Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, EX, MX, NFX, PTX, QFX, SRX, vSRX

Alert Description

Junos Software Service Release version 20.2R3-S5 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 20.2R3-S5 is now available.

20.2R3-S5 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 PFE
1590037HEAP malloc(0) is seen with base configurations
Product-Group=junos
On EX4300 Series platforms, if the ukern malloc function is invoked with size 0, the malloc call might have the potential for heap memory corruption in the caller code.
PR NumberSynopsisCategory: EX4300 Platform
1623215Traffic loss might be seen when the interface fails to verify the parameter "LOCAL-FAULT"
Product-Group=junos
On all EX4300 platforms( excluding EX4300-MP), when the interface fails to verify the interface parameter "Local-fault", traffic loss might be seen.
1655530The dc-pfe might crash due to the VCCP flap
Product-Group=junos
On all Junos EX and QFX platforms configured with Virtual Chassis (VC), with the Virtual Chassis Control Protocol (VCCP) flaps or any configuration change which causes VCCP to flap, might lead to the process dc-pfe crash.
PR NumberSynopsisCategory: EX4300 routing implementation
1655654Few EX platforms does not generate ICMPv6 too big messages
Product-Group=junos
Few EX platforms may not generate ICMPv6 too long messages which could cause the path MTU (maximum transmission unit) discovery to fail. As a result, IPv6 session establishment may fail.
PR NumberSynopsisCategory: EX2300/3400 PFE
1653260L2PT may not work for AE interfaces in Q-in-Q environment.
Product-Group=junos
This issue Affects all EX-2300,EX-3400,EX-4300MP,EX4600,EX4600-40F. L2PT may not work for AE interfaces in Q-in-Q environment.
PR NumberSynopsisCategory: EX2300/3400 platform
1649338The VC port might not be formed automatically after Zeroize
Product-Group=junos
On all EX3400/EX4400 platforms, the Virtual-Chassis (VC) port might not be formed automatically after executing the command "request system zeroize".
PR NumberSynopsisCategory: QFX Multichassis Link Aggregrate
1639713Traffic loss might be seen for the mac addresses learned on the ICL interface
Product-Group=junos
On all QFX platforms configured with Multichassis Link Aggregation Groups (MC-LAG), when the Interchassis Link (ICL) and mc-ae interfaces are flapped and BUM traffic is sent to mc-ae, some mac entries are learned on the ICL interface with flag DLR. This may cause traffic loss with certain traffic flow.
PR NumberSynopsisCategory: QFX PFE CoS
1650051The fixed classifier may not work in MPLS and VXLAN scenario
Product-Group=junos
On QFX5100 platforms, traffic may not get classified based on a fixed classifier in MPLS as well as the VXLAN scenario.
PR NumberSynopsisCategory: QFX PFE MPLS
1665778Transit MPLS traffic can get dropped on the QFX5120 P router.
Product-Group=junosvae
FLAP of RSVP link protection LSP creates the stale entries in the QFX5120 PFE LABEL swap table. This PFE table size is 16k and once it will hit the limit genuine MPLS Label will fail to program and traffic hitting the failed ingress label will get black holed.
PR NumberSynopsisCategory: Sflow on QFX 5100,5200, 5110
1598239Sflow impacts on ICMP traffic on QFX5XXX platforms
Product-Group=junos
On QFX5XXX platforms in sflow scenario, CPU/host bound ICMP traffic from or to the sampled interface might be dropped, which might have impact on services based on ICMP probes like RPM.
PR NumberSynopsisCategory: MX Layer 2 Forwarding Module
1647660The "jnxL2aldMacNotificationMIBObjects" does not work on certain Junos and EVO platforms
Product-Group=junos
On all Junos and Evo platforms, this issue was seen when executing a CLI command to read "jnxL2aldMacNotificationMIBObjects" without enabling the mac-notification variable.
PR NumberSynopsisCategory: A15 specific issue
1617103Execute RSI on SRX5K platform with IOC2 card installed may trigger data plane failover
Product-Group=junos
On SRX5K platforms with 19.4R1 or newer version, if the I/O card (IOC2) line card is installed, data plane failover might be triggered on executing every request system information (RSI), which might impact traffic.
PR NumberSynopsisCategory: a20a40 specific issue
1648850Fabric Board reset with an error message may be observed on certain Junos platforms
Product-Group=junos
On some Junos platforms, a major alarm may be raised for Fabric and Control Board, while there is not actually a hardware error present. This issue might impact the SRX with SCB4, MX platforms with SCB3 and EX9200 series with SF3. This is a timing issue and the system will self recover but there might be a momentary service impact.
PR NumberSynopsisCategory: BBE Layer-2 Bitstream Access
1652337The L2BSA subscribers may not be able to browse due to incorrect entries in the VPLS mac-table
Product-Group=junos
On All Junos platforms, a few L2BSA(Layer 2 Bit Stream Access) subscribers with specific S-VLAN (stacked VLAN) allocated from a specified VLAN range may face issues with traffic forwarding due to incorrect/duplicate entries which might block the genuine subscribers. When this happens, subscriber traffic could be dropped.
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1646846The bbe-statsd daemon might crash after ISSU
Product-Group=junos
On all MX platforms with the subscriber management scenario, when ISSU happens from pre 18.4 to post 18.4, subscribers that re-logged in pre 18.4 are called preNG subscribers. For any of the preNG subscribers, if the ipv4/ipv6 family interface goes up/down, the issue is triggered.
PR NumberSynopsisCategory: BBE Remote Access Server
1667002CoA-NAK might not be sent for a coa-request-retry of the same service
Product-Group=junos
On Junos MX platforms with BBE deployment, a service request is sent via CoA from RADIUS (Remote Authentication Dial-In User Service) server. If the RADIUS server resends the same request, it should be responded with a NACK. However, CoA-NACK might not be sent for a coa-request-retry of the same service/subscriber. Instead, the packets were dropping silently.
PR NumberSynopsisCategory: ACX VxLAN Issue
1665828MAC-IP bindings for IPv4 (ARP) and IPv6 (ND) may not be processed for IRB interfaces in an EVPN scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, when EVPN (Ethernet Virtual Private Network) related configuration is introduced from baseline, due to a rare timing issue between the IRB (Integrated Routing and Bridging) interfaces coming up and an attempt is made by the 'l2ald' (l2 address learning) daemon to process the corresponding MAC-IP entries, this issue may occur. This may also occur when IRB logical units are activated and deactivated.
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1642383Flowd crash when back to back sigpack is updated at the time of stress traffic
Product-Group=junos
The flowd might crash when back to back sigpack is updated when heavy traffic is going on.
