Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX PTX QFX MX NFX SRX vSRX

Alert Description

Junos Software Service Release version 22.1R3-S1 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as needed and follow the prompts

Solution

Junos Software service Release version 22.1R3-S1 is now available.

22.1R3-S1 - List of Fixed issues

PR NumberSynopsisCategory: Daily JUNOS build failures - automated builder use only
1691209Use latest os-package when upgrading
Product-Group=junos
Upgrade to 22.3R1 while using os-package published between July 2022 and November 2022 may incorrectly link os-libs package
PR NumberSynopsisCategory: EX4300 PFE
1697685Gratuitous ARP reply will not update the ARP cache
Product-Group=junos
On EX4300 platforms, the ARP (Address Resolution Protocol) cache will not be updated upon receiving the Gratuitous ARP reply even with "gratuitous-arp-reply" configured.
PR NumberSynopsisCategory: EX4300 Platform
1678506The interface on the device will go down when one or more interfaces are connected to the Advantech3260 device at another end
Product-Group=junosvae
On EX4300 platforms with version 19.1R3 and above, the interface on the device will go down when the device is connected to the Advantech3260 device at the other end. It will have a traffic impact.
PR NumberSynopsisCategory: EX4300 Filters implementation
1699777TCAM space might be exhausted when learning DHCP snooping entries on a trusted port
Product-Group=junos
On EX, QFX5k, and MX platforms having persistent binding for DHCP (Dynamic Host Configuration Protocol) snooping configured might cause TCAM (Ternary Content Addressable Memory) space exhaustion for DHCP snooping learning on the trusted port after the device reboot.
PR NumberSynopsisCategory: EX4300 Layer 2 implementation
1697995Dot1x authentication failure for EVPN VXLAN enabled port
Product-Group=junos
On Junos EX4300-48MP platforms, dot1x authentication fails with EVPN-VXLAN (Ethernet VPN-Virtual extensible LANs) end to end configuration on a user port.
PR NumberSynopsisCategory: EX2300/3400 platform
1680408On Ex2300 and EX3400, "set system ports console log-out-on-disconnect" does not allow user to log in via console.
Product-Group=junos
On certain units, with "set system ports console log-out-on-disconnect", when you login to the device via a console, the user will be kicked out to the login prompt and be asked to login again.
1705387On EX3400-24P platforms, the fxpc process crashes after upgrading from 21.4R1.12 to any 22.xRx version except 22.4
Product-Group=junos
On EX3400-24P platforms, after upgrading from 21.4R1.12 to 22.xRx release and when the cables are plugged/unplugged from the port, the fxpc (Packet Forwarding Engine manager) process crash is seen. The issue will not be seen on the 22.4 release.
PR NumberSynopsisCategory: EX-Series VC Infrastructure
1689946Instability observed after mastership switchover on members with SFP-T pluggable installed on EX4600-VC
Product-Group=junos
On Junos EX4600 Virtual Chassis (VC), a routing engine master switchover may lead members to disconnect from the VC for approx. 2 mins before the members re-join the VC. This instability will lead to traffic loss. This only happens on members with SFP-T pluggable installed.
PR NumberSynopsisCategory: a20a40 specific issue
1698797Fabric monitoring suspension and control link failure may cause HA cluster outage
Product-Group=junos
In HA cluster, a local node failure which causes control link to go down may not guarantee the other node to take over primary if the fabric link monitoring suspension was triggered earlier before (e.g. - caused by a minor hardware failure), as the fabric link down event would be ignored when the other node was in RG0 ineligible state. This is a corner case to https://www.juniper.net/documentation/us/en/software/junos/chassis-cluster-security-devices/topics/topic-map/security-chassis-cluster-failover-parameters.html#id-understanding-chassis-cluster-control-link-heartbeats-failure-and-recovery__d27575e82. And PR1698797 fixed this defect.
PR NumberSynopsisCategory: Express Broadway PFE L3
1680757BFD sessions will remain down in the EVPN-VxLAN scenario
Product-Group=junos
On QFX 10008 and QFX10016 platforms, in a distributed mode Bidirectional Forwarding Detection(BFD) session might remain down if the anchor FPC and the FPC where BFD packets are received over Virtual Tunnel Endpoint (VTEP) are different.
1697827Traffic drop is observed after deleting or deactivating the logical interface
Product-Group=junos
On Junos QFX10K platforms configured with multiple logical interfaces (IFLs) on the same physical interface (IFD), if any one of the logical interfaces (IFL) is deleted or deactivated, it will cause a complete traffic drop on the other IFLs of the same IFD.
PR NumberSynopsisCategory: Virtual-chassis platform/chassisd infrastructure PRs for MX
1670345The PFE I/O chip setup failed for some interfaces and causes those interfaces missing in PFE after backup chassis upgraded via Sequential Upgrade
Product-Group=junos
When the MX virtual-chassis was upgraded by using the Sequential Upgrade method, there is the possibility that PFE provisioning may start before link training completes and all PICs are online. In such scenario, the ifd provisioning is preserved and if the preserved state is applied to the PFE before fabric training has completed and all the PICs have been powered on, ifd missing errors will be seen.
1697630MX-VC: The backup VC router could become master after the system reboot
Product-Group=junos
On Junos MX platforms when VC (Virtual Chassis) configuration is done and after the VC membership election, when routers are rebooted, the previously elected primary router will become the backup router and the backup router will come up as the primary router.
