Alert Type
PSN - Product Support Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX, MX, EX, PTX, QFX, vMX, cSRX, vRR, NFX, SRX, vSRX, JWEB.
Alert Description
Junos Software Service Release version 20.4R3-S3 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 20.4R3-S3 is now available.
20.4R3-S3 - List of Fixed issues
PR Number
Synopsis
Category: EX4300 PFE
1630935
Application of firewall filters might break connectivity towards the hosts on EX4300
Product-Group=junos
On EX4300 platforms except EX4300-MP/EX4300-48MP, once input/output firewall filters are applied to the interfaces under family ethernet-switching, it might result in disrupting the connectivity towards few hosts connected to the device and thus impacts the related traffic.
PR Number
Synopsis
Category: EX4300 Platform
1634781
The PFE might get crash when VC member flaps on EX platforms
Product-Group=junos
On EX platforms, Virtual Chassis (VC) PFE crashes and more than one Routing Engine showing as MASTER when there is VC link flap between FPCs. There will be traffic loss until PFE comes up. The PFE will come up automatically and traffic will be resumed.
PR Number
Synopsis
Category: EX2300/3400 PFE
1633115
Traffic loss for 20 sec on VC with AE link-protection when rebooting backup FPC
Product-Group=junos
On EX/QFX series Virtual Chassis (VC) with Aggregated Ethernet (AE) link-protection configured, traffic loss could be seen for around 20 sec when the traffic is passing through backup link and backup FPC is rebooted.
1636422
IRB traffic drop might be observed when mac-persistence-timer expires
Product-Group=junos
On EX2300-VC Junos platforms with IRB (Integrated Routing and Bridging) configured with members across master and backup VC, after a power cycle or running master switchover once the configured mac-persistence-timer expires, it might result in complete drop of traffic at IRB interfaces.
PR Number
Synopsis
Category: EX2300/3400 platform
1627673
System time may not be updated after reboot on EX2300 platform
Product-Group=junos
System time may not be updated after reboot. Symptoms seen are: 1) After USB image installation, CLI is not working fine. 2) When DHCP persistence is configured with DHCP security and device reboots, the lease time values may show a high lease value post reboot.
1649338
The VC port might not be formed automatically after Zeroize
Product-Group=junos
On all EX3400 platforms, the Virtual-Chassis (VC) port might not be formed automatically after executing the command "request system zeroize".
PR Number
Synopsis
Category: QFX Multichassis Link Aggregrate
1639713
Traffic loss might be seen for the mac addresses learned on the ICL interface
Product-Group=junos
On all QFX platforms configured with Multichassis Link Aggregation Groups (MC-LAG), when the Interchassis Link (ICL) and mc-ae interfaces are flapped and BUM traffic is sent to mc-ae, some mac entries are learned on the ICL interface with flag DLR. This may cause traffic loss with certain traffic flow.
PR Number
Synopsis
Category: QFX PFE CoS
1631448
The uplink interface remains down for a longer duration due to VXLAN scaled configuration
Product-Group=junos
On all Junos QFX5K platforms, with Virtual Extensible LAN (VXLAN) and the filters applied on the VXLAN interface both having scaled configuration, if the device reboots, the uplink interface might remain down for a longer duration, resulting in service impact.
PR Number
Synopsis
Category: QFX PFE MPLS
1607169
MPLS VPN packets drop due to missing ARP entry on PE
Product-Group=junos
On QFX5K and EX4600 platforms, with Multiprotocol Label Switching (MPLS) over Integrated Routing and Bridging (IRB) interface on Provider Edge router (PE router), PE might not have any ARP resolution for MPLS forwarded Virtual Private Network (VPN) packets, resulting in reachability issue from remote Customer Edge (CE) or PE device.
PR Number
Synopsis
Category: SPC3 HW and SW Issues
1625579
The flowd process lost heartbeat for 45 consecutive seconds without alarm raised
Product-Group=junos
On SRX5K platforms with SPC3 card used, if the flowd process lost heartbeat for 45 consecutive seconds, all FPCs might reboot. However, the device marks the flowd process as down without alarm raised, the failover does not happen right away. Traffic loss might be seen due to this issue. Fix raises alarm at earlier stage. If cluster, there will be sooner failover.
1638975
The spcd process might crash during certain Linux based FPC card restart
Product-Group=junos
On MX and SRX platform with SPC3 card, when normal restart done for the FPC card sometimes PCI scan takes little bit longer time (>2500ms)than usual (less then 2000ms) which result in ukern schedule to mistakenly abort.
PR Number
Synopsis
Category: A15 specific issue
1617103
Execute RSI on SRX5K platform with IOC2 card installed may trigger data plane failover.
Product-Group=junos
Execute RSI on SRX5K platform with IOC2 card installed may trigger data plane failover.
PR Number
Synopsis
Category: a20a40 specific issue
1648850
SCB reset with Error : zfchip_scan line = 844 name = failed due to PIO errors
Product-Group=junos
On SRX5000 series with SCB4, in rare occasions a Major Alarm may be raised for the SCB momentarily, while there is not actually a hardware error present. In a chassis cluster this will trigger an unexpected failover. This issue would be applicable for MX series with SCBE3 and EX9200 series with EX9200-SF3 as well.
PR Number
Synopsis
Category: chassisd related issues for high-end SRX platforms
1570433
Missing snmp operation state method for SRX5800/MX960 platform
Product-Group=junos
Missing snmp operation state method for PDM (Power Distribution Module) on SRX5800/MX960 platform.
PR Number
Synopsis
Category: the SMGD redundancy plugin in SMGD
1631858
DHCP ALQ Syslog error bbesmgd[26939]: LIBSDB_RSMON_PS_TABLE_PTR_FAILURE: sdb_get_ps_interface_table_record:2076 failed to get the ps_table_header ptr
Product-Group=junos
DHCP ALQ Syslog error bbesmgd[26939]: LIBSDB_RSMON_PS_TABLE_PTR_FAILURE: sdb_get_ps_interface_table_record:2076 failed to get the ps_table_header ptr
PR Number
Synopsis
Category: Border Gateway Protocol
1600599
Kernel crash might be observed on platforms having BGP configured with family L2VPN
Product-Group=junos
On all Junos OS and Junos Evolved platforms running Border Gateway Protocol (BGP) with Layer 2 VPN (L2VPN) scenario, kernel crash might be observed.
1616595
The wrong BGP path might get selected even when a better or preferred route is available
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, in the scenario of "no-install" configured under the BGP family, the wrong BGP path might get selected as an active route even when a better or preferred route is available.
