Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Alert Description

Junos Software Service Release version 21.1R3-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.1R3-S2 is now available.

21.1R3-S2 - List of Fixed issues

PR NumberSynopsisCategory: EX2300/3400 platform
1649338The VC port might not be formed automatically after Zeroize
Product-Group=junos
On all EX3400/EX4400 platforms, the Virtual-Chassis (VC) port might not be formed automatically after executing the command "request system zeroize".
PR NumberSynopsisCategory: QFX Multichassis Link Aggregrate
1639713Traffic loss might be seen for the mac addresses learned on the ICL interface
Product-Group=junos
On all QFX platforms configured with Multichassis Link Aggregation Groups (MC-LAG), when the Interchassis Link (ICL) and mc-ae interfaces are flapped and BUM traffic is sent to mc-ae, some mac entries are learned on the ICL interface with flag DLR. This may cause traffic loss with certain traffic flow.
PR NumberSynopsisCategory: A15 specific issue
1617103Execute RSI on SRX5K platform with IOC2 card installed may trigger data plane failover
Product-Group=junos
Execute RSI on SRX5K platform with IOC2 card installed may trigger data plane failover.
PR NumberSynopsisCategory: the SMGD redundancy plugin in SMGD
1631858Operations dependent on the SDB shared memory might be impacted
Product-Group=junos
On MX-Series devices, all the subscriber services dependent on the SDB Shared memory access by the daemon bbe-smgd might be impacted when no-advertise-route-on-backup knob is configured.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1646010IRB might not send out arp-reply if "no-arp-suppression" is configured
Product-Group=junos
On all Junos platforms, when "no-arp-suppression" is configured, the Layer 2 Address Learning Manager (L2ALM) will not respond to Address Resolution Protocol (ARP) request for Integrated Routing and Bridging (IRB) IP, and traffic to IRB will be lost.
PR NumberSynopsisCategory: ISIS routing protocol
1610983Junos OS and Junos OS Evolved: The rpd CPU spikes to 100% after a malformed ISIS TLV has been received (CVE-2022-22196)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker with an established ISIS adjacency to cause a Denial of Service (DoS); Please refer to https://kb.juniper.net/JSA69509 [juniper.net] for more information.
PR NumberSynopsisCategory: jdhcpd daemon
1644919The jdhcpd core might be seen if TCP connection is restarted between the ALQ peers
Product-Group=junos
On all Junos MX platforms, jdhcpd crash might be seen due to Transmission Control Protocol (TCP) connection restart between a pair of Dynamic Host Configuration Protocol (DHCP) Active Lease Query (ALQ) peers. TCP connection restart might happen if there are route flaps, remote DHCP daemon restart, configuration update, etc. When this crash happens, jdhcpd daemon will restart, impacting DHCP subscriber services.
1651768DHCP packets might not be sent to the clients when 'forward-only' is reconfigured under the routing instance
Product-Group=junos
On EX9200, and EX4300 platforms, when 'forward-only' is reconfigured under the routing instance, after deleting the configuration, Dynamic Host Configuration Protocol (DHCP) packets might not be sent to the clients.
PR NumberSynopsisCategory: Layer 2 Control Module
1647000Traffic loop might occur due to STP ports not created in new master RE after switchover due to reboot of master RE on EX4300, EX3400, and EX2300 platforms in Virtual Chassis (VC) scenario
Product-Group=junos
On EX4300, EX3400, and EX2300 platforms in Virtual Chassis (VC) scenario, when GRES and NSB are configured, after switchover due to master RE reboot, STP ports will not be created for interfaces part of old master RE that underwent reboot.
PR NumberSynopsisCategory: Multicast for L3VPNs
1647149The routing protocol process might stop working when de-activating and activating the same provider tunnel from one to another instance in a single commit
Product-Group=junos
On all platforms when de-activating and activating the same provider tunnel from one to another instance in a single commit, the routing protocol process might stop working.
PR NumberSynopsisCategory: MX Timing software
1631261A clksync crash might be observed and PTP might get stuck
Product-Group=junos
On MX platforms with PTP (Precision Time Protocol) hybrid mode enabled, if PTP client is configured in more than one interface and if those are in different FPC slots, disabling/deactivating/flapping of PTP configured interface or change in master clock interface parameters might result in clksync crash. Once this happens, PTP might get stuck at holdover state and thus affects clock functionality. However, deactivating and activating PTP configuration could restore the issue. The issue could be rare.