PR NumberSynopsisCategory: AF interface in Node Virtualization
1602531Junos OS: MX Series with MPC11: In a GNF / node slicing scenario gathering AF interface statistics can lead to a kernel crash (CVE-2022-22207)
Product-Group=junos
A Use After Free Vulnerability in the Advanced Forwarding Toolkit (AFT) manager process (aftmand) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a kernel crash due to intensive polling of Abstracted Fabric (AF) interface statistics and thereby a Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA69711 [juniper.net] for more information.
PR NumberSynopsisCategory: EVPN control plane issues
1659786The process rpd might crash when protocol EVPN is deactivated
Product-Group=junos
On all Junos and Junos OS Evolved platforms, with multiple activating/deactivating Ethernet Virtual Private Network (EVPN) or deactivating the Virtual Routing and Forwarding (VRF) instance with protocols EVPN for type 5 route, the process rpd might crash.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1611699Modifying (add/del/change) the attributes (for eg, vlan id, encapsulation, protocols, mac/mac-ip limit etc) of routing-instance or default-switch will cause re-incarnation of routing instance/switch
Product-Group=junos
Any change in attribute of routing instance or default-switch may cause route deletion and addition due to deletion and addition of routing-instance or default-switch
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1649841In EVPN-VxLAN environment, non-VxLAN traffic might be dropped if VxLAN and non-VxLAN traffic share the same ECMP next-hop
Product-Group=junos
On Junos QFX platforms, in Ethernet VPN-Virtual Extensible LAN (EVPN-VxLAN) environment, non-VxLAN packets might be dropped if VxLAN and non-VxLAN traffic are sharing the same Equal Cost Multi-Path (ECMP) next-hop. Traffic drop might be seen for all L3 unicast routes which share ECMP links with the VxLAN routes.
PR NumberSynopsisCategory: IDP policy
1657056The flowd core might be observed when IDP policy rulebase changes
Product-Group=junos
A change in IDP lsys policy configuration while the system is processing traffic may cause a flowd coredump in rare cases.
PR NumberSynopsisCategory: MX Inline Jflow
1652901The syslog errors and PPE traps might be observed
Product-Group=junos
On MS-MPC/MPC-3D/MPC1/MPC1E/EX9200-40T/EX9200-40F/SRX5K-SPC-4-15-320/SRX5K-MPC/SRX5K-MPC3-100G10G/SRX5K-MPC3-40G10 linecards, syslog errors and PPE(Packet Forwarding Engine) traps might be observed due to exhaustion of NH partition of memory.
PR NumberSynopsisCategory: jdhcpd daemon
1651768DHCP packets might not be sent to the clients when 'forward-only' is reconfigured under the routing instance
Product-Group=junos
On EX9200, and EX4300 platforms, when 'forward-only' is reconfigured under the routing instance, after deleting the configuration, Dynamic Host Configuration Protocol (DHCP) packets might not be sent to the clients.
PR NumberSynopsisCategory: jl2tpd daemon
1667861L2TP session might not come up when L2TP access-line-information is not configured
Product-Group=junos
When MX platform running JUNOS enhanced subscriber management feature as LNS (L2TP network server) receives DSL/PON attributes from LAC (L2TP access concentrator) and "services L2TP access-line-information" switch is not configured, the l2TP session might be disconnected.
PR NumberSynopsisCategory: Flow Module
1601806On SRX-Series devices using Unified Policies with IPv6, when attempting to reject certain dynamic-applications a flowd core could be generated
Product-Group=junos
On SRX-Series devices using Unified Policies with IPv6, when attempting to reject certain dynamic-applications a flowd core could be generated.
PR NumberSynopsisCategory: SRX Firewall Authentication
165112922.1R1:AUTH:unable to get the "firewall-authentication users" details on node 1
Product-Group=junos
Functionality Impact - Authentication entries will not be synced to secondary node in the HA setup and when switchover happens, already established authentication sessions will be lost and clients will have to login again with authentication credentials.
PR NumberSynopsisCategory: Firewall Network Address Translation
1645039Datapath daemon might crash resulting in total traffic and service failure
Product-Group=junos
On all SRX-Series devices, when policy configuration is modified and committed multiple times while the device is handling MS-RPC traffic with more than 1000 RPC port map entries present in the device, it may result in datapath daemon crash.
PR NumberSynopsisCategory: Firewall Policy
1653413Unified policy url-category does not work when "application-system-cache security-services" is enabled.
Product-Group=junos
On SRX series platform, unified policy url-category does not work when "application-system-cache security-services" is enabled.
PR NumberSynopsisCategory: User Firewall related issues
1637548Unable to connect to domain controller on installing Microsoft KB update
Product-Group=junos
On all SRX platforms, when the User Identification feature is used with Active Directory, after the Domain Controller server installs updates related to Microsoft's KB article KB5004442 [juniper.net], SRX is no longer able to connect to it.
PR NumberSynopsisCategory: Layer 2 Control Module
1647000Traffic loop might occur due to STP ports not created in new master RE after switchover due to reboot of master RE on EX4300, EX3400, and EX2300 platforms in Virtual Chassis (VC) scenario
Product-Group=junos
On EX4300, EX3400, and EX2300 platforms in Virtual Chassis (VC) scenario, when GRES and NSB are configured, after switchover due to master RE reboot, STP ports will not be created for interfaces part of old master RE that underwent reboot.
PR NumberSynopsisCategory: lacp protocol
1635935Traffic loss may be seen on QFX10K due to congestion
Product-Group=junosvae
During congestion PPMAN(Periodic packet management) run short of resource leading to PDUs (Protocol Data Units) getting failed to be sent. Due to PPMAN queue starvation across TX/RX path, LACP sessions may not get a chance to transmit PDUs which can further lead to peer lacp timeout, aggregated ethernet interface flap and traffic loss.
1640240Aggregated Ethernet interface remains up instead of down after deleting loopback and ae interface ip on neighbor while verifying BFD sessions on router
Product-Group=junos
Aggregated Ethernet child interfaces with LACP configurations are not timing out even if peer is gone and not sending any bridge protocol data unit (BPDU).
PR NumberSynopsisCategory: lldp sw on MX platform
1669677LLDP neighborship might fail if the chassis-id format of the LLDP packet is xx:xx:xx:88:8e:xx
Product-Group=junos
On all Junos platforms, Link Layer Discovery Protocol (LLDP) neighborship fails if the chassis-id format of the LLDP packet is xx:xx:xx:88:8e:xx.
PR NumberSynopsisCategory: Jflow and sflow on MX
1550140Sflow asks for license upon config commit.
Product-Group=junos
Sflow asks for license upon config commit.
PR NumberSynopsisCategory: Track Mt Rainier RE platform software issues
1656746The configuration of management interface might not work
Product-Group=junos
On NG-RE (Next Generation Routing Engine) based platforms with Linux version WRL9 and LTS19, after system reboot the management interface configurations might not be applied to the interface.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1644616GARP reply doesn't update ARP entry though gratuitous-arp-reply option is configured.
