Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, EX, MX, NFX, PTX, QFX, SRX

Alert Description

Junos Software Service Release version 21.4R2-S1 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.4R2-S1 is now available.

21.4R2-S1 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 Platform
1655530The dc-pfe might crash due to the VCCP flap
Product-Group=junos
On all Junos EX and QFX platforms configured with Virtual Chassis (VC), with the Virtual Chassis Control Protocol (VCCP) flaps or any configuration change which causes VCCP to flap, might lead to the process dc-pfe crash.
PR NumberSynopsisCategory: EX2300/3400 PFE
1653260L2PT may not work for AE interfaces in Q-in-Q environment.
Product-Group=junos
This issue Affects all EX-2300,EX-3400,EX-4300MP,EX4600,EX4600-40F. L2PT may not work for AE interfaces in Q-in-Q environment.
PR NumberSynopsisCategory: EX2300/3400 platform
1649338The VC port might not be formed automatically after Zeroize
Product-Group=junos
On all EX3400/EX4400 platforms, the Virtual-Chassis (VC) port might not be formed automatically after executing the command "request system zeroize".
PR NumberSynopsisCategory: QFX Multichassis Link Aggregrate
1639713Traffic loss might be seen for the mac addresses learned on the ICL interface
Product-Group=junos
On all QFX platforms configured with Multichassis Link Aggregation Groups (MC-LAG), when the Interchassis Link (ICL) and mc-ae interfaces are flapped and BUM traffic is sent to mc-ae, some mac entries are learned on the ICL interface with flag DLR. This may cause traffic loss with certain traffic flow.
PR NumberSynopsisCategory: JUNOS kernel/ukernel changes for ACX
1639459Odin: When panic command issued, dump is complete, but while rebooting the box is stuck
Product-Group=junos
A missing component in the dump kernel prevented the ACX-710 from rebooting after dumping completed.
PR NumberSynopsisCategory: "agentd" software daemon
1657886The agentd and eventd process might cause high CPU utilization and may also affect Telemetry services
Product-Group=junos
On all Junos and Junos Evolved platforms, high CPU utilization is observed with the 'agentd' and 'eventd' processes. This is caused by 'rpd' issues.
1665516Na-grpcd process can core during longevity flap tests
Product-Group=junos
Due to race condition happening at the time of streaming and simultaneous disconnection of clients, na-grpcd can core at rare ocassions. This will cause temporary outage of streaming telemetry services. The service will self recover upon restart of the process.
PR NumberSynopsisCategory: Border Gateway Protocol
1626717The rpd dump file might be seen while processing the BGP updates
Product-Group=junos
The rpd crash files might be observed on Junos and Junos OS Evolved platforms while processing updates for BGP (Border Gateway Protocol) NLRI (Network Layer Reachability Information). This is observed only in specific circumstances like the route is first learned from an external BGP peer and a BGP policy with more than 4000 terms of different IPv6 (Internet Protocol) prefixes is present on the system. The issue may be due to the larger number of match terms in BGP import policy, to avoid the issue the policy terms matching IP addresses are minimal.
1643089The rpd crash files may be seen on MX and PTX platforms
Product-Group=junos
The rpd (routing process daemon) process might crash in the BGP (Border Gateway Protocol) rib-sharding scenario on all Junos and Junos Evolved MX and PTX platforms. The rpd crash may cause service impact. However, the rpd restarts and recovers by itself.
1643178On all junos platforms, when a route is received with broadcast address as next-hop, the platform may not consider it as an invalid route and drop the traffic intended for the destination
Product-Group=junos
On all Junos platforms, in an eBGP scenario, if a route is received with a broadcast address next hop, it successfully programs it into the RIB (Routing Information Base), and eventually the route gets programmed into the FIB (Forwarding Information Base) as well. The treating of an invalid next hop as a valid one makes the platform try and fail when traffic for that route is received.
1648471An RPD crash was observed on all Junos platforms
Product-Group=junos
An rpd crash might be observed on all Junos platforms once the RPKI configuration is activated along with BGP SRv6 at the same time.
1651211Delay in BGP session establishment due to longer time for the listening task to be ready on all platforms running "rpd"
Product-Group=junos
On all platforms running rpd, the longer time for the listening task to be ready might have the longest time for the active task to be created, resulting in BGP session delay establishment.
1655228An RPD process crash may be observed, when the received prefix count exceeds configured "prefix-limit"
Product-Group=junos
In all Junos and Junos Evolved platforms, when the BGP neighbor is brought down due to the received prefix count exceeding configured "prefix-limit" and if BGP disable and enable operation performed to bring the BGP session up then the "rpd" process crash might be observed.
1664168The v4 prefixes might not be advertised over the BGPv6 sessions
Product-Group=junos
On all MX platforms with BGP rib-sharding and update-threading configured, the v4 prefixes might not be advertised over the BGPv6 sessions.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1658839The packetio may core when router reboot or FPC reboot is triggered
Product-Group=junos
In case the main thread of packetio terminates, but AppService thread is still running, it may try to access global objects that might have been freed on termination of the main thread might result in packetio PFE process core.
