Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, EX, MX, PTX, QFX, NFX, SRX, VRR, vMX, vSRX

Alert Description

Junos Software Service Release version 19.3R3-S5 is now available for download from the Junos software download site
Download Junos Software Service Release:
  1. Go to  Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select  Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 19.3R3-S5 is now available.

19.3R3-S5 - List of Fixed issues
PR Number Synopsis Category: EX4300 PFE
1619173 After the device reboot port state remains stuck and causes packet drops
Product-Group=junos
On EX4300 platforms except for EX4300-MP, if the device reboots while the traffic is sent to all multicast queues, the ports might get stuck and cause packet drops despite the port state shown as UP.
1623429 Route leak from master routing-instance to custom routing-instance failure occurs for local interface
Product-Group=junos
Local interface(e.g..lo0.0) is configured under master routing-instance and leaked the route to another routing-instance.
PR Number Synopsis Category: EX4300 Layer 2 implementation
1600029 On EX4300 platform MAC addresses aging issue is seen
Product-Group=junos
On EX4300 platforms, some of the MAC addresses might not aged out specific to virtual chassis. When a LAG (aggregate interface) is configured and if any of the FPC member of virtual chassis has no interface part of LAG, then MACs learnt on the LAG interface may not aged out.
PR Number Synopsis Category: EX2300/3400 PFE
1612596 On EX2300/EX3400/EX4300-MP/EX4400 series is causing MAC move when the IGMP query packet received on backup FPC port
Product-Group=junos
On EX2300/EX3400/EX4300-MP/EX4400 series is configured as Virtual Chassis (VC) and Internet Group Management Protocol(IGMP) query packet received on backup Flexible PIC Concentrators(FPC) port are getting looped and it causes MAC move in peer box
1616646 PFE might crash due to deletion of storm control configuration for IFL in CLI which may lead to traffic loss
Product-Group=junos
On Junos EX and QFX platforms with storm control IFL entry, when deleting the storm control configuration in CLI PFE reboot might occur due to access of storm control IFL entry memory that was freed during deletion which might lead to traffic loss.
1619970 Junos OS: EX2300 Series, EX2300-MP Series, EX3400 Series: A slow memory leak due to processing of specific IPv6 packets (CVE-2022-22180)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the processing of specific IPv6 packets on certain EX Series devices may lead to exhaustion of DMA memory causing a Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA11286 [juniper.net] for more information.
1627857 Packet drop might be observed when L2PT is configured on transit device
Product-Group=junos
On ACX/EX/QFX Junos platforms with Q-in-Q setup in SP(Service Provider) style configuration, when L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch, mac rewritten packets might get dropped on the transit device due to which protocol (for example, STP) convergence fails between the end nodes and thus L2PT breakage could be observed for service-VLANs included in the environment.
1632643 Unicast ARP packets with the first four bytes of its destination MAC matching to system macs of a transit system gets trapped by the system
Product-Group=junos
On EX2300 platforms as transit switches, when no-arp-trap is enabled, if the ARP packets are unicast of which the destination MAC has upper four bytes matching to the system MAC, the ARP packets are not forwarded but trapped.
PR Number Synopsis Category: EX-Series VC Infrastructure
1622283 During NSSU, errors related to link might be observed while IFDs are attached/detached
Product-Group=junos
On QFX and EX which supports Virtual Chassis (VC), during Nonstop software upgrade (NSSU) errors might be observed while Interface Physical Device (IFDs) are getting attached/detached. Ports will be down during the issue and traffic loss might be observed.
PR Number Synopsis Category: QFX PFE CoS
1633827 Unable to configure policer with "bandwidth-limit" more than 50G
Product-Group=junos
On EX4650 and on all QFX5k (except QFX5220 and QFX5770) platforms, a policer with a "bandwidth-limit" of more than 50G may not be configured for a 100G port.
PR Number Synopsis Category: Border Gateway Protocol
1620463 The rpd may crash and restart when NSR is enabled
Product-Group=junos
On all Junos with NSR (nonstop routing) enabled the rpd crash and restart may occur when RPKI (Resource Public Key Infrastructure) records are being replicated between the primary and backup RE (Routing Engine) and some of the records are withdrawn over the RPKI session.
1626367 Time delay to export prefixes to BGP neighbors might occur post applying peer-specific BGP export policies
Product-Group=junos
On all Junos and EVO Platforms, when BGP export policies were changed from deny all to the peer-specific export policies, it might take several hours for the RPD/BGP to finish the export evaluation.
