Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Alert Description
Note: EVPN/VXLAN
- Due to a software defect in EVPN/VXLAN, we do not recommend deploying 19.4R3-S7, or 19.4R3-S8 in the EVPN/VXLAN environment
Junos Software Service Release version 19.4R3-S8 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 19.4R3-S8 is now available.
19.4R3-S8 - List of Fixed issues
PR Number
Synopsis
Category: EX4300 PFE
1622404
VSTP might not work in Q in Q environment
Product-Group=junos
On EX4300 platforms, when L2PT(layer 2 protocol tunneling) and VSTP are enabled using SP(service provider) style configuration, VSTP might not work.
1630616
The ARP resolution may get failed on VRRP enabled interface
Product-Group=junos
On EX4300, ARP resolution against virtual IP on VRRP enabled interface may get fail with "no-arp-trap" is configured due to which service may get affected.
1630935
Application of firewall filters might break connectivity towards the hosts on EX4300
Product-Group=junos
On EX4300 platforms except EX4300-MP/EX4300-48MP, once input/output firewall filters are applied to the interfaces under family ethernet-switching, it might result in disrupting the connectivity towards few hosts connected to the device and thus impacts the related traffic.
PR Number
Synopsis
Category: EX4300 Virtual Chassis
1624850
Delay might be observed while establishing the virtual-chassis post upgrading or rebooting device
Product-Group=junos
On all EX4300 platforms except EX4300-48MP with virtual chassis ports using the DAC cables, there might be a delay in establishing the virtual-chassis post upgrading or rebooting the device.
PR Number
Synopsis
Category: EX2300/3400 PFE
1564941
The DHCP client might not obtain IP address when dhcp-security is configured
Product-Group=junos
On EX2300 platforms, if enterprise Style (EP) and service provider (SP) style configurations are mixed on a trunk interface, the DHCP client under SP style configuration might not obtain IP address when dhcp-security is enabled on one of the trunk VLANs.
1627857
Packet drop might be observed when L2PT is configured on transit device
Product-Group=junos
On ACX/EX/QFX Junos platforms with Q-in-Q setup in SP(Service Provider) style configuration, when L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch, mac rewritten packets might get dropped on the transit device due to which protocol (for example, STP) convergence fails between the end nodes and thus L2PT breakage could be observed for service-VLANs included in the environment.
1630553
The Error nessage "BCM_PVLAN_UTILS: ERR: pfe_bcm_pvlan_utils_get_sec_bd(),789: Failed to get Secondary-bd" is logged when received a dhcp packet on Private vlan.
Product-Group=junos
The Error message "BCM_PVLAN_UTILS: ERR: pfe_bcm_pvlan_utils_get_sec_bd(), 789: Failed to get Secondary-bd" is logged when received a dhcp packet on Private vlan in the switch which enabled Dynamic Host Configuration Protocol (DHCP) snooping. The error messages can be ignored safely.
1632643
Unicast ARP packets with the first four bytes of its destination MAC matching to system macs of a transit system gets trapped by the system
Product-Group=junos
On EX2300 platforms as transit switches, when no-arp-trap is enabled, if the ARP packets are unicast of which the destination MAC has upper four bytes matching to the system MAC, the ARP packets are not forwarded but trapped.
1633115
Traffic loss for 20 sec on VC with AE link-protection when rebooting backup FPC
Product-Group=junos
On EX/QFX series Virtual Chassis (VC) with Aggregated Ethernet (AE) link-protection configured, traffic loss could be seen for around 20 sec when the traffic is passing through backup link and backup FPC is rebooted.
PR Number
Synopsis
Category: EX2300/3400 platform
1627673
System time may not be updated after reboot on EX2300 platform
Product-Group=junos
System time may not be updated after reboot. Symptoms seen are: 1) After USB image installation, CLI is not working fine. 2) When DHCP persistence is configured with DHCP security and device reboots, the lease time values may show a high lease value post reboot.
PR Number
Synopsis
Category: QFX Multichassis Link Aggregrate
1639713
Traffic loss might be seen for the mac addresses learned on the ICL interface
Product-Group=junos
On all QFX platforms configured with Multichassis Link Aggregation Groups (MC-LAG), when the Interchassis Link (ICL) and mc-ae interfaces are flapped and BUM traffic is sent to mc-ae, some mac entries are learned on the ICL interface with flag DLR. This may cause traffic loss with certain traffic flow.
PR Number
Synopsis
Category: SPC3 HW and SW Issues
1638975
The spcd process might crash during certain Linux based FPC card restart
Product-Group=junos
On MX and SRX platform with SPC3 card, when normal restart done for the FPC card sometimes PCI scan takes little bit longer time (>2500ms)than usual (less then 2000ms) which result in ukern schedule to mistakenly abort.
PR Number
Synopsis
Category: CoS support on ACX
1633427
The storm-control rate-limit might not work with VPLS policer under IFL
Product-Group=junos
On ACX5448 platforms, when storm-control rate-limit is configured on the physical interface along with the VPLS(Virtual Private LAN Service) filter and policer configured under attached IFL(logical interface), storm-control rate-limit might not get applied to the ingress traffic and hence entire traffic might get forwarded further unexpectedly.
PR Number
Synopsis
Category: MPC Fusion SW
1463859
The MPC2E-NG or MPC3E-NG card with specific MIC might crash after a high rate of interface flaps.
Product-Group=junos
If any MIC of type MIC-3D-2XGE-XFP, MIC-3D-4XGE-XFP, MIC-3D-20GE-SFP-E, MIC-3D-20GE-SFP-EH, or MIC-MACSEC-20GE is installed in an MPC2E-NG or MPC3E-NG card, the microkernel (uKern) might hog the CPU on Packet Forwarding Engine when there is a high rate of interface flaps (~30/40 flaps per second). This eventually causes the MPC2E-NG/MPC3E-NG card to crash and generate an NGMPC core file (or dump file). Normally the excessive interface flapping won't happen frequently. This issue might be caused by the external environment. The fix for this issue causes a regression as documented in
TSB17782
[juniper.net]
and PR1508794 which affects interfaces with "WAN-PHY" framing.
PR Number
Synopsis
Category: A15 specific issue
1617103
Execute RSI on SRX5K platform with IOC2 card installed may trigger data plane failover
Product-Group=junos
Execute RSI on SRX5K platform with IOC2 card installed may trigger data plane failover.
PR Number
Synopsis
Category: a20a40 specific issue
1648850
SCB reset with Error : zfchip_scan line = 844 name = failed due to PIO errors
Product-Group=junos
On SRX5000 series with SCB4, in rare occasions a Major Alarm may be raised for the SCB momentarily, while there is not actually a hardware error present. In a chassis cluster this will trigger an unexpected failover. This issue would be applicable for MX series with SCBE3 and EX9200 series with EX9200-SF3 as well.
