Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 21.4R3-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.4R3-S2 is now available.

21.4R3-S2 - List of Fixed issues

PR NumberSynopsisCategory: Daily JUNOS build failures - automated builder use only
1691209Use latest os-package when upgrading
Product-Group=junos
Upgrade to 22.3R1 while using os-package published between July 2022 and November 2022 may incorrectly link os-libs package
PR NumberSynopsisCategory: EX-Series VC Infrastructure
1685067EX4600-VC - Master RE reboot and All-member reboot lead to PFE Manager hogging logs when SFP-T is plugged in
Product-Group=junos
On Junos EX4600 Virtual Chassis (VC), the master RE reboot and all-members reboot lead to the PFE Manager hogging logs when SFP-T pluggable is installed in. The PFE Manager hogging logs has no functionality impact (PR 1641556).
PR NumberSynopsisCategory: SRX-1RU System Hardware defects
165814822.2TOT SecPDT: SRX4600: After ISSU upgrade completed, RG1 nodes priority remains in CS state and fab interfaces are down.
Product-Group=junos
In some of releases including 21.2R3 or 20.4R3, when performing SRX4600 ISSU from these release to a newer release, in some scenarios, e.g. with some traffics and big volume of configurations, after node1 is upgraded and a RG0 failover is performed from node0 to node1, it is observed that RE CPU on both nodes are 0% idle which causes some RE daemons (e.g. jsrpd) scheduling slip on old-version node0, which can sometimes lead to temporarily control-link down, which further causes node0 to go to ineligible state. This further leads to node0's EEPROM being programed a zero (unexpected) value to primary-id before its reboot. Later when node0 boots up, node0's flowd will be stuck reading EEPROM primary-id since it's zero. This leads to node0's control-port brought up by flowd late and finally causes a RG0 split-brain. A cluster reboot may be needed to fix the issue. It is unclear why RE is so busy during ISSU in such setup, while the manual failover of RG0 on same setup never leads to node0 to go to ineligible state. A few suggestions: 1. Please reduce traffics and configurations during ISSU, better to do in maintenance window and add back after ISSU complete. 2. Before ISSU, perform a few times of manual RG0 failover and monitor RE CPU percentage. If RE CPU percentage is very high for a few seconds on both nodes, please consider to reduce traffics. 3. If the ISSU older image is on any releases that are with fix of this PR, this problem will not be seen.
PR NumberSynopsisCategory: a20a40 specific issue
1681701"%DAEMON-4: Set system alarm failed: Operation not supported by device" message is seen on high end SRX
Product-Group=junos
On high end SRX platform, "%DAEMON-4: Set system alarm failed: Operation not supported by device" message is seen when system/chassis alarm is generated
PR NumberSynopsisCategory: BBE Autoconfigured DVLAN related issues
1680453The process bbe-smgd on the router would stop processing new PPPoE subscribers session
Product-Group=junos
On all Junos platforms configured with subscriber-management, the process bbe-smgd will stop processing new PPPoE (Point-to-Point Protocol over Ethernet) connections due to a memory leak in the control packet pool of the PPPoE plugin.
PR NumberSynopsisCategory: Express Broadway PFE L3
1680757BFD sessions will remain down in the EVPN-VxLAN scenario
Product-Group=junos
On QFX 10008 and QFX10016 platforms, in a distributed mode Bidirectional Forwarding Detection(BFD) session might remain down if the anchor FPC and the FPC where BFD packets are received over Virtual Tunnel Endpoint (VTEP) are different.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for cos
1650598MX960:: Syslog errors HALP-trinity_vbf_flow_unbind_handler:1107: vbf flow 624626: ifl 526 not found,fpc5 vbf_var_get_ifs:754: ifl not found,PFE_ERROR_NOT_FOUND seen frequently on MPC7E in 5.5K DCIP/10kPPPoE FTTB Stress Test
Product-Group=junos
With MPC7 cards used as Junos Subscriber Management access cards, the following log message may be generated upon disconnect: HALP-trinity_vbf_flow_unbind_handler:xxxx: vbf flow xxxxx: ifl xxx not found,fpcx vbf_var_get_ifs:xxx: ifl not found It indicates that a second call to release resources is generated for the same subscriber flow. The request is ignored and no functional impact is observed.
PR NumberSynopsisCategory: EVPN ELAN/E-TREE
1690590Packet forwarding fails on specific ACX Junos platforms due to flapping of core interface member link in the MPLS-EVPN environment
Product-Group=junos
On specific ACX Junos platforms (ACX5448/ACX710), forwarding traffic is getting impacted the MPLS-EVPN environment as kernel memory is exhausted with continuous core link flaps.
