Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX, EX, MX, NFX, PTX, QFX, SRX, vSRX
Alert Description
Junos Software Service Release version 21.2R3-S4 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 21.2R3-S4 is now available.
21.2R3-S4 - List of Fixed issues
PR Number
Synopsis
Category: Daily JUNOS build failures - automated builder use only
1691209
Use latest os-package when upgrading
Product-Group=junos
Upgrade to 22.3R1 while using os-package published between July 2022 and November 2022 may incorrectly link os-libs package
PR Number
Synopsis
Category: EX4300 PFE
1675977
The fxpc process crash might be observed on EX4300 and EX4300-VC platforms
Product-Group=junos
On EX4300 platforms, if there are mac-move events, the fxpc (Packet Forwarding Engine manager) crash might be observed due to race conditions.
1697685
Gratuitous ARP reply will not update the ARP cache
Product-Group=junos
On EX4300 platforms, the ARP (Address Resolution Protocol) cache will not be updated upon receiving the Gratuitous ARP reply even with "gratuitous-arp-reply" configured.
PR Number
Synopsis
Category: EX4300 Platform
1678506
The interface on the device will go down when one or more interfaces are connected to the Advantech3260 device at another end
Product-Group=junosvae
On EX4300 platforms with version 19.1R3 and above, the interface on the device will go down when the device is connected to the Advantech3260 device at the other end. It will have a traffic impact.
1680225
On EX4300-Virtual Chassis (VC) platforms, the pfex process might crash when PIC 2 is detached
Product-Group=junos
On EX4300-Virtual Chassis (VC) platforms, Packet Forwarding Engine process (pfex) crash will be seen when Physical Interface Card 2(PIC 2) is detached then Physical Interface(IFD) is getting deleted before logical interface (IFL)deletion.
PR Number
Synopsis
Category: EX4300 Filters implementation
1699777
TCAM space might be exhausted when learning DHCP snooping entries on a trusted port
Product-Group=junos
On EX, QFX5k, and MX platforms having persistent binding for DHCP (Dynamic Host Configuration Protocol) snooping configured might cause TCAM (Ternary Content Addressable Memory) space exhaustion for DHCP snooping learning on the trusted port after the device reboot.
PR Number
Synopsis
Category: EX2300/3400 PFE
1634433
The fxpc process crash might be triggered when a MAC is aging out
Product-Group=junos
On all EX platforms, fxpc process crash may trigger due to the mod operation with zero present in code which leads to unexpected behavior, this is very specific to code usage which impacts the service outage.
PR Number
Synopsis
Category: EX2300/3400 platform
1680408
On Ex2300 and EX3400, "set system ports console log-out-on-disconnect" does not allow user to log in via console.
Product-Group=junos
On certain units, with "set system ports console log-out-on-disconnect", when you login to the device via a console, the user will be kicked out to the login prompt and be asked to login again.
PR Number
Synopsis
Category: SRX-1RU System Hardware defects
1658148
SRX4600 platforms in split brain scenario post ISSU
Product-Group=junos
Junos SRX4600 platforms might go into spit brain mode after ISSU (In-Service Software Upgrade) is performed in presence of heavy traffic or huge volume of configuration. This issue causes one of the nodes to go into ineligible state, the control port is brought up late causing the split brain issue. Once the issue happens, there is traffic outage after ISSU as RG0 (Redundancy Group 0) split-brain happens, and one node may stuck in FPC (Flexible PIC Concentrator) present state.
PR Number
Synopsis
Category: SPC3 HW and SW Issues
1692611
SRX cluster may fail in a rare scenario when node status changes to disabled state without going through the ineligible state
Product-Group=junos
On SRX platforms with chassis cluster configured, the RE(Routing-Engine) & PFE (Packet Forwarding Engine) connection may break, and the cluster may fail when the node status changes from primary/secondary state to disabled state without going through the ineligible state.
PR Number
Synopsis
Category: CoS support on ACX
1689604
EVPN Packets may go to incorrect queues due to the wrong classification and may lead to packets drop during congestion
Product-Group=junos
On Junos ACX5448 and ACX710 devices, in EVPN (Ethernet Virtual private network) with a multihoming scenario, if one link fails traffic will switch over to another link. When FPC is restarted and the dot1p classifier is changed, restore the failed link. Packets may not go to the correct queue due to the wrong classification when traffic switches back to the original link, and traffic drops may happen during congestion.
PR Number
Synopsis
Category: a20a40 specific issue
1681701
"%DAEMON-4: Set system alarm failed: Operation not supported by device" message is seen on high end SRX
Product-Group=junos
On high end SRX platform, "%DAEMON-4: Set system alarm failed: Operation not supported by device" message is seen when system/chassis alarm is generated
1698797
Fabric monitoring suspension and control link failure may cause HA cluster outage
Product-Group=junos
In HA cluster, a local node failure which causes control link to go down may not guarantee the other node to take over primary if the fabric link monitoring suspension was triggered earlier before (e.g. - caused by a minor hardware failure), as the fabric link down event would be ignored when the other node was in RG0 ineligible state. This is a corner case to https://www.juniper.net/documentation/us/en/software/junos/chassis-cluster-security-devices/topics/topic-map/security-chassis-cluster-failover-parameters.html#id-understanding-chassis-cluster-control-link-heartbeats-failure-and-recovery__d27575e82. And PR1698797 fixed this defect.
PR Number
Synopsis
Category: BBE Autoconfigured DVLAN related issues
1680453
The process bbe-smgd on the router would stop processing new PPPoE subscribers session
Product-Group=junos
On all Junos platforms configured with subscriber-management, the process bbe-smgd will stop processing new PPPoE (Point-to-Point Protocol over Ethernet) connections due to a memory leak in the control packet pool of the PPPoE plugin.
PR Number
Synopsis
Category: BBE interface related issues
1687138
The PIMv6 is not getting enabled for L2TP subscribers
Product-Group=junos
On MX platforms, the Protocol-Independent Multicast version 6 (PIMv6) might not get enabled when it is configured over the Layer 2 Tunneling Protocol (L2TP) Subscriber Interface using the Dynamic-profiles.
PR Number
Synopsis
Category: Bi Directional Forwarding Detection (BFD)
1675921
Micro BFD session state in RE remain UP even peer side session is down.
Product-Group=junos
Any platforms with Micro BFD configured on member links of the LAG/ae interface, BFD Session state in RE remains as UP always even though PEER device has ceased.
PR Number
Synopsis
Category: Border Gateway Protocol
1635018
The BGP family route-target might not work in hierarchical Route Reflector scenario
Product-Group=junos
On all Junos and EVO platforms, BGP family route-target (RT) might not work in a hierarchical Route Reflector (RR) scenario, when the same RT is used, route might be rejected as there is a loop.
1652666
Wrong next-hop weight might be observed with BGP PIC enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms, wrong weight might be observed with BGP PIC (Border Gateway Protocol Prefix Independent Coverage) enabled.
1660456
Incorrect inactive routes are being propagated to neighbors with add-path
Product-Group=junos
On all Junos and Junos Evolved platforms that support add-path which is used to advertise inactive external BGP routes from the VRF table, changes to that route may not be propagated. To avoid the issue please use advertise-external knob instead of add-path to advertise not best eBGP routes internally.
1660571
Damping policy not working as expected when import policy and damping policy are changed in one commit
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, when BGP damping is configured, the routes show default damping parameters when both import policy and damping policy are changed in one commit.
