Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 20.2R3-S6 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 20.2R3-S6 is now available.

Junos Software service Release version 20.2R3-S6 is now available.

20.2R3-S6 - List of Fixed issues

PR NumberSynopsisCategory: EX9200 Platform
1569230The 40G DAC connection between EX9253 and the peers might not come up
Product-Group=junos
DAC cable might not come up in 40G mode between EX9253 when any interface on PIC0 of FPC 0 or FPC 1 is connected to the peers.
PR NumberSynopsisCategory: EX2300/3400 PFE
1647209DHCP traffic might be dropped when DHCP-security and RTG are enabled
Product-Group=junos
On EX2300, EX2300-48MP, and EX3400 platforms, when DHCP-security and Redundant Trunk Group (RTG) are enabled clients connected over RTG might not get DHCP IP and DHCP traffic might be dropped.
1678430AE interface will receive unknown unicast traffic on FPC3 reboot of a VC
Product-Group=junos
On VC (Virtual Chassis) supporting EX and QFX platforms, having VC of 4 or more nodes, with an AE (Aggregated Ethernet) interface connected to other VC members, if FPC3 (Flexible PIC Concentrator) of VC is rebooted, unknown unicast traffic will be received on the AE interface.
PR NumberSynopsisCategory: EX2300/3400 platform
1667564High numbers of PDs connected may result in high CPU utilization
Product-Group=junos
On EX2300 and EX3400 platforms, high CPU utilization may be observed when more PoE devices (more than 25 PDs) are connected to the switch.
PR NumberSynopsisCategory: EX-Series VC Infrastructure
1685067EX4600-VC - Master RE reboot and All-member reboot lead to PFE Manager hogging logs when SFP-T is plugged in
Product-Group=junos
On Junos EX4600 Virtual Chassis (VC), the master RE reboot and all-members reboot lead to the PFE Manager hogging logs when SFP-T pluggable is installed in. The PFE Manager hogging logs has no functionality impact (PR 1641556).
1689946Instability observed after mastership switchover on members with SFP-T pluggable installed on EX4600-VC
Product-Group=junos
On Junos EX4600 Virtual Chassis (VC), a routing engine master switchover may lead members to disconnect from the VC for approx. 2 mins before the members re-join the VC. This instability will lead to traffic loss. This only happens on members with SFP-T pluggable installed.
PR NumberSynopsisCategory: QFX PFE CoS
1688455The FPC crash would be observed when the same CoS configuration is applied with wildcard for all the physical interfaces and AE
Product-Group=junos
On all Junos platforms, in a scaled scenario when some of the ge/xe/et interfaces are members of Aggregated Ethernet (AE) and the Class of Service (CoS) forwarding-class-set configuration is applied with a wildcard for all the physical interfaces and AE, it would trigger a Flexible PIC Concentrators (FPC) crash which leads to traffic loss.
PR NumberSynopsisCategory: "agentd" software daemon
1566528On the QFX5100 Virtual Chassis, the following continuous message is observed: agentd-pfe-proxy_telemetry_publisher.
Product-Group=junos
In QFX / Ex Series devices in a Virtual Chassis with Junos telemetry interface (JTI) or Jvision, the data from line card Packet Forwarding Engines might not be published properly by the agentd process to the Message Queuing Telemetry Transport (MQTT) protocol. The continuous mosquitto message might be flooded and fill up the master system at a high rate (thousands per hour). Then Packet Forwarding Engine telemetry might not be streamed out.
PR NumberSynopsisCategory: a20a40 specific issue
1642138Missing boot parameters on Junos SRX5K platforms will result in fabric plane CRC link errors
Product-Group=junos
Fabric plane CRC link errors are detected on Junos SRX5K platforms which can cause an HA switchover and in worst case scenario, throughput issues for user traffic. The hardware error message "Minor CB (Control Board) Fabric Chip Not Online" is displayed and is caused by fabric plane CRC error like "FPC plane CRC link error". The issue happens in HA (High Availability) scenario with SCB4 (Switch Control Board) and IOC3 (Input Output, I/O) cards in use.
