Alert Type

PSN - Product Support Notification
Low/NotificationSRN
Low/NotificationSRN

Product Affected

ACX, EX, NTX, PTX, QFX, SRX, vRR, vSRX

Alert Description

Junos Software Service Release version 21.3R2-S1 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.3R2-S1 is now available.

21.3R2-S1 - List of Fixed issues

PR NumberSynopsisCategory: EX2300/3400 platform
1627673System time may not be updated after reboot on EX2300 platform
Product-Group=junos
System time may not be updated after reboot. Symptoms seen are: 1) After USB image installation, CLI is not working fine. 2) When DHCP persistence is configured with DHCP security and device reboots, the lease time values may show a high lease value post reboot.
PR NumberSynopsisCategory: JUNOS kernel/ukernel changes for ACX
1629700ACX-710: when panic command issued, box is stuck and no vmcore file formed
Product-Group=junos
A problem in the rescue dumper kernel caused ACX-710 switches to hang after a panic, without saving a crash dump.
1640143JDI-REG-REGRESSIONS: PLATFORM :ACX710: "USB Installation is done, Please remove the USB media to continue" message not seen when USB image is used to recover the box
Product-Group=junos
USB installation requires a keypress before reboot to enable removal of USB device before system is restarted. Failing to remove USB stick will cause installation to start again. This fix prompts user for a keypress after installation and before reboot.
PR NumberSynopsisCategory: OpenSSH and related subsystems
1571179SHA-1 system login password format not accepted post upgrade
Product-Group=junos
If the Junos config contains a SHA-1 hashed password for a specific user, that user will be unable to login post upgrade. To identify any SHA-1 hashed passwords, run the following from the edit command line: # show | match \$sha1\$ Post upgrade do not use the SHA-1 password format. If the password format is set to SHA-1, the password will be hashed with SHA-512 instead.
PR NumberSynopsisCategory: ACX BFD specific issues
1635020IPv6 BFD session over AE interface might remain down on ACX5448/ACX710 platforms
Product-Group=junos
On ACX5448/ACX710 platforms, if IPv6 BFD is configured over an AE interface with more than one child member, the BFD session might stay down.
PR NumberSynopsisCategory: DNX L2 related features
1642187High priority packets might be dropped on ACX5448 platform
Product-Group=junos
On ACX5448 platform, if storm-control is configured on the interface, high priority broadcast/multicast/unknown unicast packets received on that interface might be dropped irrespective of the storm-control rate configured, thus impacting traffic.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1639991Recovery snapshot might fail if OAM volume is already mounted
Product-Group=junos
Recovery snapshot might fail with the error "The OAM volume is too small to store a snapshot" if OAM volume is already mounted.
PR NumberSynopsisCategory: VRR (Virtual Route Reflector) for MX
1644806Video console for vRR might not work after an upgrade
Product-Group=junos
Video console (ttyv0) for vRR might not work when upgraded from legacy Junos (using FreeBSD 6.X) to Junos with upgraded FreeeBSD (FreeBSD 10 and later). Serial console (ttyd0 or ttyu0) works without any issues. The fix is to enable both serial (comconsole) and video (vidconsole) consoles on vRR using upgraded FreeBSD.
PR NumberSynopsisCategory: QFX L2 PFE
1638619Targeted broadcast or WOL feature may not work on QFX 5k platforms
Product-Group=junos
On QFX platforms, Wake On LAN(WOL) feature stops working as the affected platforms erroneously process such packets. This might cause a blackhole in the network for such traffic.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1644152Packets are dropped in ingress QFX5K with EVPN-LAG multihoming due to VP-LAG programming issue
Product-Group=junos
In multihoming EVPN-VXLAN environment with QFX5K series platforms (QFX5110/5120/5200/5210/5220) working as PE devices, packets to some destinations might be dropped in ingress PE, due to a VP-LAG (Virtual Port LAG) programming issue in PFE (Packet Forwarding Engine) in specific cases.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Interface
1618891One-time interface flap might be seen on the QFX5120 platform
Product-Group=junos
On QFX5120 platforms, the flap might be observed on the interface when applying the configuration unrelated to the respective interfaces.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1630408Index of the link might get missed in the distribution table of PFEs after the flap
Product-Group=junos
On MX platforms with the scenario of BGP and BFD running, it might bring ECMP links up and down which might impact traffic distribution and keep one of the ECMP links unused.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1637304FPC crash might be seen on all MX platforms with BBE subscriber
Product-Group=junos
FPC might crash on all MX platforms with Broadband Edge (BBE) subscribers and the traffic flowing through the impacted FPC will get affected.
PR NumberSynopsisCategory: Issues related to port-mirroring functionality on JUNOS
1634570The fpc might crash on enabling port-mirroring
Product-Group=junos
On vMX/MX150 platforms, if port-mirroring is enabled with scaled flows (10k or more flows for immediate crash) and throughput scenario, the fpc crash might be observed. However, the issue could be restored after self-reboot.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1634027Automation Infra may fail when the interface is pre-configured with flexible-vlan-tagging
Product-Group=junos
On all Junos and Evolved(EVO) platforms, when two interfaces are configured in the device under the same commit action and if one of the interfaces is pre-configured with flexible-vlan-tagging knob, it might impact the automation infra which includes commit, op, event, and JET scripts to fail.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1641025Unable to access configure exclusive mode after mgd process is killed
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, when copy-config, get-configuration, and discard-change RPCs run in two parallel NETCONF sessions and the database is also accessed in parallel by two NETCONF sessions, it leads to database corruption and mgd-related services might crash.
 
 

21.3R2-S1 - List of Known issues

PR NumberSynopsisCategory: Firewall Network Address Translation
1636596In AA mode with NAT config, on RG failover, traffic getting dropped on SRX
Product-Group=junos
In AA mode with NAT config, on RG failover, traffic getting dropped on SRX
PR NumberSynopsisCategory: MPC11 ULC platform software related issues.
1597728MX2010, MX2020: MPC11E: ISSU is not supported for upgrade from 21.2 to 21.3 and 21.4 releases due to a flag day change
Product-Group=junos
MX2010, MX2020: MPC11E: ISSU is not supported for software upgrades from 21.2 to 21.3 and 21.4 releases due to a flag day change
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1642851Traffic drop due to incorrect memory allocation for the default route on MPC10E and MPC11E line cards
Product-Group=junos
On MPC10E & MPC11E line cards default route information might be overwritten/lost due to incorrect memory allocation.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1632411JDI-RCT:M/Mx: MAC addresses not learnt for some bridge domains
Product-Group=junos
Macs are not getting learned initially on a specific bridge domain. However, the macs are learned in that specific BD after some duration. This delay in mac learning will be fixed in the upcoming releases.
1640254The input-vlan-map (pop) might not work on PS interfaces if the native VLAN is in use on the uplink interface
Product-Group=junos
On MX platforms input-vlan-map (pop) might not work on Pseudowire Subscriber (PS) interfaces if the native VLAN is configured on the uplink interface under the pseudowire headend termination (PWHT) scenario.
 

Modification History

First publication 2022-04-20