1673160
The routes with an independent resolution can trigger an rpd crash when the last BGP peer is down
Product-Group=junos
On all Junos and Junos Evolved platforms, Independent resolution routes imported from another table (i.e. VRFs with color routes that need resolution) can trigger an rpd crash when the last BGP peer is down.
1679646
The AGGREGATOR attribute will not be set correctly when the independent-domain is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in BGP(Border Gateway Protocol) deployments with the "independent-domain" and aggregate routes configured under routing-instance, the AGGREGATOR attribute encapsulated within the ATTR_SET will not be populated correctly. This can result in unintended behavior or service impact because the BGP neighbors receiving this update may discard it as it is not RFC complaint.
PR Number
Synopsis
Category: Track PRs in BGP BMP area & is part of BGP inside RPD.
1695320
BMP EOR is sent with wrong peer address causing BMP failure
Product-Group=junos
On all Junos and Junos Evolved platforms, on removing and re-applying BMP (BGP Monitoring Protocol) configuration, the EOR (End-of-RIB) message sent by the router has the wrong peer address updated causing BMP collector failure. There is no traffic impact due to this issue.
PR Number
Synopsis
Category: QFX52xx platforms Interface running EVO
1641313
Junos OS Evolved: A specific SNMP GET operation and a specific CLI command cause resources to leak and eventually the evo-pfemand process will crash (CVE-2023-22400)
Product-Group=junos
An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). Refer to https://kb.juniper.net/
JSA70196
[juniper.net]
for more information.
PR Number
Synopsis
Category: Express Broadway PFE L3
1680757
BFD sessions will remain down in the EVPN-VxLAN scenario
Product-Group=junos
On QFX 10008 and QFX10016 platforms, in a distributed mode Bidirectional Forwarding Detection(BFD) session might remain down if the anchor FPC and the FPC where BFD packets are received over Virtual Tunnel Endpoint (VTEP) are different.
1697827
Traffic drop is observed after deleting or deactivating the logical interface
Product-Group=junos
On Junos QFX10K platforms configured with multiple logical interfaces (IFLs) on the same physical interface (IFD), if any one of the logical interfaces (IFL) is deleted or deactivated, it will cause a complete traffic drop on the other IFLs of the same IFD.
PR Number
Synopsis
Category: Virtual-chassis platform/chassisd infrastructure PRs for MX
1670345
The PFE I/O chip setup failed for some interfaces and causes those interfaces missing in PFE after backup chassis upgraded via Sequential Upgrade
Product-Group=junos
When the MX virtual-chassis was upgraded by using the Sequential Upgrade method, there is the possibility that PFE provisioning may start before link training completes and all PICs are online. In such scenario, the ifd provisioning is preserved and if the preserved state is applied to the PFE before fabric training has completed and all the PICs have been powered on, ifd missing errors will be seen.
1697630
MX-VC: The backup VC router could become master after the system reboot
Product-Group=junos
On Junos MX platforms when VC (Virtual Chassis) configuration is done and after the VC membership election, when routers are rebooted, the previously elected primary router will become the backup router and the backup router will come up as the primary router.
PR Number
Synopsis
Category: Class of Service
1693977
The oid tree jnxCosQstatEntry returns nothing for some interfaces after restarting class-of-service
Product-Group=junos
The oid tree jnxCosQstatEntry returns nothing for some interfaces after restarting class-of-service.
PR Number
Synopsis
Category: Enhanced Broadband Edge support for cos
1650598
MX960:: Syslog errors HALP-trinity_vbf_flow_unbind_handler:1107: vbf flow 624626: ifl 526 not found, fpc5 vbf_var_get_ifs:754: ifl not found, PFE_ERROR_NOT_FOUND seen frequently on MPC7E in 5.5K DCIP/10kPPPoE FTTB Stress Test
Product-Group=junos
With MPC7 cards used as Junos Subscriber Management access cards, the following log message may be generated upon disconnect: HALP-trinity_vbf_flow_unbind_handler:xxxx: vbf flow xxxxx: ifl xxx not found, fpcx vbf_var_get_ifs:xxx: ifl not found It indicates that a second call to release resources is generated for the same subscriber flow. The request is ignored and no functional impact is observed.
PR Number
Synopsis
Category: QFX Access Control related
1693640
The dot1x reauthentication will not work for a port with VoIP VLAN
Product-Group=junos
On Junos EX platforms, the dot1x clients will remain in connecting state after the 'clear dot1x interface' is done due to which the interface would not get authenticated to become a member of the configured access VLAN. When this happens, VLAN membership will not be formed.
1696906
The dot1x authentication will not be enabled on interfaces with specific configuration combination
Product-Group=junos
On QFX and EX platforms running Junos, the dot1x authentication will not get enabled on the interfaces when both "set protocols dot1x authenticator interface server-fail-voip vlan-name " and "set switch-options voip interface vlan " are configured. As a result, the dot1x authentication will not work on the interfaces.
1702388
Dot1x memory is spiking up even after clearing the dot1x sessions
Product-Group=junos
Memory leaks were observed in the following two scenarios: i) The command "clear dot1x interface" leaks 1280 bytes every time it is issued. ii) When dot1x is configured for a single supplicant mode on an interface, and then deleted, there is a memory leak of 8kb (8192 bytes) + 28 bytes every rotation.
PR Number
Synopsis
Category: Device Configuration Daemon
1682271
Node Slicing: In a rare scenario, the FPC/SLC will get stuck in the ready state after a restart
Product-Group=junos
On Junos MX platforms, in a rare scenario, FPC/SLC (Flexible PIC Concentrator/Sub Line Card) may get stuck in the ready state after restarting it and the error message of 'Device busy' will be observed in Syslog.
1695663
The Unicast traffic is dropped on QFX5100/EX46xx-VC platforms
Product-Group=junosvae
On QFX5100/EX46xx Junos platforms configured with Virtual Chassis(VC), if a master member is unplugged or forced to power off, the unicast traffic is dropped due to mac-persistence-timer expiry there is a difference in mac addresses between logical aggregated parent interface and member aggregated ethernet(ae) interface.
PR Number
Synopsis
Category: Firewall Filter
1697959
Deactivating and activating the GRES causes churn in dfwd filter addition/deletion
Product-Group=junos
On all Junos dual-RE platforms, when performing activate/deactivate Graceful Routing Engine Switchover (GRES) multiple times synchronization issues are observed between the master and backup dfwd process.
PR Number
Synopsis
Category: DNX L2 related features
1678752
The LLDP packets will not be transmitted over l2circuit on the ACX platform
Product-Group=junos
On ACX710/ACX5448 platforms in the layer2 circuit scenario, after enabling and disabling the LLDP (Link Layer Discovery Protocol) protocol on the port, LLDP packets will not be transmitted on the created l2circuit if LLDP gets activated before the l2circuit. LLDP traffic will be impacted as packets won't reach the neighbor device.
PR Number
Synopsis
Category: Control Plane for Node Virtualization
1683312
'clear interfaces statistics all' taking more than 9 min due to invalid PIC configuration inside GNF.
Product-Group=junos
Invalid PIC configuration inside GNF may add delay to 'clear interface statistic all' command. This issue does not impact any functionality. chassis fpc pic
1695510
MPC11E goes offline with "fpc-slice" configured
Product-Group=junos
On MX2020 platforms with MPC11E in the Junos Node Slicing environment, when "fpc-slice" is configured results in MPC11E going offline.