Product-Group=junos
Receiving GARP reply doesn't help update ARP entry though gratuitous-arp-reply option is configured. As a result, traffic loss might be seen depending on the timing.
PR NumberSynopsisCategory: "ifstate" infrastructure
1642172Junos OS: RIB and PFEs can get out of sync due to a memory leak caused by interface flaps or route churn (CVE-2022-22209)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a Denial of Service (DoS).Please refer to https://kb.juniper.net/JSA69713 [juniper.net] for more information.
PR NumberSynopsisCategory: Kernel Multicast Infrastructure
1555274Multicast traffic in MVPN setup might be blackholed on some PTX platforms acting as transit LSR
Product-Group=junos
On PTX3000/PTX5000/PTX10008/PTX10016 platforms in MVPN setup with aggregated Ethernet(AE) having 2 interfaces on 2 different PFE's, if protocol status of one AE member interface goes down (mBFD Down or disabling lacp on the peer), but physical state remains Up, multicast traffic might be blackholed.
1653920Traffic blackhole might be seen due to next-hop install failure on Junos PTX platforms
Product-Group=junos
On Junos PTX platforms there might be a traffic blackhole which happens because of next-hop installation failure for multicast RSVP(Resource Reservation Protocol) P2MP(Point to Multipoint) traffic. This issue might only be encountered in a scaled RSVP P2MP environment after a network event which might cause reconvergence.
PR NumberSynopsisCategory: Kernel MPLS / Tag / P2MP Infrastructure
1654798RE kernel crash might be observed in the one-hop-LSP MPLS scenario with RE outbound traffic if 'routing-option resolution preserve-nexthop-hierarchy' is configured globally
Product-Group=junos
On all Junos platforms, if 'routing-option resolution preserve-nexthop-hierarchy' is configured globally, Routing-engine (RE) kernel crash might be observed in the one-hop-LSP Multiprotocol Label Switching (MPLS) scenario with RE outbound traffic.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1609630BFD over GRE tunnel interface stuck in "init" state with GRES enabled
Product-Group=junos
On all JUNOS platforms, when disabling the physical interface where GRE tunnels is established and performing a GRES (Graceful Routing Engine Switchover). After GRES, enabling the physical interface will cause BFD to become stuck in init state.
PR NumberSynopsisCategory: OSPF routing protocol
1659366The memory leak and process rpd crash might be observed when the peer interface flaps continuously in the Segment Routing
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with Segment Routing, when the peer interface flaps continuously, the memory leak might be observed which might lead to the process rpd crash.
PR NumberSynopsisCategory: Express Chip L3 software
1629200The vmhost crash might be seen in a rare condition when route addition and change
Product-Group=junos
On some QFX/PTX platforms, when route addition and change, in a rare condition, an invalid hash index value might be calculated and cause vmhost crash.
1649586Junos OS: PTX Series: FPCs may restart unexpectedly upon receipt of specific MPLS packets with certain multi-unit interface configurations (CVE-2022-22202)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability on specific PTX Series devices, including the PTX1000, PTX3000 (NextGen), PTX5000, PTX10002-60C, PTX10008, and PTX10016 Series, in Juniper Networks Junos OS allows an unauthenticated MPLS-based attacker to cause a Denial of Service (DoS) by triggering the dcpfe process to crash and FPC to restart. On affected PTX Series devices, processing specific MPLS packets received on an interface with multiple units configured may cause FPC to restart unexpectedly. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://kb.juniper.net/JSA69706 [juniper.net] for more information.
1663881ALB stats not showing in CLI
Product-Group=junos
Adaptive [Load Balancing] Statistics are not updated under 'show interfaces aeX extensive' on the QFX10k platform.
PR NumberSynopsisCategory: vMX Platform Infrastructure related issue tracking
1634908LACP interface might go down when a sub-interface configuration is added and committed to the AE interface
Product-Group=junos
On all MX150 platforms, when an Aggregate Ethernet (AE) interface is configured with LACP and adding a sub-interface configuration under the AE interface causes the LACP down leads to traffic loss.
PR NumberSynopsisCategory: QFX5K hostpath
1615447The packet drop might be seen when packet size exceeds 9000 MTU
Product-Group=junosvae
On QFX platforms where Packet Forwarding Engine (PFE) is running in lxc container and EX4650, packet drop might be observed if the packet size is greater than 9000 MTU (Maximum Transmission Unit).
1630201LACP timeout might be observed during high CPU utilization
Product-Group=junos
On QFX5100 switches, when the CPU utilization (Routing Engine and FPC) is 85 percentage or more and there are multiple Network Configuration Protocol (NETCONF) sessions running or SNMP polling is happening over multiple sessions simultaneously, the LACP session configured in fast mode might timeout.
PR NumberSynopsisCategory: QFX L2 PFE
1546572The dcpfe process might crash on QFX10K platforms
Product-Group=junos
On QFX10K platforms the dcpfe might crash if with traffic bring all SIBs offline and then bring them online, it also might happen during the reboot of FPC.
1558128The MAC addresses learned in a Virtual Chassis might fail due to aging out in the MAC scaling environment
Product-Group=junos
On EX2300, EX3400, EX4300, and EX4600 switches and the QFX5000 line of switches, the MAC addresses learned in a Virtual Chassis might fail due to aging out in the MAC scaling environment where a large number of MAC addresses are learned. This issue was observed with 280000 MAC entries in the Virtual Chassis devices.
1602318EVPN/VXLAN arp-suppression does not respond to ARP request when VLAN ID under interface (IFL) is different with VLAN ID under vlan (BD) in SP style.
Product-Group=junos
When VLAN ID under interface (IFL) is different with VLAN ID under vlan (BD), EVPN/VXLAN arp-suppression does not respond to ARP request. In the following example, when ARP packet with vlan 1918 is received on ae0, the proxy arp does not respond to the ARP request.
1626011The third 802.1Q tag might not be pushed onto the stack in the Q-in-Q tunneling
Product-Group=junos
In the Q-in-Q tunneling scenario, when dual VLAN tagged multicast packets (e.g., OSPF protocol packets) are received into a C-VLAN interface with an 'input-VLAN-map push' configuration, the VLAN swap operation will be done instead of the push operation. This issue could cause the packets to egress the S-VLAN interface with two VLAN tags instead of three VLAN tags
1629680Traffic might get dropped when "family ethernet-switching" is configured on the interface in Q-in-Q scenario
Product-Group=junos
In Q-in-Q scenario, traffic starts getting dropped when "family ethernet-switching" is added to ingress interface, which is already configured with "encapsulation extended-vlan-bridge". This is due to incorrect port setting in hardware.
1649637The local-minimum-links feature not working as expected on QFX5100 VC platforms
Product-Group=junos
On the QFX5100 VC(Virtual-Chassis) platform, the AE(Aggregated Ethernet) interface might not go down on a single interface flap in the bundle even though the knob "local-minimum-links" is configured on the device.
