Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, PTX, QFX running Junos Evolved Software

Alert Description

Junos Software Service Release version 21.4R2-S1-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.4R2-S1-EVO is now available.

21.4R2-S1-EVO - List of Fixed issues

PR NumberSynopsisCategory: bug and enchancement in RPD Infra
1655249When disabling/removing warm standby config and enable/adding NSR, please split these into two separate config commits.
Product-Group=evo
When disabling/removing warm standby config and enable/adding NSR, please split these into two separate config commits.
PR NumberSynopsisCategory: "agentd" software daemon
1665516Na-grpcd process can core during longevity flap tests
Product-Group=evo
Due to race condition happening at the time of streaming and simultaneous disconnection of clients, na-grpcd can core at rare ocassions. This will cause temporary outage of streaming telemetry services. The service will self recover upon restart of the process.
PR NumberSynopsisCategory: Border Gateway Protocol
1626717The rpd dump file might be seen while processing the BGP updates
Product-Group=evo
The rpd crash files might be observed on Junos and Junos OS Evolved platforms while processing updates for BGP (Border Gateway Protocol) NLRI (Network Layer Reachability Information). This is observed only in specific circumstances like the route is first learned from an external BGP peer and a BGP policy with more than 4000 terms of different IPv6 (Internet Protocol) prefixes is present on the system. The issue may be due to the larger number of match terms in BGP import policy, to avoid the issue the policy terms matching IP addresses are minimal.
1643178On all junos platforms, when a route is received with broadcast address as next-hop, the platform may not consider it as an invalid route and drop the traffic intended for the destination
Product-Group=evo
On all Junos platforms, in an eBGP scenario, if a route is received with a broadcast address next hop, it successfully programs it into the RIB (Routing Information Base), and eventually the route gets programmed into the FIB (Forwarding Information Base) as well. The treating of an invalid next hop as a valid one makes the platform try and fail when traffic for that route is received.
1648471An RPD crash was observed on all Junos platforms
Product-Group=evo
An rpd crash might be observed on all Junos platforms once the RPKI configuration is activated along with BGP SRv6 at the same time.
1655228An RPD process crash may be observed, when the received prefix count exceeds configured "prefix-limit"
Product-Group=evo
In all Junos and Junos Evolved platforms, when the BGP neighbor is brought down due to the received prefix count exceeding configured "prefix-limit" and if BGP disable and enable operation performed to bring the BGP session up then the "rpd" process crash might be observed.
PR NumberSynopsisCategory: EVO Layer-2 switching for BCM XGS Platforms
1650329QFX5130: Few macs will be missing from "show ethernet-switching table"
Product-Group=evo
During bulk mac move scenarios, we will see few mac entries are missing in RE CLI "show ethernet-switching table", even though those entries are present in Hardware. As mac is present in Hardware, there will not be any impact to packet forwarding.
PR NumberSynopsisCategory: EVO L3 routing for BCM XGS Platforms
1652873EVO QFX "EvoPfemand-main" process memory leak
Product-Group=evo
EVO QFX switch platforms may experience a memory leak in the "EvoPfemand-main" process. The memory leak was caused by a software fault while deleting mac addresses. The memory leak condition can be detectable by the cli "show system processes extensive no-forwarding".
PR NumberSynopsisCategory: PFE COS features on BT based platforms
1668861PTX10008 EVO : CoS cores due to invalid snmp index handling missing in iterator
Product-Group=evo
CoS cores due to invalid snmp index handling missing in iterator on PTX10008 EVO
PR NumberSynopsisCategory: Express BT PFE L3 Features
1657532The evo-aftmand-bt crash might be observed on EVO platforms
Product-Group=evo
On all EVO platforms, when the same firewall filter is applied to an ingress as well the egress direction, the evo-aftmand-bt crash might be observed, if the firewall filter is activated or deactivated a few times(4-5 times).
1657584PTX10008 EVO : Family MPLS Firewall filter not working on ingress
Product-Group=evo