PR NumberSynopsisCategory: Class of Service
1693977The oid tree jnxCosQstatEntry returns nothing for some interfaces after restarting class-of-service
Product-Group=junos
The oid tree jnxCosQstatEntry returns nothing for some interfaces after restarting class-of-service.
PR NumberSynopsisCategory: QFX Access Control related
1693640The dot1x reauthentication will not work for a port with VoIP VLAN
Product-Group=junos
On Junos EX platforms, the dot1x clients will remain in connecting state after the 'clear dot1x interface' is done due to which the interface would not get authenticated to become a member of the configured access VLAN. When this happens, VLAN membership will not be formed.
1702388Dot1x memory is spiking up even after clearing the dot1x sessions
Product-Group=junos
Memory leaks were observed in the following two scenarios: i) The command "clear dot1x interface" leaks 1280 bytes every time it is issued. ii) When dot1x is configured for a single supplicant mode on an interface, and then deleted, there is a memory leak of 8kb (8192 bytes) + 28 bytes every rotation.
PR NumberSynopsisCategory: Device Configuration Daemon
1682271Node Slicing: In a rare scenario, the FPC/SLC will get stuck in the ready state after a restart
Product-Group=junos
On Junos MX platforms, in a rare scenario, FPC/SLC (Flexible PIC Concentrator/Sub Line Card) may get stuck in the ready state after restarting it and the error message of 'Device busy' will be observed in Syslog.
1695663The Unicast traffic is dropped on QFX5100/EX46xx-VC platforms
Product-Group=junos
On QFX5100/EX46xx Junos platforms configured with Virtual Chassis(VC), if a master member is unplugged or forced to power off, the unicast traffic is dropped due to mac-persistence-timer expiry there is a difference in mac addresses between logical aggregated parent interface and member aggregated ethernet(ae) interface.
PR NumberSynopsisCategory: Firewall Filter
1697959Deactivating and activating the GRES causes churn in dfwd filter addition/deletion
Product-Group=junos
On all Junos dual-RE platforms, when performing activate/deactivate Graceful Routing Engine Switchover (GRES) multiple times synchronization issues are observed between the master and backup dfwd process.
PR NumberSynopsisCategory: CoS support on DNX
1703840CoS rewrite rules will not work in L3VPN scenario
Product-Group=junos
On Junos OS ACX710/ACX5448 platforms, in Layer 3 Virtual Private Network (L3VPN) scenario, Class of Service (CoS) Experimental (EXP) rewrite rules configuration will not take effect. Thus CoS remarking will not work properly leading to the wrong remarking on Multiprotocol Label Switching (MPLS) packets.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1695510MPC11E goes offline with "fpc-slice" configured
Product-Group=junos
On MX2020 platforms with MPC11E in the Junos Node Slicing environment, when "fpc-slice" is configured results in MPC11E going offline.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1620724The mgd core might be observed on EVO platforms
Product-Group=junos
On all EVO platforms, the mgd core might be observed, when repetitive netconf private session edits + commits is performed.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1702016ARP/ND doesn't resolve when extended-vlan-list is configured for the specific VLAN
Product-Group=junos
On all Junos & Junos Evolved platforms, ARP(Address resolution protocol)/ND(Neighbour discovery) doesn't resolve when extended-vlan-list is configured for the specific VLAN(virtual local area network).
PR NumberSynopsisCategory: EX4100 RE, Platform Infra, Drivers
1672731The vmcore might be seen with the back-to-back reboot
Product-Group=junos
On the EX4100 platform with VC setup, upon continuous back-to-back switch reboot, vmcore might be noticed when the switch boots back. The vmcore might lead to a kernel crash.
PR NumberSynopsisCategory: EX4400 PFE software
1694800On a PVLAN with DAI ARP packets will be forwarded between isolated ports
Product-Group=junos
On Junos based EX platforms, when Dynamic ARP (Address Resolution Protocol) Inspection (DAI) is configured on PVLAN (Private Virtual Local Area Network), ARP packets coming from the LAG (Link Aggregation Group) are forwarded to other isolated access ports.
1704470Traffic drops observed with hierarchal overlay ECMP configuration
Product-Group=junos
On EX4400 platforms in the EVPN-VXLAN environment, the overlay ECMP (equal-cost multipath) route does not get programmed in hardware resulting in traffic drops when hierarchal overlay ECMP is configured.
PR NumberSynopsisCategory: EX Entry Level Access VC platform
1704457The PXE BIOS recovery fails on EX9204/9208/9214 VC setup
Product-Group=junos
On EX9204/9208/9214 platforms configured in a Virtual Chassis(VC) setup, if the SSD(solid-state drive) local disk is erased or there is a hardware failure for EX9200-40XS FPC, the EX9200-40XS recovery will fail if performed through the PXE(Preboot Execution Environment) and stuck in a boot loop.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1693424Traffic loss is observed when the ECMP path is IRB over AE (IPv4 -> MPLS)
Product-Group=junos
On QFX10002 platforms, when the ECMP (Equal-cost multi-path) path is IRB (Integrated routing and bridging) over AE (Aggregated Ethernet) {IPv4 -> MPLS (Multiprotocol Label Switching)} results in packets getting discarded for which traffic loss is observed.
PR NumberSynopsisCategory: GMIC2 platform driver issues
1693211MACsec on logical interfaces fails after port flap
Product-Group=junos
