Alert Type

PSN - Product Support Notification
Low/NotificationSRN
Low/NotificationSRN

Product Affected

ACX, MX, EX, PTX, QFX, vMX, vRR, NFX, SRX, vSRX.

Alert Description

Junos Software Service Release version 21.1R3-S1 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.1R3-S1 is now available.

21.1R3-S1 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 PFE
1630616The ARP resolution may get failed on VRRP enabled interface
Product-Group=junos
On EX4300, ARP resolution against virtual IP on VRRP enabled interface may get fail with "no-arp-trap" is configured due to which service may get affected.
1630935Application of firewall filters might break connectivity towards the hosts on EX4300
Product-Group=junos
On EX4300 platforms except EX4300-MP/EX4300-48MP, once input/output firewall filters are applied to the interfaces under family ethernet-switching, it might result in disrupting the connectivity towards few hosts connected to the device and thus impacts the related traffic.
PR NumberSynopsisCategory: EX4300 Platform
1623215Traffic loss might be seen when the interface fails to verify the parameter "LOCAL-FAULT"
Product-Group=junos
On all EX4300 platforms( excluding EX4300-MP), when the interface fails to verify the interface parameter "Local-fault", traffic loss might be seen.
1634781The PFE might get crash when VC member flaps on EX platforms
Product-Group=junos
On EX platforms, Virtual Chassis (VC) PFE crashes and more than one Routing Engine showing as MASTER when there is VC link flap between FPCs. There will be traffic loss until PFE comes up. The PFE will come up automatically and traffic will be resumed.
PR NumberSynopsisCategory: EX2300/3400 PFE
1616646PFE might crash due to deletion of storm control configuration for IFL in CLI which may lead to traffic loss
Product-Group=junos
On Junos EX and QFX platforms with storm control IFL entry, when deleting the storm control configuration in CLI PFE reboot might occur due to access of storm control IFL entry memory that was freed during deletion which might lead to traffic loss.
1627857Packet drop might be observed when L2PT is configured on transit device
Product-Group=junos
On ACX/EX/QFX Junos platforms with Q-in-Q setup in SP(Service Provider) style configuration, when L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch, mac rewritten packets might get dropped on the transit device due to which protocol (for example, STP) convergence fails between the end nodes and thus L2PT breakage could be observed for service-VLANs included in the environment.
1632643Unicast ARP packets with the first four bytes of its destination MAC matching to system macs of a transit system gets trapped by the system
Product-Group=junos
On EX2300 platforms as transit switches, when no-arp-trap is enabled, if the ARP packets are unicast of which the destination MAC has upper four bytes matching to the system MAC, the ARP packets are not forwarded but trapped.
1633115Traffic loss for 20 sec on VC with AE link-protection when rebooting backup FPC
Product-Group=junos
On EX/QFX series Virtual Chassis (VC) with Aggregated Ethernet (AE) link-protection configured, traffic loss could be seen for around 20 sec when the traffic is passing through backup link and backup FPC is rebooted.
1637784MAC address might not be learned on the new interface after MAC move
Product-Group=junos
On EX3400/EX4300/EX2300 platforms, when dot1x authentication is configured for a MAC-based VLAN (MBV) and if MAC move happens, the old MBV entry might not get cleared because of which MAC address might not be learned on the new interface and result in traffic loss.
PR NumberSynopsisCategory: EX2300/3400 platform
1627673System time may not be updated after reboot on EX2300 platform
Product-Group=junos
System time may not be updated after reboot. Symptoms seen are: 1) After USB image installation, CLI is not working fine. 2) When DHCP persistence is configured with DHCP security and device reboots, the lease time values may show a high lease value post reboot.
PR NumberSynopsisCategory: IGP-Static, RIP, OSPF, ISIS
1634747ISIS last transition time never increments
Product-Group=junos
On ACX710 platform ISIS last transition time never increments even though session remains stable for long time.
PR NumberSynopsisCategory: QFX PFE CoS
1631448The uplink interface remains down for a longer duration due to VXLAN scaled configuration
Product-Group=junos
On all Junos QFX5K platforms, with Virtual Extensible LAN (VXLAN) and the filters applied on the VXLAN interface both having scaled configuration, if the device reboots, the uplink interface might remain down for a longer duration, resulting in service impact.
PR NumberSynopsisCategory: ACX GE, 10GE, PoE, IDT framers
1633226Speed 10m configuration error on ACX5048 and ACX5096 platforms
Product-Group=junos
On ACX5048 and ACX5096 platforms interface speed 10m is not supported on 1G interface. This issue was introduced due to a bug fix and it has been resolved with this PR.