PR NumberSynopsisCategory: BBE Autoconfigured DVLAN related issues
1680453The process bbe-smgd on the router would stop processing new PPPoE subscribers session
Product-Group=junos
On all Junos platforms configured with subscriber-management, the process bbe-smgd will stop processing new PPPoE (Point-to-Point Protocol over Ethernet) connections due to a memory leak in the control packet pool of the PPPoE plugin.
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1676049Minor memory leak in 'bbe-statsd' daemon may be seen when subscriber-management is enabled on MX platforms
Product-Group=junos
On MX platforms, a minor memory leak may be seen over time for transient subscriber sessions which last for around 30 seconds or less. The issue is reproducible consistently and may result in 'bbe-statsd' daemon crash over time.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1678016Traffic drops due to the generation of the FPC core, which makes the system unstable.
Product-Group=junos
All Junos (other than MX) configured with sBFD responder with the following command: "set protocols bfd sbfd local-discriminator <>" which triggers FPC core and leads to drops traffic.
PR NumberSynopsisCategory: Border Gateway Protocol
1635390BGP routes might be left stale on the router
Product-Group=junos
On all Junos and Junos Evolved platforms, if the BGP peer goes down, and the very last route in the list is marked as a high priority, BGP might assume no more routes to delete, causing routes to be stale.
1680360InboundConvergencePending flag is set after RE switchover
Product-Group=junos
When the BGP EOR update is received, the BGP flag "InboundConvergencePending" should be cleared on both master and backup RE. However, after performing RE switchover, the flag "InboundConvergencePending" might be re-set on master or backup RE, which is unexpected. The potential impact may be seen ONLY when BGP multipath is used. The multipath calculation may not start or stop as expected.
PR NumberSynopsisCategory: BBE Remote Access Server
1669284Errors are seen when the accounting server source address is IPv6
Product-Group=junos
On all Junos platforms having a profile assigned to the RI (Routing Instance) and using a source IPv6 (Internet Protocol version6) address for the radius server, errors might be observed and the accounting services might not work in an expected manner.
PR NumberSynopsisCategory: Firewall Filter
1670622Traffic loss may be observed when changing firewall configuration
Product-Group=junos
On MX platforms supporting MPC7/8/9 line cards, traffic loss may be observed if the firewall configuration changes are made when PFE 0 (Packet Forwarding Engine) is in a disabled state. It is a rare occurrence.
PR NumberSynopsisCategory: ACX platform interface issues
1573324Wrong optic threshold values show on ACX5448 platform for QSFP-100G-LR4-T2
Product-Group=junos
On ACX5448 with QSFP-100G-LR4-T2 installed, optic threshold values are not displayed correctly.
PR NumberSynopsisCategory: OAM support on DNX
1560182When an RDI is received with CCM packet, sessions are not deleted
Product-Group=junos
RDI received in CCM messages are not handled and hence the CFM sessions will not go down on receiving RDI indication from peer. With this fix, RDI indication from peer will be handled.
PR NumberSynopsisCategory: ACX IFL, IFF creation
1638581L3 interface creation may fail on the ACX5448 and ACX710 platforms
Product-Group=junos
On the ACX5448 and ACX710 platforms, Layer 3 interface creation may fail due to a base MAC address programmed on the PFE. As a result, the simplest symptom is ping failure.
PR NumberSynopsisCategory: ACX VRRP
1666853Traffic loss is observed when the VRRP is configured over the AE interface
Product-Group=junos
On ACX5448 platforms, the Virtual Router Redundancy Protocol (VRRP) is up from Routing Engine (RE) but the group is not created under the Packet Forwarding Engine (PFE) due to this VRRP virtual IP (VIP) is neither responding to ping nor accept any traffic when the VRRP is configured over Aggregated Ethernet (AE) interface. This results in traffic loss.
