Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX EX MX NFX PTX QFX SRX vSRX
Alert Description
Junos Software Service Release version 21.4R3-S2 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 21.4R3-S2 is now available.
21.4R3-S2 - List of Fixed issues
PR Number
Synopsis
Category: Daily JUNOS build failures - automated builder use only
1691209
Use latest os-package when upgrading
Product-Group=junos
Upgrade to 22.3R1 while using os-package published between July 2022 and November 2022 may incorrectly link os-libs package
PR Number
Synopsis
Category: EX-Series VC Infrastructure
1685067
EX4600-VC - Master RE reboot and All-member reboot lead to PFE Manager hogging logs when SFP-T is plugged in
Product-Group=junos
On Junos EX4600 Virtual Chassis (VC), the master RE reboot and all-members reboot lead to the PFE Manager hogging logs when SFP-T pluggable is installed in. The PFE Manager hogging logs has no functionality impact (PR 1641556).
PR Number
Synopsis
Category: SRX-1RU System Hardware defects
1658148
22.2TOT SecPDT: SRX4600: After ISSU upgrade completed, RG1 nodes priority remains in CS state and fab interfaces are down.
Product-Group=junos
In some of releases including 21.2R3 or 20.4R3, when performing SRX4600 ISSU from these release to a newer release, in some scenarios, e.g. with some traffics and big volume of configurations, after node1 is upgraded and a RG0 failover is performed from node0 to node1, it is observed that RE CPU on both nodes are 0% idle which causes some RE daemons (e.g. jsrpd) scheduling slip on old-version node0, which can sometimes lead to temporarily control-link down, which further causes node0 to go to ineligible state. This further leads to node0's EEPROM being programed a zero (unexpected) value to primary-id before its reboot. Later when node0 boots up, node0's flowd will be stuck reading EEPROM primary-id since it's zero. This leads to node0's control-port brought up by flowd late and finally causes a RG0 split-brain. A cluster reboot may be needed to fix the issue. It is unclear why RE is so busy during ISSU in such setup, while the manual failover of RG0 on same setup never leads to node0 to go to ineligible state. A few suggestions: 1. Please reduce traffics and configurations during ISSU, better to do in maintenance window and add back after ISSU complete. 2. Before ISSU, perform a few times of manual RG0 failover and monitor RE CPU percentage. If RE CPU percentage is very high for a few seconds on both nodes, please consider to reduce traffics. 3. If the ISSU older image is on any releases that are with fix of this PR, this problem will not be seen.
PR Number
Synopsis
Category: a20a40 specific issue
1681701
"%DAEMON-4: Set system alarm failed: Operation not supported by device" message is seen on high end SRX
Product-Group=junos
On high end SRX platform, "%DAEMON-4: Set system alarm failed: Operation not supported by device" message is seen when system/chassis alarm is generated
PR Number
Synopsis
Category: BBE Autoconfigured DVLAN related issues
1680453
The process bbe-smgd on the router would stop processing new PPPoE subscribers session
Product-Group=junos
On all Junos platforms configured with subscriber-management, the process bbe-smgd will stop processing new PPPoE (Point-to-Point Protocol over Ethernet) connections due to a memory leak in the control packet pool of the PPPoE plugin.
PR Number
Synopsis
Category: Express Broadway PFE L3
1680757
BFD sessions will remain down in the EVPN-VxLAN scenario
Product-Group=junos
On QFX 10008 and QFX10016 platforms, in a distributed mode Bidirectional Forwarding Detection(BFD) session might remain down if the anchor FPC and the FPC where BFD packets are received over Virtual Tunnel Endpoint (VTEP) are different.
PR Number
Synopsis
Category: Enhanced Broadband Edge support for cos
1650598
MX960:: Syslog errors HALP-trinity_vbf_flow_unbind_handler:1107: vbf flow 624626: ifl 526 not found,fpc5 vbf_var_get_ifs:754: ifl not found,PFE_ERROR_NOT_FOUND seen frequently on MPC7E in 5.5K DCIP/10kPPPoE FTTB Stress Test
Product-Group=junos
With MPC7 cards used as Junos Subscriber Management access cards, the following log message may be generated upon disconnect: HALP-trinity_vbf_flow_unbind_handler:xxxx: vbf flow xxxxx: ifl xxx not found,fpcx vbf_var_get_ifs:xxx: ifl not found It indicates that a second call to release resources is generated for the same subscriber flow. The request is ignored and no functional impact is observed.
PR Number
Synopsis
Category: EVPN ELAN/E-TREE
1690590
Packet forwarding fails on specific ACX Junos platforms due to flapping of core interface member link in the MPLS-EVPN environment
Product-Group=junos
On specific ACX Junos platforms (ACX5448/ACX710), forwarding traffic is getting impacted the MPLS-EVPN environment as kernel memory is exhausted with continuous core link flaps.
PR Number
Synopsis
Category: ACX platform interface issues
1685431
ACX710 : Auto-mdix is not working in ACX710
Product-Group=junos
Due to auto-mdix being disabled on the PHY, ACX-710 does not recognize SFP-T optics with straight cables. So the port will not come up. Port will come up only when customer changes to cross-cable
PR Number
Synopsis
Category: ACX VRRP
1666853
Traffic loss is observed when the VRRP is configured over the AE interface
Product-Group=junos
On ACX5448 platforms, the Virtual Router Redundancy Protocol (VRRP) is up from Routing Engine (RE) but the group is not created under the Packet Forwarding Engine (PFE) due to this VRRP virtual IP (VIP) is neither responding to ping nor accept any traffic when the VRRP is configured over Aggregated Ethernet (AE) interface. This results in traffic loss.
