Alert Type

PSN - Product Support Notification
Low/NotificationSRN
Low/NotificationSRN

Product Affected

ACX, PTX, QFX running Junos Evolved software

Alert Description

Junos Software Service Release version 20.4R3-S3-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 20.4R3-S3-EVO is now available.

20.4R3-S3-EVO - List of Fixed issues

PR NumberSynopsisCategory: Border Gateway Protocol
1600599Kernel crash might be observed on platforms having BGP configured with family L2VPN
Product-Group=evo
On all Junos OS and Junos Evolved platforms running Border Gateway Protocol (BGP) with Layer 2 VPN (L2VPN) scenario, kernel crash might be observed.
1616595The wrong BGP path might get selected even when a better or preferred route is available
Product-Group=evo
On all Junos OS and Junos OS Evolved devices, in the scenario of "no-install" configured under the BGP family, the wrong BGP path might get selected as an active route even when a better or preferred route is available.
1643246The BGP peer might stay down in shards after doing a rollback
Product-Group=evo
In the BGP scenario with rib-sharding enabled, when a BGP group has at least 2 peers if changing BGP prefix-limit maximum to a lower value than the received number of prefixes, and also changing BGP teardown idle-timeout to a lower value, then committing the configuration, after that executing 'rollback 1', the BGP peer might stay down in shards and routes might not be learned anymore.
PR NumberSynopsisCategory: PTX10003 Platform related issues
1654762[PTX10003] SSD DGM28-B56D81BCBQ || RE 0 SSD Primary minimum supported firmware version mismatch
Product-Group=evo
PTX10003 may show alarm "RE # SSD Primary minimum supported firmware version mismatch" if the routing-engine is installed with Innodisk SSD. root@lab> show system alarms no-forwarding 4 alarms currently active Alarm time Class Description 2022-01-03 15:24:35 +08 Minor RE 0 SSD Primary minimum supported firmware version mismatch 2022-01-03 15:24:36 +08 Minor RE 0 SSD Secondary minimum supported firmware version mismatch
PR NumberSynopsisCategory: Express BT PFE L3 Features
1635130Label stack might be corrupted after PFE restart
Product-Group=evo
On PTX10004/PTX10008/PTX100001 platforms, when MPLS Label is enabled with entropy and in a PHP role and PFE is restarted, the traffic stream which carries Transport Label + ELI Label + Entropy Label + VPN Label might be dropped on the egress PE router.
1651932An error might be seen when the member link on an AE bundle is deleted
Product-Group=evo
On all EVO PTX platforms, gRPC connection between the "evo-aftmand" process and the "cda" process maybe disconnect with the messages "[Error] CDA: exprGrpcAsyncApi: failed cq read", and "GOAWAY with error code ENHANCE_YOUR_CALM". When the disconnection happens, the Junos Evolved system can no longer retrieve status or programs forwarding ASICs. This is a catastrophic failure.
PR NumberSynopsisCategory: Express BX PFE L3 Features
1648156EVO adding config "hash-key family inet layer-4" disables inet Hash-key Protocol.
Product-Group=evo
EVO adding config "hash-key family inet layer-4" disables inet Hash-key Protocol.
PR NumberSynopsisCategory: Firewall related development
1639391PFE corruption might be seen due to the unsupported configuration of BGP flowspec
Product-Group=evo
On EVO platforms for the 20.4R3 release, the unsupported configuration of BGP flow spec "interface-group exclude" might lead to some errors and PFE corruption which did not permit filter bind.
1651411The firewalld process might crash when nested filters are used as input list
Product-Group=evo
On all Evo platforms, when nested firewall filters are applied as input-list and the sum of length of filter and term names exceed 124, firewalld process might crash and generate alarms. The filter might not get publsihed and might result in traffic being handled incorrectly.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1598217arpd and ndp daemon crash in scale setups
Product-Group=evo
In scaled scenarios (4k BDs, IRBs), with restart of l2ald and pfe daemons, arpd and ndp daemon crash is observed and it recover by itself and no functionality impact expected
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1601251The alarm "Host 0 Active Disk Usage Exceeded" might be generated due to a large number of files under /var/log/journal which were held by the Eventd daemon
Product-Group=evo
On all Junos EVO platforms, the alarm "Host 0 Active Disk Usage Exceeded" might be generated due to a large number of files under /var/log/journal which were already marked as deleted in the "lsof" command, but they still are held by the Eventd daemon and disk space is not released. The RE will crash if the disk space of /var is exhausted.
PR NumberSynopsisCategory: SNMP, mib2d issues
1635958False traffic spikes seen SNMP graphs when ifHCOutOctets or ifHCInOctets are used .
Product-Group=evo
False traffic spikes seen SNMP graphs when ifHCOutOctets or ifHCInOctets are used .
PR NumberSynopsisCategory: Express PFE CoS Features
1648760EVO snmpwalk do not return value for index 0
Product-Group=evo
EVO - snmpwalk over leaf of jnxCosQstatTable do not return value for index 0
PR NumberSynopsisCategory: PFE infra to support jvision for EVO
1640442[jvision] [jvisiontag] Verification of DB data collection is failing after executing the jvision decoder
Product-Group=evo
The system ID that is exported should be different for UDP and GRPC/GNMI. In the case of UDP, the system name should be appended with the local IP address.
PR NumberSynopsisCategory: Protocol Independant Multicast
1621358Initial multicast register packets may get dropped
Product-Group=evo
On MX platforms, initial multicast register packets may get dropped, this may affect multicast services.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1613160IGP routing updates may be delayed to program in Packet Forwarding Engine after interface flaps in a scaled BGP routes environment
Product-Group=evo
When a large number of BGP routing updates (e.g. 2M BGP IPv4 routes and 500K BGP IPv6 routes) triggered by interface flapping are pushed to the Packet Forwarding Engine at the same time, the IGP routing updates might be delayed to program in Packet Forwarding Engine. This might cause the sessions (e.g. LDP, RSVP) that rely on IGP to flap.
PR NumberSynopsisCategory: PTX10008 EVO Resiliency Improvement
1625305JNP10008-SF3, SIB-JNP10004 and JNP10016-SF3 memory errors handling improvement
Product-Group=evo
This software change improves the SIB3 shared memory error handling. The improved behavior is as follows. Once the software detects a SIB3 multi-bit uncorrectable ECC memory error event, the SIB3 will be offline immediately. The software will no longer attempt to recover the suspected SIB3 by rebooting it. The software does not provide an option to keep the SIB3 offline persistent across reboots via configuration. . (https://kb.juniper.net/TSB18257 [juniper.net])
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1627986FPC might restart with syslog filter action configured
Product-Group=evo
On EVO-based PTX platforms and all MX series platforms with MPC10+, configuring syslog as a filter action may cause the FPC to restart.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1641025Unable to access configure exclusive mode after mgd process is killed
Product-Group=evo
On all Junos OS and Junos OS Evolved devices, when copy-config, get-configuration, and discard-change RPCs run in two parallel NETCONF sessions and the database is also accessed in parallel by two NETCONF sessions, it leads to database corruption and mgd-related services might crash.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1646480The vrrpd core might be observed after interface state change
Product-Group=evo
On all Junos/EVO platforms with VRRP (Virtual Router Redundancy Protocol) implemented, if "startup-silent-period" is configured as 1sec and if state of any interfaces included in VRRP-group changes, it might result in vrrpd (VRRP daemon) crash, impacting the related services. However, configuring startup-silent-period between 2 and 2000sec and restarting vrrpd will help to restore the services.
PR NumberSynopsisCategory: Express PFE L2 fwding Features on ZX platforms
1643308The addition of new member to LAG might result in FPC crash
Product-Group=evo
On all PTX platforms running EVO with LAG (Link Aggregation Group) enabled, when a new member is added to an existing AE (Aggregate Ethernet) interface which has L2 (Layer 2) configuration and has MAC (Media Access Control) learning happening around the same time, it might cause memory corruption. This would result in FPC crash with core. The issue is rare.
 