1650416L2PT configuration on a transit switch in a Q-in-Q environment breaks L2PT
Product-Group=junos
L2PT on a transit switchs like Ex4600 and QFX in a Q-in-Q environment breaks L2PT for other S-VLANs if uplink is AE (Aggregated Ethernet) interface.
1652976The inner tag (C-tag) value might get modified to zero for egress traffic when the inner tag values are copied to the outer tag (S-tag)
Product-Group=junos
On all QFX5120 and EX4650 Junos platforms, when priority bits (P-bits) in C-tag are copied to S-tag in the switch, and then the C-tag is reset to 0.
1660787CoS might not get applied on VC ports
Product-Group=junosvae
CoS configs are not getting applied on vcp port in QFX5100 VC.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1564787QFX 5100 VC/VCF : Observing Error log for (pkt trace rx Ucast lpbk) (rcv pkt cb called port 1 pkt_len 68 cos 15 higig)
Product-Group=junos
In QFX5100 VC/VCF, we may see the below logs in the syslog messages. These messages are the debugging logs and does not have any functional impact. The logs appear due to wrong categorization of syslog level for the below messages. Dec 18 21:47:49 [TRACE] [Sat Dec 19 05:43:21.807 LOG: Err] rcv pkt cb called port 1 pkt_len 68 cos 15 higig 0xfb1b0069 0x2080000 0x8000000 0xe0690200 Dec 18 21:47:49 [TRACE] dc 10 0e 7e b6 b1 c2 00 00 00 00 82 dc 10[Sat Dec 19 05:43:22.159 LOG: Err] (pkt trace rx Ucast lpbk) rx port 13 queue 15 len 68 rx untagged = 0 hwtoken = 105
1573047A traffic loop might be observed after the VCP interface flap
Product-Group=junos
Traffic loop might be seen on QFX5K VCF (Virtual Chassis Fabric) when VCP (Virtual Chassis Port) cable is reseated. This is a rare issue and hard to reproduce. It might also lead to traffic loss when the issue happens.
1650335Traffic Loss will be observed with Virtual-Router
Product-Group=junos
In EX4K and QFX5K platforms, traffic loss will be observed with virtual-router function.
PR NumberSynopsisCategory: QFX MPLS PFE
1666760BGP-LU traffic might be dropped when "CCNH ingress labeled-bgp inet" is configured
Product-Group=junos
On Junos PTX platforms, the native inet packet might not be forwarded correctly when "Chained Composite Next-Hop (CCNH) ingress labeled-bgp inet" is configured. PFE wrongly adds Label 3 to the incoming inet packet and sent the MPLS frame to the edge device where it fails.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1645929An interface might be detached from LACP when configuring VLAN tagging in the EVPN-VXLAN scenario on Junos QFX5K platforms
Product-Group=junos
On Junos QFX5K platforms, the LACP packet might get intercepted and the interface detached from LACP when configuring VLAN tagging in the EVPN-VXLAN scenario.
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1611354The ports might remain in downstate on QFX5K platforms
Product-Group=junosvae
In a rare scenario, if the upgrade is being performed or ports are continuously flapped on QFX5K platforms, then interfaces might remain in downstate and need to reset in order to restore it.
1661349VC in unstable state for 3-7 minutes causing traffic loss
Product-Group=junos
EX4600 and QFX5100-24Q devices VC(Virtual-chassis) is in unstable state for 3-7 minutes causing traffic loss.
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1667952QFX5100VC SNMP : jnxPowerSupplyFailure and jnxPowerSupplyOK are not getting generated for Backup FPC
Product-Group=junos
On QFX5100VC, jnxPowerSupplyFailure and jnxPowerSupplyOK are not getting generated for Backup FPC.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Interface
1629637The interface on the peer device might remain up even after disabling the 10G interface on the Juniper device
Product-Group=junos
On QFX5120-48T and QFX5120-48Y platforms, after disabling the 10G interface on the device the interface on the peer device might remain up.
1657534Cannot fetch the interface FEC details after disabling/enabling interface
Product-Group=junos
On Junos platforms, on the QFX5200-32C-32Q platform, on disabling and enabling interfaces, the Fast Ethernet channel (FEC) might mismatch and the FEC details link might not come up.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1653723Port might be down after inserting specific SFP
Product-Group=junosvae
On QFX5100-48S platforms with QFX-5e img and 10G interface, insertion of transceivers- SFP-SX or SFP-LX10 into a 1G port might make other neighbour 10G ports down, affecting the related traffic.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1622580LED indicator might be showing 'ON' status once QSFP is removed.
Product-Group=junos
LED indicator might show ?ON' status when QSFP enabled with channelized port is removed. This issue is seen on EX or QFX platforms like EX4600/4650, QFX5100/5110/5120/5210 and QFX10002-36Q/10002-72Q/QFX10008. This is a display issue. There is no service impact when this issue occurs
1634495Traffic loss might be observed on EX4650-48Y and QFX5120-48Y switches when there is a link flap
Product-Group=junos
On EX4650-48Y and QFX5120-48Y switches when there is a link flap, the link/interface might take more than expected time to come up resulting in increased traffic loss.
1646894Restarting one of the FPCs may cause traffic loss in QFX VC scenario
Product-Group=junosvae
On QFX with the Virtual Chassis (VC) scenario, when traffic coming into master FPC and going out from the backup FPC, reboot the backup FPC, the master FPC still thinks the backup link is present, and "show lacp interface" also continues showing the backup link as collecting / distributing. Therefore, master FPC continues sending the echo reply through the backup link which fails since the backup is powered off, which might lead to a traffic drop.
PR NumberSynopsisCategory: QFX5K Timing software
1600807QFX5200: Observed dcpfe core-dump while testing ISSU from 21.1R1.11 to 21.2R1.7
Product-Group=junosvae
High Risk in Fixing this issue. SW upgrade does happens but dcpfe is cored once. Functionality impact may be: Links flap, which may have a slight traffic drop. None other known so far.
PR NumberSynopsisCategory: Related to sw defects for K2-RE
1662913The watchdog timeout is encountered and the system reboots after the 'request system halt' command executed
Product-Group=junos
On all platforms with RE-1800 & RE-2000, after the 'request system halt' command is executed, the watchdog timeout is encountered and causes the routing engine (RE) to fail to boot.
PR NumberSynopsisCategory: Routing Information Protocol
1660424A policy with a policy action "community" configuration may not work
Product-Group=junos
On all Junos and Evolved platforms, when a policy with policy action "community set/add/delete" is configured and the same policy is imported under Routing Information Protocol(RIP) protocol, community configuration may not work.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1498087Traffic loss might be seen if the routing instance is deactivated and then re-activated quickly
Product-Group=junos
In a routing instance with table next hop scenario (e.g., if EVPN routing instance is configured, the l2ald process creates a routing table and the EVPN adds a route pointing to this table as table next hop in the rpd process), if the routing table created within the routing instance is deleted and then re-added (e.g. deactivated and then re-activated the routing instance) very fast before the rpd can delete the route pointing to the table next hop, then the route in the rpd uses the staled table next hop, resulting in traffic loss. Sampling the configuration that delays the route deleting in the rpd increases the possibility of hitting the issue.