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1663563Transit traffic drop was seen for BGP-LU(Border Gateway Protocol-Labeled Unicast) prefix on ACX5448/ACX710 when BGP-LU label routes has ECMP(Equal-Cost Multipath) forwarding path
Product-Group=junos
On ACX5448/ACX710, transit traffic drop is observed for BGP-LU prefix when ECMP is enabled. It is acting as a transit router between two routers and BGP-LU prefix route towards any of them has ECMP path. This issue may impact a forwarding plane and cause a traffic impact.
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1642383Flowd crash when back to back sigpack is updated at the time of stress traffic
Product-Group=junos
The flowd might crash when back to back sigpack is updated when heavy traffic is going on.
PR NumberSynopsisCategory: EX4400 PFE software
1663126SSH traffic might be affected when filter log action is used
Product-Group=junos
On EX4400 and EX4100 platforms, when a filter is configured with log action, Secure Shell (SSH) packet might hit queue 15 where it will be discarded after logging causing SSH to fail.
PR NumberSynopsisCategory: Express pfe Mclag
1666399Static MACs are not programmed after reboot, resulting in floods of unicast traffic
Product-Group=junos
After rebooting, we see that the link does not have a static MAC address. This results in unicast traffic flooding and sometimes traffic drops for this static MAC.
PR NumberSynopsisCategory: Express ASIC platform
1643743Observed the alarmd core in PTX router after loading the baseline configuration
Product-Group=junos
Under some circumstances, alarmd will core due to some discrepancy in Junos-sync component.
PR NumberSynopsisCategory: ISIS routing protocol
1617527The "rpd" core was observed during ISIS (Intermediate System to Intermediate System) instance deletion when SRMS (Segment Routing Mapping Server) server is configured with domain wide flooding
Product-Group=junos
On all Junos platforms and Junos Evolved platforms, "rpd" core was generated when SRMS server is configured with domain wide flooding and ISIS instance is deleted. It may impact control plane and cause a traffic impact.
PR NumberSynopsisCategory: Firewall Network Address Translation
1645039Datapath daemon might crash resulting in total traffic and service failure
Product-Group=junos
On all SRX-Series devices, when policy configuration is modified and committed multiple times while the device is handling MS-RPC traffic with more than 1000 RPC port map entries present in the device, it may result in datapath daemon crash.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1632932[SNMP] Whenever snmp get request is performed with multiple OIDs and a few OID requests are for invalid tunnels (tunnels which are not present), ?No Such Instance currently exists at this OID? is received even for valid tunnels.
Product-Group=junos
[SNMP] Whenever snmp get request is performed with multiple OIDs and a few OID requests are for invalid tunnels (tunnels which are not present), "No Such Instance currently exists at this OID" is received even for valid tunnels.
PR NumberSynopsisCategory: Platform infra to support jvision
1628807Interface sensor data may not be decoded on line cards (MPC10E/MPC11/MPC12/LC9600) and Junos Evolved platforms
Product-Group=junos
On MX platforms having line cards (MPC10E/MPC11/MPC12/LC9600) and Junos Evolved platforms, the interface sensor data might not be decoded.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1658869The license might get out of sync between master and backup RE
Product-Group=junos
On all Junos OS Evolved platforms, the license might get out of sync between master and backup RE after the Routing Engine (RE) switchover.
PR NumberSynopsisCategory: Multicast Listener Discovery
1656311The rpd process crash might be observed with PIM configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if the interface is enabled with Protocol Independent Multicast (PIM) (enables Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) implicitly) and the same interface is configured under a non-forwarding instance, then the process rpd crash might be observed.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1655177The "rpd" process may get crash when container Label Switch Path (LSP) is configured with "default-template"
Product-Group=junos
On all Junos and Junos Evolved platforms, if container LSP is configured in non-master instance with "default-template" and if normalization gets triggered then "rpd" may crash .
1659340LSPs are getting stuck in a down state after deactivating/activate protocol BGP
Product-Group=junos
On all Junos and EVO platforms, when deactivating and activating protocol BGP it impacts the dynamic MVPN P2MP LSPs to stuck in the down state which leads to MVPN traffic loss.
1664670Dynamic label space usage crossed the threshold limit of 90 percent
Product-Group=junos
On all Junos and EVO platforms, in warm standby mode, when the MPLS route is learnt on the standby, a label was allocated. As protocols are not running it will not be automatically synced/mirrored. But in case the route is deleted, this was not deallocated back and will result in traffic loss.
PR NumberSynopsisCategory: Multicast for L3VPNs
1617620[mvpn] QFX10k : Auto-RP is going down after some time on QFX10k in NGMVPN scenario
Product-Group=junos
Auto-RP packets arriving on LSI interface was not handled in case of QFX, because of which only the first packet was getting punted to CPU and the rest packets were getting discarded at Network Input because the eth header and mpls header was getting stripped off. To handle this case we have added a new sequence type for ucode instruction for AUTO-RP packets.