1643246
The BGP peer might stay down in shards after doing a rollback
Product-Group=junos
In the BGP scenario with rib-sharding enabled, when a BGP group has at least 2 peers if changing BGP prefix-limit maximum to a lower value than the received number of prefixes, and also changing BGP teardown idle-timeout to a lower value, then committing the configuration, after that executing 'rollback 1', the BGP peer might stay down in shards and routes might not be learned anymore.
1651211
Delay in BGP session establishment due to longer time for the listening task to be ready on all platforms running rpd
Product-Group=junos
On all platforms running rpd, the longer time for the listening task to be ready might have the longest time for the active task to be created, resulting in BGP session delay establishment.
PR Number
Synopsis
Category: BBE Remote Access Server
1650243
DHCP clients with static IP addresses binding might get disconnected
Product-Group=junos
On all Junos platforms having static IP address binding with MAC addresses under access configuration might get disconnected.
PR Number
Synopsis
Category: PTX Chassis Manager
1602292
Junos OS: PTX10002-60C System: After upgrading, configured firewall filters may be applied on incorrect interfaces (CVE-2021-31382)
Product-Group=junosvae
On PTX10002-60C System, after upgrading to an affected release, a Race Condition vulnerability between the chassis daemon (chassisd) and firewall process (dfwd) of Juniper Networks Junos OS, may update the devices interfaces with incorrect firewall filters. This issue only occurs when upgrading the device to an affected version of Junos OS. Refer to https://kb.juniper.net/
JSA11250
[juniper.net]
for more information.
PR Number
Synopsis
Category: Class of Service
1603909
802.1p rewrite policies might not have any effect if the rewrite is tied to CCC interfaces
Product-Group=junos
On the MX platform with trio-based line cards, the Class of Service rewrite policy might not work if the rewrite-rules are tied to CCC interfaces.
1650089
Interface burst size becomes low in pfe, when 'rate-limit-burst' knob is removed
Product-Group=junos
When rate-limit-burst knob is deleted, burst size will fall back to the previously calculated burst size with the tx rate. In the above mentioned trigger, as the rate-limit-burst configs was present when the system is coming up, the burst size from the tx rate is not at all computed and when the user try to delete the knob, it is fall back to this un-computed burst size(default to 0). This is the reason for very small burst size configured to the rate limit queues. To fix this issue, we allow the burst size to be calculated even when global ratelimit knob is present and store it and use the burst size calculated from the global rate limit knob.
PR Number
Synopsis
Category: QFX Control Plane VXLAN
1645591
The MAC address might not be visible in the EVPN/VXLAN environment
Product-Group=junos
On all QFX5K platforms with EVPN-VxLAN, the MAC address might get stuck in the pending list of VTEP (Virtual Tunnel End Points) and not get installed. This issue can lead to traffic loss or reachability issues.
PR Number
Synopsis
Category: dhcpd daemon
1613738
DHCP relay no-snoop might not work with DHCP local server in the same routing-instance
Product-Group=junos
When DHCP relay and local server are configured in the same routing-instance, with no-snoop enabled for DHCP relay but not enabled for local server, configuration change committed to the DHCP local server might break no-snoop functionality for the DHCP relay.
PR Number
Synopsis
Category: ACX IFL, IFF creation
1638581
L3 interface creation may fail on the ACX5448 and ACX710 platforms
Product-Group=junos
On the ACX5448 and ACX710 platforms, Layer 3 interface creation may fail due to a base MAC address programmed on the PFE. As a result, the simplest symptom is ping failure.
PR Number
Synopsis
Category: Covers Application classification workflows apart from custo
1632205
Signature package update may fail and the appid process may crash on SRX devices
Product-Group=junos
On SRX platforms, with a sig-pack update if any application is moved to DEPRICATED and if that application was part of any custom group, signature upgrade may fail. Due to this sometimes the appid process may crash.
1637181
The srxpfe process might crash while installing IDP sigpack with scaled traffic on SRX platforms
Product-Group=junos
On SRX platforms, while installing IDP(Intrusion Detection and Prevention) sigpack in a loop (installing private IDP sigpacks for particular versions alternatively) srxpfe process might crash.
PR Number
Synopsis
Category: EVO linux defects & enhancement requests
1601251
The alarm "Host 0 Active Disk Usage Exceeded" might be generated due to a large number of files under /var/log/journal which were held by the Eventd daemon
Product-Group=junos
On all Junos EVO platforms, the alarm "Host 0 Active Disk Usage Exceeded" might be generated due to a large number of files under /var/log/journal which were already marked as deleted in the "lsof" command, but they still are held by the Eventd daemon and disk space is not released. The RE will crash if the disk space of /var is exhausted.
PR Number
Synopsis
Category: EVPN Layer-2 Forwarding
1613201
IRB proxy-arp unrestricted might not work if EVPN/l2alm proxy is enabled
Product-Group=junos
On all Junos platforms, if Ethernet Virtual Private Network (EVPN)/Layer 2 Address Learning Manager (l2alm) proxy is enabled, Integrated Routing and Bridging (IRB) proxy-arp unrestricted might not work and impact the traffic.
1646010
IRB might not send out arp-reply if "no-arp-suppression" is configured
Product-Group=junos
On all Junos platforms, when "no-arp-suppression" is configured, the Layer 2 Address Learning Manager (L2ALM) will not respond to Address Resolution Protocol (ARP) request for Integrated Routing and Bridging (IRB) IP, and traffic to IRB will be lost.
PR Number
Synopsis
Category: Express PFE Services including JTI, TOE, HostPath, Jflow
1502645
The JFlow service might not work as expected and underreport the traffic
Product-Group=junos
On PTX Series routers and QFX Series switches running Junos OS, the JFlow service might not report the accurate throughput rate. This issue is seen when there is high sampled traffic rate with low flow cache hit ratio.
PR Number
Synopsis
Category: Host firmware issues
1519348
'show system firmware' command shows FPC is in INVALID STATE, but FPC is online
Product-Group=junos
FPC status is Invalid state under 'show system firmware'; but FPC is online under 'show chassis fpc' . This does not have any operational impact.
PR Number
Synopsis
Category: Integrated Routing & Bridging (IRB) module
1623262
Host generated IPv4 traffic sent over IPv6 next-hop with IRB interface might get dropped
Product-Group=junos
On all Junos platforms that support IRB(Integrated routing and bridging), when host originated IPv4 traffic is sent over IPv6 next-hop with IRB interface, the traffic might get dropped because of ether-type mismatch. This is because the ether-type field in L2 header is set to IPv6 (instead of IPv4) always due to the IPv6 next hop.
PR Number
Synopsis
Category: ISIS routing protocol
1610983
Junos OS and Junos OS Evolved: The rpd CPU spikes to 100% after a malformed ISIS TLV has been received (CVE-2022-22196)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker with an established ISIS adjacency to cause a Denial of Service (DoS); Please refer to https://kb.juniper.net/
JSA69509
[juniper.net]
for more information.
