Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX PTX QFX MX NFX SRX vSRX

Alert Description


Junos Software Service Release version 21.3R3-S4 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.3R3-S4 is now available.

21.3R3-S4 - List of Fixed issues 

PR NumberSynopsisCategory: EX4300 PFE
1697685Gratuitous ARP reply will not update the ARP cache
Product-Group=junos
On EX4300 platforms, the ARP (Address Resolution Protocol) cache will not be updated upon receiving the Gratuitous ARP reply even with "gratuitous-arp-reply" configured.
PR NumberSynopsisCategory: EX4300 Platform
1678506The interface on the device will go down when one or more interfaces are connected to the Advantech3260 device at another end
Product-Group=junosvae
On EX4300 platforms with version 19.1R3 and above, the interface on the device will go down when the device is connected to the Advantech3260 device at the other end. It will have a traffic impact.
PR NumberSynopsisCategory: EX4300 Filters implementation
1699777TCAM space might be exhausted when learning DHCP snooping entries on a trusted port
Product-Group=junos
On EX, QFX5k, and MX platforms having persistent binding for DHCP (Dynamic Host Configuration Protocol) snooping configured might cause TCAM (Ternary Content Addressable Memory) space exhaustion for DHCP snooping learning on the trusted port after the device reboot.
PR NumberSynopsisCategory: EX2300/3400 PFE
1695771Traffic loss is seen when a MAC moves from dot1x port to non-dot1x port
Product-Group=junos
On all Junos and Junos OS Evolved platforms is having dot1x enabled interface. When two or more MAC addresses are learnt on a dot1x port, and if one of them is shifted to a non-dot1x port, the MAC address that was moved is still seen as a MAC-based VLAN entry on the Layer2 Address Learning Manager (l2alm). This could lead to network traffic being lost.
1706845Layer 3 forwarding issues for IRB
Product-Group=junos
On EX2300, EX3400, EX4400, EX4100 and EX4300-MP platforms, when master FPC with mac-persistence-timer configured on a virtual chassis switch is halted, it leads to layer 3 (l3) forwarding issues for the integrated routing and bridging (IRB).
PR NumberSynopsisCategory: PR category for Talus FPGA
1706756TX would be stuck and no packet can be transferred by the SPC3 card
Product-Group=junos
On SRX5400, SRX5600, and SRX5800 platforms, TX(transmit) would be stuck and no packet can be transferred by the SPC3 card.
PR NumberSynopsisCategory: ChassisD changes specific for ACX series
1717105SNMP MIB OID output showing wrong temperature value if device running under negative temperature
Product-Group=junos
On all Junos platforms, devices may display wrong temperature values when executing commands. The temperature value is processed as positive integers but not negative integers. Hence, the negative temperature value is showing the wrong value.
PR NumberSynopsisCategory: JUNOS kernel/ukernel changes for ACX
1713699The member interface will not be added to the AE bundle if the link-speed of the AE interface doesn't match that of the member
Product-Group=junos
On Junos ACX5048 and ACX5096 platforms, if the link-speed is configured under the aggregated-ether-options hierarchy of the Aggregated Ethernet (AE) interface and the link-speed value does not match with the member link-speed, the member interface will not be added to the AE bundle.
PR NumberSynopsisCategory: australia related kernel issue
1714002vmcores can be seen on SRX5k platforms when the fxp0 interface is configured under management-instance
Product-Group=junos
On Junos SRX5K series platforms, when the 'set system management-instance' command is committed on the secondary node, continuous VMcores are observed on the secondary node leading to the kernel crash. The secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until management-instance knob is removed using "delete system management-instance".
PR NumberSynopsisCategory: Border Gateway Protocol
1635390BGP routes might be left stale on the router
Product-Group=junos
On all Junos and Junos Evolved platforms, if the BGP peer goes down, and the very last route in the list is marked as a high priority, BGP might assume no more routes to delete, causing routes to be stale.
1695062Traffic blackholing is observed when removing the BGP routes take a long time to get removed from RIB
Product-Group=junos
On Junos platforms, if a BGP (Border Gateway Protocol) peer is going down and stays down and the system might take an extremely long time to complete removing the BGP routes. The issue observed when a BGP peer sends many routes, only a small amount of routes are selected as the active routes in the RIB (Routing Information Base), and if the BGP delete job gets only a small part of the CPU time as other work in the routing process utilize the CPU.
PR NumberSynopsisCategory: BBE Remote Access Server
1697392A few subscriber sessions will not be up post RE switchover
Product-Group=junos
On MX platforms, in a high scale subscriber scenario with close to 100% address pool utilization, when the session table and the IP pool database are out of sync and a switchover is performed, authd assigns an in-used IP address to the new subscriber session. This issue doesn't have an impact on existing subscribers but is not able to keep the new sessions up.
1710145High CPU utilization is seen on Junos MX series platforms
Product-Group=junos
This issue is seen on Junos MX series platforms that support authd process. when authd traces are enabled in scale setup with 10k+ routing instances, authd will keep generating some logs. These logs consumes CPU cycles and makes authd process to utilize 100% CPU.
PR NumberSynopsisCategory: Virtual-chassis platform/chassisd infrastructure PRs for MX
1706268FPC offline can be seen on MX-VC during the sequential upgrade
Product-Group=junos
On Junos MX-VC (Virtual Chassis), CCL (Chassis Control Link), and CRC (Cyclic Redundancy Check) errors can be seen after FPC (Flexible PIC Concentrator) detach during the sequential OS (Operating System) upgrade of MX-VC system. The CCL and CRC errors are expected after the FPC detaches and eventually, the FPC is marked offline by the MX-VC and there is an unexpected chassisd process restart. The chassisd restarted because of the connection failure between LCC (Linecard Chassis Control) chassisd and SCC (Switch Chassis Control) chassisd which is triggered by the sequence of messages exchanged between the LCC and SCC after the FPC detach event. There will be a traffic impact as the FPC will be offline, and the system recovers to a working state by itself.
PR NumberSynopsisCategory: Class of Service
1702836Control packets would be dropped when CoS configuration under AE wildcard IFLs gets applied to AE control IFLs as well
Product-Group=junos
On MX platforms, when Aggregated Ethernet (AE) working in hierarchical-scheduler or per-unit-scheduler mode and AE class of service (CoS) configuration having wildcard on AE Logical Interface (IFLs) is committed in a single commit with AE interface flap, then the wildcard configuration gets applied to AE control IFL also. Ideally, any wildcard CoS configuration should not get attached to control IFLs. Only explicit configurations should be attached to control IFLs. This can lead to unintentional behavior.
PR NumberSynopsisCategory: Device Configuration Daemon
1682271Node Slicing: In a rare scenario, the FPC/SLC will get stuck in the ready state after a restart