PR NumberSynopsisCategory: Manageability for Node Virtualization
1583324JDM server creation might fail on junos node slicing setup in in-chassis mode
Product-Group=junos
On MX platforms the JDM (Juniper Device Manager) server could not be created in in-chassis mode of junos node slicing, which results in mgd process crash and affects GNF's (Guest Network Function) provisioning.
PR NumberSynopsisCategory: SNMP, mib2d issues
1669510The snmpd core might be observed with filter-duplicates configuration
Product-Group=junos
On all Junos and EVO platforms configured with filter-duplicates, the snmpd core might be observed if the SNMP query is made simultaneously from NMS (Network Management System) as well from the CLI.
PR NumberSynopsisCategory: EVPN control plane issues
1680421EVPN MPLS traffic drop can be observed in a multi-vendor PE CE setup with single-active LAG
Product-Group=junos
On all Junos platforms running EVPN (Ethernet Virtual Private Network) MPLS (Multi-Protocol Labeled Switching) and a single active LAG (Link Aggregation), the traffic can get forwarded to the NDF (Non-Designed Forwarder) router which can lead to a traffic drop. This issue is seen in multi-vendor PE (Provider Edge) CE (Customer Edge) setup when there is a DF switchover i.e DF (Designated Forwarder) role changes and the backup router starts advertising the EVPN type 2 route, now there is another switchover and the old DF again becomes the DF and advertises EVPN type 1 route but the NDF does not withdraw its route consequently the traffic gets forwarded to the NDF.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1649234The kernel crash would be observed in an EVPN multi-homed scenario
Product-Group=junos
On QFX10002/QFX10008/QFX10016 (only QFX10K) platforms, when Assisted Replication (AR) feature as Replicator role is used in an Ethernet VPN (EVPN) multi-homed scenario, there would be out-of-bound memory access issue observed which could result in the kernel crash leading to the service impact.
1677521The ARP/ND entries are not relearnt as expected on the spine with EVPN-VxLAN
Product-Group=junos
On the spine node of the EVPN-VxLAN scenario, after the initial learning of an ARP(Address Resolution Protocol) or ND (Neighbor Discovery) entry has timed out, the node may not learn that entry again.
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1674116The BFD packets will drop in an EVPN-VxLAN scenario due to incorrect layer3 offset being set in the host path
Product-Group=junos
On all QFX10000-60C platforms with Ethernet VPN-Virtual Extensible LAN (EVPN-VxLAN) scenario, the Bidirectional Forwarding Detection (BFD) packets are getting classified as packets of different protocols like Virtual Router Redundancy Protocol (VRRP), depending on the value at an incorrect offset which leads to BFD packet drop.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1654215The ARP might not resolve with the native-vlan configuration
Product-Group=junos
On all QFX10002-36Q/QFX10002-72Q/QFX10008/QFX10016 platforms, when Service Provider(SP) style is configured with IRB and native-vlan leads to ARP failure.
1659732On QFX10K Junos platforms configuration of IGMP group range might result in traffic loss
Product-Group=junos
On QFX10K Junos platforms, the configuration of the IGMP group range might result in a specific multicast route getting programmed and this might cause traffic loss.
PR NumberSynopsisCategory: Express ASIC interface
1669267PCS errored blocks count increments on PTX3000/PTX5000 after Junos software upgrade
Product-Group=junos
On PTX platforms, packets drop is seen because of increment in PCS and framing errors on some of the 100GE ports on PIC or its peer devices after firmware migration.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1650112Packet loss might be seen on SRX4100 and SRX4200 devices from 20.2R2
Product-Group=junosvae
Packet loss might be seen on SRX4100 and SRX4200 devices from 20.2R2
PR NumberSynopsisCategory: idp flow creation, deletion,notification, session mgr intfce
1686105IDP unwanted attacks (false positives) detected on the traffic
Product-Group=junos
On all Junos SRX platforms with 19.4 and 20.1 releases, IDP (Intrusion Detection and Prevention) false positive attacks can be exempted from the policy for traffic continuity. The impact is that unexpected signatures may trigger in certain conditions and IDP false positive attacks may be detected.