1647149The routing protocol process might stop working when de-activating and activating the same provider tunnel from one to another instance in a single commit
Product-Group=junos
On all platforms when de-activating and activating the same provider tunnel from one to another instance in a single commit, the routing protocol process might stop working.
PR NumberSynopsisCategory: MX Timing software
1660844Transit PTP over IP packet drop might be observed on an AE interface
Product-Group=junos
On Junos MX/EX/SRX platforms with specific line cards e.g. MPC2E-NG, 3E-NG, 5E,6E,7E,8E,9E, LC2101, when Precision Time Protocol (PTP) over IP encapsulation is configured, there might be transit PTP packet drop when reconfiguring child interfaces of an Aggregate-Ethernet (AE) bundle from one FPC to the other. This issue might be restored by deactivating and activating PTP stream.
PR NumberSynopsisCategory: IPv6/ND/ICMPv6 issues
1635867IPv6 route advertisement sent on management interfaces might cause other devices to fail to get the dhcpv6 address
Product-Group=junos
On all Junos platforms, if ZTP (Zero Touch Provisioning) is used, the dhcpv6 address might not be received when IPv6 route advertisement is sent on management interfaces without having the managed-configurations.
PR NumberSynopsisCategory: OSPF routing protocol
1659366The memory leak and process rpd crash might be observed when the peer interface flaps continuously in the Segment Routing
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with Segment Routing, when the peer interface flaps continuously, the memory leak might be observed which might lead to the process rpd crash.
PR NumberSynopsisCategory: MPLS Point-to-Multipoint TE
1652439P2MP LSP flaps after the MVPN CE facing interface goes down
Product-Group=junos
On all Junos and EVO platforms, P2MP (Point-to-Multipoint) LSP (Label-Switched Paths) which is configured as a static provider tunnel for (S,G) in an MVPN (Multicast Virtual Private Network) instance may flap when the MVPN CE (Customer Edge) facing interface goes down and intermittent traffic loss might be observed.
1654226The route might stay Up though LSP is down after the primary LSP interface is administratively disabled
Product-Group=junos
After a link-protected LSP undergoes local reversion, the PLR reinstates local (link) protection successfully. However, the LP-MP does not properly detect that its Phop node has signaled itself as the PLR. This causes the downstream node not to properly consider itself as LP-MP. Hence, when there is a second failure on the same link connecting these two nodes, the LSP state is blown off from the downstream node. The downstream node deletes the LSP state and drops traffic arriving on the bypass.
PR NumberSynopsisCategory: Express Chip L3 software
1663881ALB stats not showing in CLI
Product-Group=junos
Adaptive [Load Balancing] Statistics are not updated under 'show interfaces aeX extensive' on the QFX10k platform.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1660369QFX : OSPF Flow Check function violating RFC6864
Product-Group=junos
QFX is using IPv4 ID field for a OSPF flow check function, but it is violating RFC6864.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1659533Traffic loss might be seen when a VxLAN port is recovering from a failure
Product-Group=junos
On all Junos platforms, the Virtual Extensible LAN (VxLAN) port goes to Spanning Tree Protocol (STP) BLK state when the port is down and takes a while to go back to the FWD state when the link is up. Traffic loss is seen in this case.
1662515BUM traffic received on CE interface will loopback to ingress interface after removing EVPN VXLAN FRR config (reroute-address)
Product-Group=junos
BUM traffic received on CE interface will loopback to ingress interface after removing EVPN VXLAN FRR config (reroute-address)
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1667952QFX5100VC SNMP : jnxPowerSupplyFailure and jnxPowerSupplyOK are not getting generated for Backup FPC
Product-Group=junos
On QFX5100VC, jnxPowerSupplyFailure and jnxPowerSupplyOK are not getting generated for Backup FPC.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Interface
1654459LACP sent IN SYNC to server facing interface when core-isolation is in effect
Product-Group=junos
In all Junos and Junos Evolved platforms, in the case of "core-isolation" is in effect, and if AE (AE with LACP) links between leaf and CE device flaps then, these flaps may enable LACP links during "core-isolation". This may cause CE to forward traffic to the node where the core is down.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1653723Port might be down after inserting specific SFP
Product-Group=junosvae
On QFX5100-48S platforms with QFX-5e img and 10G interface, insertion of transceivers- SFP-SX or SFP-LX10 into a 1G port might make other neighbour 10G ports down, affecting the related traffic.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1634495Traffic loss might be observed on EX4650-48Y and QFX5120-48Y switches when there is a link flap
Product-Group=junos
On EX4650-48Y and QFX5120-48Y switches when there is a link flap, the link/interface might take more than expected time to come up resulting in increased traffic loss.
1658568QFX5120: "request system power-off" doesn't work and vmcore is generated
Product-Group=junosvae
On QFX5120 platform, "request system power-off" doesn't work and system will be rebooted. At that time, vmcore is generated.
1659453The slave PTP device will not lock its clock with the master PTP device
Product-Group=junos
On all Junos platforms, when a slave Precision Time Protocol (PTP) member that used one IPV6 address went for a reboot and came back with another IP address via Dynamic Host Configuration Protocol (DHCP), which can end up in multiple entries for the same source port.