PR Number Synopsis Category: BBE Remote Access Server
1625858 Radius CoA (Change of Authorization) NAK may not be sent with the configured Source Address in a virtual-router environment
Product-Group=junos
On all Junos, when running a radius server in multiple routing instances, the CoA NAK messages uses the interface address instead of the configured source address for non-existent sessions. This issue happens when the Radius server is configured in different virtual routers with different settings.
PR Number Synopsis Category: MX Platform SW - Power Management
1545838 FPC(s) may not boot-up on MX960/EX9214 in a certain condition
Product-Group=junos
On MX960/EX9214 platforms with high-capacity/normal-capacity power supplies, FPC(s) may fail to come online when the corresponding power is restored afterward but not present during the power-up stage.
PR Number Synopsis Category: PTX Chassis Manager
1602292 Junos OS: PTX10002-60C System: After upgrading, configured firewall filters may be applied on incorrect interfaces (CVE-2021-31382)
Product-Group=junosvae
On PTX10002-60C System, after upgrading to an affected release, a Race Condition vulnerability between the chassis daemon (chassisd) and firewall process (dfwd) of Juniper Networks Junos OS, may update the devices interfaces with incorrect firewall filters. This issue only occurs when upgrading the device to an affected version of Junos OS. Refer to https://kb.juniper.net/JSA11250 [juniper.net] for more information.
PR Number Synopsis Category: Chotu platform software
1519530 Traffic loss might happen when an Uncorrected (Fatal) AER error is detected
Product-Group=junosvae
On MX2008, traffic loss might happen, if an AER error (Uncorrected fatal error) is detected, it brings down all Switch Fabric Boards (SFBs), but the RE in question will do nothing. The fix is to let the RE reboot in this situation.
PR Number Synopsis Category: CFM
1620536 OAM CFM session doesn't come Up if ERPS configured and CFM control traffic uses the same VLAN as ERPS control traffic
Product-Group=junos
Ethernet Ring Protection Switching (ERPS) is a ring protection scheme for Ethernet networks When EPRS and Connectivity Fault Management(CFM) are configured together. CFM packets will be dropped, hence, CFM session won?t come up
PR Number Synopsis Category: JUNOS kernel/ukernel changes for DNX
1463745 The PFE or FPC might not come up after repeated powering-off/powering-on or rebooting ACX5448
Product-Group=junosvae
After repeated powering-off/powering-on or rebooting ACX5448, the SMBUS transactions timeout might occur in a rare case. It could result in the PFE or FPC not coming up. It is a rare timing issue and was observed once in hundreds of iterations of powering-off/powering-on or rebooting. The subsequent reboot can clear this issue.
PR Number Synopsis Category: Covers Application classification workflows apart from custo
1574056 srxpfed/flowd might crash when deactivating and activating application-identification based policies /application-services configurations on SRX platforms
Product-Group=junos
On SRX platforms, memory is exhausting when the device is processing heavy traffic load or any configuration changes. Due to this, srxpfed/flowd might crash while deactivating and activating application-identification based policies/application-services configurations. This crash might cause temporary traffic loss.
1608915 On All SRX devices that use Layer 7 inspection like ipd or APPId, a coredump may be seen in rare situations
Product-Group=junos
AppID is double freeing the memory during appsigpack switch in a corner case which is causing the core. This double free can also happen without appsigpack switch in a rare corner case.
1625364 Coredumps might be reported on installing IDP security package
Product-Group=junos
On SRX platforms, when installing IDP sigpack, it might impact SRXPFE core file generation. It is a memory corruption issue.
PR Number Synopsis Category: Covers custom app
1628202 The error might be seen after configuring a unified security policy allowing some app categories
Product-Group=junos
On SRX platforms, after committing the configuration of a unified security policy with some app categories, an error might be seen. Due to this unified security policy configuration might get failed.
PR Number Synopsis Category: EVO linux defects & enhancement requests
1569843 Junos OS Evolved: BGP and LDP sessions with TCP MD5 authentication established with peers not configured for authentication (CVE-2021-0297)
Product-Group=junos
A vulnerability in the processing of TCP MD5 authentication in Juniper Networks Junos OS Evolved may allow a BGP or LDP session configured with MD5 authentication to succeed, even if the peer does not have TCP MD5 authentication enabled. This could lead to untrusted or unauthorized sessions being established, resulting in an impact on confidentiality or stability of the network. Please refer to https://kb.juniper.net/JSA11211 [juniper.net] for more information.
PR Number Synopsis Category: EVPN Layer-2 Forwarding
1611618 Missing MAC address entries in EVPN mac-table despite the presence of the corresponding Type 2 route
Product-Group=junos
On all Ethernet VPN (EVPN) supported platforms, once the interface Media Access Control (MAC) limit is reached, even after the MAC addresses learned on the interface have aged out, several newly learned remote MAC addresses might be missing from the EVPN mac-table despite the presence of the corresponding Type 2 routes.
