Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 20.4R3-S7 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as needed and follow the prompts

Solution

Junos Software service Release version 20.4R3-S7 is now available.

20.4R3-S7 - List of Fixed issues 

PR NumberSynopsisCategory: JUNOS bugs found in UAC integration
1692398Connection fails are observed on Junos despite a valid auth entry
Product-Group=junos
On Junos platforms, authentication failures and connection drops are observed for a few users when UAC (Unified Access Control) modules fail to look up the roles.
PR NumberSynopsisCategory: EX2300/3400 PFE
1695771Traffic loss is seen when a MAC moves from dot1x port to non-dot1x port
Product-Group=junos
On all Junos and Junos OS Evolved platforms is having dot1x enabled interface. When two or more MAC addresses are learnt on a dot1x port, and if one of them is shifted to a non-dot1x port, the MAC address that was moved is still seen as a MAC-based VLAN entry on the Layer2 Address Learning Manager (l2alm). This could lead to network traffic being lost.
1706845Layer 3 forwarding issues for IRB
Product-Group=junos
On EX2300, EX3400, EX4400, EX4100 and EX4300-MP platforms, when master FPC with mac-persistence-timer configured on a virtual chassis switch is halted, it leads to layer 3 (l3) forwarding issues for the integrated routing and bridging (IRB).
PR NumberSynopsisCategory: Accounting Profile
1706085Firewall filter counters are not written to accounting file when interface-specific knob is used
Product-Group=junos
On all Junos platforms, when firewall filters are configured with 'interface-specific' knob to log packet counters on the accounting file using 'accounting-options', firewall filter counters are not written to this file. This causes problem in fetching the filter counters.
PR NumberSynopsisCategory: ChassisD changes specific for ACX series
1717105SNMP MIB OID output showing wrong temperature value if device running under negative temperature
Product-Group=junos
On all Junos platforms, devices may display wrong temperature values when executing commands. The temperature value is processed as positive integers but not negative integers. Hence, the negative temperature value is showing the wrong value.
PR NumberSynopsisCategory: JUNOS kernel/ukernel changes for ACX
1713699The member interface will not be added to the AE bundle if the link-speed of the AE interface doesn't match that of the member
Product-Group=junos
On Junos ACX5048 and ACX5096 platforms, if the link-speed is configured under the aggregated-ether-options hierarchy of the Aggregated Ethernet (AE) interface and the link-speed value does not match with the member link-speed, the member interface will not be added to the AE bundle.
PR NumberSynopsisCategory: "agentd" software daemon
1665516Na-grpcd process core observed in telemetry services
Product-Group=junos
On all Junos and Junos OS Evolved platforms, due to race condition happening at the time of AFT streaming and simultaneous multiple attempts to subscribe and unsubscribe AFT sensors, followed by modifying firewall filter configurations, na-grpcd can core on rare occasions. This will cause a temporary outage of streaming telemetry services. The service will self-recover upon restart of the process.
PR NumberSynopsisCategory: australia related kernel issue
1714002vmcores can be seen on SRX5k platforms when the fxp0 interface is configured under management-instance
Product-Group=junos
On Junos SRX5K series platforms, when the 'set system management-instance' command is committed on the secondary node, continuous VMcores are observed on the secondary node leading to the kernel crash. The secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until management-instance knob is removed using "delete system management-instance".
PR NumberSynopsisCategory: srx5k service offloading related PR
1702138TCP packet drops are seen when services-offload is enabled
Product-Group=junos
On Junos SRX5400, SRX5600, SRX5800 and SRX4600 Platforms, packet drops may be observed while services-offload is enabled.
PR NumberSynopsisCategory: the SMGD redundancy plugin in SMGD
1718342In a DHCP ALQ subscriber scenario delete-binding-on-renegotiation knob does not work as expected due to a synchronization error between the primary and the backup routers
Product-Group=junos
On Junos platforms, active lease query (ALQ) synchronization between peers is not happening properly. Traffic forwarding impact would be observed if there was a switchover from the Primary to the Backup. The primary router will correctly delete-binding-on-renegotiation and create a new session, but the backup router keeps the old session and old MAC address. (DHCP overrides have delete-binding-on-renegotiation configured and work as expected on the primary router whereas no notification is sent to the backup to delete the session)
PR NumberSynopsisCategory: Border Gateway Protocol
1635390BGP routes might be left stale on the router
Product-Group=junos
On all Junos and Junos Evolved platforms, if the BGP peer goes down, and the very last route in the list is marked as a high priority, BGP might assume no more routes to delete, causing routes to be stale.
1679646The AGGREGATOR attribute will not be set correctly when the independent-domain is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in BGP(Border Gateway Protocol) deployments with the "independent-domain" and aggregate routes configured under routing-instance, the AGGREGATOR attribute encapsulated within the ATTR_SET will not be populated correctly. This can result in unintended behavior or service impact because the BGP neighbors receiving this update may discard it as it is not RFC complaint.
1695062Traffic blackholing is observed when removing the BGP routes take a long time to get removed from RIB
Product-Group=junos
On Junos platforms, if a BGP (Border Gateway Protocol) peer is going down and stays down and the system might take an extremely long time to complete removing the BGP routes. The issue observed when a BGP peer sends many routes, only a small amount of routes are selected as the active routes in the RIB (Routing Information Base), and if the BGP delete job gets only a small part of the CPU time as other work in the routing process utilize the CPU.
PR NumberSynopsisCategory: Virtual-chassis platform/chassisd infrastructure PRs for MX