PR NumberSynopsisCategory: Related to sw defects for K2-RE
1662913The watchdog timeout is encountered and the system reboots after the 'request system halt' command executed
Product-Group=junos
On all platforms with RE-1800 & RE-2000, after the 'request system halt' command is executed, the watchdog timeout is encountered and causes the routing engine (RE) to fail to boot.
PR NumberSynopsisCategory: RPD Interfaces related issues
1639134The dynamic tunnel might flap every 15 mins with a non-forwarding route
Product-Group=junos
On all Junos and Junos Evolved platforms, the dynamic tunnel might flap every 15 mins when a non-forwarding route is resolving over the dynamic tunnel. The non-forward route resolution on a dynamic tunnel route might not be successful. As the route resolution is having impact, traffic drop might be seen in peer nodes.
1659102The rpd memory leak might be seen while processing vlan-ccc configuration
Product-Group=junos
On all Junos and Junos Evolved platforms, when deleting/adding the whole interface unit of family vlan-ccc, the rpd will observe a memory leak.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1623170BGP Flowspec might not show counters
Product-Group=junos
On all Junos and Junos Evolved platforms, when installing an IPv6 firewall filter using BGP flowspec, matching traffic counters may show "0" values.
1641297KRT queue entries are stuck during RE switchover when backup RPD is not yet ready.
Product-Group=junos
This is a rare scenario. In a dual RE setup, Assume the backup RPD has just started and re-syncing all states from FIB(Kernel). The backup RPD is not yet ready for switchover. If we do RE switchover manually via CLI or if any master RE HW crash occurs, We end up in not installing some of the FIB entries. The work around is to restart the RPD in new Master RE.
1660484Soft assertions in RPD will fail during GRES
Product-Group=junos
The issue is seen when doing GRES with flowspec configuration in all Junos and EVO platforms.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1659255The multipath route might be missing when multipath is configured
Product-Group=junos
On all Junos and Evolved platforms, when multipath is configured multipath computation is missed for the routes resulting in missing multipath routes.
1668481The BGP multipath might not install some of the available next-hops
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with BGP multipath, if the number of BGP paths available for multipath is greater than the maximum-ecmp configured (default 16), multipath might not install some of the next-hops. This might lead to an undesired ECMP load-balancing of traffic.
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1658277Some L3VPN prefixes are not active because nexthop is not usable
Product-Group=junos
If preserve-nexthop-hierarchy knob was deconfigured and if no-propagate-ttl config within VRF is opposite to global config,some routes can be inactive. Secondary nexthops may not be resolved and active, hence L3VPN routes are not active.
1658678The rpd crash might be triggered when the BGP route resolves over another BGP route
Product-Group=junos
On all Junos and EVO platforms, when the BGP route resolves over another BGP default route such that the default route is an EIBGP load-balanced route, then the resolution loop may go into infinite recursion leading to stack corruption and rpd core.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1644421An error might be observed while executing a commit for openconfig instance type
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when configuring the network instance for openconfig, an error might be observed while executing a commit if the configured network instance type is "default_instance" but the instance name is not default.
PR NumberSynopsisCategory: Resource Reservation Protocol
1667708Transit LSR might stop sending RESV msg if there is no RRO in the LSP's PATH message
Product-Group=junos
On all Junos and Junos Evolved platforms, if the ingress router is from a different vendor and the PATH message doesn't have RRO (RECORD_ROUTE object), the Junos devices will not process such packets, and the tunnel remains down.
1670638Premature RSVP Path Error BW-Unavailable originated by PLR
Product-Group=junos
With the "rsvp local reversion" configuration a PLR originates the "Bw_unavailable PathErr" during FRR (Fast Reroute). Junos Label Edge Router (LER or ingress router) ignores this type of PathErr message. However, this can be a problem if an ingress LER implementation reacts to this PathErr by bringing down the protected LSP causing packet loss.
PR NumberSynopsisCategory: PTX10K platform specific fabric PRs
1646617EVO: disable operational commands
Product-Group=junos
We disable commands which are not applicable to Junos Evolved platforms. See external description for detail
PR NumberSynopsisCategory: SW PRs for SCBE3 fabric
1658206The CPU usage SPMB can hit 100% for a short while
Product-Group=junos
This issue is seen on the MX20XX platform the CPU usage SPMB can hit 100% for 10 or 20 seconds.
PR NumberSynopsisCategory: security-intelligence feature on SRX
1638923Kernel panic might be seen during boot
Product-Group=junos
On Junos platforms kernel panic might be seen during the boot sequence.