Product-Group=junos
On Junos MX platforms, in a rare scenario, FPC/SLC (Flexible PIC Concentrator/Sub Line Card) may get stuck in the ready state after restarting it and the error message of 'Device busy' will be observed in Syslog.
1695663The Unicast traffic is dropped on QFX5100/EX46xx-VC platforms
Product-Group=junosvae
On QFX5100/EX46xx Junos platforms configured with Virtual Chassis(VC), if a master member is unplugged or forced to power off, the unicast traffic is dropped due to mac-persistence-timer expiry there is a difference in mac addresses between logical aggregated parent interface and member aggregated ethernet(ae) interface.
PR NumberSynopsisCategory: CoS support on DNX
1703840CoS rewrite rules will not work in L3VPN scenario
Product-Group=junos
On Junos OS ACX710/ACX5448 platforms, in Layer 3 Virtual Private Network (L3VPN) scenario, Class of Service (CoS) Experimental (EXP) rewrite rules configuration will not take effect. Thus CoS remarking will not work properly leading to the wrong remarking on Multiprotocol Label Switching (MPLS) packets.
PR NumberSynopsisCategory: VPWS, L2 CKT, EVPN-VPWS
1683900ACX5448:ACX710 L2Circuit traffic drop with control-word enabled or control-word config change.
Product-Group=junos
ACX5448:ACX710 L2Circuit traffic drop with control-word enabled or control-word config change.
PR NumberSynopsisCategory: ACX LAG infrastructure
1714111The traffic through the AE member link will be dropped
Product-Group=junos
On ACX5448 and ACX710 platforms, when the Aggregate Ethernet (AE) interface is configured with tagging-mode (e.g flexible-vlan-tagging) but without any encapsulation and the member port is added to the AE interface after service creation, then the ingress traffic through the member port will be dropped as it was not yet part of the AE interface.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1683312'clear interfaces statistics all' taking more than 9 min due to invalid PIC configuration inside GNF.
Product-Group=junos
Invalid PIC configuration inside GNF may add delay to 'clear interface statistic all' command. This issue does not impact any functionality. chassis fpc pic 
1695510MPC11E goes offline with "fpc-slice" configured
Product-Group=junos
On MX2020 platforms with MPC11E in the Junos Node Slicing environment, when "fpc-slice" is configured results in MPC11E going offline.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1703226The l2ld process will crash when an IFL is changed to trunk mode and a new VLAN is added
Product-Group=junos
On all Junos Evolved platforms, the Layer 2 address learning daemon (l2ald) process will crash when there is a scaled configuration to commit and a Logical Interface (IFL) mode is changed from access to the trunk and a new Virtual Local Area Network (VLAN) is added to the IFL in a single commit. This issue will impact new MAC learning until the l2ald process recovers.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1662954In EVPN-MPLS Mutihoming scenario DF election will get stuck in the Preference based state
Product-Group=junos
On all Junos and Junos Evolved platforms supporting preference-based DF (Designated Forwarder) election in EVPN-MPLS Multihoming scenario, the DF election will be stuck in the Preference based state if there will be a change in the df-election on the fly.
1702016ARP/ND doesn't resolve when extended-vlan-list is configured for the specific VLAN
Product-Group=junos
On all Junos & Junos Evolved platforms, ARP(Address resolution protocol)/ND(Neighbour discovery) doesn't resolve when extended-vlan-list is configured for the specific VLAN(virtual local area network).
PR NumberSynopsisCategory: EX4400 PFE software
1701546The BFD session will remain in init/down state in the Virtual Chassis scenario
Product-Group=junos
On Junos EX and QFX Virtual Chassis platforms configured with Bidirectional Forwarding Detection (BFD) over the Aggregate Ethernet (AE) interface, when the BFD control plane traffic is received on the lag member port which is present as non-anchor FPC of the BFD session, the BFD session will be stuck in the Init/down state. Only single-hop BFD sessions will be impacted.
1704470Traffic drops observed with hierarchal overlay ECMP configuration
Product-Group=junos
On EX4400 platforms in the EVPN-VXLAN environment, the overlay ECMP (equal-cost multipath) route does not get programmed in hardware resulting in traffic drops when hierarchal overlay ECMP is configured.
PR NumberSynopsisCategory: EX Entry Level Access VC platform
1704457The PXE BIOS recovery fails on EX9204/9208/9214 VC setup
Product-Group=junos
On EX9204/9208/9214 platforms configured in a Virtual Chassis(VC) setup, if the SSD(solid-state drive) local disk is erased or there is a hardware failure for EX9200-40XS FPC, the EX9200-40XS recovery will fail if performed through the PXE(Preboot Execution Environment) and stuck in a boot loop.
PR NumberSynopsisCategory: Express PFE MPLS Features
1712076FPC memory leak will cause FPC crash
Product-Group=junos
On PTX and QFX10K platforms, enabling the collection of LSP (label-switched path) statistics for telemetry data using the CLI command 'set protocols mpls sensor-based-stats' will cause FPC (Flexible Physical Interface Cards (PIC) Concentrators) memory leak and a huge leak may result in FPC crash.
PR NumberSynopsisCategory: SRX1500 platform software
1656738The fxp0 interface might remain 'UP' when the cable is disconnected
Product-Group=junosvae
On specific SRX platforms, the fxp0 interface might remain up even when the cable is disconnected.
PR NumberSynopsisCategory: Express ASIC platform
1683562On PTX5000 platforms when a command is issued to power off an FPC, it gets stuck in the 'Announce Offline' state
Product-Group=junos
When an FPC (Flexible PIC Concentrator) on PTX5000 platforms is shut down by issuing a request command (request chassis offline slot ) or by FPC power off configuration (set chassis fpc x power off), it gets stuck in the 'Announce Offline' state since the associated timer (fru_graceful_offline_timer) doesn't increment and expire as it is supposed to.
PR NumberSynopsisCategory: idp flow creation, deletion, notification, session mgr intfce
1705491Network outage caused during change in IDP policy
Product-Group=junos
Junos SRX platforms experience traffic outage during change in IDP (Intrusion Detection and Prevention) policy.
PR NumberSynopsisCategory: MX Inline Jflow
1708485The Inline Flow Monitoring is not working on Junos MX-VC platforms
Product-Group=junos
In a Virtual-chassis (VC) scenario on Junos MX platforms installed with MPC7E Flexible PIC Concentrators (FPC), if the inline-jflow Sampling is enabled, the Inline Flow Monitoring will not work as data is not getting exported to the collector.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1610540QFX5200 mib OID ifOutDiscards misbehaving and returning value 0 which is not expected
Product-Group=junos
ifOutDiscards(Output Error Drops) returning value 0 for AE interface intermittently. Issue is observed when we receive both SYNC and ASYNC request at the same time for AE member link interface. SYNC request from mib2d(since ASYNC is not supported by QFX for AE) and ASYNC request is from sflowd. Before post-processing completes for the pending SYNC request if ASYNC request is created, ASYNC q_counters is taken for stats calculation and it results in 0.
1649958The user-defined speed does not take effect on the AE interface in certain scenarios on Junos platforms