PTX10008 EVO JNP10K-LC1201 line card does not support family MPLS firewall filter on egress due to hardware limitation. Although it is not supported on egress, we can configure it on the egress of an interface with 'fast-lookup-filter' option. If we switch the family MPLS filter configuration from egress to ingress, it will lose the functionality. This issue only occurs when the 'fast-lookup-filter' is attached to the ingress of an interface, because the option is not supported on ingress. The family MPLS firewall filter on ingress will recover the functionality by restarting the FPC on which the filter is configured. After code fix, 'fast-lookup-filter' is no-op on ingress family MPLS firewall filter, so that we can still configure the filter to the ingress.
1658839The packetio may core when router reboot or FPC reboot is triggered
Product-Group=evo
In case the main thread of packetio terminates, but AppService thread is still running, it may try to access global objects that might have been freed on termination of the main thread might result in packetio PFE process core.
PR NumberSynopsisCategory: DNX L2 related features
1651580On ACX7100/ACX7509 OAM link fault management (LFM) Discovery state is is not correct. Discovery state is either Active Send Local or Fault.
Product-Group=evo
On ACX7100/ACX7509 OAM link fault management (LFM) Discovery state is is not correct for some interfaces and discovery state is either Active Send Local or Fault.
PR NumberSynopsisCategory: FIB telemetry, fibtd, libocaft repositories
1662999PDT: Ondatra: network-instance name for streaming telemetry to be changed from default to DEFAULT to align with CONFIG stanza
Product-Group=evo
for ONDATRA test case which tested this with different network-instance names - DEFAULT. test is failing. for TEST to pass ,use network-instance names - default.
PR NumberSynopsisCategory: Firewall related development
1651411The firewalld process might crash when nested filters are used as input list
Product-Group=evo
On all Evo platforms, when nested firewall filters are applied as input-list and the sum of length of filter and term names exceed 124, firewalld process might crash and generate alarms. The filter might not get publsihed and might result in traffic being handled incorrectly.
PR NumberSynopsisCategory: Issues related to evo operations - libevo infra, typeinfo ..
1657797The rpd might fail on backup RE on EVO platforms
Product-Group=evo
On all EVO chassis platforms with NSR(Nonstop-routing) enabled, the rpd(routing protocol daemon) on backup RE might fail to start upon system bootup. This will impact the redundancy, as the routing might not happen on backup RE, if switchover happens.
PR NumberSynopsisCategory: System Management daemon and related issues
1589737PTX10008 EVO : CB goes into fault state if power-on cli is executed while node is powering off
Product-Group=evo
On PTX10008 EVO, CB goes into fault state if "request node power-on" CLI is executed while node is powering off. After code fix, power-on of node is not allowed if power-off was issued within last few minutes.
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1654140Configuring family MTU explicitly on an interface may cause host traffic to drop
Product-Group=evo
If a user configures the "family inet", "family inet6", or "family mpls" MTU values on an interface and the resulting MPLS MTU is greater than inet MTU, then MPLS host traffic (i.e., being generated by the RE) sent over an interface with problematic protocol MTU values may be dropped.
PR NumberSynopsisCategory: EVO RPD agent PRs
1652595The rpd agent crash might be triggered after the interface flap for the backup RE
Product-Group=evo
On all EVO chassis platforms, the interface flap may trigger the rpd agent crash. When the interfaces are flapped, a timing scenario can cause the backup routing process to crash. The service will self restore after the crash.
PR NumberSynopsisCategory: PR related to socket replication in EVO
1671458EVO NSR: Do not send unreplicate message to backup during switchover
Product-Group=evo
During swo, if unreplicate message reaches backup first before backup recovery on the connection is complete then it can lead to leaking the connection on the backup as well as recover does not happen on it. On subsequent switchover such connection may flap. The fix is highly recommended to be present in the image.
PR NumberSynopsisCategory: Express PFE FW Features
1668564BT - IPv6 Filter next-header match hop-by-hop next-header changes
Product-Group=evo
