Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, EX, MX, NFX, PTX, QFX, SRX, vSRX

Alert Description

Junos Software Service Release version 21.2R3-S4 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.2R3-S4 is now available.

21.2R3-S4 - List of Fixed issues

PR NumberSynopsisCategory: Daily JUNOS build failures - automated builder use only
1691209Use latest os-package when upgrading
Product-Group=junos
Upgrade to 22.3R1 while using os-package published between July 2022 and November 2022 may incorrectly link os-libs package
PR NumberSynopsisCategory: EX4300 PFE
1675977The fxpc process crash might be observed on EX4300 and EX4300-VC platforms
Product-Group=junos
On EX4300 platforms, if there are mac-move events, the fxpc (Packet Forwarding Engine manager) crash might be observed due to race conditions.
1697685Gratuitous ARP reply will not update the ARP cache
Product-Group=junos
On EX4300 platforms, the ARP (Address Resolution Protocol) cache will not be updated upon receiving the Gratuitous ARP reply even with "gratuitous-arp-reply" configured.
PR NumberSynopsisCategory: EX4300 Platform
1678506The interface on the device will go down when one or more interfaces are connected to the Advantech3260 device at another end
Product-Group=junosvae
On EX4300 platforms with version 19.1R3 and above, the interface on the device will go down when the device is connected to the Advantech3260 device at the other end. It will have a traffic impact.
1680225On EX4300-Virtual Chassis (VC) platforms, the pfex process might crash when PIC 2 is detached
Product-Group=junos
On EX4300-Virtual Chassis (VC) platforms, Packet Forwarding Engine process (pfex) crash will be seen when Physical Interface Card 2(PIC 2) is detached then Physical Interface(IFD) is getting deleted before logical interface (IFL)deletion.
PR NumberSynopsisCategory: EX4300 Filters implementation
1699777TCAM space might be exhausted when learning DHCP snooping entries on a trusted port
Product-Group=junos
On EX, QFX5k, and MX platforms having persistent binding for DHCP (Dynamic Host Configuration Protocol) snooping configured might cause TCAM (Ternary Content Addressable Memory) space exhaustion for DHCP snooping learning on the trusted port after the device reboot.
PR NumberSynopsisCategory: EX2300/3400 PFE
1634433The fxpc process crash might be triggered when a MAC is aging out
Product-Group=junos
On all EX platforms, fxpc process crash may trigger due to the mod operation with zero present in code which leads to unexpected behavior, this is very specific to code usage which impacts the service outage.
PR NumberSynopsisCategory: EX2300/3400 platform
1680408On Ex2300 and EX3400, "set system ports console log-out-on-disconnect" does not allow user to log in via console.
Product-Group=junos
On certain units, with "set system ports console log-out-on-disconnect", when you login to the device via a console, the user will be kicked out to the login prompt and be asked to login again.
PR NumberSynopsisCategory: SRX-1RU System Hardware defects
1658148SRX4600 platforms in split brain scenario post ISSU
Product-Group=junos
Junos SRX4600 platforms might go into spit brain mode after ISSU (In-Service Software Upgrade) is performed in presence of heavy traffic or huge volume of configuration. This issue causes one of the nodes to go into ineligible state, the control port is brought up late causing the split brain issue. Once the issue happens, there is traffic outage after ISSU as RG0 (Redundancy Group 0) split-brain happens, and one node may stuck in FPC (Flexible PIC Concentrator) present state.
PR NumberSynopsisCategory: SPC3 HW and SW Issues
1692611SRX cluster may fail in a rare scenario when node status changes to disabled state without going through the ineligible state
Product-Group=junos
On SRX platforms with chassis cluster configured, the RE(Routing-Engine) & PFE (Packet Forwarding Engine) connection may break, and the cluster may fail when the node status changes from primary/secondary state to disabled state without going through the ineligible state.
PR NumberSynopsisCategory: CoS support on ACX
1689604EVPN Packets may go to incorrect queues due to the wrong classification and may lead to packets drop during congestion
Product-Group=junos
On Junos ACX5448 and ACX710 devices, in EVPN (Ethernet Virtual private network) with a multihoming scenario, if one link fails traffic will switch over to another link. When FPC is restarted and the dot1p classifier is changed, restore the failed link. Packets may not go to the correct queue due to the wrong classification when traffic switches back to the original link, and traffic drops may happen during congestion.
PR NumberSynopsisCategory: a20a40 specific issue
1681701"%DAEMON-4: Set system alarm failed: Operation not supported by device" message is seen on high end SRX
Product-Group=junos
On high end SRX platform, "%DAEMON-4: Set system alarm failed: Operation not supported by device" message is seen when system/chassis alarm is generated
1698797Fabric monitoring suspension and control link failure may cause HA cluster outage
Product-Group=junos
In HA cluster, a local node failure which causes control link to go down may not guarantee the other node to take over primary if the fabric link monitoring suspension was triggered earlier before (e.g. - caused by a minor hardware failure), as the fabric link down event would be ignored when the other node was in RG0 ineligible state. This is a corner case to https://www.juniper.net/documentation/us/en/software/junos/chassis-cluster-security-devices/topics/topic-map/security-chassis-cluster-failover-parameters.html#id-understanding-chassis-cluster-control-link-heartbeats-failure-and-recovery__d27575e82. And PR1698797 fixed this defect.
PR NumberSynopsisCategory: BBE Autoconfigured DVLAN related issues
1680453The process bbe-smgd on the router would stop processing new PPPoE subscribers session
Product-Group=junos
On all Junos platforms configured with subscriber-management, the process bbe-smgd will stop processing new PPPoE (Point-to-Point Protocol over Ethernet) connections due to a memory leak in the control packet pool of the PPPoE plugin.
PR NumberSynopsisCategory: BBE interface related issues
1687138The PIMv6 is not getting enabled for L2TP subscribers
Product-Group=junos
On MX platforms, the Protocol-Independent Multicast version 6 (PIMv6) might not get enabled when it is configured over the Layer 2 Tunneling Protocol (L2TP) Subscriber Interface using the Dynamic-profiles.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1675921Micro BFD session state in RE remain UP even peer side session is down.
Product-Group=junos
Any platforms with Micro BFD configured on member links of the LAG/ae interface, BFD Session state in RE remains as UP always even though PEER device has ceased.
PR NumberSynopsisCategory: Border Gateway Protocol
1635018The BGP family route-target might not work in hierarchical Route Reflector scenario
Product-Group=junos
On all Junos and EVO platforms, BGP family route-target (RT) might not work in a hierarchical Route Reflector (RR) scenario, when the same RT is used, route might be rejected as there is a loop.
1652666Wrong next-hop weight might be observed with BGP PIC enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms, wrong weight might be observed with BGP PIC (Border Gateway Protocol Prefix Independent Coverage) enabled.
1660456Incorrect inactive routes are being propagated to neighbors with add-path
Product-Group=junos
On all Junos and Junos Evolved platforms that support add-path which is used to advertise inactive external BGP routes from the VRF table, changes to that route may not be propagated. To avoid the issue please use advertise-external knob instead of add-path to advertise not best eBGP routes internally.