PR NumberSynopsisCategory: ACX platform interface issues
1685431ACX710 : Auto-mdix is not working in ACX710
Product-Group=junos
Due to auto-mdix being disabled on the PHY, ACX-710 does not recognize SFP-T optics with straight cables. So the port will not come up. Port will come up only when customer changes to cross-cable
PR NumberSynopsisCategory: ACX VRRP
1666853Traffic loss is observed when the VRRP is configured over the AE interface
Product-Group=junos
On ACX5448 platforms, the Virtual Router Redundancy Protocol (VRRP) is up from Routing Engine (RE) but the group is not created under the Packet Forwarding Engine (PFE) due to this VRRP virtual IP (VIP) is neither responding to ping nor accept any traffic when the VRRP is configured over Aggregated Ethernet (AE) interface. This results in traffic loss.
PR NumberSynopsisCategory: Control plane EVPN multicast
1670435EVPN multicast traffic may get impacted because of routes getting stuck in the kernel routing table (krt) queue
Product-Group=junos
On all Junos and Junos Evolved platforms with Ethernet Virtual Private Network(EVPN) enabled, in the presence of certain triggers like rpd restart, rollback of configuration etc., EVPN multicast routes might get stuck in the kernel routing table (krt) queue due to which the corresponding routes in the forwarding table may point to 'fictitious' next hops, resulting in traffic disruption.
PR NumberSynopsisCategory: EX4400 platform
1691174The factory default config does not have xe-0/2/0.
Product-Group=junos
On EX4400-24T, it is observed that the factory default configuration does not have interface xe-0/2/0.
PR NumberSynopsisCategory: Express ASIC platform
1683562On PTX5000 platforms when a command is issued to power off an FPC, it gets stuck in the 'Announce Offline' state
Product-Group=junos
When an FPC (Flexible PIC Concentrator) on PTX5000 platforms is shut down by issuing a request command (request chassis offline slot ) or by FPC power off configuration (set chassis fpc x power off), it gets stuck in the 'Announce Offline' state since the associated timer (fru_graceful_offline_timer) doesn't increment and expire as it is supposed to.
PR NumberSynopsisCategory: idp flow creation, deletion,notification, session mgr intfce
1665442Execute RSI on SRX5K platform may generate flowd core-dump and trigger data plane failover
Product-Group=junos
On SRX5K platforms, a dataplane failover might be triggered by a flowd coredump when executing the command "request support information".
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1680889Traffic drop would be observed only when the backup link is up on link-protection LAG interface
Product-Group=junos
On all Junos platforms, when the Link Aggregation Group (LAG) interface is configured with static link-protection, the packet goes out via the active member (primary) link of LAG; instead, if the backup link comes up first, then a timer of 10 seconds kicks to start and once the timer expires then the backup link is marked to be a new active link of LAG which takes the traffic.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1685406The protocol MTU for the IRB interface is not rolled back when the MTU of the IRB or IFD interfaces is modified or deleted
Product-Group=junos
On all Junos platforms, the maximum transmission unit (MTU) on the Integrated Routing and Bridging (IRB) interface is not getting reset when the MTU configuration on IRB or IFD is removed. When MTU configuration is removed from the IRB interface, the internal data structure for the MTU configuration is not getting reset which might affect traffic and it is a rare case.
PR NumberSynopsisCategory: JFlow bug tracker for SRX platforms
1688627The system may crash when Jflow inactive timeout is configured to be less than 'previous flow-inactive-timeout + 180' seconds
Product-Group=junos
On SRX platforms, when Jflow inactive timeout is configured to be less than 'previous flow-inactive-timeout + 180' seconds result in a system crash and core files are generated.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1686613SIP calls are getting dropped due to NAT failure and SIP ALG is enabled
Product-Group=junos
On all MX and SRX platforms which support the SIP ALG (Session Initiation Protocol Application Layer Gateway) feature, SIP calls are getting dropped due to NAT (Network Address Translation) failure and failure to allocate XLATE context. The issue happens when there are multiple SIP INVITEs with different media IPs that arrive on the same SIP call. The drop is seen from the 4th SIP INVITE packet onwards.
PR NumberSynopsisCategory: Flow Module
1692100SOF was incorrectly offloading short-lived flows leading to early exhaustion of NP memory, reducing overall device performance
Product-Group=junos
On SRX5K and SRX4600 series platforms, Automated Express Path (SOF) was incorrectly offloading short-lived flows. This consumed additional resources on the Network Processor (NP) which could lead to an early exhaustion of its memory, reducing overall device performance. By default, Automated Express Path (SOF) is designed to offload flows which are high bandwidth/throughput in nature.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1686648In specific scenario, condition route-active-on import is not working properly after RG0 failover.
Product-Group=junos
In specific scenario, condition route-active-on import is not working properly after RG0 failover.
1691071Chassis cluster IP monitoring on the secondary node failed after the system reboot on the SRX platforms
Product-Group=junos
On SRX platforms, IP monitoring on the secondary node failed when a Reth (redundant Ethernet) interface consists of two or more than two interfaces on each node. Reth member interface which has a higher port number cannot receive ICMP (Internet Control Message Protocol) packet used for IP monitoring, which will then put the system in an error state.