PR Number
Synopsis
Category: Manageability for Node Virtualization
1583324
JDM server creation might fail on junos node slicing setup in in-chassis mode
Product-Group=junos
On MX platforms the JDM (Juniper Device Manager) server could not be created in in-chassis mode of junos node slicing, which results in mgd process crash and affects GNF's (Guest Network Function) provisioning.
PR Number
Synopsis
Category: EVPN control plane issues
1672749
Traffic drop might be observed in the EVPN-VPWS scenario
Product-Group=junos
On Junos and Junos OS Evolved platforms that support Ethernet Virtual Private Lan-Virtual Private Wire service (EVPN-VPWS), traffic drop might be observed in the EVPN-VPWS scenario during a new nexthop addition due to a delay in processing the EVPN route resolution.
PR Number
Synopsis
Category: EVPN Layer-2 Forwarding
1649234
The kernel crash would be observed in an EVPN multi-homed scenario
Product-Group=junos
On QFX10002/QFX10008/QFX10016 (only QFX10K) platforms, when Assisted Replication (AR) feature as Replicator role is used in an Ethernet VPN (EVPN) multi-homed scenario, there would be out-of-bound memory access issue observed which could result in the kernel crash leading to the service impact.
1662954
In EVPN-MPLS Mutihoming scenario DF election will get stuck in the Preference based state
Product-Group=junos
On all Junos and Junos Evolved platforms supporting preference-based DF (Designated Forwarder) election in EVPN-MPLS Multihoming scenario, the DF election will be stuck in the Preference based state if there will be a change in the df-election on the fly.
1702016
IPv4/IPv6 ping from PE (IRB interface) to CE works only when extended-vlan-list is configured for the specific Vlan
Product-Group=junos
On all Junos & Junos Evolved platforms, IPv4/IPv6 ping from PE(Provider edge) with IRB(Integrated routing and bridging) interface to CE works only when extended-vlan-list is configured for the specific Vlan.
PR Number
Synopsis
Category: Control plane EVPN multicast
1670435
EVPN multicast traffic may get impacted because of routes getting stuck in the kernel routing table (krt) queue
Product-Group=junos
On all Junos and Junos Evolved platforms with Ethernet Virtual Private Network(EVPN) enabled, in the presence of certain triggers like rpd restart, rollback of configuration etc., EVPN multicast routes might get stuck in the kernel routing table (krt) queue due to which the corresponding routes in the forwarding table may point to 'fictitious' next hops, resulting in traffic disruption.
PR Number
Synopsis
Category: EX4400 PFE software
1694800
On a PVLAN with DAI ARP packets will be forwarded between isolated ports
Product-Group=junos
On Junos based EX platforms, when Dynamic ARP (Address Resolution Protocol) Inspection (DAI) is configured on PVLAN (Private Virtual Local Area Network), ARP packets coming from the LAG (Link Aggregation Group) are forwarded to other isolated access ports.
1704470
Traffic drops observed with hierarchal overlay ECMP configuration
Product-Group=junos
On EX4400 platforms in the EVPN-VXLAN environment, the overlay ECMP (equal-cost multipath) route does not get programmed in hardware resulting in traffic drops when hierarchal overlay ECMP is configured.
PR Number
Synopsis
Category: EX4400 platform
1690674
On EX4100 and EX4400 platform, alarm 'PEM is not supported' might be seen.
Product-Group=junos
On EX4100 and EX4400 platform, system alarm 'PEM is not supported' might be seen with a specific trigger and it keeps remain even after supplied power.
PR Number
Synopsis
Category: EX Entry Level Access VC platform
1704457
The PXE boot recovery fails on EX9204/9208/9214 VC setup
Product-Group=junos
On EX9204/9208/9214 platforms configured in a Virtual Chassis(VC) setup, if the MPC7E SSD(solid-state drive) local disk is erased or there is a hardware failure, the MPC7E BIOS boot/recovery if attempted through the PXE will not happen and stuck in a boot loop.
PR Number
Synopsis
Category: Express PFE L2 fwding Features
1693424
Traffic loss is observed when the ECMP path is IRB over AE (IPv4 -> MPLS)
Product-Group=junos
On QFX10002 platforms, when the ECMP (Equal-cost multi-path) path is IRB (Integrated routing and bridging) over AE (Aggregated Ethernet) {IPv4 -> MPLS (Multiprotocol Label Switching)} results in packets getting discarded for which traffic loss is observed.
PR Number
Synopsis
Category: Express ASIC interface
1693367
On all Junos PTX3000 and PTX5000, upgrading from older Junos to 20.2R1 or later release might trigger intermittent link flapping
Product-Group=junos
On all Junos PTX3000 and PTX5000, 40GE/100GE ports on any PIC module might run into continuous link flapping after 1st FPC/PIC boot-up process since upgrading from older Junos to 20.2R1 or later releases.
PR Number
Synopsis
Category: GMIC2 platform driver issues
1693211
MACsec on logical interfaces fails after port flap
Product-Group=junos
MACsec configured on logical interfaces (IFL) would fail to restore after a flap of the parent physical interface. This will lead to Cyclic Redundancy Check (CRC) errors and failure to pass traffic.
PR Number
Synopsis
Category: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1663050
The rpd core may be seen when there is a synchronization issue
Product-Group=junos
On Junos ACX710 device, the rpd core may be seen. The rpd keeps running and there is no functional impact.
PR Number
Synopsis
Category: Kernel software for AE/AS/Container
1649958
The user-defined speed does not take effect on the AE interface in certain scenarios on Junos platforms
Product-Group=junos
On Junos platforms supporting GRES (Graceful Routing Engine Switchover), the bandwidth flag on the backup RE (Routing Engine) for the AE interfaces is set unconditionally, hence the bandwidth is struck at a value despite not being set by the user statically. When GRES is performed followed by link delete/add for the AE interface, the interface would get stuck with the bandwidth and gets synced with the backup RE. There can be seen partial service impact in the case of the RSVP (Resource Reservation Protocol) and the restoration to recover from this issue is to configure bandwidth manually and then remove the configuration.
1680889
Traffic drop would be observed only when the backup link is up on link-protection LAG interface
Product-Group=junos
On all Junos platforms, when the Link Aggregation Group (LAG) interface is configured with static link-protection, the packet goes out via the active member (primary) link of LAG; instead, if the backup link comes up first, then a timer of 10 seconds kicks to start and once the timer expires then the backup link is marked to be a new active link of LAG which takes the traffic.
PR Number
Synopsis
Category: Integrated Routing & Bridging (IRB) module
1685406
The protocol MTU for the IRB interface is not rolled back when the MTU of the IRB or IFD interfaces is modified or deleted
Product-Group=junos
On all Junos platforms, the maximum transmission unit (MTU) on the Integrated Routing and Bridging (IRB) interface is not getting reset when the MTU configuration on IRB or IFD is removed. When MTU configuration is removed from the IRB interface, the internal data structure for the MTU configuration is not getting reset which might affect traffic and it is a rare case.
PR Number
Synopsis
Category: ISIS routing protocol
1677567
Label traffic will be dropped at the one-hop LSP stitching node if the packet has more than one label
Product-Group=junos
On all Junos and Junos Evolved platforms supporting the Segment Routing (SR) feature, when segment routing and Label Distribution Protocol (LDP) stitching are configured, the label traffic drop is observed at the one-hop Label Switched Path (LSP) stitching node when the labeled packet is received with more than one label.