 

20.4R3-S3-EVO - List of Known issues

PR NumberSynopsisCategory: EVO platform software
1597999PTX10001-36MR: Inconsistency in the platform name used in multiple places, version, snmp mibs, etc.
Product-Group=evo
"show snmp mib walk sysDescr" will show ptx10001-36mr
PR NumberSynopsisCategory: EVO Class of Services
1652342Show Class-of-service Interface may not show the Classifier bind info on an IFL with only Inet/Inet6 (without family mpls or not with any rewrite rules)
Product-Group=evo
Show Class-of-service Interface may not show the Classifier bind info on an IFL with only Inet/Inet6 (without family mpls or not with any rewrite rules). Show issue, Classifier will be still present and functional. No impact to the traffic
PR NumberSynopsisCategory: ISIS routing protocol
1610983Junos OS and Junos OS Evolved: The rpd CPU spikes to 100% after a malformed ISIS TLV has been received (CVE-2022-22196)
Product-Group=evo
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker with an established ISIS adjacency to cause a Denial of Service (DoS); Please refer to https://kb.juniper.net/JSA69509 [juniper.net] for more information.
PR NumberSynopsisCategory: PTX10K specific platform PRs
1654715Platform probe crash on image downgrade
Product-Group=evo
After an image downgrade the platform_probe utility crashes leading to brcm init failures. FPCs do not boot if this happens.