PR Number
Synopsis
Category: jdhcpd daemon
1620461
Circuit-id handled incorrectly with backup node for ALQ with Topology discover configured
Product-Group=junos
Topology Discovery using mapping between Local and Remote Incoming Interface or DHCP Packet Receiving interface on Remote ALQ (Active-leasequery)peer is used to host subscribers.The mapped Remote Incoming Interface is used inside Option-82 and this will conflict with the circuit-id of the incoming DHCP packet on DHCP RELAY-1 and circuit-id of option-82 is over written leading to lose of information.
1638050
Traffic loss may happen when there is a mismatch of subscribers between the master and backup relay
Product-Group=junos
On MX Series platforms, there may be a mismatch in subscriber information between the devices when the two devices are configured as Dynamic Host Configuration Protocol (DHCP) relay Active lease Query (ALQ) peers. This is a timing issue that occurs frequently when the lease timer is less than 300secs.
1644919
The jdhcpd core might be seen if TCP connection is restarted between the ALQ peers
Product-Group=junos
On all Junos MX platforms, jdhcpd crash might be seen due to Transmission Control Protocol (TCP) connection restart between a pair of Dynamic Host Configuration Protocol (DHCP) Active Lease Query (ALQ) peers. TCP connection restart might happen if there are route flaps, remote DHCP daemon restart, configuration update, etc. When this crash happens, jdhcpd daemon will restart, impacting DHCP subscriber services.
PR Number
Synopsis
Category: Flow Module
1601806
On SRX-Series devices using Unified Policies with IPv6, when attempting to reject certain dynamic-applications a flowd core could be generated
Product-Group=junos
On SRX-Series devices using Unified Policies with IPv6, when attempting to reject certain dynamic-applications a flowd core could be generated
PR Number
Synopsis
Category: High Availability/NSRP/VRRP
1594187
SRX chassis cluster redundancy group IP-monitoring might fail for redundancy group on secondary node
Product-Group=junos
On SRX5000 devices with multiple IOC cards where RETH LAG is used with chassis cluster IP-monitoring, chassis cluster redundancy group IP-monitoring might fail for the redundancy group on secondary node with reason "secondary arp entry not found".
1606724
Secondary node in a chassis cluster might go into reboot loop on SRX platforms
Product-Group=junos
On SRX1500/4100/4200, the secondary node in a chassis cluster might go into reboot loop after RG0 (redundancy-group 0) failover and secondary node is rebooted manually.
1632586
Annotate ip command might bring IP monitoring down and both nodes in MNHA (Multinode high-availability) mode goes into INELIGIBLE state
Product-Group=junos
On SRX5k series platforms with MNHA mode, if "monitor ip" is configured under routing-instance and when try to add annotate ip command both devices might move into INELIGIBLE state and complete traffic may drop during the issue.
PR Number
Synopsis
Category: Firewall Network Address Translation
1631815
New persistent NAT or normal source NAT sessions might fail due to noncleared aged out sessions
Product-Group=junos
On high end SRX platforms with Central Point (CP) architecture and Services Processing Units (SPUs), if configured with all these features "persistent NAT, hairpin, source NAT", persistent NAT sessions might get stuck and aged out Persistent NAT sessions might not get cleared, due to which the new persistent NAT or normal source NAT session might fail.
PR Number
Synopsis
Category: User Firewall related issues
1637548
Unable to connect to domain controller on installing Microsoft KB update
Product-Group=junos
On all SRX platforms, when the User Identification feature is used with Active Directory, after the Domain Controller server installs updates related to Microsoft's KB article
KB5004442
[juniper.net]
, SRX is no longer able to connect to it.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1636458
On all SRX products, when nat traversal is configured and working for an ipsec tunnel, there is a chance that the tunnel might stop processing packets after a rekey
Product-Group=junos
On all SRX products, when nat traversal is configured and working for an ipsec tunnel, there is a chance that the tunnel might stop processing packets after a rekey. This is happening only in 20.4R3 and later releases
PR Number
Synopsis
Category: jsscd daemon
1634371
In subscriber scenario, traffic drop might be seen when AE member link is removed
Product-Group=junos
On all Junos MX platforms configured with Dynamic Host Configuration Protocol (DHCP) subscribers over the Aggregated Ethernet (AE) interface and static subscribers, traffic loss might be seen for the static subscribers when the AE interface member link is removed. The static subscribers might be logged-out and logged-in automatically without any intervention.
PR Number
Synopsis
Category: Platform infra to support jvision
1615045
Export memory and temperature metrics for all existing components when it subscribes to telemetry sensor
Product-Group=junos
On all Junos platforms, the device may export memory, allocated power and temperature metrics for all existing components no matter if those leafs are supported on the components, such as exporting memory utilization for a PIC component or a transceiver, which could consume more resources on both the device and collector.
PR Number
Synopsis
Category: Layer 2 Control Module
1647000
Traffic loop might occur due to STP ports not created in new master RE after switchover due to reboot of master RE on EX4300, EX3400, and EX2300 platforms in Virtual Chassis (VC) scenario
Product-Group=junos
On EX4300, EX3400, and EX2300 platforms in Virtual Chassis (VC) scenario, when GRES and NSB are configured, after switchover due to master RE reboot, STP ports will not be created for interfaces part of old master RE that underwent reboot.
PR Number
Synopsis
Category: SW PRs for MPC10E Interfaces
1638410
PFE might get stuck after 100G/400G interface flaps
Product-Group=junos
On Junos platforms equipped with MPC10E/MPC11E/LC2301/MX10K-LC9600 line cards, when any 100G/400G interface with high priority class-of-service scheduler configuration flaps, it might result in series of error messages during high traffic flow. Eventually this would result in PFE-disable action, impacting the related traffic. However, the issue could be recovered after FPC reboot.
PR Number
Synopsis
Category: Multicast Routing
1638141
The multicast traffic might get dropped in the PFE
Product-Group=junos
On MX platforms, multicast traffic might not be forwarded over User Datagram Protocol (UDP) encapsulation (ud)tunnels if the Automatic Multicast Tunnelling (AMT) is enabled. The multicast traffic might leave the AMT interface, but might be dropped in the Packet Forwarding Engine (PFE).
PR Number
Synopsis
Category: MX Timing software
1442055
PTP packets dropped depending on multicast configuration
Product-Group=junos
PTP master and PTP slave port configuration only accepts PTP packets with multicast MAC address according to the port settings If forwardable multicast is configured, only PTP packets with forward-able MAC address is accepted, non-forwardable is dropped. link-local multicast is configured, only PTP packets with non-forwardable MAC address is accepted, forwardable is dropped.