PR Number
Synopsis
Category: Control plane EVPN multicast
1670435
EVPN multicast traffic may get impacted because of routes getting stuck in the kernel routing table (krt) queue
Product-Group=junos
On all Junos and Junos Evolved platforms with Ethernet Virtual Private Network(EVPN) enabled, in the presence of certain triggers like rpd restart, rollback of configuration etc., EVPN multicast routes might get stuck in the kernel routing table (krt) queue due to which the corresponding routes in the forwarding table may point to 'fictitious' next hops, resulting in traffic disruption.
PR Number
Synopsis
Category: EX4400 platform
1691174
The factory default config does not have xe-0/2/0.
Product-Group=junos
On EX4400-24T, it is observed that the factory default configuration does not have interface xe-0/2/0.
PR Number
Synopsis
Category: Express ASIC platform
1683562
On PTX5000 platforms when a command is issued to power off an FPC, it gets stuck in the 'Announce Offline' state
Product-Group=junos
When an FPC (Flexible PIC Concentrator) on PTX5000 platforms is shut down by issuing a request command (request chassis offline slot ) or by FPC power off configuration (set chassis fpc x power off), it gets stuck in the 'Announce Offline' state since the associated timer (fru_graceful_offline_timer) doesn't increment and expire as it is supposed to.
PR Number
Synopsis
Category: idp flow creation, deletion,notification, session mgr intfce
1665442
Execute RSI on SRX5K platform may generate flowd core-dump and trigger data plane failover
Product-Group=junos
On SRX5K platforms, a dataplane failover might be triggered by a flowd coredump when executing the command "request support information".
PR Number
Synopsis
Category: Kernel software for AE/AS/Container
1680889
Traffic drop would be observed only when the backup link is up on link-protection LAG interface
Product-Group=junos
On all Junos platforms, when the Link Aggregation Group (LAG) interface is configured with static link-protection, the packet goes out via the active member (primary) link of LAG; instead, if the backup link comes up first, then a timer of 10 seconds kicks to start and once the timer expires then the backup link is marked to be a new active link of LAG which takes the traffic.
PR Number
Synopsis
Category: Integrated Routing & Bridging (IRB) module
1685406
The protocol MTU for the IRB interface is not rolled back when the MTU of the IRB or IFD interfaces is modified or deleted
Product-Group=junos
On all Junos platforms, the maximum transmission unit (MTU) on the Integrated Routing and Bridging (IRB) interface is not getting reset when the MTU configuration on IRB or IFD is removed. When MTU configuration is removed from the IRB interface, the internal data structure for the MTU configuration is not getting reset which might affect traffic and it is a rare case.
PR Number
Synopsis
Category: JFlow bug tracker for SRX platforms
1688627
The system may crash when Jflow inactive timeout is configured to be less than 'previous flow-inactive-timeout + 180' seconds
Product-Group=junos
On SRX platforms, when Jflow inactive timeout is configured to be less than 'previous flow-inactive-timeout + 180' seconds result in a system crash and core files are generated.
PR Number
Synopsis
Category: Adresses ALG issues found in JSF
1686613
SIP calls are getting dropped due to NAT failure and SIP ALG is enabled
Product-Group=junos
On all MX and SRX platforms which support the SIP ALG (Session Initiation Protocol Application Layer Gateway) feature, SIP calls are getting dropped due to NAT (Network Address Translation) failure and failure to allocate XLATE context. The issue happens when there are multiple SIP INVITEs with different media IPs that arrive on the same SIP call. The drop is seen from the 4th SIP INVITE packet onwards.
PR Number
Synopsis
Category: Flow Module
1692100
SOF was incorrectly offloading short-lived flows leading to early exhaustion of NP memory, reducing overall device performance
Product-Group=junos
On SRX5K and SRX4600 series platforms, Automated Express Path (SOF) was incorrectly offloading short-lived flows. This consumed additional resources on the Network Processor (NP) which could lead to an early exhaustion of its memory, reducing overall device performance. By default, Automated Express Path (SOF) is designed to offload flows which are high bandwidth/throughput in nature.
PR Number
Synopsis
Category: High Availability/NSRP/VRRP
1686648
In specific scenario, condition route-active-on import is not working properly after RG0 failover.
Product-Group=junos
In specific scenario, condition route-active-on import is not working properly after RG0 failover.
1691071
Chassis cluster IP monitoring on the secondary node failed after the system reboot on the SRX platforms
Product-Group=junos
On SRX platforms, IP monitoring on the secondary node failed when a Reth (redundant Ethernet) interface consists of two or more than two interfaces on each node. Reth member interface which has a higher port number cannot receive ICMP (Internet Control Message Protocol) packet used for IP monitoring, which will then put the system in an error state.