PR NumberSynopsisCategory: ZT/YT pfe CDA issues
163258521.4R1.2 - RESET PFE - Single hop BFD session over AE stuck at INIT after "reset PFE"
Product-Group=junos
It is noted that the single hop BFD session over AE is not fully functional after exercising PFE reset feature. The BFD session was up before PFE reset operation is initiated but after the reset the BFD rx session is not fully functional.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1633286The ppman process might crash and MPC cards will be stuck in the ISSU state when "Unified ISSU with Enhanced Mode" is performed
Product-Group=junos
On MX platforms, when "Unified In-Service Software Upgrade (ISSU) with Enhanced Mode" is performed, ppman crash may be seen and MPC10 and MPC11 cards will be stuck in the ISSU reboot state. The crash is seen if the node has both Link Aggregation Control Protocol (LACP) and Link Fault Management (LFM) sessions. Traffic loss might be seen due to the crash and wrong card state.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1658017AFT sensor UDP output not decodable using Junos Proto file.
Product-Group=junos
UDP Telemetry output fields may misalign on AFT-based line cards such as MPC10/11 or Junos Evolved platform.
1669559AFT daemon might crash on the device when prefix length is zero
Product-Group=junos
All AFT-based platforms with zero prefix-length configured will observe crashes in the advanced forwarding toolkit process.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1614480Filter related service will not work when the filter is deleted/re-added frequently for AE interface
Product-Group=junos
On MX platforms, during reboot, the AE ifls are first added, then deleted and again added, this flapping causes corner case where the filter attachment ipc has older AE ifl index on which the filter bind fails. Filter will not be attached to the interface, so any filter related service will not work.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1631217The core interface goes down
Product-Group=junos
Using static LSP(labeled switched path) configuration, the child node is not removed from the flood composite when the core interface goes down.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1659783The device might reboot post configuration commit confirm
Product-Group=junos
The user cannot enter the request system reboot command once the user schedules a commit operation with commit confirmed configuration.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1624562The core files may not get deleted using CLI "file delete /var/core/*/vmcore*"
Product-Group=junos
File delete with regex may fail, if using filename without regex it works.
1643209Commit fails with message "statement does not match patch" due to TOD mismatches between Primary RE and Backup RE
Product-Group=junos
When time-zone for the router is set as EST5EDT and if the TOD (Time-Of-Day) values under "event-options generate-events" are modified in different time zones, that is TOD configurations created on EST time zones are getting modified in EDT time zone, then it can cause commit failures. When such commits happens at different time-zones, internally, it generates a patch file and tries to load the patch at both RE. But due to different time zone, it is not getting excepted by backup RE.
PR NumberSynopsisCategory: usf nat related issues
1632278DSLite not working on MX platform installed with MPC7E line card and SPC3 service PIC.
Product-Group=junos
DSLite not working on MX platform installed with MPC7E line card and SPC3 service PIC.
 
 

21.4R2-S1 - List of Known issues

PR NumberSynopsisCategory: EX4300 routing implementation
1655654EX4300-48MP does not generate ICMPv6 too big messages
Product-Group=junos
Few EX platforms may not generate ICMPv6 too long messages which could cause the path MTU (maximum transmission unit) discovery to fail. As a result, IPv6 session establishment may fail.
PR NumberSynopsisCategory: IPSec Group VPN implementation common for Junos and SRX plat
1566044Continuous Deactivate/activate of security config can lead to process restart
Product-Group=junos
When Deactivate/Activate of security configuration is executed continuously, there are instances in which when gkmd process can core while the process exits.
PR NumberSynopsisCategory: NFX Series Platform Software
1659161With NFX3, CLI responses may be slow depending on CLI commands
Product-Group=junos
n nfx-3, Junos/JCP runs in a virtual machine on top of Linux (WRL) hypervisor and JDM is run inside a docker container. When a Junos CLI is run, the CLI is run on Junos or JDM or on both, depending on the type of CLI. This applies to both operational commands and configuration commits. Most of the CLIs that are handled by JDM as well as some CLIs that are handled by Junos, require actions to be performed on, or data to be mined from, the host/hypervisor. The communication among Junos, JDM and hypervisor is through ssh and internal bridges. Because of this architecture, the CLI operations take some time which in turn also depends on the type of CLI.
PR NumberSynopsisCategory: "agentd" software daemon
1665516Na-grpcd process can core during longevity flap tests
Product-Group=junos
Due to race condition happening at the time of streaming and simultaneous disconnection of clients, na-grpcd can core at rare ocassions. This will cause temporary outage of streaming telemetry services. The service will self recover upon restart of the process.
PR NumberSynopsisCategory: MX Layer 2 Forwarding Module
1663717Traffic loss is observed in the VPLS scenario after the upgrade
Product-Group=junos
On all Junos platforms with VPLS configuration, traffic loss is observed due to failure in ARP resolution. The ping fails for devices configured on VPLS after the upgrade.
PR NumberSynopsisCategory: BBE Autoconfigured DVLAN related issues
1626558The autoconf might not work if the DHCPv4 Discover message has option 80 (rapid commit) ahead of option 82
Product-Group=junos
If in the client's DHCP discover packet there has option 80 ahead of option 82, the auto-configure feature can not extract the subscriber's ACI (Agent Circuit-ID) and ARI (Agent Remote-ID). This leads to authentication failure when creating the Dynamic VLAN interface where option 82 is requested.