1713502The firmware upgradation will fail for MPC7E line card in MX-VC scenario
Product-Group=junos
On MX-VC platforms, the MPC7E firmware upgrade cannot be completed due to the TFTP (Trivial File Transfer Protocol) timeout error due to which the firmware image can't be put into FPC and the upgrade will not get succeed.
PR NumberSynopsisCategory: Class of Service
1702836Control packets would be dropped when CoS configuration under AE wildcard IFLs gets applied to AE control IFLs as well
Product-Group=junos
On MX platforms, when Aggregated Ethernet (AE) working in hierarchical-scheduler or per-unit-scheduler mode and AE class of service (CoS) configuration having wildcard on AE Logical Interface (IFLs) is committed in a single commit with AE interface flap, then the wildcard configuration gets applied to AE control IFL also. Ideally, any wildcard CoS configuration should not get attached to control IFLs. Only explicit configurations should be attached to control IFLs. This can lead to unintentional behavior.
PR NumberSynopsisCategory: Device Configuration Daemon
1650676The dcd core may be seen on the backup RE after GRES is disabled if targeted distributed configuration is used
Product-Group=junos
The device control daemon (dcd) on the backup RE might crash immediately after GRES and NSR are disabled if AE logical interfaces are configured with targeted distribution.
1682271Node Slicing: In a rare scenario, the FPC/SLC will get stuck in the ready state after a restart
Product-Group=junos
On Junos MX platforms, in a rare scenario, FPC/SLC (Flexible PIC Concentrator/Sub Line Card) may get stuck in the ready state after restarting it and the error message of 'Device busy' will be observed in Syslog.
1692404Incompatible/unsupported configuration is not getting validated correctly during ISSU/normal upgrade causing the traffic loss
Product-Group=junos
On all Junos platforms, while performing the Junos upgrade from the release before 20.4 to a higher version having an incorrect configuration may fail. This issue may lead to traffic loss or network outages.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1702016ARP/ND doesn't resolve when extended-vlan-list is configured for the specific VLAN
Product-Group=junos
On all Junos & Junos Evolved platforms, ARP(Address resolution protocol)/ND(Neighbour discovery) doesn't resolve when extended-vlan-list is configured for the specific VLAN(virtual local area network).
1709007In EVPN scenario, proxy-arp on IRB interfaces do not work as expected
Product-Group=junos
On all Junos and Junos Evolved platforms with EVPN(Ethernet Virtual Private Network) scenario, IRB(Integrated Routing and Bridging) interfaces send gratuitous arp for IPs that are already present in the network, which triggers a duplicate IP error on the end device/host.
PR NumberSynopsisCategory: MPC10 platform specific issues on EX92xx platform
1692365A self-ping blackhole is seen along with fmpc process crash in a rare scenario causing traffic loss
Product-Group=junos
On MX platforms with MPC10, MPC11, and LC9600, traffic impact is seen on the fabric links due to self-ping blackhole and fmpc process crash under the scaled config scenario.
PR NumberSynopsisCategory: EX Entry Level Access VC platform
1704457The PXE BIOS recovery fails on EX9204/9208/9214 VC setup
Product-Group=junos
On EX9204/9208/9214 platforms configured in a Virtual Chassis(VC) setup, if the SSD(solid-state drive) local disk is erased or there is a hardware failure for EX9200-40XS FPC, the EX9200-40XS recovery will fail if performed through the PXE(Preboot Execution Environment) and stuck in a boot loop.
PR NumberSynopsisCategory: Express PFE dhcp
1688316DHCPv6 packets are not forwarded if it contains the trailer or extra bytes out of the IP stack
Product-Group=junos
On QFX10002-36Q/QFX10002-72Q platforms, the DHCPv6 (Dynamic Host Configuration Protocol) solicit packets containing extra bytes in DHCPv6 header trailer are not getting forwarded to the DHCP server due to which IPv6 (Internet Protocol) assignment will not take place when DHCPv6 relay is configured.
PR NumberSynopsisCategory: Express PFE MPLS Features
1712076FPC memory leak will cause FPC crash
Product-Group=junos
On PTX and QFX10K platforms, enabling the collection of LSP (label-switched path) statistics for telemetry data using the CLI command 'set protocols mpls sensor-based-stats' will cause FPC (Flexible Physical Interface Cards (PIC) Concentrators) memory leak and a huge leak may result in FPC crash.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1630981BGP down due to BFD expired; failover restored services
Product-Group=junos
All VPN traffic may internally drop during encryption / decryption processing in HW engine requiring PFE plane reset.
PR NumberSynopsisCategory: MX Inline Jflow
1708195SRR : Unsupported AsIndex logs reported continuously on the device for MPC10/MPC11 linecards
Product-Group=junos
During transitioning window with high BGP scale, when old AS-Path are getting deleted and new getting allocated it can happen that on RPD the as_index count can go more than the max supported value on FPC, thus these errors can be reported. AS-Path are reference counted and during transitioning state where some routes have updated to new as-paths some routes may still be holding reference to old AS-Path index, so increasing the as_index allocation count to exceed max support value on line-card. This issue is -high scale specific and should not happen if the surge is only of ADD operation. This issue should not impact operational traffic and only monitoring services might get impacted.
1708485The Inline Flow Monitoring is not working on Junos MX-VC platforms
Product-Group=junos
In a Virtual-chassis (VC) scenario on Junos MX platforms installed with MPC7E Flexible PIC Concentrators (FPC), if the inline-jflow Sampling is enabled, the Inline Flow Monitoring will not work as data is not getting exported to the collector.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1610540QFX5200 mib OID ifOutDiscards misbehaving and returning value 0 which is not expected
Product-Group=junos
ifOutDiscards(Output Error Drops) returning value 0 for AE interface intermittently. Issue is observed when we receive both SYNC and ASYNC request at the same time for AE member link interface. SYNC request from mib2d(since ASYNC is not supported by QFX for AE) and ASYNC request is from sflowd. Before post-processing completes for the pending SYNC request if ASYNC request is created, ASYNC q_counters is taken for stats calculation and it results in 0.