Next-header keyword for IPv6 filter has a change of behavior for BT platforms. The change came in as part of RLI-52460. Customers need to change the next-header keyword to payload-protocol keyword to match the backward compatible behavior. Next-header field is now matches the MX behavior (matches the first header of IPv6 extension headers.)
PR NumberSynopsisCategory: ISIS routing protocol
1617527The "rpd" core was observed during ISIS (Intermediate System to Intermediate System) instance deletion when SRMS (Segment Routing Mapping Server) server is configured with domain wide flooding
Product-Group=evo
On all Junos platforms and Junos Evolved platforms, "rpd" core was generated when SRMS server is configured with domain wide flooding and ISIS instance is deleted. It may impact control plane and cause a traffic impact.
PR NumberSynopsisCategory: PFE infra to support jvision for EVO
1640442[jvision] [jvisiontag] Verification of DB data collection is failing after executing the jvision decoder
Product-Group=evo
The system ID that is exported should be different for UDP and GRPC/GNMI. In the case of UDP, the system name should be appended with the local IP address.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1655177The "rpd" process may get crash when container Label Switch Path (LSP) is configured with "default-template"
Product-Group=evo
On all Junos and Junos Evolved platforms, if container LSP is configured in non-master instance with "default-template" and if normalization gets triggered then "rpd" may crash .
PR NumberSynopsisCategory: Multicast for L3VPNs
1647149The routing protocol process might stop working when de-activating and activating the same provider tunnel from one to another instance in a single commit
Product-Group=evo
On all platforms when de-activating and activating the same provider tunnel from one to another instance in a single commit, the routing protocol process might stop working.
PR NumberSynopsisCategory: OSPF routing protocol
1659366The memory leak and process rpd crash might be observed when the peer interface flaps continuously in the Segment Routing
Product-Group=evo
On all Junos and Junos OS Evolved platforms configured with Segment Routing, when the peer interface flaps continuously, the memory leak might be observed which might lead to the process rpd crash.
PR NumberSynopsisCategory: MPLS Point-to-Multipoint TE
1654226The route might stay Up though LSP is down after the primary LSP interface is administratively disabled
Product-Group=evo
After a link-protected LSP undergoes local reversion, the PLR reinstates local (link) protection successfully. However, the LP-MP does not properly detect that its Phop node has signaled itself as the PLR. This causes the downstream node not to properly consider itself as LP-MP. Hence, when there is a second failure on the same link connecting these two nodes, the LSP state is blown off from the downstream node. The downstream node deletes the LSP state and drops traffic arriving on the bypass.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Interface
1654459LACP sent IN SYNC to server facing interface when core-isolation is in effect
Product-Group=evo
In all Junos and Junos Evolved platforms, in the case of "core-isolation" is in effect, and if AE (AE with LACP) links between leaf and CE device flaps then, these flaps may enable LACP links during "core-isolation". This may cause CE to forward traffic to the node where the core is down.
PR NumberSynopsisCategory: RPD Interfaces related issues
1659102The rpd memory leak might be seen while processing vlan-ccc configuration
Product-Group=evo
On all Junos and Junos Evolved platforms, when deleting/adding the whole interface unit of family vlan-ccc, the rpd will observe a memory leak.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1623170BGP Flowspec might not show counters
Product-Group=evo
On all Junos and Junos Evolved platforms, when installing an IPv6 firewall filter using BGP flowspec, matching traffic counters may show "0" values.
1641297KRT queue entries are stuck during RE switchover when backup RPD is not yet ready.
Product-Group=evo
This is a rare scenario. In a dual RE setup, Assume the backup RPD has just started and re-syncing all states from FIB(Kernel). The backup RPD is not yet ready for switchover. If we do RE switchover manually via CLI or if any master RE HW crash occurs, We end up in not installing some of the FIB entries. The work around is to restart the RPD in new Master RE.