PR NumberSynopsisCategory: JFlow bug tracker for SRX platforms
1688627The system may crash when Jflow inactive timeout is configured to be less than 'previous flow-inactive-timeout + 180' seconds
Product-Group=junos
On SRX platforms, when Jflow inactive timeout is configured to be less than 'previous flow-inactive-timeout + 180' seconds result in a system crash and core files are generated.
PR NumberSynopsisCategory: l2 flow module
1599891OSPF neighbor won't establish under Transparent mode when neighborship across different zone
Product-Group=junos
Some of the OSPF neighborship might not able to establish after system bootup when the neigborship connect to SRX via different zone under transparent mode
PR NumberSynopsisCategory: IPSEC/IKE VPN
1673391High Control Plane CPU utilisation while the kmd process is stuck after the core file
Product-Group=junos
On all SRX platforms, during key management (kmd) core file, with VPN/Internet Key Exchange (IKE) implemented and a high number of file descriptors open, the kmd process will reach above 80% CPU utilisation and stay for a long period of time if the kmd process is stuck after the core file is generated.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1612738The process l2ald may crash during routing-instance configuration change
Product-Group=junos
If configuration change in EVPN routing instance may cause existing dynamic mesh group readded to kernel. This cause l2ald core. But this core doesn't affect service and l2ald will return to correct state after core.
1638987Missing mac-ip entry for IRB learnt from a remote Vtep while the entry exists in MAC table and Routing table.
Product-Group=junos
In an Ethernet VPN (EVPN) VXLAN network, a device can function as a Layer 3 gateway on which you can configure integrated routing and bridging (IRB) interfaces. When you configure an IRB interface with a virtual gateway address (VGA), the device creates a default Layer 3 virtual gateway with the specified IP address. When one of the L3 gateway devices goes down, the leaf switch may miss the IRB entry on mac-ip table.
PR NumberSynopsisCategory: Label Distribution Protocol
1680574In an LDP -> BGP LU stitching scenario, Multiple LSPs will not be installed in the forwarding table, even if BGP Multipath and ECMP are enabled
Product-Group=junos
On all Junos and Junos OS Evolved Platforms, when BGP LU (Labeled Unicast) routes are exported to LDP (Label Distribution Protocol) to perform LDP->BGP-LU stitching, LDP installs only one NH(Next Hop) in the forwarding table instead of multiple NHs, even when BGP Multipath and ECMP are enabled. This issue will be seen for both EBGP (External Border Gateway Protocol) and IBGP (Internal Border Gateway Protocol) multipaths on PTX platforms and for only iBGP multipaths on all other platforms.
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1658164Fabric Destination error/Fabric plane in check state
Product-Group=junos
Fabric Plane check/error alarm can be seen due to overrun interrupt being set in MS-MPC line cards. Latency difference between the SFB2/SFB3 and the MS-MPC cards potentially causes overruns to increase during the traffic burst.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1673348CPU utilization of rpd process may reach 100% while reporting LSP states to pccd if the IS-IS update churn is high
Product-Group=junos
On all Junos and Junos Evolved platforms where PCEP (Path Computation Element Protocol) is provisioned, after IS-IS (Intermediate System-Intermediate System) PDU (Protocol Data Unit) flooding, rpd (routing protocol daemon) re-computes LSPs (Label Switched Path) and sends those to the pccd (path computation client daemon) which in turn reports those to PCE (Path Computation Element) for processing. If the update churn is high, this may cause the rpd to reach or get stuck at 100% CPU utilization.
PR NumberSynopsisCategory: Kernel Composite Next Hop (composite / l3vpn) Infrastructure
1608991Public nexthops cleanup fails for "mpls" family nexthops on MX platforms
Product-Group=junos
On MX platforms, when GRES is performed multiple times, public nexthops cleanup failed for "mpls" family nexthops and system might not be GRES ready (init_err connection_errsoft_mask_err).