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1687244unexpected default event-rate value for event mode logging
Product-Group=junos
On SRX platform, when event mode logging is used without event-rate option, the logging rate was unexpectedly set to 100 although the default event rate is 1500
PR NumberSynopsisCategory: IPSEC/IKE VPN
1667223VPN traffic loss is seen after HA node reboot while using traffic selectors
Product-Group=junos
On all Platforms, traffic across static VPNs (Virtual Private Network) with traffic selectors might be affected after reboot of one node in the cluster and failover to it.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1686523VPLS traffic loss might be seen when deleting and adding a routing-instance
Product-Group=junos
VPLS (Virtual Private LAN Service) traffic stops on all Junos and Junos Evolved platforms after adding/changing interfaces in the routing instance. Restarting l2ald daemon may restore the VPLS services.
PR NumberSynopsisCategory: Label Distribution Protocol
1670334Traffic loss will be seen in an LDP->BGP-LU stitching scenario
Product-Group=junos
On all QFX platforms, traffic loss can happen when the BGP-LU (Labeled Unicast) routes are exported to LDP (Label Distribution Protocol) to perform LDP->BGP-LU stitching, on a device with directly connected BGP peers.
PR NumberSynopsisCategory: MPC11 ULC interface software related issues.
1685997The 100G interfaces on an MPC11E remain in a down state on MX platforms after a system or FPC restart
Product-Group=junos
On MX2010/MX2020 platforms, 100G interfaces remain in a down state after the reboot of the MPC11E line card or a restart of the system.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1655031The rpd core is seen due to IGP database and BGP LS database out of sync
Product-Group=junos
On all Junos and Junos OS Evolved platforms, rpd core is hit when the events for deleting prefixes, sids, links and nodes come in out of order which occasionally leads to IGP database and BGP LS database out of sync.
1690458On a controller based MPLS setup with container LSPs, rpd daemon crashes after LSP deletion occurs
Product-Group=junos
On all Junos-based platforms, in a scenario where an external controller is provisioned, rpd crashes when an externally controlled container LSP (Label Switched Path) is deleted and the software tries to update its status.
PR NumberSynopsisCategory: Used for tracking OVSDB software issues and features
1687847OVSDB certificate files are not copied from the Master to the Backup
Product-Group=junos
On all Junos devices which support OVSDB (Open vSwitch Database) functionality, when a new backup is added on VC (virtual chassis), the master does not copy the certificate files to the backup. This impacts the OVSDB functionality and affects the traffic.
PR NumberSynopsisCategory: Path computation client daemon
1675816In a rare case, 'pccd' will crash when the PCEP connection is down
Product-Group=junos
On all Junos and Junos Evolved platforms, on the intermediate device when connection towards Path Computation Element (PCE) is down, Path Computation Element Protocol (PCEP) session will be down resulting in pccd crash. Routing protocols are not impacted but pccd crashes.
PR NumberSynopsisCategory: Protocol Independant Multicast
1675212MX304:Bugatti: KRT queue shows deferred operation while creating IFL after FPC offline/online event
Product-Group=junos
Dynamic IFL add request is waiting to be processed in KRT queue during that if chassid down event occurs. To handle the chassid down event RPD Infra sends notification to protocol(producer of Dynamic IFL add request) and it is producer jobs to DELETE the dynamic ifls request which were there in the KRT queue. PIM code is not clearing those Dyanamic IFLs ADD request during chassis fpc down event. Hence getting error 'ENOENT -- Item not found' when chassis comes back up.
PR NumberSynopsisCategory: JRR - VRR running on SRX4200
1691694A 802.1Q tagged Ethernet traffic with an expected VLAN ID and with a non-zero 802.1P value ingressing a JRR200 VLAN enabled interface is dropped.
Product-Group=junos
A 802.1Q tagged Ethernet traffic with an expected VLAN ID and with a non-zero 802.1P value ingressing a JRR200 VLAN enabled interface is dropped. This problem could happen at a JRR200 system running a 21.1+ JUNOS release.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1687395On single PFE with Fusion satellite, LACP is not sending PDUs
Product-Group=junos
On platforms supporting Fusion technology, LACP (Link Aggregation Control Protocol) is not up on the aggregate ethernet interfaces when a satellite device is connected to an aggregate device with a single PFE (Packet Forwarding Engine) and is upgraded to a software version 19.4 and above.
PR NumberSynopsisCategory: QFX L2 PFE
1667069PVLAN IGMP packet is forwarded between Isolated ports and also duplicated to primary vlan port (Promiscous).
Product-Group=junos
When Isolated port receives IGMP packet, it should not be forwarded to other Isolated ports but was forwarded and also duplicated to primary vlan port (Promiscous).
