628845QFX5120VC : Restarting one of the FPCs may cause traffic loss in QFX VC scenario
Product-Group=junosvae
On QFX5120 with the Virtual Chassis (VC) scenario, when traffic coming in master FPC and going out from backup FPC, reboot the backup FPC, the master FPC still thinks the backup link is present, and show lacp interface also continues showing the backup link as collecting / distributing. Therefore, master FPC continues sending the echo reply through the backup link which fails since the backup is powered off, which might lead to traffic drop.
1639926MAC-move might be observed when dhcp-security is configured
Product-Group=junos
On QFX5K/EX46x0 VC (Virtual chassis) Junos platforms with DHCP(Dynamic Host Configuration Protocol) server-client scenario and "dhcp-security" configured under vlan on any of the intermediate node between the server and client, once DHCP client requests an IP to the server and if both the ingress and egress interface lies on the same FPC, request packets might get reinjected back to the same interface causing MAC (Media Access Control) moves. Thus, allocated IP might not reach the client. Eventually, no clients might be able to login.
  Category: QFX L3 data-plane/forwarding
1475478Inaccurate allocated memory for 'nh' and 'dfw_rulemask' under kernel might be observed
Product-Group=junos
Kernel allocated memory (in bytes) for 'nh' and 'dfw_rulemask' might not be accurately represented by the FPC memory sensor. Memory corruption under kernel will occur which means free memory is more than allocated and current allocation is negative. There is no functional impact only ukernel statistics issue.
1608610FPC might crash post firewall filter configuration changes in QFX platforms
Product-Group=junos
On QFX5110/5120 platforms with VXLAN routing scenarios, FPC might crash when there is a change in firewall filter configuration which is applied on IRB. This issue might not affect the 20.3R1 version.
  Category: QFX EVPN / VxLAN
1612905Arp resolution for data traffic received over Type5 might fail
Product-Group=junos
Arp resolution for Data traffic received over Type5 might fail if the VNI ussed for decap for a given tunnel is also used for Encap VNI for another tunnel. When Encap VNI for a tunnel is created first followed by Decap VNI(same vni) for another tunnel we fail to update the routing instance needed for Decap.
1627363RE generated traffic might not be forwarded when next-hop is indirect unilist of EVPN Type 5 tunnel
Product-Group=junos
On QFX5110/QFX5120 platforms with EVPN-VXLAN scenario, if the knob "preserve-nexthop-hierarchy" is configured, RE generated traffic might not be forwarded when next-hop is indirect unilist and learnt by EVPN Type 5 route.
1635347Data might not be exchanged via EVPN-VxLAN domain
Product-Group=junos
On QFX5000 series platforms (i.e., QFX5100 and QFX5200 etc) running Junos system ONLY, if VLAN ID configured on Leaf devices is different, traffic from different end-hosts might not be transported via Ethernet VPN and Virtual Extensible LAN (EVPN-VxLAN) domain. There is a service impact when this issue happens.
1636950Traffic blackhole might be observed when STP is configured in VxLAN environment
Product-Group=junos
On QFX platforms in VxLAN scenario, if STP is enabled on all the interfaces of the switch, ethernet table might not get populated to locally connected devices resulting in traffic blackhole.
  Category: QFX VCCP
1628447802.1p BA classification might not work on mixed VC when interface has a DSCP and 802.1p classifier
Product-Group=junos
In a mixed (QFX5K and EX4300) VC (Virtual-Chassis) scenario, when traffic enters the VC on an EX4300, the classification for IP traffic (DSCP classifier) is working fine, but MPLS traffic is not correctly classified (802.1p classifier is NOT working and all traffic is classified as Best Effort) that might lead to incorrect QoS treatment for MPLS traffic.
  Category: QFX5100 Interface related issues
1633998The VCPs connected with the AOC cable might not come up after upgrading to 17.3 or later releases
Product-Group=junos
On QFX5100/EX4600 platforms with the Virtual Chassis (VC) scenario, if the Virtual Chassis Ports (VCPs) are connected through QSFP+40GE-AOC cable, post upgrading to 17.3 or later releases, VCPs might not come up or flap impacting VC functionality and services.
  Category: QFX5200/5110/5120/5210 Platfom issues
1630380QFX5k : Chassis Status LED doesn't work as document described
Product-Group=junosvae
On QFX5k series switch which is woking on 5e image, chassis status LED does not work properly. You may see unexpected state of SYS or MST LED on master or backup FPC.
  Category: RPD policy options
1565629The rpd might crash when the deletion of routing table occurs
Product-Group=junos
The rpd might crash when the deletion of routing table occurs.