MACsec configured on logical interfaces (IFL) would fail to restore after a flap of the parent physical interface. This will lead to Cyclic Redundancy Check (CRC) errors and failure to pass traffic.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1649958The user-defined speed does not take effect on the AE interface in certain scenarios on Junos platforms
Product-Group=junos
On Junos platforms supporting GRES (Graceful Routing Engine Switchover), the bandwidth flag on the backup RE (Routing Engine) for the AE interfaces is set unconditionally, hence the bandwidth is struck at a value despite not being set by the user statically. When GRES is performed followed by link delete/add for the AE interface, the interface would get stuck with the bandwidth and gets synced with the backup RE. There can be seen partial service impact in the case of the RSVP (Resource Reservation Protocol) and the restoration to recover from this issue is to configure bandwidth manually and then remove the configuration.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1685406The protocol MTU for the IRB interface is not rolled back when the MTU of the IRB or IFD interfaces is modified or deleted
Product-Group=junos
On all Junos platforms, the maximum transmission unit (MTU) on the Integrated Routing and Bridging (IRB) interface is not getting reset when the MTU configuration on IRB or IFD is removed. When MTU configuration is removed from the IRB interface, the internal data structure for the MTU configuration is not getting reset which might affect traffic and it is a rare case.
PR NumberSynopsisCategory: ISIS routing protocol
1696598Wrong SRTE Secondary path weight makes the secondary path active in forwarding table
Product-Group=junos
On all Junos and Junos Evolved platforms, SRTE (Segment Routing Traffic Engineering) Secondary LSP (Label Switched Path) should be only on standby in the forwarding table however it is also active and forwarding traffic due to the wrong metric calculation.
PR NumberSynopsisCategory: jdhcpd daemon
1688272IPv4 ALQ not working with authentication
Product-Group=junos
IPv4 ALQ not working with authentication. The below error would be seen on the backup router: "Message failed sanity test - the access-profile info is invalid. length:0 "
1698798A dcd process crash is observed continuously when the dhcp-service is restarted
Product-Group=junos
On MX platforms that support Broadband Edge (BBE) functionality, the dcd crash continuously occurs when the subscribers are logged in using the DHCP dynamic profile and dhcp-service is restarted having the configuration like "set chassis network-services enhanced-ip" enabled.
PR NumberSynopsisCategory: Flow Module
1699578Application traffic drop seen on all SRX platforms due to TCP window size issue
Product-Group=junos
On all SRX platforms, on rare occasions, after the SYN-ACK is established with the application server, the server will cause the TCP window size drop to zero after declaring a larger initial TCP window in the ACK packet. Though this is not prohibited but generally not expected behavior. Due to this, the packet will be dropped for that particular session.
PR NumberSynopsisCategory: SRX Firewall Authentication
1685116The user authentication page is not rendering on the client browser
Product-Group=junos
On all Junos SRX platforms due to cross-origin restriction access, the domain page does not load. The issue happened due to a firewall authentication failure.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1678772New secondary node to go into a disabled state after ISSU and failover RG0 because of fabric link failure
Product-Group=junos
On SRX5K platforms with SPC3 card, the primary node will lose the backup node and fabric link failure is observed resulting in the new secondary node going into a disabled state after ISSU (In-Service Software Upgrade) and failover RG0 (redundancy group) in a chassis cluster environment.
1691071Chassis cluster IP monitoring on the secondary node failed after the system reboot on the SRX platforms
Product-Group=junos
On SRX platforms, IP monitoring on the secondary node failed when a Reth (redundant Ethernet) interface consists of two or more than two interfaces on each node. Reth member interface which has a higher port number cannot receive ICMP (Internet Control Message Protocol) packet used for IP monitoring, which will then put the system in an error state.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1648249Vmcore is seen on Junos platforms when data plane IPSec is configured
Product-Group=junos
On Junos platforms, when data plane IPsec (IP Security) is configured, the IP layer passes bad mbuf information to the IPsec layer causing the core which is triggered by data plane ESP (Encapsulating Security Payload) packets coming to RE (Routing Engine).
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1693301MACSec session will not come up on the new fallback key during the primary key transition
Product-Group=junos
On all Junos and Evolved platforms, during the primary key transition on the MACSec session, when a new fallback key is updated on the MACSec peers the session will not come up due to the primary key remaining live on the same interface. When this happens, there will be a traffic drop on the MACSec interface. This is a rare issue and only occurs when a certain sequence of steps is performed.
1694129dot1xd.core-tarball.0.tgz is observed in 22.1R3 at #0x009113f0 in __mem_assert()
Product-Group=junos
MACSec dot1xd restarts unexpectedly with the _mem_assert( ) in the free_jemalloc(). This happens when an authentication request comes in right after the dot1xd restart.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1694648The rpd crash will be observed during the MPLS label block allocation