Product-Group=junos
On Junos platforms supporting GRES (Graceful Routing Engine Switchover), the bandwidth flag on the backup RE (Routing Engine) for the AE interfaces is set unconditionally, hence the bandwidth is struck at a value despite not being set by the user statically. When GRES is performed followed by link delete/add for the AE interface, the interface would get stuck with the bandwidth and gets synced with the backup RE. There can be seen partial service impact in the case of the RSVP (Resource Reservation Protocol) and the restoration to recover from this issue is to configure bandwidth manually and then remove the configuration.
1671135RE reboot can be seen when PPPoE subscribers login
Product-Group=junos
On all Junos platforms supporting PPPoE (Point-to-Point Protocol over Ethernet) the RE (Routing Engine) can reboot with a 'vmcore' generated during the PPPoE subscriber login. This issue can be triggered when the system has demux (demultiplexing) interface configuration and static VXLAN (Virtual Extensible Local Area Network) is configured at BD (Bridge-Domain). There will be a traffic impact because of the RE reboot but the system reverts to a functioning state without manual intervention.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1685406The protocol MTU for the IRB interface is not rolled back when the MTU of the IRB or IFD interfaces is modified or deleted
Product-Group=junos
On all Junos platforms, the maximum transmission unit (MTU) on the Integrated Routing and Bridging (IRB) interface is not getting reset when the MTU configuration on IRB or IFD is removed. When MTU configuration is removed from the IRB interface, the internal data structure for the MTU configuration is not getting reset which might affect traffic and it is a rare case.
PR NumberSynopsisCategory: ISIS routing protocol
1696598Wrong SRTE Secondary path weight makes the secondary path active in forwarding table
Product-Group=junos
On all Junos and Junos Evolved platforms, SRTE (Segment Routing Traffic Engineering) Secondary LSP (Label Switched Path) should be only on standby in the forwarding table however it is also active and forwarding traffic due to the wrong metric calculation.
PR NumberSynopsisCategory: jdhcpd daemon
1698798A dcd process crash is observed continuously when the dhcp-service is restarted
Product-Group=junos
On MX platforms that support Broadband Edge (BBE) functionality, the dcd crash continuously occurs when the subscribers are logged in using the DHCP dynamic profile and dhcp-service is restarted having the configuration like "set chassis network-services enhanced-ip" enabled.
1713619A jdhcpd process crash is observed on all Junos platforms
Product-Group=junos
On all Junos platforms with DHCP (Dynamic Host Configuration Protocol) relay/server/client configured, a jdhcpd process crash is observed when FPC (Flexible PIC Concentrator) is restarted or rebooted and the DHCP functionality could be impacted.
1714260The DHCPv4 relay will send two option-82 to the server and the DHCP session will not be established
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when Dynamic Host Configuration Protocol (DHCPv4) Relay is configured with forward-only mode along with "trust-option-82", DHCP-relay should not add another option 82 to the packet sent to the DHCP server. The DHCP server upon receiving the packet with two option-82 will respond only with 1st header of option-82 which might get dropped by the relay, thus the packet is not forwarded to the DHCP client and the DHCP session won't get established.
PR NumberSynopsisCategory: Flow Module
1699578Application traffic drop seen on all SRX platforms due to TCP window size issue
Product-Group=junos
On all SRX platforms, on rare occasions, after the SYN-ACK is established with the application server, the server will cause the TCP window size drop to zero after declaring a larger initial TCP window in the ACK packet. Though this is not prohibited but generally not expected behavior. Due to this, the packet will be dropped for that particular session.
1705996A flowd process crash is seen on SRX4100/4200/4600, vSRX, and SRX5K with SPC3 card when a route is changed frequently
Product-Group=junos
In a race condition, when PMI (power-mode-ipsec) is enabled and routes are changing frequently (3~5sec) on SRX4100/4200/4600, vSRX, and SRX5K with SPC3 card, a flowd process crash will be seen.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1678772New secondary node to go into a disabled state after ISSU and failover RG0 because of fabric link failure
Product-Group=junos
On SRX5K platforms with SPC3 card, the primary node will lose the backup node and fabric link failure is observed resulting in the new secondary node going into a disabled state after ISSU (In-Service Software Upgrade) and failover RG0 (redundancy group) in a chassis cluster environment.
1686648Policy configured with condition route-active-on import is not working properly after RG0 failover
Product-Group=junos
In a specific scenario, condition route-active-on import is not working properly after RG0 failover.
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1631149SRX5600/5800 - SNMP mib queries may result in occasional response timeouts
Product-Group=junos
SRX5600/5800 - SNMP MIB queries for jnxJsSPUMonitoringMIB objects (1.3.6.1.4.1.2636.3.39.1.12.1.x) may result in occasional response timeouts
1708777Setting the security log profile without a category or stream will lead to srxpfe process crash
Product-Group=junos
On all Junos SRX platforms, when security log profile is added without a category or stream can cause the srxpfe to crash. Due to this there will be complete traffic loss.
PR NumberSynopsisCategory: Firewall Policy
1698508Security policies go out of sync during ISSU
Product-Group=junos
On all Junos platforms, policies go out of sync between RE (Routing Engine) and PFE (Packet Forwarding Engine) after performing ISSU (In-service software upgrade) leading to the wrong policy lookup.
PR NumberSynopsisCategory: Security platform jweb support
1712454[Jweb] "address-book attach zone" is unexpectedly removed when address-book entry is added or removed by Jweb
Product-Group=junos
On SRX platform series, when address-book entry is added or removed by Jweb, "address-book attach zone" might be unexpectedly removed at configuration commit.
PR NumberSynopsisCategory: Layer 2 VPN related issues
1654516Routes flapping when configuration changes are applied to custom routing instance
Product-Group=junos
Routes flapping when configuration changes are applied to a custom routing instance.
PR NumberSynopsisCategory: Layer 2 Control Module
1717267Traffic loop is seen due to incorrect root bridge ID
Product-Group=junos
On all Junos and Junos Evolved platforms, in VSTP (Virtual Spanning-Tree Protocol) topology, whenever a new vlan is added in between previously configured vlan group followed by configuring the system-identifier, the bridge priority will change for existing vlans which might give incorrect system ID or bridge ID creating a traffic loop.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1716270mac-move-limit : MMAS flag not getting reset after interface recovers due to l2-learning restart
Product-Group=junos
MMAS Flag will not be displayed for interface after it recovers due to l2-learning process restart