1631274PTP (Precision Time Protocol) might not lock on MX with MX-MPC2E-3D-P and MPC2E-3D LC
Product-Group=junos
On all MX platforms with MX-MPC2E-3D-P and MPC2E-3D LC linecards, traffic might be flapping between ACQUIRING and HOLDOVER states while PTP with telemetry NPU is enabled.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1639991Recovery snapshot might fail if OAM volume is already mounted
Product-Group=junos
Recovery snapshot might fail with the error "The OAM volume is too small to store a snapshot" if OAM volume is already mounted.
PR NumberSynopsisCategory: Kernel MPLS / Tag / P2MP Infrastructure
1654798RE kernel crash might be observed in the one-hop-LSP MPLS scenario with RE outbound traffic if 'routing-option resolution preserve-nexthop-hierarchy' is configured globally
Product-Group=junos
On all Junos platforms, if 'routing-option resolution preserve-nexthop-hierarchy' is configured globally, Routing-engine (RE) kernel crash might be observed in the one-hop-LSP Multiprotocol Label Switching (MPLS) scenario with RE outbound traffic.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1644480OAMD process is not enabled on MX10008/MX10016 causing GRE keepalives adjacency down
Product-Group=junosvae
OAMD process is not enabled to spawn by itself on mx10008/mx10016.
PR NumberSynopsisCategory: Issues related to PKI daemon
1655571Certificate-based VPN tunnel is not established
Product-Group=junos
On vSRX using a Cloud Hardware Security Module (HSM), certificate-based IPSec VPN tunnels are not getting established.
PR NumberSynopsisCategory: QFX L2 PFE
1626011The third 802.1Q tag might not be pushed onto the stack in the Q-in-Q tunneling
Product-Group=junos
In the Q-in-Q tunneling scenario, when dual VLAN tagged multicast packets (e.g., OSPF protocol packets) are received into a C-VLAN interface with an 'input-VLAN-map push' configuration, the VLAN swap operation will be done instead of the push operation. This issue could cause the packets to egress the S-VLAN interface with two VLAN tags instead of three VLAN tags
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1637013The PFE might crash while removing the port from a vlan
Product-Group=junos
On all Junos QFX5K platforms, when a port is part of multiple VXLANs, native-vlan, and user-defined VLAN, then the PFE might crash while removing the port from a user-defined VLAN.
1644152Packets are dropped in ingress QFX5K with EVPN-LAG multihoming due to VP-LAG programming issue
Product-Group=junos
In multihoming EVPN-VXLAN environment with QFX5K series platforms (QFX5110/5120/5200/5210/5220) working as PE devices, packets to some destinations might be dropped in ingress PE, due to a VP-LAG (Virtual Port LAG) programming issue in PFE (Packet Forwarding Engine) in specific cases.
PR NumberSynopsisCategory: QFX VCCP
1651316The VCP link might take longer time to come up during system reboot/PFE restart
Product-Group=junos
While performing reboot or Packet Forwarding Engine (PFE) restart, the links connected to Virtual Chassis Port (VCP) might take longer time to come up.
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1611354The ports might remain in downstate on QFX5K platforms
Product-Group=junosvae
In a rare scenario, if the upgrade is being performed or ports are continuously flapped on QFX5K platforms, then interfaces might remain in downstate and need to reset in order to restore it.
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1634533When a new member is added to the VCF, the backup FPC will restart
Product-Group=junos
Backup FPC lose their connection to the master when new members are added to the VCF (Virtual Chassis Fabric).
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1622580LED indicator might be showing 'ON' status once QSFP is removed.
Product-Group=junos
LED indicator might show ?ON' status when QSFP enabled with channelized port is removed. This issue is seen on EX or QFX platforms like EX4600/4650, QFX5100/5110/5120/5210 and QFX10002-36Q/10002-72Q/QFX10008. This is a display issue. There is no service impact when this issue occurs
PR NumberSynopsisCategory: RPM and TWAMP
1634129IP monitor may install default route with incorrect preference value when multiple IP monitoring is configured
Product-Group=junos
On all Junos platforms, when Real-Time Performance Monitoring (RPM) policies along with IP monitoring features are configured with different preferred route metrics in their rules, the traffic may get diverted through the wrong routes and route priority also may not apply to traffic.
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1655088BFD may flap when the hold down/up timer is configured
Product-Group=junos
It takes a while for traffic to resume after the Link fault has been resolved.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1606967'WO-0: OGE0 dequeue watermark hit' may seen with L2 related configuration and receiving jumbo-frame packets.