1671135RE reboot can be seen when PPPoE subscribers login
Product-Group=junos
On all Junos platforms supporting PPPoE (Point-to-Point Protocol over Ethernet) the RE (Routing Engine) can reboot with a 'vmcore' generated during the PPPoE subscriber login. This issue can be triggered when the system has demux (demultiplexing) interface configuration and static VXLAN (Virtual Extensible Local Area Network) is configured at BD (Bridge-Domain). There will be a traffic impact because of the RE reboot but the system reverts to a functioning state without manual intervention.
1698781The kernel crash can be seen in the VPLS scenario
Product-Group=junos
On Junos platforms, Kernel crashes can happen in VPLS (Virtual Private LAN Service) scenario. This issue is seen when the VPLS has IRB (Integrated Routing and Bridging) interface and the next-hop of IRB is RLT (Redundant Logical Tunnel) interface. This issue is triggered when there is an ARP request sent from the IRB interface. There can be a service impact because of this issue as the device can reboot.
PR NumberSynopsisCategory: ISIS routing protocol
1699076The rpd process might crash when SPF is recalculated
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) process can crash due to periodic SPF (Shortest Path first) recalculation when ISIS (Intermediate System to Intermediate System) connected or direct routes get deleted.
PR NumberSynopsisCategory: jdhcpd daemon
1689005DHCP packets might not be sent to the clients when 'forward-only' is reconfigured under the routing instance
Product-Group=junos
On all Junos platforms, reconfiguring 'forward-only' in any routing instance is leading to deactivate of [default:default] jdhcpd filter. Dynamic Host Configuration Protocol (DHCP) packets might not be sent to the clients.
PR NumberSynopsisCategory: JFlow bug tracker for SRX platforms
1716707J-flow sends wrong IP in sampling records when NAT is configured for traffic along with input sampling
Product-Group=junos
When NAT (Network Address Translation) is configured on interfaces along with sampling, the J-flow record will contain NAT'ed IP as opposed to the original IP.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1715315The PPTP connection is not stable and is lost in DS-Lite+ALG scenario
Product-Group=junos
On all Junos MX platforms with MS-MPC/MS-MIC cards in DS-Lite (Dual-stack Lite)+ ALG scenario, the Point-to-Point Tunneling Protocol (PPTP) connection between the client and server is not stable and is lost. The PPTP failure occurred due TCP keepalive mechanism that is always broken due to wrong data in the generated tcp-tickle packet.
PR NumberSynopsisCategory: Flow Module
1692559High latency and packet drops will be observed with the "transmit-rate exact" knob enabled for one or more schedulers of an IFL/IFD
Product-Group=junos
On SRX1500, SRX4100, SRX4200, vSRX and NFX platforms, when one or more schedulers of an IFL/IFD queue have the knob "transmit-rate exact" enabled and shaping globally disabled, the packets start getting queued for the shaping disabled queue, and the backpressure verification is being ignored on the fast path processing. Now, if the shaping-enabled queue receives packets after idling for a long time, this will result in large numbers of packets getting enqueued at the egress queue and depletion of Memory Buffer (mbufs), leading to high latency and packet drop.
1703678Packets are dropped because flow sessions will not be created for the MPLS routed traffic
Product-Group=junos
On Junos SRX platforms, when there is a race condition between flow Multiprotocol Label Switching (MPLS) configured (knob: set security forwarding-options family mpls mode flow-based) and MPLS routing config. Flow processing is not invoked for MPLS routed traffic. It leads to packet drops for the MPLS routed traffic since sessions are not created.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1686648Policy configured with condition route-active-on import is not working properly after RG0 failover
Product-Group=junos
In a specific scenario, condition route-active-on import is not working properly after RG0 failover.
1702763The secure tunnel interface does not work properly in SRX standalone mode
Product-Group=junos
On Junos SRX5400/5600/5800/4100/4200/4600/1500/vSRX3.0 platforms, when the secure tunnel interface (st0) st0.16000-st0.16385 is defined in standalone mode, st0.16000-st0.16385 does not work properly which leads to a traffic impact. From 20.4R1 onwards, st0.16000-st0.16385 is hardcoded to be added to a high-availability zone, so it will not work in other zones.
1704670From 20.4 onwards, St0.16000 to st0.16385 will not be allowed to be configured in HA and MNHA mode
Product-Group=junos
On SRX5000/SRX4100/4200/SRX4600/SRX1500/vSRX3.0 from 20.4 onwards, st0.16000 to st0.16385 will be disallowed to be configured in cluster HA (High Availability) and MNHA (MultiNode High Availability)mode. This range of st0 subunits will not be used for regular IPsec VPN traffic secure-tunnel interfaces and reserved only for HA link encryption internal usage. This PR introduced a commit check to avoid this configuration.
PR NumberSynopsisCategory: interfaces and zones for junos js software
1711729The 'targeted-broadcast' feature will not work on some SRX platforms.
Product-Group=junos
On SRX 1500, SRX4100, SRX4200 and SRX4600 based platforms running Junos, 'targeted-broadcast' feature will not work. As a result, features like wake-on LAN (WOL) which rely on targeted broadcast will be affected.
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1631149SRX5600/5800 - SNMP mib queries may result in occasional response timeouts
Product-Group=junos
SRX5600/5800 - SNMP MIB queries for jnxJsSPUMonitoringMIB objects (1.3.6.1.4.1.2636.3.39.1.12.1.x) may result in occasional response timeouts
PR NumberSynopsisCategory: Firewall Policy
1698508Security policies go out of sync during ISSU
Product-Group=junos
On all Junos platforms, policies go out of sync between RE (Routing Engine) and PFE (Packet Forwarding Engine) after performing ISSU (In-service software upgrade) leading to the wrong policy lookup.
PR NumberSynopsisCategory: Security platform jweb support