PR Number
Synopsis
Category: BBE interface related issues
1629910
The egress traffic on non-targeted iflset of subscribers might not be forwarded correctly over targeted AE interface
Product-Group=junos
In subscriber traffic across links over an aggregated Ethernet (AE) interface scenario, the egress data of subscriber applications (e.g. PPPoE/ L2TP/ MPLS/DHCP) attached logical interface sets (iflset, e.g. pppoe-iflset/demux-iflset) are configured at Layer 3 to handle many sets of subscriber queues respectively over one targeted-distribution enabled Layer 2 ifl of AE interface (e.g. ae-x/y/z.1). In some rare cases, if the member link/FPC of AE are flapped, the underlying ifd of the AE bundle might not be attached to iflset again. Then the egress traffic forwarding function of subscribers over the AE interface (e.g. traffic redistribution/CoS scheduling resources) might be impacted.
1633392
The bbe-smgd process might crash after removing and adding a child link from AE interface
Product-Group=junos
On MX platforms enabled with dynamic-profiles for subscribers and the subscribers are configured over AE [Aggregate Ethernet] interface with targeted-distribution. When the child links of the AE interface are removed and then added, it could lead to bbe-smgd crash in the backup RE. This in-turn could affect the control plane subscriber services when the primary RE fails during such event.
PR Number
Synopsis
Category: BBE Statistics daemon & libraries
1646846
The bbe-statsd daemon might crash after ISSU
Product-Group=junos
On all MX platforms with the subscriber management scenario, when ISSU happens from pre 18.4 to post 18.4, subscribers that re-logged in pre 18.4 are called preNG subscribers. For any of the preNG subscribers, if the ipv4/ipv6 family interface goes up/down, the issue is triggered.
PR Number
Synopsis
Category: Border Gateway Protocol
1600599
Kernel crash might be observed on platforms having BGP configured with family L2VPN
Product-Group=junos
On all Junos OS and Junos Evolved platforms running Border Gateway Protocol (BGP) with Layer 2 VPN (L2VPN) scenario, kernel crash might be observed.
PR Number
Synopsis
Category: Class of Service
1639518
Queue flush failure logs are reported for 100G interfaces of MPC10E/MPC11E cards that are part of AE bundles post flapping of other member links.
Product-Group=junos
Queue flush failure logs are reported for 100G interfaces of MPC10E/MPC11E cards that are part of AE bundles post flapping of other member links.
1650089
Interface burst size becomes low in pfe, when 'rate-limit-burst' knob is removed
Product-Group=junos
When rate-limit-burst knob is deleted, burst size will fall back to the previously calculated burst size with the tx rate. In the above mentioned trigger, as the rate-limit-burst configs was present when the system is coming up, the burst size from the tx rate is not at all computed and when the user try to delete the knob, it is fall back to this un-computed burst size(default to 0). This is the reason for very small burst size configured to the rate limit queues. To fix this issue, we allow the burst size to be calculated even when global ratelimit knob is present and store it and use the burst size calculated from the global rate limit knob.
PR Number
Synopsis
Category: Device Configuration Daemon
1583702
Members mac might be different from parent reth0 interface, resulting loss of traffic
Product-Group=junos
After configuring mac address in reth interface, the reth won't work properly.
PR Number
Synopsis
Category: CoS support on DNX
1623922
[RIO/acx5448] COS - EXP rewrite is not working in l3vpn scenario when mf filter is configured.
Product-Group=junos
In DSCP classifier remark internal priority is populated with forwarding class and color. This remark internal priority is used as key for EXP rewrite. When applying mf filter, it modifies the remark_int_priority only with forwarding class. As the remark_int_priority modified by the mf filter, there will not be any matching rewrite rule.
PR Number
Synopsis
Category: Covers Application classification workflows apart from custo
1637181
The srxpfe process might crash while installing IDP sigpack with scaled traffic on SRX platforms
Product-Group=junos
On SRX platforms, while installing IDP(Intrusion Detection and Prevention) sigpack in a loop (installing private IDP sigpacks for particular versions alternatively) srxpfe process might crash.
1638588
AppID installation failure on the secondary HA node in case of failover
Product-Group=junos
On SRX platforms, installation of Application Identification service failed on the secondary HA node in case of failover due to checksum validation.
PR Number
Synopsis
Category: eventd, syslog infra issues
1611885
Master-eventd process might go down when syslog configuration is misconfigured
Product-Group=junos
On all Junos Operating System Evolved(EVO) based platforms with misconfigured syslog, master-eventd process might go down.
PR Number
Synopsis
Category: EVPN control plane issues
1632364
The rpd may crash when moving an interface from VPLS to EVPN-VPWS instance
Product-Group=junos
On all Junos and Evo platforms, the rpd process crashes may be seen if an interface is moved from Virtual Private LAN Service (VPLS) instance to Ethernet VPN-Virtual Private Wire service (EVPN-VPWS) instance in one commit (deleting the former and creating the latter).
PR Number
Synopsis
Category: EX driver issues
1600291
The SFP-T port might stop forwarding traffic on EX4600 platforms
Product-Group=junos
On EX4600, after performing an upgrade, the peer device is rebooted, the peer interface is disabled/enabled or rebooting EX4600, then the SFP-T port on EX4600 might remain in up state but could not forward traffic.
PR Number
Synopsis
Category: EX4400 PFE software
1603015
On EX4400 dot1x authentication may not work on EVPN/xlan enabled endpoints.
Product-Group=junos
On EX4400 dot1x authentication may not work on EVPN/xlan enabled endpoints. The issue is due to EAPOL packets received on VxLAN ports are not processed in hostpath.
PR Number
Synopsis
Category: Express PFE FW Features
1637328
Filters with Unsupported match/action by kernel filters, will not be learnt by firewall MIB daemon.
Product-Group=junosvae
Filters with Unsupported match/action by kernel filters, will not be learnt by firewall MIB daemon.
1652762
Configuring gre-key in firewall filter may breaks the dscp classification
Product-Group=junos
Differentiated Services Code Point (DSCP) is a means of classifying and managing network traffic and of providing quality of service (QoS) in Layer 3 IP networks. When the Range field of gre_key flt_type (promote gre-key) is incorrectly mapped to legacy TOS (Type of service) field for DSCP, the classification may fails and filter might not work properly.
PR Number
Synopsis
Category: Express PFE Services including JTI, TOE, HostPath, Jflow
1637364
True Outgoing Interface in ECMP traffic is not getting reported correctly by jflow
Product-Group=junos
On Junos PTX series, True Outgoing Interface(OIF) reporting might not happen correctly for ECMP traffic when ingress sampling is configured on AE interface.
PR Number
Synopsis
Category: Express PFE MPLS Features
1590387
ISIS adjacency is not coming up through TCC l2circuit
Product-Group=junos
On ACX/PTX/QFX platforms( PTX10002/10003/ 10008/ 10016/QFX10002/ 10003/10008/ 10016/ ACX6360) if protocols l2circuit and channel tcc is enabled for providing layer 2 transaction, ISIS connection through the layer 2 domain might get failed and traffic loss might be seen.
PR Number
Synopsis
Category: Flow-tap software
1647179
DTCP radius-flow-tap fails to program PFE when trigger X-NAS-Port-Id exceeds 48 character length.