PR Number Synopsis Category: Express PFE Services including JTI, TOE, HostPath, Jflow
1617932 Performance of Jflow service might be impacted on PTX platforms
Product-Group=junos
On PTX platforms with inline Jflow configured, when fragmented traffic related to different families are sampled in an interleaved fashion (for example: one packet related to IPv4 followed by packet related to IPv6 followed by packet related to IPv4) then logs will get generated and based on the traffic pps, the logs generated might bombard the messages file and other important logs might be lost and might impact the performance of Jflow service.
PR Number Synopsis Category: Express PFE L2 fwding Features
1627566 QFX10002-60C platform might not respond back to ICMP packets received with TTL or hop limit value of 1
Product-Group=junos
On QFX10002-60C platform when ICMPv4 (Internet Control Message Protocol) packet with TTL (Time To Live) value of 1 or ICMPv6 packet with hop limit value of 1 is received at the IRB (Integrated Routing and Bridging) interface, it might not respond back with the corresponding ICMP error codes [TTL expired or hop limit exceeded] to the source device.
PR Number Synopsis Category: Express PFE MPLS Features
1628196 EAPol packets over l2circuit may get dropped at the tunnel start
Product-Group=junos
On all PTX routers in the Layer 2 circuit scenario, when the "l2circuit-control-passthrough" option is enabled, Extensible Authentication Protocol over LAN (EAPoL) packets might not go over the Layer 2 circuit as expected.
PR Number Synopsis Category: Enhanced Broadband Edge support for firewall
1626091 The bbe-smgd might crash on backup RE after ISSU/GRES
Product-Group=junos
On all Junos platforms with BNG enabled, after performing GRES or ISSU if a family is bouncing in a dual-stack scenario, then bbe-smgd might crash on backup RE and the traffic might get impacted if any switchover takes place.
PR Number Synopsis Category: IDP policy
1601380 The srxpfe might crash while the IDP security package contains a new detector
Product-Group=junos
On all SRX platforms, the srxpfe process might crash and generate a core dump while installing the IDP security package which has the new detector version.
PR Number Synopsis Category: Kernel software for AE/AS/Container
1577799 Kernel crash may be observed on the backup RE after GRES
Product-Group=junos
If a child member interface is deleted from an AE interface after NSSU/ISSU, then performing GRES may cause the kernel crash on the new backup device/RE in a rare case.
PR Number Synopsis Category: ISIS routing protocol
1633858 IS-IS database may not be synchronized in some multiple areas scenario
Product-Group=junos
On all platforms with IS-IS multiple areas scenario, if the knob "flood-group" is enabled, IS-IS Databases may not get synchronized between areas after clearing the IS-IS DB or making the DB change in any other way. This is because when link-state packet (LSP) is fragmented, only the first packet has the area ID list (for flood-group matching), while the rest of the fragmented LSPs do not have that list, which will result in these packets not being flooded, so that ISIS will not work properly. Note: Flood Group is a feature of IS-IS, used to limit link-state packet data unit (PDU) flooding over IS-IS interfaces. When a link-state packet (LSP) that is not self-originated will be flooded only through the interface belonging to the flood group that has the configured area ID in the LSP. This helps minimize the routes and topology information, thus ensuring optimal convergence.
PR Number Synopsis Category: ISSU related issues for MMx
1611165 Erratic behaviour may be seen on platforms using MPC line cards after ISSU is performed
Product-Group=junos
Services like subscriber management, Multi link point-to-point, MAC ageing, flow exporting may completely fail or behave erratically after performing ISSU on MX platforms which use MPC line cards.
PR Number Synopsis Category: jdhcpd daemon
1588813 Delegated prefix ipv6 address is missing in accounting stop messages
Product-Group=junos
DP (Delegated prefix) is cleared when underlying session (dhcpv6 over ppp) ifl is deconfigured. DP is not seen in Radius accounting stop messages.
1594371 Junos OS: jdhcpd crashes upon receipt of a specific DHCPv6 packet (CVE-2022-22163)
Product-Group=junos
An Improper Input Validation vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11271 [juniper.net] for more information.