1681614LLDP neighborship fails to come up with a Private VLAN configuration
Product-Group=junos
On the Junos platforms, In a Virtual Chassis (VC) scenario if the interface is configured with Private VLAN (PVLAN) and connected through the Flexible PIC Concentrator (FPC) of the non-master switch, the LLDP (Link Layer Discovery Protocol) neighborship fails to come up and traffic through the interface will be impacted.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1687565VxLAN configured on access port breaks L2 connectivity with "vxlan encapsulate-inner-vlan" knob
Product-Group=junos
On all Junos QFX5k platforms, L2 connectivity fails when "vxlan encapsulate-inner-vlan" knob is configured on an access port. It impacts a forwarding plane and causes a traffic impact.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 linecard, serdes and uboot
1688993On QFX10008/QFX10016 platforms fails to detect flaps even though the remote device connected has observed flaps
Product-Group=junos
On QFX10008/QFX10016 platforms, interface faults(Local/Remote) of very short duration (<30msec) can go undetected. The interface does not go down due to these faults leading to unidirectional link and traffic blackholing.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1676740,The traffic doesn't re-route quickly causing traffic blackholing
Product-Group=junos
On all VMHOST based platforms, traffic blackholing happens because the traffic doesn't re-route quickly as chassisd doesn't recognize an FPC failure from a BAD_VOLTAGE notification.
PR NumberSynopsisCategory: QFX5100 Interface related issues
1688023The LLDP output packets are not transmitting on the em0 interface of Junos and Junos OS Evolved platforms
Product-Group=junos
On Junos and Junos OS Evolved platforms, if a management Ethernet interface(em0) has an inet or inet6 family configured and "delete interfaces em0" is issued, the Link Layer Discovery Protocol (LLDP) output packets will stop transmitting, causing the LLDP neighborship to remain down in peer router.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1639252High CPU utilization for rpd process might be seen
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, the rpd process might utilize a large amount of the CPU during commit. This might only be seen in a scaled static route setup with virtual routing and forwarding (VRF) and Bidirectional Forwarding Detection (BFD) configured. The reason for the CPU spike is that kernel routing table (KRT) might get stuck and keep running for a long time. The high CPU might hamper the rpd process functionality in rare cases. However, the system recovers by itself when it encounters this issue.
1686211The rpd crash would be observed when two separate next-hops in rpd map to the same next-hop-index in the kernel
Product-Group=junos
On all Junos and Junos Evolved platforms, when a route is getting installed to the forwarding table, associated next-hops also get installed in the forwarding table. As part of this installation process, the Junos kernel allocates the next-hop-index for the next-hop. The rpd sets this next-hop-index in its database when two separate next-hops for instance NH1 and NH2 in the rpd map to the same next-hop NH in the kernel. In such case, NH1 and NH2 next-hops in rpd will have the same next-hop-index leading to the rpd crash.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1683883srv6-oam: more than one label stack is not suppoting,gives as "Maximum number of sids supported is 0" error in srv6 ping in Alfa-Romeo[lc9600]
Product-Group=junosvae
When "Ping/traceroute srv6 spring-te sids-stack sids[] nexthop-interface <> nexthop-address <>" command is initiated and "maximum-srv6-sids" stanza is not present in default platform conf files, Ping/traceroute will be aborted with error "maximum-srv6-sids supported is 0". As a workaround, please set the below configurations, after which SRv6 Ping/traceroute will be successful. "set routing-options platform-parameters maximum-srv6-sids 6" Note: In case of traceroute, after above configuration is committed, "mplsoamd" daemon restart is required.
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1692063PCS errors and framing errors on 100GE interfaces on certain Juniper platforms
Product-Group=junos
On certain Junos platforms with specific PIC (Physical Interface Card)/MIC (Modular Interface Card)/FPC (Flexible PIC Concentrator), PCS (Physical Coding Sublayer) errors and framing errors would be seen on 100GE interfaces with LR4 optics or its peer device on Junos to 20.2R1 or later releases. The framing/CRC (Cyclic Redundancy Check) errors which would be seen when the PCS error rate is high could lead to packet drops hence impacting data services. As a workaround enabling FEC (forwarding Error Correction) feature on the impacted interface may reduce the frequency of packet drop.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1689705SNMP MIB walk for jnxBoxDescr OID returns incorrect value
Product-Group=junosvae
On SRX4600 platforms running Junos, SNMP MIB walk for jnxBoxDescr OID returns the incorrect chassis name and model. This is only a display issue with no service impact.
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1688416The COS queue burst size computation was incorrect when the explicit queue shaping rate was not configured, causing initial packet drops
Product-Group=junos
On specific linecards MPC10/11/LC9600 and MX304 device, there was an issue with the COS (Class of Service) queue burst size calculation when the explicit queue shaping-rate was not configured, resulting in an initial packet drop and the COS queue burst size computation was incorrect which causes packets to drop initially.
1696089FPC crash is observed in GNF scenario with CoS configuration
Product-Group=junos
On Junos and Junos Evolved platforms, in GNF (Guest Network Function) setup when CoS (Class of Service) configuration is attached on an IFL (Interface Logical) stacked over another IFL and the CoS configuration message is received on an FPC (Flexible PIC Concentrators) which does not host the IFLs IFD (Interface Device), then the FPC can crash because the FPC does not have any information about the IFLs or underlying IFDs.
