Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX running Junos Evolved Software

Alert Description


Junos Software Service Release version 21.2R3-S4-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.2R3-S4-EVO is now available.

21.2R3-S4-EVO - List of Fixed issues

PR NumberSynopsisCategory: Border Gateway Protocol
1660456Incorrect inactive routes are being propagated to neighbors with add-path
Product-Group=evo
On all Junos and Junos Evolved platforms that support add-path which is used to advertise inactive external BGP routes from the VRF table, changes to that route may not be propagated. To avoid the issue please use advertise-external knob instead of add-path to advertise not best eBGP routes internally.
1660571Damping policy not working as expected when import policy and damping policy are changed in one commit
Product-Group=evo
On all Junos OS and Junos OS Evolved devices, when BGP damping is configured, the routes show default damping parameters when both import policy and damping policy are changed in one commit.
1673160The routes with an independent resolution can trigger an rpd crash when the last BGP peer is down
Product-Group=evo
On all Junos and Junos Evolved platforms, Independent resolution routes imported from another table (i.e. VRFs with color routes that need resolution) can trigger an rpd crash when the last BGP peer is down.
1679646The AGGREGATOR attribute will not be set correctly when the independent-domain is configured
Product-Group=evo
On all Junos and Junos OS Evolved platforms, in BGP(Border Gateway Protocol) deployments with the "independent-domain" and aggregate routes configured under routing-instance, the AGGREGATOR attribute encapsulated within the ATTR_SET will not be populated correctly. This can result in unintended behavior or service impact because the BGP neighbors receiving this update may discard it as it is not RFC complaint.
PR NumberSynopsisCategory: EVO Layer-2 switching for BCM XGS Platforms
1687475QFX EVO: vlan tag of transit IGMP report will be removed when igmp-snooping is enabled.
Product-Group=evo
On QFX series switch running on EVO, vlan tag of transit IGMP report will be removed when igmp-snooping is enabled.
PR NumberSynopsisCategory: QFX52xx platforms Interface running EVO
1641313Junos OS Evolved: Specific SNMP GET operations will cause resources to leak and eventually the evo-pfemand process will crash (CVE-2023-22400)
Product-Group=evo
An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA70196 [juniper.net] for more information.
PR NumberSynopsisCategory: Configd, ffp issues
1698347The BFD fails to come up when RE filter is configured with apply-path
Product-Group=evo
On Junos OS Evolved platforms, the Bidirectional Forwarding Detection (BFD) protocol will fail to come up. This happens when the Routing Engine (RE) filter is applied with the filter term having source-prefix-list derived from apply-path configured with - "interfaces <*> aggregated-ether-options bfd-liveness-detection neighbor". The issue occured in the commit handling after correcting the apply-path string.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1649234The kernel crash would be observed in an EVPN multi-homed scenario
Product-Group=evo
On QFX10002/QFX10008/QFX10016 (only QFX10K) platforms, when Assisted Replication (AR) feature as Replicator role is used in an Ethernet VPN (EVPN) multi-homed scenario, there would be out-of-bound memory access issue observed which could result in the kernel crash leading to the service impact.
1662954In EVPN-MPLS Mutihoming scenario DF election will get stuck in the Preference based state
Product-Group=evo
On all Junos and Junos Evolved platforms supporting preference-based DF (Designated Forwarder) election in EVPN-MPLS Multihoming scenario, the DF election will be stuck in the Preference based state if there will be a change in the df-election on the fly.
PR NumberSynopsisCategory: Control plane EVPN multicast
1670435EVPN multicast traffic may get impacted because of routes getting stuck in the kernel routing table (krt) queue
Product-Group=evo
On all Junos and Junos Evolved platforms with Ethernet Virtual Private Network(EVPN) enabled, in the presence of certain triggers like rpd restart, rollback of configuration etc., EVPN multicast routes might get stuck in the kernel routing table (krt) queue due to which the corresponding routes in the forwarding table may point to 'fictitious' next hops, resulting in traffic disruption.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1690458On a controller based MPLS setup with container LSPs, rpd daemon crashes after LSP deletion occurs
Product-Group=evo
On all Junos-based platforms, in a scenario where an external controller is provisioned, rpd crashes when an externally controlled container LSP (Label Switched Path) is deleted and the software tries to update its status.
1694648The rpd crash will be observed during the MPLS label block allocation
Product-Group=evo