Product-Group=junos
'WO-0: OGE0 dequeue watermark hit' may seen withL2 related configuration and receiving jumbo-frame packets. It may happen under traffic packet size being more than about 3kbyte. Repeating this error will cause 'ZTCHIP_MQSS_CMERROR_WO_INT_REG_PKT_ERR' Major alarm. Since this Major alarm default reaction is 'disable-pfe' , in the worst case, related interfaces will be down and affected user traffic.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1630408Index of the link might get missed in the distribution table of PFEs after the flap
Product-Group=junos
On MX platforms with the scenario of BGP and BFD running, it might bring ECMP links up and down which might impact traffic distribution and keep one of the ECMP links unused.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1633825The linecard crash might be observed in a Subscriber scenario
Product-Group=junos
On all Junos platforms except with MPC10 or later, enabled with interface sensors on subscriber interfaces over an Aggregated Ethernet(AE), the linecard crash might be observed if a new member interface is added to an AE interface for an existing subscribers running the interface sensors or a line card is started. This is a timing issue.
PR NumberSynopsisCategory: Trio pfe qos software
1657203PFE might get disabled if a packet with a small size is transmitted out of the queue
Product-Group=junos
In MX platforms, if a packet with a small size (for example 64 Byte) is transmitted out of the queue then there might be PFE get disabled.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1643416RE switchover may result in traffic loss in a certain scenario
Product-Group=junos
On all Junos platforms that support MPLS with GRES and NSR enabled, on RE switchover through CLI or system reboot, traffic loss may happen.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1634027Automation Infra may fail when the interface is pre-configured with flexible-vlan-tagging
Product-Group=junos
On all Junos and Evolved(EVO) platforms, when two interfaces are configured in the device under the same commit action and if one of the interfaces is pre-configured with flexible-vlan-tagging knob, it might impact the automation infra which includes commit, op, event, and JET scripts to fail.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1641025Unable to access configure exclusive mode after mgd process is killed
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, when copy-config, get-configuration, and discard-change RPCs run in two parallel NETCONF sessions and the database is also accessed in parallel by two NETCONF sessions, it leads to database corruption and mgd-related services might crash.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1639242On Junos 20.3 and later release, the tracking routes of VRRP might become unknown after upgradation
Product-Group=junos
On all Junos 20.3 and later release, after upgradation the Virtual Router Redundancy Protocol (VRRP) state will not be correct and tracking routes of VRRP might show as unknown. The intended router might not be the VRRP master instead the peer router with less priority will be master. The route states are not correct because "route add" messages are not received at 'vrrpd' after activation of the interface. When the interface is activated an interface route is created for the address configured on the interface, 'vrrpd' will receive the addition and then update the track route state accordingly. When this is not being received at 'vrrpd' tracking routes might become unknown.
1646480The vrrpd core might be observed after interface state change
Product-Group=junos
On all Junos/EVO platforms with VRRP (Virtual Router Redundancy Protocol) implemented, if "startup-silent-period" is configured as 1sec and if state of any interfaces included in VRRP-group changes, it might result in vrrpd (VRRP daemon) crash, impacting the related services. However, configuring startup-silent-period between 2 and 2000sec and restarting vrrpd will help to restore the services.
PR NumberSynopsisCategory: Xellent Platform issues
1620527QSFP in slot et-0/0/0 may not come up after plug-in
Product-Group=junos
On QFX and PTX platforms using QSFP and optic toolkit, QSFP in slot et-0/0/0 might not come up after plug-in. When this happens, one/few ports may start showing i2c errors and eventually do not come up. Hence the link would not come up in that particular port.
PR NumberSynopsisCategory: usf ams related issues
1626027Service set gets into INIT_PEND state after performing GRES on Junos platforms with SPC3 card
Product-Group=junos
On Junos platforms with SPC3 cards after performing graceful Routing Engine switchover (GRES) service set might get into INIT_PEND state.
 