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1686654Subscribers are not able to connect to the device after the device reboot
Product-Group=junos
Due to a rare timing issue all subscribers may fail to connect and get suck in init state after reboot of MX broadband network gateway (BNG).
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1711422A dot1xd crash is seen on Junos EX2300 platforms
Product-Group=junos
On Junos EX2300, if the Master Session Key (MSK) parameters are received from RADIUS (Remote Authentication Dial-In User Service) as part of authentication, a dot1xd crash could be observed which will impact the authentication on the dot1x enabled ports.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1655031The rpd core is seen due to IGP database and BGP LS database out of sync
Product-Group=junos
On all Junos and Junos OS Evolved platforms, rpd core is hit when the events for deleting prefixes, sids, links and nodes come in out of order which occasionally leads to IGP database and BGP LS database out of sync.
1701420The rpd core and traffic loss is observed on Junos and Junos Evolved platforms
Product-Group=junos
On Junos and Junos OS platforms, if an LSP (Label-Switched-Path) is configured and delegated to an external controller is disabled (not deleted from configuration), and then a rpd restart or RE (Routing Engine) switchover takes place, the rpd process crashes and generates core resulting in traffic loss.
PR NumberSynopsisCategory: MX Timing software
1696957In the rare scenario, huge PTP Time errors are introduced and propagated to the downstream devices after the chassis reboot
Product-Group=junos
On MX240, MX480, MX960, MX2010, and MX2020 platforms, the remote PTP (Precision Time Protocol) clock will recover the PTP clock with Time errors after a chassis reboot on the device running as Boundary Clock.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1642287Kernel crash is seen on the device if the device is continuously power cycled
Product-Group=junos
This issue is applicable to EX3400/EX2300/EX4100. There is a possibility of kernel crash when the system will be in the process of coming up after reboot (and observed only with multiple iterations of continuous reboot cycles). This is observed only during the init sequence of the management driver and impact is limited to increased system boot time.
1700629The command "request system zeroize" might not work properly on EX4400.
Product-Group=junos
When issuing the "request system zeroize" command, an error message might be seen.
1704032VM process crashes if a file is shared between the host operating system and the guest operating system using virtFS
Product-Group=junos
On Virtual Machines (VM) based platforms running Junos images, files are not shared between the host operating system and guest operating system via Virtual Filesystem (virtFS). When this issue happens, the device will be restarted.
1717710Unable to take recovery snapshots after USB upgrade is performed on ACX710
Product-Group=junos
On ACX710 platform, the OAM (Operations, Administration and Maintenance) volume seems unpopulated when an upgrade is performed with USB (Universal Serial Bus) drive or zeroize media. This leads to failure in taking recovery snapshots.
PR NumberSynopsisCategory: OSPF routing protocol
1705975OSPF routes are not getting installed after the interface is flapped
Product-Group=junos
On all Junos and Junos Evolved platforms, the OSPF (Open Shortest Path First) routes are not getting installed when the interface is flapped multiple times. A deadlock is created when the OSPF routers wait for an LSA (Link State Advertisement) with a P2P (Point-to-Point) link to be advertised from its neighbouring router to add it to its router LSA and at the same time the neighbouring router also waits for an LSA with a P2P link to be advertised to add it to its router LSA. Both the OSPF routers advertise their router LSA without a P2P link and as a result, routes are not getting installed.
PR NumberSynopsisCategory: Express Chip L3 software
1658317BFD session session-state is showing DOWN while checking Micro BFD Sessions with Authentication in Non-Distributed Mode
Product-Group=junos
BFD session session-state is showing DOWN when operating in centralized Mode. Packet loss may be seen.
PR NumberSynopsisCategory: Issues related to PKI daemon
1669426Gradually increasing jsd memory usage will lead to jsd process crash
Product-Group=junos
On all platforms supporting PKI (Public Key Infrastructure) and JTI (Juniper Extension Toolkit), gradually increasing jsd (Juniper Extension Toolkit (JET) service process) memory usage will lead to a jsd crash. It will restart automatically.
PR NumberSynopsisCategory: QFX access control list
1679574Firewall functions will not work as expected when egress firewall filter is configured
Product-Group=junos
On QFX5K/EX4400/EX4650 platforms, Egress firewall filter will not work as expected. There is no impact to traffic, but firewall functions will not work.
1695820On QFX5110-VC-VCF platforms, traffic impact is seen when the firewall filter with DSCP action is enabled
Product-Group=junos
On QFX5100-VC-VCF (Virtual-Chassis Fabric) when the firewall filter with action DSCP (Differentiated Services Code Point) is configured and is applied to any interface, the commit check gives a warning on FPC2 (Flexible PIC Concentrators) if the master has member id 0 and traffic drop can be seen.
1710776The message "fpc0 list_get_head, list has bad magic (0x0)" maybe output after the commit operation is complete
Product-Group=junos
When a VACL filter is added or deleted, the message "fpc0 list_get_head, list has bad magic (0x0)" maybe output.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1695847Traffic forwarding fails when deleting all L2 related configurations
Product-Group=junos
On QFX and EX series platforms, traffic loss will be observed for deleting all Layer2 related configurations when both L2 and Layer3 configurations are present.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1712405VXLAN traffic gets dropped after new L3 VLANs are created
Product-Group=junos
Traffic black-holing in EVPN (Ethernet VPN) fabric when performing configuration of new VLANs, it is found that L3 VLANs are having IPV4 bits disabled.
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1679919PFE process crash might be observed on QFX5100 platforms
Product-Group=junosvae
On QFX5100 platforms (both stand-alone and VC scenario) running Junos, occasionally during the normal operation of the device, PFE (Packet Forwarding Engine) can crash resulting in total loss of traffic. The PFE reboots itself following the crash.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1660532The port LEDs do not light up when 40G/100G physical interfaces are up.
Product-Group=junosvae
The port LEDs do not light up when 40G/100G physical interfaces are up. This is a display issue. There is no service impact when this issue occurs.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1696119Traffic drop is observed for the VCP ports when there is traffic congestion in the egress queues
Product-Group=junos
On QFX5110 with Virtual Chassis configured, if any of the egress queues 3 or 4 is congested it causes buffer stuck error messages and traffic drop on the VCP (Virtual Chassis port) ports.
1709938VC members are split when removing and inserting em0 cable
Product-Group=junosvae