  Category: RPD route tables, resolver, routing instances, static routes
1635009Multipath route getting formed for a VPN prefix due to incorrect BGP route selection logic
Product-Group=junos
On all Junos and EVO platforms running BGP, when a specific route is received from multiple places under a VRF, multipath route is getting formed even though the BGP route selection algorithm has the active route with higher local preference. Once multipath is formed, the traffic forwarding is happening based on that, and it may result in some traffic going to an unwanted path. Please refer to KB37775 [juniper.net] for more details.
  Category: IPSEC functionality on M/MX/T ser
1630070The kmd daemon might crash with core every few minutes on MX platforms
Product-Group=junos
On MX platforms in the IPSEC VPN scenario, The kmd daemon might crash every few minutes due to a timing issue in the establishment phase, which will lead to IPSEC VPN flapping.
1631443The kmd might crash since the pkid requested memory leak happens on M/MX platforms
Product-Group=junos
In IPsec running M/MX platforms, in some rare cases (e.g., after rebooting router/upgrading MPC/SCB), the kmd (Key Manager Daemon) will crash due to pkid (handling Public Key Infrastructure function) requested memory leak. Then IPSec key negotiation service might be impacted and IPSec traffic loss might follow.
  Category: SRX branch platforms
1620888Traffic may get dropped due to memory issue on some SRX devices
Product-Group=junos
On SRX300/320/340/345/380/550M platforms, the memory partition limits may be wrongly set at the boot-up time. This may cause the traffic to drop.
1630886LLDP packets may be sent with incorrect source MAC for RETH/LAG child members
Product-Group=junos
On all platforms, when LLDP is run on child members of LAG/Redundant Ethernet (RETH) interfaces, LLDP packets may not be sent out with interface hardware address as source MAC. Instead, packets will be sent out using LAG/RETH interfaces MAC address. So, in case if the RETH/LAG interface MAC address changes, the source MAC address of LLDP packets will also change dynamically. Which will affect any service that relays on LLDP.
1633503Tasks of download manager may not be resumed post reboot
Product-Group=junos
The function of Automatic resume on reboot in Download manager feature might not work when downloading files.
  Category: SRX5XX platform
1575231The fxp0 interface of an SRX550 in cluster might become unreachable from an external network
Product-Group=junos
On SRX550 configured with chassis cluster, fxp0 interfaces might not be reachable from external management interface when the fxp0 and redundant Ethernet(reth) interfaces are in separate routing instances. This is because there is no ARP entry for the reth interface in fxp0 ARP table. As a result of this, SRX cluster cannot be accessed from an external management network.
  Category: MPC7/8/9 Interface Issues
1626130Some Interfaces may not come online after linecard reboot
Product-Group=junos
On all Junos platforms, when the line-card is installed and if reboot is performed, some interfaces may remain down. This may impact traffic.
  Category: MX10003/MX204 Platform SW - Chassisd s/w defects
1315577MX10003 : Despite of having all AC low/high PEM, "Mix of AC PEMs" alarm is raised
Product-Group=junosvae
When there is an input failure on one of the AC PEMs (low or high) its wrongly categorized as "Mix of AC PEMs", so instead of "PEM <> input failure" you will see "Mix of AC PEMs" alarm raised.
  Category: MX10002 Platform SW - Platform s/w defects
1587694PEM capacity shows incorrectly on MX10003 platform
Product-Group=junosvae
On MX10003 platform, PEM capacity may be incorrectly shown by CLI command 'show chassis power' after a PEM swap.
  Category: ZT/YTpfe bridging, learning, stp, oam, irb software
1601065Duplicate Address Detection(DAD) flags can be seen for IRB interfaces after configuration removal and restoration which may lead to blocking the traffic
Product-Group=junos
On MX platforms using MPC10 and MPC11E line cards with IPV6 configured, Duplicate address detection flags are seen for IRB interfaces. This happens when a device is configured with multiple member L2 interfaces and IRB interfaces, with one or two L2 interfaces going into STP blocked state. This issue can cause potential service impact on the device.
1604150VRRP and BFD might flap on IRB interface on MPC10/11 line cards
Product-Group=junos
On all MPC10/11 line cards, the VRRP and BFD might flap on the IRB interface configured with IPv6. IPv6 control packets from IRB do not honor the STP rule on egress IFL. The IRB injected packets come down as PTYPE=CONTROL, SUBTYPE=0. Subtype 0 is LACP, which would bypass egress STP Check. Hence, the IPv6 Router Advertisement packets are not getting treated similar to the ARP packets and not getting dropped in this scenario. This will cause the MAC to move across the loop environment.
  Category: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1619111Degraded traffic processing performance might be observed in case of processing very high PPS rate traffic
Product-Group=junos
MX-Series devices processing very high Packets per second (PPS) rate transit traffic might not show traffic processing performance enough and drop traffic.