1643863[subscriber_services] [all] : :JDI-REG-SUBSCRIBER_SERVICES:mx480:DHCP:Verify dhcp client count failed and 64k DHCPv4 subscribers are not bound as expected count
Product-Group=junos
On DHCP Subscribers stacked over AutoConf (dynamic) Vlans shows subscriber summary different count that actual DHCP bindings.
PR NumberSynopsisCategory: BBE Layer-2 Bitstream Access
1652337The L2BSA subscribers may not be able to browse due to incorrect entries in the VPLS mac-table
Product-Group=junos
On All Junos platforms, a few L2BSA(Layer 2 Bit Stream Access) subscribers with specific S-VLAN (stacked VLAN) allocated from a specified VLAN range may face issues with traffic forwarding due to incorrect/duplicate entries which might block the genuine subscribers. When this happens, subscriber traffic could be dropped.
PR NumberSynopsisCategory: Border Gateway Protocol
1635018The BGP family route-target might not work in hierarchical Route Reflector scenario
Product-Group=junos
On all Junos and EVO platforms, BGP family route-target (RT) might not work in a hierarchical Route Reflector (RR) scenario, when the same RT is used, route might be rejected as there is a loop.
1648471An RPD crash was observed on all Junos platforms
Product-Group=junos
An rpd crash might be observed on all Junos platforms once the RPKI configuration is activated along with BGP SRv6 at the same time.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1635143The rpd may crash due to memory pressure for high BGP scale with flapping route and BGP Monitoring Protocol (BMP) collector/station is very slow on all Junos and EVO platforms
Product-Group=junos
On all devices running Junos OS or Junos OS Evolved, where this is a high BGP scale with flapping route and the BGP Monitoring Protocol (BMP) collector/station is very slow, the rpd process might crash due to memory pressure.
PR NumberSynopsisCategory: BBE Remote Access Server
1655832JDI-RCT:BBE:Authd core@thr_kill () at thr_kill.S:3
Product-Group=junos
During ISSU upgrade, intermittent AUTHD core is seen. Core does not have a functional impact
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1629943When root login is disabled, FPCs can become unresponsive after upgrade to 21.4
Product-Group=junos
For ACX5448, MX204 and MX2008 "VM Host-based" platforms, starting with Junos 21.4R1 or later, ssh and root login is required for copying line card image (chspmb.elf for MX2008) from Junos VM to Linux host during installation. The ssh and root login are required during installation. Use "deny-password" instead of "deny" as default root-login option under ssh config to allow internal trusted communication. Ref https://kb.juniper.net/TSB18224 [juniper.net]
PR NumberSynopsisCategory: Class of Service
1666010Creating AE interfaces in per-unit-scheduler mode and committing COS config on AE IFLs in a single commit can lead to race-conditions
Product-Group=junos
The AE interfaces in per-unit-scheduler mode and committing COS config on AE IFLs in a single commit leads to race-conditions.
PR NumberSynopsisCategory: Firewall Filter
1573350Traffic drop seen and filter not hitting as expected for match condition traffic class with FLT option configured
Product-Group=junos
When the "fast-lookup-filter" statement is configured with a match that is not supported in the FLT hardware, traffic might be lost.
PR NumberSynopsisCategory: dhcpd daemon
1649638The jdhcpd daemon might crash after Junos upgrade
Product-Group=junos
On all MX platforms, jdhcpd core dumps might observed when using legacy DHCP feature with pseudowire interface after the Junos upgrade.
PR NumberSynopsisCategory: Firewall support for DNX
1648968If a firewall has a log action and it's applied on physical interface or lo0, the LDP can't go up
Product-Group=junos
On ACX5448 platform, if a firewall has a log action and it's applied on physical interface or lo0, the LDP neighbor can't go up.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1620705Dvaita:SUBLC:ISSU: fabric/Destination errors seen after ISSU is done on GNF without enhanced-mode
Product-Group=junos
fabric/Destination errors will be seen when ISSU is done on GNF without enhanced-mode. This is seen with and without SLC Config
PR NumberSynopsisCategory: EX4400 PFE software
1659384port/mac gbp tags may not be carried forward to the spine
Product-Group=junos
port/mac gbp tags may not be carried forward to the spine
PR NumberSynopsisCategory: EX4400 platform
1658798VCP ports might not be created by default when system is booted from PXE
Product-Group=junos
When an EX4400 switch is booted using network install / PXE, the VCP ports might not get created. User has to reboot the system once again using cli "request system reboot" for the VCP ports to get created.
PR NumberSynopsisCategory: Express PFE FW Features
1651546Transit traffic might get dropped and protocols might be down when firewall filters are modified
Product-Group=junos
On all PTX and QFX platforms except QFX5k, a change operation in firewall filters might lead to drops observed in transit packets. When the issue hits, we might face connectivity issues and protocols going down. This is a timing issue and hard to reproduce.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1621998AR:Firewall: percentage physical-interface policer is not working on AE, after switching between baseline config to policer config.