Product-Group=junos
DTCP radius-flow-tap fails to program PFE when trigger X-NAS-Port-Id exceeds 48 character length.
PR Number
Synopsis
Category: Express ASIC interface
1606008
Link flaps might be observed momentarily on PTX5000 routers
Product-Group=junos
On PTX5000 routers with QSFP-100GBASE-LR4 optics, after a software upgrade, link flaps might be observed momentarily due to a firmware upgrade issue. This issue might cause traffic impact.
PR Number
Synopsis
Category: SRX4100/SRX4200 platform software
1626562
A major alarm DPDK (data plane development kit) Tx stuck issue of SRX4100/4200
Product-Group=junos
On the SRX4100 and SRX4200 platforms, it can detect DPDK (data plane development kit) Tx stuck issue and trigger a major chassis alarm goes which might trigger RG1 failover to the healthy node. A DPDK reset will be triggered only to the stuck port and if the reset resolves the tx stuck issue, the major chassis alarm will go off.
PR Number
Synopsis
Category: Signature Database
1594283
IDP signature DB update fails
Product-Group=junos
On SRX Branch platforms, it is unable to use latest signature pack due to IDP DB failing to update.
PR Number
Synopsis
Category: BSDX Software installation issues
1639610
The error is seen during the NON-ISSU upgrade from 15.1 to 18.2 and later releases
Product-Group=junos
In SRX5400, SRX5600, SRX5800 platform while performing NON-ISSU software upgrade from 15.1 to 18.1 and later releases error is seen.
PR Number
Synopsis
Category: Kernel software for AE/AS/Container
1466531
The following error message is observed after GRES: [user.err aftd-trio: [Error] IF:Unable to add member to aggregate member list, member already exists, aggIflName:ps1.0 memberIflName:lt-3/0/0.32767].
Product-Group=junos
You may see "lag_remove_link_from_stack_bundle ... with err=2", or "aftd-trio: [Error] IF: Unable to add member to aggregate member list, member already exists" when performing GRES or ISSU. These messages are expected because these are the result of the FPC receiving duplicate IPC messages from the Routing Engine.
1641988
The VMcore might be observed on EX platforms in rare scenario
Product-Group=junos
On EX platforms, the Routing Engine (RE) might get crashed and result in VMcore, if the kernel sends a request to PFE for fetching the statistics of an Aggregated Ethernet (AE) with more than one member link. This issue appears when the member link gets lost for certain reasons in background and at the same time the kernel's request arrives. Since AE member link has lost, PFE might not send statistics response to kernel within 10 seconds(default time) and error might be returned. This invalid memory access might result in RE crash by generating VMcore. This could be a rare case scenario.
PR Number
Synopsis
Category: Integrated Routing & Bridging (IRB) module
1623262
Host generated IPv4 traffic sent over IPv6 next-hop with IRB interface might get dropped
Product-Group=junos
On all Junos platforms that support IRB(Integrated routing and bridging), when host originated IPv4 traffic is sent over IPv6 next-hop with IRB interface, the traffic might get dropped because of ether-type mismatch. This is because the ether-type field in L2 header is set to IPv6 (instead of IPv4) always due to the IPv6 next hop.
PR Number
Synopsis
Category: Firewall Network Address Translation
1631815
New persistent NAT or normal source NAT sessions might fail due to noncleared aged out sessions
Product-Group=junos
On high end SRX platforms with Central Point (CP) architecture and Services Processing Units (SPUs), if configured with all these features "persistent NAT, hairpin, source NAT", persistent NAT sessions might get stuck and aged out Persistent NAT sessions might not get cleared, due to which the new persistent NAT or normal source NAT session might fail.
PR Number
Synopsis
Category: JSR Application Services
1586367
Extra data-plane CPU cycles for processing GTP traffic on SRX5000 Series device
Product-Group=junos
On SRX5000 Series device with enhanced Central Point (CP) architecture, the Tunnel Endpoint Identifier (TEID) will be decoded incorrectly, which results in extra data-plane CPU cycles for session lookup, the performance for processing GTP traffic will be impacted.
PR Number
Synopsis
Category: User Firewall related issues
1637548
Unable to connect to domain controller on installing Microsoft KB update
Product-Group=junos
On all SRX platforms, when the User Identification feature is used with Active Directory, after the Domain Controller server installs updates related to Microsoft's KB article
KB5004442
[juniper.net]
, SRX is no longer able to connect to it.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1608724
The process "iked" crash might be seen for IKEv1 based VPN tunnels
Product-Group=junos
The process "iked" might crash when IPsec negotiation is initiated via ike_peer_est_immediately_timeout due to IPsec SAs not being present but ike SA is present.
PR Number
Synopsis
Category: jsscd daemon
1634371
In subscriber scenario, traffic drop might be seen when AE member link is removed
Product-Group=junos
On all Junos MX platforms configured with Dynamic Host Configuration Protocol (DHCP) subscribers over the Aggregated Ethernet (AE) interface and static subscribers, traffic loss might be seen for the static subscribers when the AE interface member link is removed. The static subscribers might be logged-out and logged-in automatically without any intervention.
PR Number
Synopsis
Category: Platform infra to support jvision
1615045
Export memory and temperature metrics for all existing components when it subscribes to telemetry sensor
Product-Group=junos
On all Junos platforms, the device may export memory, allocated power and temperature metrics for all existing components no matter if those leafs are supported on the components, such as exporting memory utilization for a PIC component or a transceiver, which could consume more resources on both the device and collector.
1624623
The mcontrol may frequently miss keepalives from backup RE
Product-Group=junos
If telemetry takes 10 above seconds or lower reporting interval (e.g. 5/7.5/15 seconds) in a Jvision/Telemetry with dual -RE platforms, while subscribing the RE related sensor "/components/component/properties/property/state/value/" or "/components/component/", it might cause high CPU usage on chassisd and RE mastership-refresh issue handled by mcontrol watchdog, then the frequent loss of keepalive-message might be sent between the REs, unexpected RE failover and unstable control plane/chassis components might be seen on the system.
PR Number
Synopsis
Category: Layer2 forwarding on EX/NTF/PTX/QFX
1643258
Traffic impact might be seen if persistent-learning is enabled on an interface
Product-Group=junos
On all Junos and Junos evolved platforms, clearing the mac from an interface on which persistent-learning is enabled might result in traffic impact. Please restart l2ald process to resolve the issue.
PR Number
Synopsis
Category: lacp protocol
1640240
Aggregated Ethernet interface remains up instead of down after deleting loopback and ae interface ip on neighbor while verifying BFD sessions on router
Product-Group=junos
Aggregated Ethernet child interfaces with LACP configurations are not timing out even if peer is gone and not sending any bridge protocol data unit (BPDU).
PR Number
Synopsis
Category: SW PRs for MPC10E Interfaces
1638410
PFE might get stuck after 100G/400G interface flaps
Product-Group=junos
On Junos platforms equipped with MPC10E/MPC11E/ LC2301/MX10K-LC9600 line cards, when any 100G/400G interface with high priority class-of-service scheduler configuration flaps, it might result in series of error messages during high traffic flow. Eventually this would result in PFE-disable action, impacting the related traffic. However, the issue could be recovered after FPC reboot.