1626041Trio-based line cards might crash when PFE memory is hot-banking
Product-Group=junos
Trio-based line cards crash might be seen when Packet Forwarding Engine (PFE) memory is hot-banking. It is a rare issue.
  Category: Trio pfe bridging, learning, stp, oam, irb software
1607767FPC crash might be seen due to mac-move between two interfaces under same bridge domain
Product-Group=junos
On all Trio based platforms, continuous mac-move between interfaces under same bridge domain can lead to memory corruption there by crashing the FPC.
  Category: Trio pfe l3 forwarding issues
1568944Traffic might be dropped when the default route is changed in inet.0 table
Product-Group=junos
Traffic might be dropped on MX Series routers or the EX9200 line of switches when the default route is changed in the inet.0 table. It might take 2 to 3 seconds to be updated in the Packet Forwarding Engine. This issue can be recovered automatically.
  Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1598123Interface configuration may get stuck and may not update after several ephemeral commits
Product-Group=junos
After several ephemeral commits interface configurations may get stuck and may not get updated on all Junos platforms.
1608718In an SRX cluster with VPN configuration, primary node in cluster may generate kmd core files in a loop when a commit fails with "lock can not be taken on other node" followed by another commit.
Product-Group=junos
When a commit is failed due to "lock can not be taken on other node", "/var/etc/vpn_tunnel.id+" and other ffp(foreign file propagation) files are not getting cleaned up on srx cluster. In next commit, these stale ffp files are activated for use, it is resulting in discrepancy and resulting in assert failure in applications/KMD daemons. The problem moves to the secondary node if the failover is executed.
1628046The process mgd may crash with errors if scripts synchronize is configured
Product-Group=junos
On every commit, when "system scripts synchronize" is configured, dob reference count increments (leaks). Over a period of time, juniper-config dop refcount increases infinitely and could reach the maximum value of 65535 and it overflows to zero. Once it hits zero, "insist error dop->do_refcount != 0" error is seen in the logs.
  Category: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1612535Syslog messages may be lost partially in case of lots of messages generated to eventd
Product-Group=junos
On all Junos/EVO platforms, with 100 or more IFL's up/down, a lot of messages will be generated within few ms and eventd may not be able to process all of messages and may be collected/lost partially.
  Category: QFX RCB issues
1598814EVPN-VXLAN:QFX10008: RE1 went to DB prompt when tried loading profile configs over LRM configs
Product-Group=junos
RE1 went to DB prompt when tried loading profile configs over LRM configs.
  Category: PTX/QFX10002/8/16 specific software components
1544095100G ER4, ER4 Lite or 100G_AOC_BER_10_E_M12 optics might not work
Product-Group=junos
On PTX1k and PTX10K platforms, if 100G ER4, ER4 Lite or 100G_AOC_BER_10_E_M12 on 100G port is implemented, and if fec mode is not configured on port via CLI with these optics, due to default fec mode mismatch between PTX10K and PTX1K, the port will not come up impacting all services associated with port.
1599183False fan failure alarm flaps (set and cleared) frequently
Product-Group=junosvae
Fan Trays (FT) on PTX10008/10016 EVO system has implemented dampening with the zero speed failures. The same will be implemented in Junos.
  Category: MX10K platform
1623273chassisd memory leak may be seen after adding or removing an interface configuration
Product-Group=junos
On MX10008/10016 platforms, after adding/deleting interface in a loop, chassisd memory leak(approx. 24 byte of memory per commit) may be seen.
  Category: VMHOST platforms software
1547669WR Linux 6 platforms and WR Linux 9 platforms might be stuck after upgrading or downgrading image version and restarting the device
Product-Group=junos
On Wind River Linux 6 (WR Linux 6) platforms and WR Linux 9 platforms using VMHOST based routing engine (RE), device might be stuck after upgrading image or downgrading image and reload the device. There is service impact if this issue happens.
1605971VM host platforms might boot exactly 30 minutes after executing 'request vmhost halt' command
Product-Group=junos
On all VM host platforms running Junos OS Release 19.3R1 onwards, when 'request vmhost halt' is executed, the system reboots after exactly 30 minutes instead of maintaining the halt condition.
  Category: VNID L2-forwarding on Trio
1630163Scenario where within a VRF multiple VXLAN type-5 tunnels with same decap prefix are not handled on MPC10/11
Product-Group=junos
On MPC10/11 line cards, EVPN/VXLAN scenario where within a VRF multiple VXLAN type-5 tunnels with same decap prefix are created is not well handled, which might lead to traffic drop.
 

View TSB18293 Known Issues [juniper.net] list for additional information.

Modification History

2022-03-08 Removed PR1603836/1599431 from Known issues (Resolved in 20.4R3)
2022-02-18 First publication