1712454[Jweb] "address-book attach zone" is unexpectedly removed when address-book entry is added or removed by Jweb
Product-Group=junos
On SRX platform series, when address-book entry is added or removed by Jweb, "address-book attach zone" might be unexpectedly removed at configuration commit.
PR NumberSynopsisCategory: Platform infra to support jvision
1661423Continuous error logs and Telemetry data might not be populated
Product-Group=junos
On all Junos platforms, error logs are observed and telemetry data related to the transceiver does not get correctly populated for PICs (Physical Interface Cards). This is a non-service impacting issue.
PR NumberSynopsisCategory: Key Management Daemon
1719216A stale nat-long-route entry is present in the device causing incoming packets to be dropped
Product-Group=junos
On all MX platforms with MS-MPC cards, When there is an active NAT (Network Address Translation) enabled IPSec (IP security) tunnel already present for a particular service-set, any change in the outside logical interface (IFL) becomes a stale entry in the forwarding table causing IKE (Internet Key Exchange) control and data traffic to drop.
PR NumberSynopsisCategory: Layer 2 Control Module
1717267Traffic loop is seen due to incorrect root bridge ID
Product-Group=junos
On all Junos and Junos Evolved platforms, in VSTP (Virtual Spanning-Tree Protocol) topology, whenever a new vlan is added in between previously configured vlan group followed by configuring the system-identifier, the bridge priority will change for existing vlans which might give incorrect system ID or bridge ID creating a traffic loop.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1716270mac-move-limit : MMAS flag not getting reset after interface recovers due to l2-learning restart
Product-Group=junos
MMAS Flag will not be displayed for interface after it recovers due to l2-learning process restart
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1686654Subscribers are not able to connect to the device after the device reboot
Product-Group=junos
Due to a rare timing issue all subscribers may fail to connect and get suck in init state after reboot of MX broadband network gateway (BNG).
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1688972PFE wedge will be seen due to fast link flaps
Product-Group=junos
When the 10/40/100G links of the same PFE (Packet Forwarding Engine) on MPC10E/MPC11E/LC2301/MX10K-LC9600 line cards flap continuously, the whole PFE can wedge and all the links in that PFE will be affected.
PR NumberSynopsisCategory: MPC11 ULC interface software related issues.
1703374Some of the interfaces are going down on rebooting the MPC11E line card
Product-Group=junos
The reboot of the MPC11E line card on MX2010/MX2020 platforms makes some of the interfaces down. Hence the traffic carried over the down interfaces will be dropped. This is caused by racing conditions between multiple processes during the addition of the interfaces after the FPC/PIC restart.
PR NumberSynopsisCategory: Interface related ISSU PRs on Mx-series
1689199The logical interface policer is not working as expected when applied to filter input-list/output-list
Product-Group=junos
The logical interface policer does not work when configured using filter input-list/output-list.
PR NumberSynopsisCategory: Track Mt Rainier RE NIC issues in Linux
1695794The RE mastership switchover will not be triggered when the internal master interface on VMHost is down
Product-Group=junos
On VMHost platforms, the Flexible PIC Concentrator (FPC) will be disconnected and the Routing Engine (RE) mastership will not be triggered when the master internal interface(eth1/eth2) is down. Traffic loss will be seen as FPCs are disconnected.
PR NumberSynopsisCategory: Kernel Composite Next Hop (composite / l3vpn) Infrastructure
1677512The next-hops entries are not cleared in some error-handling scenarios
Product-Group=junos
On all Junos platforms, the reference counts are not cleared which in turn is blocking the deletion of the route tables when routing protocols (OSPF/BGP, etc) are enabled on em0.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1669072Junos OS: NFX Series: 'set system ports console insecure' allows root password recovery (CVE-2023-28972)
Product-Group=junos
An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. Please refer to https://supportportal.juniper.net/JSA70596 [juniper.net] for more information.
1704032VM process crashes if a file is shared between the host operating system and the guest operating system using virtFS
Product-Group=junos
On Virtual Machines (VM) based platforms running Junos images, files are not shared between the host operating system and guest operating system via Virtual Filesystem (virtFS). When this issue happens, the device will be restarted.
PR NumberSynopsisCategory: OSPF routing protocol
1705975OSPF routes are not getting installed after the interface is flapped
Product-Group=junos
On all Junos and Junos Evolved platforms, the OSPF (Open Shortest Path First) routes are not getting installed when the interface is flapped multiple times. A deadlock is created when the OSPF routers wait for an LSA (Link State Advertisement) with a P2P (Point-to-Point) link to be advertised from its neighbouring router to add it to its router LSA and at the same time the neighbouring router also waits for an LSA with a P2P link to be advertised to add it to its router LSA. Both the OSPF routers advertise their router LSA without a P2P link and as a result, routes are not getting installed.
PR NumberSynopsisCategory: Express Chip L3 software
1564147The dcpfe process might crash in ECMP scenario
Product-Group=junos
On PTX Series routers and the QFX10000 line of switches, if more than 64-link ECMP is configured, the memory leak for the dcpfe process could be observed, which might lead to a crash. The dcpfe crash is restored automatically after some time.
PR NumberSynopsisCategory: Interface related issues. Port up/down, stats, CMLC , serdes
1575673Error messages reported on trying to read information from the phy of a tranceiver: dcbcm_xcvr_phy_mdio_sgmii_lnk_op - Failed to MDIO read
Product-Group=junos
Error messages reported on trying to read information from the phy of a tranceiver: dcbcm_xcvr_phy_mdio_sgmii_lnk_op - Failed to MDIO read