1660571Damping policy not working as expected when import policy and damping policy are changed in one commit
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, when BGP damping is configured, the routes show default damping parameters when both import policy and damping policy are changed in one commit.
1673160The routes with an independent resolution can trigger an rpd crash when the last BGP peer is down
Product-Group=junos
On all Junos and Junos Evolved platforms, Independent resolution routes imported from another table (i.e. VRFs with color routes that need resolution) can trigger an rpd crash when the last BGP peer is down.
1679646The AGGREGATOR attribute will not be set correctly when the independent-domain is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in BGP(Border Gateway Protocol) deployments with the "independent-domain" and aggregate routes configured under routing-instance, the AGGREGATOR attribute encapsulated within the ATTR_SET will not be populated correctly. This can result in unintended behavior or service impact because the BGP neighbors receiving this update may discard it as it is not RFC complaint.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1695320BMP EOR is sent with wrong peer address causing BMP failure
Product-Group=junos
On all Junos and Junos Evolved platforms, on removing and re-applying BMP (BGP Monitoring Protocol) configuration, the EOR (End-of-RIB) message sent by the router has the wrong peer address updated causing BMP collector failure. There is no traffic impact due to this issue.
PR NumberSynopsisCategory: QFX52xx platforms Interface running EVO
1641313Junos OS Evolved: A specific SNMP GET operation and a specific CLI command cause resources to leak and eventually the evo-pfemand process will crash (CVE-2023-22400)
Product-Group=junos
An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA70196 [juniper.net] for more information.
PR NumberSynopsisCategory: Express Broadway PFE L3
1680757BFD sessions will remain down in the EVPN-VxLAN scenario
Product-Group=junos
On QFX 10008 and QFX10016 platforms, in a distributed mode Bidirectional Forwarding Detection(BFD) session might remain down if the anchor FPC and the FPC where BFD packets are received over Virtual Tunnel Endpoint (VTEP) are different.
1697827Traffic drop is observed after deleting or deactivating the logical interface
Product-Group=junos
On Junos QFX10K platforms configured with multiple logical interfaces (IFLs) on the same physical interface (IFD), if any one of the logical interfaces (IFL) is deleted or deactivated, it will cause a complete traffic drop on the other IFLs of the same IFD.
PR NumberSynopsisCategory: Virtual-chassis platform/chassisd infrastructure PRs for MX
1670345The PFE I/O chip setup failed for some interfaces and causes those interfaces missing in PFE after backup chassis upgraded via Sequential Upgrade
Product-Group=junos
When the MX virtual-chassis was upgraded by using the Sequential Upgrade method, there is the possibility that PFE provisioning may start before link training completes and all PICs are online. In such scenario, the ifd provisioning is preserved and if the preserved state is applied to the PFE before fabric training has completed and all the PICs have been powered on, ifd missing errors will be seen.
1697630MX-VC: The backup VC router could become master after the system reboot
Product-Group=junos
On Junos MX platforms when VC (Virtual Chassis) configuration is done and after the VC membership election, when routers are rebooted, the previously elected primary router will become the backup router and the backup router will come up as the primary router.
PR NumberSynopsisCategory: Class of Service
1693977The oid tree jnxCosQstatEntry returns nothing for some interfaces after restarting class-of-service
Product-Group=junos
The oid tree jnxCosQstatEntry returns nothing for some interfaces after restarting class-of-service.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for cos
1650598MX960:: Syslog errors HALP-trinity_vbf_flow_unbind_handler:1107: vbf flow 624626: ifl 526 not found, fpc5 vbf_var_get_ifs:754: ifl not found, PFE_ERROR_NOT_FOUND seen frequently on MPC7E in 5.5K DCIP/10kPPPoE FTTB Stress Test
Product-Group=junos
With MPC7 cards used as Junos Subscriber Management access cards, the following log message may be generated upon disconnect: HALP-trinity_vbf_flow_unbind_handler:xxxx: vbf flow xxxxx: ifl xxx not found, fpcx vbf_var_get_ifs:xxx: ifl not found It indicates that a second call to release resources is generated for the same subscriber flow. The request is ignored and no functional impact is observed.
PR NumberSynopsisCategory: QFX Access Control related
1693640The dot1x reauthentication will not work for a port with VoIP VLAN
Product-Group=junos
On Junos EX platforms, the dot1x clients will remain in connecting state after the 'clear dot1x interface' is done due to which the interface would not get authenticated to become a member of the configured access VLAN. When this happens, VLAN membership will not be formed.
1696906The dot1x authentication will not be enabled on interfaces with specific configuration combination
Product-Group=junos
On QFX and EX platforms running Junos, the dot1x authentication will not get enabled on the interfaces when both "set protocols dot1x authenticator interface server-fail-voip vlan-name " and "set switch-options voip interface vlan " are configured. As a result, the dot1x authentication will not work on the interfaces.
1702388Dot1x memory is spiking up even after clearing the dot1x sessions
Product-Group=junos
Memory leaks were observed in the following two scenarios: i) The command "clear dot1x interface" leaks 1280 bytes every time it is issued. ii) When dot1x is configured for a single supplicant mode on an interface, and then deleted, there is a memory leak of 8kb (8192 bytes) + 28 bytes every rotation.
PR NumberSynopsisCategory: Device Configuration Daemon
1682271Node Slicing: In a rare scenario, the FPC/SLC will get stuck in the ready state after a restart
Product-Group=junos
On Junos MX platforms, in a rare scenario, FPC/SLC (Flexible PIC Concentrator/Sub Line Card) may get stuck in the ready state after restarting it and the error message of 'Device busy' will be observed in Syslog.
1695663The Unicast traffic is dropped on QFX5100/EX46xx-VC platforms
Product-Group=junosvae
On QFX5100/EX46xx Junos platforms configured with Virtual Chassis(VC), if a master member is unplugged or forced to power off, the unicast traffic is dropped due to mac-persistence-timer expiry there is a difference in mac addresses between logical aggregated parent interface and member aggregated ethernet(ae) interface.
PR NumberSynopsisCategory: Firewall Filter
1697959Deactivating and activating the GRES causes churn in dfwd filter addition/deletion
Product-Group=junos
On all Junos dual-RE platforms, when performing activate/deactivate Graceful Routing Engine Switchover (GRES) multiple times synchronization issues are observed between the master and backup dfwd process.
PR NumberSynopsisCategory: DNX L2 related features
1678752The LLDP packets will not be transmitted over l2circuit on the ACX platform
Product-Group=junos
On ACX710/ACX5448 platforms in the layer2 circuit scenario, after enabling and disabling the LLDP (Link Layer Discovery Protocol) protocol on the port, LLDP packets will not be transmitted on the created l2circuit if LLDP gets activated before the l2circuit. LLDP traffic will be impacted as packets won't reach the neighbor device.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1683312'clear interfaces statistics all' taking more than 9 min due to invalid PIC configuration inside GNF.