PR NumberSynopsisCategory: Kernel MPLS / Tag / P2MP Infrastructure
1681892The RE crashes when MPLS next-hop is created and deleted frequently
Product-Group=junos
On all Junos platforms, when the system is up for a very long time, tag stats counters increase and cross the 32-bit capacity when MPLS next-hop is created/deleted frequently, resulting in RE (routing engine) crash.
PR NumberSynopsisCategory: PFE Peer Infra
1667674The FPC might fail to initialize on Junos platforms
Product-Group=junos
On all Junos platforms, in a very corner case, the FPC (Flexible PIC Concentrators) might fail to initialize and remains in a stuck state when an FPC is installed or rebooted.
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1685070Multiple bbe-smgd cores might be observed resulting in subscribers being lost or failing to login in the Enhanced subscriber scenario
Product-Group=junos
On MX platforms, multiple bbe-smgd cores might be observed due to out-of-bound memory access in the Enhanced subscriber scenario when bringing up PPPoE (Point-to-Point Protocol over Ethernet) subscribers and ACI (agent circuit identifier)/ARI (agent remote identifier) are part of the payload.
PR NumberSynopsisCategory: Chassis mgmt for all QFX systems - chassis MIB, alarms, CLI
1603588Chassisd generates "Cannot read hw.chassis.startup_time value: m" every 5 seconds on QFX10008
Product-Group=junos
On QFX platforms, the "Cannot read hw.chassis.startup_time value:m" error log is generated every 5 seconds in the output by "show log chassisd". This is a cosmetic message. There is no impact to the system.
PR NumberSynopsisCategory: QFX L2 PFE
1667069PVLAN IGMP packet is forwarded between Isolated ports and also duplicated to primary vlan port (Promiscous).
Product-Group=junos
When Isolated port receives IGMP packet, it should not be forwarded to other Isolated ports but was forwarded and also duplicated to primary vlan port (Promiscous).
1676772VLAN translation mapping gets deleted when one of the member interface removed from LAG
Product-Group=junos
On all QFX5k, EX4650 and EX4600 platforms, if port has VLAN translation configuration and LAG interfaces connected on same FPC then incoming traffic can drop if one member of LAG interface is deleted/removed.
PR NumberSynopsisCategory: QFX VCCP
1646561VCP neighborship might not be formed on the LX4 40G VCP port
Product-Group=junos
On all QFX5100 Virtual Chassis platforms, after the reboot, Virtual Chassis port (VCP) ports may not establish a VCP connection and Cyclic Redundancy Check (CRC) errors are also observed.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 optics related issues.
1677325Interfaces with QFX-10000-30C and QFX10000-30C-M Line Cards will not work properly
Product-Group=junos
On QFX10K platforms, interfaces with QFX-10000-30C and QFX10000-30C-M Line Cards will not work properly with FEC (Forward Error Configuration) and links connected to them will remain down.
PR NumberSynopsisCategory: rosen-6 and rosen-7 mvpn bugs
1592303The rpd process might crash when deactivating or deleting a routing-instance
Product-Group=junos
On all Junos and Junos Evo platforms, rpd core might be seen in the RE (Routing Engine), when deactivating or deleting a routing instance configured with NG-MVPN (Next Generation Multicast VPN), PIM (Protocol Independent Multicast) and having three or more entries of the same MVPN routes inside it [example - receiving 3 or more route entries for 1 MVPN route from different route reflectors].
PR NumberSynopsisCategory: RPD Interfaces related issues
1659102The rpd memory leak might be seen while processing vlan-ccc configuration
Product-Group=junos
On all Junos and Junos Evolved platforms, when deleting/adding the whole interface unit of family vlan-ccc, the rpd will observe a memory leak.
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1661815Traffic loss might be seen in certain IPsec VPN and Group-VPN scenario
Product-Group=junos
Group-vpn (gkmd daemon) and IPsec-vpn (kmd daemon) configured at the same time on a device and when SAs are present for both the type of configurations, leads to traffic loss.