1578111The KRT queue might get stuck during GRES RE switchover
Product-Group=junos
The KRT queue might get stuck during the GRES RE switchover. This issue will occur when rpd gets rtm_change for a next-hop from the kernel while switchover is in progress when rpd (task) has become master, but KRT is still in backup state.
1583249The rpd in backup might core and restart
Product-Group=junos
On all Junos and Evolved platforms, the rpd in the backup may core and restart when the forwarding-table is deleted.
PR NumberSynopsisCategory: Resource Reservation Protocol
1637645The rpd memory leak may be observed in a subscriber management environment with RSVP
Product-Group=junos
On MX platforms, in subscriber management environment with Psuedowire Headend Termination (PWHT) configured, when the subscribers are added and deleted, the memory leak in rpd process may be observed. The creation and deletion of demux interfaces will cause this issue with Resource Reservation Setup Protocol (RSVP) configured. The system will run out of memory eventually, causing the rpd crash when the new memory is requested.
1640918When the primary path goes down MPLS LSP does not use the most preferred path after the primary path restoration
Product-Group=junos
On all JUNOS and JUNOS Evolved platforms supporting RSVP-TE(Resource Reservation Protocol-Traffic Engineering), when the primary path goes down the MPLS(Multi-Protocol Labeled Switching) LSP(Label Switched Path) switches to an alternate path and LSP does not prefer the IGP(Interior Gateway Protocol) path even when the optimal primary link is restored. This issue may be encountered on 18.1R1 and higher with no-cspf(constrained shortest path first) LSP with no configured ERO(Explicit Route Objects) & fast-reroute. To avoid the issue the MPLS LSP should be cleared via CLI(Command Line Interface).
PR NumberSynopsisCategory: SW PRs for SCBE3 fabric
1612957The PFE/SIB/SCBE/FPCs might reboot due to the unexpected fabric errors shown up on MX240/480/960 platforms
Product-Group=junos
In MX240/480/960 platforms with SCBE3-MX and Enhanced midplane scenario, in some rare cases, if flooding huge traffic from MPC7/MPC8/MPC9 to MPC2E/MPC3E/MPC4E/MPC5E and flapping the interface on MPC2E/MPC3E/MPC4E/MPC5E, it will cause the unexpected request time errors on MPC7/MPC8/MPC9 since the MPC2E/MPC3E/MPC4E/MPC5E might not be able to handle such high volume of requests, it will cause PFE destinations to become unreachable even when the fabrics are online. Then PFE/SIB/SCBE/FPCs might reboot automatically while these accumulated fabric errors hit the fabric connectivity restoration conditions of the Fabric Healing process (FHP).
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1635882IPsec tunnel may not establish after a flap
Product-Group=junos
IPsec tunnel may not establish after a flap if the remote end is aggressively retrying and sending many IKE requests.
PR NumberSynopsisCategory: SRX Argon module
1610260Enabling security-metadata-streaming-policy might cause PFE crash
Product-Group=junos
On SRX-Series firewall, in some rare occasions, enabling security-metadata-streaming-policy on zone pair based policy might cause packet forwarding engine (PFE) crash and lead to disconnections during PFE reboot.
PR NumberSynopsisCategory: SRX RTCOM module bugs
1588593Updates were made to RTCOM to reduce its overall memory usage, improving holistic scale of Layer-7 services
Product-Group=junos
Updates were made to RTCOM to reduce its overall memory usage, improving holistic scale of Layer-7 services
PR NumberSynopsisCategory: security-intelligence feature on SRX
1638923Kernel panic might be seen during boot
Product-Group=junos
On Junos platforms kernel panic might be seen during the boot sequence.
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1651526PCS Errored blocks count increments after Junos software upgrade
Product-Group=junos
20.2R1 and later release has introduced firmware version for PHY chip on some MIC and PIC models. After that migration, some of the 100GE ports on MIC/PIC or its peer devices would see PCS and framing errors.
1655088BFD may flap when the hold down/up timer is configured
Product-Group=junos
It takes a while for traffic to resume after the Link fault has been resolved.
PR NumberSynopsisCategory: MX10002 Platform SW - Platform s/w defects
1631010,The FPC might crash after enabling MACsec
Product-Group=junos
On MX10003/MX2K with MPC8/9 line cards/PTX10001-20C/ACX6360 platforms, when MACsec (Media Access Control Security) is enabled on ports, FPC might crash with PFEMan (PFE Management) core, which would impact the related traffic. However, the issue could be self-recovered. The issue could be very rare.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1630408Index of the link might get missed in the distribution table of PFEs after the flap
Product-Group=junos
On MX platforms with the scenario of BGP and BFD running, it might bring ECMP links up and down which might impact traffic distribution and keep one of the ECMP links unused.
PR NumberSynopsisCategory: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1645505FPC crash might occur during ISSU upgrade
Product-Group=junos
On MX/EX/SRX platforms, FPC crash might be observed during ISSU (In-Service Software Upgrade)upgrade in specific line cards (eg MPC9/8/7).
1652416LMEM Parity Error in shared LMEM are not handled properly
Product-Group=junos
When the linecard boots up, any LMEM HW error affecting one of 'high zones' (addr > 3072) will trigger the issue.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1633825The linecard crash might be observed in a Subscriber scenario
Product-Group=junos
On all Junos platforms except with MPC10 or later, enabled with interface sensors on subscriber interfaces over an Aggregated Ethernet(AE), the linecard crash might be observed if a new member interface is added to an AE interface for an existing subscribers running the interface sensors or a line card is started. This is a timing issue.
1636579DHCP offer not getting processed in the routing instance when using LT interfaces
Product-Group=junos
On MX platforms with Trio chipset, DHCP will not work in case of DHCP relay configured under "vrf" with LT interface, this may affect services for hosts.
1647214DHCP Subscriber traffic might get dropped due to the rpf-check filter
Product-Group=junos
On all Junos platforms running BroadBand Edge(BBE) subscribers, when the rpf-check CLI knob is present in the configuration but the Reverse Path Forwarding (RPF) feature is not getting applied to certain subscribers which leads to DHCP subscriber traffic drop.
1668976Traffic loss might be observed for the multicast traffic
Product-Group=junos
On all MX platforms where BBE subscriber services are configured, multicast traffic loss might be observed for subscribers if the multicast group id is larger than 255.