PR Number
Synopsis
Category: all logging related bugs on srx platforms
1687244
unexpected default event-rate value for event mode logging
Product-Group=junos
On SRX platform, when event mode logging is used without event-rate option, the logging rate was unexpectedly set to 100 although the default event rate is 1500
PR Number
Synopsis
Category: IPSEC/IKE VPN
1667223
VPN traffic loss is seen after HA node reboot while using traffic selectors
Product-Group=junos
On all Platforms, traffic across static VPNs (Virtual Private Network) with traffic selectors might be affected after reboot of one node in the cluster and failover to it.
PR Number
Synopsis
Category: Layer2 forwarding on EX/NTF/PTX/QFX
1686523
VPLS traffic loss might be seen when deleting and adding a routing-instance
Product-Group=junos
VPLS (Virtual Private LAN Service) traffic stops on all Junos and Junos Evolved platforms after adding/changing interfaces in the routing instance. Restarting l2ald daemon may restore the VPLS services.
PR Number
Synopsis
Category: Label Distribution Protocol
1670334
Traffic loss will be seen in an LDP->BGP-LU stitching scenario
Product-Group=junos
On all QFX platforms, traffic loss can happen when the BGP-LU (Labeled Unicast) routes are exported to LDP (Label Distribution Protocol) to perform LDP->BGP-LU stitching, on a device with directly connected BGP peers.
PR Number
Synopsis
Category: MPC11 ULC interface software related issues.
1685997
The 100G interfaces on an MPC11E remain in a down state on MX platforms after a system or FPC restart
Product-Group=junos
On MX2010/MX2020 platforms, 100G interfaces remain in a down state after the reboot of the MPC11E line card or a restart of the system.
PR Number
Synopsis
Category: Multiprotocol Label Switching
1655031
The rpd core is seen due to IGP database and BGP LS database out of sync
Product-Group=junos
On all Junos and Junos OS Evolved platforms, rpd core is hit when the events for deleting prefixes, sids, links and nodes come in out of order which occasionally leads to IGP database and BGP LS database out of sync.
1690458
On a controller based MPLS setup with container LSPs, rpd daemon crashes after LSP deletion occurs
Product-Group=junos
On all Junos-based platforms, in a scenario where an external controller is provisioned, rpd crashes when an externally controlled container LSP (Label Switched Path) is deleted and the software tries to update its status.
PR Number
Synopsis
Category: Used for tracking OVSDB software issues and features
1687847
OVSDB certificate files are not copied from the Master to the Backup
Product-Group=junos
On all Junos devices which support OVSDB (Open vSwitch Database) functionality, when a new backup is added on VC (virtual chassis), the master does not copy the certificate files to the backup. This impacts the OVSDB functionality and affects the traffic.
PR Number
Synopsis
Category: Path computation client daemon
1675816
In a rare case, 'pccd' will crash when the PCEP connection is down
Product-Group=junos
On all Junos and Junos Evolved platforms, on the intermediate device when connection towards Path Computation Element (PCE) is down, Path Computation Element Protocol (PCEP) session will be down resulting in pccd crash. Routing protocols are not impacted but pccd crashes.
PR Number
Synopsis
Category: Protocol Independant Multicast
1675212
MX304:Bugatti: KRT queue shows deferred operation while creating IFL after FPC offline/online event
Product-Group=junos
Dynamic IFL add request is waiting to be processed in KRT queue during that if chassid down event occurs. To handle the chassid down event RPD Infra sends notification to protocol(producer of Dynamic IFL add request) and it is producer jobs to DELETE the dynamic ifls request which were there in the KRT queue. PIM code is not clearing those Dyanamic IFLs ADD request during chassis fpc down event. Hence getting error 'ENOENT -- Item not found' when chassis comes back up.
PR Number
Synopsis
Category: JRR - VRR running on SRX4200
1691694
A 802.1Q tagged Ethernet traffic with an expected VLAN ID and with a non-zero 802.1P value ingressing a JRR200 VLAN enabled interface is dropped.
Product-Group=junos
A 802.1Q tagged Ethernet traffic with an expected VLAN ID and with a non-zero 802.1P value ingressing a JRR200 VLAN enabled interface is dropped. This problem could happen at a JRR200 system running a 21.1+ JUNOS release.
PR Number
Synopsis
Category: Periodic Packet Management Daemon
1687395
On single PFE with Fusion satellite, LACP is not sending PDUs
Product-Group=junos
On platforms supporting Fusion technology, LACP (Link Aggregation Control Protocol) is not up on the aggregate ethernet interfaces when a satellite device is connected to an aggregate device with a single PFE (Packet Forwarding Engine) and is upgraded to a software version 19.4 and above.
PR Number
Synopsis
Category: QFX L2 PFE
1667069
PVLAN IGMP packet is forwarded between Isolated ports and also duplicated to primary vlan port (Promiscous).
Product-Group=junos
When Isolated port receives IGMP packet, it should not be forwarded to other Isolated ports but was forwarded and also duplicated to primary vlan port (Promiscous).
1681614
LLDP neighborship fails to come up with a Private VLAN configuration
Product-Group=junos
On the Junos platforms, In a Virtual Chassis (VC) scenario if the interface is configured with Private VLAN (PVLAN) and connected through the Flexible PIC Concentrator (FPC) of the non-master switch, the LLDP (Link Layer Discovery Protocol) neighborship fails to come up and traffic through the interface will be impacted.
