Alert Type
PSN - Product Support Notification
Risk
Risk Description
Low/Notification
SRN
Impact
Impact Description
Low/Notification
SRN
Product Affected
ACX, EX, NTX, PTX, QFX, SRX, vRR, vSRX
Alert Description
Junos Software Service Release version 21.3R2-S1 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 21.3R2-S1 is now available.
21.3R2-S1 - List of Fixed issues
PR Number
Synopsis
Category: EX2300/3400 platform
1627673
System time may not be updated after reboot on EX2300 platform
Product-Group=junos
System time may not be updated after reboot. Symptoms seen are: 1) After USB image installation, CLI is not working fine. 2) When DHCP persistence is configured with DHCP security and device reboots, the lease time values may show a high lease value post reboot.
PR Number
Synopsis
Category: JUNOS kernel/ukernel changes for ACX
1629700
ACX-710: when panic command issued, box is stuck and no vmcore file formed
Product-Group=junos
A problem in the rescue dumper kernel caused ACX-710 switches to hang after a panic, without saving a crash dump.
1640143
JDI-REG-REGRESSIONS: PLATFORM :ACX710: "USB Installation is done, Please remove the USB media to continue" message not seen when USB image is used to recover the box
Product-Group=junos
USB installation requires a keypress before reboot to enable removal of USB device before system is restarted. Failing to remove USB stick will cause installation to start again. This fix prompts user for a keypress after installation and before reboot.
PR Number
Synopsis
Category: OpenSSH and related subsystems
1571179
SHA-1 system login password format not accepted post upgrade
Product-Group=junos
If the Junos config contains a SHA-1 hashed password for a specific user, that user will be unable to login post upgrade. To identify any SHA-1 hashed passwords, run the following from the edit command line: # show | match \$sha1\$ Post upgrade do not use the SHA-1 password format. If the password format is set to SHA-1, the password will be hashed with SHA-512 instead.
PR Number
Synopsis
Category: ACX BFD specific issues
1635020
IPv6 BFD session over AE interface might remain down on ACX5448/ACX710 platforms
Product-Group=junos
On ACX5448/ACX710 platforms, if IPv6 BFD is configured over an AE interface with more than one child member, the BFD session might stay down.
PR Number
Synopsis
Category: DNX L2 related features
1642187
High priority packets might be dropped on ACX5448 platform
Product-Group=junos
On ACX5448 platform, if storm-control is configured on the interface, high priority broadcast/multicast/unknown unicast packets received on that interface might be dropped irrespective of the storm-control rate configured, thus impacting traffic.
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1639991
Recovery snapshot might fail if OAM volume is already mounted
Product-Group=junos
Recovery snapshot might fail with the error "The OAM volume is too small to store a snapshot" if OAM volume is already mounted.
PR Number
Synopsis
Category: VRR (Virtual Route Reflector) for MX
1644806
Video console for vRR might not work after an upgrade
Product-Group=junos
Video console (ttyv0) for vRR might not work when upgraded from legacy Junos (using FreeBSD 6.X) to Junos with upgraded FreeeBSD (FreeBSD 10 and later). Serial console (ttyd0 or ttyu0) works without any issues. The fix is to enable both serial (comconsole) and video (vidconsole) consoles on vRR using upgraded FreeBSD.
PR Number
Synopsis
Category: QFX L2 PFE
1638619
Targeted broadcast or WOL feature may not work on QFX 5k platforms
Product-Group=junos
On QFX platforms, Wake On LAN(WOL) feature stops working as the affected platforms erroneously process such packets. This might cause a blackhole in the network for such traffic.
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1644152
Packets are dropped in ingress QFX5K with EVPN-LAG multihoming due to VP-LAG programming issue
Product-Group=junos
In multihoming EVPN-VXLAN environment with QFX5K series platforms (QFX5110/5120/5200/5210/5220) working as PE devices, packets to some destinations might be dropped in ingress PE, due to a VP-LAG (Virtual Port LAG) programming issue in PFE (Packet Forwarding Engine) in specific cases.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Interface
1618891
One-time interface flap might be seen on the QFX5120 platform
Product-Group=junos
On QFX5120 platforms, the flap might be observed on the interface when applying the configuration unrelated to the respective interfaces.
PR Number
Synopsis
Category: ZT/YT pfe l3 forwarding issues
1630408
Index of the link might get missed in the distribution table of PFEs after the flap
Product-Group=junos
On MX platforms with the scenario of BGP and BFD running, it might bring ECMP links up and down which might impact traffic distribution and keep one of the ECMP links unused.
PR Number
Synopsis
Category: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1637304
FPC crash might be seen on all MX platforms with BBE subscriber
Product-Group=junos
FPC might crash on all MX platforms with Broadband Edge (BBE) subscribers and the traffic flowing through the impacted FPC will get affected.
PR Number
Synopsis
Category: Issues related to port-mirroring functionality on JUNOS
1634570
The fpc might crash on enabling port-mirroring
Product-Group=junos
On vMX/MX150 platforms, if port-mirroring is enabled with scaled flows (10k or more flows for immediate crash) and throughput scenario, the fpc crash might be observed. However, the issue could be restored after self-reboot.
PR Number
Synopsis
Category: Junos Automation, Commit/Op/Event and SLAX
1634027
Automation Infra may fail when the interface is pre-configured with flexible-vlan-tagging
Product-Group=junos
On all Junos and Evolved(EVO) platforms, when two interfaces are configured in the device under the same commit action and if one of the interfaces is pre-configured with flexible-vlan-tagging knob, it might impact the automation infra which includes commit, op, event, and JET scripts to fail.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1641025
Unable to access configure exclusive mode after mgd process is killed
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, when copy-config, get-configuration, and discard-change RPCs run in two parallel NETCONF sessions and the database is also accessed in parallel by two NETCONF sessions, it leads to database corruption and mgd-related services might crash.
21.3R2-S1 - List of Known issues
PR Number
Synopsis
Category: Firewall Network Address Translation
1636596
In AA mode with NAT config, on RG failover, traffic getting dropped on SRX
Product-Group=junos
In AA mode with NAT config, on RG failover, traffic getting dropped on SRX
PR Number
Synopsis
Category: MPC11 ULC platform software related issues.
1597728
MX2010, MX2020: MPC11E: ISSU is not supported for upgrade from 21.2 to 21.3 and 21.4 releases due to a flag day change
Product-Group=junos
MX2010, MX2020: MPC11E: ISSU is not supported for software upgrades from 21.2 to 21.3 and 21.4 releases due to a flag day change
PR Number
Synopsis
Category: ZT/YT pfe l3 forwarding issues
1642851
Traffic drop due to incorrect memory allocation for the default route on MPC10E and MPC11E line cards
Product-Group=junos
On MPC10E & MPC11E line cards default route information might be overwritten/lost due to incorrect memory allocation.
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1632411
JDI-RCT:M/Mx: MAC addresses not learnt for some bridge domains
Product-Group=junos
Macs are not getting learned initially on a specific bridge domain. However, the macs are learned in that specific BD after some duration. This delay in mac learning will be fixed in the upcoming releases.
1640254
The input-vlan-map (pop) might not work on PS interfaces if the native VLAN is in use on the uplink interface
Product-Group=junos
On MX platforms input-vlan-map (pop) might not work on Pseudowire Subscriber (PS) interfaces if the native VLAN is configured on the uplink interface under the pseudowire headend termination (PWHT) scenario.
Modification History
First publication 2022-04-20
21.3R2-S1: Software Release Notification for JUNOS Software Version 21.3R2-S1