Product-Group=junos
Invalid PIC configuration inside GNF may add delay to 'clear interface statistic all' command. This issue does not impact any functionality. chassis fpc pic
1695510MPC11E goes offline with "fpc-slice" configured
Product-Group=junos
On MX2020 platforms with MPC11E in the Junos Node Slicing environment, when "fpc-slice" is configured results in MPC11E going offline.
PR NumberSynopsisCategory: Manageability for Node Virtualization
1583324JDM server creation might fail on junos node slicing setup in in-chassis mode
Product-Group=junos
On MX platforms the JDM (Juniper Device Manager) server could not be created in in-chassis mode of junos node slicing, which results in mgd process crash and affects GNF's (Guest Network Function) provisioning.
PR NumberSynopsisCategory: EVPN control plane issues
1672749Traffic drop might be observed in the EVPN-VPWS scenario
Product-Group=junos
On Junos and Junos OS Evolved platforms that support Ethernet Virtual Private Lan-Virtual Private Wire service (EVPN-VPWS), traffic drop might be observed in the EVPN-VPWS scenario during a new nexthop addition due to a delay in processing the EVPN route resolution.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1649234The kernel crash would be observed in an EVPN multi-homed scenario
Product-Group=junos
On QFX10002/QFX10008/QFX10016 (only QFX10K) platforms, when Assisted Replication (AR) feature as Replicator role is used in an Ethernet VPN (EVPN) multi-homed scenario, there would be out-of-bound memory access issue observed which could result in the kernel crash leading to the service impact.
1662954In EVPN-MPLS Mutihoming scenario DF election will get stuck in the Preference based state
Product-Group=junos
On all Junos and Junos Evolved platforms supporting preference-based DF (Designated Forwarder) election in EVPN-MPLS Multihoming scenario, the DF election will be stuck in the Preference based state if there will be a change in the df-election on the fly.
1702016IPv4/IPv6 ping from PE (IRB interface) to CE works only when extended-vlan-list is configured for the specific Vlan
Product-Group=junos
On all Junos & Junos Evolved platforms, IPv4/IPv6 ping from PE(Provider edge) with IRB(Integrated routing and bridging) interface to CE works only when extended-vlan-list is configured for the specific Vlan.
PR NumberSynopsisCategory: Control plane EVPN multicast
1670435EVPN multicast traffic may get impacted because of routes getting stuck in the kernel routing table (krt) queue
Product-Group=junos
On all Junos and Junos Evolved platforms with Ethernet Virtual Private Network(EVPN) enabled, in the presence of certain triggers like rpd restart, rollback of configuration etc., EVPN multicast routes might get stuck in the kernel routing table (krt) queue due to which the corresponding routes in the forwarding table may point to 'fictitious' next hops, resulting in traffic disruption.
PR NumberSynopsisCategory: EX4400 PFE software
1694800On a PVLAN with DAI ARP packets will be forwarded between isolated ports
Product-Group=junos
On Junos based EX platforms, when Dynamic ARP (Address Resolution Protocol) Inspection (DAI) is configured on PVLAN (Private Virtual Local Area Network), ARP packets coming from the LAG (Link Aggregation Group) are forwarded to other isolated access ports.
1704470Traffic drops observed with hierarchal overlay ECMP configuration
Product-Group=junos
On EX4400 platforms in the EVPN-VXLAN environment, the overlay ECMP (equal-cost multipath) route does not get programmed in hardware resulting in traffic drops when hierarchal overlay ECMP is configured.
PR NumberSynopsisCategory: EX4400 platform
1690674On EX4100 and EX4400 platform, alarm 'PEM is not supported' might be seen.
Product-Group=junos
On EX4100 and EX4400 platform, system alarm 'PEM is not supported' might be seen with a specific trigger and it keeps remain even after supplied power.
PR NumberSynopsisCategory: EX Entry Level Access VC platform
1704457The PXE boot recovery fails on EX9204/9208/9214 VC setup
Product-Group=junos
On EX9204/9208/9214 platforms configured in a Virtual Chassis(VC) setup, if the MPC7E SSD(solid-state drive) local disk is erased or there is a hardware failure, the MPC7E BIOS boot/recovery if attempted through the PXE will not happen and stuck in a boot loop.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1693424Traffic loss is observed when the ECMP path is IRB over AE (IPv4 -> MPLS)
Product-Group=junos
On QFX10002 platforms, when the ECMP (Equal-cost multi-path) path is IRB (Integrated routing and bridging) over AE (Aggregated Ethernet) {IPv4 -> MPLS (Multiprotocol Label Switching)} results in packets getting discarded for which traffic loss is observed.
PR NumberSynopsisCategory: Express ASIC interface
1693367On all Junos PTX3000 and PTX5000, upgrading from older Junos to 20.2R1 or later release might trigger intermittent link flapping
Product-Group=junos
On all Junos PTX3000 and PTX5000, 40GE/100GE ports on any PIC module might run into continuous link flapping after 1st FPC/PIC boot-up process since upgrading from older Junos to 20.2R1 or later releases.
PR NumberSynopsisCategory: GMIC2 platform driver issues
1693211MACsec on logical interfaces fails after port flap
Product-Group=junos
MACsec configured on logical interfaces (IFL) would fail to restore after a flap of the parent physical interface. This will lead to Cyclic Redundancy Check (CRC) errors and failure to pass traffic.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1663050The rpd core may be seen when there is a synchronization issue
Product-Group=junos
On Junos ACX710 device, the rpd core may be seen. The rpd keeps running and there is no functional impact.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1649958The user-defined speed does not take effect on the AE interface in certain scenarios on Junos platforms
Product-Group=junos
On Junos platforms supporting GRES (Graceful Routing Engine Switchover), the bandwidth flag on the backup RE (Routing Engine) for the AE interfaces is set unconditionally, hence the bandwidth is struck at a value despite not being set by the user statically. When GRES is performed followed by link delete/add for the AE interface, the interface would get stuck with the bandwidth and gets synced with the backup RE. There can be seen partial service impact in the case of the RSVP (Resource Reservation Protocol) and the restoration to recover from this issue is to configure bandwidth manually and then remove the configuration.
1680889Traffic drop would be observed only when the backup link is up on link-protection LAG interface
Product-Group=junos
On all Junos platforms, when the Link Aggregation Group (LAG) interface is configured with static link-protection, the packet goes out via the active member (primary) link of LAG; instead, if the backup link comes up first, then a timer of 10 seconds kicks to start and once the timer expires then the backup link is marked to be a new active link of LAG which takes the traffic.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1685406The protocol MTU for the IRB interface is not rolled back when the MTU of the IRB or IFD interfaces is modified or deleted
Product-Group=junos
On all Junos platforms, the maximum transmission unit (MTU) on the Integrated Routing and Bridging (IRB) interface is not getting reset when the MTU configuration on IRB or IFD is removed. When MTU configuration is removed from the IRB interface, the internal data structure for the MTU configuration is not getting reset which might affect traffic and it is a rare case.