PR Number Synopsis Category: jl2tpd daemon
1629104 L2TP tunnels may go down and not able to re-establish after restarting the bbe-smgd process
Product-Group=junos
On MX configured as L2TP access concentrator (LAC), if the bbe-smgd process is restarted when L2TP tunnels are getting down (e.g., L2TP tunnel will get down due to retransmission timed out caused by loss of IP connection between LAC and LNS) and later on the same tunnels are selected to tunnel new subscriber sessions, these L2TP tunnels may be stuck in down state and not be able to re-establish. The issue could cause the subscriber to lose connectivity. This is a timing issue.
PR Number Synopsis Category: User Firewall related issues
1589108 The jsqlsyncd process files generation might cause device to panic crash after upgrade
Product-Group=junos
On SRX-Series devices configured in high-availability, after upgrade jsqlsyncd process files might get generated which might result in device panic crash.
1605933 Memory leak at the useridd process might be observed when Integrated User Firewall is configured
Product-Group=junos
On SRX-Series devices having Integrated User Firewall enabled with Active Directory as the authentication source, memory leak might be observed at the useridd process.
PR Number Synopsis Category: Security platform jweb support
1629978 skip to jweb not working for srx300
Product-Group=junos
The J-Web setup wizard may not function correctly on SRX300 and SRX320 devices. The work around is to perform initial configuration manually.
PR Number Synopsis Category: jsscd daemon
1620827 Static-subscribers session might get stuck in initializing state after ungraceful routing engine switchover
Product-Group=junos
On all MX platforms configured with static subscriber management, subscriber sessions might get stuck in initializing state. This is triggered when Graceful Routing Engine Switchover(GRES) is not enabled on the device and Junos upgrade is performed manually on each routing engine.
PR Number Synopsis Category: Layer 2 Circuit issues
1626219 The rpd process might crash during ISSU if the auto-sensing knob is enabled for l2circuit
Product-Group=junos
On all platforms which support the In-Service Software Upgrade (ISSU) feature, if the auto-sensing knob is enabled for l2circuit, the routing protocol daemon (rpd) might crash while performing ISSU. Traffic loss might be seen when the rpd is down and service can recover after rpd comes back up.
PR Number Synopsis Category: Layer 2 Control Module
1602588 Junos OS and Junos OS Evolved: An l2cpd memory leak can occur when specific LLDP packets are received leading to a DoS (CVE-2022-22172)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a memory leak. Continued exploitation can lead to memory exhaustion and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11278 [juniper.net] for more information.
PR Number Synopsis Category: Layer2 forwarding on EX/NTF/PTX/QFX
1599094 The l2ald process may crash due to memory leak when all active interfaces in a VLAN are unstable
Product-Group=junos
When none of the constituent active interfaces on a VLAN is stable, memory leak may occur which might eventually lead l2ald to crash. No memory leak will be seen if one or some constituent interfaces are flapping but the VLAN has at least one active stable interface overall.
1627617 The line card might crash and reload if the EVPN MAC entry is not deleted correctly
Product-Group=junos
On all Junos and EVO platforms, the line card might crash and reload in an EVPN-MPLS scenario when there is a MAC move from local to remote and the request to delete MAC entry is received from remote. Core files are generated and complete traffic loss might be observed until the line card reloads.
PR Number Synopsis Category: PTX1000 platform
1530529 PTX1000 might become unreachable with no console access after performing vmhost reboot post image upgrade
Product-Group=junosvae
After performing vmhost reboot post image upgrade on PTX1000, in a rare condition, the switch fabric chip might not come out of the reset mode due to an initialization problem. On PTX1000, the switch fabric chip is one of the essential devices which need to be active before the JUNOS VM is initialized. Since the switch fabric chip is still in reset mode, the JUNOS VM fails to be launched. As per design, once the JUNOS VM launching is triggered, the console will get associated with the JUNOS VM. Because JUNOS VM has failed to be launched, there would be no access on the console at this point.
PR Number Synopsis Category: Platform issues specific to MS-MPC (XLP)
1597624 The mspmand process might crash if memory leak issue occurs on MX platforms with MS-MPC/MS-MIC
Product-Group=junos
On MX platforms with MS-MPC/MS-MIC installed, POE(Packet Ordering Engine) recovery for a jbuf in mspmand process gets triggered if either of the following scenarios happen: 1.buffer leak or 2.buffer not processed by services such as infra/plugin within 10 sec due to a deadlock or application holding the buffer for long This may lead to mspmand process core dump and the PIC restarts impacting the traffic on this PIC. Once the is mspmand cored, the MS-MPC/MS-MIC will restart and recover.
PR Number Synopsis Category: MX104 Software - Chassis Daemon
1626486 The chassisd might crash on MX104
Product-Group=junos
On the MX104 platform, when 'Invalid Chassis Model' occurs in the chassisd daemon, the chassisd might crash which might lead to interfaces down and automatic recovery. The fix is to solve avoid this chassisd core during 'Invalid Chassis Model' scenario.