PR NumberSynopsisCategory: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1681533The line card gets crashed during node/interface statistics reporting with resource monitoring
Product-Group=junos
On MX platforms with specific line cards, the MPC may crash and generate core dumps in a corner case during node/interface statistics reporting scenario when resource monitoring is used.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1689621"failed to get template var id" error messages are generated by FPC when BFD liveness detection is negotiated by DHCP subscriber which has lawful intercept enabled
Product-Group=junos
In subscriber management environment, "failed to get template var id" error messages are generated by FPC when BFD liveness detection is negotiated by DHCP subscriber which has lawful intercept enabled.
PR NumberSynopsisCategory: Trio pfe multicast software
1682383Incorrect programming of next-hop based on RVT interface hosted on MPC10E/MPC11E, LC9600, MX304 leads to traffic drops
Product-Group=junos
On MX304 and MX platforms MPC10E, MPC11E, and LC9600 line cards, traffic loss is observed for the traffic not being directed from the core to the routing-instance in MVPN (Multicast VPN) (hot-root-standby) environment with RVT (Redundant Virtual Tunnel) interface as upstream. The tunnel attribute for the RVT interface is not set, due to which it returns failure which in turn results in the default Ethernet encapsulation creation.
PR NumberSynopsisCategory: VMHOST platforms software
1646339The alarm might not be generated for EDAC errors until the FPC is rebooted
Product-Group=junos
On all MX and PTX platforms, EDAC errors are triggered but alarms are not observed until the FPC gets rebooted due to the data corruption in hardware.
PR NumberSynopsisCategory: usf nat related issues
1692525ALG child session will not be transported through the DS-Lite tunnel which might lead to traffic failures in absence of a direct route to the host
Product-Group=junos
On Junos MX240/MX480/MX960 platform with MX-SPC3, a tunnel ID of the control session is not updated properly on the gate created for Session Initiation Protocol (SIP) Application Layer Gateway (ALG), which is leading to the gate hit session not mapping back to the Dual-Stack Lite (DS-Lite) tunnel. This might result in traffic failure if the client does not have a direct route to the host.
 
 

21.4R3-S2 - List of Known issues

PR NumberSynopsisCategory: EX4300 Platform implementation
1668414On EX4300-48MP, NSSU abort is seen with "error: rebooting VC". VC instability and dc-pfe core is observed after reboot.
Product-Group=junos
On EX4300-48MP, NSSU abort is seen with "error: rebooting VC". VC instability and dc-pfe core is observed after reboot.
PR NumberSynopsisCategory: EX2300/3400 PFE
1647209DHCP traffic might be dropped when DHCP-security and RTG are enabled
Product-Group=junos
On EX2300, EX2300-48MP, and EX3400 platforms, when DHCP-security and Redundant Trunk Group (RTG) are enabled clients connected over RTG might not get DHCP IP and DHCP traffic might be dropped.
1685938MAC address learning might not happen on specific EX/QFX platforms
Product-Group=junos
On specific EX/QFX platforms (EX2300/EX3400/EX4300-MP/EX4100/EX4400/QFX5K), MAC learning is not happening in any of the interfaces of the particular VLAN (contains both LAG (Link Aggregation Group) and non-LAG interfaces) when VSTP (VLAN Spanning Tree Protocol) is enabled on LAG interface with no child interface and VSTP is disabled for non-LAG interfaces. It causes a traffic impact as mac address learning does not happen for all interfaces on the VLAN.
PR NumberSynopsisCategory: EX-Series VC Infrastructure
1700133EX4600 VC: Member Disconnect observed during VC initialization after reboot (with I2C read access failure)
Product-Group=junos
When ?request system reboot all members? command is executed on EX4600VC, post reboot one of the FPCs may disconnect and join the VC back. The FPC reboots with reason "FXPC_RENESAUS_RETRY_FAILURE: fxpc_fpga_fpc_ideeprom_read: FAILED retry to Renesaus chip", This issue may be hit approximately once in 10-12 attempts of cli command ?request system reboot all members? execution.
PR NumberSynopsisCategory: SPC3 HW and SW Issues
1692611SRX cluster may fail in a rare scenario when node status changes to disabled state without going through the ineligible state
Product-Group=junos
On SRX platforms with chassis cluster configured, the RE(Routing-Engine) & PFE (Packet Forwarding Engine) connection may break, and the cluster may fail when the node status changes from primary/secondary state to disabled state without going through the ineligible state.
PR NumberSynopsisCategory: CoS support on ACX
1689604EVPN Traffic is classfied in the wrong queue
Product-Group=junos
The classifier on CE facing interface is not bound correctly after core facing interface flaps. It makes the traffic going to the wrong queue. Restart the FPC can restore the device.
PR NumberSynopsisCategory: ACX Services feature
1633395Delegated BFD sessions configured on routing-instance may fail to come up
Product-Group=junos
On ACX5448 and ACX710 platforms, all types of delegated BFD sessions configured on routing-instance other than the default routing-instance might not come up.
PR NumberSynopsisCategory: Border Gateway Protocol
1652666Wrong next-hop weight might be observed with BGP PIC enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms, wrong weight might be observed with BGP PIC (Border Gateway Protocol Prefix Independent Coverage) enabled.