1635877
Precision Time Protocol (PTP) packets having huge correction-field (CF) value coming out from MX platforms
Product-Group=junos
From MX platforms showing huge correction-field (CF) values on downstream devices in Precision Time Protocol (PTP) packets due to PTP failure on ports.
PR Number
Synopsis
Category: Track Mt Rainier SPMB platform software issues
1637950
SPMB might crash immediately after a switchover
Product-Group=junos
On dual RE PTX5K platforms equipped with SPMB type- PTX5K CB PMB, immediately after a switchover, if the new master SPMB (Switch Processor Mezzanine Board) finds any CB-to-SIB PCI (Control Board - Switch Interface Board Peripheral Component Interconnect) link down error, then the new master SPMB might crash causing a traffic blackhole for about 2-3 minutes while the SIBs (Switch Interface Board) are re-initialized.
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1639991
Recovery snapshot might fail if OAM volume is already mounted
Product-Group=junos
Recovery snapshot might fail with the error "The OAM volume is too small to store a snapshot" if OAM volume is already mounted.
PR Number
Synopsis
Category: Protocol Independant Multicast
1621358
Initial multicast register packets may get dropped
Product-Group=junos
On MX platforms, initial multicast register packets may get dropped, this may affect multicast services.
PR Number
Synopsis
Category: Issues related to PKI daemon
1573892
The process pkid may be observed during local certificate enrollment
Product-Group=junos
PKID core might occur during cert signature validation . This core is not very frequent and occurs due to memory corruption .
PR Number
Synopsis
Category: VRR (Virtual Route Reflector) for MX
1644806
Video console for vRR might not work after an upgrade
Product-Group=junos
Video console (ttyv0) for vRR might not work when upgraded from legacy Junos (using FreeBSD 6.X) to Junos with upgraded FreeeBSD (FreeBSD 10 and later). Serial console (ttyd0 or ttyu0) works without any issues. The fix is to enable both serial (comconsole) and video (vidconsole) consoles on vRR using upgraded FreeBSD.
PR Number
Synopsis
Category: QFX access control list
1619405
On Junos QFX-5110 platforms, dot1x based firewall policers may not work
Product-Group=junosvae
When dot1x based firewall policers are configured on QFX-5110 platforms, even though the configuration is accepted without any errors, it may not take effect.
1643457
ICMP TTL exceeded packets are not sent out of the switch
Product-Group=junos
On the QFX5000 line of switches, ICMP TTL exceeded message might not be sent back to the source when TTL expired in inner payload with GRE encapsulated received packet.
PR Number
Synopsis
Category: QFX L2 PFE
1602318
EVPN/VXLAN arp-suppression does not respond to ARP request when VLAN ID under interface (IFL) is different with VLAN ID under vlan (BD) in SP style.
Product-Group=junos
When VLAN ID under interface (IFL) is different with VLAN ID under vlan (BD), EVPN/VXLAN arp-suppression does not respond to ARP request. In the following example, when ARP packet with vlan 1918 is received on ae0, the proxy arp does not respond to the ARP request.
1633452
The FBF filtered VLAN traffic will not be passed properly to the forwarding routing instances over AE interfaces on QFX5K/EX4600/EX4650 platforms
Product-Group=junos
On QFX5K/EX4600/EX4650 platforms with IPv4 Filter-based forwarding (FBF) scenario, when IPv4 FBF is used with 802.1Q VLAN tag enabled layer-3 AE interfaces, the VLAN filtered configuration enabled by FBF filter will be stored in the VLAN filter processor (VFP) ternary content addressable memory (TCAM). But, in some cases of adding/deleting the configuration of the routing instances (then routing-instance) in FBF filter, the stale allocated entries in VFP TCAM might not be deleted from the system, the memory slices of VFP TCAM will be exhausted until it is run out. Finally, there are not enough memory slices left to store the VLAN filtered information for the forwarding routing instances, then the FBF filtered VLAN traffic will not be forwarded correctly since the FBF filters might not be programmed/processed on the system.
1637249
Configuring L2PT on a transit switch in a Q-in-Q environment breaks L2PT for other S-VLANs
Product-Group=junos
When L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch using SP style configuration, protocol convergence between end nodes might fail.
1638619
Targeted broadcast or WOL feature may not work on QFX 5k platforms
Product-Group=junos
On QFX platforms, Wake On LAN(WOL) feature stops working as the affected platforms erroneously process such packets. This might cause a blackhole in the network for such traffic.
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1637013
The PFE might crash while removing the port from a vlan
Product-Group=junos
On all Junos QFX5K platforms, when a port is part of multiple VXLANs, native-vlan, and user-defined VLAN, then the PFE might crash while removing the port from a user-defined VLAN.
1644152
Packets are dropped in ingress QFX5K with EVPN-LAG multihoming due to VP-LAG programming issue
Product-Group=junos
In multihoming EVPN-VXLAN environment with QFX5K series platforms (QFX5110/5120/5200/5210/5220) working as PE devices, packets to some destinations might be dropped in ingress PE, due to a VP-LAG (Virtual Port LAG) programming issue in PFE (Packet Forwarding Engine) in specific cases.
PR Number
Synopsis
Category: QFX VCCP
1639543
In a VCF scenario on QFX5100, VCP interfaces might flap or not come up at all and CRC errors might increase
Product-Group=junos
When VCF(Virtual Chassis Fabric) is set up on QFX5100 platforms, all the VCP(VC port) interfaces on a particular FPC(Flexible PIC Concentrator) might fail to join the VCF and CRC errors on those might increase. A subsequent reboot of the FPC may lead it to a "Not Present" state.
1651316
The VCP link might take longer time to come up during system reboot/PFE restart
Product-Group=junos
While performing reboot or Packet Forwarding Engine (PFE) restart, the links connected to Virtual Chassis Port (VCP) might take longer time to come up.
PR Number
Synopsis
Category: QFX10008/16 QFX10002 linecard, serdes and uboot
1632440
The interface might remain in the "UP/UP" state even the interface is admin disabled
Product-Group=junos
On the QFX10002/QFX10008/QFX10016 platforms, if reboot the FPC with interface admin disabled configuration, the interface might remain in the "UP/UP" state.
PR Number
Synopsis
Category: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1629735
"show interface extensive" might not show Local/Remote fault
Product-Group=junos
On QFX10K platforms, "show interface extensive" might not show if the fault is on the local side or on the remote side. There is no impact on traffic but it provides important information on where the fault is while debugging the link down issues.