PR Number Synopsis Category: MX10K platform
1569167 The agent sensor __default_fabric_sensor__ are partly applied to some FPCs, which causes zero payload issue AGENTD received empty payload for pfe sensor __default_fabric_sensor__.
Product-Group=junos
PR 1507864 had fixed the invalid data exported from PFE (empty payload), which could be ignored. However, the system logs this event as an error. The fix changed the event as an info.
PR Number Synopsis Category: FreeBSD Kernel Infrastructure
1570148 A false error related to insufficient space might appear while installing a Junos image that is corrupted
Product-Group=junos
On all Junos platforms, the upgrade might fail with a false error related to insufficient space when trying to install Junos from a corrupted package.
1581171 The upgrade might fail when the space is enough for the new Junos file but is tight
Product-Group=junos
On all platforms with FreeBSD 11 or 12 based Junos, the upgrade might fail with the message "Error: not enough space to unpack " when the space is enough for the new Junos file but is tight. The issue is because space_available uses K bytes while space_required uses byte when calculates the space. The space_required might become bigger than space_available even when the real space_available is bigger than the space_required. Hence the message "Error: not enough space to unpack " is seen during the upgrade.
1601904 The process rpd may slip due to a FreeBSD defect
Product-Group=junos
The process rpd may slip due to a FreeBSD defect. See [FreeBSD id=227689](https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=227689) for more information.
PR Number Synopsis Category: vMX Data Plane Issues
1599158 Junos OS: vMX and MX150: Specific packets might cause a memory leak and eventually an FPC reboot (CVE-2022-22168)
Product-Group=junos
An Improper Validation of Specified Type of Input vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to trigger a Missing Release of Memory after Effective Lifetime vulnerability. Continued exploitation of this vulnerability will eventually lead to an FPC reboot and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11275 [juniper.net] for more information.
1624057 Packet loss may be seen when enabling output sampling on the source interface of Tunnel
Product-Group=junos
On vMX/MX150 platforms, when enabling output sampling on the source interface of any kind of Tunnels that flow cached, like GRE, L2TP, MPLSoGRE, etc, packet loss may be seen. If pinging from the remote tunnel IP address, the local tunnel responses the first ICMP echo request packet but not for the subsequent ICMP echo request packets. Similarly, other protocols packet loss over Tunnel will be seen as well.
PR Number Synopsis Category: vMX Platform Infrastructure related issue tracking
1537729 MX150 Unexpected Behavior after using the command request system software validate
Product-Group=junos
'request system software validate' command is disabled currently from 19.4 and above. Customer can validate the same using 'request system software add'.
PR Number Synopsis Category: VRR (Virtual Route Reflector) for MX
1635950 vRR VM might establish its identity as "Olive" after a CLI s/w upgrade
Product-Group=junos
vRR VM might come up as Olive after a CLI sw upgrade using junos-install-mx* package if the XML used to spawn the VM didn't have SMBIOS entry "VRR".
PR Number Synopsis Category: QFX L2 PFE
1618352 Core dumps may be seen on EX and QFX devices after configuration changes
Product-Group=junos
On EX and QFX platforms with IGMP-snooping enabled, the device may generate a core dump (fxpc core) and cause traffic outage while processing IGMP packet during configuration changes.
1637249 Configuring L2PT on a transit switch in a Q-in-Q environment breaks L2PT for other S-VLANs
Product-Group=junos
When L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch using SP style configuration, protocol convergence between end nodes might fail.
PR Number Synopsis Category: QFX L3 data-plane/forwarding
1608610 FPC might crash post firewall filter configuration changes in QFX platforms
Product-Group=junos
On QFX5110/5120 platforms with VXLAN routing scenarios, FPC might crash when there is a change in firewall filter configuration which is applied on IRB. This issue might not affect the 20.3R1 version.
PR Number Synopsis Category: QFX EVPN / VxLAN
1561588 Dcpfe process might crash on after committing EVPN-VXLAN profile configuration and ARP resolution may fail causing traffic issues.
Product-Group=junos
Dcpfe process might crash on after committing EVPN-VXLAN profile configuration and ARP resolution may fail causing traffic issues.
1611488 Inter-vlan connectivity might be lost in an EVPN-VXLAN with CRB topology
Product-Group=junos
In a fabric consisting of 2 or more spines and QFX5k as leaf switches in an EVPN-VXLAN CRB(Ehernet VPN-Virtual Extensible LAN Centrally-routed Bridging) overlay topology with VGA(Virtual Gateway Address) configured on the spine, inter-vlan connectivity with the hosts connected to leaf switches might be lost when the interfaces on second spine connected to leaf switches is enabled.