PR NumberSynopsisCategory: ACX Services feature
1626058Unicast packet loss might be observed due to control-word configuration
Product-Group=junos
On ACX5448/ACX710 platforms, enabling control-word for Virtual Private LAN Service (VPLS) instance might result in unicast packet loss.
PR NumberSynopsisCategory: This category is for Broadband Edge accounting related issue
1628139Memory leak may occur on PFED process when the flat-file-profile is configured with knob 'use-fc-ingress-stats'
Product-Group=junos
In a scaled Subscriber Service Accounting scenario(~32K IFLs), if flat-file-profile is configured with 'use-fc-ingress-stats' knob, the memory leak on PFED(Packet Forwarding Engine Daemon) process may occur and if it crosses 80% of the total allocated memory of the process, it may crash.
PR NumberSynopsisCategory: BBE interface related issues
1629910The egress traffic on non-targeted iflset of subscribers might not be forwarded correctly over targeted AE interface
Product-Group=junos
In subscriber traffic across links over an aggregated Ethernet (AE) interface scenario, the egress data of subscriber applications (e.g. PPPoE/L2TP/MPLS/DHCP) attached logical interface sets (iflset, e.g. pppoe-iflset/demux-iflset) are configured at Layer 3 to handle many sets of subscriber queues respectively over one targeted-distribution enabled Layer 2 ifl of AE interface (e.g. ae-x/y/z.1). In some rare cases, if the member link/FPC of AE are flapped, the underlying ifd of the AE bundle might not be attached to iflset again. Then the egress traffic forwarding function of subscribers over the AE interface (e.g. traffic redistribution/CoS scheduling resources) might be impacted.
1633392The bbe-smgd process might crash after removing and adding a child link from AE interface
Product-Group=junos
On MX platforms enabled with dynamic-profiles for subscribers and the subscribers are configured over AE [Aggregate Ethernet] interface with targeted-distribution. When the child links of the AE interface are removed and then added, it could lead to bbe-smgd crash in the backup RE. This in-turn could affect the control plane subscriber services when the primary RE fails during such event.
PR NumberSynopsisCategory: Border Gateway Protocol
1600599Kernel crash might be observed on platforms having BGP configured with family L2VPN
Product-Group=junos
On all Junos OS and Junos Evolved platforms running Border Gateway Protocol (BGP) with Layer 2 VPN (L2VPN) scenario, kernel crash might be observed.
1632132The BGP session might flap after rpd crash with 'switchover-on-routing-crash' and NSR enabled in a highly scaled environment
Product-Group=junos
On all Junos platforms that support NSR (Nonstop active routing), when 'switchover-on-routing-crash' is enabled, the rpd process crash will lead to Routing Engine switchover. In a highly scaled environment (about 15~19 million BGP routes), BGP (Border Gateway Protocol) session which is still sending update packets of size more than 2k might flap even when NSR is enabled. This might lead to loss of traffic till the BGP session converges after the flap. This does not happen always but happens sporadically. The switchover can be either due to rpd process crash or when switchover is performed manually.
1643246The BGP peer might stay down in shards after doing a rollback
Product-Group=junos
In the BGP scenario with rib-sharding enabled, when a BGP group has at least 2 peers if changing BGP prefix-limit maximum to a lower value than the received number of prefixes, and also changing BGP teardown idle-timeout to a lower value, then committing the configuration, after that executing 'rollback 1', the BGP peer might stay down in shards and routes might not be learned anymore.
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1645591The MAC address might not be visible in the EVPN/VXLAN environment
Product-Group=junos
On all QFX5K platforms with EVPN-VxLAN, the MAC address might get stuck in the pending list of VTEP (Virtual Tunnel End Points) and not get installed. This issue can lead to traffic loss or reachability issues.
PR NumberSynopsisCategory: Device Configuration Daemon
1609838SNMP_TRAP_LINK_UP & SNMP_TRAP_LINK_DOWN trap might be seen while activating and deactivating firewall filters
Product-Group=junos
Unexpected LINK_UP/LINK_DOWN messages on vme interface might be seen in the syslog as part of config update on firewall filter. This issue is ONLY seen when vme interface is not configured, but not seen when vme interface is configured. And This issue only happens when virtual chassis is configured on the platform like EX Series or QFX Series Virtual Chassis.
PR NumberSynopsisCategory: Firewall Filter
1598530The IPv6 filter for family bridge cannot be referenced onto IFL
Product-Group=junosvae
On MX10008/MX10016 platforms, the IPv6 filter for family bridge cannot be referenced onto IFL. Commit check will fail for such configuration.
