Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, PTX, and QFX Series running Junos Evolved Software

Alert Description

Junos Software Service Release version 21.1R3-S1-EVO is now available for download from the Junos software download site
Download Junos Software Service Release:
  1. Go to  Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select  Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.1R3-S1-EVO is now available.

21.1R3-S1-EVO - List of Fixed issues

PR Number Synopsis Category: Border Gateway Protocol
1600599 Kernel crash might be observed on platforms having BGP configured with family L2VPN
Product-Group=evo
On all Junos OS and Junos Evolved platforms running Border Gateway Protocol (BGP) with Layer 2 VPN (L2VPN) scenario, kernel crash might be observed.
1632132 The BGP session might flap after rpd crash with 'switchover-on-routing-crash' and NSR enabled in a highly scaled environment
Product-Group=evo
On all Junos platforms that support NSR (Nonstop active routing), when 'switchover-on-routing-crash' is enabled, the rpd process crash will lead to Routing Engine switchover. In a highly scaled environment (about 15~19 million BGP routes), BGP (Border Gateway Protocol) session which is still sending update packets of size more than 2k might flap even when NSR is enabled. This might lead to loss of traffic till the BGP session converges after the flap. This does not happen always but happens sporadically. The switchover can be either due to rpd process crash or when switchover is performed manually.
1643246 The BGP peer might stay down in shards after doing a rollback
Product-Group=evo
In the BGP scenario with rib-sharding enabled, when a BGP group has at least 2 peers if changing BGP prefix-limit maximum to a lower value than the received number of prefixes, and also changing BGP teardown idle-timeout to a lower value, then committing the configuration, after that executing 'rollback 1', the BGP peer might stay down in shards and routes might not be learned anymore.
PR Number Synopsis Category: Express BT PFE L3 Features
1603145 The picd process restart might cause aftmand process crash
Product-Group=evo
On all Evo PTX platforms with Adaptive Load Balancing (ALB) configured on Aggregated Ethernet (AE) interface, if the picd process restarts, Advanced Forwarding Toolkit manager (aftmand) process might crash impacting the services.
1632385 P2MP LSP ping and traceroute from bud-node fails when the branch is on another PFE
Product-Group=evo
On PTX10001-36MR or PTX10004/PTX10008/PTX10016 which uses line cards PTX10K-LC1202/JNP10K-LC1202, when Point-to-Multi-point (P2MP) label-switched path (LSP) ping is initiated on a bud-node, ping fails if the brach is on another PFE. LSP ping packets will always have IP TTL as 1 on a bud-node/PHP node hence ping fails when the branch interfaces are on different PFEs.
PR Number Synopsis Category: Lacp related problems and issues.
1636093 Some daemons might get stuck when snmpd is at 100% CPU utilization
Product-Group=evo
On all Junos and EVO platforms, when snmpd is at 100% CPU utilization and some daemons are trying to raise an SNMP trap, these daemons might get stuck which results in unbaling to handle any incoming corresponding packets and unbaling to response to any CLI commands.
PR Number Synopsis Category: SNMP, mib2d issues
1635958 False traffic spikes seen SNMP graphs when ifHCOutOctets or ifHCInOctets are used .
Product-Group=evo
False traffic spikes seen SNMP graphs when ifHCOutOctets or ifHCInOctets are used .
PR Number Synopsis Category: Issues related to PKI daemon
1573892 The process pkid may be observed during local certificate enrollment
Product-Group=evo
PKID core might occur during cert signature validation . This core is not very frequent and occurs due to memory corruption .
PR Number Synopsis Category: AMS (aggregated MS interface) related issues for load balanc
1628076 ECMP may not work properly when AMS is configured as next-hop with ECMP
Product-Group=evo
On MX Series platforms with MPC10/MPC11 and MS-MPC/MS-MIC are used, if aggregated multiservices (AMS) interface is configured as next-hop with equal-cost multipath (ECMP), load balancing will not happen properly according to source-ip hashing.
PR Number Synopsis Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1632853 MGD core might be observed upon ISSU upgrade
Product-Group=evo
On SRX platforms with cluster configured, mgd cores were observed during ISSU from 21.1 to 21.2.
 

21.1R3-S1-EVO - List of Known issues

PR Number Synopsis Category: Border Gateway Protocol
1626756 Multipath route with List-NH which has Indirect-NH as members fails into BGP-LU
Product-Group=evo
"RT-multipath route with List-Next-hop which has Indirect-Next-hop as members" is unable to advertise into BGP-labeled-unicast address family. This scenario could happen in Carrier's Carrier (CsC) VRF which is also the reported case.
PR Number Synopsis Category: Alias for DHCP issue on DNX based platform.
1610229 Restarting the DHCP process on ACX5000s platforms may take longer than expected
Product-Group=evo
A restart of DHCP takes more time because of internal issues with the SIGTERM event.
PR Number Synopsis Category: EVO Netstack FIB Service Daemon
1612208 Egress TCP RST may not have correctly populated DSCP field
Product-Group=evo
Egress TCP RST may not have correctly populated DSCP field
PR Number Synopsis Category: Issues related to debug utilties - objmon,objshell/Dashboard
1602272 Junos OS and Junos OS Evolved: python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API via timed processing of valid PKCS#1 v1.5 ciphertext. (CVE-2020-25659)
Product-Group=evo
A vulnerability in the python cryptographic library as used in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to perform timing oracle attacks against RSA decryption. Please refer to https://kb.juniper.net/JSA11245 [juniper.net] for more information.
PR Number Synopsis Category: Express PFE FW Features
1622313 AFT Firewall telemetry (ZT): Suppressed 'state' container and modified field numbers in the render proto. This is to sync with uKernel proto.
Product-Group=evo
Changes are done to have the Firewall UDP telemetry output same while moving between MPC10E (AFT) and MPC7E (uKernel).
PR Number Synopsis Category: Issues related to Junos licensing infrastructure
1628733 PTX10008 EVO : license installation fails with "validation hook evaluation failed" commit error
Product-Group=evo
On PTX10008 EVO, license installation succeeds with "request system license add terminal" CLI command, but installing the same license fails with "validation hook evaluation failed" error while performing commit.
PR Number Synopsis Category: Issues related to PKI daemon
1549954 PKI CMPv2 client certificate enrolment does not work on SRX when using root-CA.
Product-Group=evo
The PKI CMPv2 (RFC 4210) client certificate enrolment does not properly work on SRX Series devices when using root-CA.
PR Number Synopsis Category: ZT/YTpfe bridging, learning, stp, oam, irb software
1638489 Interoperability issue between legacy line cards and MPC10E/11E may cause incorrect load balancing over aggregate ethernet links
Product-Group=evo
On MX platforms, due to a software defect seen in interoperability scenarios on newer AFT-based MX cards (MPC10E and MPC11E), packets entering through legacy(non-AFT) card interfaces and exiting through AE interfaces via IRB may get incorrectly load balanced.
PR Number Synopsis Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1598123 Interface configuration may get stuck and may not update after several ephemeral commits
Product-Group=evo
After several ephemeral commits interface configurations may get stuck and may not get updated on all Junos platforms.
PR Number Synopsis Category: VNID L2-forwarding on Trio
1630163 Scenario where within a VRF multiple VXLAN type-5 tunnels with same decap prefix are not handled on MPC10/11
Product-Group=evo
On MPC10/11 line cards, EVPN/VXLAN scenario where within a VRF multiple VXLAN type-5 tunnels with same decap prefix are created is not well handled, which might lead to traffic drop.
 

Modification History

First publication 2022-03-08