On all Junos and Junos Evolved platforms in the Multiprotocol Label Switching (MPLS) scenario, the rpd crash will happen in rare conditions during MPLS label block allocation.
1697982[MX]L2VPN ping is failing when UHP rsvp LSP is used
Product-Group=evo
MPLS L2VPN ping is getting failed when MX is egress. In egress, RE verifies whether received label is VC label or not. For most of the platforms, tunnel label will be removed in PFE before punting the echo request packet to RE. But in this platform, tunnel label is not removed hence RE verifies this tunnel label and it is returning no-mapping.
PR NumberSynopsisCategory: OSPF routing protocol
1700966OSPF stuck in InitStrictBFD state for the neighbor which doesn't send LLS header
Product-Group=evo
When Strict BFD (Bidirectional Forwarding Detection) for OSPF (Open Shortest Path First) configured on all Junos OS and Junos OS Evolved platforms, and one or more OSPF neighbors don't support Link-Local Signaling ("LLS", RFC5613), the adjacency with these neighbor(s) might stuck in InitStrictBFD state upon adjacency initialization. Neighbor doesn't support LLS, hence it doesn't attach the LLS header, which is a pre-requisite for Strict BFD.
PR NumberSynopsisCategory: QFX5100 Interface related issues
1688023The LLDP output packets are not transmitting on the em0 interface of Junos and Junos OS Evolved platforms
Product-Group=evo
On Junos and Junos OS Evolved platforms, if a management Ethernet interface(em0) has an inet or inet6 family configured and "delete interfaces em0" is issued, the Link Layer Discovery Protocol (LLDP) output packets will stop transmitting, causing the LLDP neighborship to remain down in peer router.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1587054The MVPN traffic loss might be seen due to the flooded multicast next-hop is missed
Product-Group=evo
On the Evo platform in the MVPN scenario, the KRT queue will exchange the next-hop ID to the rpd. In some rare cases, if the same next-hop ID is used for 2 multicast next-hops due to memory resizing, the flooded next-hop might be deleted improperly during deactivating or activating AE interfaces in seconds intervals, then it might not be assigned to the changed multicast next-hop correctly. It will cause KRT queue to be stuck with some errors, the following MVPN traffic loss might be seen due to the multicast next-hop issue happens.
1678217PFE memory usage gets impacted after GRES
Product-Group=evo
On all Junos and Junos Evolved platforms, when GRES(Graceful Routing Engine Switchover) is performed, rpd doesn't delete some unused indirect nexthops after switchover. It will impact PFE(Packet Forwarding Engine) memory usage.
PR NumberSynopsisCategory: Issue related to mcnh routing infrastructure within RPD
1658425The next-hop does not be updated and errors observed when aggregated interface goes down
Product-Group=evo
On all Junos OS Evolved platforms, dependency errors after interface flap are observed due to uncleared multicast composite next hop from RPD(routing protocol process daemon).
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1670316Layer 2 packets other than IPv4/IPv6 (e.g. CFM) will get forwarded as out of order via MPC10 and MPC11 in the egress direction
Product-Group=evo
On specific MX devices with MPC10 and MPC11 linecards, Layer 2 packets (i.e. other than IPv4/IPv6, e.g. CFM), may get forwarded as out of order in the egress direction. The issue is not seen for IPv4/IPv6/MPLS Encapsulated IPv4/MPLS Encapsulated IPv6 traffic/MPLS Encapsulated Ethernet+IP traffic.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1660931Lockout-period might not work as expected
Product-Group=evo
Lockout-period might not work as expected and the user gets locked out.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1680178VRRP master-master condition might occur when there are more than two devices in the VRRP group
Product-Group=evo
When more than two devices are part of the VRRP group and a lower priority master sends a keepalive as master, low priority backup may transition to master state and get stuck.
 
 

21.2R3-S4-EVO - List of Known issues

PR NumberSynopsisCategory: Express BT PFE L3 Features
1651473The BFD session might flap in some scaled system with churn
Product-Group=evo
On all Junos and Junos Evolved AFT (Advanced Forwarding Toolkit) platforms, this is infrastructure enhancement which was done to avoid BFD session flapping during the system churn. Without this infra enhancement, BFD session flap would happen in some scaled system with churn.

Resolved In: evo:20.4R3-S5-EVO evo:21.3R3-EVO evo:21.4R1-S2-EVO evo:21.4R2-EVO evo:21.4R3-EVO evo:22.1R2-EVO evo:22.2R1-EVO evo:22.3R1-EVO junos:21.3R3 junos:21.4R3 junos:22.1R2 junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: Interface PR for LC1202 LC
1633740The carrier transition value is incorrectly updated on flapping the interface
Product-Group=evo
On PTX10004/PTX10008/PTX10016 platforms with PTX10K-LC1202/JNP10K-LC1202, on interface flapping, carrier transition value is incorrectly updated.

Resolved In:

Modification History

First publication 2023-01-13