PR NumberSynopsisCategory: EVPN ELAN/E-TREE
1638386Locally switched traffic might be dropped on ACX5448 with ESI configured
Product-Group=junos
When an ACX5448 platform works as provider edge (PE) device in an Ethernet VPN-Multiprotocol Label Switching (EVPN-MPLS) environment, if it is connected to more than one customer edge (CE) devices and CE-facing interfaces are configured with Ethernet Segment Identifier (ESI), the Layer 2 traffic which is locally switched by the ACX5448 between CEs might be dropped randomly.
PR NumberSynopsisCategory: ACX platform interface issues
1635763The LACP delay may be observed with an "aggregate wait time" of more than 1 second
Product-Group=junos
On all Juniper platforms which are connected with another vendor device, in case of "aggregate-wait-time" of more than 1 second configured, the LACP may take more time to move into the active state.
PR NumberSynopsisCategory: DNX VPLS
1626267VPLS traffic loss might be observed post route flap
Product-Group=junos
On ACX5448 and ACX710 platforms, if route flap occurs, post which routes are re-learned and even if the Virtual private LAN service (VPLS) connection is up, VPLS traffic loss might still be observed.
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1626589The application package installation might fail with error in SRX platforms
Product-Group=junos
On SRX platforms, the application package installation might fail when the application/groups are enabled/disabled multiple times. This issue happens because each time when enable/disable is called, some of the memory does not get free.
PR NumberSynopsisCategory: Lacp related problems and issues.
1636093Some daemons might get stuck when snmpd is at 100% CPU utilization
Product-Group=junos
On all Junos and EVO platforms, when snmpd is at 100% CPU utilization and some daemons are trying to raise an SNMP trap, these daemons might get stuck which results in unbaling to handle any incoming corresponding packets and unbaling to response to any CLI commands.
PR NumberSynopsisCategory: EVPN control plane issues
1626416Multiple memory leaks might be seen leading to process rpd crash
Product-Group=junos
Multiple memory leaks might be seen, which might lead to the process rpd crash. Issue 1- On QFX platforms configured with EVPN-VxLAN memory leaks might be seen due to BGP communities. Issue 2- On all Junos and Junos OS Evolved platforms memory leaks might be seen due to MAC mobility.
PR NumberSynopsisCategory: EX driver issues
1600291The SFP-T port might stop forwarding traffic on EX4600 platforms
Product-Group=junos
On EX4600, after performing an upgrade, the peer device is rebooted, the peer interface is disabled/enabled or rebooting EX4600, then the SFP-T port on EX4600 might remain in up state but could not forward traffic.
PR NumberSynopsisCategory: Express PFE MPLS Features
1590387ISIS adjacency is not coming up through TCC l2circuit
Product-Group=junos
On ACX/PTX/QFX platforms(PTX10002/10003/10008/10016/QFX10002/10003/10008/10016/ACX6360) if protocols l2circuit and channel tcc is enabled for providing layer 2 transaction, ISIS connection through the layer 2 domain might get failed and traffic loss might be seen.
PR NumberSynopsisCategory: Flow-tap software
1647179DTCP radius-flow-tap fails to program PFE when trigger X-NAS-Port-Id exceeds 48 character length.
Product-Group=junos
DTCP radius-flow-tap fails to program PFE when trigger X-NAS-Port-Id exceeds 48 character length.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1641988The VMcore might be observed on EX platforms in rare scenario
Product-Group=junos
On EX platforms, the Routing Engine (RE) might get crashed and result in VMcore, if the kernel sends a request to PFE for fetching the statistics of an Aggregated Ethernet (AE) with more than one member link. This issue appears when the member link gets lost for certain reasons in background and at the same time the kernel's request arrives. Since AE member link has lost, PFE might not send statistics response to kernel within 10 seconds(default time) and error might be returned. This invalid memory access might result in RE crash by generating VMcore. This could be a rare case scenario.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1623262Host generated IPv4 traffic sent over IPv6 next-hop with IRB interface might get dropped
Product-Group=junos
On all Junos platforms that support IRB(Integrated routing and bridging), when host originated IPv4 traffic is sent over IPv6 next-hop with IRB interface, the traffic might get dropped because of ether-type mismatch. This is because the ether-type field in L2 header is set to IPv6 (instead of IPv4) always due to the IPv6 next hop.
PR NumberSynopsisCategory: Application aware Quality-of-Service
1640768Configuration change during AppQoS session might result in PFE crash with flowd core
Product-Group=junos
On SRX/NFX platforms supporting Application Aware Quality Of Service (AppQoS), when the session is in process by AppQoS module and if any configuration change is pushed to PFE at the same time, PFE might crash with flowd core resulting in the traffic outage. Issue could be recovered by disabling AppQoS. It could be a rare timing issue.