PR NumberSynopsisCategory: Trio pfe qos software
1657203PFE might get disabled if a packet with a small size is transmitted out of the queue
Product-Group=junos
In MX platforms, if a packet with a small size (for example 64 Byte) is transmitted out of the queue then there might be PFE get disabled.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1543684PFE NH free error messages are seen on all FPCs
Product-Group=junos
The PFE NH Free error messages "cassis_free_internal simple size 2 @ 0x00071ff7 does not match sizes 4096/0" might be seen on all MX FPCs.
PR NumberSynopsisCategory: Issues related to port-mirroring functionality on JUNOS
1654812Port mirroring traffic not being flooded on the expected interfaces
Product-Group=junos
Whenever trunk interface connected to port mirroring output, VLAN is flapped then port mirroring traffic is stopped in case output of port mirroring is VLAN.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1604157Junos OS and Junos OS Evolved: /var/run/.env files are potentially not deleted during termination of a gRPC connection causing inode exhaustion (CVE-2022-22215)
Product-Group=junos
A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable authentication module (PAM) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). Please refer https://kb.juniper.net/JSA69719 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1502499File descriptors might be leaked in eventd when "load replace" is used to update "system syslog source-address"
Product-Group=junos
Each time "load replace" is used to update "system syslog source-address", a new file descriptor is created which eventually leads to eventd reaching its limit of maximum open files (i.e. 1024).
PR NumberSynopsisCategory: usf nat related issues
1610977Traffic might not be processed when mams-members are replaced in the AMS bundle
Product-Group=junos
On all MX platforms with SPC3 card having MAMs interface configured in AMS bundle, traffic/data packet loss might be seen. Packets might be seen discarded as "NAT allocation failures".
 
 

20.2R3-S5 - List of Known issues

PR NumberSynopsisCategory: EX4300 PFE
1671304Commit fails on EX4300 as EX4600 and EX4300 mixed virtual-chassis is not able to create more than 1024 IFLs
Product-Group=junos
Commit check fails on EX4300 when mixed mode virtual-chassis is configured between EX4600 and EX4300 and IFL (logical interface) is created on an aggregate interface having more than 1024 IFLs. Commit failure will be seen.
PR NumberSynopsisCategory: EX4300 Platform
1634781The PFE might get crash when VC member flaps on EX platforms
Product-Group=junos
On EX platforms, Virtual Chassis (VC) PFE crashes and more than one Routing Engine showing as MASTER when there is VC link flap between FPCs. There will be traffic loss until PFE comes up. The PFE will come up automatically and traffic will be resumed.
PR NumberSynopsisCategory: EX4300 Platform implementation
1673693EX4300-48MP VC generates disk drive smart error clear alarm chassisd messages every 5 seconds if FPC2 is in Virtual Chassis.
Product-Group=junosvae
EX4300-48MP VC generates disk drive smart error clear alarm chassisd messages every 5 seconds if FPC2 is in Virtual Chassis.
PR NumberSynopsisCategory: EX2300/3400 PFE
1633883The EX2300 may unexpectedly drop VOIP VLAN traffic after reboot
Product-Group=junos
On the EX2300 platform, the traffic drop may be observed on VOIP VLAN after the device reboot. Voice VLAN on EX2300 may not forward traffic correctly out of the interface when the device is either power-cycled / halted / power off or power on, and may not communicate with the default gateway.
PR NumberSynopsisCategory: QFX Multichassis Link Aggregrate
1296784QFX5100 / EX4600 - MC-LAG with vlan-rewrite does not work
Product-Group=junos
MCLAG with vlan-rewrite is not a supported feature.
PR NumberSynopsisCategory: SPC3 HW and SW Issues
1641793Traffic might be dropped due to the RX queue being full
Product-Group=junos
Incoming packets might be sent to RX queues of core0 or core14 mistakenly, might result in the queue buffer full and the packets getting dropped.
PR NumberSynopsisCategory: S/W Diags support for ACX series SKUs.
1513553ACX710 with the console cable plugged in may find that the system boot is interrupted
Product-Group=junos
For ACX710, if the console cable is plugged in and the terminal connection is active and sending characters to the interface, the system boot may be interrupted and the ACX710 boot will be stalled at the uboot# prompt.
PR NumberSynopsisCategory: BBE database related issues
1648565MX960 :: bbe-statsd core observed at vlogging,smid_reregister,sdb_db_check,Juniper::SmidInterface::isReady in bbe-smgd daemon restart test
Product-Group=junos
During bbe-smgd daemon restart there is a small window during which requests for subscriber statistics results in bbe-statsd daemon core. There is no functional impact as the system returns to normal after both daemons finally restart.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1675921Micro BFD session state in RE remain UP even peer side session is down.
Product-Group=junos
Any platforms with Micro BFD configured on member links of the LAG/ae interface, BFD Session state in RE remains as UP always even though PEER device has ceased.
PR NumberSynopsisCategory: Border Gateway Protocol
1635390BGP routes might be left stale on the router
Product-Group=junos
On all Junos and Junos Evolved platforms, if the BGP peer goes down, and the very last route in the list is marked as a high priority, BGP might assume no more routes to delete, causing routes to be stale.
1655228An RPD process crash may be observed, when the received prefix count exceeds configured "prefix-limit"
Product-Group=junos
In all Junos and Junos Evolved platforms, when the BGP neighbor is brought down due to the received prefix count exceeding configured "prefix-limit" and if BGP disable and enable operation performed to bring the BGP session up then the "rpd" process crash might be observed.
1669930BGP inactive routes may not be advertised to peers in BGP-LU scenario
Product-Group=junos
If BGP-LU(labeled-unicast) is configured using "rib inet.3/inet6.3" address family, BGP inactive routes are not re-distributed to BGP-LU peers, leading to improper traffic patterns.
PR NumberSynopsisCategory: MX Platform SW - ukern core dumps
1539305On the MX2020 router, the next hops are less than a total of nhdb 4MPOST GRES.
Product-Group=junos
In scaled mx2020 router, with vrf localisation enabled, 4 million nexthop scale, 800k route scale. FPCs may go offline on GRES. Post GRES, router continues to report many fabric related CM_ALARMs. FPC may continue to reboot and not come online. Rebooting master and backup RE will help recover and get router back into stable state.
PR NumberSynopsisCategory: CoS support on DNX
1574601On ACX5448/710 platforms 802.1P rewrite might not work
Product-Group=junos
On ACX5448/710 platforms, if Dot1p COS rewrite is applied on Dot1q based core interface, after restart or PFE restart, Dot1p rewrite is not working and sending all traffic with "Priority: Best Effort".
PR NumberSynopsisCategory: SNMP, mib2d issues
1669510The snmpd core might be observed with filter-duplicates configuration
Product-Group=junos
On all Junos and EVO platforms configured with filter-duplicates, the snmpd core might be observed if the SNMP query is made simultaneously from NMS (Network Management System) as well from the CLI.