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1687565
VxLAN configured on access port breaks L2 connectivity with "vxlan encapsulate-inner-vlan" knob
Product-Group=junos
On all Junos QFX5k platforms, L2 connectivity fails when "vxlan encapsulate-inner-vlan" knob is configured on an access port. It impacts a forwarding plane and causes a traffic impact.
PR Number
Synopsis
Category: QFX10008/16 QFX10002 linecard, serdes and uboot
1688993
On QFX10008/QFX10016 platforms fails to detect flaps even though the remote device connected has observed flaps
Product-Group=junos
On QFX10008/QFX10016 platforms, interface faults(Local/Remote) of very short duration (<30msec) can go undetected. The interface does not go down due to these faults leading to unidirectional link and traffic blackholing.
PR Number
Synopsis
Category: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1676740
,The traffic doesn't re-route quickly causing traffic blackholing
Product-Group=junos
On all VMHOST based platforms, traffic blackholing happens because the traffic doesn't re-route quickly as chassisd doesn't recognize an FPC failure from a BAD_VOLTAGE notification.
PR Number
Synopsis
Category: QFX5100 Interface related issues
1688023
The LLDP output packets are not transmitting on the em0 interface of Junos and Junos OS Evolved platforms
Product-Group=junos
On Junos and Junos OS Evolved platforms, if a management Ethernet interface(em0) has an inet or inet6 family configured and "delete interfaces em0" is issued, the Link Layer Discovery Protocol (LLDP) output packets will stop transmitting, causing the LLDP neighborship to remain down in peer router.
PR Number
Synopsis
Category: KRT Queue issues within RPD
1639252
High CPU utilization for rpd process might be seen
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, the rpd process might utilize a large amount of the CPU during commit. This might only be seen in a scaled static route setup with virtual routing and forwarding (VRF) and Bidirectional Forwarding Detection (BFD) configured. The reason for the CPU spike is that kernel routing table (KRT) might get stuck and keep running for a long time. The high CPU might hamper the rpd process functionality in rare cases. However, the system recovers by itself when it encounters this issue.
1686211
The rpd crash would be observed when two separate next-hops in rpd map to the same next-hop-index in the kernel
Product-Group=junos
On all Junos and Junos Evolved platforms, when a route is getting installed to the forwarding table, associated next-hops also get installed in the forwarding table. As part of this installation process, the Junos kernel allocates the next-hop-index for the next-hop. The rpd sets this next-hop-index in its database when two separate next-hops for instance NH1 and NH2 in the rpd map to the same next-hop NH in the kernel. In such case, NH1 and NH2 next-hops in rpd will have the same next-hop-index leading to the rpd crash.
PR Number
Synopsis
Category: Bug and Review Tracking for Segment routing traffic eng
1683883
srv6-oam: more than one label stack is not suppoting,gives as "Maximum number of sids supported is 0" error in srv6 ping in Alfa-Romeo[lc9600]
Product-Group=junosvae
When "Ping/traceroute srv6 spring-te sids-stack sids[] nexthop-interface <> nexthop-address <>" command is initiated and "maximum-srv6-sids" stanza is not present in default platform conf files, Ping/traceroute will be aborted with error "maximum-srv6-sids supported is 0". As a workaround, please set the below configurations, after which SRv6 Ping/traceroute will be successful. "set routing-options platform-parameters maximum-srv6-sids 6" Note: In case of traceroute, after above configuration is committed, "mplsoamd" daemon restart is required.
PR Number
Synopsis
Category: MPC7/8/9 Interface Issues
1692063
PCS errors and framing errors on 100GE interfaces on certain Juniper platforms
Product-Group=junos
On certain Junos platforms with specific PIC (Physical Interface Card)/MIC (Modular Interface Card)/FPC (Flexible PIC Concentrator), PCS (Physical Coding Sublayer) errors and framing errors would be seen on 100GE interfaces with LR4 optics or its peer device on Junos to 20.2R1 or later releases. The framing/CRC (Cyclic Redundancy Check) errors which would be seen when the PCS error rate is high could lead to packet drops hence impacting data services. As a workaround enabling FEC (forwarding Error Correction) feature on the impacted interface may reduce the frequency of packet drop.
PR Number
Synopsis
Category: SRX-1RU platfom related protocol, QoS, filtering features et
1689705
SNMP MIB walk for jnxBoxDescr OID returns incorrect value
Product-Group=junosvae
On SRX4600 platforms running Junos, SNMP MIB walk for jnxBoxDescr OID returns the incorrect chassis name and model. This is only a display issue with no service impact.
PR Number
Synopsis
Category: ZT/YT pfe qos software issues
1688416
The COS queue burst size computation was incorrect when the explicit queue shaping rate was not configured, causing initial packet drops
Product-Group=junos
On specific linecards MPC10/11/LC9600 and MX304 device, there was an issue with the COS (Class of Service) queue burst size calculation when the explicit queue shaping-rate was not configured, resulting in an initial packet drop and the COS queue burst size computation was incorrect which causes packets to drop initially.
1696089
FPC crash is observed in GNF scenario with CoS configuration
Product-Group=junos
On Junos and Junos Evolved platforms, in GNF (Guest Network Function) setup when CoS (Class of Service) configuration is attached on an IFL (Interface Logical) stacked over another IFL and the CoS configuration message is received on an FPC (Flexible PIC Concentrators) which does not host the IFLs IFD (Interface Device), then the FPC can crash because the FPC does not have any information about the IFLs or underlying IFDs.