1680775The dynamic tunnel route gets removed when a new tunnel is brought up for the same selector
Product-Group=junos
On M/MX platforms, a dynamic tunnel route (pointing to the inside interface) gets removed when a new tunnel is brought up for the same selector. When the ARI (Auto Route Insertion) route is added for two or more DEP (Dynamic End Point) tunnels belonging to two different service sets with the same selector (destination address), the ARI route gets overwritten by the tunnel which comes up last in the order, leading to traffic drop.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1666548The "snmpd" process might crash if SNMP timeout happens
Product-Group=junos
On all Junos and EVO platforms, the "snmpd" process might crash, if there is no response for the SNMP requests and a timeout happens.
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1571326HTTPS connection might timeout when remote access VPN connection with Juniper Secure connect fails
Product-Group=junos
On all SRX-series devices with tcp-encap profile (with ssl-t profile i.e pfv2) attached to ike-gw, when large number of sessions (say above 4lacs) are processed by flow, remote access VPN connection fails. This leads to HTTPS connection timeout.
PR NumberSynopsisCategory: SRX branch platforms
1675853Netbios traffic (IRB broadcast) is getting dropped post upgrade on the SRX platform
Product-Group=junos
On SRX platforms, NetBIOS (Network Basic Input/Output System) broadcast packets originating from the client do not reach the SRX routing engine, which is required in case "set forwarding-options helpers port 137" is configured to forward NetBIOS to a server.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1642851Traffic drop due to incorrect memory allocation for the default route on MPC10E and MPC11E line cards
Product-Group=junos
On MPC10E & MPC11E line cards default route information might be overwritten/lost due to incorrect memory allocation.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1629136,FPC crash might be observed in the subscriber scenarios
Product-Group=junos
On all Junos platforms which support subscriber configuration, in a very rare scenario the FPC crash might be observed, when the subscriber logs out. The issue is due to out-of-bound memory access while deleting the subscriber prefix.
1670577Subscriber traffic drops are seen on all Junos MX platforms with reason of 'sw error' in PFE State Invalid after ISSU
Product-Group=junos
Subscriber traffic is getting dropped with reason as 'sw error' on all Junos MX platforms after ISSU (In-service Software Upgrade) and RPF (Reverse Path Forwarding) drop counter is getting incremented. Traffic drop is subjected to where the RPF check feature is applied for subscribers. There is no workaround except reconnecting lost subscribers again for service restoration.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1677631DHCP bindings will fail for the client connected on an LT interface when DHCP snooping is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms, Dynamic Host Configuration Protocol (DHCP) bindings will fail for the clients connected on an LT(Logical Tunnel) interface when DHCP snooping is enabled. This issue is not seen when DHCP snooping is disabled or when clients and server are on other interfaces.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1673176"gethostbyname: Host name lookup failure" is displayed during commit
Product-Group=junos
On all SRX Series devices with J-Web enabled, "gethostbyname: Host name lookup failure" is displayed during commit. This issue is a display issue and doesn't have any service impact.
PR NumberSynopsisCategory: Issues related to all UI tools (mgd-bsd/cli-bsd, XML and DMI
1681656System uptime display is shown in minutes instead of seconds
Product-Group=junos
On all Junos and Junos Evolved platforms, after the device reboot, show system uptime command is showing time in minutes instead of seconds for 24 hours.
PR NumberSynopsisCategory: Virtual Private Networks - rpd
1661542Traffic drop may be seen when Inter-AS option-B label spoofing is configured along with vrf-table-label
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when the router is configured as both Autonomous System Border Router and Provider Edge (ASBR and PE), and virtual-router/mpls-forwarding as "forwarding-context" is in use along with "vrf-tabel-label" for the Local Layer 3 Virtual Private Network - Virtual Routing and Forwarding (L3VPN VRF) traffic drop may be seen.