PR Number
Synopsis
Category: QFX5100 Interface related issues
1638045
Delay might be observed for the interfaces to come up after reboot/transceiver replacement
Product-Group=junos
On QFX5100/EX4600 Junos platforms with 2-member VC(Virtual Chassis) setup, after the device reboot or QSFP+-40G-SR4 SFP (small form-factor pluggable) replacement, the VC port might remain down and takes longer time (approximately 5-20min) to come up even if the cable is connected properly to the interface.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Interface
1618891
One-time interface flap might be seen on the QFX5120 platform
Product-Group=junos
On QFX5120 platforms, the flap might be observed on the interface when applying the configuration unrelated to the respective interfaces.
PR Number
Synopsis
Category: KRT Queue issues within RPD
1613160
IGP routing updates may be delayed to program in Packet Forwarding Engine after interface flaps in a scaled BGP routes environment
Product-Group=junos
When a large number of BGP routing updates (e.g. 2M BGP IPv4 routes and 500K BGP IPv6 routes) triggered by interface flapping are pushed to the Packet Forwarding Engine at the same time, the IGP routing updates might be delayed to program in Packet Forwarding Engine. This might cause the sessions (e.g. LDP, RSVP) that rely on IGP to flap.
PR Number
Synopsis
Category: RPD policy options
1537306
The interface-routes rib-group policy does not work as expected in the VXLAN scenario
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms in the VXLAN scenario, the interface-routes rib-group user-defined policy does not work as expected. This issue will cause all the direct routes to leak from the exported route table to the imported route table.
1616167
The rpd process might get stuck at 100% when EVPN vrf-target is enabled and after any configuration change
Product-Group=junos
On all Junos and EVO platforms with EVPN (Ethernet VPN)/EVPN-VXLAN (Virtual Extensible LAN Protocol) implemented, any configuration (related/unrelated) change with the knobs 'vrf-target auto' and/or 'protocols evpn vni-options vni vrf-target ' being enabled might result in CPU spike and thus, rpd (routing protocol process) gets stuck at 100%. Traffic could be blackholed during the incident happening and could be back to normal once CPU usage is decremented after an interval.
1646603
Existing routing policies might change when global default route-filter walkup is changed
Product-Group=junos
When "set policy-options default route-filter walkup" configuration is changed( add/delete), existing routing-policies might change and all the existing "from" matching criteria will be removed from the routing-policies in the policy-db.
PR Number
Synopsis
Category: RPM and TWAMP
1634129
IP monitor may install default route with incorrect preference value when multiple IP monitoring is configured
Product-Group=junos
WOn all Junos Platforms, When RPM policies along with IP monitoring features are configured with different preferred route metrics in their rules, the traffic may get diverted through the wrong routes and route priority also may not apply to traffic.
PR Number
Synopsis
Category: SW PRs for SCBE3 fabric
1606296
Fabric error might be seen when MPC10E to MPC2/MPC3/MPC4/MPC5/MPC6 based FPC fabric traffic is congested
Product-Group=junos
On the MX240/480/960 system with both MPC10E and MPC2/MPC3/MPC4/MPC5/MPC6 based FPCs are installed, when MPC10E sends high traffic to MPC4E or other mentioned cards as the destination, the destination line card will not be able to cope up with MPC10E traffic flow.
1612957
The PFE/SIB/SCBE/FPCs might reboot due to the unexpected fabric errors shown up on MX240/480/960 platforms
Product-Group=junos
In MX240/480/960 platforms with SCBE3-MX and Enhanced midplane scenario, in some rare cases, if flooding huge traffic from MPC7/MPC8/MPC9 to MPC2E/MPC3E/MPC4E/MPC5E and flapping the interface on MPC2E/MPC3E/MPC4E/MPC5E, it will cause the unexpected request time errors on MPC7/MPC8/MPC9 since the MPC2E/MPC3E/MPC4E/MPC5E might not be able to handle such high volume of requests, it will cause PFE destinations to become unreachable even when the fabrics are online. Then PFE/SIB/SCBE/FPCs might reboot automatically while these accumulated fabric errors hit the fabric connectivity restoration conditions of the Fabric Healing process (FHP).
PR Number
Synopsis
Category: track Prs of Dynamic Address module running on SRX
1634881
Most of the Dynamic Address Entries might report 0 IPv4 entries
Product-Group=junos
When using security intelligence with SRX devices, the DAE (dynamic address entries) might show 0 IPv4 entries.
PR Number
Synopsis
Category: Stout cards (MPC7, MPC8, MPC9) microkernel issues
1539779
MX2K-MPC7/8/9 Default threshold for single-bit correctable ECC errors on Stout PMB DDR memory increased from 1 to 10 before declaring a minor alarm.
Product-Group=junos
The threshold for declaring a minor alarm was changed to 10 correctable ECC errors per 24 hours due to excessive RMA's.
PR Number
Synopsis
Category: MX10002 Platform SW - Platform s/w defects
1631010
,The FPC might crash after enabling MACsec
Product-Group=junos
On MX10003/MX2K with MPC8/9 line cards/PTX10001-20C/ACX6360 platforms, when MACsec (Media Access Control Security) is enabled on ports, FPC might crash with PFEMan (PFE Management) core, which would impact the related traffic. However, the issue could be self-recovered. The issue could be very rare.
PR Number
Synopsis
Category: SRX-1RU platfom related protocol, QoS, filtering features et
1630990
The srxpfe process might crash on SRX4600
Product-Group=junosvae
On SRX4600, a corruption in memory buffer (m_buf) might lead to srxpfe crash. Core files are generated and hardware monitoring failures might be observed when the process crashes.
1641517
Multiple J-UKERN core files might be generated during the sanity test
Product-Group=junos
On SRX4600 platform, the CPU may overrun while performing sanity check due to incompatibility issues between ukern scheduler and Linux driver which might lead to traffic loss.
PR Number
Synopsis
Category: ZT/YT pfe firewall software
1627986
FPC might restart with syslog filter action configured
Product-Group=junos
On EVO-based PTX platforms and all MX series platforms with MPC10+, configuring syslog as a filter action may cause the FPC to restart.
PR Number
Synopsis
Category: ZT/YT pfe l3 forwarding issues
1630408
Index of the link might get missed in the distribution table of PFEs after the flap
Product-Group=junos
On MX platforms with the scenario of BGP and BFD running, it might bring ECMP links up and down which might impact traffic distribution and keep one of the ECMP links unused.
PR Number
Synopsis
Category: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1637304
FPC crash might be seen on all MX platforms with BBE subscriber
Product-Group=junos
FPC might crash on all MX platforms with Broadband Edge (BBE) subscribers and the traffic flowing through the impacted FPC will get affected.
PR Number
Synopsis
Category: Trio pfe qos software
1619630
CoS custom classifier might not work on logical interface
Product-Group=junos
On all MX Series routers, in a rare case when the Packet Forwarding Engine receives the CoS classifier binding message before the logical interface family creation message, traffic might be classified with default classifier instead of custom classifier. Due to this, traffic might not be classified and mapped to the right queue, so the traffic might not get the correct CoS treatment.