PR Number
Synopsis
Category: jdhcpd daemon
1698798
A dcd process crash is observed continuously when the dhcp-service is restarted
Product-Group=junos
On MX platforms that support Broadband Edge (BBE) functionality, the dcd crash continuously occurs when the subscribers are logged in using the DHCP dynamic profile and dhcp-service is restarted having the configuration like "set chassis network-services enhanced-ip" enabled.
PR Number
Synopsis
Category: JFlow bug tracker for SRX platforms
1688627
The system may crash when Jflow inactive timeout is configured to be less than 'previous flow-inactive-timeout + 180' seconds
Product-Group=junos
On SRX platforms, when Jflow inactive timeout is configured to be less than 'previous flow-inactive-timeout + 180' seconds result in a system crash and core files are generated.
PR Number
Synopsis
Category: Flow Module
1645050
No new connections will be allowed to get created on SRX Platforms due to 'resource-manager' feature being wrongly kicked-in
Product-Group=junos
On all non-5k SRX platforms, when the CPU thread utilization exceeds 95% the 'resource-manager' will wrongly kick in and drop the traffic associated with new sessions.
1692100
SOF was incorrectly offloading short-lived flows leading to early exhaustion of NP memory, reducing overall device performance
Product-Group=junos
On SRX5K and SRX4600 series platforms, Automated Express Path (SOF) was incorrectly offloading short-lived flows. This consumed additional resources on the Network Processor (NP) which could lead to an early exhaustion of its memory, reducing overall device performance. By default, Automated Express Path (SOF) is designed to offload flows which are high bandwidth/throughput in nature.
1699578
Application traffic drop seen on all SRX platforms after the upgrade to 21.2R3-S2
Product-Group=junos
On all SRX platforms, on rare occasions, after the SYN-ACK is established with the application server, the server will cause the TCP window size drop to zero after declaring a larger initial TCP window in the ACK packet. Though this is not prohibited but generally not expected behavior. Due to this, the packet will be dropped for that particular session.
PR Number
Synopsis
Category: SRX Firewall Authentication
1685116
The user authentication page is not rendering on the client browser
Product-Group=junos
On all Junos SRX platforms due to cross-origin restriction access, the domain page does not load. The issue happened due to a firewall authentication failure.
PR Number
Synopsis
Category: High Availability/NSRP/VRRP
1678772
New secondary node to go into a disabled state after ISSU and failover RG0 because of fabric link failure
Product-Group=junos
On SRX5K platforms with SPC3 card, the primary node will lose the backup node and fabric link failure is observed resulting in the new secondary node going into a disabled state after ISSU (In-Service Software Upgrade) and failover RG0 (redundancy group) in a chassis cluster environment.
1691071
Chassis cluster IP monitoring on the secondary node failed after the system reboot on the SRX platforms
Product-Group=junos
On SRX platforms, IP monitoring on the secondary node failed when a Reth (redundant Ethernet) interface consists of two or more than two interfaces on each node. Reth member interface which has a higher port number cannot receive ICMP (Internet Control Message Protocol) packet used for IP monitoring, which will then put the system in an error state.
PR Number
Synopsis
Category: all logging related bugs on srx platforms
1631149
SRX5600/5800 - SNMP mib queries may result in occasional response timeouts
Product-Group=junos
SRX5600/5800 - SNMP MIB queries for jnxJsSPUMonitoringMIB objects (1.3.6.1.4.1.2636.3.39.1.12.1.x) may result in occasional response timeouts
1687244
unexpected default event-rate value for event mode logging
Product-Group=junos
On SRX platform, when event mode logging is used without event-rate option, the logging rate was unexpectedly set to 100 although the default event rate is 1500.
PR Number
Synopsis
Category: Firewall Network Address Translation
1655197
Syslog mode stream performance limitation for pba-interim-logging
Product-Group=junos
Syslog mode stream performance limitation for pba-interim-logging during syslog messages bursts.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1636458
IPsec tunnel might stop processing traffic
Product-Group=junos
On all Junos SRX products, when NAT-T(nat traversal) is configured and working for an IPsec tunnel, the tunnel might stop processing the traffic after session rekey. This issue may only be encountered on Junos release 20.4R3 or higher and to recover from the issue the ike negotiation needs to be restarted.
1648249
Vmcore is seen on Junos platforms when data plane IPSec is configured
Product-Group=junos
On Junos platforms, when data plane IPsec (IP Security) is configured, the IP layer passes bad mbuf information to the IPsec layer causing the core which is triggered by data plane ESP (Encapsulating Security Payload) packets coming to RE (Routing Engine).
PR Number
Synopsis
Category: Label Distribution Protocol
1676503
The rpd crashes very rarely when constructing LDP trace message irrespective of enable/disable LDP traceoptions
Product-Group=junos
The rpd (routing process daemon) crashes very rarely when constructing LDP trace message with LDP traceoptions enabled or disabled.
PR Number
Synopsis
Category: Port-based link layer security services and protocols that a
1693730
Traffic loss will be seen when MACSEC is configured
Product-Group=junos
On all Junos platforms where MACSEC(Media Access Control Security) is configured with 60s SAK (secure association key) rollover, traffic loss will be observed during RE (Routing Engine) switchover.
PR Number
Synopsis
Category: SW PRs for MPC10E Interfaces
1688972
PFE wedge will be seen due to fast link flaps
Product-Group=junos
When the 10/40/100G links of the same PFE (Packet Forwarding Engine) on MPC10E/MPC11E/LC2301/MX10K-LC9600 line cards flap continuously, the whole PFE can wedge and all the links in that PFE will be affected.
PR Number
Synopsis
Category: MPC11 ULC interface software related issues.
1703374
Some of the interfaces are going down on rebooting the MPC11E line card
Product-Group=junos
The reboot of the MPC11E line card on MX2010/MX2020 platforms makes some of the interfaces down. Hence the traffic carried over the down interfaces will be dropped. This is caused by racing conditions between multiple processes during the addition of the interfaces after the FPC/PIC restart.
PR Number
Synopsis
Category: Multiprotocol Label Switching
1602127
Traffic loss might happen in some SR-TE scenario
Product-Group=junos
On all platforms with SR-TE scenario, traffic loss might happen if put local node SID as the first hop of an SR-based LSP that is a static configured segment-list due to an incorrect auto-translate configuration.
1690458
On a controller based MPLS setup with container LSPs, rpd daemon crashes after LSP deletion occurs
Product-Group=junos
On all Junos-based platforms, in a scenario where an external controller is provisioned, rpd crashes when an externally controlled container LSP (Label Switched Path) is deleted and the software tries to update its status.
1694648
The rpd crash will be observed during the MPLS label block allocation
Product-Group=junos
On all Junos and Junos Evolved platforms in the Multiprotocol Label Switching (MPLS) scenario, the rpd crash will happen in rare conditions during MPLS label block allocation.
1697982
[MX]L2VPN ping is failing when UHP rsvp LSP is used
Product-Group=junos
MPLS L2VPN ping is getting failed when MX is egress. In egress, RE verifies whether received label is VC label or not. For most of the platforms, tunnel label will be removed in PFE before punting the echo request packet to RE. But in this platform, tunnel label is not removed hence RE verifies this tunnel label and it is returning no-mapping.