PR NumberSynopsisCategory: Xellent Platform issues
1568294Another port will also be shutdown after shutting down one port on PTX10002-60C/QFX10002-60C
Product-Group=junos
On PTX10002-60C/QFX10002-60C platform, after disabling the standalone/non-channelized port (e.g. port 6, 16,26,36,46,56), then another port on that port group will aslo be disabled. For example, disable et-0/0/36, port et-0/0/30 is going to down as well. This issue is only exposed when using DAC cables.
 
 

20.2R3-S6 - List of Known issues

PR NumberSynopsisCategory: "agentd" software daemon
1598351Subscriber management daemons might continuously core and shutdown with RE sensors invalid configured
Product-Group=junos
On all platforms support JTI (Junos telemetry interface), when 'set services analytics export-profile xxx format gpb-sdm' and 'set services analytics export-profile xxx transport tcp' are enabled on RE sensors, subscriber management related daemons (like authd, bbe-smgd, bbe-statsd, jdhcpd, smid) might continuously crash and core dumps are observed.
1656313Invalid forwarding class configuration in "services analytics export profile" might lead to traffic drop
Product-Group=junos
In a telemetry scenario, the configuration of an invalid "forwarding-class" value at the [edit services analytics export profile] hierarchy goes through in spite of the forwarding-class containing an invalid value. Due to this, the FPC might crash and could cause traffic loss.
PR NumberSynopsisCategory: Border Gateway Protocol
1675893The process rpd (route process daemon) crashes with BGP VPN (Border gateway protocol - Virtual Private Network) config, while ebgp (external bgp) routes exported into ibgp (internal bgp) core with vrf (virtual route forward) configured
Product-Group=junos
On all Junos devices, rpd crashes with BGP VPN configured with vrf-label and exporting eBGP routes to iBGP.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1657659Junos OS Evolved: PTX Series: Multiple FPCs become unreachable due to continuous polling of specific SNMP OID (CVE-2022-22211)
Product-Group=junos
A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows an unprivileged attacker to cause Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA69916 [juniper.net] for more information.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1685453PICs on the GNF failed to come online after the chassisd restart
Product-Group=junos
On MX platforms supporting node-slicing (MX480, MX960, MX2010, MX2020 & MX2008) have an issue that when GNF (Guest Network Function) chassisd restarts, the FPC doesn't restart as expected which causes the PIC (Physical Interface Card) to be offline.
PR NumberSynopsisCategory: EX-Series VC Infrastructure
1700134EX4600 VC: CMQFX PIC reset: Member Disconnect observed during VC initialization after reboot
Product-Group=junos
On EX4600 VC, when an FPC comes up after reboot by the "request system reboot all members" command, if a new PIC is detected during initialization, the PIC validation may fail due to an invalid pic slot.
PR NumberSynopsisCategory: MX Inline Jflow
1588093The Aftcore messages might be seen after the MPC10E/MPC11E line card comes up
Product-Group=junos
On MX platforms, the AftCore messages might be seen after the MPC10E/MPC11E line card comes up. These messages will not affect traffic forwarding and Jflow learning/export. But if the 'nexthop-learning' knob is configured, Jflow will not report the correct outgoing interface (OIF)/Gateway (GW) when the flow destination is reachable through multiple paths.
PR NumberSynopsisCategory: Fast Ethernet interfaces
1684142Traffic is getting impacted as interface hold-time is not working with wan-phy framing
Product-Group=junos
On all Junos MX series platforms, when hold timer and wan-phy are configured, traffic gets impacted when the link goes down on an interface within the configured hold timer.
PR NumberSynopsisCategory: ISIS routing protocol
1515967rpd memory leak if more than one ip-reach tlv is originated for same prefix.