PR NumberSynopsisCategory: Flow Module
1634146Packets may not be classified according to the CoS rewrite configuration
Product-Group=junos
When SPC3 card is used on SRX platforms, with flow mode clear text fragmented packets might not be properly classified according to the CoS rewrite configuration.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1631938BFD over high-availability ICL link might flap
Product-Group=junos
BFD over high-availability ICL link may flap if there were many rekeyed SAs due to simultaneous rekey. Now oldest IPsec SAs are deleting so that at max only 2 SAs are associated with HA Link tunnels.
PR NumberSynopsisCategory: Firewall Network Address Translation
1631815New persistent NAT or normal source NAT sessions might fail due to noncleared aged out sessions
Product-Group=junos
On high end SRX platforms with Central Point (CP) architecture and Services Processing Units (SPUs), if configured with all these features "persistent NAT, hairpin, source NAT", persistent NAT sessions might get stuck and aged out Persistent NAT sessions might not get cleared, due to which the new persistent NAT or normal source NAT session might fail.
PR NumberSynopsisCategory: User Firewall related issues
1637548Unable to connect to domain controller on installing Microsoft KB update
Product-Group=junos
On all SRX platforms, when the User Identification feature is used with Active Directory, after the Domain Controller server installs updates related to Microsoft's KB article KB5004442 [juniper.net], SRX is no longer able to connect to it.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1574409The SRXPFE process might crash and generate a core file when IPsec VPN is used
Product-Group=junosvae
On SRX4000 and SRX5000 Series devices, the SRXPFE process might crash and generate a core file when IPsec VPN is configured.
1627557Traffic over IPSec tunnels may be dropped post control link failure
Product-Group=junos
After control-link failure, the traffic over IPSec tunnels might be dropped.
1638437The kmd process might crash if the IKE negotiation fragment packets are missed during initiating an IKE SA rekey
Product-Group=junos
If IPsec IKEv2 is used and IKE negotiation fragment packets are missed during initiating an IKE SA rekey, the kmd process might crash. There will be temporary IPSec traffic interruption until the issue is restored automatically.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1626714Broadcast traffic might not be forwarded to LT interface in VPLS routing instance after LT interface is deleted then added back
Product-Group=junos
On MX platforms, when Logical Tunnels (LT) interface is used for VPLS, VPLS broadcast traffic might not be forwarded to LT interface properly after deleting the LT interface adding it back, which might cause LT interface missing from VPLS flood topology and eventually affects VPLS communication.
1629678The l2ald might be stuck in "issu state" when ISSU is aborted
Product-Group=junos
On all Junos platforms, when Unified In-service Software Upgrade (ISSU) is aborted, Layer 2 Address Learning Daemon (l2ald) may not be able to read 'issu abort' notification and l2ald might be stuck in 'issu state' and l2ald will not process new events while in 'issu state'.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1634464License may get lost after switchover
Product-Group=junos
On all platforms that are on Agile LKG licensing infrastructure, all operationally added licenses may be lost after switchover.
PR NumberSynopsisCategory: MX Timing software
1622108When PHY-Sync state moved to False it internally disables the PHY-timestamping of PTP packets.
Product-Group=junos
When the PHY-sync state of a line card moves to FALSE permanently, it fails to send a degraded clock class to its downstream neighbours.
1634569PTP clock class might incorrectly be downgraded to 248 when PTP is enabled on Linecard/MIC which does not support phy-timestamping
Product-Group=junos
When PTP slave is configured on MICs (MPC2E-3D-NG-Q, MPC3E-3D-NG-Q and MIC3-3D-10XGE-SFPP) that does not support phy-timestamping, the PTP TX clock class might incorrectly be degraded to 248 causing the downstream PTP nodes to look for another best master clock.
PR NumberSynopsisCategory: Track Mt Rainier SPMB platform software issues
1637950SPMB might crash immediately after a switchover
Product-Group=junos
On dual RE PTX5K platforms equipped with SPMB type- PTX5K CB PMB, immediately after a switchover, if the new master SPMB (Switch Processor Mezzanine Board) finds any CB-to-SIB PCI (Control Board - Switch Interface Board Peripheral Component Interconnect) link down error, then the new master SPMB might crash causing a traffic blackhole for about 2-3 minutes while the SIBs (Switch Interface Board) are re-initialized.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1570148A false error related to insufficient space might appear while installing a Junos image that is corrupted
Product-Group=junos
On all Junos platforms, the upgrade might fail with a false error related to insufficient space when trying to install Junos from a corrupted package.