PR NumberSynopsisCategory: ISIS routing protocol
1677567Label traffic will be dropped at the one-hop LSP stitching node if the packet has more than one label
Product-Group=junos
On all Junos and Junos Evolved platforms supporting the Segment Routing (SR) feature, when segment routing and Label Distribution Protocol (LDP) stitching are configured, the label traffic drop is observed at the one-hop Label Switched Path (LSP) stitching node when the labeled packet is received with more than one label.
PR NumberSynopsisCategory: jdhcpd daemon
1698798A dcd process crash is observed continuously when the dhcp-service is restarted
Product-Group=junos
On MX platforms that support Broadband Edge (BBE) functionality, the dcd crash continuously occurs when the subscribers are logged in using the DHCP dynamic profile and dhcp-service is restarted having the configuration like "set chassis network-services enhanced-ip" enabled.
PR NumberSynopsisCategory: JFlow bug tracker for SRX platforms
1688627The system may crash when Jflow inactive timeout is configured to be less than 'previous flow-inactive-timeout + 180' seconds
Product-Group=junos
On SRX platforms, when Jflow inactive timeout is configured to be less than 'previous flow-inactive-timeout + 180' seconds result in a system crash and core files are generated.
PR NumberSynopsisCategory: Flow Module
1645050No new connections will be allowed to get created on SRX Platforms due to 'resource-manager' feature being wrongly kicked-in
Product-Group=junos
On all non-5k SRX platforms, when the CPU thread utilization exceeds 95% the 'resource-manager' will wrongly kick in and drop the traffic associated with new sessions.
1692100SOF was incorrectly offloading short-lived flows leading to early exhaustion of NP memory, reducing overall device performance
Product-Group=junos
On SRX5K and SRX4600 series platforms, Automated Express Path (SOF) was incorrectly offloading short-lived flows. This consumed additional resources on the Network Processor (NP) which could lead to an early exhaustion of its memory, reducing overall device performance. By default, Automated Express Path (SOF) is designed to offload flows which are high bandwidth/throughput in nature.
1699578Application traffic drop seen on all SRX platforms after the upgrade to 21.2R3-S2
Product-Group=junos
On all SRX platforms, on rare occasions, after the SYN-ACK is established with the application server, the server will cause the TCP window size drop to zero after declaring a larger initial TCP window in the ACK packet. Though this is not prohibited but generally not expected behavior. Due to this, the packet will be dropped for that particular session.
PR NumberSynopsisCategory: SRX Firewall Authentication
1685116The user authentication page is not rendering on the client browser
Product-Group=junos
On all Junos SRX platforms due to cross-origin restriction access, the domain page does not load. The issue happened due to a firewall authentication failure.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1678772New secondary node to go into a disabled state after ISSU and failover RG0 because of fabric link failure
Product-Group=junos
On SRX5K platforms with SPC3 card, the primary node will lose the backup node and fabric link failure is observed resulting in the new secondary node going into a disabled state after ISSU (In-Service Software Upgrade) and failover RG0 (redundancy group) in a chassis cluster environment.
1691071Chassis cluster IP monitoring on the secondary node failed after the system reboot on the SRX platforms
Product-Group=junos
On SRX platforms, IP monitoring on the secondary node failed when a Reth (redundant Ethernet) interface consists of two or more than two interfaces on each node. Reth member interface which has a higher port number cannot receive ICMP (Internet Control Message Protocol) packet used for IP monitoring, which will then put the system in an error state.
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1631149SRX5600/5800 - SNMP mib queries may result in occasional response timeouts
Product-Group=junos
SRX5600/5800 - SNMP MIB queries for jnxJsSPUMonitoringMIB objects (1.3.6.1.4.1.2636.3.39.1.12.1.x) may result in occasional response timeouts
1687244unexpected default event-rate value for event mode logging
Product-Group=junos
On SRX platform, when event mode logging is used without event-rate option, the logging rate was unexpectedly set to 100 although the default event rate is 1500.
PR NumberSynopsisCategory: Firewall Network Address Translation
1655197Syslog mode stream performance limitation for pba-interim-logging
Product-Group=junos
Syslog mode stream performance limitation for pba-interim-logging during syslog messages bursts.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1636458IPsec tunnel might stop processing traffic
Product-Group=junos
On all Junos SRX products, when NAT-T(nat traversal) is configured and working for an IPsec tunnel, the tunnel might stop processing the traffic after session rekey. This issue may only be encountered on Junos release 20.4R3 or higher and to recover from the issue the ike negotiation needs to be restarted.
1648249Vmcore is seen on Junos platforms when data plane IPSec is configured
Product-Group=junos
On Junos platforms, when data plane IPsec (IP Security) is configured, the IP layer passes bad mbuf information to the IPsec layer causing the core which is triggered by data plane ESP (Encapsulating Security Payload) packets coming to RE (Routing Engine).
PR NumberSynopsisCategory: Label Distribution Protocol
1676503The rpd crashes very rarely when constructing LDP trace message irrespective of enable/disable LDP traceoptions
Product-Group=junos
The rpd (routing process daemon) crashes very rarely when constructing LDP trace message with LDP traceoptions enabled or disabled.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1693730Traffic loss will be seen when MACSEC is configured
Product-Group=junos
On all Junos platforms where MACSEC(Media Access Control Security) is configured with 60s SAK (secure association key) rollover, traffic loss will be observed during RE (Routing Engine) switchover.
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1688972PFE wedge will be seen due to fast link flaps
Product-Group=junos
When the 10/40/100G links of the same PFE (Packet Forwarding Engine) on MPC10E/MPC11E/LC2301/MX10K-LC9600 line cards flap continuously, the whole PFE can wedge and all the links in that PFE will be affected.
PR NumberSynopsisCategory: MPC11 ULC interface software related issues.
1703374Some of the interfaces are going down on rebooting the MPC11E line card
Product-Group=junos
The reboot of the MPC11E line card on MX2010/MX2020 platforms makes some of the interfaces down. Hence the traffic carried over the down interfaces will be dropped. This is caused by racing conditions between multiple processes during the addition of the interfaces after the FPC/PIC restart.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1602127Traffic loss might happen in some SR-TE scenario
Product-Group=junos
On all platforms with SR-TE scenario, traffic loss might happen if put local node SID as the first hop of an SR-based LSP that is a static configured segment-list due to an incorrect auto-translate configuration.
1690458On a controller based MPLS setup with container LSPs, rpd daemon crashes after LSP deletion occurs
Product-Group=junos
On all Junos-based platforms, in a scenario where an external controller is provisioned, rpd crashes when an externally controlled container LSP (Label Switched Path) is deleted and the software tries to update its status.
1694648The rpd crash will be observed during the MPLS label block allocation
Product-Group=junos
On all Junos and Junos Evolved platforms in the Multiprotocol Label Switching (MPLS) scenario, the rpd crash will happen in rare conditions during MPLS label block allocation.
1697982[MX]L2VPN ping is failing when UHP rsvp LSP is used
Product-Group=junos
MPLS L2VPN ping is getting failed when MX is egress. In egress, RE verifies whether received label is VC label or not. For most of the platforms, tunnel label will be removed in PFE before punting the echo request packet to RE. But in this platform, tunnel label is not removed hence RE verifies this tunnel label and it is returning no-mapping.