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1695847Traffic forwarding fails when deleting all L2 related configurations
Product-Group=junos
On QFX and EX series platforms, traffic loss will be observed for deleting all Layer2 related configurations when both L2 and Layer3 configurations are present.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1688323Traffic loss is observed in IP fabric when there is a change in the underlay network
Product-Group=junos
On Junos QFX5K series platforms, configuration-change/protocol flapping/port flapping in Ethernet Virtual private network (EVPN) Virtual Extensible LAN (VXLAN) can cause traffic loss (changes related to the underlay network).
1712405VXLAN traffic gets dropped after new L3 VLANs are created
Product-Group=junos
Traffic black-holing in EVPN (Ethernet VPN) fabric when performing configuration of new VLANs, it is found that L3 VLANs are having IPV4 bits disabled.
PR NumberSynopsisCategory: QFX5100 Interface related issues
1665800Ports with SFP-T 1G plugged in may go to hung state on QFX5100 platforms
Product-Group=junos
When the remote end server/system reboots, QFX5100 platform ports with SFP-T 1G inserted may go into a hung state and remain in that state even after the reboot is complete. This may affect traffic after the remote end system comes online and resumes traffic transmission.
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1671293VC members are reloading randomly
Product-Group=junos
On QFX5110 platforms, in a rare scenario, VC (Virtual Chassis) members are getting reloaded as the PRIVATE PFEMAN sockets related to the VC are getting dropped.
1679919PFE process crash might be observed on QFX5100 platforms
Product-Group=junosvae
On QFX5100 platforms (both stand-alone and VC scenario) running Junos, occasionally during the normal operation of the device, PFE (Packet Forwarding Engine) can crash resulting in total loss of traffic. The PFE reboots itself following the crash.
1689499The virtual-chassis-port set interface remains disabled even after it has been enabled with 'request virtual-chassis vc-port set interface vcp-[disable]' command
Product-Group=junos
On Junos QFX5100 and EX4600-Virtual Chassis (VC) and Virtual Chassis Fabric (VCF) platforms on upgrading Virtual Chassis Fabric (VCF) and toggling the interface, when FPC (Flexible PIC Concentrators) is disabled and rebooted, the member fails to join the virtual chassis and the interface remains disabled even after been enabled.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1657534FEC link is down after disabling/enabling interface
Product-Group=junos
On the QFX5200-32C-32Q platform, on disabling and enabling interfaces, the Forward Error Correction (FEC) might mismatch. It impacts service as the FEC link might not come up.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1710855The FPC will be offline after upgrading the system
Product-Group=junosvae
On the Junos QFX5100 platform, after upgrading the system to the affected TVP/5e releases the PFE (Packet forwarding Engine) will crash continuously and Flexible PIC Concentrators (FPC) will remain down. TVP/5e Junos only needed if mixed VC of QFX5100 & QFX5110 need to form.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1678217PFE memory usage gets impacted after GRES
Product-Group=junos
On all Junos and Junos Evolved platforms, when GRES(Graceful Routing Engine Switchover) is performed, rpd doesn't delete some unused indirect nexthops after switchover. It will impact PFE(Packet Forwarding Engine) memory usage.
PR NumberSynopsisCategory: Issue related to mcnh routing infrastructure within RPD
1658425The next-hop does not be updated and errors observed when aggregated interface goes down
Product-Group=junos
On all Junos OS Evolved platforms, dependency errors after interface flap are observed due to uncleared multicast composite next hop from RPD(routing protocol process daemon).
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1668481The BGP multipath might not install some of the available next hops
Product-Group=junos
On all Junos and Junos Evolved platforms configured with BGP multipath, if the number of BGP paths available for multipath is greater than the maximum-ecmp configured (default 16), multipath might not install some of the next hops. This might lead to an undesired ECMP load-balancing of traffic.
PR NumberSynopsisCategory: RPD policy options
1670998The rpd process crashes whenever it is getting shut down with router reboot, rpd restart, RE switchover, software upgrade
Product-Group=junos
The routing process daemon crashes whenever the rpd process is getting shutting down with router reboot, rpd restart, RE switchover, and software upgrade with Border Gateway Protocol configured on the device.
1706143Issue in committing more than 23, 4-byte AS on Junos and Junos Evolved platforms
Product-Group=junos
On all Junos and Junos Evolved platforms, when a 4 byte autonomous system (AS) number is committed with more than 23 as-path in as-path-prepend policy it gives "rpd string" error and the configuration commit fails.
PR NumberSynopsisCategory: Resource Reservation Protocol
1593959ISIS BFD sessions may take a long time to recover when the interface flaps
Product-Group=junos
When RSVP link-protection bypass LSPs active after the primary link goes down and comes back up. The BFD session over the interface stays down until all LSPs using the bypass LSPs come back up. This happens because RSVP installs a /32 route pointing to the bypass tunnel which is required to signal backup LSPs. This route is removed when all LSPs stop using bypass after the link comes back up. This is day 1 RSVP behavior.
1703424Path Tear message is not forwarded by PLR to merge point which is causing data plane blackholing
Product-Group=junos
On all Junos and Junos OS Evolved platforms, the PLR (point of local repair)is not sending the pathtear message when the merge point supports enhanced FRR while the route reaching the neighbor is using a shortcut route under MVPN (Multicast Virtual Private Network) configured scenario.
PR NumberSynopsisCategory: Secure Web Proxy functionality on Junos
1719703The flowd process crash is observed when the web proxy packet reinjection fails
Product-Group=junos
On SRX-branch series, SRX4100, SRX4200, and vSRX platforms, packet reinjection fails if the load on the system is high and the web proxy tries to reinject the packet.