PR Number Synopsis Category: QFX VCCP
1628447 802.1p BA classification might not work on mixed VC when interface has a DSCP and 802.1p classifier
Product-Group=junos
In a mixed (QFX5K and EX4300) VC (Virtual-Chassis) scenario, when traffic enters the VC on an EX4300, the classification for IP traffic (DSCP classifier) is working fine, but MPLS traffic is not correctly classified (802.1p classifier is NOT working and all traffic is classified as Best Effort) that might lead to incorrect QoS treatment for MPLS traffic.
PR Number Synopsis Category: QFX5100 Virtual Chassis
1601557 Removing and adding VC ports might cause the FPC to reboot
Product-Group=junos
On QFX5100-24Q/QFX5100-48S/QFX5100-48T/QFX5100-96S Virtual Chassis (VC) setup, when the 10G VCP port is removed and added (logically/physically), the remaining 10G VCP ports are getting flap, causing the FPC to restart and the VC to lose the connection between members and rejoins to VC after sometime. Logically by using the commands "request virtual-chassis vc-port delete pic-slot port member " and "request virtual-chassis vc-port set pic-slot port member " to remove and add respectively. Physically by plugging and unplugging the optics corresponding to the VC port.
1619997 Disabled VCP (Virtual chassis port) will be UP after the optic on it is reseated
Product-Group=junos
On all EX and QFX platforms, disabled VCP(Virtual Chassis Port) using the command "request virtual-chassis vc-port set interface vcp-xx/xx/xx disable member XX" will be up after the optic on it is reseated. It should keep disabling VC on the port. After it is UP and then a Master switchover is performed, the port will be disabled.
PR Number Synopsis Category: RPD Next-hop issues including indirect, CNH, and MCNH
1537869 Certain Linux based FPCs might reboot if TNP neighbor towards backup RE continuously flaps on dual-RE platforms
Product-Group=junosvae
On dual-RE platforms, if certain Linux based FPCs (i.e., MPC7E/8E/9E/EX9200-40XS/EX9200-12QS, MPC10E/EX9200-15C, MX10003-LC2103, MX10K-LC2101, MX-SPC3) are installed, when TNP (Trivial Network Protocol) neighbor towards backup RE continuously flaps, FPC might reboot after GRES due to the TNP neighbor issue.
PR Number Synopsis Category: RPD policy options
1537306 The interface-routes rib-group policy does not work as expected in the VxLAN scenario
Product-Group=junos
On all Junos and EVO platforms in the VxLAN scenario, the interface-routes rib-group user-defined policy does not work as expected. This issue will cause all the direct routes to leak from the exported route table to the imported route table.
PR Number Synopsis Category: RPD route tables, resolver, routing instances, static routes
1635009 Multipath route getting formed for a VPN prefix due to incorrect BGP route selection logic
Product-Group=junos
On all Junos and EVO platforms running BGP, when a specific route is received from multiple places under a VRF, multipath route is getting formed even though the BGP route selection algorithm has the active route with higher local preference. Once multipath is formed, the traffic forwarding is happening based on that, and it may result in some traffic going to an unwanted path. Please refer to KB37775 [juniper.net] for more details.
PR Number Synopsis Category: IPSEC functionality on M/MX/T ser
1631443 The kmd might crash since the pkid requested memory leak happens on M/MX platforms
Product-Group=junos
In IPsec running M/MX platforms, in some rare cases (e.g., after rebooting router/upgrading MPC/SCB), the kmd (Key Manager Daemon) will crash due to pkid (handling Public Key Infrastructure function) requested memory leak. Then IPSec key negotiation service might be impacted and IPSec traffic loss might follow.
PR Number Synopsis Category: SRX branch platforms
1580667 [SRX] error message tcp_timer_keep:Local(0x81100001:60753) Foreign(0x8f100001:33010) is seen in messages log every 80 seconds
Product-Group=junos
On SRX series platform with Chassis Cluster, tcp_timer_keep:Local(0x81100001:60753) Foreign(0x8f100001:33010) is seen in messages log every 80 seconds.
PR Number Synopsis Category: SRX5XX platform
1575231 The fxp0 interface of an SRX550 in cluster might become unreachable from an external network
Product-Group=junos
On SRX550 configured with chassis cluster, fxp0 interfaces might not be reachable from external management interface when the fxp0 and redundant Ethernet(reth) interfaces are in separate routing instances. This is because there is no ARP entry for the reth interface in fxp0 ARP table. As a result of this, SRX cluster cannot be accessed from an external management network.