1660484Soft assertions in RPD will fail during GRES
Product-Group=evo
The issue is seen when doing GRES with flowspec configuration in all Junos and EVO platforms.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1659255The multipath route might be missing when multipath is configured
Product-Group=evo
On all Junos and Evolved platforms, when multipath is configured multipath computation is missed for the routes resulting in missing multipath routes.
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1658678The rpd crash might be triggered when the BGP route resolves over another BGP route
Product-Group=evo
On all Junos and EVO platforms, when the BGP route resolves over another BGP default route such that the default route is an EIBGP load-balanced route, then the resolution loop may go into infinite recursion leading to stack corruption and rpd core.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1644421An error might be observed while executing a commit for openconfig instance type
Product-Group=evo
On all Junos and Junos OS Evolved platforms, when configuring the network instance for openconfig, an error might be observed while executing a commit if the configured network instance type is "default_instance" but the instance name is not default.
PR NumberSynopsisCategory: PTX10K platform specific fabric PRs
1646617EVO: disable operational commands
Product-Group=evo
We disable commands which are not applicable to Junos Evolved platforms. See external description for detail
PR NumberSynopsisCategory: PTX10K Line Card specific interface PRs
1661215Channelized interface might go down if low-light-alarm/low-light-warning is enabled
Product-Group=evo
On Junos Evolved platforms or specific Junos platforms /linecards (MX304/MPC11/MPC12/LC2301/LC9600) equipped with QSFP-DD optics and if it has channelized interfaces, there might be chances for the channelized interface to immediately go down when either of knobs "low-light-alarm" or "low-light-warning" is enabled. The issue is expected to occur only when any other channel of same interface is down.
PR NumberSynopsisCategory: PTX10K specific platform PRs
1659377PTX10008 EVO : hwdre core is generated after RE switchover
Product-Group=evo
HWDRE core is generated after RE switchover on PTX10008 EVO if the chassis faces power shortage and SIB is powered down.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1633286The ppman process might crash and MPC cards will be stuck in the ISSU state when "Unified ISSU with Enhanced Mode" is performed
Product-Group=evo
On MX platforms, when "Unified In-Service Software Upgrade (ISSU) with Enhanced Mode" is performed, ppman crash may be seen and MPC10 and MPC11 cards will be stuck in the ISSU reboot state. The crash is seen if the node has both Link Aggregation Control Protocol (LACP) and Link Fault Management (LFM) sessions. Traffic loss might be seen due to the crash and wrong card state.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1643209Commit fails with message "statement does not match patch" due to TOD mismatches between Primary RE and Backup RE
Product-Group=evo
When time-zone for the router is set as EST5EDT and if the TOD (Time-Of-Day) values under "event-options generate-events" are modified in different time zones, that is TOD configurations created on EST time zones are getting modified in EDT time zone, then it can cause commit failures. When such commits happens at different time-zones, internally, it generates a patch file and tries to load the patch at both RE. But due to different time zone, it is not getting excepted by backup RE.
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1665131PTX10003 load balance v4_dscp and v6_dscp is enabled by default
Product-Group=evo
PTX10003 load balance v4_dscp and v6_dscp is enabled by default. This default behavior may cause traffic loss / out of order / retransmission to some application. To turn it off, please contact JTAC to get PFE commands to disable the hashing as there's no configuration knob to change this behavior. With the fix of this PR: 1. v4_dscp and v4_dp is set default as 0(disabled), config "hash-key family inet layer-4 type-of-service" will enable v4_dscp and v4_dp: set forwarding-options hash-key family inet layer-4 type-of-service 2. v6_dscp and v6_dp is set default as 0(disable), config "hash-key family inet6 layer-3 traffic-class" will enable v6_dscp and v6_dp set forwarding-options hash-key family inet6 layer-3 traffic-class
 