 

21.1R3-S2 - List of Known issues

PR NumberSynopsisCategory: Border Gateway Protocol
1655228An RPD process crash may be observed, when the received prefix count exceeds configured "prefix-limit"
Product-Group=junos
In all Junos and Junos Evolved platforms, when the BGP neighbor is brought down due to the received prefix count exceeding configured "prefix-limit" and if BGP disable and enable operation performed to bring the BGP session up then the "rpd" process crash might be observed.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1613201IRB proxy-arp unrestricted might not work if EVPN/l2alm proxy is enabled
Product-Group=junos
On all Junos platforms, if Ethernet Virtual Private Network (EVPN)/Layer 2 Address Learning Manager (l2alm) proxy is enabled, Integrated Routing and Bridging (IRB) proxy-arp unrestricted might not work and impact the traffic.
PR NumberSynopsisCategory: FIB telemetry daemon
1653942When fib-streaming is enabled and two or more collectors are involved, fibtd core may be observed due to a timing sync issue
Product-Group=junos
On all junos and EVO platforms, when two or more collectors have subscribed to gAFT sensors on the device, fibtd daemon(forwarding information base processing daemon) observes a core and initial sync with the collectors are lost. This will cause the device to stop streaming telemetry data.
PR NumberSynopsisCategory: IDP policy
1634305PFE core dump failover or traffic blackhole observed on all Junpos platforms
Product-Group=junos
On all Junos platforms, the core dump was seen after installing a private IDP security package multiple times in a scaled environment.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1634908LACP interface might go down when a sub-interface configuration is added and committed to the AE interface
Product-Group=junos
On all MX150 platforms, when an Aggregate Ethernet (AE) interface is configured with LACP and adding a sub-interface configuration under the AE interface causes the LACP down leads to traffic loss.
PR NumberSynopsisCategory: ISIS routing protocol
1559005[protocols_vpn] [l3vpn] vmx : clns ping through l3vpn is failing
Product-Group=junos
Release note is not required for this feature
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1609630BFD over GRE tunnel interface stuck in "init" state with GRES enabled
Product-Group=junos
On all JUNOS platforms, when disabling the physical interface where GRE tunnels is established and performing a GRES (Graceful Routing Engine Switchover). After GRES, enabling the physical interface will cause BFD to become stuck in init state.
PR NumberSynopsisCategory: Chassis mgmt for all QFX systems - chassis MIB, alarms, CLI
1584902The the QFX5000 and QFX10000 lines of switches might hang for some time after reboot
Product-Group=junosvae
On the QFX5000 and QFX10000 lines of switches, during reboot in certain instances the device might get into a state where the Junos virtual machine hangs until the NMI is triggered and reboots fully. The system recovers after approximately 30 minutes.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Interface
1654459LACP sent IN SYNC to server facing interface when core-isolation is in effect
Product-Group=junos
In all Junos and Junos Evolved platforms, in the case of "core-isolation" is in effect, and if AE (AE with LACP) links between leaf and CE device flaps then, these flaps may enable LACP links during "core-isolation". This may cause CE to forward traffic to the node where the core is down.
PR NumberSynopsisCategory: Resource Reservation Protocol
1637645The rpd memory leak may be observed in a subscriber management environment with RSVP
Product-Group=junos
On MX platforms, in subscriber management environment with Psuedowire Headend Termination (PWHT) configured, when the subscribers are added and deleted, the memory leak in rpd process may be observed. The creation and deletion of demux interfaces will cause this issue with Resource Reservation Setup Protocol (RSVP) configured. The system will run out of memory eventually, causing the rpd crash when the new memory is requested.
PR NumberSynopsisCategory: PTX10K specific platform PRs