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1713725IPv6 Fragmentation is not working on MS-MPC/MS-MIC in DS-Lite scenario
Product-Group=junos
On all Junos MX platforms with MS-MPC/MS-MIC cards in DS-Lite(Dual-stack Lite) scenario , Address Family Transition Router (AFTR) always failed to fragment newly generated IPV6 packet that has packet size larger than mtu-v6 value. packet will be dropped and will not reach to the softwire initiator (B4)
PR NumberSynopsisCategory: SRX branch platforms
1646943No system or chassis alarm will be seen when device booting from backup partition
Product-Group=junos
On Junos SRX branch platforms, when the device boots up from the backup partition, the alert message will not be notified in "show system alarm". This issue has been seen from Junos 19.4R2 release.
PR NumberSynopsisCategory: SRX5XX platform
1634965[SRX] SRX550HM interfaces LED of ge-0/0/6-9 will auto turn off after device bootup some minutes
Product-Group=junos
SRX550HM interfaces LED of ge-0/0/6-9 will auto turn off after device bootup some minutes.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1712727Continuous vmcores observed on the secondary node when committing set system management-instance command
Product-Group=junos
On Junos SRX4600 device, when the "set system management-instance" command is synced to the secondary node, continuous VMcores are observed on primary and secondary nodes. The secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until management-instance knob is removed using "delete system management-instance"
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1704129Traffic is blocked on a queue when enhanced priority mode is configured
Product-Group=junos
On MPC1-9, JNP10K-LC2101, JNP10003-LC2103, JNP10K-LC480 line cards, with scheduler map configuration change in enhanced priority mode, traffic is blocked on a queue.
PR NumberSynopsisCategory: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1692256PFE will be disabled whenever XQ_TOE CM error is being detected
Product-Group=junos
On specific line cards or devices with specific line cards MPC2E-3D-NG/MPC3E-3D-NG/MPC5E/MPC6E/EX9200-6QS/SRX5K-MPC3-100G10G/SRX5K-MPC3-40G10G, XQ_TOE CM errors were classified as 'Major' error which triggers disable-pfe action while XQ_TOE errors are classified as Minor error. Once disable-pfe action is triggered, all the interfaces on the impacted PFE will go down and traffic through that PFE will be impacted.
1720591In a rare case FPC crashes and reboots generating a core
Product-Group=junos
On all Junos platforms, in a rare scenario, GRES (Graceful Routing Engine switchover) may result in LACP (Link Aggregation Control Protocol) on the new master being down which may cause an FPC crash.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1706446No network reachability when enabling the routing-service knob for PPPoE subscribers over AE
Product-Group=junos
On all Junos platforms configured with PPPoE subscribers, when the PPPoE (Point-to-Point Protocol over Ethernet) subscriber is configured on the AE (Aggregated Ethernet) interface while enabling the routing-service knob, the service will not get enabled and the subscriber traffic gets impacted.
PR NumberSynopsisCategory: Trio pfe qos software
1706494Severity reclassification of queuing ASIC XQSS and memory parity error auto recovery
Product-Group=junos
On Junos with MX platform using specific MPC7E/MPC8E/MPC9E/JNP10K-LC2101/JNP10003-LC2103/JNP10K-LC480 line cards in the event of a transient memory hardware issue, parity errors are generated which cannot be rectified by the ASIC. When the Flexible PIC Concentrators(FPC) encounters such an error, it will automatically deactivate the Packet Forwarding Engine(PFE) which leads to traffic impact.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1659783The configuration might roll back after performing "commit confirmed" and then reboot
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, the configuration might roll back after performing "commit confirmed" and then a reboot.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1708321MX960 :: CST:RE goes to amnesiac state, when rebooting the DUT -mgd: error: translation script failure
Product-Group=junos
When a toggle attribute with variable is committed under dynamic-profiles hierarchy, upon reboot system will go to amnesiac mode
PR NumberSynopsisCategory: PTX/QFX100002/8/16 interface software
1712007The interface does not come up or keeps flapping
Product-Group=junos
On Junos PTX10008/PTX100016 devices with LC1101/LC1102 line cards, any event that causes an interface state change can lead to interface flapping or the interface may not come back at all. This leads to traffic impact on that interface.
PR NumberSynopsisCategory: VSRX platform software
1711733RSI does not collect PFE related commands on vSRX3 in Chassis cluster
Product-Group=junos
RSI collection operation will set proper PFE target to be connected to collect PFE related information for different platforms. for vSRX3.0 in chassis cluster, it doesn't set the PFE target correctly which would result it fail to connect to PFE to collect PFE related information.
PR NumberSynopsisCategory: Xellent Platform issues
1585728High FPC CPU utilization might be seen on PTX10002-60C and QFX10002-60C devices
Product-Group=junos
On PTX10002-60C and QFX10002-60C devices, if a high number of optics are plugged in and interfaces are down, high FPC CPU utilization might be seen because the PIC periodic thread consumes a lot of CPU.
1709817Ports with QSA adapter are down
Product-Group=junos
On Junos PTX1000 and PTX10002-60C/QFX10002-60C platforms, ports which use the QSA (QSFP-to-SFP Adapter) may not come up when running software version containing the fix for PR 1620527.
PR NumberSynopsisCategory: usf nat related issues
1718840The PPTP connection itself won't work when trying to establish PPTP connection along with DSLITE
Product-Group=junos
On Junos MX and SRX platforms with SPC3 cards, Point-to-Point Tunneling Protocol (PPTP) connection between client and server always failed along with Dual-Stack Lite (DSLITE) scenario. PPTP failure occurred due to Generic Routing Encapsulation tunnel (GRE) wrong call-id swapping that taken place by Address Family Transition Router (AFTR). Traffic will not pass through the tunnel at all as the tunnel does not establish.
 