PR NumberSynopsisCategory: vMX Data Plane Issues
1641119IPv4 and v6 packet header corruption could happen with some sampling scenario
Product-Group=junos
On vMX/MX150/NFX150 platforms, when sampling is enabled on input WAN interfaces and the sampled packet go out through a GRE tunnel, IPv4/6 header corruption may happen. Due to IP header corruption, remote router reports L3 incompletes at receiving interface.
PR NumberSynopsisCategory: Issues related to PKI daemon
1573892The process pkid may be observed during local certificate enrollment
Product-Group=junos
PKID core might occur during cert signature validation . This core is not very frequent and occurs due to memory corruption .
1580442PKID core during auto-re-enrollment of CMPv2 certificates.
Product-Group=junos
During auto-reenrollment of cmpv2 certificates, if the CA server is unresponsive and cmpv2 request retries has reached the maximum limit, then pkid core might occur. This is a corner case scenario and core is not frequent .
PR NumberSynopsisCategory: VRR (Virtual Route Reflector) for MX
1635950vRR VM might establish its identity as "Olive" after a CLI s/w upgrade
Product-Group=junos
vRR VM might come up as Olive after a CLI sw upgrade using junos-install-mx* package if the XML used to spawn the VM didn't have SMBIOS entry "VRR".
PR NumberSynopsisCategory: QFX Platform related (SYSLOG/ALARMS/miscellaneous)
1598805The interface on SFP-T or SFP-SX might stop forwarding traffic on EX4600
Product-Group=junos
On EX4600, the interfaces on SFP-T or SFP-SX might stop forwarding traffic when MACSec and auto-negotiation is enabled on the ports. The interfaces would still show as up and the transmit and receive counters will increase. However, the transmit counters on the port will not increase.
PR NumberSynopsisCategory: QFX access control list
1643457ICMP TTL exceeded packets are not sent out of the switch
Product-Group=junos
On the QFX5000 line of switches, ICMP TTL exceeded message might not be sent back to the source when TTL expired in inner payload with GRE encapsulated received packet.
PR NumberSynopsisCategory: QFX L2 PFE
1633452The FBF filtered VLAN traffic will not be passed properly to the forwarding routing instances over AE interfaces on QFX5K/EX4600/EX4650 platforms
Product-Group=junos
On QFX5K/EX4600/EX4650 platforms with IPv4 Filter-based forwarding (FBF) scenario, when IPv4 FBF is used with 802.1Q VLAN tag enabled layer-3 AE interfaces, the VLAN filtered configuration enabled by FBF filter will be stored in the VLAN filter processor (VFP) ternary content addressable memory (TCAM). But, in some cases of adding/deleting the configuration of the routing instances (then routing-instance) in FBF filter, the stale allocated entries in VFP TCAM might not be deleted from the system, the memory slices of VFP TCAM will be exhausted until it is run out. Finally, there are not enough memory slices left to store the VLAN filtered information for the forwarding routing instances, then the FBF filtered VLAN traffic will not be forwarded correctly since the FBF filters might not be programmed/processed on the system.
1637249Configuring L2PT on a transit switch in a Q-in-Q environment breaks L2PT for other S-VLANs
Product-Group=junos
When L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch using SP style configuration, protocol convergence between end nodes might fail.
1638619Targeted broadcast or WOL feature may not work on QFX 5k platforms
Product-Group=junos
On QFX platforms, Wake On LAN(WOL) feature stops working as the affected platforms erroneously process such packets. This might cause a blackhole in the network for such traffic.
1639926MAC-move might be observed when dhcp-security is configured
Product-Group=junos
On QFX5K/EX46x0 VC (Virtual chassis) Junos platforms with DHCP(Dynamic Host Configuration Protocol) server-client scenario and "dhcp-security" configured under vlan on any of the intermediate node between the server and client, once DHCP client requests an IP to the server and if both the ingress and egress interface lies on the same FPC, request packets might get reinjected back to the same interface causing MAC (Media Access Control) moves. Thus, allocated IP might not reach the client. Eventually, no clients might be able to login.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1624925QFX5K log messages: fpc0 SRIRAM Tx VxLAN Ucast: ifd_out = vtep dst_gport is (c00000X) so do not process pkt further
Product-Group=junos
Log messages "fpc0 SRIRAM Tx VxLAN Ucast: ifd_out = vtep dst_gport is (c00000X) so do not process pkt further" can show up on QFX5K switches (where X = different values). These are harmless messages.
1636950Traffic blackhole might be observed when STP is configured in VxLAN environment
Product-Group=junos
On QFX platforms in VxLAN scenario, if STP is enabled on all the interfaces of the switch, ethernet table might not get populated to locally connected devices resulting in traffic blackhole.