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1640254
The input-vlan-map (pop) might not work on PS interfaces if the native VLAN is in use on the uplink interface
Product-Group=junos
On MX platforms input-vlan-map (pop) might not work on Pseudowire Subscriber (PS) interfaces if the native VLAN is configured on the uplink interface under the pseudowire headend termination (PWHT) scenario.
1643416
RE switchover may result in traffic loss in a certain scenario
Product-Group=junos
On all Junos platforms that support MPLS with GRES and NSR enabled, on RE switchover through CLI or system reboot, traffic loss may happen.
PR Number
Synopsis
Category: Trio pfe l3 forwarding issues
1618391
A device which is configured IP interface(ip-x/x/x) cannot sent out encapsulated IPv4-over-IPv6 packets to a remote device in case of transit packets
Product-Group=junos
Transit IPv4-over-IPv6 encapsulated packets cannot pass through using IP over IP interface(ip-x/x/x). This behavior has been seen in'transit' packets only.
PR Number
Synopsis
Category: Issues related to port-mirroring functionality on JUNOS
1634570
The fpc might crash on enabling port-mirroring
Product-Group=junos
On vMX/MX150 platforms, if port-mirroring is enabled with scaled flows (10k or more flows for immediate crash) and throughput scenario, the fpc crash might be observed. However, the issue could be restored after self-reboot.
PR Number
Synopsis
Category: Junos Automation, Commit/Op/Event and SLAX
1634027
Automation Infra may fail when the interface is pre-configured with flexible-vlan-tagging
Product-Group=junos
On all Junos and Evolved(EVO) platforms, when two interfaces are configured in the device under the same commit action and if one of the interfaces is pre-configured with flexible-vlan-tagging knob, it might impact the automation infra which includes commit, op, event, and JET scripts to fail.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1626721
Junos upgrade may fail with error "configuration database size limit exceeded"
Product-Group=junos
On MX/M/T/PTX platforms, image validation during Junos upgrade may generate "configuration database size limit exceeded" error log resulting in upgrade failure.
1641025
Unable to access configure exclusive mode after mgd process is killed
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, when copy-config, get-configuration, and discard-change RPCs run in two parallel NETCONF sessions and the database is also accessed in parallel by two NETCONF sessions, it leads to database corruption and mgd-related services might crash.
PR Number
Synopsis
Category: For GPRS security features on highend SRX series
1629672
The Create Bearer Request might be dropped on SRX platforms
Product-Group=junos
On SRX platforms, with GTP ALG (General Packet Radio Switching Tunnelling Protocol Application Layer Gateway) enabled, if Create session response is received with cause value among 17 to 19, Control Tunnel (C-Tunnel) might not get created and hence might drop further GTP messages.
PR Number
Synopsis
Category: Virtual Router Redundancy Protocol
1646480
The vrrpd core might be observed after interface state change
Product-Group=junos
On all Junos/EVO platforms with VRRP (Virtual Router Redundancy Protocol) implemented, if "startup-silent-period" is configured as 1sec and if state of any interfaces included in VRRP-group changes, it might result in vrrpd (VRRP daemon) crash, impacting the related services. However, configuring startup-silent-period between 2 and 2000sec and restarting vrrpd will help to restore the services.
PR Number
Synopsis
Category: usf ams related issues
1626027
Service set gets into INIT_PEND state after performing GRES on Junos platforms with SPC3 card
Product-Group=junos
On Junos platforms with SPC3 cards after performing graceful Routing Engine switchover (GRES) service set might get into INIT_PEND state.
20.4R3-S3 - List of Known issues
PR Number
Synopsis
Category: EX4300 PFE
1590037
HEAP malloc(0) is seen with base configurations
Product-Group=junos
On EX4300 Series platforms, if the ukern malloc function is invoked with size 0, the malloc call might have the potential for heap memory corruption in the caller code.
PR Number
Synopsis
Category: BBE Statistics daemon & libraries
1646846
The bbe-statsd daemon might crash after ISSU
Product-Group=junos
On all MX platforms with the subscriber management scenario, when ISSU happens from pre 18.4 to post 18.4, subscribers that re-logged in pre 18.4 are called preNG subscribers. For any of the preNG subscribers, if the ipv4/ipv6 family interface goes up/down, the issue is triggered.
PR Number
Synopsis
Category: PTX Chassis Manager
1517804
Junos OS: PTX1000 System: After upgrading, configured firewall filters may be applied on incorrect interfaces (CVE-2021-31382)
Product-Group=junosvae
On PTX1000 System, after upgrading to an affected release, a Race Condition vulnerability between the chassis daemon (chassisd) and firewall process (dfwd) of Juniper Networks Junos OS, may update the devices interfaces with incorrect firewall filters. This issue only occurs when upgrading the device to an affected version of Junos OS. Refer to https://kb.juniper.net/
JSA11250
[juniper.net]
for more information.
PR Number
Synopsis
Category: dhcpd daemon
1649638
The jdhcpd daemon might crash after Junos upgrade
Product-Group=junos
On all MX platforms, jdhcpd core dumps might observed when using legacy DHCP feature with pseudowire interface after the Junos upgrade.
PR Number
Synopsis
Category: VPWS, L2 CKT, EVPN-VPWS
1651727
ACX710 - l2circuit not working after deactivate/activate interface ae
Product-Group=junos
On ACX710 platform with versions prior to 21.2R1 after deactivate/activate a l2circuit using a aggregate interface, will trigger ACX_PFE_ERROR an unexpected behaviour could be seen. To recover, restart the pfe will clear the error status. Following logs will be seen after commit. ACX_PFE_ERROR: dnx_cntr_ifl_counter_clear: unable to find core for if ACX_PFE_ERROR: pfe_ifl_family_platform_detach: Failed to del logical if for ifl ae PFE: ifl-family(14) platform detach failed for ifd ae.* [generic failure]
PR Number
Synopsis
Category: EVPN control plane issues
1632364
The rpd may crash when moving an interface from VPLS to EVPN-VPWS instance
Product-Group=junos
On all Junos and Evo platforms, the rpd process crashes may be seen if an interface is moved from Virtual Private LAN Service (VPLS) instance to Ethernet VPN-Virtual Private Wire service (EVPN-VPWS) instance in one commit (deleting the former and creating the latter).
PR Number
Synopsis
Category: Express PFE MPLS Features
1590387
ISIS adjacency is not coming up through TCC l2circuit
Product-Group=junos
On ACX/PTX/QFX platforms(PTX10002/10003/10008/10016/QFX10002/10003/10008/10016/ACX6360) if protocols l2circuit and channel tcc is enabled for providing layer 2 transaction, ISIS connection through the layer 2 domain might get failed and traffic loss might be seen.