On QFX5120-48YM, QFX5120-48Y-8C, QFX5120-32C and EX4650-48Y platforms, when the management em0 cable is removed and reinserted in the Virtual Chassis (VC) environment, the VC members will split into separate VCs. The VC members will remain in the split state for approximately 5 mins.
1710855The FPC will be offline after upgrading the system
Product-Group=junosvae
On the Junos QFX5100 platform, after upgrading the system to the affected TVP/5e releases the PFE (Packet forwarding Engine) will crash continuously and Flexible PIC Concentrators (FPC) will remain down. TVP/5e Junos only needed if mixed VC of QFX5100 & QFX5110 need to form
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover, 
1701146The rpd crash will be observed when any commit is performed
Product-Group=junos
On all Junos and Evolved platforms with RSVP auto-mesh dynamic tunnel configuration, whenever a commit is done the rpd (Routing Process Daemon) crash will be seen. This happens due to null pointer access in the memory.
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1699115Transit tunnels fails and remains down on all Junos based MX and SRX platform with IKE-NAT-ALG enabled
Product-Group=junos
On all Junos based MX and SRX platforms, the transit tunnels are not getting established and remained down due to a 10240 IKE (Internet Key Exchange) cookie limitation on MX-SPC3 and 10240 cookie limitation on the SRX platform. IKE tunnel sessions are getting dropped on the device and caused a traffic impact.
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1701305On Junos platforms with MS-MPC cards the IKE ALG inactivity timeout value stays fixed
Product-Group=junos
On Junos platforms having MS-MPC (Multi-Service Modular PIC Concentrator), the value for the inactivity timeout for IKE (Internet Key Exchange) ALG (Application Level gateway) is automatically set to 14400 seconds even though a custom timeout value is configured by the customer. This issue is seen only in the case of IKEv1 having SFW (Stateful Firewall) without any NAT (Network Address Translation) configuration. When this issue is seen IKE transit tunnel sessions remain in the session table longer than expected, not honoring the configured timeout value. This issue is self-recoverable.
1713725IPv6 Fragmentation is not working on MS-MPC/MS-MIC in DS-Lite scenario
Product-Group=junos
On all Junos MX platforms with MS-MPC/MS-MIC cards in DS-Lite(Dual-stack Lite) scenario , Address Family Transition Router (AFTR) always failed to fragment newly generated IPV6 packet that has packet size larger than mtu-v6 value. packet will be dropped and will not reach to the softwire initiator (B4)
PR NumberSynopsisCategory: All Asgard Platform Related Issues
1335526The ppmd process might crash after an upgrade on SRX platforms
Product-Group=junos
On SRX platforms with Bidirectional Forwarding Detection (BFD) enabled for multiple protocols (such as OSPF, ISIS, BGP, PIM), the ppmd process might crash after an upgrade.
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1701183Traffic loss is seen due to interface flap when changing speed from 10G and 1G
Product-Group=junos
On Junos MX204/MX10003, traffic loss is seen on 4x10G Channelized interfaces when the speed is changed from 10G to 1G on one lane which causes the other 3 lanes to flap and stay down.
PR NumberSynopsisCategory: SRX-1RU platfom chassisd SW defects
1711467SRX4600 doesn't support ae interfaces
Product-Group=junos
On Junos SRX4600 platforms, ae interfaces doesn't come up or not work properly when configured in HA (High Availability) cluster mode.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1683213SRX4600HA might not failover properly due to a hardware failure
Product-Group=junosvae
In SRX4600 platform, there is a possibility of raising alarm function might not work in FPGA failure. It might affect device availability.
1712727Continuous vmcores observed on the secondary node when committing set system management-instance command
Product-Group=junos
On Junos SRX4600 device, when the "set system management-instance" command is synced to the secondary node, continuous VMcores are observed on primary and secondary nodes. The secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until management-instance knob is removed using "delete system management-instance"
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1704129Traffic is blocked on a queue when enhanced priority mode is configured
Product-Group=junos
On MPC1-9, JNP10K-LC2101, JNP10003-LC2103, JNP10K-LC480 line cards, with scheduler map configuration change in enhanced priority mode, traffic is blocked on a queue.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1692070The firewall bridge filter policers (attached to AE interface) are not working on all Junos MX platform with MPC10 card upon deactivate-activate a term intended to limit overall traffic
Product-Group=junos
Traffic policing will not work as expected on all Junos MX platform with MPC10 card after doing deactivation-activation of the term intended to limit overall traffic when the firewall and policers are applied to the bridge unit using shared-bandwidth-policers on AE (Aggregated Ethernet) interface.
1697404FPC crash will be observed when firewall filter is unconfigured and reconfigured with same index
Product-Group=junos
On Junos platforms with MPC10E/MPC11E/LC-9600 cards, Flexible PIC Concentrators (FPC) crash will be seen when frequent ADD/DELETE operations of filter are performed.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1706446No network reachability when enabling the routing-service knob for PPPoE subscribers over AE
Product-Group=junos
On all Junos platforms configured with PPPoE subscribers, when the PPPoE (Point-to-Point Protocol over Ethernet) subscriber is configured on the AE (Aggregated Ethernet) interface while enabling the routing-service knob, the service will not get enabled and the subscriber traffic gets impacted.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1699245The mgd process might crash during commit synchronize
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines, during commit script synchronize, the backup Routing Engine mgd get process crashes once the memory leak reaches 65K. When this happens, commit configurations from the primary Routing Engine fail.
PR NumberSynopsisCategory: PTX/QFX100002/8/16 interface software
1712007The interface does not come up or keeps flapping
Product-Group=junos
On Junos PTX10008/PTX100016 devices with LC1101/LC1102 line cards, any event that causes an interface state change can lead to interface flapping or the interface may not come back at all. This leads to traffic impact on that interface.
PR NumberSynopsisCategory: For GPRS security features on highend SRX series
1704472GTPv2 Message Filtering is not working
Product-Group=junos
GTPv2 Message Filtering not working - resolved
PR NumberSynopsisCategory: VMHOST platforms software
1686825The pre-installed optional packages and JSUs will be lost after a VMHost rollback
Product-Group=junos
On VMHost based platforms, the pre-installed optional packages and Junos Selective Update (JSU) packages will be lost when a VMHost reboot is performed after VMHost rollback.
PR NumberSynopsisCategory: Xellent Platform issues
1709817Ports with QSA adapter are down
Product-Group=junos
On Junos PTX1000 and PTX10002-60C/QFX10002-60C platforms, ports which use the QSA (QSFP-to-SFP Adapter) may not come up when running software version containing the fix for PR 1620527.