PR Number
Synopsis
Category: MX Timing software
1635877
Precision Time Protocol (PTP) packets having huge correction-field (CF) value coming out from MX platforms
Product-Group=junos
From MX platforms showing huge correction-field (CF) values on downstream devices in Precision Time Protocol (PTP) packets due to PTP failure on ports.
PR Number
Synopsis
Category: Track Mt Rainier RE platform software issues
1568038
The chassisd might crash on MX/PTX/EX92xx platforms with NG-RE
Product-Group=junos
On MX/PTX/EX92xx platforms with NG-RE, when message length is less than the message header length, which is received in chassisd from the host, the chassisd might crash.
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1639991
Recovery snapshot might fail if OAM volume is already mounted
Product-Group=junos
Recovery snapshot might fail with the error "The OAM volume is too small to store a snapshot" if OAM volume is already mounted.
PR Number
Synopsis
Category: Kernel Multicast Infrastructure
1608311
Intermittent p2mp traffic drop might be seen in MVPN scenario
Product-Group=junos
On MX platforms that support enhanced IP, intermittent p2mp traffic drop might be seen in the case of MVPN with p2mp. When the multicast composite NH involves unicast NH pointing to pseudo interfaces like interface vt-, irb or lsi and the other unicast next-hop is spread across multiple line cards/PFEs, if a new member joins or an existing member leaves the multicast stream traffic drop might be seen.
PR Number
Synopsis
Category: vMX Data Plane Issues
1641119
IPv4 and v6 packet header corruption could happen with some sampling scenario
Product-Group=junos
On vMX/ MX150/ NFX150 platforms, when sampling is enabled on input WAN interfaces and the sampled packet go out through a GRE tunnel, IPv4/6 header corruption may happen. Due to IP header corruption, remote router reports L3 incompletes at receiving interface.
PR Number
Synopsis
Category: vMX Platform Infrastructure related issue tracking
1643932
VRRP and ISIS fails to converge after interface flap
Product-Group=junos
On VMX platforms with i40e drivers, VRRP and ISIS might fail to converge after the interface flaps which might affect multicast services.
PR Number
Synopsis
Category: VRR (Virtual Route Reflector) for MX
1635950
vRR VM might establish its identity as "Olive" after a CLI s/w upgrade
Product-Group=junos
vRR VM might come up as Olive after a CLI sw upgrade using junos-install-mx* package if the XML used to spawn the VM didn't have SMBIOS entry "VRR".
PR Number
Synopsis
Category: Chassis mgmt for all QFX systems - chassis MIB, alarms, CLI
1589572
QFX5210-64C - PSU jfirmware upgrade through JUNOS
Product-Group=junos
Add a command-line to upgrade the jfirmware for PSU through JUNOS. The command is the same as the existing command to upgrade Junos.
PR Number
Synopsis
Category: QFX L2 PFE
1484336
The dcpfe might crash on platforms with auto-channelization enabled
Product-Group=junos
On QFX Series and EX Series switches with auto-channelization support, an optic speed mismatch connection might cause the auto-channelization to get into an infinite loop trying to match a proper speed. In this case, due to some memory leaks, the resources get exhausted, resulting in system crash. The traffic gets disrupted when the system dcpfe restarts.
1626011
The third 802.1Q tag might not be pushed onto the stack in the Q-in-Q tunneling
Product-Group=junos
In the Q-in-Q tunneling scenario, when dual VLAN tagged multicast packets (e.g., OSPF protocol packets) are received into a C-VLAN interface with an 'input-VLAN-map push' configuration, the VLAN swap operation will be done instead of the push operation. This issue could cause the packets to egress the S-VLAN interface with two VLAN tags instead of three VLAN tags
1633452
The FBF filtered VLAN traffic will not be passed properly to the forwarding routing instances over AE interfaces on QFX5K/ EX4600/ EX4650 platforms
Product-Group=junos
On QFX5K/ EX4600/ EX4650 platforms with IPv4 Filter-based forwarding (FBF) scenario, when IPv4 FBF is used with 802.1Q VLAN tag enabled layer-3 AE interfaces, the VLAN filtered configuration enabled by FBF filter will be stored in the VLAN filter processor (VFP) ternary content addressable memory (TCAM). But, in some cases of adding/deleting the configuration of the routing instances (then routing-instance) in FBF filter, the stale allocated entries in VFP TCAM might not be deleted from the system, the memory slices of VFP TCAM will be exhausted until it is run out. Finally, there are not enough memory slices left to store the VLAN filtered information for the forwarding routing instances, then the FBF filtered VLAN traffic will not be forwarded correctly since the FBF filters might not be programmed/processed on the system.
1637249
Configuring L2PT on a transit switch in a Q-in-Q environment breaks L2PT for other S-VLANs
Product-Group=junos
When L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch using SP style configuration, protocol convergence between end nodes might fail.
1638619
Targeted broadcast or WOL feature may not work on QFX 5k platforms
Product-Group=junos
On QFX platforms, Wake On LAN(WOL) feature stops working as the affected platforms erroneously process such packets. This might cause a blackhole in the network for such traffic.
PR Number
Synopsis
Category: QFX VCCP
1559172
The VCF might become not stable
Product-Group=junos
When adding a new leaf to VCF of 12 members without setting its VC mode to 'fabric' on QFX5100 platforms, it might cause the VCF to become not stable.
1639543
In a VCF scenario on QFX5100, VCP interfaces might flap or not come up at all and CRC errors might increase
Product-Group=junos
When VCF (Virtual Chassis Fabric) is set up on QFX5100 platforms, all the VCP (VC port) interfaces on a particular FPC (Flexible PIC Concentrator) might fail to join the VCF and CRC errors on those might increase. A subsequent reboot of the FPC may lead it to a "Not Present" state.
PR Number
Synopsis
Category: QFX10008/16 QFX10002 linecard, serdes and uboot
1632440
The interface might remain in the "UP/UP" state even the interface is admin disabled
Product-Group=junos
On the QFX10002/ QFX10008/ QFX10016 platforms, if reboot the FPC with interface admin disabled configuration, the interface might remain in the "UP/UP" state.
PR Number
Synopsis
Category: QFX5100 Interface related issues
1638045
Delay might be observed for the interfaces to come up after reboot/transceiver replacement
Product-Group=junos
On QFX5100/EX4600 Junos platforms with 2-member VC(Virtual Chassis) setup, after the device reboot or QSFP+-40G-SR4 SFP (small form-factor pluggable) replacement, the VC port might remain down and takes longer time (approximately 5-20min) to come up even if the cable is connected properly to the interface.
PR Number
Synopsis
Category: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1611354
The ports might remain in downstate on QFX5K platforms
Product-Group=junosvae
In a rare scenario, if the upgrade is being performed or ports are continuously flapped on QFX5K platforms, then interfaces might remain in downstate and need to reset in order to restore it.