PR Number
Synopsis
Category: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1681533
The line card gets crashed during node/interface statistics reporting with resource monitoring
Product-Group=junos
On MX platforms with specific line cards, the MPC may crash and generate core dumps in a corner case during node/interface statistics reporting scenario when resource monitoring is used.
PR Number
Synopsis
Category: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1689621
"failed to get template var id" error messages are generated by FPC when BFD liveness detection is negotiated by DHCP subscriber which has lawful intercept enabled
Product-Group=junos
In subscriber management environment, "failed to get template var id" error messages are generated by FPC when BFD liveness detection is negotiated by DHCP subscriber which has lawful intercept enabled.
PR Number
Synopsis
Category: Trio pfe multicast software
1682383
Incorrect programming of next-hop based on RVT interface hosted on MPC10E/MPC11E, LC9600, MX304 leads to traffic drops
Product-Group=junos
On MX304 and MX platforms MPC10E, MPC11E, and LC9600 line cards, traffic loss is observed for the traffic not being directed from the core to the routing-instance in MVPN (Multicast VPN) (hot-root-standby) environment with RVT (Redundant Virtual Tunnel) interface as upstream. The tunnel attribute for the RVT interface is not set, due to which it returns failure which in turn results in the default Ethernet encapsulation creation.
PR Number
Synopsis
Category: VMHOST platforms software
1646339
The alarm might not be generated for EDAC errors until the FPC is rebooted
Product-Group=junos
On all MX and PTX platforms, EDAC errors are triggered but alarms are not observed until the FPC gets rebooted due to the data corruption in hardware.
PR Number
Synopsis
Category: usf nat related issues
1692525
ALG child session will not be transported through the DS-Lite tunnel which might lead to traffic failures in absence of a direct route to the host
Product-Group=junos
On Junos MX240/MX480/MX960 platform with MX-SPC3, a tunnel ID of the control session is not updated properly on the gate created for Session Initiation Protocol (SIP) Application Layer Gateway (ALG), which is leading to the gate hit session not mapping back to the Dual-Stack Lite (DS-Lite) tunnel. This might result in traffic failure if the client does not have a direct route to the host.
21.4R3-S2 - List of Known issues
PR Number
Synopsis
Category: EX4300 Platform implementation
1668414
On EX4300-48MP, NSSU abort is seen with "error: rebooting VC". VC instability and dc-pfe core is observed after reboot.
Product-Group=junos
On EX4300-48MP, NSSU abort is seen with "error: rebooting VC". VC instability and dc-pfe core is observed after reboot.
PR Number
Synopsis
Category: EX2300/3400 PFE
1647209
DHCP traffic might be dropped when DHCP-security and RTG are enabled
Product-Group=junos
On EX2300, EX2300-48MP, and EX3400 platforms, when DHCP-security and Redundant Trunk Group (RTG) are enabled clients connected over RTG might not get DHCP IP and DHCP traffic might be dropped.
1685938
MAC address learning might not happen on specific EX/QFX platforms
Product-Group=junos
On specific EX/QFX platforms (EX2300/EX3400/EX4300-MP/EX4100/EX4400/QFX5K), MAC learning is not happening in any of the interfaces of the particular VLAN (contains both LAG (Link Aggregation Group) and non-LAG interfaces) when VSTP (VLAN Spanning Tree Protocol) is enabled on LAG interface with no child interface and VSTP is disabled for non-LAG interfaces. It causes a traffic impact as mac address learning does not happen for all interfaces on the VLAN.
PR Number
Synopsis
Category: EX-Series VC Infrastructure
1700133
EX4600 VC: Member Disconnect observed during VC initialization after reboot (with I2C read access failure)
Product-Group=junos
When ?request system reboot all members? command is executed on EX4600VC, post reboot one of the FPCs may disconnect and join the VC back. The FPC reboots with reason "FXPC_RENESAUS_RETRY_FAILURE: fxpc_fpga_fpc_ideeprom_read: FAILED retry to Renesaus chip", This issue may be hit approximately once in 10-12 attempts of cli command ?request system reboot all members? execution.
PR Number
Synopsis
Category: SPC3 HW and SW Issues
1692611
SRX cluster may fail in a rare scenario when node status changes to disabled state without going through the ineligible state
Product-Group=junos
On SRX platforms with chassis cluster configured, the RE(Routing-Engine) & PFE (Packet Forwarding Engine) connection may break, and the cluster may fail when the node status changes from primary/secondary state to disabled state without going through the ineligible state.
PR Number
Synopsis
Category: CoS support on ACX
1689604
EVPN Traffic is classfied in the wrong queue
Product-Group=junos
The classifier on CE facing interface is not bound correctly after core facing interface flaps. It makes the traffic going to the wrong queue. Restart the FPC can restore the device.
PR Number
Synopsis
Category: ACX Services feature
1633395
Delegated BFD sessions configured on routing-instance may fail to come up
Product-Group=junos
On ACX5448 and ACX710 platforms, all types of delegated BFD sessions configured on routing-instance other than the default routing-instance might not come up.