PR NumberSynopsisCategory: EX Diagnostics Software
1598805The interface on SFP-T or SFP-SX might stop forwarding traffic on EX4600
Product-Group=junos
On EX4600, the interfaces on SFP-T or SFP-SX might stop forwarding traffic when MACSec and auto-negotiation is enabled on the ports. The interfaces would still show as up and the transmit and receive counters will increase. However, the transmit counters on the port will not increase.
PR NumberSynopsisCategory: EX4400 PFE software
1603015On EX4400 dot1x authentication may not work on EVPN/xlan enabled endpoints.
Product-Group=junos
On EX4400 dot1x authentication may not work on EVPN/xlan enabled endpoints. The issue is due to EAPOL packets received on VxLAN ports are not processed in hostpath.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1659732On QFX10K Junos platforms configuration of IGMP group range might result in traffic loss
Product-Group=junos
On QFX10K Junos platforms, the configuration of the IGMP group range might result in a specific multicast route getting programmed and this might cause traffic loss.
PR NumberSynopsisCategory: Express pfe Mclag
1666399Static MACs are not programmed after reboot, resulting in floods of unicast traffic
Product-Group=junos
After rebooting, we see that the link does not have a static MAC address. This results in unicast traffic flooding and sometimes traffic drops for this static MAC.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1626562A major alarm DPDK (data plane development kit) Tx stuck issue of SRX4100/4200
Product-Group=junos
On the SRX4100 and SRX4200 platforms, it can detect DPDK (data plane development kit) Tx stuck issue and trigger a major chassis alarm goes which might trigger RG1 failover to the healthy node. A DPDK reset will be triggered only to the stuck port and if the reset resolves the tx stuck issue, the major chassis alarm will go off.
PR NumberSynopsisCategory: ISIS routing protocol
1613384The rpd crash might be seen on all Junos and Junos OS Evolved platforms
Product-Group=junos
The rpd crash might be seen on all Junos and Junos OS Evolved platforms if Topology-Independent Loop-Free Alternate (TI-LFA) or MLA feature ends up having more than 5 SIDs SRv6-SIDs in the primary Segment Routing over IPv6(SRv6) path (in case of Micro-loop avoidance) or 6 SRv6 SIDs in the backup path(TI-LFA). SR-MPLS is not impacted. The rpd crash recovers automatically when the rpd process restarts.
PR NumberSynopsisCategory: SRX Firewall Authentication
1673125Information about users groups is not displayed completely
Product-Group=junos
On SRX platforms using authentication-scheme (pass-through/web-auth/web-redir) and authentication sources (firewall-user/ldap/radius) do not display the complete user's group information because the display buffer for showing group names for an authentication entry is too small.
PR NumberSynopsisCategory: Firewall Policy
1669386Security policy state may be invalid on SRX platforms
Product-Group=junos
On SRX platforms, when dynamic-application-group and all the internal applications in that group are configured separately on the security policy, that security policy state may become invalid.
PR NumberSynopsisCategory: Platform infra to support jvision
1558377MPC10E reporting ipc_pipe_get_packet() error fabric self ping blackhole
Product-Group=junos
MPC10E if you configure additional fabric service analytic sensors, sensord process might stop processing further fabric data from PlatformD and fills up all packet heap buffer. This results in fabric self-ping blackhole condition and disable-pfe action is executed. This can happen during commit of the new fabric sensors or at a later time.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1664955MAC addresses learned on the RTG interface are not aging out
Product-Group=junos
On Junos EX/NFX/QFX platforms, stale MAC addresses entry not getting removed for RTG (Redundant trunk groups) interfaces.
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1560772Interface not able to send/receive packets after repeated 100G link flaps on MPC10E
Product-Group=junos
On all Junos platforms with MPC10E line-cards, repeated 100GE interface link flaps may result in complete traffic stall (packets no longer going out the interface). 10GE links are not exposed and 40GE links are far less sensitive compared to 100GE interfaces. MPC11E line-card is not exposed.
1601049Interface flap might trigger major alarm causing disble-pfe action when high priority scheduler is configured
Product-Group=junos
On all Junos platforms with MPC10E line-cards, repeated 100GE interface link flaps may result in loss of traffic going out of the interface. Each 100GE interface down event might not flush the stream and triggers a major alarm causing disable-pfe action. This is specific to interfaces configured with high priority scheduler. MPC11E card is not exposed.
1638410PFE might get stuck after 100G/400G interface flaps
Product-Group=junos
On Junos platforms equipped with MPC10E/MPC11E/LC2301/MX10K-LC9600 line cards, when any 100G/400G interface with high priority class-of-service scheduler configuration flaps, it might result in series of error messages during high traffic flow. Eventually this would result in PFE-disable action, impacting the related traffic. However, the issue could be recovered after FPC reboot.
PR NumberSynopsisCategory: Microkernel for neo mpc
1664602Line card may crash after offline/online plane
Product-Group=junos
On platforms supporting MQ and XM-based line cards, destination error, self-ping error and line cards can be offline after swapping the XM-based uplink cards and toggling the fabric planes. The issue will be seen on other MQ-based line cards in the chassis.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1668090Junos upgrade might fail due to file system corruption
Product-Group=junos
On all Junos platforms, file system corruption can result in a corrupted package/db which might lead to an upgrade failure.
PR NumberSynopsisCategory: for all ipv6 related issues
1662707IPv6 ND packets might be dropped in QFX5100 and QFX5110 platforms
Product-Group=junos
On QFX5100 and QFX5110 platforms, with L2circuit configured, after performing an upgrade, the IPv6 ND (Neighbor Discovery) packets might be dropped.
PR NumberSynopsisCategory: QFX PFE
1576060On the QFX5100-48T switch, the 10G interface might be auto-negotiated at 1G speed instead of 10G
Product-Group=junos
On the QFX5100-48T switch, auto-negotiation might fail to work and the 10G interface might be auto-negotiated at 1G speed instead of 10G. This issue might cause a link down.
PR NumberSynopsisCategory: qfx-sw-mclag
1623707The LACP delay may be observed with an "aggregate wait time" of more than 1 second
Product-Group=junos
On all Juniper platforms which are connected with another vendor device, in the case of "multi-chassis LAG" and if "aggregate-wait-time" of more than 1 second configured, the LACP may take more time to move into the active state.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1665306On QFX5K series platforms, duplicate packets might be seen in the multihomed scenario in an EVPN-VxLAN fabric when unicast ARP packets are received
Product-Group=junos
On QFX5K series platforms, when unicast ARP (Address Resolution Protocol) is received for a MAC address that is already learned in an EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) environment, the ARP request is flooded and duplicate packets might be seen on leaf devices. We might see some service impact where split-horizon might not work or continuous mac-move might be seen. This issue is rare and very unlikely to occur in a production environment due to presence of intermediate switches which might resolve the unicast ARP query.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Interface
1629637The interface on the peer device might remain up even after disabling the 10G interface on the Juniper device
Product-Group=junosvae
On QFX5120-48T and QFX5120-48Y platforms, after disabling the 10G interface on the device the interface on the peer device might remain up.