Product-Group=junos
On all Junos and Junos Evolved platforms in the Multiprotocol Label Switching (MPLS) scenario, the rpd crash will happen in rare conditions during MPLS label block allocation.
1701420The rpd core and traffic loss is observed on Junos and Junos Evolved platforms
Product-Group=junos
On Junos and Junos OS platforms, if an LSP (Label-Switched-Path) is configured and delegated to an external controller is disabled (not deleted from configuration), and then a rpd restart or RE (Routing Engine) switchover takes place, the rpd process crashes and generates core resulting in traffic loss.
1701800Memory leak issue in TED
Product-Group=junos
On all Junos and Junos Evolved platforms, a memory leak is observed in TED (Traffic Engineering Database) when the inet tables is not cleaned up after routing instance deactivation.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1700629The command "request system zeroize" might not work properly on EX4400.
Product-Group=junos
When issuing the "request system zeroize" command, an error message might be seen.
PR NumberSynopsisCategory: Kernel MPLS / Tag / P2MP Infrastructure
1702220LDP flaps will be observed having LT interface with VLAN and LDP running between the logical-system instance and global instance
Product-Group=junos
On Junos platforms, when the LT (Logical Tunnel) interface with VLAN and LDP (Label Distribution Protocol) is configured between the logical-system instance and global instance LDP flaps are observed.
PR NumberSynopsisCategory: TCP/UDP transport layer
1685113BGP session flap with error BGP_IO_ERROR_CLOSE_SESSION
Product-Group=junos
On all Junos and Junos Evolved platforms, a random BGP (Border Gateway Protocol) session flaps will be observed immediately after committing certain configuration changes with the error "BGP_IO_ERROR_CLOSE_SESSION" along with a TCP connection reset. This issue is generic to any TCP (Transmission Control Protocol) connection that has MD5 (Message-Digest Algorithm) enabled on it, eg targeted LDP. Following error is also reported: rpd: bgp_pp_recv: rejecting connection from a.b.c.d (Internal AS xyz), peer in state Established rpd: bgp_pp_recv:5159: NOTIFICATION sent to a.b.c.d+64150 (proto): code 6 (Cease) subcode 5 (Connection Rejected)
PR NumberSynopsisCategory: Provider Backbone (PBB) EVPN PFE functionality on MX
1529940PBB-EVPN PE cannot learn remote CE MAC address due to ARP suppression enabled
Product-Group=junos
In PBB-EVPN (Provider Backbone Bridging - Ethernet VPN) environment, ARP suppression feature which is not supported by PBB might be enabled unexpectedly. This could cause MAC addresses of remote CEs not to be learned and hence traffic loss.
PR NumberSynopsisCategory: QFX access control list
1692993The fxpc coredump is generated and an FPC restart results in traffic impact
Product-Group=junos
On all Junos platforms, when Ethernet Ring Protection (ERPS) is configured and the CLI command 'request support information' is executed, a coredump is generated and the FPC restarts, affecting traffic.
1695820On QFX5110-VC-VCF platforms, traffic impact is seen when the firewall filter with DSCP action is enabled
Product-Group=junos
On QFX5100-VC-VCF (Virtual-Chassis Fabric) when the firewall filter with action DSCP (Differentiated Services Code Point) is configured and is applied to any interface, the commit check gives a warning on FPC2 (Flexible PIC Concentrators) if the master has member id 0 and traffic drop can be seen.
PR NumberSynopsisCategory: QFX L2 PFE
1694076PFE crash is seen on all Junos QFX5K and EX46xx platforms with L2PT configuration
Product-Group=junos
PFE (Packet Forwarding Engine) crashes on all Junos QFX5K and EX46xx platforms when L2PT (Layer 2 Protocol Tunneling) is configured on the interface having flexible-vlan-tagging with encapsulation extended-vlan-bridge. It causes a traffic impact.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1696979VSTP will not work in the EVPN-VxLAN network
Product-Group=junos
On all Junos QFX5K platforms, when using transparent mode EVPN-VxLAN (Ethernet Virtual Private Network-Virtual extensible LANs), the tagged BPDUs (Bridge Protocol Data Units) are dropped instead of being pushed into the VxLAN tunnel. This issue might affect all the services related to L2PT (Layer Two Protocol Tunneling).
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1671293VC members are reloading randomly
Product-Group=junosvae
On QFX5110 platforms, in a rare scenario, VC (Virtual Chassis) members are getting reloaded as the PRIVATE PFEMAN sockets related to the VC are getting dropped.
1694996All members of the VCF will not reboot on QFX5k platforms
Product-Group=junos
On QFX5k platforms with VCF(Virtual Chassis Fabric), when "request system reboot at now" CLI is executed from any member of VC then it will be pushed to all other members of VC. But sometimes member from which CLI is executed goes into a reboot so CLI can't be pushed to other members until it comes up again, when "request system reboot" without "at now" works as expected. This command should not be used in VC as some members will not reboot or there may be a time delay between reboot of members which will make VC unstable.
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover,
1701146The rpd crash will be observed when any commit is performed
Product-Group=junos