PR Number
Synopsis
Category: Border Gateway Protocol
1652666
Wrong next-hop weight might be observed with BGP PIC enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms, wrong weight might be observed with BGP PIC (Border Gateway Protocol Prefix Independent Coverage) enabled.
1659441
Routing Process Daemon (rpd) crashes and restarts when a specific timing condition is hit with BGP configuration
Product-Group=junos
On all Junos platforms and all Junos Evolved platforms, Routing Process Daemon (rpd) crashes and restarts when BGP (Border Gateway Protocol) is configured and a specific timing condition is hit for secondary route. This issue might cause a traffic impact.
1677624
Bgp peers status is not as expected
Product-Group=junos
Not fixed in the Current release, the issue was recreated only with IXIA connection. Arp response is not received in the DUT port to store the destination MAC address. unable to determine if the issue is with the MX port or medium or IXIA port.
1679646
The AGGREGARTOR attribute will not be set correctly when the independent-domain is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in BGP deployments with the "independent-domain" and aggregate routes configured under routing-instance, the AGGREGATOR attribute encapsulated within the ATTR_SET will not be populated correctly. This can result in unintended behavior or service impact because the BGP neighbors receiving this update may discard it as it is not RFC complaint.
1691131
Backup Path is Not Found in ASBR6 MPLS Table while verifying BGP Multipath Protection functionality
Product-Group=junos
Backup Path is Not Found in ASBR6 MPLS Table while verifying BGP Multipath Protection functionality
PR Number
Synopsis
Category: MX Platform SW - FRU Management
1676008
MPC stuck in present state with log " graceful offline in progress, returning false" flooding
Product-Group=junos
In over temperature situation, there will be a 10s timer before device bring the FPC down . However in some situation due to high temperature, a FPC offline action will be triggered before the 10s timer expires. Then the FPC will stuck in Present/Announce offline state. Cli offline/online it or physical reseat will not be able to recover the issue. When the issue happening, you may observe log message " graceful offline in progress, returning false" flooding: <<< fpc_ok_to_start_generic: [FPC 0] gracefull offline in progress, returning false fpc_ok_to_start_generic: [FPC 0] gracefull offline in progress, returning false <<< Below MPCs are affected by this issue: MPC7/8/9 MPC10 MPC11 LC480 LC2101 LC9600 LC304 LC4800 FPC-P2, FPC-P3
PR Number
Synopsis
Category: Class of Service
1693977
The oid tree jnxCosQstatEntry returns nothing for some interfaces after restarting class-of-service
Product-Group=junos
When the oid tree of jnxCosQstatEntry is used to get value, and cosd restart or global swichover happens, the oid woun't return values for that oid. That is because the IFD/IFL async events come from kernel before cosd triggers snmp_subagent_init. The fix will make sure cosd triggers snmp_subagent_init before IFD/IFL async events.
PR Number
Synopsis
Category: QFX Control Plane VXLAN
1650202
ARP/NS response to anycast IRB might fail due to missing mac-ip entry
Product-Group=junos
On all Junos and EVO platforms, IRB (Integrated routing and bridging) static entry might be missing in the mac-ip-table for mac move allowed for local static IRB entry.
PR Number
Synopsis
Category: ACX BFD specific issues
1670684
New BFD sessions will not come up on ACX5448/ACX710 due to continuous flaps
Product-Group=junos
On ACX710/ACX5448 platforms, if the Bidirectional Forwarding Detection(BFD) endpoint ID in chipset level reaches ~8K (for ACX710) or ~16k (for ACX5448),the following BFD session can't be created properly and be stuck at Init state. Once the issue is hit, disable BFD configuration and restart the bfdd process to make the endpoint ID roll over from 16.
PR Number
Synopsis
Category: Control Plane for Node Virtualization
1683312
'clear interfaces statistics all' taking more than 9 min due to invalid PIC configuration inside GNF.
Product-Group=junos
Invalid PIC configuration inside GNF may add delay to 'clear interface statistic all' command. This issue does not impact any functionality. chassis fpc pic
1685453
PICs on the GNF failed to come online after the chassisd restart
Product-Group=junos
On MX platforms supporting node-slicing (MX480, MX960, MX2010, MX2020 & MX2008) have an issue that when GNF (Guest Network Function) chassisd restarts, the FPC doesn't restart as expected which causes the PIC (Physical Interface Card) to be offline.
PR Number
Synopsis
Category: Express PFE L2 fwding Features
1693424
Traffic loss is observed when the ECMP path is IRB over AE (IPv4->MPLS)
Product-Group=junos
On QFX10002 platforms, when the ECMP (Equal-cost multi-path) path is IRB (Integrated routing and bridging) over AE (Aggregated Ethernet) {IPv4->MPLS (Multiprotocol Label Switching)} results in packets getting discarded for which traffic loss is observed.
PR Number
Synopsis
Category: Express PFE L3 Multicast
1678723
On QFX10008, pps statistics for multicast packets is not as expected
Product-Group=junos
On QFX10008, Statistics for multicast packets is not as expected as the packets has L2 header stripped during replication in PFE because of which it is not forwarded to the next hop.
PR Number
Synopsis
Category: Express ASIC interface
1669267
PCS errored blocks count increments on PTX3000/PTX5000 after Junos software upgrade
Product-Group=junos
On PTX platforms, packets drop is seen because of increment in PCS and framing errors on some of the 100GE ports on PIC or its peer devices after firmware migration.