PR Number Synopsis Category: Stout cards (MPC8, MPC9) fabric issues
1617469 MPC8E in 1.6T bandwidth mode may not work correctly
Product-Group=junos
If MPC8E is set in 1.6T bandwidth mode, it may not work correctly and the end result is that the MPC8E will not be able to see 1.6T throughput (as configured) and will see fabric drops at higher traffic rates. The 1.6T bandwidth fabric parameters are not getting applied to SFBs.
PR Number Synopsis Category: ZT/YT pfe firewall software
1627986 FPC might restart with syslog filter action configured
Product-Group=junos
On EVO-based PTX platforms and all MX series platforms with MPC10+, configuring syslog as a filter action may cause the FPC to restart.
PR Number Synopsis Category: Trio pfe bridging, learning, stp, oam, irb software
1594146 Incorrect Encapsulation/Decapsulation VNI pairs might get created and destroyed for type-5 tunnel in EVPN deployment
Product-Group=junos
On MX240/MX480/MX960/MX2008/MX2010/MX2020/EX9200 series configured with EVPN deployment and VXLAN Type-5 configuration with route leaking is enabled on remote PE VRF then VXLAN decapsulation may have issues leading to packet drops in PFE.
PR Number Synopsis Category: VMHOST platforms software
1529710 Multiple FRUs disconnection alarms might be displayed post the firmware upgrade
Product-Group=junosvae
On the MX/PTX platforms with NG-RE installed, after upgrading the Intel i40e-NVM firmware to version 6.01, the FRUs disconnection alarms may be seen along with traffic loss. Please refer to the TSB17603 [juniper.net] (https://kb.juniper.net/TSB17603 [juniper.net]) to upgrade Junos software and Intel i40e-NVM firmware.
 

19.3R3-S5 - List of Known issues
PR Number Synopsis Category: ESWD
1287184 The EX ESWD memory might leak upon interface flapping with STP configured and configured with NSB (Non-Stop Bridging)
Product-Group=junos
When EX Series (applicable platforms: EX2200, EX3300, EX4200, EX4500, EX4550, EX6200, EX8200, and XRE200) is configured with STP and NSB (non-stop bridging), the interface flapping ( link up/down events) might cause eswd memory leak.
PR Number Synopsis Category: ACX GE, 10GE, PoE, IDT framers
1633226 Speed 10m configuration error on ACX5048 and ACX5096 platforms
Product-Group=junos
On ACX5048 and ACX5096 platforms interface speed 10m is not supported on 1G interface. This issue was introduced due to a bug fix and it has been resolved with this PR.
PR Number Synopsis Category: Bi Directional Forwarding Detection (BFD)
1599431 Some BFD sessions stuck in Init state after FPC restart
Product-Group=junos
After a reboot or chassis restart, everything goes Up and is stable. However, after restarting FPC 3 a good number of BGP sessions never recover. The reason is BFD (see the piece of log below) show bfd session | except up Detect Transmit Address State Interface Time Interval Multiplier XX.XX.XX.XX Init ae-x/x/x 6.000 2.000 3 XX:XX Init xe-x/x/x 256.000 2.000 3 After restarting fpc(Flexible PIC Concentrators ), there is a delay of 12-15sec delay to receive the PIPE close message. Few sessions which are using AE interface may stuck in init state forever. Which may impact traffic.
PR Number Synopsis Category: BBE Remote Access Server
1626718 ESSM sessions may get terminated in Radius as class attribute has got corrupted after performing ISSU
Product-Group=junos
When the ESSM (Extensible Subscriber Services Manager) service is getting created on existing subscriber session, the class attribute is wrongly formed. This happens when Radius sends class attribute in access-accept messages after performing ISSU.
PR Number Synopsis Category: MPC5/6E PFE ISSU software
1542882 The JNH memory leak could be observed on MPCs or MICs
Product-Group=junos
On all Junos platforms with Trio-based line cards, a Junos next-hop (JNH) memory leak might be observed. This issue is due to the counters applications under firewall filters taking the additional memory space from the shared JNH pool. In an extreme scenario, this could also lead to FPC crash.
PR Number Synopsis Category: CFM
1536417 FPC might core if CFM flap trap monitor feature in use
Product-Group=junos
FPC might core if flap-trap-monitor feature under "set protocols oam ethernet cfm performance-monitoring sla-iterator-profiles" is used and performance monitoring flap occurs.