On all Junos and Evolved platforms with RSVP auto-mesh dynamic tunnel configuration, whenever a commit is done the rpd (Routing Process Daemon) crash will be seen. This happens due to null pointer access in the memory.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1699557The rpd crash is observed when rib-sharding configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, rpd crash observed while configuring BGP rib-sharding as route re-resolve happens due to another best match route. Traffic drop can be seen during rpd process recovery.
PR NumberSynopsisCategory: Resource Reservation Protocol
1661526The rpd crash would be observed in a RSVP scenario
Product-Group=junos
On all Junos and Junos Evolved platforms with RSVP enabled, the rpd (routing protocol daemon) crash will be observed while updating the RSVP path information with a new metric. When this happens, the core files are generated and some traffic loss will be seen.
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1699115Transit tunnels fails and remains down on all Junos based MX and SRX platform with IKE-NAT-ALG enabled
Product-Group=junos
On all Junos based MX and SRX platforms, the transit tunnels are not getting established and remained down due to a 10240 IKE (Internet Key Exchange) cookie limitation on MX-SPC3 and 10240 cookie limitation on the SRX platform. IKE tunnel sessions are getting dropped on the device and caused a traffic impact.
PR NumberSynopsisCategory: Cover Logical System Infrastrcuture Development
1694449The process srxpfd/ flowd will crash on SRX devices
Product-Group=junos
On all SRX platforms (except branch SRX series) configured with chassis cluster redundancy group, when numerous logical interfaces or IFLs (> 1K) are deleted and traffic is running for those IFLs, or if the RG failover then the process srxpfed/ flowd will crash.
PR NumberSynopsisCategory: SSL Proxy functionality on JUNOS
1705044The flowd crash and core will be observed when TLS 1.3 session ticket is received on SSL-I
Product-Group=junos
On SRX platforms with SSL (Secure Sockets Layer) Proxy configured, due to timing sync issues, if TLS (Transport Layer Security) 1.3 session ticket is received on the server (SSL-Initiator), while on the client (SSL-Terminator) TLS 1.2 handshake is finished, proxy session info is cleared resulting in core when saving session ticket in the session cache.
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1701183Traffic loss is seen due to interface flap when changing speed from 10G and 1G
Product-Group=junos
On Junos MX204, traffic loss is seen on 4x10G Channelized interfaces when the speed is changed from 10G to 1G on one lane which causes the other 3 lanes to flap and stay down.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1683213SRX4600HA might not failover properly due to a hardware failure
Product-Group=junosvae
In SRX4600 platform, there is a possibility of raising alarm function might not work in FPGA failure. It might affect device availability.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1692070The firewall bridge filter policers (attached to AE interface) are not working on all Junos MX platform with MPC10 card upon deactivate-activate a term intended to limit overall traffic
Product-Group=junos
Traffic policing will not work as expected on all Junos MX platform with MPC10 card after doing deactivation-activation of the term intended to limit overall traffic when the firewall and policers are applied to the bridge unit using shared-bandwidth-policers on AE (Aggregated Ethernet) interface.
1692781The FPC crash is observed with out-of-bound access to the filter action table
Product-Group=junos
On all Junos platforms with MPC10 and above line cards, the FPC crashed due to out-of-bound filter access observed during back-to-back GRES operations.
1701320Traffic loss is seen on MPC10E due to null pointer access without any safe check
Product-Group=junos
On the Junos MX series platforms with MPC10/11, when the line card is inserted, it restarts and traffic loss is seen generating the core dump due to the null pointer access without any safe check.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1701147FPC restart and core dump generated in MPLS scaled scenario with "always-mark-connection-protection-tlv" configured
Product-Group=junos
FPC restart and core dump generated in MPLS scaled scenario with "always-mark-connection-protection-tlv" configured.
PR NumberSynopsisCategory: Configuration management, ffp, load action
1671112Test Configuration might fail even though the config file is having valid configurations
Product-Group=junos
Root cause; In test configuration flow we are calling mustd as "/usr/sbin/mustd -q /var/run/db/file.data /var/run/db/file.data+ -F -m" where we just copy the existing cog.db (generated out of committed config) as cdg.db+ , use it for testing the configuration passed, and remove it once the testing is done. This is creating the issue because the configuration is tested against the existing cdg.db. Fix would be to create the cdg.db fresh from the configuration to be tested and test the configuration against that. This new cdg.db should not replace the existing one in /var/run/db.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1679413Configuration filtering doesn't work when the logical system is present
Product-Group=junos
On SRX platforms, configuration filtering doesn't work when the logical system is present.
1699245The mgd process might crash during commit synchronize
Product-Group=junos
On all Junos OS and Evolved OS platforms with dual RE (Routing Engine) during commit script synchronize, backup RE mgd get crash once the memory leak reaches to 65K due to which commit configuration will fail which are performed through Master RE.
PR NumberSynopsisCategory: For GPRS security features on highend SRX series
1704472GTPv2 Message Filtering is not working
Product-Group=junos
GTPv2 Message Filtering not working - resolved
 