PR NumberSynopsisCategory: RPD Interfaces related issues
1639134The dynamic tunnel might flap every 15 mins with a non-forwarding route
Product-Group=junos
On all Junos and Junos Evolved platforms, the dynamic tunnel might flap every 15 mins when a non-forwarding route is resolving over the dynamic tunnel. The non-forward route resolution on a dynamic tunnel route might not be successful. As the route resolution is having impact, traffic drop might be seen in peer nodes.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1664527The routing process on the device might crash when the IP address of local interface is changed to the IP address of BGP peer
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd process might crash when the IP address of local interfaces is changed to BGP peer's IP address. When the IP address is changed, Router NH is created. When this route is leaked to another routing instance, flag is set on the same Router NH instead of creating a new one. This leads to rpd crash. Core files are generated and some traffic impact might be seen.
PR NumberSynopsisCategory: Issue related to mcnh routing infrastructure within RPD
1663568The forwarding plane is not updated properly in scaled MVPN scenario after receiving PIM leave messages
Product-Group=junos
On all Junos and Junos Evolved platforms, when IFLs from non-default routing instances are being added with the OIF scaling of more than 2000 there will be a spillover of IFLNHs into different next hops due to this the outgoing interfaces (OIFs) will not be deleted from multicast next-hop.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1659255The multipath route might be missing when multipath is configured
Product-Group=junos
On all Junos and Evolved platforms, when multipath is configured multipath computation is missed for the routes resulting in missing multipath routes.
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1658277Some L3VPN prefixes are not active because nexthop is not usable
Product-Group=junos
If preserve-nexthop-hierarchy knob was deconfigured and if no-propagate-ttl config within VRF is opposite to global config,some routes can be inactive. Secondary nexthops may not be resolved and active, hence L3VPN routes are not active.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1662109On all Junos platforms, when route leaking is performed between Routing Instances, if local-as is configured, then routes from all protocols might be hidden
Product-Group=junos
On all Junos platforms, when route leaking is performed between Routing Instances, if local-as is configured, then routes from all protocols might be hidden
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1575138[MPC10] - Traffic drops while routing from MPC10 to other type of MPC when configured with WAN-PHY mode on the "other" MPCs
Product-Group=junos
A router will drop traffics when using "wan-phy" mode on a router with MPC10E mixed with other types of MPC -- such as MPC3E. This issue affects JUNOS software versions prior to 20.1R1.
PR NumberSynopsisCategory: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1648473The FPC crash might be observed during ISSU
Product-Group=junos
On all Junos platforms with scaled environment equipped with specific line cards like MPC7E/MPC8E/MPC9E etc., when there are memory errors, the FPC crash might be observed. This happens during ISSU (In-service software upgrade).
1651407CCL-DT-BNG: show interface and monitoring interface (ifd level) counters are tripled.
Product-Group=junos
In a subscriber management scenario requiring four subscriber accurate accounting statistics per packet, three stats are handled correctly while the fourth one - ifd stat - is not handled correctly due to this PR. The net effect is only the ifd byte statistic may not be accurate while the ifd packet count is still accurate. Also there is no service or traffic impact due to this issue.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1472511Unknown unicast filter applied in the EVPN routing instance blocks unexpected traffic.
Product-Group=junos
unknown unicast filter applied in EVPN routing-instance blocks unexpected traffic
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1663136commit failure when changing BGP well-known community attributes
Product-Group=junos
RCA: After doing multiple testing and trying on various combination it is concluded that issue is happening once we set the community number for a attribute and then try to set community string for the same attribute. Below is the error seen : [edit] root@snagar-re0# set routing-instances L3VPN1 routing-options static route 0.0.0.0/0 community 65535:65281 [edit] root@snagar-re0# set routing-instances L3VPN1 routing-options static route 0.0.0.0/0 community no-export error: could not add object to patricia tree error: statement creation failed: no-export Actually there is a community_map variable in ui code which have the mapping of community names with its corresponding community number. For eg: static const char *community_map[] = { "graceful-shutdown", "65535:0", "Graceful Shutdown", "no-export", "65535:65281", "Do not advertise outside your confederation/AS", ??? ???????? }; On triaging deeper , it is observed that when we try to add community attribute or node we always pass community number as key. However , key size is calculated on passed string. As a result , when community number in the command is passed, key size will be calculated on that and stored. Now when string i.e community name is passed (note that key will still be community number here) , size for the key will calculated on passed string. Now , at this stage even the attribute is same and key passed is also same, child for the node is not found and flow continues to create the object and add that. Later we got the above error as same attribute is already there.
1669375commit failure when changing BGP well-known community attributes
Product-Group=junos
RCA: After doing multiple testing and trying on various combination it is concluded that issue is happening once we set the community number for a attribute and then try to set community string for the same attribute. Below is the error seen : [edit] root@snagar-re0# set routing-instances L3VPN1 routing-options static route 0.0.0.0/0 community 65535:65281 [edit] root@snagar-re0# set routing-instances L3VPN1 routing-options static route 0.0.0.0/0 community no-export error: could not add object to patricia tree error: statement creation failed: no-export Actually there is a community_map variable in ui code which have the mapping of community names with its corresponding community number. For eg: static const char *community_map[] = { "graceful-shutdown", "65535:0", "Graceful Shutdown", "no-export", "65535:65281", "Do not advertise outside your confederation/AS", ??? ???????? }; On triaging deeper , it is observed that when we try to add community attribute or node we always pass community number as key. However , key size is calculated on passed string. As a result , when community number in the command is passed, key size will be calculated on that and stored. Now when string i.e community name is passed (note that key will still be community number here) , size for the key will calculated on passed string. Now , at this stage even the attribute is same and key passed is also same, child for the node is not found and flow continues to create the object and add that. Later we got the above error as same attribute is already there.
PR NumberSynopsisCategory: VMHOST platforms software
1613229The "FPC 0 Major Errors" alarm might be seen on PTX10002-60C/QFX10002-60C due to a rare timing issue
Product-Group=junosvae
On PTX10002-60C/QFX10002-60C, after the system is rebooted, the "FPC 0 Major Errors" alarm might be seen due to a rare timing issue. The issue could cause the host path traffic to get dropped. It is a rare issue and does not always happen during reboot. Please try to perform "request vmhost reboot" for recovery.
PR NumberSynopsisCategory: Virtual Private LAN Services
1655858The Pseudo Wires might go down in VPLS scenario
Product-Group=junos
On all Junos/Junos Evolved platforms with VPLS (virtual private LAN service) deployed, deactivating and activating the neighbour under the default mesh-group might lead Pseudo Wires(PW) to go down. This happens when there is a change in default mesh-group and that might not be updating the PW status. This can be recovered by deactivating and activating the complete routing instance under the mesh-group.

Modification History

First publication 2022-08-04