1659441Routing Process Daemon (rpd) crashes and restarts when a specific timing condition is hit with BGP configuration
Product-Group=junos
On all Junos platforms and all Junos Evolved platforms, Routing Process Daemon (rpd) crashes and restarts when BGP (Border Gateway Protocol) is configured and a specific timing condition is hit for secondary route. This issue might cause a traffic impact.
1677624Bgp peers status is not as expected
Product-Group=junos
Not fixed in the Current release, the issue was recreated only with IXIA connection. Arp response is not received in the DUT port to store the destination MAC address. unable to determine if the issue is with the MX port or medium or IXIA port.
1679646The AGGREGARTOR attribute will not be set correctly when the independent-domain is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in BGP deployments with the "independent-domain" and aggregate routes configured under routing-instance, the AGGREGATOR attribute encapsulated within the ATTR_SET will not be populated correctly. This can result in unintended behavior or service impact because the BGP neighbors receiving this update may discard it as it is not RFC complaint.
1691131Backup Path is Not Found in ASBR6 MPLS Table while verifying BGP Multipath Protection functionality
Product-Group=junos
Backup Path is Not Found in ASBR6 MPLS Table while verifying BGP Multipath Protection functionality
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1676008MPC stuck in present state with log " graceful offline in progress, returning false" flooding
Product-Group=junos
In over temperature situation, there will be a 10s timer before device bring the FPC down . However in some situation due to high temperature, a FPC offline action will be triggered before the 10s timer expires. Then the FPC will stuck in Present/Announce offline state. Cli offline/online it or physical reseat will not be able to recover the issue. When the issue happening, you may observe log message " graceful offline in progress, returning false" flooding: <<< fpc_ok_to_start_generic: [FPC 0] gracefull offline in progress, returning false fpc_ok_to_start_generic: [FPC 0] gracefull offline in progress, returning false <<< Below MPCs are affected by this issue: MPC7/8/9 MPC10 MPC11 LC480 LC2101 LC9600 LC304 LC4800 FPC-P2, FPC-P3
PR NumberSynopsisCategory: Class of Service
1693977The oid tree jnxCosQstatEntry returns nothing for some interfaces after restarting class-of-service
Product-Group=junos
When the oid tree of jnxCosQstatEntry is used to get value, and cosd restart or global swichover happens, the oid woun't return values for that oid. That is because the IFD/IFL async events come from kernel before cosd triggers snmp_subagent_init. The fix will make sure cosd triggers snmp_subagent_init before IFD/IFL async events.
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1650202ARP/NS response to anycast IRB might fail due to missing mac-ip entry
Product-Group=junos
On all Junos and EVO platforms, IRB (Integrated routing and bridging) static entry might be missing in the mac-ip-table for mac move allowed for local static IRB entry.
PR NumberSynopsisCategory: ACX BFD specific issues
1670684New BFD sessions will not come up on ACX5448/ACX710 due to continuous flaps
Product-Group=junos
On ACX710/ACX5448 platforms, if the Bidirectional Forwarding Detection(BFD) endpoint ID in chipset level reaches ~8K (for ACX710) or ~16k (for ACX5448),the following BFD session can't be created properly and be stuck at Init state. Once the issue is hit, disable BFD configuration and restart the bfdd process to make the endpoint ID roll over from 16.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1683312'clear interfaces statistics all' taking more than 9 min due to invalid PIC configuration inside GNF.
Product-Group=junos
Invalid PIC configuration inside GNF may add delay to 'clear interface statistic all' command. This issue does not impact any functionality. chassis fpc pic
1685453PICs on the GNF failed to come online after the chassisd restart
Product-Group=junos
On MX platforms supporting node-slicing (MX480, MX960, MX2010, MX2020 & MX2008) have an issue that when GNF (Guest Network Function) chassisd restarts, the FPC doesn't restart as expected which causes the PIC (Physical Interface Card) to be offline.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1693424Traffic loss is observed when the ECMP path is IRB over AE (IPv4->MPLS)
Product-Group=junos
On QFX10002 platforms, when the ECMP (Equal-cost multi-path) path is IRB (Integrated routing and bridging) over AE (Aggregated Ethernet) {IPv4->MPLS (Multiprotocol Label Switching)} results in packets getting discarded for which traffic loss is observed.
PR NumberSynopsisCategory: Express PFE L3 Multicast
1678723On QFX10008, pps statistics for multicast packets is not as expected
Product-Group=junos
On QFX10008, Statistics for multicast packets is not as expected as the packets has L2 header stripped during replication in PFE because of which it is not forwarded to the next hop.
PR NumberSynopsisCategory: Express ASIC interface
1669267PCS errored blocks count increments on PTX3000/PTX5000 after Junos software upgrade
Product-Group=junos
On PTX platforms, packets drop is seen because of increment in PCS and framing errors on some of the 100GE ports on PIC or its peer devices after firmware migration.