PR Number Synopsis Category: CoS support on DNX
1603622 RED-dropped packets might be observed if hierarchical-scheduler is configured on ACX5448 platforms
Product-Group=junos
On ACX5448 platforms, if hierarchical-scheduler is configured for an interface, during interface flaps or configuration changes, some of PFE buffers might become out of sync, which might cause packets drops even without congestion.
PR Number Synopsis Category: eventd, syslog infra issues
1611885 Master-eventd process might go down when syslog configuration is misconfigured
Product-Group=junos
On all Junos Operating System Evolved(EVO) based platforms with misconfigured syslog, master-eventd process might go down.
PR Number Synopsis Category: EX driver issues
1600291 The SFP-T port might stop forwarding traffic on EX4600 platforms
Product-Group=junos
On EX4600, after performing an upgrade, the peer device is rebooted, the peer interface is disabled/enabled or rebooting EX4600, then the SFP-T port on EX4600 might remain in up state but could not forward traffic.
PR Number Synopsis Category: EX optics issues
1611772 Traffic stops when traffic is switching from one LAG member to another member in case of MACSEC is configured
Product-Group=junos
During config change of MACSEC on LAG, LAG members (port) is reinitializing the STP from fresh and due to STP state of port is getting modifying, it went to disable state and traffic loss occurred.
PR Number Synopsis Category: Express PFE FW Features
1637328 Filters with Unsupported match/action by kernel filters, will not be learnt by firewall MIB daemon.
Product-Group=junosvae
Filters with Unsupported match/action by kernel filters, will not be learnt by firewall MIB daemon.
PR Number Synopsis Category: Flow-tap software
1647179 DTCP radius-flow-tap fails to program PFE when trigger X-NAS-Port-Id exceeds 48 character length.
Product-Group=junos
DTCP radius-flow-tap fails to program PFE when trigger X-NAS-Port-Id exceeds 48 character length.
PR Number Synopsis Category: Fast Ethernet interfaces
1613430 Static route might not work on vSRX
Product-Group=junos
On vSRX instance instantiated in Google Cloud, static route might not work.
PR Number Synopsis Category: Layer 2 Control Module
1629011 Traffic drop might be reported on the interface after reboot or power cycle
Product-Group=junos
On Junos and EVO platforms, after reboot or power cycle, aggregated ethernet (AE) interfaces will have spanning tree protocol (STP) state discarding after the box comes up. It might cause traffic drop on the interface.
PR Number Synopsis Category: Multiprotocol Label Switching
1614248 The rpd core dumps might occur for few value configurations of signaling bandwidth on container LSP
Product-Group=junos
If there is a large difference between current bandwidth usage and configured values of splitting-merging merging-bandwidth or splitting-merging minimum-signaling-bandwidth or minimum-bandwidth(template level)on container LSP(e.g. the current bandwidth which is coming is 4.5Gbps , the minimum-signaling-bandwidth is configured as 1bps), then it may result in crashing and restarting of Routing Protocol Daemon(rpd).
1616841 Protected LSP goes down with strict hops and link protection configured
Product-Group=junos
On all Junos and all EVO platforms, the sub-LSP of a Point-to-Multipoint Label Switched Path(P2MP LSP) with link-protection and having strict hops goes down when a protected link on more than one sub-LSP goes down simultaneously and TED(Traffic Engineering Database) notification or RSVP tunnel local repair message not received before the CSPF(Constrained Shortest Path First) computation. As a result, the sub-LSP fails and traffic drop is seen.
PR Number Synopsis Category: IPv6/ND/ICMPv6 issues
1631607 ipv6 host route prefix match disappear from 'forwarding-table' after a ping test, ping continues to work, forwarding table entry is not shown. No impact in traffic.
Product-Group=junos
IPv6 route resolutions for ipv6 hosts is missing from the 'route forwarding-table' after pinging hosts within the ip prefix.
PR Number Synopsis Category: OSPF routing protocol
1636028 RPD memory leak on OSPF SR routers when deploy in a network with mixed OSPF SR/Non-SR router
Product-Group=junos
When mixing OSPF Segment Routing (SR) routers with non-SR routers, you may see memory leak on the SR routers.
PR Number Synopsis Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1452136 The mgd might crash when you use the replace pattern command.
Product-Group=junos
When you use the "replace pattern" command to replace the name in the apply-group, the mgd crashes.
PR Number Synopsis Category: PFE on Aggregation Device
1607750 Configuring port mirroring firewall filter in a bridge domain with IRB might cause traffic loss over IRB
Product-Group=junos
On Junos Fusion setup, if a port mirroring firewall filter is configured in a bridge domain with Integrated Routing and Bridging (IRB), traffic over IRB might get dropped, resulting in service impact.

Modification History

First publication - 2022-02-28