1701420
The rpd core and traffic loss is observed on Junos and Junos Evolved platforms
Product-Group=junos
On Junos and Junos OS platforms, if an LSP (Label-Switched-Path) is configured and delegated to an external controller is disabled (not deleted from configuration), and then a rpd restart or RE (Routing Engine) switchover takes place, the rpd process crashes and generates core resulting in traffic loss.
1701800
Memory leak issue in TED
Product-Group=junos
On all Junos and Junos Evolved platforms, a memory leak is observed in TED (Traffic Engineering Database) when the inet tables is not cleaned up after routing instance deactivation.
PR Number
Synopsis
Category: MX Timing software
1657291
PTP passthrough packets are timestamped by certain Linecards on MX platforms
Product-Group=junos
On Junos MX platforms, when we install MPC2E-NG/3E-NG with MIC-3D-20GE-SFP-E and MPC5E/6E with SFPP OTN MIC (Modular Interface Card) (MIC6-10G-OTN), enable PTP (Precision Time Protocol)-BC (Boundary Clock) and enable PHY-timestamping, the transit PTPoIPv4/v6transit packets are getting timestamped. This can cause sync issues with the PTPoIP GM (Grandmaster) which can impact PTP applications.
1671262
PTP server state stuck in acquiring state when configured on a port enabled with Ingress Queueing Feature
Product-Group=junos
On MX and EX platforms, with Trio-based line cards, configuring ingress queuing on the interface where Precision Time Protocol (PTP) packets are received, Ingress Queueing duration was not accounted for in the PTP fields and results in a delay in processing.
PR Number
Synopsis
Category: MX104 Software - PHY drivers
1652647
The interface on copper SFP takes 2 times of hold-time up timer to come online
Product-Group=junos
On MX platform, after the UP hold timer expires, the interface with copper tristate SFP comes up and back to down and restarts the hold timer. If the hold-time up is set to 60 seconds, at 60 seconds the interface goes up but immediately goes down. Then after another 60 seconds, it comes online which could cause a slower convergence time.
PR Number
Synopsis
Category: Microkernel for neo mpc
1670137
Multibit ECC error causes the whole MX platform chassis to go down
Product-Group=junos
Faulty FPC (Flexible PIC Concentrator) on the MX platform chassis exhibiting multibit ECC (Error Checking and Correction) error (L2 cache error) will trigger this issue. The whole chassis goes down until the faulty FPC is removed from the chassis.
PR Number
Synopsis
Category: Track Mt Rainier RE NIC issues in Linux
1695794
The RE mastership switchover will not be triggered when the internal master interface on VM Host is down
Product-Group=junos
On VM Host platforms, the Flexible PIC Concentrator (FPC) will be disconnected and the Routing Engine (RE) mastership will not be triggered when the master internal interface(eth1/eth2) is down. Traffic loss will be seen as FPCs are disconnected.
PR Number
Synopsis
Category: Category for tracking Olympus-MX issues
1670507
Fabric Destination error and Fabric plane going in check state after changing the fabric redundancy mode
Product-Group=junos
On MX240/480/960 platforms, Fabric drops are observed when changing the fabric redundancy mode.
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1642287
Kernel crash is seen on the device if the device is continuously power cycled
Product-Group=junos
This issue is applicable to EX3400/EX2300/EX4100. There is a possibility of kernel crash when the system will be in the process of coming up after reboot (and observed only with multiple iterations of continuous reboot cycles). This is observed only during the init sequence of the management driver and impact is limited to increased system boot time.
1681783
On Ex4400 upgrade failure happens when upgrading through a USB drive.
Product-Group=junos
On EX4400 upgrade failure happens when upgrading through a USB drive.
1700629
The command "request system zeroize" might not work properly on EX4400.
Product-Group=junos
When issuing the "request system zeroize" command, an error message might be seen.
PR Number
Synopsis
Category: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1697643
NTP threshold reject action does not work on all Junos platforms
Product-Group=junos
When CLI command "set system ntp threshold action reject" is set on all Junos platforms, the nodes are still getting NTP updates although the NTP time is above the configured threshold.
PR Number
Synopsis
Category: TCP/UDP transport layer
1685113
BGP session flap with error BGP_IO_ERROR_CLOSE_SESSION
Product-Group=junos
On all Junos and Junos Evolved platforms, a random BGP (Border Gateway Protocol) session flaps will be observed immediately after committing certain configuration changes with the error "BGP_IO_ERROR_CLOSE_SESSION" along with a TCP connection reset. This issue is generic to any TCP (Transmission Control Protocol) connection that has MD5 (Message-Digest Algorithm) enabled on it, eg targeted LDP. Following error is also reported: rpd: bgp_pp_recv: rejecting connection from a.b.c.d (Internal AS xyz), peer in state Established rpd: bgp_pp_recv:5159: NOTIFICATION sent to a.b.c.d+64150 (proto): code 6 (Cease) subcode 5 (Connection Rejected)
PR Number
Synopsis
Category: OSPF routing protocol
1700966
OSPF stuck in InitStrictBFD state for the neighbor which doesn't send LLS header
Product-Group=junos
When Strict BFD (Bidirectional Forwarding Detection) for OSPF (Open Shortest Path First) configured on all Junos OS and Junos OS Evolved platforms, and one or more OSPF neighbors don't support Link-Local Signaling ("LLS", RFC5613), the adjacency with these neighbor(s) might stuck in InitStrictBFD state upon adjacency initialization. Neighbor doesn't support LLS, hence it doesn't attach the LLS header, which is a pre-requisite for Strict BFD.
PR Number
Synopsis
Category: Used for tracking OVSDB software issues and features
1687847
OVSDB certificate files are not copied from the Master to the Backup
Product-Group=junos
On all Junos devices which support OVSDB (Open vSwitch Database) functionality, when a new backup is added on VC (virtual chassis), the master does not copy the certificate files to the backup. This impacts the OVSDB functionality and affects the traffic.
PR Number
Synopsis
Category: MPLS Point-to-Multipoint TE
1654226
The route might stay up but LSP remains down after the primary LSP interface is administratively disabled
Product-Group=junos
After a link-protected LSP (Label Switched Path) undergoes local reversion, the PLR (Point of Local Repair) reinstates local (link) protection successfully. However, the link might not properly detect that its Phop (penultimate hop) node has signaled itself as the PLR. This can cause the downstream node not to properly consider itself as LP-MP (link-protecting Merge Point). Hence when there is a second failure on the same link connecting these two nodes the LSP state is deleted from the downstream node dropping traffic arriving on the bypass.
PR Number
Synopsis
Category: Provider Backbone (PBB) EVPN PFE functionality on MX
1529940
PBB-EVPN PE cannot learn remote CE MAC address due to ARP suppression enabled
Product-Group=junos
In PBB-EVPN (Provider Backbone Bridging - Ethernet VPN) environment, ARP suppression feature which is not supported by PBB might be enabled unexpectedly. This could cause MAC addresses of remote CEs not to be learned and hence traffic loss.
PR Number
Synopsis
Category: Path computation client daemon
1623445
cPCE: PCCD is sending LSP delete operation instead of deleting specific instance
Product-Group=junos
PCE: PCCD is sending LSP delete operation instead of deleting specific instance, this is causing cycle of Add/Delete with PCE.