Product-Group=junos
Percentage physical-interface policer is not working on AE, after switching between baseline config to policer config
PR NumberSynopsisCategory: IDP policy
1657056The flowd core might be observed when IDP policy rulebase changes
Product-Group=junos
A change in IDP lsys policy configuration while the system is processing traffic may cause a flowd coredump in rare cases.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1629345Inter vlan ipv6 traffic loss for some hosts after configuration remove and restore.
Product-Group=junos
For a topology with VSTP and VRRP configured and IPV6 traffic, if VSTP bridge priority is changed a couple of times (to trigger toggling of root bridge), it is possible that V6 traffic drop is seen on some of the streams.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1655140The Juniper secure connect VPN users may face login issues intermittently
Product-Group=junos
On SRX Series devices, when using the Juniper Secure Connect VPN client with Radius authentication for login requests, users may get the PAP (password authentication protocol) and CHAP (Challenge Handshake Authentication Protocol) authentication failure error message. When this happens, VPN connections might not be established all the time even though the number of IPs in the address pool is greater than supported remote-access users.
PR NumberSynopsisCategory: PFE infra to support jvision
1627752"agentd_telemetry_uninstall_sensor: Deleting subscription from daemon aftsysinfo failed after mgmt_sock_retries 601, ret -1" error message seen after stopping jtimon
Product-Group=junos
On DUT with scaled MPLSVPN config and jvision sensors configured, stream of error messages "agentd_telemetry_uninstall_sensor: Deleting subscription from daemon aftsysinfo failed after mgmt_sock_retries 601, ret -1" is seen on stopping jtimon. Sensor packet drops may be seen when the error message scrolls on DUT
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1650597Inter DC ARP request packet will be dropped in DC-GW enabled with Port mirroring configs
Product-Group=junos
Inter DC ARP request packet will be dropped in DC-GW enabled with Port mirroring configs
PR NumberSynopsisCategory: Multiprotocol Label Switching
1655177The "rpd" process may get crash when container Label Switch Path (LSP) is configured with "default-template"
Product-Group=junos
On all Junos and Junos Evolved platforms, if container LSP is configured in non-master instance with "default-template" and if normalization gets triggered then "rpd" may crash .
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1646428USF_IPSEC: Post GRES, VM cores are seen on new master and backup REs.
Product-Group=junos
When multihop multipath EBGP is configured over IPSEC tunnels established using SPC3, vmcores are seen
PR NumberSynopsisCategory: Kernel Multicast Infrastructure
1653920Traffic blackhole might be seen due to next-hop install failure on Junos PTX platforms
Product-Group=junos
On Junos PTX platforms there might be a traffic blackhole which happens because of next-hop installation failure for multicast RSVP(Resource Reservation Protocol) P2MP(Point to Multipoint) traffic. This issue might only be encountered in a scaled RSVP P2MP environment after a network event which might cause reconvergence.
PR NumberSynopsisCategory: Kernel Stats Infrastructure
1629930JDI-RCT: AlfaRomeo:Bugatti: %KERN-7: if_pfe_msg_handler: pfe_peer_msg_handler error: 2 for msg type 10, msg subtype 6, opcode 2 and peer index 0 errors seen on provisioning test configs
Product-Group=junos
Below IPC timeouts logs can be seen for statistics query to kernel(queried from cli or daemons querying internally)when there is config churn, or large number of IPCs getting exchanged between kernel and pfe in the system. if_pfe_msg_handler: pfe_peer_msg_handler error: for msg type , msg subtype , opcode and peer index Default IPC timeout value in kernel for IPC statistics request is 10s. This can be incremented to larger value by setting below hidden config to avoid IPC timeout errors. # set system stats-timeout-lifetime 15 # commit
PR NumberSynopsisCategory: vMX Data Plane Issues
1669261VMX crash as result of riot out of memory condition, reporting Interrupted thread 30 TTP Transmit.
Product-Group=junos
VMX crash as result of riot out of memory condition, reporting Interrupted thread 30 TTP Transmit. The memory leak can be observed when checking RSI for pool-0 values. request support information | match pool-0 - Pool-0 Values below 2000 are suspect memory problem.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1641297KRT queue entries are stuck during RE switchover when backup RPD is not yet ready.
Product-Group=junos
This is a rare scenario. In a dual RE setup, Assume the backup RPD has just started and re-syncing all states from FIB(Kernel). The backup RPD is not yet ready for switchover. If we do RE switchover manually via CLI or if any master RE HW crash occurs, We end up in not installing some of the FIB entries. The work around is to restart the RPD in new Master RE.
PR NumberSynopsisCategory: Issue related to mcnh routing infrastructure within RPD
1663568The forwarding plane is not updated properly in scaled MVPN scenario after receiving PIM leave messages
Product-Group=junos
On all Junos and Junos Evolved platforms, when IFLs from non-default routing instances are being added with the OIF scaling of more than 2000 there will be a spillover of IFLNHs into different next hops due to this the outgoing interfaces (OIFs) will not be deleted from multicast next-hop.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1583245The next hop of static LSP for MPLS might get stuck in dead state after changing the network mask of the outgoing interface
Product-Group=junos
With static label-switched path (LSP) for MPLS configured with next hop and multiple interface address (IFA) are configured on an interface, the next hop might get stuck in dead state when changing the network mask and keeping the IP address unchanged for the outgoing interface through which the LSP next hop is reachable.