 

22.1R3-S1 - List of Known issues

PR NumberSynopsisCategory: EX4300 Platform
1635689On EX4300 platforms, continuous MACsec interfaces flaps over an extended period of time
Product-Group=junosvae
On EX4300, MACsec enabled interfaces flaps continuously over an extended period of time(~24 hours) may result in PFE core and IFDs going down.

Resolved In: junos:21.4R3-S1 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: EX2300/3400 platform
1706116Alarms were not generated as expected when the Management Interface Link was down
Product-Group=junos
On Junos EX3400 device, whenever the Management Interface Link is Down, the alarm was not getting generated as expected.

Resolved In: junos:22.3R3 junos:22.4R2 junos:23.1R2
PR NumberSynopsisCategory: EX-Series VC Infrastructure
1685067EX4600-VC - Master RE reboot and All-member reboot lead to PFE Manager hogging logs when SFP-T is plugged in
Product-Group=junos
On Junos EX4600 Virtual Chassis (VC), the master RE reboot and all-members reboot lead to the PFE Manager hogging logs when SFP-T pluggable is installed in. The PFE Manager hogging logs has no functionality impact (PR 1641556).

Resolved In: junos:20.2R3-S6 junos:21.4R3-S2
PR NumberSynopsisCategory: CoS support on ACX
1689604EVPN Packets may go to incorrect queues due to the wrong classification and may lead to packets drop during congestion
Product-Group=junos
On Junos ACX5448 and ACX710 devices, in EVPN (Ethernet Virtual private network) with a multihoming scenario, if one link fails traffic will switch over to another link. When FPC is restarted and the dot1p classifier is changed, restore the failed link. Packets may not go to the correct queue due to the wrong classification when traffic switches back to the original link, and traffic drops may happen during congestion.

Resolved In: junos:21.2R3-S4 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: OAM support on ACX
1637615Junos OS: ACX2K Series: Receipt of a high rate of specific traffic will lead to a Denial of Service (DoS) (CVE-2023-22391)
Product-Group=junos
A vulnerability in class-of-service (CoS) queue management in Juniper Networks Junos OS on the ACX2K Series devices allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA70187 [juniper.net] for more information.

Resolved In: junos:19.4R3-S9 junos:20.2R3-S7 junos:20.3R3-S6 junos:20.3X75-D35 junos:20.3X75-D42 junos:20.4R3-S4 junos:21.2R3-S3 junos:21.3R3-S3
PR NumberSynopsisCategory: Border Gateway Protocol
1687273'OSPF Route Type Extended Community' cannot be configured as 'rte-type'
Product-Group=junos
The issue is not addressed for 22.1R3 and will be addressed in future releases

Resolved In:
1689904BGP LU Advertisements fail with the message "BGP label allocation failure: Need a gateway"
Product-Group=junos
On all Junos and Junos Evolved platforms BGP-LU (Border Gateway Protocol Labeled-Unicast) Advertisements fail with the message "BGP label allocation failure: Need a gateway" based on timing conditions involving route resolution and installation.