1701420The rpd core and traffic loss is observed on Junos and Junos Evolved platforms
Product-Group=junos
On Junos and Junos OS platforms, if an LSP (Label-Switched-Path) is configured and delegated to an external controller is disabled (not deleted from configuration), and then a rpd restart or RE (Routing Engine) switchover takes place, the rpd process crashes and generates core resulting in traffic loss.
1701800Memory leak issue in TED
Product-Group=junos
On all Junos and Junos Evolved platforms, a memory leak is observed in TED (Traffic Engineering Database) when the inet tables is not cleaned up after routing instance deactivation.
PR NumberSynopsisCategory: MX Timing software
1657291PTP passthrough packets are timestamped by certain Linecards on MX platforms
Product-Group=junos
On Junos MX platforms, when we install MPC2E-NG/3E-NG with MIC-3D-20GE-SFP-E and MPC5E/6E with SFPP OTN MIC (Modular Interface Card) (MIC6-10G-OTN), enable PTP (Precision Time Protocol)-BC (Boundary Clock) and enable PHY-timestamping, the transit PTPoIPv4/v6transit packets are getting timestamped. This can cause sync issues with the PTPoIP GM (Grandmaster) which can impact PTP applications.
1671262PTP server state stuck in acquiring state when configured on a port enabled with Ingress Queueing Feature
Product-Group=junos
On MX and EX platforms, with Trio-based line cards, configuring ingress queuing on the interface where Precision Time Protocol (PTP) packets are received, Ingress Queueing duration was not accounted for in the PTP fields and results in a delay in processing.
PR NumberSynopsisCategory: MX104 Software - PHY drivers
1652647The interface on copper SFP takes 2 times of hold-time up timer to come online
Product-Group=junos
On MX platform, after the UP hold timer expires, the interface with copper tristate SFP comes up and back to down and restarts the hold timer. If the hold-time up is set to 60 seconds, at 60 seconds the interface goes up but immediately goes down. Then after another 60 seconds, it comes online which could cause a slower convergence time.
PR NumberSynopsisCategory: Microkernel for neo mpc
1670137Multibit ECC error causes the whole MX platform chassis to go down
Product-Group=junos
Faulty FPC (Flexible PIC Concentrator) on the MX platform chassis exhibiting multibit ECC (Error Checking and Correction) error (L2 cache error) will trigger this issue. The whole chassis goes down until the faulty FPC is removed from the chassis.
PR NumberSynopsisCategory: Track Mt Rainier RE NIC issues in Linux
1695794The RE mastership switchover will not be triggered when the internal master interface on VM Host is down
Product-Group=junos
On VM Host platforms, the Flexible PIC Concentrator (FPC) will be disconnected and the Routing Engine (RE) mastership will not be triggered when the master internal interface(eth1/eth2) is down. Traffic loss will be seen as FPCs are disconnected.
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1670507Fabric Destination error and Fabric plane going in check state after changing the fabric redundancy mode
Product-Group=junos
On MX240/480/960 platforms, Fabric drops are observed when changing the fabric redundancy mode.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1642287Kernel crash is seen on the device if the device is continuously power cycled
Product-Group=junos
This issue is applicable to EX3400/EX2300/EX4100. There is a possibility of kernel crash when the system will be in the process of coming up after reboot (and observed only with multiple iterations of continuous reboot cycles). This is observed only during the init sequence of the management driver and impact is limited to increased system boot time.
1681783On Ex4400 upgrade failure happens when upgrading through a USB drive.
Product-Group=junos
On EX4400 upgrade failure happens when upgrading through a USB drive.
1700629The command "request system zeroize" might not work properly on EX4400.
Product-Group=junos
When issuing the "request system zeroize" command, an error message might be seen.
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1697643NTP threshold reject action does not work on all Junos platforms
Product-Group=junos
When CLI command "set system ntp threshold action reject" is set on all Junos platforms, the nodes are still getting NTP updates although the NTP time is above the configured threshold.
PR NumberSynopsisCategory: TCP/UDP transport layer
1685113BGP session flap with error BGP_IO_ERROR_CLOSE_SESSION
Product-Group=junos
On all Junos and Junos Evolved platforms, a random BGP (Border Gateway Protocol) session flaps will be observed immediately after committing certain configuration changes with the error "BGP_IO_ERROR_CLOSE_SESSION" along with a TCP connection reset. This issue is generic to any TCP (Transmission Control Protocol) connection that has MD5 (Message-Digest Algorithm) enabled on it, eg targeted LDP. Following error is also reported: rpd: bgp_pp_recv: rejecting connection from a.b.c.d (Internal AS xyz), peer in state Established rpd: bgp_pp_recv:5159: NOTIFICATION sent to a.b.c.d+64150 (proto): code 6 (Cease) subcode 5 (Connection Rejected)
PR NumberSynopsisCategory: OSPF routing protocol
1700966OSPF stuck in InitStrictBFD state for the neighbor which doesn't send LLS header
Product-Group=junos
When Strict BFD (Bidirectional Forwarding Detection) for OSPF (Open Shortest Path First) configured on all Junos OS and Junos OS Evolved platforms, and one or more OSPF neighbors don't support Link-Local Signaling ("LLS", RFC5613), the adjacency with these neighbor(s) might stuck in InitStrictBFD state upon adjacency initialization. Neighbor doesn't support LLS, hence it doesn't attach the LLS header, which is a pre-requisite for Strict BFD.
PR NumberSynopsisCategory: Used for tracking OVSDB software issues and features
1687847OVSDB certificate files are not copied from the Master to the Backup
Product-Group=junos
On all Junos devices which support OVSDB (Open vSwitch Database) functionality, when a new backup is added on VC (virtual chassis), the master does not copy the certificate files to the backup. This impacts the OVSDB functionality and affects the traffic.
PR NumberSynopsisCategory: MPLS Point-to-Multipoint TE
1654226The route might stay up but LSP remains down after the primary LSP interface is administratively disabled
Product-Group=junos
After a link-protected LSP (Label Switched Path) undergoes local reversion, the PLR (Point of Local Repair) reinstates local (link) protection successfully. However, the link might not properly detect that its Phop (penultimate hop) node has signaled itself as the PLR. This can cause the downstream node not to properly consider itself as LP-MP (link-protecting Merge Point). Hence when there is a second failure on the same link connecting these two nodes the LSP state is deleted from the downstream node dropping traffic arriving on the bypass.
PR NumberSynopsisCategory: Provider Backbone (PBB) EVPN PFE functionality on MX
1529940PBB-EVPN PE cannot learn remote CE MAC address due to ARP suppression enabled
Product-Group=junos
In PBB-EVPN (Provider Backbone Bridging - Ethernet VPN) environment, ARP suppression feature which is not supported by PBB might be enabled unexpectedly. This could cause MAC addresses of remote CEs not to be learned and hence traffic loss.