 


 

21.3R3-S4 - List of Known issues 

PR NumberSynopsisCategory: EX4300 HA (GRES, NSR, NSB)
1665562EX4300-48MP: VC: NSSU aborted with Backup RE maybe in inconsistent state
Product-Group=junosvae
For NSSU to work fix should be present in the Base image. The issue started from 21.4R2 onwards. e.g If NSSU is done from 21.4 to 22.2 fix should be present in 21.4 image.

Resolved In: junos:20.4R3-S4 junos:21.3R3-S1 junos:21.4R3 junos:21.4R3-S4 junos:22.1R2 junos:22.1R3 junos:22.2R1 junos:22.2R2 junos:22.3R1 junos:22.4R1
PR NumberSynopsisCategory: EX-Series VC Infrastructure
1685067EX4600-VC - Master RE reboot and All-member reboot lead to PFE Manager hogging logs when SFP-T is plugged in
Product-Group=junos
On Junos EX4600 Virtual Chassis (VC), the master RE reboot and all-members reboot lead to the PFE Manager hogging logs when SFP-T pluggable is installed in. The PFE Manager hogging logs has no functionality impact (PR 1641556).

Resolved In: junos:20.2R3-S6 junos:21.4R3-S2
PR NumberSynopsisCategory: Anything related to Multicast
1461339Mcast traffic drops is observed with the following error message: brcm_rt_ip_mc_ipmc_install.
Product-Group=junos
Following two Failure messages seen brcm_rt_ip_mc_ipmc_install:2455 Failed (Invalid parameter:-4) This message is due to IPMC Group being used is not created, when RE tried to add this check indicates there is a parameter mis-match. brcm_rt_ip_mc_ipmc_install:2455 Failed (Internal error:-1) This message is due to Failure to read IPMC Table or any memory/register

Resolved In: 
PR NumberSynopsisCategory: BBE dynamic profile related issues
1714778Cleanup of a dynamic vlan may fail leaving it in active but unusable state if SDB was briefly unavailable
Product-Group=junos
In the rare scenario cleanup of a dynamic vlan session may fail if SDB (subscriber database) was briefly unavailable. Such dynamic vlan will stay in active state, but all subscriber connection attempts over this vlan will fail.

Resolved In: evo:22.3R3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:20.2R3-S4-J9 junos:21.2R3-S5 junos:21.4R3-S2-J9 junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: the SMGD redundancy plugin in SMGD
1718342In a DHCP ALQ subscriber scenario delete-binding-on-renegotiation knob does not work as expected due to a synchronization error between the primary and the backup routers
Product-Group=junos
On Junos platforms, active lease query (ALQ) synchronization between peers is not happening properly. Traffic forwarding impact would be observed if there was a switchover from the Primary to the Backup. The primary router will correctly delete-binding-on-renegotiation and create a new session, but the backup router keeps the old session and old MAC address. (DHCP overrides have delete-binding-on-renegotiation configured and work as expected on the primary router whereas no notification is sent to the backup to delete the session)

Resolved In: evo:22.3R3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:20.4R3-S7 junos:21.2R3-S5 junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Border Gateway Protocol
1689904BGP LU Advertisements fail with the message "BGP label allocation failure: Need a gateway"
Product-Group=junos
On all Junos and Junos Evolved platforms BGP-LU (Border Gateway Protocol Labeled-Unicast) Advertisements fail with the message "BGP label allocation failure: Need a gateway" based on timing conditions involving route resolution and installation.

Resolved In: evo:22.3R3-EVO evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:22.1R3-S2 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1712805The generation of the VXLAN table appears to be lost after loading configuration
Product-Group=junos
On all Junos and Juos OS Evolved platforms that have EVPN-VXLAN enabled, the generation of the VXLAN table and the message during the setup of the EVPN/VXLAN connection seems to get lost because of a timing issue between the layer2 address learning daemon(l2ald) and routing protocol daemon( rpd ) connections.

Resolved In: junos:21.2R3-S5 junos:21.4R3-S3 junos:22.1R3-S2 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Device Configuration Daemon
1679952After changing the settings related interface, a particular interface does not flap but a LAG interface may flap on all Junos platforms except MX
Product-Group=junos
The LAG (Link Aggregation Group) member links may flap on all Junos platforms except MX when the configuration of any interface is changed/modified. The flap is not seen always.

Resolved In: junos:21.4R3 junos:21.4R3-S4 junos:22.1R3 junos:22.1R3-S2 junos:22.2R2 junos:22.2R3 junos:22.3R1 junos:22.3R2 junos:22.4R1
1692404Incompatible/unsupported configuration is not getting validated correctly during ISSU/normal upgrade causing the traffic loss
Product-Group=junos
On all Junos platforms, while performing the Junos upgrade from the release before 20.4 to a higher version having an incorrect configuration may fail. This issue may lead to traffic loss or network outages.

Resolved In: junos:20.4R3-S7 junos:21.2R3-S5 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: Firewall Filter
1647669mib2d core hitting @mib2d_fwstats_async_handler_cb rtslib_async_process_msg during GRES testing with page pooling enabled
Product-Group=junos
mib2d core hitting @mib2d_fwstats_async_handler_cb rtslib_async_process_msg during GRES testing with page pooling enabled

Resolved In: evo:22.1R3-EVO evo:22.2R2-EVO evo:22.3R1-EVO junos:21.2R3-S3 junos:21.4R2-S2 junos:21.4R3 junos:22.1R3 junos:22.2R2 junos:22.3R1
PR NumberSynopsisCategory: VPWS, L2 CKT, EVPN-VPWS
1704044[ACX-All] ECMP LB/LS is not working with VPN traffic forwarding, when FRR path is live in egress
Product-Group=junos
In an ACX system, when we have FRR path & ECMP, we get disjoint nexthop members with different weights, under a single unilist in pfe.