Product-Group=junos
RPD memory leak and eventually coredump if ISIS receives more than one ip-reach tlv is originated for same prefix.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1598207Sometimes MPLS LSP may go down due to a timing issue when a protected link goes down
Product-Group=junos
When a protected link goes down, MPLS gets tunnel local repair message from RSVP and trigger CSPF computation. Next, MPLS gets link protection information through RRO notification. If MPLS receives TED notification first before RRO notification, then CSPF computation fails. Since the link protection flag is not set, MPLS thinks it is an unprotected link and brings down the LSP.
1616841Protected LSP goes down with strict hops and link protection configured
Product-Group=junos
On all Junos and all EVO platforms, the sub-LSP of a Point-to-Multipoint Label Switched Path(P2MP LSP) with link-protection and having strict hops goes down when a protected link on more than one sub-LSP goes down simultaneously and TED(Traffic Engineering Database) notification or RSVP tunnel local repair message not received before the CSPF(Constrained Shortest Path First) computation. As a result, the sub-LSP fails and traffic drop is seen.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1668090Junos upgrade might fail due to file system corruption
Product-Group=junos
On all Junos platforms, file system corruption can result in a corrupted package/db which might lead to an upgrade failure.
PR NumberSynopsisCategory: Protocol Independant Multicast
1676154The rpd crash can be seen in MoFRR scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd ( routing protocol daemon) can crash when PIM (Protocol Independent Multicast), MoFRR (Multicast only Fast Reroute) configuration is present and some network churn event such as continuous interface cost changes, resulting in a change of active and backup paths for ECMP (Equal Cost Multi-Path) happens. There will be service impact because of the rpd crash but the system self-recovers until the next crash.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1620642BGP session may not establish between loopback interfaces when routes are learnt through type5 EVPN routes
Product-Group=junos
On QFX5k platforms,BGP session may not establish between loopback interfaces when routes are learnt through type5 EVPN routes.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1651827The MAC address from local CE may not be learned due to the VLAN programming issue
Product-Group=junos
On QFX5k series platforms, MAC address from local CE (customer edge) might not get learned when EVPN (Ethernet VPN)/VxLAN (Virtual Extensible LAN) is configured. The traffic drop is expected as MAC learning may not happen.
PR NumberSynopsisCategory: Resource Reservation Protocol
1657872Memory utilization keeps incrementing due to the path error message
Product-Group=junos
On all Junos and Junos Evolved platforms, when a no-cspf Label Switched Path (LSP) with strict Explicit Route Object (ERO) is configured and the egress device is disconnected, a high rate of Path Error (PathErr) messages are observed which is leading to high memory utilization and triggering the chassisd crash that causes the device to be out of control, either it can not be accessible via console/ssh or it will not trigger Routing Engine (RE) switchover as well if it is dual-RE. So this would cause an outage.
PR NumberSynopsisCategory: SRX branch platforms
1594014During reboot, "warning: requires 'idp-sig' license" can be seen on the screen even when the device has valid license
Product-Group=junos
If a device is rebooted manually or reboots for any other reason, The following messages can be seen on the boot up screen even when the device has valid license and proper configuration to use the features like IDP/UTM
1658276reth interface does not go up due to speed mismatch when reth interface speed is changed afger RG0 failover
Product-Group=junos
On SRX series platform with chassis cluster enabled, reth interface might not go up due to speed mismatch when reth interface speed is changed afger RG0 failover
PR NumberSynopsisCategory: Configuration management, ffp, load action
1671112Test Configuration might fail even though the config file is having valid configurations
Product-Group=junos
Root cause; In test configuration flow we are calling mustd as "/usr/sbin/mustd -q /var/run/db/file.data /var/run/db/file.data+ -F -m" where we just copy the existing cog.db (generated out of committed config) as cdg.db+ , use it for testing the configuration passed, and remove it once the testing is done. This is creating the issue because the configuration is tested against the existing cdg.db. Fix would be to create the cdg.db fresh from the configuration to be tested and test the configuration against that. This new cdg.db should not replace the existing one in /var/run/db.

 

 

Modification History

2022-11-22 - Update content of PR1700134 and 16850687 - contents missed from previous publication
First publication 2022-11-17