PR Number
Synopsis
Category: Issues related to PKI daemon
1669426
jsd memory leak and may lead jsd restart.
Product-Group=junos
You may see memory usage of jsd is increasing gradually. When the jsd process crashes, it will restart automatically.
PR Number
Synopsis
Category: JRR - VRR running on SRX4200
1691694
A 802.1Q tagged Ethernet traffic with an expected VLAN ID and with a non-zero 802.1P value ingressing a JRR200 VLAN enabled interface is dropped.
Product-Group=junos
A 802.1Q tagged Ethernet traffic with an expected VLAN ID and with a non-zero 802.1P value ingressing a JRR200 VLAN enabled interface is dropped. This problem could happen at a JRR200 system running a 21.1+ JUNOS release.
PR Number
Synopsis
Category: vMX Platform Infrastructure related issue tracking
1671347
MX150 platform reports error for bandwidth license
Product-Group=junos
MX150 reporting error for bandwidth license restricting bandwidth after upgrade.
PR Number
Synopsis
Category: QFX access control list
1679574
Firewall functions will not work as expected when egress firewall filter is configured
Product-Group=junos
On QFX5K/EX4400/EX4650 platforms, Egress firewall filter will not work as expected. There is no impact to traffic, but firewall functions will not work.
1695820
On QFX5110-VC-VCF platforms, the commit check throws an error when the firewall filter with DSCP action is enabled
Product-Group=junos
On QFX5110-VC-VCF (Virtual-Chassis Fabric) platform, if the master has member id 0, the commit check gives a warning on FPC (Flexible PIC Concentrators) and throws an error, when the firewall filter with action DSCP (Differentiated Services Code Point) is configured and is applied it to any interface, with member 1 as the master.
PR Number
Synopsis
Category: QFX L2 PFE
1672583
The link is up after a power cycle and software reboot but traffic does not flow
Product-Group=junos
On the EX4600 device with SFP-LX10/SFP-SX, after a power cycle/software reboot, all ports are initialized and links are up with auto-negotiation enabled. Few ports are up and traffic flows whereas few ports are up but no traffic flow through them.
1694076
PFE crash is seen on all Junos QFX5K and EX46xx platforms with L2PT configuration
Product-Group=junos
PFE (Packet Forwarding Engine) crashes on all Junos QFX5K and EX46xx platforms when L2PT (Layer 2 Protocol Tunneling) is configured on the interface having flexible-vlan-tagging with encapsulation extended-vlan-bridge. It causes a traffic impact.
PR Number
Synopsis
Category: QFX L3 data-plane/forwarding
1695943
JUNOS_REG:: QFX5110-32Q:VC:: :After loading "20.4R3-S5.3" dcpfe core is observed and device is unstable
Product-Group=junos
On QFX5K VCF platform, the PFE core will be seen due to invalid usage of snprintf (PR 1688206).
PR Number
Synopsis
Category: QFX MPLS PFE
1687257
QFX5120 will drop ingress traffic on an l2circuit configured interface on continuous flapping
Product-Group=junosvae
On QFX5120 platforms, when a flap occurs in a Layer 2 Circuit (L2Circuit) configured interface, l2circuit configuration programming fails on the interface and leads to a traffic drop.
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1651827
The MAC address from local CE may not be learned due to the VLAN programming issue
Product-Group=junos
On QFX5k series platforms, MAC address from local CE (customer edge) might not get learned when EVPN (Ethernet VPN)/VxLAN (Virtual Extensible LAN) is configured. The traffic drop is expected as MAC learning may not happen.
1687565
VxLAN configured on access port breaks L2 connectivity with "vxlan encapsulate-inner-vlan" knob
Product-Group=junos
On all Junos QFX5k platforms, L2 connectivity fails when "vxlan encapsulate-inner-vlan" knob is configured on an access port. It impacts a forwarding plane and causes a traffic impact.
1691417
When a new VLAN is added on trunk interfaces, the newly added VLAN member drops the traffic
Product-Group=junos
On QFX5K platforms with Virtual Extensible VLAN (VXLAN) configuration, when a new Virtual Local Area Network (VLAN) is added to the trunk, it is not getting added and traffic loss will be seen on the newly VLAN added port.
PR Number
Synopsis
Category: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1670240
The dcpfe process might generate core-dumps and FPC might crash after line card reboot or switchover
Product-Group=junos
On QFX10K, PTX10K, PTX5K, PTX3K, and PTX1K platforms, the dcpfe process might generate core-dumps and FPC might crash after line card boot or switchover. The BIST (Built-in Self Test) might report an error in the HMC (Hybrid Memory Cube) and restart the dcpfe process causing FPC crash.
1676740
, The traffic doesn't re-route quickly causing traffic blackholing
Product-Group=junos
On all VMHOST based platforms, traffic blackholing happens because the traffic doesn't re-route quickly as chassisd doesn't recognize an FPC failure from a BAD_VOLTAGE notification.
PR Number
Synopsis
Category: QFX5100 Interface related issues
1688023
The LLDP output packets are not transmitting on the em0 interface of Junos and Junos OS Evolved platforms
Product-Group=junos
On Junos and Junos OS Evolved platforms, if a management Ethernet interface(em0) has an inet or inet6 family configured and "delete interfaces em0" is issued, the Link Layer Discovery Protocol (LLDP) output packets will stop transmitting, causing the LLDP neighborship to remain down in peer router.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Interface
1657534
FEC link is down after disabling/enabling interface
Product-Group=junos
On the QFX5200-32C-32Q platform, on disabling and enabling interfaces, the Fast Ethernet channel (FEC) might mismatch. It impacts service as the FEC link might not come up.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Platform optics related issues
1660532
The port LEDs do not light up when 40G physical interfaces are up.
Product-Group=junosvae
The port LEDs do not light up when 40G physical interfaces are up. This is a display issue. There is no service impact when this issue occurs.
PR Number
Synopsis
Category: KRT Queue issues within RPD
1587054
The MVPN traffic loss might be seen due to the flooded multicast next-hop is missed
Product-Group=junos
On the Evo platform in the MVPN scenario, the KRT queue will exchange the next-hop ID to the rpd. In some rare cases, if the same next-hop ID is used for 2 multicast next-hops due to memory resizing, the flooded next-hop might be deleted improperly during deactivating or activating AE interfaces in seconds intervals, then it might not be assigned to the changed multicast next-hop correctly. It will cause KRT queue to be stuck with some errors, the following MVPN traffic loss might be seen due to the multicast next-hop issue happens.
1678217
PFE memory usage gets impacted after GRES
Product-Group=junos
On all Junos and Junos Evolved platforms, when GRES(Graceful Routing Engine Switchover) is performed, rpd doesn't delete some unused indirect nexthops after switchover. It will impact PFE(Packet Forwarding Engine) memory usage.
1686211
The rpd crash would be observed when two separate next-hops in rpd map to the same next-hop-index in the kernel
Product-Group=junos
On all Junos and Junos Evolved platforms, when a route is getting installed to the forwarding table, associated next-hops also get installed in the forwarding table. As part of this installation process, the Junos kernel allocates the next-hop-index for the next-hop. The rpd sets this next-hop-index in its database when two separate next-hops for instance NH1 and NH2 in the rpd map to the same next-hop NH in the kernel. In such case, NH1 and NH2 next-hops in rpd will have the same next-hop-index leading to the rpd crash.