PR NumberSynopsisCategory: Path computation client daemon
1623445cPCE: PCCD is sending LSP delete operation instead of deleting specific instance
Product-Group=junos
PCE: PCCD is sending LSP delete operation instead of deleting specific instance, this is causing cycle of Add/Delete with PCE.
PR NumberSynopsisCategory: Issues related to PKI daemon
1669426jsd memory leak and may lead jsd restart.
Product-Group=junos
You may see memory usage of jsd is increasing gradually. When the jsd process crashes, it will restart automatically.
PR NumberSynopsisCategory: JRR - VRR running on SRX4200
1691694A 802.1Q tagged Ethernet traffic with an expected VLAN ID and with a non-zero 802.1P value ingressing a JRR200 VLAN enabled interface is dropped.
Product-Group=junos
A 802.1Q tagged Ethernet traffic with an expected VLAN ID and with a non-zero 802.1P value ingressing a JRR200 VLAN enabled interface is dropped. This problem could happen at a JRR200 system running a 21.1+ JUNOS release.
PR NumberSynopsisCategory: vMX Platform Infrastructure related issue tracking
1671347MX150 platform reports error for bandwidth license
Product-Group=junos
MX150 reporting error for bandwidth license restricting bandwidth after upgrade.
PR NumberSynopsisCategory: QFX access control list
1679574Firewall functions will not work as expected when egress firewall filter is configured
Product-Group=junos
On QFX5K/EX4400/EX4650 platforms, Egress firewall filter will not work as expected. There is no impact to traffic, but firewall functions will not work.
1695820On QFX5110-VC-VCF platforms, the commit check throws an error when the firewall filter with DSCP action is enabled
Product-Group=junos
On QFX5110-VC-VCF (Virtual-Chassis Fabric) platform, if the master has member id 0, the commit check gives a warning on FPC (Flexible PIC Concentrators) and throws an error, when the firewall filter with action DSCP (Differentiated Services Code Point) is configured and is applied it to any interface, with member 1 as the master.
PR NumberSynopsisCategory: QFX L2 PFE
1672583The link is up after a power cycle and software reboot but traffic does not flow
Product-Group=junos
On the EX4600 device with SFP-LX10/SFP-SX, after a power cycle/software reboot, all ports are initialized and links are up with auto-negotiation enabled. Few ports are up and traffic flows whereas few ports are up but no traffic flow through them.
1694076PFE crash is seen on all Junos QFX5K and EX46xx platforms with L2PT configuration
Product-Group=junos
PFE (Packet Forwarding Engine) crashes on all Junos QFX5K and EX46xx platforms when L2PT (Layer 2 Protocol Tunneling) is configured on the interface having flexible-vlan-tagging with encapsulation extended-vlan-bridge. It causes a traffic impact.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1695943JUNOS_REG:: QFX5110-32Q:VC:: :After loading "20.4R3-S5.3" dcpfe core is observed and device is unstable
Product-Group=junos
On QFX5K VCF platform, the PFE core will be seen due to invalid usage of snprintf (PR 1688206).
PR NumberSynopsisCategory: QFX MPLS PFE
1687257QFX5120 will drop ingress traffic on an l2circuit configured interface on continuous flapping
Product-Group=junosvae
On QFX5120 platforms, when a flap occurs in a Layer 2 Circuit (L2Circuit) configured interface, l2circuit configuration programming fails on the interface and leads to a traffic drop.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1651827The MAC address from local CE may not be learned due to the VLAN programming issue
Product-Group=junos
On QFX5k series platforms, MAC address from local CE (customer edge) might not get learned when EVPN (Ethernet VPN)/VxLAN (Virtual Extensible LAN) is configured. The traffic drop is expected as MAC learning may not happen.
1687565VxLAN configured on access port breaks L2 connectivity with "vxlan encapsulate-inner-vlan" knob
Product-Group=junos
On all Junos QFX5k platforms, L2 connectivity fails when "vxlan encapsulate-inner-vlan" knob is configured on an access port. It impacts a forwarding plane and causes a traffic impact.
1691417When a new VLAN is added on trunk interfaces, the newly added VLAN member drops the traffic
Product-Group=junos
On QFX5K platforms with Virtual Extensible VLAN (VXLAN) configuration, when a new Virtual Local Area Network (VLAN) is added to the trunk, it is not getting added and traffic loss will be seen on the newly VLAN added port.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1670240The dcpfe process might generate core-dumps and FPC might crash after line card reboot or switchover
Product-Group=junos
On QFX10K, PTX10K, PTX5K, PTX3K, and PTX1K platforms, the dcpfe process might generate core-dumps and FPC might crash after line card boot or switchover. The BIST (Built-in Self Test) might report an error in the HMC (Hybrid Memory Cube) and restart the dcpfe process causing FPC crash.
1676740, The traffic doesn't re-route quickly causing traffic blackholing
Product-Group=junos
On all VMHOST based platforms, traffic blackholing happens because the traffic doesn't re-route quickly as chassisd doesn't recognize an FPC failure from a BAD_VOLTAGE notification.
PR NumberSynopsisCategory: QFX5100 Interface related issues
1688023The LLDP output packets are not transmitting on the em0 interface of Junos and Junos OS Evolved platforms
Product-Group=junos
On Junos and Junos OS Evolved platforms, if a management Ethernet interface(em0) has an inet or inet6 family configured and "delete interfaces em0" is issued, the Link Layer Discovery Protocol (LLDP) output packets will stop transmitting, causing the LLDP neighborship to remain down in peer router.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Interface
1657534FEC link is down after disabling/enabling interface
Product-Group=junos
On the QFX5200-32C-32Q platform, on disabling and enabling interfaces, the Fast Ethernet channel (FEC) might mismatch. It impacts service as the FEC link might not come up.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1660532The port LEDs do not light up when 40G physical interfaces are up.
Product-Group=junosvae
The port LEDs do not light up when 40G physical interfaces are up. This is a display issue. There is no service impact when this issue occurs.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1587054The MVPN traffic loss might be seen due to the flooded multicast next-hop is missed
Product-Group=junos
On the Evo platform in the MVPN scenario, the KRT queue will exchange the next-hop ID to the rpd. In some rare cases, if the same next-hop ID is used for 2 multicast next-hops due to memory resizing, the flooded next-hop might be deleted improperly during deactivating or activating AE interfaces in seconds intervals, then it might not be assigned to the changed multicast next-hop correctly. It will cause KRT queue to be stuck with some errors, the following MVPN traffic loss might be seen due to the multicast next-hop issue happens.
1678217PFE memory usage gets impacted after GRES
Product-Group=junos
On all Junos and Junos Evolved platforms, when GRES(Graceful Routing Engine Switchover) is performed, rpd doesn't delete some unused indirect nexthops after switchover. It will impact PFE(Packet Forwarding Engine) memory usage.