Resolved In: 
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1712564Transit traffic drop is observed for the BGP-LU route prefixes with ECMP forwarding path on Junos ACX5448/ACX710 platforms
Product-Group=junos
On Junos ACX5448/ACX710 platforms, if the BGP-LU route prefixes points towards the ECMP forwarding path, the transit traffic drop is observed for the BGP-LU routes, due to the incorrect programming for the routes.

Resolved In: junos:22.1R3-S2 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: EX4400 platform
1696444A serial number of SFP is not shown in "show chassis hardware" on EX4400.
Product-Group=junos
When a sfp is unplugged or plugged in, it may not be recognized.

Resolved In: junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R2-S1 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Express PFE MPLS Features
1645488Junos ACX/PTX/QFX platforms might silently discard packets after an interface flaps
Product-Group=junos
On certain ACX Series, PTX Series, or QFX Series devices running Junos OS, the device might silently discard packets when the backoff time is set on port or with congestion during link down and up events. There will be a service impact because of the traffic drops. As restoration, the egress Flexible PIC Concentrator (FPC) needs to be rebooted.

Resolved In: junos:18.2X75-D67 junos:20.3X75-D35 junos:20.3X75-D50 junos:21.4R3 junos:22.1R3 junos:22.2R2 junos:22.3R1 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: FIPS related issues
1623128The device will be unavailable while performing FIPS 140-2/FIPS 140-3 level 2 internal test on FreeBSD 12 based Junos platforms
Product-Group=junos
When Federal Information Processing Standards (FIPS) 140-2/140-3 defines security level 2 is enabled on the FreeBSD 12 based Junos platforms, the series of known answer test (KAT) self-tests will be performed automatically and stuck in kernel_kats test due to unsupported FIPS features, then the device will be unreachable or will be rebooted again and again, there is no impact to the customer since some FIPS 140-2/140-3 level2 features do not apply to FreeBSD 12 officially.

Resolved In: evo:21.4R2-EVO evo:22.1R1-EVO evo:22.2R1-EVO junos:21.4R2 junos:22.1R1 junos:22.2R1
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1626562A major alarm DPDK (data plane development kit) Tx stuck issue of SRX4100/4200
Product-Group=junosvae
On the SRX4100 and SRX4200 platforms, it can detect DPDK (data plane development kit) Tx stuck issue and trigger a major chassis alarm goes which might trigger RG1 failover to the healthy node. A DPDK reset will be triggered only to the stuck port and if the reset resolves the tx stuck issue, the major chassis alarm will go off.

Resolved In: junos:19.4R3-S8 junos:19.4R3-S9 junos:20.2R3-S7 junos:20.4R3-S4 junos:21.2R3-S1 junos:21.2R3-S3 junos:21.4R3-S3 junos:22.2R1 junos:22.2R2 junos:22.3R1 junos:22.4R1
1630981BGP down due to BFD expired; failover restored services
Product-Group=junos
All VPN traffic may internally drop during encryption / decryption processing in HW engine requiring PFE plane reset.

Resolved In: junos:20.4R3-S7 junos:21.4R3-S3 junos:23.2R1
PR NumberSynopsisCategory: Interface Information Display
1636668Management interface speed is incorrectly reported as 10G instead of 1G
Product-Group=junos
On VM Host platforms, the management interface speed may incorrectly be displayed as 10G instead of 1G - this is a cosmetic issue.

Resolved In: evo:22.1R3-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:21.2R3-S5 junos:21.4R3-S3 junos:22.1R3 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: ISIS routing protocol
1674804Segment-routing may incorrectly set a pop action for paths using a Strict SPF(1) Algorithm
Product-Group=junos
On all Junos and Junos Evolved platforms, segment-routing sets a pop action for paths using a Strict SPF(1) Algorithm incorrectly.

Resolved In: evo:21.4R2-S2-EVO evo:21.4R3-EVO evo:22.1R3-EVO evo:22.2R2-EVO evo:22.3R1-EVO evo:22.4R1-EVO junos:21.4R2-S2 junos:21.4R3 junos:22.1R3 junos:22.2R2 junos:22.3R1 junos:22.4R1
PR NumberSynopsisCategory: jdhcpd daemon
1689005DHCP packets might not be sent to the clients when 'forward-only' is reconfigured under the routing instance
Product-Group=junos
On all Junos platforms, reconfiguring 'forward-only' in any routing instance is leading to deactivate of [default:default] jdhcpd filter. Dynamic Host Configuration Protocol (DHCP) packets might not be sent to the clients.

Resolved In: evo:20.4R3-S7-EVO evo:21.2R3-S5-EVO evo:21.4R3-S4-EVO evo:22.2R3-S1-EVO evo:22.3R2-EVO evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.4R3-S7 junos:21.2R3-S5 junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: Flow Module
1715918SRX5600 | FTPS connection is impacted with ftps-extension config in the device.
Product-Group=junos
FTPS connection to the server will not be successful until the first attempt is aborted and a new connection to the server is made.

Resolved In: junos:22.2R3-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1688972PFE wedge will be seen due to fast link flaps
Product-Group=junos
When the 10/40/100G links of the same PFE (Packet Forwarding Engine) on MPC10E/MPC11E/LC2301/MX10K-LC9600 line cards flap continuously, the whole PFE can wedge and all the links in that PFE will be affected.

Resolved In: evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S2-J8 junos:21.2R3-S3-J10 junos:21.2R3-S4 junos:21.4R3-S3 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: Microkernel for neo mpc
1670137Multibit ECC error causes the whole MX platform chassis to go down
Product-Group=junos
Faulty FPC (Flexible PIC Concentrator) on the MX platform chassis exhibiting multibit ECC (Error Checking and Correction) error (L2 cache error) will trigger this issue. The whole chassis goes down until the faulty FPC is removed from the chassis.

Resolved In: junos:21.2R3-S4 junos:21.4R3-S3 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:22.4R2
PR NumberSynopsisCategory: TCP/UDP transport layer
1694463The vmcore crash observed in low memory conditions
Product-Group=junos
On all Junos platforms, when there are low memory conditions vmcore crash is observed which impacts the traffic.