PR NumberSynopsisCategory: Interface Information Display
1611623SRX1500: Traffic fail seen on irb interface for network control forwarding class when verifying dscp classification based on single and multiple code-points
Product-Group=junos
Traffic drop might be seen on irb interface on SRX1500 for network control forwarding class when verifying dscp classification based on single and multiple code-points.
PR NumberSynopsisCategory: ISIS routing protocol
1674804Segment-routing may incorrectly set a pop action for paths using a Strict SPF(1) Algorithm
Product-Group=junos
On all Junos and Junos Evolved platforms, segment-routing sets a pop action for paths using a Strict SPF(1) Algorithm incorrectly.
1677567Label traffic will be dropped at the one-hop LSP stitching node if the packet has more than one label
Product-Group=junos
On all Junos and Junos Evolved platforms supporting the Segment Routing (SR) feature, when segment routing and Label Distribution Protocol (LDP) stitching are configured, the label traffic drop is observed at the one-hop Label Switched Path (LSP) stitching node when the labeled packet is received with more than one label.
PR NumberSynopsisCategory: jdhcpd daemon
1688272IPv4 ALQ not working with authentication
Product-Group=junos
IPv4 ALQ not working with authentication. The below error would be seen on the backup router: "Message failed sanity test - the access-profile info is invalid. length:0 "
PR NumberSynopsisCategory: jl2tpd daemon
1667950VMcore or RE crash might be triggered due to the memory corruption when the FPC is restarted for LNS subscribers
Product-Group=junos
On all MX platforms, when Flexible PIC Concentrators (FPCs) restart for L2TP network server (LNS) subscribers stacked over aggregated service interface (asi) and LNS subscribers belong to more than one routing instance causes the VMcore or Routing Engine (RE) crash and brings down all the traffic.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1693730Traffic loss will be seen when MACSEC is configured
Product-Group=junos
On all Junos platforms where MACSEC(Media Access Control Security) is configured with 60s SAK (secure association key) rollover, traffic loss will be observed during RE (Routing Engine) switchover.
PR NumberSynopsisCategory: SW PRs for MPC10E Chassisd
1664448The command "show chassis fpc" shows inaccurate information about heap memory
Product-Group=junos
The command "show chassis fpc" shows inaccurate information about heap memory in output.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1655031The rpd core is seen due to IGP database and BGP LS database out of sync
Product-Group=junos
On all Junos and Junos OS Evolved platforms, rpd core is hit when the events for deleting prefixes, sids, links and nodes come in out of order which occasionally leads to IGP database and BGP LS database out of sync.
1697982[MX]L2VPN ping is failing when UHP rsvp LSP is used.
Product-Group=junos
MPLS L2VPN ping is getting failed when MX is egress. In egress, RE verifies whether received label is VC label or not. For most of the platforms, tunnel label will be removed in PFE before punting the echo request packet to RE. But in this platform, tunnel label is not removed hence RE verifies this tunnel label and it is returning no-mapping.
PR NumberSynopsisCategory: Multicast for L3VPNs
1675099The multicast receiver receives no traffic in an extranet scenario having an SPT tree already established
Product-Group=junos
On Junos and Junos Evolved MX/PTX platforms, if the SPT (Shortest-Path Tree) tree is already established on PE (Provider Edge) it sends (s,g,rpt) prune which will lead to no traffic to the multicast receiver in an extranet scenario.
PR NumberSynopsisCategory: Express Chip L3 software
1660606MVPN traffic is getting dropped on PTX/QFX series platforms
Product-Group=junos
On all Junos PTX and QFX10k series platforms, MVPN (Multicast Virtual Private Network) traffic is getting dropped with a discarded error. This is because, the way LSI (Label Switched Interface) interface data is carried from ASIC (Application-Specific Integrated Circuit) to PFE (Packet Forwarding Engine) is changed, causing MVPN to break.
PR NumberSynopsisCategory: QFX MPLS PFE
1687257QFX5120 will drop ingress traffic on a l2circuit configured interface if that interface flaps repeatedly.
Product-Group=junosvae
QFX5120 will drop ingress traffic on a l2circuit configured interface if that interface flaps repeatedly.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1670240The dcpfe process might generate core-dumps and FPC might crash after line card reboot or switchover
Product-Group=junos
On QFX10K, PTX10K, PTX5K, PTX3K, and PTX1K platforms, the dcpfe process might generate core-dumps and FPC might crash after line card boot or switchover. The BIST (Built-in Self Test) might report an error in the HMC (Hybrid Memory Cube) and restart the dcpfe process causing FPC crash.
PR NumberSynopsisCategory: QFX5100 Interface related issues
1665800Ports with SFP-T 1G plugged in may go to hung state on QFX5100 platforms
Product-Group=junos
When the remote end server/system reboots, QFX5100 platform ports with SFP-T 1G inserted may go into a hung state and remain in that state even after the reboot is complete. This may affect traffic after the remote end system comes online and resumes traffic transmission.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1660532The port LEDs do not light up when 40G physical interfaces are up.