 

20.4R3-S7 - List of Known issues 

PR NumberSynopsisCategory: EX4300 Platform implementation
1712785BTB: [interfaces] : :Mojito_Royale:CPLD firmware fails to upgrade from 2.2 to 2.5 with 22.4R1.10 image
Product-Group=junosvae
CPLD firmware fails to upgrade from 2.2 to 2.5 with 22.4R1.10 image

Resolved In: junos:21.2R3-S5 junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: EX2300/3400 PFE
1679094DHCP binding will fail for the clients (Clients connected on an AE interface with 2 or more VLANs) on a VLAN where DHCP security is not configured
Product-Group=junos
On Junos EX2300, EX3400, and EX4300-MP, DHCP (Dynamic Host Configuration Protocol) binding will fail for clients on a VLAN where DHCP security is not configured. This is seen when an Aggregated Ethernet (AE) interface has two or more VLANs, and DHCP security is configured on only one interface DHCP security is not configured on the other VLAN.

Resolved In: junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S3 junos:21.4R3 junos:21.4R3-S4 junos:22.1R3 junos:22.1R3-S2 junos:22.2R2 junos:22.2R3 junos:22.2R3-S1 junos:22.3R1 junos:22.3R2 junos:22.3R3 junos:22.4R1
PR NumberSynopsisCategory: EX2300/3400 platform
1695057The l2cpd telemetry crash would be observed when the LLDP Netconf notification from external controllers along with Netconf services configuration is present on the device
Product-Group=junos
On all Junos and Junos Evolved platforms, configuring Link Layer Discovery Protocol (LLDP) with "system services netconf notification" enabled will trigger the l2cpd crash. This crash causes the CPU to spike.

Resolved In: evo:21.4R3-S4-EVO evo:22.1R3-S2-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.3R3-EVO evo:22.4R1-S2-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:21.2R3-S5 junos:21.4R3-S4 junos:22.3R2 junos:22.3R3 junos:22.4R1-S2 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: EX-Series VC Infrastructure
1685067EX4600-VC - Master RE reboot and All-member reboot lead to PFE Manager hogging logs when SFP-T is plugged in
Product-Group=junos
On Junos EX4600 Virtual Chassis (VC), the master RE reboot and all-members reboot lead to the PFE Manager hogging logs when SFP-T pluggable is installed in. The PFE Manager hogging logs has no functionality impact (PR 1641556).

Resolved In: junos:20.2R3-S6 junos:21.4R3-S2
PR NumberSynopsisCategory: Anything related to Multicast
1461339Mcast traffic drops is observed with the following error message: brcm_rt_ip_mc_ipmc_install.
Product-Group=junos
Following two Failure messages seen brcm_rt_ip_mc_ipmc_install:2455 Failed (Invalid parameter:-4) This message is due to IPMC Group being used is not created, when RE tried to add this check indicates there is a parameter mis-match. brcm_rt_ip_mc_ipmc_install:2455 Failed (Internal error:-1) This message is due to Failure to read IPMC Table or any memory/register

Resolved In: 
PR NumberSynopsisCategory: MPC Fusion SW
1716766A 10G port on a MPC2E or MPC3E 4x10G MIC can randomly flap constantly every few seconds
Product-Group=junos
On Junos MX platforms, the interface flaps in every few seconds on the 10G port on 4x10G MIC on MPC2E-NG or MPC3E-NG card whatever cause the interface to go down.

Resolved In: evo:22.3R3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.2R3-S5 junos:21.2X33-J1 junos:21.2X33-J2 junos:21.4R3-S4 junos:22.1R3-S2 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Issues related to Common BIOS on x86 based designs
1677257USB format installation stops on QFX10002-60C swithes.
Product-Group=junos
When QFX10002-60C is formatted with USB, "Reboot now?" appears, and if you press "y, " the screen becomes garbled and you cannot operate it at all.

Resolved In: 
PR NumberSynopsisCategory: PTX10003 Interface related issues
1580113JVISION optics sensor's alarm data type changed from " bool_val" to "str_val"
Product-Group=junos
it changes the format specifier of alarms from string to boolean for following leafs. lane_tx_loss_of_signal_alarm lane_rx_loss_of_signal_alarm lane_tx_laser_disabled_alarm

Resolved In: evo:20.4R2-EVO evo:21.2R2-EVO evo:21.3R1-EVO evo:21.4R1-EVO junos:20.4R3 junos:21.2R2 junos:21.3R1 junos:21.4R1
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1643855Traffic might be impacted due to the rcp session number reaching the maximum limit
Product-Group=junos
On dual Routing Engine platforms, if there are communication issues between the primary Routing Engine and the backup Routing Engine, the remote copy process (rcp) might spawn database sync sessions that exceed 75 sessions. This can impact services such as performing a configuration commit, which might fail.

Resolved In: evo:20.4R3-S4-EVO evo:21.3R3-EVO evo:21.4R2-EVO evo:22.1R1-EVO evo:22.2R1-EVO junos:18.2R3-S7-J2 junos:18.2X43-J1 junos:20.3X75-D50 junos:20.4R3-S4 junos:21.1R3-S3 junos:21.2R3-S2 junos:21.3R3 junos:21.4R2 junos:22.1R1 junos:22.2R1
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1712554[MPC10E] If both Macsec IFL and Macsec IFD coexist on the channelized interface, enabling macsec on the Channelized IFD impacts the Macsec Traffic on other channelized IFL interface with in the same port and vice versa.
Product-Group=junos
If both Macsec IFL and Macsec IFD coexist on the channelized interface, enabling macsec on the Channelized IFD impacts the Macsec Traffic on other channelized IFL interface with in the same port and vice versa. This issue is applicable on MPC10E and MPC11E platforms.

Resolved In: evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: EVPN control plane issues
1723832The rpd core is seen in the long-running devices with EVPN enabled
Product-Group=junos
On Junos and Junos Evolved platforms, BGP (Border Gateway Protocol) community object reference count is not handled properly during the process of remote BGP peer routes update event. The community reference count is increasing during the increment function. However, decrement functions are not called in one of the places after processing the routes update. This will lead to a disturbance of the continuity reference count, which will cause an rpd crash.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-S4-EVO evo:22.1R3-S3-EVO evo:22.2R3-S1-EVO evo:22.3R3-EVO evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.2R3-S5 junos:21.4R3-S2-J16 junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Express pfe Mclag
1610173Continuous L3 traffic drop might be observed with MC-LAG configuration on QFX10K platforms
Product-Group=junos
On QFX10K platforms with MC-LAG configured, When trying to add or remove the MC-LAG configuration continuous L3 traffic drop might be observed which might not be recovered.