PR NumberSynopsisCategory: Resource Reservation Protocol
1670638Premature RSVP Path Error BW-Unavailable originated by PLR
Product-Group=junos
With the "rsvp local reversion" configuration a PLR originates the "Bw_unavailable PathErr" during FRR (Fast Reroute). Junos Label Edge Router (LER or ingress router) ignores this type of PathErr message. However, this can be a problem if an ingress LER implementation reacts to this PathErr by bringing down the protected LSP causing packet loss.
PR NumberSynopsisCategory: PTX10K platform specific fabric PRs
1646617EVO: disable operational commands
Product-Group=junos
We disable commands which are not applicable to Junos Evolved platforms. See external description for detail
PR NumberSynopsisCategory: SW PRs for SCBE3 fabric
1657378The low priority stream may get stuck and all traffic might be dropped
Product-Group=junos
On MX-Series devices, the low priority stream might be marked as a destination error and as a result, the low priority stream is stuck and all traffic might get dropped.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1657176SR-TE LSP state might go down due to "Compute Result failure"
Product-Group=junos
On all Junos and Junos OS Evolved Platforms, the node index in the link key is short and cannot hold when the node's index is more than 32 bits long. Once this index exceeds its limitation, SR-TE (Segment Routing-Traffic Engineering) LSP might go down due to "Compute Result failure".
PR NumberSynopsisCategory: SRX Argon module
164666121.3R2:SRX_RIAD:srx1500,srx4200:SKYATP:IMAP/IMAPS Email permitted counter is not incremented in AAMW email statistics while testing whole email block.
Product-Group=junos
The SKYATP:IMAP/IMAPS Email permitted counter may have incorrect value under certain conditions.
PR NumberSynopsisCategory: MX10002 Platform SW - Platform s/w defects
1637756Syslog error @Err] MQSS(0): DRD: Error: WAN reorder ID timeout error - Valid 1, Reorder ID 0 after loading image.
Product-Group=junos
Packets may reach the lookup ASIC before the ASIC programming is completed. This causes the ASIC error "MQSS: DRD: Error: WAN reorder ID timeout".
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1636785FRR loss of around 18- 20 seconds seen during LAG bundle failure triggers with scaled configuration
Product-Group=junos
FRR loss of around 18- 20 seconds seen during LAG bundle failure triggers with scaled configuration
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1624219The AE bundle might not be active for 5-10 mins till LACP converges for the given bundle
Product-Group=junos
In a scaled setup with LDP over RSVP configuration and maximum-ecmp as 32 or 64, line card CPU usage can remain high for extended duration on link flap operation. In this duration, LACP might take 5+ minutes to converge and the AE bundle to be active.
1631612[Indus][Daniel][mx10008] 100% CPU Utilization for ~20 mins on Indus and Daniel cards with FIT configuration after any negative trigger
Product-Group=junos
In scaled setup with high number of nexthops and routes, a config churn could lead to high cpu utilization and delayed convergence for Indus and Daniel MPC linecards
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1602536Observed memory leak in eventd leak during GRES
Product-Group=junos
A minor memory leak is seen in the event-daemon process when multiple GRES switchovers are performed.
PR NumberSynopsisCategory: VMHOST platforms software
1646339The alarm might not be generated for EDAC errors until the FPC is rebooted
Product-Group=junos
On all MX and PTX platforms, EDAC errors are triggered but alarms are not observed until the FPC gets rebooted due to the data corruption in hardware.
PR NumberSynopsisCategory: usf nat related issues
1579627USP-SPC3: While configuring /8 pool with blk size as 1, syslog RT_NAT_POOL_MEMORY_SHORTAGE is generated, but the re outputs for source nat pool and source nat port-block shows empty
Product-Group=junos
This issue is caused by /8 pool with block size as 1, when the config is committed the block creation utilizes more memory causing NAT pool memory shortage which is currently being notified to customer with syslog tagged RT_NAT_POOL_MEMORY_SHORTAGE.
1646822NAT session reverse traffic fails due to NAT routes getting deleted from routing instance.
Product-Group=junos
With overlapping NAT pool configured with different NAT rules under different service sets, when service outside interface is moved between different routing instances (EX: from vr1 to default, and from default to vr1), NAT routes corresponding to the service-set in default routing instance are getting deleted, resulting in reverse path traffic failure for NAT sessions.
PR NumberSynopsisCategory: Unified Services Framework
1644579Stateful sync failing between active and backup MX chassis
Product-Group=junos
Stateful sync failing between active and backup MX chassis because active chassis might not detect TCP connection down.
PR NumberSynopsisCategory: usf traffic load balancing relared issues
1624572flowd core observed with TLB configuration only with combination of MPC10 card with older MPC card.
Product-Group=junos
This issue only occurs with MPC10 and other MPC(MPC3) both are online. The problem not occur if the older MPC is offline or not present.

 

Modification History

First publication 2022-07-23