Resolved In: evo:23.1R1-EVO evo:23.2R1-EVO junos:23.1R1
PR NumberSynopsisCategory: EX4400 platform
1683753EX/QFX SNMP: jnxOperatingDescr.1.1.0.0 returns blank, but jnxOperatingState.1.1.0.0 returns value.
Product-Group=junos
On EX/QFX series switch, jnxOperatingDescr.1.1.0.0 returns blank, but jnxOperatingState.1.1.0.0 returns value.

Resolved In: evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:21.4R3-S3 junos:22.2R3 junos:22.3R1-S2 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: Express ASIC platform
1683562On PTX5000 platforms when a command is issued to power off an FPC, it gets stuck in the 'Announce Offline' state
Product-Group=junos
When an FPC (Flexible PIC Concentrator) on PTX5000 platforms is shut down by issuing a request command (request chassis offline slot ) or by FPC power off configuration (set chassis fpc x power off), it gets stuck in the 'Announce Offline' state since the associated timer (fru_graceful_offline_timer) doesn't increment and expire as it is supposed to.

Resolved In: junos:19.2R3-S5-J2 junos:20.4R3-S2-J17 junos:20.4R3-S5-J3 junos:20.4R3-S6 junos:21.4R3-S2 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1626562A major alarm DPDK (data plane development kit) Tx stuck issue of SRX4100/4200
Product-Group=junosvae
On the SRX4100 and SRX4200 platforms, it can detect DPDK (data plane development kit) Tx stuck issue and trigger a major chassis alarm goes which might trigger RG1 failover to the healthy node. A DPDK reset will be triggered only to the stuck port and if the reset resolves the tx stuck issue, the major chassis alarm will go off.

Resolved In: junos:19.4R3-S8 junos:19.4R3-S9 junos:20.2R3-S7 junos:20.4R3-S4 junos:21.2R3-S1 junos:21.2R3-S3 junos:21.4R3-S3 junos:22.2R1 junos:22.2R2 junos:22.3R1 junos:22.4R1
PR NumberSynopsisCategory: Flow Module
1708646TCP session timeout seen on GRE tunnel
Product-Group=junos
On GRE (Generic Routing Encapsulation) tunnel, TCP (Transmission Control Protocol) session lasts only 20sec and the session timeout seen due to high latency observed.

Resolved In: junos:21.4R3-S3 junos:22.2R2-S2 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1631149SRX5600/5800 - SNMP mib queries may result in occasional response timeouts
Product-Group=junos
SRX5600/5800 - SNMP MIB queries for jnxJsSPUMonitoringMIB objects (1.3.6.1.4.1.2636.3.39.1.12.1.x) may result in occasional response timeouts

Resolved In: junos:20.4R3-S7 junos:21.2R3-S4 junos:21.4R3-S3 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
169092122.4R1:SRX_RIAD:srx5600:MN_HA:ike cookies didn't change in rekey lifetime expire cases after manual failover
Product-Group=junos
Sometimes after manual failover, IKE-SA rekey does not succeed. In order to recover from this scenario, enable dead-peer-detection with always-send

Resolved In: junos:23.1R1
PR NumberSynopsisCategory: MX Timing software
1696957In the rare scenario, huge PTP Time errors are introduced and propagated to the downstream devices after the chassis reboot
Product-Group=junos
On MX240, MX480, MX960, MX2010, and MX2020 platforms, the remote PTP (Precision Time Protocol) clock will recover the PTP clock with Time errors after a chassis reboot on the device running as Boundary Clock.

Resolved In: evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.4R3-S6 junos:21.4R3-S3 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1649799A rare corner case would lead to the restart of the device with a VMCORE crash
Product-Group=junos
On EX3400-48P or EX3400-48T or EX-3400-24T platforms, a rare corner case, would lead to the restart of the device with a VMCORE crash.

Resolved In: junos:21.2R3-S3 junos:21.2R3-S4 junos:21.3R3-S2 junos:21.4R3 junos:22.1R3 junos:22.1R3-S1
PR NumberSynopsisCategory: OSPF routing protocol
1705975OSPF routes are not getting installed after the interface is flapped
Product-Group=junos
On all Junos and Junos Evolved platforms, the OSPF (Open Shortest Path First) routes are not getting installed when the interface is flapped multiple times. A deadlock is created when the OSPF routers wait for an LSA (Link State Advertisement) with a P2P (Point-to-Point) link to be advertised from its neighbouring router to add it to its router LSA and at the same time the neighbouring router also waits for an LSA with a P2P link to be advertised to add it to its router LSA. Both the OSPF routers advertise their router LSA without a P2P link and as a result, routes are not getting installed.