PR Number
Synopsis
Category: Interface Information Display
1611623
SRX1500: Traffic fail seen on irb interface for network control forwarding class when verifying dscp classification based on single and multiple code-points
Product-Group=junos
Traffic drop might be seen on irb interface on SRX1500 for network control forwarding class when verifying dscp classification based on single and multiple code-points.
PR Number
Synopsis
Category: ISIS routing protocol
1674804
Segment-routing may incorrectly set a pop action for paths using a Strict SPF(1) Algorithm
Product-Group=junos
On all Junos and Junos Evolved platforms, segment-routing sets a pop action for paths using a Strict SPF(1) Algorithm incorrectly.
1677567
Label traffic will be dropped at the one-hop LSP stitching node if the packet has more than one label
Product-Group=junos
On all Junos and Junos Evolved platforms supporting the Segment Routing (SR) feature, when segment routing and Label Distribution Protocol (LDP) stitching are configured, the label traffic drop is observed at the one-hop Label Switched Path (LSP) stitching node when the labeled packet is received with more than one label.
PR Number
Synopsis
Category: jdhcpd daemon
1688272
IPv4 ALQ not working with authentication
Product-Group=junos
IPv4 ALQ not working with authentication. The below error would be seen on the backup router: "Message failed sanity test - the access-profile info is invalid. length:0 "
PR Number
Synopsis
Category: jl2tpd daemon
1667950
VMcore or RE crash might be triggered due to the memory corruption when the FPC is restarted for LNS subscribers
Product-Group=junos
On all MX platforms, when Flexible PIC Concentrators (FPCs) restart for L2TP network server (LNS) subscribers stacked over aggregated service interface (asi) and LNS subscribers belong to more than one routing instance causes the VMcore or Routing Engine (RE) crash and brings down all the traffic.
PR Number
Synopsis
Category: Port-based link layer security services and protocols that a
1693730
Traffic loss will be seen when MACSEC is configured
Product-Group=junos
On all Junos platforms where MACSEC(Media Access Control Security) is configured with 60s SAK (secure association key) rollover, traffic loss will be observed during RE (Routing Engine) switchover.
PR Number
Synopsis
Category: SW PRs for MPC10E Chassisd
1664448
The command "show chassis fpc" shows inaccurate information about heap memory
Product-Group=junos
The command "show chassis fpc" shows inaccurate information about heap memory in output.
PR Number
Synopsis
Category: Multiprotocol Label Switching
1655031
The rpd core is seen due to IGP database and BGP LS database out of sync
Product-Group=junos
On all Junos and Junos OS Evolved platforms, rpd core is hit when the events for deleting prefixes, sids, links and nodes come in out of order which occasionally leads to IGP database and BGP LS database out of sync.
1697982
[MX]L2VPN ping is failing when UHP rsvp LSP is used.
Product-Group=junos
MPLS L2VPN ping is getting failed when MX is egress. In egress, RE verifies whether received label is VC label or not. For most of the platforms, tunnel label will be removed in PFE before punting the echo request packet to RE. But in this platform, tunnel label is not removed hence RE verifies this tunnel label and it is returning no-mapping.
PR Number
Synopsis
Category: Multicast for L3VPNs
1675099
The multicast receiver receives no traffic in an extranet scenario having an SPT tree already established
Product-Group=junos
On Junos and Junos Evolved MX/PTX platforms, if the SPT (Shortest-Path Tree) tree is already established on PE (Provider Edge) it sends (s,g,rpt) prune which will lead to no traffic to the multicast receiver in an extranet scenario.
PR Number
Synopsis
Category: Express Chip L3 software
1660606
MVPN traffic is getting dropped on PTX/QFX series platforms
Product-Group=junos
On all Junos PTX and QFX10k series platforms, MVPN (Multicast Virtual Private Network) traffic is getting dropped with a discarded error. This is because, the way LSI (Label Switched Interface) interface data is carried from ASIC (Application-Specific Integrated Circuit) to PFE (Packet Forwarding Engine) is changed, causing MVPN to break.
PR Number
Synopsis
Category: QFX MPLS PFE
1687257
QFX5120 will drop ingress traffic on a l2circuit configured interface if that interface flaps repeatedly.
Product-Group=junosvae
QFX5120 will drop ingress traffic on a l2circuit configured interface if that interface flaps repeatedly.
PR Number
Synopsis
Category: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1670240
The dcpfe process might generate core-dumps and FPC might crash after line card reboot or switchover
Product-Group=junos
On QFX10K, PTX10K, PTX5K, PTX3K, and PTX1K platforms, the dcpfe process might generate core-dumps and FPC might crash after line card boot or switchover. The BIST (Built-in Self Test) might report an error in the HMC (Hybrid Memory Cube) and restart the dcpfe process causing FPC crash.
PR Number
Synopsis
Category: QFX5100 Interface related issues
1665800
Ports with SFP-T 1G plugged in may go to hung state on QFX5100 platforms
Product-Group=junos
When the remote end server/system reboots, QFX5100 platform ports with SFP-T 1G inserted may go into a hung state and remain in that state even after the reboot is complete. This may affect traffic after the remote end system comes online and resumes traffic transmission.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Platform optics related issues
1660532
The port LEDs do not light up when 40G physical interfaces are up.