PR Number
Synopsis
Category: rosen-6 and rosen-7 mvpn bugs
1642182
The Multicast Tunnel interface is not selected as per the configuration for the Draft-Rosen
Product-Group=junos
On all Junos and Junos Evolved platforms, the Multicast Tunnel (MT) interface might not be selected as per the configuration for the Draft-Rosen thus, the traffic might not flow through the specified tunnel.
PR Number
Synopsis
Category: RPD Infrastructure Issues.
1546600
The traffic of MPLS-IPv4 FEC might not be forwarded properly in JFlow or inline-JFlow scenario
Product-Group=junos
When JFlow or inline-JFlow is enabled with mpls-template or mpls-ipv4-template, if nexthop-learning is enabled, MPLS top label address will be populated for MPLS-IPv4 FEC (Forwarding Equivalence Class). Under a race condition where MPLS-IPv4 FEC is associated with multiple labels and multiple next hops for each label, the MPLS top label address value might be reversed (a.b.c.d -> d.c.b.a) because of stale FEC entry generated in the system. Then the MPLS-IPv4 FEC traffic might be impacted.
PR Number
Synopsis
Category: Resource Reservation Protocol
1637645
The rpd memory leak may be observed in a subscriber management environment with RSVP
Product-Group=junos
On MX platforms, in subscriber management environment with Psuedowire Headend Termination (PWHT) configured, when the subscribers are added and deleted, the memory leak in rpd process may be observed. The creation and deletion of demux interfaces will cause this issue with Resource Reservation Setup Protocol (RSVP) configured. The system will run out of memory eventually, causing the rpd crash when the new memory is requested.
PR Number
Synopsis
Category: SNMP Infrastructure (snmpd, mib2d)
1651774
VTEP might report a high speed on the sub-interface, causing SNMP alarms
Product-Group=junos
When used on the VTEP sub-interface, the ifspeed OID may show a maximum value that is not zero.
PR Number
Synopsis
Category: track Prs of Dynamic Address module running on SRX
1634881
Most of the Dynamic Address Entries might report 0 IPv4 entries
Product-Group=junos
When using security intelligence with SRX devices, the DAE (dynamic address entries) might show 0 IPv4 entries.
PR Number
Synopsis
Category: SRX branch platforms
1629568
Failure may be observed if using ZTP for provision on the SRX platforms
Product-Group=junos
SRX systems support bootstrapping with AIU and phone-home. When the DHCP option is received and doesn't have AIU option(Vendor option 43), the phone-home process tries to bootstrap the system. If it fails, then control is not given back to AIU for bootstrapping and the system gets stuck in an unprovisioned state.
PR Number
Synopsis
Category: MX10002 Platform SW - Platform s/w defects
1631010
,The FPC might crash after enabling MACsec
Product-Group=junos
On MX10003/MX2K with MPC8/9 line cards/PTX10001-20C/ACX6360 platforms, when MACsec (Media Access Control Security) is enabled on ports, FPC might crash with PFEMan (PFE Management) core, which would impact the related traffic. However, the issue could be self-recovered. The issue could be very rare.
PR Number
Synopsis
Category: SRX-1RU platfom related protocol, QoS, filtering features et
1630990
The srxpfe process might crash on SRX4600
Product-Group=junosvae
On SRX4600, a corruption in memory buffer (m_buf) might lead to srxpfe crash. Core files are generated and hardware monitoring failures might be observed when the process crashes.
PR Number
Synopsis
Category: ZT/YT pfe CDA issues
1580798
FPC might crash in rare scenario when MPC10/11 line cards are used
Product-Group=junos
On all MX platforms running Junos or EVO, when equipped with MPC10/11 line cards, in a rare condition, FPC might crash or interface statistics might stop working.
PR Number
Synopsis
Category: ZT/YT pfe l3 forwarding issues
1480308
The aftd might crash on MPC10E/MPC11E line cards
Product-Group=junos
On MX platforms with MPC10E/MPC11E used, if the configuration add/change on AE (Aggregated Ethernet)/AF (Abstracted Fabric) bundle or the number of outgoing paths changes in the multipath/ECMP (Equal-cost multipath)/LFA (Loop-free alternate)/link protection configuration scenario, the aftd (Advanced Forwarding Toolkit Daemon) crash might be seen and result in the line cards reset/reboot.
1628091
Invalid IP length packets encapsulated within MPLS may trigger PPE traps
Product-Group=junos
Bad IP length packets (ip header length field > actual packet size) when encapsulated within MPLS are dropped as expected, but **may** trigger PPE traps in some cases
1630408
Index of the link might get missed in the distribution table of PFEs after the flap
Product-Group=junos
On MX platforms with the scenario of BGP and BFD running, it might bring ECMP links up and down which might impact traffic distribution and keep one of the ECMP links unused.
PR Number
Synopsis
Category: Trio pfe qos software
1657203
PFE might get disabled if a packet with a small size is transmitted out of the queue
Product-Group=junos
In MX platforms, if a packet with a small size (for example 64 Byte) is transmitted out of the queue then there might be PFE get disabled.
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1640254
The input-vlan-map (pop) might not work on PS interfaces if the native VLAN is in use on the uplink interface
Product-Group=junos
On MX platforms input-vlan-map (pop) might not work on Pseudowire Subscriber (PS) interfaces if the native VLAN is configured on the uplink interface under the pseudowire headend termination (PWHT) scenario.
PR Number
Synopsis
Category: Issues related to port-mirroring functionality on JUNOS
1634570
The fpc might crash on enabling port-mirroring
Product-Group=junos
On vMX/MX150 platforms, if port-mirroring is enabled with scaled flows (10k or more flows for immediate crash) and throughput scenario, the fpc crash might be observed. However, the issue could be restored after self-reboot.
PR Number
Synopsis
Category: Junos Automation, Commit/Op/Event and SLAX
1542229
Junos OS: Certificate validation is skipped when fetching system scripts from a HTTPS URL (CVE-2022-22156)
Product-Group=junos
An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may compromise the integrity and confidentiality of the device. Refer to https://kb.juniper.net/
JSA11264
[juniper.net]
for more information.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1641025
Unable to access configure exclusive mode after mgd process is killed
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, when copy-config, get-configuration, and discard-change RPCs run in two parallel NETCONF sessions and the database is also accessed in parallel by two NETCONF sessions, it leads to database corruption and mgd-related services might crash.
PR Number
Synopsis
Category: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1502499
File descriptors might be leaked in eventd when "load replace" is used to update "system syslog source-address"
Product-Group=junos
Each time "load replace" is used to update "system syslog source-address", a new file descriptor is created which eventually leads to eventd reaching its limit of maximum open files (i.e. 1024).
PR Number
Synopsis
Category: PTX/QFX100002/8/16 Fabric software
1615942
90% traffic got dropped when the number of Switch Interface Board (SIB) plane is reduced from 4 to 3 on PTX10008 and PTX10016
Product-Group=junos
On PTX10008 and PTX10016 routers, when the number of Switch Interface Board (SIB) planes is reduced from 4 to 3, traffic might drop by 90%.