PR Number
Synopsis
Category: Issue related to mcnh routing infrastructure within RPD
1658425
The next-hop does not be updated and errors observed when aggregated interface goes down
Product-Group=junos
On all Junos OS Evolved platforms, dependency errors after interface flap are observed due to uncleared multicast composite next hop from RPD(routing protocol process daemon).
PR Number
Synopsis
Category: Shard routing infrastructure within RPD
1616689
The rpd memory might leak during activating and deactivating BGP
Product-Group=junos
On all Junos and Junos OS Evolved platforms, while activating and deactivating the BGP, a memory leak will be observed in rpd ( routing process daemon) which will lead to the router running out of memory.
1692818
The rpd process crash is observed
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd process crash is observed with route flap and route table deletion scenarios. It is a timing issue.
PR Number
Synopsis
Category: Resource Reservation Protocol
1657872
Memory utilization keeps incrementing due to the path error message
Product-Group=junos
On all Junos and Junos Evolved platforms, when a no-cspf Label Switched Path (LSP) with strict Explicit Route Object (ERO) is configured and the egress device is disconnected, a high rate of Path Error (PathErr) messages are observed which is leading to high memory utilization and triggering the chassisd crash that causes the device to be out of control, either it can not be accessible via console/ssh or it will not trigger Routing Engine (RE) switchover as well if it is dual-RE. So this would cause an outage.
1670638
Premature RSVP Path Error BW-Unavailable originated by PLR
Product-Group=junos
With the "rsvp local reversion" configuration a PLR originates the "Bw_unavailable PathErr" during FRR (Fast Reroute). Junos Label Edge Router (LER or ingress router) ignores this type of PathErr message. However, this can be a problem if an ingress LER implementation reacts to this PathErr by bringing down the protected LSP causing packet loss.
1681403
In the RSVP-TE scenario, with Entropy label capability is enabled during MBB issues handling Resv Messages
Product-Group=junos
On all platforms with entropy-label configured, the issue shows up during Make-Before-Break (MBB) at a transit Juniper node when non-Juniper Egress constructs and sends a Resv message with multiple flow-descriptors (includes descriptors for both old and new instances). Juniper transit device has an issue handling such Resv Messages, the RRO object that is part of the flow-descriptor was getting dropped when the LSP_ATTRIBUTES object was also present within the flow-descriptor.
PR Number
Synopsis
Category: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1701305
On Junos platforms with MS-MPC cards the IKE ALG inactivity timeout value stays fixed
Product-Group=junos
On Junos platforms having MS-MPC (Multi-Service Modular PIC Concentrator), the value for the inactivity timeout for IKE (Internet Key Exchange) ALG (Application Level gateway) is automatically set to 14400 seconds even though a custom timeout value is configured by the customer. This issue is seen only in the case of IKEv1 having SFW (Stateful Firewall) without any NAT (Network Address Translation) configuration. When this issue is seen IKE transit tunnel sessions remain in the session table longer than expected, not honoring the configured timeout value. This issue is self-recoverable.
PR Number
Synopsis
Category: Cover Logical System Infrastrcuture Development
1694449
The process srxpfd/ flowd will crash on SRX devices
Product-Group=junos
On all SRX platforms (except branch SRX series) configured with chassis cluster redundancy group, when numerous logical interfaces or IFLs (> 1K) are deleted and traffic is running for those IFLs, or if the RG failover then the process srxpfed/ flowd will crash.
PR Number
Synopsis
Category: Remote Access VPN issues on SRX
1674522
VPN tunnel will not be established in exclusive client scenario
Product-Group=junos
On SRX platforms, if NCP(Network Control Protocol) pathfinder client is enabled with tcp-encap mode, VPN(Virtual Private Network) tunnel will not be established.
PR Number
Synopsis
Category: SRX branch platforms
1594014
During reboot, "warning: requires 'idp-sig' license" can be seen on the screen even when the device has valid license
Product-Group=junos
If a device is rebooted manually or reboots for any other reason, The following messages can be seen on the boot up screen even when the device has valid license and proper configuration to use the features like IDP/UTM
PR Number
Synopsis
Category: MPC7/8/9 Interface Issues
1682962
Auto-negotiation is not getting reflected on the MPC7E-10GE line card
Product-Group=junos
On all MX platforms with MPC7E-10GE line card, auto-negotiation will not be set properly when changing the port speed from 10GE to 1G on a port with auto-negotiation configured. The port remains down until the commit is done separately for changing the port speed.
PR Number
Synopsis
Category: Stout cards (MPC7, MPC8, MPC9) microkernel issues
1539779
MX2K-MPC7/8/9 Default threshold for single-bit correctable ECC errors on Stout PMB DDR memory increased from 1 to 10 before declaring a minor alarm.
Product-Group=junos
The threshold for declaring a minor alarm was changed to 10 correctable ECC errors per 24 hours due to excessive RMA's.
PR Number
Synopsis
Category: MX10003/MX204 MPC defects tracking
1701183
Traffic loss is seen due to interface flap when changing speed from 10G and 1G
Product-Group=junos
On Junos MX204, traffic loss is seen on 4x10G Channelized interfaces when the speed is changed from 10G to 1G on one lane which causes the other 3 lanes to flap and stay down.
PR Number
Synopsis
Category: SRX-1RU platfom related protocol, QoS, filtering features et
1683213
SRX4600HA might not failover properly due to a hardware failure
Product-Group=junosvae
In SRX4600 platform, there is a possibility of raising alarm function might not work in FPGA failure. It might affect device availability.
1689705
SNMP MIB walk for jnxBoxDescr OID returns incorrect value
Product-Group=junosvae
On SRX4600 platforms running Junos, SNMP MIB walk for jnxBoxDescr OID returns the incorrect chassis name and model. This is only a display issue with no service impact.
PR Number
Synopsis
Category: ZT/YT pfe infra issues
1697215
Stoppage of statistics update on MPC10E
Product-Group=junos
We have seen the stoppage of statistics update on MPC10E cards running older releases. Please note that this issue affects only the statistics update with no impact on forwarding or connectivity. This issue is seen very rarely, and we don't know the exact trigger yet. A couple of occurrences seem to point at link flaps as trigger but not conclusive. We think this may be due to a data race condition and the changes in this PR address a potential issue.
PR Number
Synopsis
Category: ZT/YT pfe qos software issues
1688416
The COS queue burst size computation was incorrect when the explicit queue shaping rate was not configured, causing initial packet drops
Product-Group=junos
On specific linecards MPC10/11/LC9600 and MX304 device, there was an issue with the COS (Class of Service) queue burst size calculation when the explicit queue shaping-rate was not configured, resulting in an initial packet drop and the COS queue burst size computation was incorrect which causes packets to drop initially.
1696089
FPC crash is observed in GNF scenario with CoS configuration
Product-Group=junos
On Junos platforms, in GNF (Guest Network Function) setup when CoS (Class of Service) configuration is attached on an IFL (Interface Logical) stacked over another IFL and the CoS configuration message is received on an FPC (Flexible PIC Concentrators) which does not host the IFLs IFD (Interface Device), then the FPC can crash because the FPC does not have any information about the IFLs or underlying IFDs.
1705353
Syslog "[Error] COS SCHED : Token mismatch during Q stats update" seen during config change or when subscriber sessions are going down.