PR Number
Synopsis
Category: FIB telemetry daemon
1653942
When fib-streaming is enabled and two or more collectors are involved, fibtd core may be observed due to a timing sync issue
Product-Group=junos
On all junos and EVO platforms, when two or more collectors have subscribed to gAFT sensors on the device, fibtd daemon(forwarding information base processing daemon) observes a core and initial sync with the collectors are lost. This will cause the device to stop streaming telemetry data.
PR Number
Synopsis
Category: jdhcpd daemon
1617695
Enabling DHCP on Junos and Junos Evolved platforms might cause the router's file system storage to get filled up with log files
Product-Group=junos
On all Junos and Junos Evolved platforms configured as DHCP (Dynamic Host Configuration Protocol) server or relay-agent, the file system storage under /var directory might get filled up with DHCP ERA (Event Rate Analyzer) logs which is enabled by default and could result in other processes not having storage space to log details of router functionalities.
PR Number
Synopsis
Category: Flow Module
1607782
Junos OS: SRX Series: Denial of service vulnerability in flowd daemon upon receipt of a specific fragmented packet (CVE-2022-22185)
Product-Group=junos
A vulnerability in Juniper Networks Junos OS on SRX Series, allows a network-based unauthenticated attacker to cause a Denial of Service (DoS) by sending a specific fragmented packet to the device, resulting in a flowd process crash, which is responsible for packet forwarding. Continued receipt and processing of this specific packet will create a sustained DoS condition. Refer to https://kb.juniper.net/
JSA69493
[juniper.net]
for more information.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1608724
The process "iked" crash might be seen for IKEv1 based VPN tunnels
Product-Group=junos
The process "iked" might crash when IPsec negotiation is initiated via ike_peer_est_immediately_timeout due to IPsec SAs not being present but ike SA is present.
PR Number
Synopsis
Category: lacp protocol
1640240
Aggregated Ethernet interface remains up instead of down after deleting loopback and ae interface ip on neighbor while verifying BFD sessions on router
Product-Group=junos
Aggregated Ethernet child interfaces with LACP configurations are not timing out even if peer is gone and not sending any bridge protocol data unit (BPDU).
PR Number
Synopsis
Category: Issues related to Junos licensing infrastructure
1637822
Pyrite VC: Scale: MACsec: Traffic black hole with the second time master switchover for the pyrite VC
Product-Group=junos
In a fully formed VC, if back-to-back switchover happens (two times switchover), traffic loss is seen on MACSEC enabled interfaces
1640123
On QFX series base license is missing post upgrade to 20.3 and later releases
Product-Group=junos
On QFX systems with no license keys installed, upgrades to some releases after Junos 20.3 will result in non-compliance messages for some features.
PR Number
Synopsis
Category: Multiprotocol Label Switching
1654529
Mpls ping and traceroute are dropped when ptx5000 is acting as mpls egress router with default route with discard action
Product-Group=junos
MPLS LSP Ping and traceroute will not work and will get dropped on PTX5k acting as mpls egress router when there is a default route with discard action in its routing table
PR Number
Synopsis
Category: MX Timing software
1647901
When PTP with PHY-timestamping is enabled, significant clock frequency drift might be seen
Product-Group=junos
If timestamping the packet at the physical layer (also known as PHY timestamping) is enabled for Precision Time Protocol (PTP) in an l2circuit scenario, the transit PTP packets passing through the MPC2E-NG/MPC3E-NG/MPC5E/MIC-3D-20GE/10G built-in ports might be modified to have huge value in Correction Field of the PTP packet even though there is not PTP port configured on these line cards. If the transit PTP packets are used for synchronizing downstream node, the clock frequency drift could be seen.
PR Number
Synopsis
Category: OS IPv4/ARP/ICMPv4
1643110
JDI-PDT:ENT:CnB: ksyncd core seen when l2cpd and l2-learning daemons are restarted.
Product-Group=junos
When the l2cpd and l2-learning daemons are restarted manually or due to some other trigger, you might notice a live vmcore being generated on the master routing engine and a live vmcore and ksyncd core generated on the backup routing engine. These cores are intentionally generated for debugging when replication error occurs on the backup routing engine. You will not face any traffic impact due to this and the backup routing engine will recover automatically to a stable state and will function normally. The issue will not repeat without another trigger. This issue is inconsistent and might not occur in your setup. No workaround is known hence not shared.
PR Number
Synopsis
Category: Kernel MPLS / Tag / P2MP Infrastructure
1654798
RE kernel crash might be observed in the one-hop-LSP MPLS scenario with RE outbound traffic if 'routing-option resolution preserve-nexthop-hierarchy' is configured globally
Product-Group=junos
On all Junos platforms, if 'routing-option resolution preserve-nexthop-hierarchy' is configured globally, Routing-engine (RE) kernel crash might be observed in the one-hop-LSP Multiprotocol Label Switching (MPLS) scenario with RE outbound traffic.
PR Number
Synopsis
Category: TCP/UDP transport layer
1602442
On MX and PTX platforms vmcore on both the routing engines might be reported due to mbuf corruption
Product-Group=junos
On MX and PTX platforms, if BGP sessions are activated or deactivated in all the devices, a kernel crash might be seen.
PR Number
Synopsis
Category: OSPF routing protocol
1256434
LDP OSPFs are in the Synchronization state because the IGP interface is down with ldp-synchronization enabled for OSPF.
Product-Group=junos
LDP OSPF are in synchronization state because the IGP interface is down with ldp-synchronization enabled for OSPF. user@host> show ospf interface ae100.0 extensive Interface State Area DR ID BDR ID Nbrs ae100.0 PtToPt 0.0.0.0 0.0.0.0 0.0.0.0 1 Type: P2P, Address: 10.0.60.93, Mask: 255.255.255.252, MTU: 9100, Cost: 1050 Adj count: 1 Hello: 10, Dead: 40, ReXmit: 2, Not Stub Auth type: MD5, Active key ID: 1, Start time: 1970 Jan 1 00:00:00 UTC Protection type: None Topology default (ID 0) -> Cost: 1050 LDP sync state: in sync, for: 00:04:03, reason: IGP interface down config holdtime: infinity. As per the current analysis, the IGP interface goes down because although LDP notified OSPF that LDP synchronization was achieved, OSPF is not able to take note of the LDP synchronization notification, because the OSPF neighbor is not up yet.