PR Number
Synopsis
Category: VMHOST platforms software
1605971
VM host platforms might boot exactly 30 minutes after executing 'request vmhost halt' command
Product-Group=junos
On all VM host platforms running Junos OS Release 19.3R1 onwards, when 'request vmhost halt' is executed, the system reboots after exactly 30 minutes instead of maintaining the halt condition.
PR Number
Synopsis
Category: Virtual Router Redundancy Protocol
1635351
VRRP route tracking for routes in VRF might not work if "chained-composite-next-hop ingress l3vpn" is used
Product-Group=junos
In L3VPN scenario with configured "routing-options forwarding-table chained-composite-next-hop ingress l3vpn" knob, if VRRP route tracking is used to track routes inside a VRF, and if such routes are with composite next hop, they might be marked as down even they are present in the VRF, hence the VRRP route tracking might not work properly.
1638378
After upgradation, the tracking routes of VRRP might become unknown
Product-Group=junos
On all Junos platforms, after upgradation the Virtual Router Redundancy Protocol (VRRP) state will not be correct and tracking routes of VRRP might show as unknown. The intended router might not be the VRRP master instead the peer router with less priority will be master. The route states are not correct because "route add" messages are not received at 'vrrpd' after activation of the interface. When the interface is activated an interface route is created for the address configured on the interface, 'vrrpd' will receive the addition and then update the track route state accordingly. When this is not being received at 'vrrpd' tracking routes might become unknown.
PR Number
Synopsis
Category: Xellent Platform issues
1620527
QSFP in slot et-0/0/0 may not come up after plug-in
Product-Group=junos
On QFX and PTX platforms using QSFP and optic toolkit, QSFP in slot et-0/0/0 might not come up after plug-in. When this happens, one/few ports may start showing i2c errors and eventually do not come up. Hence the link would not come up in that particular port.
19.4R3-S8 - List of Known issues
PR Number
Synopsis
Category: EX4300 Platform
1659460
EX4300 "request system software add ftp" fails with the message "The /var/tmp filesystem on JUNOS is low on free disk space."
Product-Group=junos
There is a similar PR1494963 but the fix did not cover when you use FTP option with "request system software add ..". The fix of 1659460 covers the FTP case now.
PR Number
Synopsis
Category: NFX Layer 3 Features Software
1536677
nfx3:- QOS buffer memory allocation in porter-3 integrated srx is 1/10th that of vSRX 2.0/3.0 .
Product-Group=junos
QOS buffer memory allocation is low causing tail-drops on NFX150 and NFX250
PR Number
Synopsis
Category: NFX Series Platform Software
1643164
VRRP is not functional in vSRX on NFX
Product-Group=junos
On the NFX platform having VRRP configured with trust mode enabled and spoof disabled, VIP might not be reachable.
PR Number
Synopsis
Category: QFX PFE CoS
1472583
When L3 is enabled on interface then transit ARP is sent to CPU causing ARP queue congestion and traffic drop
Product-Group=junos
When L3 is enabled on interface then transit ARP (target address not mine) is sent to CPU causing ARP queue congestion and traffic drop
PR Number
Synopsis
Category: Sflow on QFX 5100,5200, 5110
1598239
Sflow impacts on ICMP traffic on QFX5XXX platforms
Product-Group=junos
On QFX5XXX platforms in sflow scenario, CPU/host bound ICMP traffic from or to the sampled interface might be dropped, which might have impact on services based on ICMP probes like RPM.
PR Number
Synopsis
Category: Bi Directional Forwarding Detection (BFD)
1243146
PFE with delegated non-inline BFD sessions may cause these BFD sessions to flap
Product-Group=junos
MX/PTX routers running Junos 15.1 or later with non-inline delegated BFD sessions such as microBFD are susceptible to BFD session flaps. The flaps are seen due to intensive RE - PFE traffic or additional threads causing PPM Data thread (especially with auth as it requires more intensive processing) starvation
PR Number
Synopsis
Category: Border Gateway Protocol
1579225
BGP-signaled dynamic tunnels might be still up after deactivating the BGP export policy from the remote peer
Product-Group=junos
In next hop-based tunnels in a Layer 3 VPNs scenario, the BGP-signaled dynamic tunnels remain in an established state and don't go down after deactivating the BGP export policy. This occurs when the export policy contains next hop and tunnel community information from the remote peer. This issue causes traffic to be forwarded towards the bad tunnels, resulting in traffic loss.
1616065
Slow memory leak (32 bytes each time) of rpd might be seen
Product-Group=junos
In the BGP rib-group scenario, a slow rpd memory leak (32 bytes each time) might be seen after BGP route with secondary route is added or updated.
1632132
The BGP session might flap after rpd crash with 'switchover-on-routing-crash' and NSR enabled in a highly scaled environment
Product-Group=junos
On all Junos platforms that support NSR (Nonstop active routing), when 'switchover-on-routing-crash' is enabled, the rpd process crash will lead to Routing Engine switchover. In a highly scaled environment (about 15~19 million BGP routes), BGP (Border Gateway Protocol) session which is still sending update packets of size more than 2k might flap even when NSR is enabled. This might lead to loss of traffic till the BGP session converges after the flap. This does not happen always but happens sporadically. The switchover can be either due to rpd process crash or when switchover is performed manually.
PR Number
Synopsis
Category: OpenSSH and related subsystems
1612947
Junos OpenSSH leaves a dangling pointer
Product-Group=junos
On all Junos OS platforms, Junos OpenSSH might leave a dangling pointer that may cause the sshd to crash with core-dumps.
PR Number
Synopsis
Category: Firewall Filter
1599075
MX: SNMP WALK ON FIREWALL COUNTERS BREAKS WITH "REQUEST FAILED: GENERAL ERROR"
Product-Group=junos
Generic error while walking through the firewall MIBs in case of list filters both on init and inet6 families (Dual Stack scenario) on same IFL. The validations were added to avoid a low probability core. And to avoid generic error, the list filters naming convention was changed to appear as different filter names for list filters when applied in Dual stack case. But, this will be a CVBC change which may not be agreed from the service releases point of view. In the mainline future releases this generic error issue will be addressed by changing the list filter names applied for init and inet6 families on same interface.
1625309
Packet loss might be reported after hitting the firewall filter on Junos platform
Product-Group=junos
On Junos platform, on the egress or ingress PFE instance, after hitting a firewall, it might lead to packet loss and impact service.
PR Number
Synopsis
Category: Ethernet OAM (LFM)
1500048
The fpc process might crash in the inline mode with CFM configured.
Product-Group=junos
On the Junos platforms with inline mode CFM (Connectivity Fault Management) configured, if there are several CFM adjacencies flapping, due to the flaw in the CFM module to process the error-adjacencies messages, the FPC may crash alongside with NPC core-dump file generated. All services/traffic configured on the FPC will see outage till FPC recovers from an automatic reboot.
PR Number
Synopsis
Category: idp flow creation, deletion,notification, session mgr intfce
1631007
IDP policy load might fail when the rule is configured other than 'any' in logical-system/tenant
Product-Group=junos
On Junos SRX platforms, Intrusion Prevention and Detection (IDP) policy load might fail when IDP rule has "from zone" or "to zone" configured other than "any" in logical-system/tenant. When this policy load fails traffic will not be inspected as per the new committed config rule.
