Alert Type
PSN - Product Support Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX, PTX, QFX running Junos Evolved Software
Alert Description
Junos Software Service Release version 21.1R3-S2-EVO is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 21.1R3-S2-EVO is now available.
21.1R3-S2-EVO - List of Fixed issues
PR Number
Synopsis
Category: Border Gateway Protocol
1643089
The rpd crash files may be seen on MX and PTX platforms
Product-Group=evo
The rpd (routing process daemon) process might crash in the BGP (Border Gateway Protocol) rib-sharding scenario on all Junos and Junos Evolved MX and PTX platforms. The rpd crash may cause service impact. However, the rpd restarts and recovers by itself.
PR Number
Synopsis
Category: Express BT PFE L3 Features
1651932
An error might be seen when the member link on an AE bundle is deleted
Product-Group=evo
On all EVO PTX platforms, gRPC connection between the "evo-aftmand" process and the "cda" process maybe disconnect with the messages "[Error] CDA: exprGrpcAsyncApi: failed cq read", and "GOAWAY with error code ENHANCE_YOUR_CALM". When the disconnection happens, the Junos Evolved system can no longer retrieve status or programs forwarding ASICs. This is a catastrophic failure.
PR Number
Synopsis
Category: bug tracker for evo
1649163
EVO:ACX When fixed classifier is detached all default classifiers should be re-attached
Product-Group=evo
When you configure classifiers on an interface, the default classifiers are removed. This may cause traffic matching default classifier to not being classified
PR Number
Synopsis
Category: Issues related to debug utilties - objmon,objshell/Dashboard
1602272
Junos OS and Junos OS Evolved: python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API via timed processing of valid PKCS#1 v1.5 ciphertext. (CVE-2020-25659)
Product-Group=evo
A vulnerability in the python cryptographic library as used in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to perform timing oracle attacks against RSA decryption. Please refer to https://kb.juniper.net/
JSA11245
[juniper.net]
for more information.
PR Number
Synopsis
Category: PRs related to software Agentd daemon on EVO
1672783
PDT: TI-S/MOP: Brackla router was not coming up, due to picd, mgd-pfe application failures.
Product-Group=evo
This issue is applicable to PTX10003. Downgrade from 21.4R2-EVO to 20.4R3-EVO fails and few Apps are not started.
PR Number
Synopsis
Category: EVPN Layer-2 Forwarding
1646010
IRB might not send out arp-reply if "no-arp-suppression" is configured
Product-Group=evo
On all Junos platforms, when "no-arp-suppression" is configured, the Layer 2 Address Learning Manager (L2ALM) will not respond to Address Resolution Protocol (ARP) request for Integrated Routing and Bridging (IRB) IP, and traffic to IRB will be lost.
PR Number
Synopsis
Category: Express PFE CoS Features
1648760
EVO snmpwalk do not return value for index 0
Product-Group=evo
EVO - snmpwalk over leaf of jnxCosQstatTable do not return value for index 0
PR Number
Synopsis
Category: Issues related to Junos licensing infrastructure
1658913
Valid software licenses might not be in sync between members in the Virtual chassis.
Product-Group=evo
Software licenses will now be synced to all members of Virtual chassis. - Warnings and alarm to be seen only on global master member in VC. - show system license. command will be executed only on global master member. - Issue is specific to all MX VC setup for all Junos. For all other members it will display the following message: root@> show system license error: This command can only be used on the master routing engine.
PR Number
Synopsis
Category: Multicast Listener Discovery
1656311
The rpd process crash might be observed with PIM configured
Product-Group=evo
On all Junos and Junos OS Evolved platforms, if the interface is enabled with Protocol Independent Multicast (PIM) (enables Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) implicitly) and the same interface is configured under a non-forwarding instance, then the process rpd crash might be observed.
PR Number
Synopsis
Category: next gen multicast for L3VPNs
1647149
The routing protocol process might stop working when de-activating and activating the same provider tunnel from one to another instance in a single commit
Product-Group=evo
On all platforms when de-activating and activating the same provider tunnel from one to another instance in a single commit, the routing protocol process might stop working.
PR Number
Synopsis
Category: Issues related to Junos Automation, Commit/Op/Event and SLAX
1634027
Automation Infra may fail when the interface is pre-configured with flexible-vlan-tagging
Product-Group=evo
On all Junos and Evolved(EVO) platforms, when two interfaces are configured in the device under the same commit action and if one of the interfaces is pre-configured with flexible-vlan-tagging knob, it might impact the automation infra which includes commit, op, event, and JET scripts to fail.
PR Number
Synopsis
Category: Issues related to confg mgmt, ffp, load-action, commit procs
1659783
The configuration might roll back after performing "commit confirmed" and then reboot
Product-Group=evo
On all Junos OS and Junos OS Evolved platforms, the configuration might roll back after performing "commit confirmed" and then a reboot.
PR Number
Synopsis
Category: Issues related to mgd, DAX API, DDL/ODL infrastructure, Juno
1598123
Interface configuration may get stuck and may not update after several ephemeral commits
Product-Group=evo
After several ephemeral commits interface configurations may get stuck and may not get updated on all Junos platforms.
1627323
Junos Fusion Satellite EX4300 upgrade fails from Aggregate Device MX104
Product-Group=evo
Junos Fusion Satellite Device (SD) EX4300 upgrade fails from Aggregate Device (AD) MX104 with dual-RE.
1641025
Unable to access configure exclusive mode after mgd process is killed
Product-Group=evo
On all Junos OS and Junos OS Evolved devices, when copy-config, get-configuration, and discard-change RPCs run in two parallel NETCONF sessions and the database is also accessed in parallel by two NETCONF sessions, it leads to database corruption and mgd-related services might crash.
PR Number
Synopsis
Category: Virtual Router Redundancy Protocol
1646480
The vrrpd core might be observed after interface state change
Product-Group=evo
On all Junos/EVO platforms with VRRP (Virtual Router Redundancy Protocol) implemented, if "startup-silent-period" is configured as 1sec and if state of any interfaces included in VRRP-group changes, it might result in vrrpd (VRRP daemon) crash, impacting the related services. However, configuring startup-silent-period between 2 and 2000sec and restarting vrrpd will help to restore the services.
21.1R3-S2-EVO - List of Known issues
PR Number
Synopsis
Category: Express PFE L3 Multicast
1669740
Multicast traffic drop might be seen on specific PTX10k platforms
Product-Group=evo
On specific PTX10k products (PTX10008/ PTX10016/ PTX10001-36MR/ PTX10K-LC1202-36MR), multicast packets get dropped when any replication applications (Multicast, P2MP (Point to Multipoint)) are used and it is flooded on interfaces spread across more than 15 PFEs (Packet Forwarding Engines). This issue might impact a forwarding plane.
PR Number
Synopsis
Category: ISIS routing protocol
1610983
Junos OS and Junos OS Evolved: The rpd CPU spikes to 100% after a malformed ISIS TLV has been received (CVE-2022-22196)
Product-Group=evo
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker with an established ISIS adjacency to cause a Denial of Service (DoS); Please refer to https://kb.juniper.net/
JSA69509
[juniper.net]
for more information.
Modification History
First Publication 2022-09-21
21.1R3-S2-EVO: Software Release Notification for JUNOS Evolved Software