Resolved In: junos:21.2R3-S5 junos:21.4R3-S3 junos:21.4R3-S4 junos:22.1R3-S2 junos:22.3R2-S1 junos:22.3R3 junos:22.4R3 junos:23.1R1
PR NumberSynopsisCategory: vMX Data Plane Issues
1669261vMX crashes due to MBUF leaks
Product-Group=junos
vMX platforms (MX150) will crash as a result of the MBUF (Memory Buffer) leak.

Resolved In: junos:20.3X75-D43 junos:20.4R3-S5 junos:21.4R3 junos:22.1R3 junos:22.3R1 junos:22.3R2 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1701739Some PPPoE subscriber connection lost during RE switchover
Product-Group=junos
On all Junos platforms, when rpd is busy on standby RE in deleting routes from previous subscriber termination, and followed by new subscriber login in master RE and switchover performed. Some PPPoE subscriber won't come up on new master RE.

Resolved In: evo:22.3R3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.2R3-S5 junos:21.4R3-S4 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: QFX PFE Class of Services
1688455The FPC crash would be observed when the same CoS configuration is applied with wildcard for all the physical interfaces and AE
Product-Group=junos
On all Junos platforms, in a scaled scenario when some of the ge/xe/et interfaces are members of Aggregated Ethernet (AE) and the Class of Service (CoS) forwarding-class-set configuration is applied with a wildcard for all the physical interfaces and AE, it would trigger a Flexible PIC Concentrators (FPC) crash which leads to traffic loss.

Resolved In: junos:20.2R3-S6 junos:21.2R3-S5 junos:21.4R3-S1 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1688323Traffic loss is observed in IP fabric when there is a change in the underlay network
Product-Group=junos
On Junos QFX5K series platforms, configuration-change/protocol flapping/port flapping in Ethernet Virtual private network (EVPN) Virtual Extensible LAN (VXLAN) can cause traffic loss (changes related to the underlay network).

Resolved In: junos:20.4R3-S7 junos:21.2R3-S5 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: QFX5K Timing software
1683308The dcpfe crash seen with PTP configuration on Junos platforms supporting boundary clock
Product-Group=junos
On Junos platforms supporting boundary clock, dcpfe crash is seen with Precision Time Protocol (PTP) configuration. This is due to a timing issue between the periodic poll and stream addition.

Resolved In: junos:21.4R3-S1 junos:22.1R3 junos:22.2R2 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1703424Path Tear message is not forwarded by PLR to merge point when merge point supports enhanced frr while route reaching merge point is using shortcut route.
Product-Group=junos
PLR not sending pathtear when merge point supports enhanced frr while route reaching neighbor is using shortcut route.

Resolved In: evo:22.3R3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:20.4R3-S7 junos:21.2R3-S5 junos:21.4R3-S4 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Secure Web Proxy functionality on Junos
1719703The flowd process crash is observed when the web proxy packet reinjection fails
Product-Group=junos
On SRX-branch series, SRX4100, SRX4200, and vSRX platforms, packet reinjection fails if the load on the system is high and the web proxy tries to reinject the packet.

Resolved In: junos:20.4R3-S7 junos:21.2R3-S5 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1655518SRv6 END.DT46 and END.DT4 configuration might not be Supported
Product-Group=junos
On PTX Junos platforms in Segment Routing IPV6 (SRv6) scenario, when END.DT46 and END.DT4 configured, traffic might be dropped.

Resolved In: junos:22.1R1-S1 junos:22.1R2 junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: SRX branch platforms
1713759Continuous vmcores observed on the secondary node when committing the "set system management-instance" command
Product-Group=junos
On Junos SRX3xx series platforms, when the "set system management-instance" command is committed on the secondary node, continuous vmcores are observed on primary and secondary nodes. No recovery action is needed for the primary node and the secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until the management-instance knob is removed using the "delete system management-instance".

Resolved In: junos:21.4R3-S3 junos:22.1R3-S2 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1689644A 1G port on a QSFPP-4x10G transceiver will be down sometimes after the FPC restart
Product-Group=junos
On MX204 device, a QSFPP-4x10G transceiver configured at 1G speed sometimes stays down after a FPC restart. Traffic will not pass through the port.

Resolved In: junos:21.2R3-S5 junos:21.4R3-S4 junos:22.1R3 junos:22.2R2-S1 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1620773SRX4600 - Packet drop or srxpfe coredump might be observed
Product-Group=junos
Packet drop or srxpfe coredump might be observed on SRX 4600 during periods of high traffic

Resolved In: junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: MX10K linecard
1688651JUNOS_REG:MX10008:Carrier transition count is more than expected at DUT(mx10008) after flapping the interface at peer non-DUT end.
Product-Group=junos
When laser off and on happens on the remote end, within an interval of less than 500 ms, the local interface undergoes additional flap, before the link comes up. There is no impact of the additional flap, as the link does come up eventually.

Resolved In: 
PR NumberSynopsisCategory: VMHOST platforms software
1605915Harmless error message might be seen when downgrading from 21.2/21.3/21.4 to 21.1 or older image on VMHost platform
Product-Group=junos
When performing downgrade from 21.2/21.3/21.4 to 21.1 or older image on VMHost platform, below harmless error messages might be seen during "request vmhost software add" command execution. mkdir: cannot create directory '/tmp/partdisk-V6pHko/jrootfs/junos': File exists. mkdir: cannot create directory '/tmp/partdisk-V6pHko/jrootfs/vm': File exists. mkdir: cannot create directory '/tmp/partdisk-V6pHko/jrootfs/spare': File exists.

Resolved In: junos:21.2R3 junos:21.3R2 junos:21.4R1 junos:22.1R1
PR NumberSynopsisCategory: VSRX platform software
1711440VLAN tagging does not work for vSRX3.0 on HyperV Windows Server 2019 Datacenter
Product-Group=junos
VLAN tagging for vSRX3.0 on HyperV Windows Server 2019 Datacenter is not working.

Resolved In: junos:21.2R3-S5 junos:21.4R3-S4 junos:22.2R3 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: usf nat related issues
1718840The PPTP connection itself won't work when trying to establish PPTP connection along with DSLITE
Product-Group=junos
On Junos MX and SRX platforms with SPC3 cards, Point-to-Point Tunneling Protocol (PPTP) connection between client and server always failed along with Dual-Stack Lite (DSLITE) scenario. PPTP failure occurred due to Generic Routing Encapsulation tunnel (GRE) wrong call-id swapping that taken place by Address Family Transition Router (AFTR). Traffic will not pass through the tunnel at all as the tunnel does not establish.

Resolved In: junos:20.4R3-S7 junos:21.2R3-S5 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1

 


Modification History

First publication 2023-04-10