PR NumberSynopsisCategory: QFX5100 Interface related issues
1633998The VCPs connected with the AOC cable might not come up after upgrading to 17.3 or later releases
Product-Group=junos
On QFX5100/EX4600 platforms with the Virtual Chassis (VC) scenario, if the Virtual Chassis Ports (VCPs) are connected through QSFP+40GE-AOC cable, post upgrading to 17.3 or later releases, VCPs might not come up or flap impacting VC functionality and services.
1638045Delay might be observed for the interfaces to come up after reboot/transceiver replacement
Product-Group=junos
On QFX5100/EX4600 Junos platforms with 2-member VC(Virtual Chassis) setup, after the device reboot or QSFP+-40G-SR4 SFP (small form-factor pluggable) replacement, the VC port might remain down and takes longer time (approximately 5-20min) to come up even if the cable is connected properly to the interface.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Interface
1632620You may see a slow response or timeout on the CLI or SNMP with accessing to sxe-0/0/0 on QFX5120-48T-6c.
Product-Group=junosvae
As some examples, SNMP walk stops working after some time or the output by "show interface" takes a pause immediately before displaying sxe-0/0/0. Internal interfaces sxe-0/0/0 and sxe-0/0/1 were created for PTP functionality. In which sxe-0/0/0 was dummy, this interface getting created in Junos side and not dcpfe side and caused these issue. There was no need to create dummy interface, the fix made sxe-0/0/0 to use for PTP functionality and removed sxe-0/0/1.
PR NumberSynopsisCategory: SRX branch platforms
1633503Tasks of download manager may not be resumed post reboot
Product-Group=junos
The function of Automatic resume on reboot in Download manager feature might not work when downloading files.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1630990The srxpfe process might crash on SRX4600
Product-Group=junosvae
On SRX4600, a corruption in memory buffer (m_buf) might lead to srxpfe crash. Core files are generated and hardware monitoring failures might be observed when the process crashes.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1638489Interoperability issue between legacy line cards and MPC10E/11E may cause incorrect load balancing over aggregate ethernet links
Product-Group=junos
On MX platforms, due to a software defect seen in interoperability scenarios on newer AFT-based MX cards (MPC10E and MPC11E), packets entering through legacy(non-AFT) card interfaces and exiting through AE interfaces via IRB may get incorrectly load balanced.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1632853MGD core might be observed upon ISSU upgrade
Product-Group=junos
On SRX platforms with cluster configured, mgd cores were observed during ISSU from 21.1 to 21.2.
PR NumberSynopsisCategory: QFX RCB issues
1635812QFX10008: chassisd crashed after configuring chassis disk-partition
Product-Group=junosvae
cli command is not supported by QFX10008 and QFX10016 platforms. Hence disabling the same.
PR NumberSynopsisCategory: VMHOST platforms software
1605971VM host platforms might boot exactly 30 minutes after executing 'request vmhost halt' command
Product-Group=junos
On all VM host platforms running Junos OS Release 19.3R1 onwards, when 'request vmhost halt' is executed, the system reboots after exactly 30 minutes instead of maintaining the halt condition.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1635351VRRP route tracking for routes in VRF might not work if "chained-composite-next-hop ingress l3vpn" is used
Product-Group=junos
In L3VPN scenario with configured "routing-options forwarding-table chained-composite-next-hop ingress l3vpn" knob, if VRRP route tracking is used to track routes inside a VRF, and if such routes are with composite next hop, they might be marked as down even they are present in the VRF, hence the VRRP route tracking might not work properly.
1637735"show vrrp extensive" doesn't show the next IFL "Interface VRRP PDU statistics"
Product-Group=junos
The "show vrrp extensive" command only shows "Interface VRRP PDU statistics" for the first logical interface. It doesn't show the next logical "Interface VRRP PDU statistics.
 
 

21.1R3-S1 - List of Known issues

PR NumberSynopsisCategory: CoS support on ACX
1633427The storm-control rate-limit might not work with VPLS policer under IFL
Product-Group=junos
On ACX5448 platforms, when storm-control rate-limit is configured on the physical interface along with the VPLS(Virtual Private LAN Service) filter and policer configured under attached IFL(logical interface), storm-control rate-limit might not get applied to the ingress traffic and hence entire traffic might get forwarded further unexpectedly.
PR NumberSynopsisCategory: Fireall support for ACX
1630280ACX5048 filters reporting TCAM errors are not installed in h/w after the upgrade from 17.4R2-S8 to 20.4R3
Product-Group=junos
This changes increase the number of family inet arp policers to 64 entries. TCAM resource shortage errors can be seen if there are more than 32 IFLs with configured arp policer.