PR Number
Synopsis
Category: Kernel software for AE/AS/Container
1464524
The harmless syslog messages might be seen during ISSU or GRES or FPC offline/online scenarios
Product-Group=junos
Some harmless syslog error messages might be seen and expected during ISSU or GRES or FPC offline/online scenarios.
1634908
LACP interface might go down when a sub-interface configuration is added and committed to the AE interface
Product-Group=junos
On all MX150 platforms, when an Aggregate Ethernet (AE) interface is configured with LACP and adding a sub-interface configuration under the AE interface causes the LACP down leads to traffic loss.
PR Number
Synopsis
Category: jdhcpd daemon
1550628
Making configuration changes with apply-group add/delete associated with DHCP may result in client connection failure
Product-Group=junos
Making configuration changes with apply-group add/delete associated with DHCP can result in client connection failure. The failure is a result of not properly clean up and the stale data have the potential for DHCP client connection failure.
1629171
IPv6 IA_NA or IA_PD routes might get deleted from the DHCPv6 client
Product-Group=junos
On MX platforms configured as DHCPv6 relay-agent with ALQ (Active Lease Query), when the IA_NA (Identity Association for Non-temporary Addresses) and IA_PD (Identity Association for Prefix Delegation) routes are requested by a client in a single solicit message and they are renewed separately in quick successions (within milliseconds), then the routes of one of the IA's which is received later by the relay-agent might not be renewed and if aggressive lease timers are configured (example 5 minutes), then the routes of IA's which is received later by the relay-agent might get deleted from the DHCPv6 client.
PR Number
Synopsis
Category: jl2tpd daemon
1493289
L2TP LNS: Subscriber that sends IRCQ that includes RFC5515 AVPs may fail to establish session
Product-Group=junos
In release 17.4 and forward, subscriber sessions on the LNS that send an ICRQ that includes RFC5515 AVPs may fail to establish a session. The client will receive a CDN error "receive-icrq-avp-missing-random-vector" in response.
PR Number
Synopsis
Category: Adresses ALG issues found in JSF
1577814
Junos OS: MX Series: Receipt of specific packet on MS-MPC/MS-MIC causes line card reset (CVE-2021-31351)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions in packet processing on the MS-MPC/MS-MIC utilized by Juniper Networks Junos OS allows a malicious attacker to send a specific packet, triggering the MS-MPC/MS-MIC to reset, causing a Denial of Service (DoS). Refer to https://kb.juniper.net/
JSA11216
[juniper.net]
for more information.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1653704
ipsec tunnel via ipv6 won't establish after rebooting
Product-Group=junos
After rebooting SRX device, IPSec tunnel using ipv6 may not up.
PR Number
Synopsis
Category: SW PRs for MPC10E Interfaces
1601049
Interface flap might trigger major alarm causing disble-pfe action when high priority scheduler is configured
Product-Group=junos
On all Junos platforms with MPC10E line-cards, repeated 100GE interface link flaps may result in loss of traffic going out of the interface. Each 100GE interface down event might not flush the stream and triggers a major alarm causing disable-pfe action. This is specific to interfaces configured with high priority scheduler. MPC11E card is not exposed.
PR Number
Synopsis
Category: Multicast for L3VPNs
1652481
MVPN Inter-AS option B shows updated PMSI attribute tunnel id when advertising type-3 routes to Intra-AS PE
Product-Group=junos
PMSI attribute should be changed when sending Multicast VPN auto-discovery(AD) route from one region to other (here region referred to BGP groups in Multicast VPN) or in case it is sent to External Border Gateway Protocol (EBGP) peer or from EBGP to Internal Border Gateway Protocol (IBGP) peer. For IBGP to IBGP in case of RR (Route Reflector), ideally it should just reflect the route and not change PMSI attribute. Hence change in PMSI may result into traffic drop for internal RR clients.
PR Number
Synopsis
Category: MX Timing software
1631274
PTP (Precision Time Protocol) might not lock on MX with MX-MPC2E-3D-P and MPC2E-3D LC
Product-Group=junos
On all MX platforms with MX-MPC2E-3D-P and MPC2E-3D LC linecards, traffic might be flapping between ACQUIRING and HOLDOVER states while PTP with telemetry NPU is enabled.
1647901
When PTP with PHY-timestamping is enabled, significant clock frequency drift might be seen
Product-Group=junos
If timestamping the packet at the physical layer (also known as PHY timestamping) is enabled for Precision Time Protocol (PTP) in an l2circuit scenario, the transit PTP packets passing through the MPC2E-NG/MPC3E-NG/MPC5E/MIC-3D-20GE/10G built-in ports might be modified to have huge value in Correction Field of the PTP packet even though there is not PTP port configured on these line cards. If the transit PTP packets are used for synchronizing downstream node, the clock frequency drift could be seen.
PR Number
Synopsis
Category: Kernel MPLS / Tag / P2MP Infrastructure
1654798
RE kernel crash might be observed in the one-hop-LSP MPLS scenario with RE outbound traffic if 'routing-option resolution preserve-nexthop-hierarchy' is configured globally
Product-Group=junos
On all Junos platforms, if 'routing-option resolution preserve-nexthop-hierarchy' is configured globally, Routing-engine (RE) kernel crash might be observed in the one-hop-LSP Multiprotocol Label Switching (MPLS) scenario with RE outbound traffic.
PR Number
Synopsis
Category: Kernel Tunnel Interface Infrastructure
1586169
GRE OAM packets are sent through queue 0 with force-control-packets-on-transit-path knob enabled
Product-Group=junos
With force-control-packets-on-transit-path knob enabled, the GRE OAM packets are expectedly sent to queue 3 (network control queue), however, the GRE OAM packets are sent to queue 0.
PR Number
Synopsis
Category: Protocol Independant Multicast
1621358
Initial multicast register packets may get dropped
Product-Group=junos
On MX platforms, initial multicast register packets may get dropped, this may affect multicast services.
PR Number
Synopsis
Category: QFX5K hostpath
1630201
LACP timeout might be observed during high CPU utilization
Product-Group=junos
On QFX5100 switches, when the CPU utilization (Routing Engine and FPC) is 85 percentage or more and there are multiple Network Configuration Protocol (NETCONF) sessions running or SNMP polling is happening over multiple sessions simultaneously, the LACP session configured in fast mode might timeout.
PR Number
Synopsis
Category: QFX PFE
1576060
On the QFX5100-48T switch, the 10G interface might be auto-negotiated at 1G speed instead of 10G
Product-Group=junos
On the QFX5100-48T switch, auto-negotiation might fail to work and the 10G interface might be auto-negotiated at 1G speed instead of 10G. This issue might cause a link down.
PR Number
Synopsis
Category: QFX L2 PFE
1560086
On the QFX5200 line of switches, the pseudorandom binary sequence (PRBS) test fails for 100GbE interfaces with the default settings.