1686211The rpd crash would be observed when two separate next-hops in rpd map to the same next-hop-index in the kernel
Product-Group=junos
On all Junos and Junos Evolved platforms, when a route is getting installed to the forwarding table, associated next-hops also get installed in the forwarding table. As part of this installation process, the Junos kernel allocates the next-hop-index for the next-hop. The rpd sets this next-hop-index in its database when two separate next-hops for instance NH1 and NH2 in the rpd map to the same next-hop NH in the kernel. In such case, NH1 and NH2 next-hops in rpd will have the same next-hop-index leading to the rpd crash.
PR NumberSynopsisCategory: Issue related to mcnh routing infrastructure within RPD
1658425The next-hop does not be updated and errors observed when aggregated interface goes down
Product-Group=junos
On all Junos OS Evolved platforms, dependency errors after interface flap are observed due to uncleared multicast composite next hop from RPD(routing protocol process daemon).
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1616689The rpd memory might leak during activating and deactivating BGP
Product-Group=junos
On all Junos and Junos OS Evolved platforms, while activating and deactivating the BGP, a memory leak will be observed in rpd ( routing process daemon) which will lead to the router running out of memory.
1692818The rpd process crash is observed
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd process crash is observed with route flap and route table deletion scenarios. It is a timing issue.
PR NumberSynopsisCategory: Resource Reservation Protocol
1657872Memory utilization keeps incrementing due to the path error message
Product-Group=junos
On all Junos and Junos Evolved platforms, when a no-cspf Label Switched Path (LSP) with strict Explicit Route Object (ERO) is configured and the egress device is disconnected, a high rate of Path Error (PathErr) messages are observed which is leading to high memory utilization and triggering the chassisd crash that causes the device to be out of control, either it can not be accessible via console/ssh or it will not trigger Routing Engine (RE) switchover as well if it is dual-RE. So this would cause an outage.
1670638Premature RSVP Path Error BW-Unavailable originated by PLR
Product-Group=junos
With the "rsvp local reversion" configuration a PLR originates the "Bw_unavailable PathErr" during FRR (Fast Reroute). Junos Label Edge Router (LER or ingress router) ignores this type of PathErr message. However, this can be a problem if an ingress LER implementation reacts to this PathErr by bringing down the protected LSP causing packet loss.
1681403In the RSVP-TE scenario, with Entropy label capability is enabled during MBB issues handling Resv Messages
Product-Group=junos
On all platforms with entropy-label configured, the issue shows up during Make-Before-Break (MBB) at a transit Juniper node when non-Juniper Egress constructs and sends a Resv message with multiple flow-descriptors (includes descriptors for both old and new instances). Juniper transit device has an issue handling such Resv Messages, the RRO object that is part of the flow-descriptor was getting dropped when the LSP_ATTRIBUTES object was also present within the flow-descriptor.
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1701305On Junos platforms with MS-MPC cards the IKE ALG inactivity timeout value stays fixed
Product-Group=junos
On Junos platforms having MS-MPC (Multi-Service Modular PIC Concentrator), the value for the inactivity timeout for IKE (Internet Key Exchange) ALG (Application Level gateway) is automatically set to 14400 seconds even though a custom timeout value is configured by the customer. This issue is seen only in the case of IKEv1 having SFW (Stateful Firewall) without any NAT (Network Address Translation) configuration. When this issue is seen IKE transit tunnel sessions remain in the session table longer than expected, not honoring the configured timeout value. This issue is self-recoverable.
PR NumberSynopsisCategory: Cover Logical System Infrastrcuture Development
1694449The process srxpfd/ flowd will crash on SRX devices
Product-Group=junos
On all SRX platforms (except branch SRX series) configured with chassis cluster redundancy group, when numerous logical interfaces or IFLs (> 1K) are deleted and traffic is running for those IFLs, or if the RG failover then the process srxpfed/ flowd will crash.
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1674522VPN tunnel will not be established in exclusive client scenario
Product-Group=junos
On SRX platforms, if NCP(Network Control Protocol) pathfinder client is enabled with tcp-encap mode, VPN(Virtual Private Network) tunnel will not be established.
PR NumberSynopsisCategory: SRX branch platforms
1594014During reboot, "warning: requires 'idp-sig' license" can be seen on the screen even when the device has valid license
Product-Group=junos
If a device is rebooted manually or reboots for any other reason, The following messages can be seen on the boot up screen even when the device has valid license and proper configuration to use the features like IDP/UTM
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1682962Auto-negotiation is not getting reflected on the MPC7E-10GE line card
Product-Group=junos
On all MX platforms with MPC7E-10GE line card, auto-negotiation will not be set properly when changing the port speed from 10GE to 1G on a port with auto-negotiation configured. The port remains down until the commit is done separately for changing the port speed.
PR NumberSynopsisCategory: Stout cards (MPC7, MPC8, MPC9) microkernel issues
1539779MX2K-MPC7/8/9 Default threshold for single-bit correctable ECC errors on Stout PMB DDR memory increased from 1 to 10 before declaring a minor alarm.
Product-Group=junos
The threshold for declaring a minor alarm was changed to 10 correctable ECC errors per 24 hours due to excessive RMA's.
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1701183Traffic loss is seen due to interface flap when changing speed from 10G and 1G
Product-Group=junos
On Junos MX204, traffic loss is seen on 4x10G Channelized interfaces when the speed is changed from 10G to 1G on one lane which causes the other 3 lanes to flap and stay down.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1683213SRX4600HA might not failover properly due to a hardware failure
Product-Group=junosvae
In SRX4600 platform, there is a possibility of raising alarm function might not work in FPGA failure. It might affect device availability.
1689705SNMP MIB walk for jnxBoxDescr OID returns incorrect value
Product-Group=junosvae
On SRX4600 platforms running Junos, SNMP MIB walk for jnxBoxDescr OID returns the incorrect chassis name and model. This is only a display issue with no service impact.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1697215Stoppage of statistics update on MPC10E
Product-Group=junos
We have seen the stoppage of statistics update on MPC10E cards running older releases. Please note that this issue affects only the statistics update with no impact on forwarding or connectivity. This issue is seen very rarely, and we don't know the exact trigger yet. A couple of occurrences seem to point at link flaps as trigger but not conclusive. We think this may be due to a data race condition and the changes in this PR address a potential issue.
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1688416The COS queue burst size computation was incorrect when the explicit queue shaping rate was not configured, causing initial packet drops
Product-Group=junos
On specific linecards MPC10/11/LC9600 and MX304 device, there was an issue with the COS (Class of Service) queue burst size calculation when the explicit queue shaping-rate was not configured, resulting in an initial packet drop and the COS queue burst size computation was incorrect which causes packets to drop initially.
1696089FPC crash is observed in GNF scenario with CoS configuration
Product-Group=junos
On Junos platforms, in GNF (Guest Network Function) setup when CoS (Class of Service) configuration is attached on an IFL (Interface Logical) stacked over another IFL and the CoS configuration message is received on an FPC (Flexible PIC Concentrators) which does not host the IFLs IFD (Interface Device), then the FPC can crash because the FPC does not have any information about the IFLs or underlying IFDs.
1705353Syslog "[Error] COS SCHED : Token mismatch during Q stats update" seen during config change or when subscriber sessions are going down.