Product-Group=junos
When a COS scheduling node (IFD/IFL/IFLSET) is being deleted due to config change or when subscriber sessions are going down, following log maybe seen sometimes right after commit: "[Error] COS SCHED : Token mismatch during Q stats update." The log will further have the following string: "Expected token:18446744073709551615 or rmngToken:18446744073709551615" Issue applicable for MPC10, MPC11, LC9600, MX304.
PR Number
Synopsis
Category: ZT/YT pfe firewall software
1567313
The sub line cards (SLC) might reboot after loading the configured inline services and services along with dfwd filters
Product-Group=junos
In an external server-based Junos Node Slicing scenario, the logical partitions (called sub line cards or SLCs) can be additionally configured for MX2K-MPC11E and assigned to different guest network functions (GNFs). If the inline services and services are applied to SLCs, some issues might happen during processing these services along with firewall process (dfwd) filter actions. Then it might cause SLCs to reboot and aftd crash.
1626115
Traffic drop might be seen in node slicing scenario
Product-Group=junos
On MX platforms that use MPC11E cards, when fast-lookup-filter is enabled, traffic drop might be seen in the node slicing scenario.
1687862
The FPC crash is observed with a "flexible-match-mask" condition
Product-Group=junos
On MX platforms with specific line cards, the Flexible PIC Concentrator (FPC) crash could be observed while configuring the firewall filter with a "flexible-match-mask" condition. However, If the FPC crash is not triggered, then the filter might not be working as expected.
1692070
The firewall bridge filter policers (attached to AE interface) are not working on all Junos MX platform with MPC10 card upon deactivate-activate a term intended to limit overall traffic
Product-Group=junos
Traffic policing will not work as expected on all Junos MX platform with MPC10 card after doing deactivation-activation of the term intended to limit overall traffic when the firewall and policers are applied to the bridge unit using shared-bandwidth-policers on AE (Aggregated Ethernet) interface.
1701320
Traffic loss is seen on MPC10E due to null pointer access without any safe check
Product-Group=junos
On the Junos MX series platforms with MPC10/11, when the line card is inserted, it restarts and traffic loss is seen generating the core dump due to the null pointer access without any safe check.
PR Number
Synopsis
Category: ZT/YTpfe bridging, learning, stp, oam, irb software
1700321
VLAN tags are imposed incorrectly when traffic is routed over IRB going out of the access interface
Product-Group=junos
On MX platforms, traffic egressing on the IRB (Integrated Routing and Bridging) interface with the underlying L2 (layer2) access port has VLAN tags imposed incorrectly.
PR Number
Synopsis
Category: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1681533
The line card gets crashed during node/interface statistics reporting with resource monitoring
Product-Group=junos
On MX platforms with specific line cards, the MPC may crash and generate core dumps in a corner case during node/interface statistics reporting scenario when resource monitoring is used.
PR Number
Synopsis
Category: Trio pfe qos software
1700860
The egress rewrite-rule might not work as expected for traffic entering the AE interface
Product-Group=junos
On all MX platforms, if the loss-priority is not explicitly configured on the AE (Aggregated Ethernet) interface, the default classifier is applied, but the loss-priority is not properly set at certain DSCP (Differentiated Services Code Point) code points and the rewrite does not execute as expected.
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1669478
Traffic drop observed with SP style configuration for the logical tunnel in layer2 domain
Product-Group=junos
On MX platforms, when the configuration for the logical tunnel in the layer2 domain is in the service provider style observing traffic drop for traffic over IRB (Integrated routing and bridging).
1670316
Layer 2 packets other than IPv4/IPv6 (e.g. CFM) will get forwarded as out of order via MPC10 and MPC11 in the egress direction
Product-Group=junos
On specific MX devices with MPC10 and MPC11 linecards, Layer 2 packets (i.e. other than IPv4/IPv6, e.g. CFM), may get forwarded as out of order in the egress direction. The issue is not seen for IPv4/IPv6/MPLS Encapsulated IPv4/MPLS Encapsulated IPv6 traffic/MPLS Encapsulated Ethernet+IP traffic.
PR Number
Synopsis
Category: Trio pfe l3 forwarding issues
1701147
FPC restart and core dump generated in MPLS scaled scenario with "always-mark-connection-protection-tlv" configured
Product-Group=junos
FPC restart and core dump generated in MPLS scaled scenario with "always-mark-connection-protection-tlv" configured.
PR Number
Synopsis
Category: Issues related to port-mirroring functionality on JUNOS
1683192
Traffic loss is seen with port-mirroring is enabled on AE interface in multicast downstream
Product-Group=junos
On MX and EX Platforms with Trio based MPCs, traffic loss is seen as multicast traffic will not be replicated to all downstream ports when port-mirroring is enabled on the AE (Aggregated Ethernet) interface with the destination port as another AE.
PR Number
Synopsis
Category: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1660931
Lockout-period might not work as expected
Product-Group=junos
Lockout-period might not work as expected and the user gets locked out.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1699245
The mgd process might crash during commit synchronize
Product-Group=junos
On all Junos OS and Evolved OS platforms with dual RE (Routing Engine) during commit script synchronize, backup RE mgd get crash once the memory leak reaches to 65K due to which commit configuration will fail which are performed through Master RE.
PR Number
Synopsis
Category: Issues related to all UI tools (mgd-bsd/cli-bsd, XML and DMI
1681656
System uptime display is shown in minutes instead of seconds
Product-Group=junos
On all Junos and Junos Evolved platforms, after the device reboot, show system uptime command is showing time in minutes instead of seconds for 24 hours.
PR Number
Synopsis
Category: For GPRS security features on highend SRX series
1704472
GTPv2 Message Filtering is not working
Product-Group=junos
GTPv2 Message Filtering not working - resolved
PR Number
Synopsis
Category: VMHOST platforms software
1646339
The alarm might not be generated for EDAC errors until the FPC is rebooted
Product-Group=junos
On all MX and PTX platforms, EDAC errors are triggered but alarms are not observed until the FPC gets rebooted due to the data corruption in hardware.
PR Number
Synopsis
Category: Virtual Router Redundancy Protocol
1680178
VRRP master-master condition might occur when there are more than two devices in the VRRP group
Product-Group=junos
When more than two devices are part of the VRRP group and a lower priority master sends a keepalive as master, low priority backup may transition to master state and get stuck.
PR Number
Synopsis
Category: VSRX platform software
1680874
vSRX instance in GCP gets stuck in halt state randomly when trying to reboot multiple times
Product-Group=junos
vSRX instance in GCP (Google Cloud Platform) freezes during restart and does not shutdown. This issue is very difficult to hit in production as it is seen very rarely after several reboots.
PR Number
Synopsis
Category: usf nat related issues
1692525
ALG child session will not be transported through the DS-Lite tunnel which might lead to traffic failures in absence of a direct route to the host
Product-Group=junos
On Junos MX240/MX480/MX960 platform with MX-SPC3, a tunnel ID of the control session is not updated properly on the gate created for Session Initiation Protocol (SIP) Application Layer Gateway (ALG), which is leading to the gate hit session not mapping back to the Dual-Stack Lite (DS-Lite) tunnel. This might result in traffic failure if the client does not have a direct route to the host.
21.2R3-S4 - List of Known issues
See -
https://supportportal.juniper.net/s/article/Junos-21-2R3-S4-list-of-Known-Issues
Modification History
First publication 2023-02-03
21.2R3-S4: Software Release Notification for JUNOS Software