Product-Group=junos
The port LEDs do not light up when 40G physical interfaces are up. This is a display issue. There is no service impact when this issue occurs.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Platfom issues
1661602
The dc-pfe process crash is observed with PTP Transparent clock on QFX platforms
Product-Group=junos
On QFX platforms that support only a PTP (Precision Time Protocol) Transparent clock, without any PTP Boundary or ordinary clock, the dc-pfe process crash is observed if there is any disconnect between PFE (Packet Forwarding Engine) and Clock sync process (clksyncd). As the dc-pfe process cores, the physical interfaces will be deleted and there will be a functional or traffic impact.
1667397
Some 10G ports are missing from FPCs after rebooting the device with 1G Ports enabled on one FPC
Product-Group=junosvae
On Junos EX4650 virtual chassis (VC) setup and QFX5120-48y platforms, after enabling 1G ports on one FPC and rebooting the entire VC, some 10G ports which have already been up and running on other FPCs may miss from CLI output of "show interfaces terse". Production traffic will be impacted by this issue. The cause of issue is that configuration change on one FPC is propagated to other members of VC. Configuration files should be removed on FPCs on which the 10G ports are present. After that, upgrade/re-image the VC to fixed versions and issue will not be observed any longer.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Virtual Chassis
1636668
Pyrite_VC: em0 interface ppeed is reflecting as 10G instead of 1G
Product-Group=junos
Management interface speed is displayed as 10G instead of 1G though there is no functionality impact.
PR Number
Synopsis
Category: Resource Reservation Protocol
1657872
Memory utilization keeps incrementing due to the path error message
Product-Group=junos
On all Junos and Junos Evolved platforms, when a no-cspf Label Switched Path (LSP) with strict Explicit Route Object (ERO) is configured and the egress device is disconnected, a high rate of Path Error (PathErr) messages are observed which is leading to high memory utilization and triggering the chassisd crash that causes the device to be out of control, either it can not be accessible via console/ssh or it will not trigger Routing Engine (RE) switchover as well if it is dual-RE. So this would cause an outage.
1681403
In the RSVP-TE scenario, with Entropy label capability is enabled during MBB issues handling Resv Messages
Product-Group=junos
On all platforms with entropy-label configured, the issue shows up during Make-Before-Break (MBB) at a transit Juniper node when non-Juniper Egress constructs and sends a Resv message with multiple flow-descriptors (includes descriptors for both old and new instances). Juniper transit device has an issue handling such Resv Messages, the RRO object that is part of the flow-descriptor was getting dropped when the LSP_ATTRIBUTES object was also present within the flow-descriptor.
PR Number
Synopsis
Category: SRX Argon module
1646661
21.3R2:SRX_RIAD:srx1500,srx4200:SKYATP:IMAP/IMAPS Email permitted counter is not incremented in AAMW email statistics while testing whole email block.
Product-Group=junos
The SKYATP:IMAP/IMAPS Email permitted counter may have incorrect value under certain conditions.
PR Number
Synopsis
Category: SRX branch platforms
1594014
During reboot, "warning: requires 'idp-sig' license" can be seen on the screen even when the device has valid license
Product-Group=junos
If a device is rebooted manually or reboots for any other reason, The following messages can be seen on the boot up screen even when the device has valid license and proper configuration to use the features like IDP/UTM
1658276
reth interface does not go up due to speed mismatch when reth interface speed is changed afger RG0 failover
Product-Group=junos
On SRX series platform with chassis cluster enabled, reth interface might not go up due to speed mismatch when reth interface speed is changed afger RG0 failover
PR Number
Synopsis
Category: MX10003/MX204 MPC defects tracking
1689644
A 1G port on a QSFPP-4x10G transceiver will be down sometimes after the FPC restart
Product-Group=junos
On MX204 device, a QSFPP-4x10G transceiver configured at 1G speed sometimes stays down after a FPC restart. Traffic will not pass through the port.
PR Number
Synopsis
Category: MX10003/MX204 Timing/Sync-E issues tracking
1663065
The offset value might be high on the downstream node while switching between line cards which impacts 5G services
Product-Group=junos
On Junos MX10003 platform, the offset value might be high on a downstream node which impacts 5G services. While switching the SyncE(Synchronous Ethernet) and slave PTP (Precision Time Protocol) interface between line cards, SyncE will be in a holdover state for a long time and the clock will not get locked. SyncE clock status can be monitored using the following command "show chassis synchronization extensive"
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1522896
Egress traffic loss might happen because of PFE MTU feature problem
Product-Group=junos
On MX and EX9200 serial platforms, under Ethernet VPN (EVPN) environment, packets routed using IRB interface could not be fragmented due to media maximum transmission unit (MTU) problem.
1686220
BFD flap is observed after VPLS mac-table clear
Product-Group=junos
BFD flap is observed after executing VPLS mac-table clear command.
1696106
On a EVPN-VXLAN scenario packets received from type-5 tunnel is not sent out to local CE
Product-Group=junos
In EVPN-VxLAN, traffic drop can be seen for some local CEs which are multihomed to at least one MX Router
Modification History
First publication 2022-12-01
21.4R3-S2: Software Release Notification for JUNOS Software