PR NumberSynopsisCategory: A15 specific issue
1617103Execute RSI on SRX5K platform with IOC2 card installed may trigger data plane failover.
Product-Group=junos
Execute RSI on SRX5K platform with IOC2 card installed may trigger data plane failover.
PR NumberSynopsisCategory: a20a40 specific issue
1648850SCB reset with Error : zfchip_scan line = 844 name = failed due to PIO errors
Product-Group=junos
On SRX5000 series with SCB4, in rare occasions a Major Alarm may be raised for the SCB momentarily, while there is not actually a hardware error present. In a chassis cluster this will trigger an unexpected failover. This issue would be applicable for MX series with SCBE3 and EX9200 series with EX9200-SF3 as well.
PR NumberSynopsisCategory: Border Gateway Protocol
1630220The BGP ECMP might not work and multipath route wont be created
Product-Group=junos
On all platforms, if BGP multipath is configured, if an active path that is not eligible for multipath later gets deleted, the device might not calculate multipath for the other routes. This causes the ECMP feature to fail and thereby causes route learning to fail.
1635700The BFD session might be down when multiple addresses of same subnet are configured
Product-Group=junos
In the single-hop BFD of BGP scenario, when multiple addresses of the same subnet are configured on the interface of the BFD session, the BFD session might be down.
PR NumberSynopsisCategory: Class of Service
1603909802.1p rewrite policies might not have any effect if the rewrite is tied to CCC interfaces
Product-Group=junos
On the MX platform with trio-based line cards, the Class of Service rewrite policy might not work if the rewrite-rules are tied to CCC interfaces.
1650089Interface burst size becomes low in pfe, when 'rate-limit-burst' knob is removed
Product-Group=junos
When rate-limit-burst knob is deleted, burst size will fall back to the previously calculated burst size with the tx rate. In the above mentioned trigger, as the rate-limit-burst configs was present when the system is coming up, the burst size from the tx rate is not at all computed and when the user try to delete the knob, it is fall back to this un-computed burst size(default to 0). This is the reason for very small burst size configured to the rate limit queues. To fix this issue, we allow the burst size to be calculated even when global ratelimit knob is present and store it and use the burst size calculated from the global rate limit knob.
PR NumberSynopsisCategory: CFM
1536417FPC might core if CFM flap trap monitor feature in use
Product-Group=junos
The Flexible PIC Concentrator (FPC) might generate a core file (or dump file) if the flap-trap-monitor feature under "set protocols oam ethernet cfm performance-monitoring sla-iterator-profiles" is used and performance monitoring flap occurs.
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1632205Signature package update may fail and the appid process may crash on SRX devices
Product-Group=junos
On SRX platforms, with a sig-pack update if any application is moved to DEPRICATED and if that application was part of any custom group, signature upgrade may fail. Due to this sometimes the appid process may crash.
PR NumberSynopsisCategory: EX4400 platform
1614145EX4400-48MP - VM cores and VC split maybe observed with multicast scale scenario
Product-Group=junos
EX4400-48MP - VM cores and VC split maybe observed with multicast scale scenario
PR NumberSynopsisCategory: EX optics issues
1611772Traffic stops when traffic is switching from one LAG member to another member in case of MACSEC is configured
Product-Group=junos
During config change of MACSEC on LAG, LAG members (port) is reinitializing the STP from fresh and due to STP state of port is getting modifying, it went to disable state and traffic loss occurred.
PR NumberSynopsisCategory: jl2tpd daemon
1630150Tunneled subscribers may be stuck in terminating state in L2TP subscriber scenario
Product-Group=junos
On all MX platforms that support enhanced subscriber management (Next Generation Subscriber Management) with Layer 2 Tunneling Protocol (L2TP) subscriber scenario, L2TP subscribers may be stuck in terminating state if the L2TP subscribers try to login.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1606724Secondary node in a chassis cluster might go into reboot loop on SRX platforms
Product-Group=junos
On SRX1500/4100/4200, the secondary node in a chassis cluster might go into reboot loop after RG0 (redundancy-group 0) failover and secondary node is rebooted manually.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1628007Traffic loss over IPSEC tunnel might be seen on SRX platforms
Product-Group=junos
On SRX platforms with IPSEC when phase-2 re-key happens or both devices initiating SA (Security Association) negotiations at the same time, out of the 2 SA's negotiated the latest SA might get deleted causing loss of traffic passing through the tunnel. This is a rare timing issue and it might also happen with other vendor device.
PR NumberSynopsisCategory: Layer 2 Control Module
1629011Traffic drop might be reported on the interface after reboot or power cycle
Product-Group=junos
On Junos and EVO platforms, after reboot or power cycle, aggregated ethernet (AE) interfaces will have spanning tree protocol (STP) state discarding after the box comes up. It might cause traffic drop on the interface.