Product-Group=junos
The port LEDs do not light up when 40G physical interfaces are up. This is a display issue. There is no service impact when this issue occurs.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1661602The dc-pfe process crash is observed with PTP Transparent clock on QFX platforms
Product-Group=junos
On QFX platforms that support only a PTP (Precision Time Protocol) Transparent clock, without any PTP Boundary or ordinary clock, the dc-pfe process crash is observed if there is any disconnect between PFE (Packet Forwarding Engine) and Clock sync process (clksyncd). As the dc-pfe process cores, the physical interfaces will be deleted and there will be a functional or traffic impact.
1667397Some 10G ports are missing from FPCs after rebooting the device with 1G Ports enabled on one FPC
Product-Group=junosvae
On Junos EX4650 virtual chassis (VC) setup and QFX5120-48y platforms, after enabling 1G ports on one FPC and rebooting the entire VC, some 10G ports which have already been up and running on other FPCs may miss from CLI output of "show interfaces terse". Production traffic will be impacted by this issue. The cause of issue is that configuration change on one FPC is propagated to other members of VC. Configuration files should be removed on FPCs on which the 10G ports are present. After that, upgrade/re-image the VC to fixed versions and issue will not be observed any longer.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Virtual Chassis
1636668Pyrite_VC: em0 interface ppeed is reflecting as 10G instead of 1G
Product-Group=junos
Management interface speed is displayed as 10G instead of 1G though there is no functionality impact.
PR NumberSynopsisCategory: Resource Reservation Protocol
1657872Memory utilization keeps incrementing due to the path error message
Product-Group=junos
On all Junos and Junos Evolved platforms, when a no-cspf Label Switched Path (LSP) with strict Explicit Route Object (ERO) is configured and the egress device is disconnected, a high rate of Path Error (PathErr) messages are observed which is leading to high memory utilization and triggering the chassisd crash that causes the device to be out of control, either it can not be accessible via console/ssh or it will not trigger Routing Engine (RE) switchover as well if it is dual-RE. So this would cause an outage.
1681403In the RSVP-TE scenario, with Entropy label capability is enabled during MBB issues handling Resv Messages
Product-Group=junos
On all platforms with entropy-label configured, the issue shows up during Make-Before-Break (MBB) at a transit Juniper node when non-Juniper Egress constructs and sends a Resv message with multiple flow-descriptors (includes descriptors for both old and new instances). Juniper transit device has an issue handling such Resv Messages, the RRO object that is part of the flow-descriptor was getting dropped when the LSP_ATTRIBUTES object was also present within the flow-descriptor.
PR NumberSynopsisCategory: SRX Argon module
164666121.3R2:SRX_RIAD:srx1500,srx4200:SKYATP:IMAP/IMAPS Email permitted counter is not incremented in AAMW email statistics while testing whole email block.
Product-Group=junos
The SKYATP:IMAP/IMAPS Email permitted counter may have incorrect value under certain conditions.
PR NumberSynopsisCategory: SRX branch platforms
1594014During reboot, "warning: requires 'idp-sig' license" can be seen on the screen even when the device has valid license
Product-Group=junos
If a device is rebooted manually or reboots for any other reason, The following messages can be seen on the boot up screen even when the device has valid license and proper configuration to use the features like IDP/UTM
1658276reth interface does not go up due to speed mismatch when reth interface speed is changed afger RG0 failover
Product-Group=junos
On SRX series platform with chassis cluster enabled, reth interface might not go up due to speed mismatch when reth interface speed is changed afger RG0 failover
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1689644A 1G port on a QSFPP-4x10G transceiver will be down sometimes after the FPC restart
Product-Group=junos
On MX204 device, a QSFPP-4x10G transceiver configured at 1G speed sometimes stays down after a FPC restart. Traffic will not pass through the port.
PR NumberSynopsisCategory: MX10003/MX204 Timing/Sync-E issues tracking
1663065The offset value might be high on the downstream node while switching between line cards which impacts 5G services
Product-Group=junos
On Junos MX10003 platform, the offset value might be high on a downstream node which impacts 5G services. While switching the SyncE(Synchronous Ethernet) and slave PTP (Precision Time Protocol) interface between line cards, SyncE will be in a holdover state for a long time and the clock will not get locked. SyncE clock status can be monitored using the following command "show chassis synchronization extensive"
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1522896Egress traffic loss might happen because of PFE MTU feature problem
Product-Group=junos
On MX and EX9200 serial platforms, under Ethernet VPN (EVPN) environment, packets routed using IRB interface could not be fragmented due to media maximum transmission unit (MTU) problem.
1686220BFD flap is observed after VPLS mac-table clear
Product-Group=junos
BFD flap is observed after executing VPLS mac-table clear command.
1696106On a EVPN-VXLAN scenario packets received from type-5 tunnel is not sent out to local CE
Product-Group=junos
In EVPN-VxLAN, traffic drop can be seen for some local CEs which are multihomed to at least one MX Router

 

Modification History

First publication 2022-12-01