Product-Group=junos
On the QFX5200 line of switches, the pseudorandom binary sequence (PRBS) test fails for 100GbE interfaces with the default settings.
1604350
On QFX5120, traffic loss when primary link disabled with AE Link Protection configuration
Product-Group=junos
On QFX5120, traffic loss may be seen when primary link disabled with AE Link Protection configuration
PR Number
Synopsis
Category: QFX MPLS PFE
1579931
QFX5120 - Observed the partial traffic loss after disabling the protected link resulting in delay in convergence for link-protection for PE1_P link
Product-Group=junos
On a QFX5120, when you disable a protected link. You may see a delay of 200-400 mSec for the system to react to the disable link event.
PR Number
Synopsis
Category: KRT Queue issues within RPD
1623170
BGP Flowspec may not shows counters for matching IPv6 firewall filter
Product-Group=junos
Releases which have PR fix 1607185, IPv6 flowspec filters which have terms that match the ICMPv6-type and ICMPv6-Code will not match correctly to the traffic.
PR Number
Synopsis
Category: RPD Next-hop issues including indirect, CNH, and MCNH
1645296
Traffic drop with EBGP multipath and EBGP paths equal to the maximum-ecmp limit
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with EBGP multipath and bgp-protect-core under the routing instance, if the number of external paths along with the BGP Prefix-Independent Convergence (PIC) backup paths reaches the maximum ECMP limit, then all the traffic towards the destination is dropped on PFE with the exception of "sw error".
PR Number
Synopsis
Category: SRX Argon module
1643373
The SKY ATP integrated service might get impacted on SRX with LSYS
Product-Group=junos
In Juniper SKY ATP Cloud with SRX cluster LSYS (logical system) scenario, the advanced-anti-malware (AAMW) daemon will be used to communicate/interoperate between the SRX LSYS and cloud server. In some rare cases, after failover of the SRX LSYS, the tenant information of the logical domains (LDOM) might not consistent with VR router (VRF). It will cause some SRX LSYSs to be unstable, Sky ATP integrated services will be impacted on the SRX cluster.
PR Number
Synopsis
Category: MPC7/8/9 Interface Issues
1486542
The following message might be observed while configuring MTU: SNMP_TRAP_LINK_DOWN
Product-Group=junos
The "SNMP_TRAP_LINK_DOWN" messages might appear in log when configuring MTU on MX interface.
PR Number
Synopsis
Category: SRX-1RU platfom related protocol, QoS, filtering features et
1637009
On SRX4600 platforms, the command "set chassis disk-partition /var " is unsupported and enabling it might lead to instability
Product-Group=junos
On SRX4600 platforms, the command "set chassis disk-partition /var" is unsupported and enabling it might lead to instability
PR Number
Synopsis
Category: ZT/YT pfe infra issues
1575138
[MPC10] - Traffic drops while routing from MPC10 to other type of MPC when configured with WAN-PHY mode on the "other" MPCs
Product-Group=junos
A router will drop traffics when using "wan-phy" mode on a router with MPC10E mixed with other types of MPC -- such as MPC3E. This issue affects JUNOS software versions prior to 20.1R1.
PR Number
Synopsis
Category: ZT/YTpfe bridging, learning, stp, oam, irb software
1650854
The IPv4 traffic drop might be observed in EVPN scenario
Product-Group=junos
In EVPN/MPLS setup with irb, when transit Layer 3 traffic hits IRB. The reported problem is happening due to a bug in ipv4_arp_ipv6_nd_snooping instruction. This would fetch a value from an uninitialised LMEM location which can cause out of bound access in entry_layer2_ipv4_arp_ipv6_nd instruction. Based on the value in that uninitialised location, the out of bound access may or may not happen. That is why this issue is seen intermittently. This is seen for IPv4 packets as the memory location would be initialised only in case of IPv6. Feb 23 12:54:01.281 chloe-re0 afeb0 LUCHIP(0) PPE_15 Errors lmem addr error Feb 23 12:54:01.356 chloe-re0 afeb0 PPE Thread Timeout Trap: Count 2, PC 614a, 0x614a: wan_out_deferred_block_alloc_post_processing 0x614a: wan_out_sys_stats_check 0x614a: skip_accurate_stat Feb 23 12:54:01.570 chloe-re0 afeb0 PPE PPE HW Fault Trap: Count 2678, PC 69ea, 0x69ea: entry_layer2_ipv4_arp_ipv6_nd 0x69ea: ipv4_arp_ipv6_nd_process_check_arp_nd_pkt Feb 23 12:54:02.177 chloe-re0 afeb0 LUCHIP(0) PPE_2 Errors lmem addr error
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1606731
The FPC might crash if 'flow-table-size' is configured on MX Series routers
Product-Group=junos
On MX Series routers, if the statement 'set chassis fpc slot-number inline-services flow-table-size' or 'set chassis fpc slot-number inline-services flex-flow-sizing' is configured, the FPC might crash.
PR Number
Synopsis
Category: Trio pfe mpls- lsps,rsvp,vpns- ccc, tcc software
1568879
BFD may set the maximum weight to the AE interface and cause traffic blackholing
Product-Group=junos
In some rare scenarios, when the FPC encounters a transient/permanent HW error and all the interfaces are brought down, but the FPC is still online, the BFD may set the maximum weight to the AE interface and cause traffic blackholing.
PR Number
Synopsis
Category: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1660931
Lockout-period might not work as expected
Product-Group=junos
Lockout-period might not work as expected and the user gets locked out.
PR Number
Synopsis
Category: DDL/ODL infrastructure and CLI/Op commands
1658154
"request system scripts refresh-from op.. " output is not working as expected
Product-Group=junos
The warning of the command "request system scripts refresh ..." is inconsistent.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1627323
Junos Fusion Satellite EX4300 upgrade fails from MX104
Product-Group=junos
Junos Fusion Satelite EX4300 upgrade is performed from MX104 as AD with dual REs. The upgrade may get stuck and not responding.
1643209
Commit fails with message "statement does not match patch" due to TOD mismatches between Primary RE and Backup RE
Product-Group=junos
When time-zone for the router is set as EST5EDT and if the TOD (Time-Of-Day) values under "event-options generate-events" are modified in different time zones, that is TOD configurations created on EST time zones are getting modified in EDT time zone, then it can cause commit failures. When such commits happens at different time-zones, internally, it generates a patch file and tries to load the patch at both RE. But due to different time zone, it is not getting excepted by backup RE.
PR Number
Synopsis
Category: VMHOST platforms software
1613229
The "FPC 0 Major Errors" alarm might be seen on PTX10002-60C/QFX10002-60C due to a rare timing issue
Product-Group=junos
On PTX10002-60C/QFX10002-60C, after the system is rebooted, the "FPC 0 Major Errors" alarm might be seen due to a rare timing issue. The issue could cause the host path traffic to get dropped. It is a rare issue and does not always happen during reboot. Please try to perform "request vmhost reboot" for recovery.
Modification History
First publication date 2022-05-25
19.4R3-S8: Software Release Notification for JUNOS Software