Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX, PTX, and QFX Series running Junos Evolved Software
Alert Description
Junos Software Service Release version 21.1R3-S1-EVO is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 21.1R3-S1-EVO is now available.
21.1R3-S1-EVO - List of Fixed issues
PR Number
Synopsis
Category: Border Gateway Protocol
1600599
Kernel crash might be observed on platforms having BGP configured with family L2VPN
Product-Group=evo
On all Junos OS and Junos Evolved platforms running Border Gateway Protocol (BGP) with Layer 2 VPN (L2VPN) scenario, kernel crash might be observed.
1632132
The BGP session might flap after rpd crash with 'switchover-on-routing-crash' and NSR enabled in a highly scaled environment
Product-Group=evo
On all Junos platforms that support NSR (Nonstop active routing), when 'switchover-on-routing-crash' is enabled, the rpd process crash will lead to Routing Engine switchover. In a highly scaled environment (about 15~19 million BGP routes), BGP (Border Gateway Protocol) session which is still sending update packets of size more than 2k might flap even when NSR is enabled. This might lead to loss of traffic till the BGP session converges after the flap. This does not happen always but happens sporadically. The switchover can be either due to rpd process crash or when switchover is performed manually.
1643246
The BGP peer might stay down in shards after doing a rollback
Product-Group=evo
In the BGP scenario with rib-sharding enabled, when a BGP group has at least 2 peers if changing BGP prefix-limit maximum to a lower value than the received number of prefixes, and also changing BGP teardown idle-timeout to a lower value, then committing the configuration, after that executing 'rollback 1', the BGP peer might stay down in shards and routes might not be learned anymore.
PR Number
Synopsis
Category: Express BT PFE L3 Features
1603145
The picd process restart might cause aftmand process crash
Product-Group=evo
On all Evo PTX platforms with Adaptive Load Balancing (ALB) configured on Aggregated Ethernet (AE) interface, if the picd process restarts, Advanced Forwarding Toolkit manager (aftmand) process might crash impacting the services.
1632385
P2MP LSP ping and traceroute from bud-node fails when the branch is on another PFE
Product-Group=evo
On PTX10001-36MR or PTX10004/PTX10008/PTX10016 which uses line cards PTX10K-LC1202/JNP10K-LC1202, when Point-to-Multi-point (P2MP) label-switched path (LSP) ping is initiated on a bud-node, ping fails if the brach is on another PFE. LSP ping packets will always have IP TTL as 1 on a bud-node/PHP node hence ping fails when the branch interfaces are on different PFEs.
PR Number
Synopsis
Category: Lacp related problems and issues.
1636093
Some daemons might get stuck when snmpd is at 100% CPU utilization
Product-Group=evo
On all Junos and EVO platforms, when snmpd is at 100% CPU utilization and some daemons are trying to raise an SNMP trap, these daemons might get stuck which results in unbaling to handle any incoming corresponding packets and unbaling to response to any CLI commands.
PR Number
Synopsis
Category: SNMP, mib2d issues
1635958
False traffic spikes seen SNMP graphs when ifHCOutOctets or ifHCInOctets are used .
Product-Group=evo
False traffic spikes seen SNMP graphs when ifHCOutOctets or ifHCInOctets are used .
PR Number
Synopsis
Category: Issues related to PKI daemon
1573892
The process pkid may be observed during local certificate enrollment
Product-Group=evo
PKID core might occur during cert signature validation . This core is not very frequent and occurs due to memory corruption .
PR Number
Synopsis
Category: AMS (aggregated MS interface) related issues for load balanc
1628076
ECMP may not work properly when AMS is configured as next-hop with ECMP
Product-Group=evo
On MX Series platforms with MPC10/MPC11 and MS-MPC/MS-MIC are used, if aggregated multiservices (AMS) interface is configured as next-hop with equal-cost multipath (ECMP), load balancing will not happen properly according to source-ip hashing.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1632853
MGD core might be observed upon ISSU upgrade
Product-Group=evo
On SRX platforms with cluster configured, mgd cores were observed during ISSU from 21.1 to 21.2.
21.1R3-S1-EVO - List of Known issues
PR Number
Synopsis
Category: Border Gateway Protocol
1626756
Multipath route with List-NH which has Indirect-NH as members fails into BGP-LU
Product-Group=evo
"RT-multipath route with List-Next-hop which has Indirect-Next-hop as members" is unable to advertise into BGP-labeled-unicast address family. This scenario could happen in Carrier's Carrier (CsC) VRF which is also the reported case.
PR Number
Synopsis
Category: Alias for DHCP issue on DNX based platform.
1610229
Restarting the DHCP process on ACX5000s platforms may take longer than expected
Product-Group=evo
A restart of DHCP takes more time because of internal issues with the SIGTERM event.
PR Number
Synopsis
Category: EVO Netstack FIB Service Daemon
1612208
Egress TCP RST may not have correctly populated DSCP field
Product-Group=evo
Egress TCP RST may not have correctly populated DSCP field
PR Number
Synopsis
Category: Issues related to debug utilties - objmon,objshell/Dashboard
1602272
Junos OS and Junos OS Evolved: python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API via timed processing of valid PKCS#1 v1.5 ciphertext. (CVE-2020-25659)
Product-Group=evo
A vulnerability in the python cryptographic library as used in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to perform timing oracle attacks against RSA decryption. Please refer to https://kb.juniper.net/
JSA11245
[juniper.net]
for more information.
PR Number
Synopsis
Category: Express PFE FW Features
1622313
AFT Firewall telemetry (ZT): Suppressed 'state' container and modified field numbers in the render proto. This is to sync with uKernel proto.
Product-Group=evo
Changes are done to have the Firewall UDP telemetry output same while moving between MPC10E (AFT) and MPC7E (uKernel).
PR Number
Synopsis
Category: Issues related to Junos licensing infrastructure
1628733
PTX10008 EVO : license installation fails with "validation hook evaluation failed" commit error
Product-Group=evo
On PTX10008 EVO, license installation succeeds with "request system license add terminal" CLI command, but installing the same license fails with "validation hook evaluation failed" error while performing commit.
PR Number
Synopsis
Category: Issues related to PKI daemon
1549954
PKI CMPv2 client certificate enrolment does not work on SRX when using root-CA.
Product-Group=evo
The PKI CMPv2 (RFC 4210) client certificate enrolment does not properly work on SRX Series devices when using root-CA.
PR Number
Synopsis
Category: ZT/YTpfe bridging, learning, stp, oam, irb software
1638489
Interoperability issue between legacy line cards and MPC10E/11E may cause incorrect load balancing over aggregate ethernet links
Product-Group=evo
On MX platforms, due to a software defect seen in interoperability scenarios on newer AFT-based MX cards (MPC10E and MPC11E), packets entering through legacy(non-AFT) card interfaces and exiting through AE interfaces via IRB may get incorrectly load balanced.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1598123
Interface configuration may get stuck and may not update after several ephemeral commits
Product-Group=evo
After several ephemeral commits interface configurations may get stuck and may not get updated on all Junos platforms.
PR Number
Synopsis
Category: VNID L2-forwarding on Trio
1630163
Scenario where within a VRF multiple VXLAN type-5 tunnels with same decap prefix are not handled on MPC10/11
Product-Group=evo
On MPC10/11 line cards, EVPN/VXLAN scenario where within a VRF multiple VXLAN type-5 tunnels with same decap prefix are created is not well handled, which might lead to traffic drop.
Modification History
First publication 2022-03-08
21.1R3-S1-EVO: Software Release Notification for JUNOS Software Version 21.1R3-S1-EVO