Resolved In: evo:22.2R3-EVO evo:22.3R2-EVO evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:21.4R3-S3 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: Express Chip L3 software
1658317BFD session session-state is showing DOWN while checking Micro BFD Sessions with Authentication in Non-Distributed Mode
Product-Group=junos
BFD session session-state is showing DOWN when operating in centralized Mode. Packet loss may be seen.

Resolved In: junos:21.4R3 junos:22.1R3 junos:22.2R2 junos:22.3R1 junos:22.4R1
PR NumberSynopsisCategory: Express Paradise PFE Sflow
1685407Sflow ingress/egress sampling not working when ECMP nexthops are involved
Product-Group=junos
Sflow ingress/egress sampling not working when ECMP nexthops are involved.

Resolved In: junos:22.2R2 junos:22.2R3 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1669426jsd memory leak and may lead jsd restart.
Product-Group=junos
You may see memory usage of jsd is increasing gradually. When the jsd process crashes, it will restart automatically.

Resolved In: evo:22.2R2-EVO evo:22.2R3-EVO evo:22.3R1-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:21.2R3-S4 junos:21.4R3-S3 junos:22.2R2 junos:22.2R3 junos:22.3R1 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: DHCP related Issues
1696120[EVPNVXLAN_L2Stitching]: Local DHCP binding is not happening from pool specific to the VRF
Product-Group=junos
DHCP relay processing in EVPN/VXLAN environments with multiple VRFs on QFX switches requires the use of forwarding-options dhcp-relay group [GROUP] interface [irb.xxx] configuration

Resolved In: junos:22.1R3-S1
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1620642BGP session may not establish between loopback interfaces when routes are learnt through type5 EVPN routes
Product-Group=junos
On QFX5k platforms, BGP session may not establish between loopback interfaces when routes are learnt through type5 EVPN routes.

Resolved In: junos:20.2R3-S4 junos:20.2R3-S6 junos:20.4R3-S2 junos:21.2R2-S2 junos:21.2R3 junos:21.2R3-S3 junos:21.2R3-S4 junos:21.3R3 junos:21.4R2 junos:21.4R3 junos:21.4R3-S3 junos:22.1R1 junos:22.1R3 junos:22.1R3-S1 junos:22.2R1 junos:22.2R2 junos:22.2R2-S2 junos:22.3R2 junos:22.3R3 junos:23.1R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1695058Intra VLAN communication breaks in SP style config using VXLAN
Product-Group=junos
Change from Enterprise (EP) to Service Provider (SP) style configuration result in reachability issue in pure L2 (Virtual Extensible LAN protocol) VXLAN setup.

Resolved In: junos:22.2R2-S2 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1694777Restarting FPC or router reboot might causes some CCC interfaces to go down due to a 'Remote CCC down'
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if CCC (Circuit Cross-Connect) is configured to use a label-switched-path such as IGP routed, i.e., no-cspf and no strict ERO (Explicit Route Object) configuration, then restarting egress CCC node or restarting FPC on the egress CCC node containing remote-interface-switch configuration multiple times may cause CCC to remain stuck in remote-if-down state, resulting in loss of traffic. (The knob 'remote-interface-switch' is configured on the egress LER of the RSVP-TE LSP (Resource Reservation Protocol-Traffic Engineering label-switched-path) which binds the LSP terminating on the node to a local interface).

Resolved In: evo:22.4R2-EVO evo:23.1R1-EVO junos:20.4R3-J8 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1707140PFE crash will be observed when pinging the local interface with an MTU of size greater than interface MTU
Product-Group=junos
On MX platforms, while pinging the local interface, when the control plane sends packets(ICMP reply) whose size is greater than the interface MTU PFE will crash.

Resolved In: junos:20.4R3-S7 junos:21.4R3-S3 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1700321VLAN tags are imposed incorrectly when traffic is routed over IRB going out of the access interface
Product-Group=junos
On MX platforms, traffic egressing on the IRB (Integrated Routing and Bridging) interface with the underlying L2 (layer2) access port has VLAN tags imposed incorrectly.

Resolved In: evo:23.1R1-EVO junos:21.2R3-S4 junos:23.1R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1522896Egress traffic loss might happen because of PFE MTU feature problem
Product-Group=junos
On MX and EX9200 serial platforms, under Ethernet VPN (EVPN) environment, packets routed using IRB interface could not be fragmented due to media maximum transmission unit (MTU) problem.

Resolved In: junos:18.4R2-S5-J1 junos:20.4R3-S4-J3 junos:21.2R3-S3 junos:21.2R3-S4 junos:21.3R3-S2 junos:21.4R3-S2 junos:22.1R3-S1 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:22.4R2
 

 

Modification History

First publication 2023-02-13