PR Number
Synopsis
Category: Chassis mgmt for all QFX systems - chassis MIB, alarms, CLI
1603588
Chassisd generates "Cannot read hw.chassis.startup_time value: m" every 5 seconds on qfx10008 and qfx10016
Product-Group=junos
The "Cannot read hw.chassis.startup_time value:m" error log is generated every 5 seconds in the output by "show log chassisd" on qfx10008 and qfx10016. This is a cosmetic message. There is no impact to the system.
PR Number
Synopsis
Category: QFX L3 data-plane/forwarding
1648272
OSPF control packets may get dropped due to the "flow check" function in the interoperability case
Product-Group=junos
In EX4600, EX4650, and QFX5k switches, OSPF control packets may get dropped if a flow check is enabled (it is enabled by default) and the control packet is received twice with the same IPv4 IP ID in a second.
PR Number
Synopsis
Category: QFX5100 Interface related issues
1655853
QFX5100 / 20.4R3-S1.3 / Interface down after upgrade
Product-Group=junos
In a rare scenario, if the upgrade is being performed or ports are continuously flapped on QFX5K platforms, then interfaces might remain in downstate and need to reset in order to restore it.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Interface
1632620
You may see a slow response or timeout on the CLI or SNMP with accessing to sxe-0/0/0 on QFX5120-48T-6c.
Product-Group=junos
As some examples, SNMP walk stops working after some time or the output by "show interface" takes a pause immediately before displaying sxe-0/0/0. Internal interfaces sxe-0/0/0 and sxe-0/0/1 were created for PTP functionality. In which sxe-0/0/0 was dummy, this interface getting created in Junos side and not dcpfe side and caused these issue. There was no need to create dummy interface, the fix made sxe-0/0/0 to use for PTP functionality and removed sxe-0/0/1.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Platfom issues
1622580
LED indicator might be showing 'ON' status once QSFP is removed.
Product-Group=junos
LED indicator might show ?ON' status when QSFP enabled with channelized port is removed. This issue is seen on EX or QFX platforms like EX4600/4650, QFX5100/5110/5120/5210 and QFX10002-36Q/10002-72Q/QFX10008. This is a display issue. There is no service impact when this issue occurs
PR Number
Synopsis
Category: KRT Queue issues within RPD
1501817
Traffic might get dropped or discarded in the fast-reroute scenario
Product-Group=junos
In the platform using INH (indirect next hop, such as Unilist) as route next hop type for multiple paths scenario (such as BGP PIC or ECMP), the session fast-reroute might be enabled in Packet Forwarding Engines (PFEs). When the version-id of session-id of INH is above 256, the PFE might not respond to session update, which might cause the session-id permanently to be stuck with the weight of 65535 in PFE. It might lead PFE to have a different view of Unilist against load-balance selectors. Then either the BGP PIC or the ECMP-FRR might not work properly and traffic might be dropped or silently discarded.
1623170
BGP Flowspec may not shows counters for matching IPv6 firewall filter
Product-Group=junos
Under investigation - When installing an IPv6 firewall filter using BGP flowspec, matching traffic counters may show "0" values.
PR Number
Synopsis
Category: Remote Access VPN issues on SRX
1658833
On SRX Series devices, when using Juniper Secure Connect VPN client with Radius authentication for config-request, if the Radius response takes more than 15 seconds, it can lead to SRX declaring authentication failure.
Product-Group=junos
On SRX Series devices, when using Juniper Secure Connect VPN client with Radius authentication for config-request, if the Radius response takes more than 15 seconds, it can lead to SRX declaring authentication failure.
PR Number
Synopsis
Category: MX10003/MX204 MPC defects tracking
1609988
MX204: Interface flaps might be observed on certain ports
Product-Group=junos
On MX204 platforms, when QSA(QSFP-to-SFP) adapter is used with any SFP/SFP+(small form-factor pluggable) optics and if interface at PIC0 is configured with 1G speed, the corresponding interface might flaps with the "Ethernet PCS Block Not Locked/Locked Delta Event" error messages leading to traffic fluctuation passing through it.
PR Number
Synopsis
Category: MX10003/MX204 Timing/Sync-E issues tracking
1620703
[timing] [ptp] MX10k3 clock event set as clock abort with ptp hybrid 8275.1 config
Product-Group=junos
In PTP Hybrid mode of operation, sometime the SyncE FSM gets stuck in clock-abort state. Deactivate and activate the SyncE/PTP configurations move the FSM to good state.
PR Number
Synopsis
Category: Trio pfe qos software
1303489
Major alarm with logs: XQCHIP(46):XQ-chip[0]: DROP protect_regs error (status=0x8)
Product-Group=junos
In some scenarios with MPC, major alarm and following messages are generated. This major error is triggered due to parity error, and the impacted queue might drop packets. This might impact the forwarding, to recover MPC card need to be rebooted.
PR Number
Synopsis
Category: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1620564
SRX Accounting and auditd process might not work on secondary node
Product-Group=junos
On SRX platforms, auditd process might not work in any of the cluster nodes except protocol master, hence accounting logs (login/logout/command execution logs) might not be sent to the configured authentication authorization and accounting (AAA) TACACS/RADIUS servers. The auditd process is responsible for accounting and hence this feature might be impacted.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1590099
21.2 SecPDT: ISSU upgrade aborted from 21.1R1.11 to 21.2I-20210415.0.0138 on SRX5K HA device
Product-Group=junos
There is a limitation where image validation may cause an MGD core thus causing ISSU to abort. This is due to incompatible BSD releases. This PR has enabled the no-validate option so that this validation can be skipped for future releases. The workaround is to use no-compatibility-check.
1627323
Junos Fusion Satelite EX4300 upgrade fails from MX104 as AD with dual REs.
Product-Group=junos
Junos Fusion Satelite EX4300 upgrade is performed from MX104 as AD with dual REs. The upgrade may get stuck and not responding.
PR Number
Synopsis
Category: Virtual Router Redundancy Protocol
1639242
On Junos 20.3 and later release, the tracking routes of VRRP might become unknown after upgradation
Product-Group=junos
On all Junos 20.3 and later release, after upgradation the Virtual Router Redundancy Protocol (VRRP) state will not be correct and tracking routes of VRRP might show as unknown. The intended router might not be the VRRP master instead the peer router with less priority will be master. The route states are not correct because "route add" messages are not received at 'vrrpd' after activation of the interface. When the interface is activated an interface route is created for the address configured on the interface, 'vrrpd' will receive the addition and then update the track route state accordingly. When this is not being received at 'vrrpd' tracking routes might become unknown.
1652549
VRRP failover over 2 seconds may be observed
Product-Group=junos
In all Junos and Junos Evolved platforms, VRRP failover over 2 seconds may be observed in case of "fast-interval" configured less than 1 second and "failover-delay" is not configured.
Modification History
First publication 2022-04-14
20.4R3-S3: Software Release Notification for JUNOS Software Version 20.4R3-S3