PR NumberSynopsisCategory: IPv6/ND/ICMPv6 issues
1631607ipv6 host route prefix match disappear from 'forwarding-table' after a ping test, ping continues to work, forwarding table entry is not shown. No impact in traffic.
Product-Group=junos
IPv6 route resolutions for ipv6 hosts is missing from the 'route forwarding-table' after pinging hosts within the ip prefix.
PR NumberSynopsisCategory: OSPF routing protocol
1636028RPD memory leak on OSPF SR routers when deploy in a network with mixed OSPF SR/Non-SR router
Product-Group=junos
When mixing OSPF Segment Routing (SR) routers with non-SR routers, you may see memory leak on the SR routers.
PR NumberSynopsisCategory: Protocol Independant Multicast
1630144The multicast forwarding cache might not get updated after deactivating the scope-policy configuration
Product-Group=junos
On all Junos and EVO platforms with multicast setup, the multicast forwarding cache might not get updated after deactivating the scope-policy configuration. This could result in the PIM register process to be incomplete and further multicast traffic to be dropped.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1627363RE generated traffic might not be forwarded when next-hop is indirect unilist of EVPN Type 5 tunnel
Product-Group=junos
On QFX5110/QFX5120 platforms with EVPN-VXLAN scenario, if the knob "preserve-nexthop-hierarchy" is configured, RE generated traffic might not be forwarded when next-hop is indirect unilist and learnt by EVPN Type 5 route.
PR NumberSynopsisCategory: QFX5100 Platform optics
1606003QFX5100 : Generate an optical power after detached and attached QSFP on disabled interface.
Product-Group=junos
On QFX5100, optical power is seen after detached and attached QSFP on disable interface.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1623170BGP Flowspec may not shows counters for matching IPv6 firewall filter
Product-Group=junos
Under investigation - When installing an IPv6 firewall filter using BGP flowspec, matching traffic counters may show "0" values.
1631871[CCL Google BX] RPD core on RE1 @ krt_inh.c,krt_nexthop.c,krt_remnant.c
Product-Group=junos
RPD core may be observed with warm-standby configurations due to reference counting issues.
PR NumberSynopsisCategory: RPD policy options
1646603Existing routing policies might change when global default route-filter walkup is changed
Product-Group=junos
When "set policy-options default route-filter walkup" configuration is changed( add/delete), existing routing-policies might change and all the existing "from" matching criteria will be removed from the routing-policies in the policy-db.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1629437The contributing routes might not be advertised properly if "from aggregate-contributor" is used
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, if a aggregate route is configured under routing-options, and if "from aggregate-contributor" is used for many contributing routes (e.g. more than 250-300 routes), the policy for these contributing routes might not work properly when the policy is exported. Due to this issue, the contributing routes might not be advertised properly.
PR NumberSynopsisCategory: Resource Reservation Protocol
1638145LSP over broadcast segment stays down when RSVP setup protection is enabled
Product-Group=junos
When RSVP setup protection is enabled, the LSP over a broadcast segment might stay down, due to a missing function of nexthop check for broadcast segment in code.
PR NumberSynopsisCategory: AMS (aggregated MS interface) related issues for load balanc
1628076ECMP may not work properly when AMS is configured as next-hop with ECMP
Product-Group=junos
On MX Series platforms with MPC10/MPC11 and MS-MPC/MS-MIC are used, if aggregated multiservices (AMS) interface is configured as next-hop with equal-cost multipath (ECMP), load balancing will not happen properly according to source-ip hashing.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1626115Traffic drop might be seen in node slicing scenario
Product-Group=junos
On MX platforms that use MPC11E cards, when fast-lookup-filter is enabled, traffic drop might be seen in the node slicing scenario.
PR NumberSynopsisCategory: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1638166AUTO-CORE-PR : JDI-RCT vRCT : vmxt_lnx core found @ topo_get_link jnh_features_get_jnh jnh_stream_attach
Product-Group=junos
vMX may see an FPC restarts when trying to gather software features of its FPC during its start up process.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1637304FPC crash might be seen on all MX platforms with BBE subscriber
Product-Group=junos
FPC might crash on all MX platforms with Broadband Edge (BBE) subscribers and the traffic flowing through the impacted FPC will get affected.
PR NumberSynopsisCategory: QFX RCB issues
1635812QFX10008: chassisd crashed after configuring chassis disk-partition
Product-Group=junos
cli command is not supported by QFX10008 and QFX10016 platforms. Hence disabling the same.
 

Modification History

First publication 2022-04-11