1585587During RE switchover if a SIB is removed, SIB might still be visible
Product-Group=junos
During RE switchover if a SIB is removed, switchover might cause the SIB to be still visible.
PR NumberSynopsisCategory: SW PRs for SCBE3 fabric
1625820Fabric request timeouts and fabric healing occur
Product-Group=junos
On MX platforms, the MPC10E-10C-MRATE went offline/online due to FO (Fabric out) timeouts.
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1658833Radius responses that take longer than 15 seconds can cause SRX to declare authentication failure
Product-Group=junos
On SRX Series devices, when using Juniper Secure Connect VPN client with Radius authentication for config-request, if the Radius response takes more than 15 seconds, it can lead to SRX declaring authentication failure.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1650854The IPv4 traffic drop might be observed in EVPN scenario
Product-Group=junos
In EVPN/MPLS setup with irb, when transit Layer 3 traffic hits IRB. The reported problem is happening due to a bug in ipv4_arp_ipv6_nd_snooping instruction. This would fetch a value from an uninitialised LMEM location which can cause out of bound access in entry_layer2_ipv4_arp_ipv6_nd instruction. Based on the value in that uninitialised location, the out of bound access may or may not happen. That is why this issue is seen intermittently. This is seen for IPv4 packets as the memory location would be initialised only in case of IPv6. Feb 23 12:54:01.281 chloe-re0 afeb0 LUCHIP(0) PPE_15 Errors lmem addr error Feb 23 12:54:01.356 chloe-re0 afeb0 PPE Thread Timeout Trap: Count 2, PC 614a, 0x614a: wan_out_deferred_block_alloc_post_processing 0x614a: wan_out_sys_stats_check 0x614a: skip_accurate_stat Feb 23 12:54:01.570 chloe-re0 afeb0 PPE PPE HW Fault Trap: Count 2678, PC 69ea, 0x69ea: entry_layer2_ipv4_arp_ipv6_nd 0x69ea: ipv4_arp_ipv6_nd_process_check_arp_nd_pkt Feb 23 12:54:02.177 chloe-re0 afeb0 LUCHIP(0) PPE_2 Errors lmem addr error
PR NumberSynopsisCategory: DDL/ODL infrastructure and CLI/Op commands
1658154"request system scripts refresh-from op.. " output is not working as expected
Product-Group=junos
The warning of the command "request system scripts refresh ..." is inconsistent.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
159009921.2 SecPDT: ISSU upgrade aborted from 21.1R1.11 to 21.2I-20210415.0.0138 on SRX5K HA device
Product-Group=junos
There is a limitation where image validation may cause an MGD core thus causing ISSU to abort. This is due to incompatible BSD releases. This PR has enabled the no-validate option so that this validation can be skipped for future releases. The workaround is to use no-compatibility-check.
1627323Junos Fusion Satellite EX4300 upgrade fails from MX104
Product-Group=junos
Junos Fusion Satelite EX4300 upgrade is performed from MX104 as AD with dual REs. The upgrade may get stuck and not responding.
PR NumberSynopsisCategory: VMHOST platforms software
1613229The "FPC 0 Major Errors" alarm might be seen on PTX10002-60C/QFX10002-60C due to a rare timing issue
Product-Group=junosvae
On PTX10002-60C/QFX10002-60C, after the system is rebooted, the "FPC 0 Major Errors" alarm might be seen due to a rare timing issue. The issue could cause the host path traffic to get dropped. It is a rare issue and does not always happen during reboot. Please try to perform "request vmhost reboot" for recovery.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1658966VRRP operations may flap when configuration changes are committed under unrelated VRRP groups present on the same physical interface
Product-Group=junos
On all Junos and Junos OS Evolved platforms, the addition or removal of VRRP group might cause other VRRP groups under the same physical interface to flap. The bug causes the already existing configuration of all VRRP groups under the same physical interfaces(along with the ones where no configuration change is being committed) to be treated as a new configuration and eventually deletes it before re-adding. This causes all VRRP sessions to flap and virtual-router uptime to be reset.

 

Modification History

First publication 2022-05-24