Product-Group=junos
When a COS scheduling node (IFD/IFL/IFLSET) is being deleted due to config change or when subscriber sessions are going down, following log maybe seen sometimes right after commit: "[Error] COS SCHED : Token mismatch during Q stats update." The log will further have the following string: "Expected token:18446744073709551615 or rmngToken:18446744073709551615" Issue applicable for MPC10, MPC11, LC9600, MX304.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1567313The sub line cards (SLC) might reboot after loading the configured inline services and services along with dfwd filters
Product-Group=junos
In an external server-based Junos Node Slicing scenario, the logical partitions (called sub line cards or SLCs) can be additionally configured for MX2K-MPC11E and assigned to different guest network functions (GNFs). If the inline services and services are applied to SLCs, some issues might happen during processing these services along with firewall process (dfwd) filter actions. Then it might cause SLCs to reboot and aftd crash.
1626115Traffic drop might be seen in node slicing scenario
Product-Group=junos
On MX platforms that use MPC11E cards, when fast-lookup-filter is enabled, traffic drop might be seen in the node slicing scenario.
1687862The FPC crash is observed with a "flexible-match-mask" condition
Product-Group=junos
On MX platforms with specific line cards, the Flexible PIC Concentrator (FPC) crash could be observed while configuring the firewall filter with a "flexible-match-mask" condition. However, If the FPC crash is not triggered, then the filter might not be working as expected.
1692070The firewall bridge filter policers (attached to AE interface) are not working on all Junos MX platform with MPC10 card upon deactivate-activate a term intended to limit overall traffic
Product-Group=junos
Traffic policing will not work as expected on all Junos MX platform with MPC10 card after doing deactivation-activation of the term intended to limit overall traffic when the firewall and policers are applied to the bridge unit using shared-bandwidth-policers on AE (Aggregated Ethernet) interface.
1701320Traffic loss is seen on MPC10E due to null pointer access without any safe check
Product-Group=junos
On the Junos MX series platforms with MPC10/11, when the line card is inserted, it restarts and traffic loss is seen generating the core dump due to the null pointer access without any safe check.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1700321VLAN tags are imposed incorrectly when traffic is routed over IRB going out of the access interface
Product-Group=junos
On MX platforms, traffic egressing on the IRB (Integrated Routing and Bridging) interface with the underlying L2 (layer2) access port has VLAN tags imposed incorrectly.
PR NumberSynopsisCategory: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1681533The line card gets crashed during node/interface statistics reporting with resource monitoring
Product-Group=junos
On MX platforms with specific line cards, the MPC may crash and generate core dumps in a corner case during node/interface statistics reporting scenario when resource monitoring is used.
PR NumberSynopsisCategory: Trio pfe qos software
1700860The egress rewrite-rule might not work as expected for traffic entering the AE interface
Product-Group=junos
On all MX platforms, if the loss-priority is not explicitly configured on the AE (Aggregated Ethernet) interface, the default classifier is applied, but the loss-priority is not properly set at certain DSCP (Differentiated Services Code Point) code points and the rewrite does not execute as expected.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1669478Traffic drop observed with SP style configuration for the logical tunnel in layer2 domain
Product-Group=junos
On MX platforms, when the configuration for the logical tunnel in the layer2 domain is in the service provider style observing traffic drop for traffic over IRB (Integrated routing and bridging).
1670316Layer 2 packets other than IPv4/IPv6 (e.g. CFM) will get forwarded as out of order via MPC10 and MPC11 in the egress direction
Product-Group=junos
On specific MX devices with MPC10 and MPC11 linecards, Layer 2 packets (i.e. other than IPv4/IPv6, e.g. CFM), may get forwarded as out of order in the egress direction. The issue is not seen for IPv4/IPv6/MPLS Encapsulated IPv4/MPLS Encapsulated IPv6 traffic/MPLS Encapsulated Ethernet+IP traffic.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1701147FPC restart and core dump generated in MPLS scaled scenario with "always-mark-connection-protection-tlv" configured
Product-Group=junos
FPC restart and core dump generated in MPLS scaled scenario with "always-mark-connection-protection-tlv" configured.
PR NumberSynopsisCategory: Issues related to port-mirroring functionality on JUNOS
1683192Traffic loss is seen with port-mirroring is enabled on AE interface in multicast downstream
Product-Group=junos
On MX and EX Platforms with Trio based MPCs, traffic loss is seen as multicast traffic will not be replicated to all downstream ports when port-mirroring is enabled on the AE (Aggregated Ethernet) interface with the destination port as another AE.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1660931Lockout-period might not work as expected
Product-Group=junos
Lockout-period might not work as expected and the user gets locked out.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1699245The mgd process might crash during commit synchronize
Product-Group=junos
On all Junos OS and Evolved OS platforms with dual RE (Routing Engine) during commit script synchronize, backup RE mgd get crash once the memory leak reaches to 65K due to which commit configuration will fail which are performed through Master RE.
PR NumberSynopsisCategory: Issues related to all UI tools (mgd-bsd/cli-bsd, XML and DMI
1681656System uptime display is shown in minutes instead of seconds
Product-Group=junos
On all Junos and Junos Evolved platforms, after the device reboot, show system uptime command is showing time in minutes instead of seconds for 24 hours.
PR NumberSynopsisCategory: For GPRS security features on highend SRX series
1704472GTPv2 Message Filtering is not working
Product-Group=junos
GTPv2 Message Filtering not working - resolved
PR NumberSynopsisCategory: VMHOST platforms software
1646339The alarm might not be generated for EDAC errors until the FPC is rebooted
Product-Group=junos
On all MX and PTX platforms, EDAC errors are triggered but alarms are not observed until the FPC gets rebooted due to the data corruption in hardware.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1680178VRRP master-master condition might occur when there are more than two devices in the VRRP group
Product-Group=junos
When more than two devices are part of the VRRP group and a lower priority master sends a keepalive as master, low priority backup may transition to master state and get stuck.
PR NumberSynopsisCategory: VSRX platform software
1680874vSRX instance in GCP gets stuck in halt state randomly when trying to reboot multiple times
Product-Group=junos
vSRX instance in GCP (Google Cloud Platform) freezes during restart and does not shutdown. This issue is very difficult to hit in production as it is seen very rarely after several reboots.
PR NumberSynopsisCategory: usf nat related issues
1692525ALG child session will not be transported through the DS-Lite tunnel which might lead to traffic failures in absence of a direct route to the host
Product-Group=junos
On Junos MX240/MX480/MX960 platform with MX-SPC3, a tunnel ID of the control session is not updated properly on the gate created for Session Initiation Protocol (SIP) Application Layer Gateway (ALG), which is leading to the gate hit session not mapping back to the Dual-Stack Lite (DS-Lite) tunnel. This might result in traffic failure if the client does not have a direct route to the host.
 
 

21.2R3-S4 - List of Known issues

See - https://supportportal.juniper.net/s/article/Junos-21-2R3-S4-list-of-Known-Issues 

Modification History

First publication 2023-02-03