 

21.4R2-S1-EVO - List of Known issues

PR NumberSynopsisCategory: Border Gateway Protocol
1651211Delay in BGP session establishment due to longer time for the listening task to be ready on all platforms running "rpd"
Product-Group=evo
On all platforms running rpd, the longer time for the listening task to be ready might have the longest time for the active task to be created, resulting in BGP session delay establishment.
PR NumberSynopsisCategory: PTX10003 Interface related issues
1615000evo-aftmand process causing increase in memory utilization
Product-Group=evo
On some Junos and Junos Evolved platforms the evo-aftmand (Advanced Forwarding Toolkit manager) process might consume high memory over a period of time leading to an increase in the shared memory utilization. No service impact as confirmed by Dev.
PR NumberSynopsisCategory: PTX10003 Platform related issues
1560111EVO:JDI_FT_REGRESSION::[fabric][BRACKLA][fabrictagtag]:: [Traffic loss is seen after restarting the SIB]
Product-Group=evo
local switching traffic sequence number were not reset
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1628843After picd or rpdagent app restart multpile object-info anomalies for evo-pfemand are seen
Product-Group=evo
After picd or rpdagent app restart multpile object-info anomalies for evo-pfemand
PR NumberSynopsisCategory: management ethernet related issues - mgmt-ethd daemon
1648371IPv6 master-only IP address does not move to the new master RE after a switchover.
Product-Group=evo
IPv6 master-only IP address does not move to the new master RE after a switchover. As a workaround please deactivate and activate the master-only IPv6 address on the new master.
PR NumberSynopsisCategory: Junos Evolved socket replication
1660685RPD after kill -9 < bfd_pid>, seeing JSR backup registration failed for task BGP_64510.100.160.24.79 error: Returned Generic Error Invalid argument
Product-Group=evo
Without the PR fix, error logs from rpd/kernel corresponding to "JSR backup registration failed" may be observed during extreme scenarios of rpd restart etc, With the PR fix, however, the issue was seen., though the frequency of the issue has drastically come down and happens rarely. The issue is benign and self recovers with no impact expected on the connection or traffic. The right fix of the issue is in the latest master branch but it cannot be backported as there risk associated with the fix complexity.
PR NumberSynopsisCategory: PR related to socket replication in EVO
1669584PDT: MTU changes in UNI facing interface shows JSR backup registration failed with error:Returned Generic Error Invalid argument
Product-Group=evo
Without the PR 1660685 fix, error logs from rpd/kernel corresponding to "JSR backup registration failed" may be observed during extreme scenarios of rpd restart etc, With the PR 1660685 fix, however, the issue is still seen, though the frequency of the issue has drastically come down and happens rarely. The issue is benign and self recovers with no impact expected on the connection or traffic. The right fix of the issue is in the latest master branch but it cannot be backported as there risk associated with the fix complexity.
PR NumberSynopsisCategory: Configd, ffp issues
1647853The traffic might not flow after deleting/adding VLAN config with load override
Product-Group=evo
On Junos Evolved platforms, when vlan-bridge and corresponding logical interface is configured, a link is created between them. When the logical interface is deleted using the load-override method, the link information is not backed up in the system. When the same logical interface is re-created, the link creation might not happen. Delete the logical interface and re-create the same using load-update to recover from the issue.
PR NumberSynopsisCategory: EVPN control plane issues
1646722IFLs aren't created post Graceful RE switchover on guardian platform with EVPN services
Product-Group=evo
On performing Graceful RE swithchover on guardian platform with EVPN services, some IFLs are missing. IFLs come up post reboot.
PR NumberSynopsisCategory: Express PFE FW Features
1589296Addition/Removal/Modification of Firewall filter applied on lo0 interface in some scenarios may result in error messages with some packet drop for very short duration of time.
Product-Group=evo
On all PTX platforms running EVO, addition/deletion/modification of the firewall filter configuration applied on loopback interface in some scenarios (like change of one-pass to two-pass filters) might result in error messages with some packet drop for very short duration ,which would be self-recovered.
PR NumberSynopsisCategory: Label Distribution Protocol
1666568RPD crashes during "restart routing" if LDP periodic statistics collection is enabled
Product-Group=evo
RPD crashes during "restart routing" if LDP periodic statistics collection is enabled
PR NumberSynopsisCategory: KRT Queue issues within RPD
1612487On backup RE during GRES, you may see "RPD_KRT_KERNEL_BAD_ROUTE: krt unsolic client.128.0.0.5+62000: lost ifl 0 for route" warning messages
Product-Group=evo
Several warning messages show up while the RPD process restarts during performing GRES on a system running Junos EVO.
PR NumberSynopsisCategory: PTX10K RE EVO Issues
1668326console is not available - ttyS0.service: Failed with result 'start-limit-hit'
Product-Group=evo
when router console does not respond at times, then to recover run via ssh "systemctl restart serial-getty@ttyS0" . failure signature to confirm from ssh: systemctl status [email protected] * [email protected] - Serial Getty on ttyS0 Loaded: loaded (/lib/systemd/system/[email protected]; enabled; vendor preset: enabled) Drop-In: /etc/systemd/system/[email protected] `-serial.conf Active: failed (Result: start-limit-hit) since Fri 2022-05-13 14:44:29 UTC; 3 weeks 6 days ago Docs: man:agetty(8) man:systemd-getty-generator(8) http://0pointer.de/blog/projects/serial-console.html Process: 24674 ExecStart=/sbin/agetty -8 -L=never --keep-baud %I 9600 $TERM (code=killed, signal=HUP) Main PID: 24674 (code=killed, signal=HUP)
PR NumberSynopsisCategory: Virtual Private LAN Services
1655858The Pseudo Wires might go down in VPLS scenario
Product-Group=evo
On all Junos/Junos Evolved platforms with VPLS (virtual private LAN service) deployed, deactivating and activating the neighbour under the default mesh-group might lead Pseudo Wires(PW) to go down. This happens when there is a change in default mesh-group and that might not be updating the PW status. This can be recovered by deactivating and activating the complete routing instance under the mesh-group.
 

Modification History

  • 2022-07-18 Updated "Known Issue" by removing PR 1614171, and 1616065 from the known issue list. These PRs are fixed since 21.4R1-EVO but incorrectly marked as not fixed in 21.4R2-S1-EVO
  • First publication 2022-07-07