Resolved In: junos:20.4R3-S1 junos:21.1R2-S2 junos:21.1R3 junos:21.2R1-S2 junos:21.2R2 junos:21.2R2-S1 junos:21.2R3 junos:21.3R1-S1 junos:21.3R2 junos:21.4R1 junos:22.1R1
PR NumberSynopsisCategory: Express PFE MPLS Features
1683123L3VPN to VXLAN traffic gets dropped on QFX platforms with QFX10000-60S-6Q and QFX10000-36Q line cards
Product-Group=junos
On QFX10008 and QFX10016 platforms with QFX10000-60S-6Q and QFX10000-36Q line cards installed, L3VPN (Layer 3 VPN) to VXLAN (Virtual Extensible LAN) traffic will not flow if the L3VPN tunnel is terminated on the affected cards.

Resolved In: junos:20.4R3-S5
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1649958The user-defined speed does not take effect on the AE interface in certain scenarios on Junos platforms
Product-Group=junos
On Junos platforms supporting GRES (Graceful Routing Engine Switchover), the bandwidth flag on the backup RE (Routing Engine) for the AE interfaces is set unconditionally, hence the bandwidth is struck at a value despite not being set by the user statically. When GRES is performed followed by link delete/add for the AE interface, the interface would get stuck with the bandwidth and gets synced with the backup RE. There can be seen partial service impact in the case of the RSVP (Resource Reservation Protocol) and the restoration to recover from this issue is to configure bandwidth manually and then remove the configuration.

Resolved In: evo:22.2R3-EVO evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:20.2R3-S7 junos:20.4R3-S6 junos:21.1R3-S5 junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: ISIS routing protocol
1677567Label traffic will be dropped at the one-hop LSP stitching node if the packet has more than one label
Product-Group=junos
On all Junos and Junos Evolved platforms supporting the Segment Routing (SR) feature, when segment routing and Label Distribution Protocol (LDP) stitching are configured, the label traffic drop is observed at the one-hop Label Switched Path (LSP) stitching node when the labeled packet is received with more than one label.

Resolved In: evo:21.4R3-EVO evo:22.1R3-EVO evo:22.2R2-EVO evo:22.3R1-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:19.2R3-S6-J1 junos:21.2R3-S4 junos:21.3R3-S3 junos:21.4R2-S1-J4 junos:21.4R3 junos:22.1R3 junos:22.2R2 junos:22.3R1 junos:22.3R2 junos:22.4R1
1718734Unexpected behavior of bandwidth based metric for IS-IS protocol
Product-Group=junos
On all Junos and Junos OS Evolved platforms unexpected behavior of bandwidth based metric in IS-IS is seen since actual bandwidth is falling back to 0 bps when one of the member interface of AE (Aggregated Ethernet) bundle (interface-group) goes down.

Resolved In: evo:21.4R3-S4-EVO evo:22.1R3-S3-EVO evo:22.2R3-S1-EVO evo:22.3R3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Firewall Network Address Translation
1712738Some sessions will not be deleted when the NAT rule is deleted from the system
Product-Group=junos
On all SRX platforms with NAT (Network Address Translation) configured, upon deleting a NAT rule the session associated with deleted rule continues to exist in the system, until the connection close initiated by the session. This is a rare timing issue.

Resolved In: junos:20.4R3-S8 junos:21.2R3-S5 junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Layer 2 VPN related issues
1654516Routes flapping when configuration changes are applied to custom routing instance
Product-Group=junos
Routes flapping when configuration changes are applied to a custom routing instance.

Resolved In: evo:21.2R3-S5-EVO evo:22.2R3-EVO evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:21.1R3-S5 junos:21.2R3-S5 junos:21.3R3-S4 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1684842Licenses on the device might become invalid when the device is upgraded from a legacy licensing-based release to an Agile licensing-based release
Product-Group=junos
This issue is applicable to all Junos. When a device with a valid license is upgraded to a release and this upgrade changes the licensing from Legacy to Agile then the installed license might show as invalid.

Resolved In: junos:20.4R3-S5 junos:21.1R3-S5 junos:21.2R3-S3 junos:21.4R3-S1 junos:22.1R3 junos:22.2R2-S2 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: SW PRs for MPC10E Chassisd
1664448The command "show chassis fpc" shows inaccurate information about heap memory
Product-Group=junos
The command "show chassis fpc" shows inaccurate information about heap memory in output.

Resolved In: evo:21.4R3-EVO evo:22.1R2-EVO evo:22.1R3-EVO evo:22.2R2-EVO evo:22.2R3-EVO evo:22.3R1-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:20.2R3-S5-J3 junos:20.2R3-S7 junos:21.1R3-S5 junos:21.2R3-S2 junos:21.3R3-S2 junos:21.4R3 junos:22.1R2 junos:22.1R3 junos:22.2R2 junos:22.2R3 junos:22.3R1 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: MPC11 ULC platform software related issues.
1715264'show system firmware' output for MPC11E may become unexpected state and firmware upgrade fails
Product-Group=junos
On MPC11E equipped MX with Junos 21.3 and earlier, the output of 'show system firmware' becomes unexpected state after some events either 'GRES Routing-Engine switchover' or CLI 'request chassis-control immediately' or 'crash of chassisd daemon'. 'request system firmware upgrade fpc slot <>' would fail. Rebooting the MPC10E resolves the problem. 21.4 and later releases does not have this problem.

Resolved In: 
PR NumberSynopsisCategory: Multiprotocol Label Switching
1570382Seeing unexpected lsp packet count for the ingress mpls lsp statistics
Product-Group=junos
When using the command "show mpls lap statistic ...", the statistic is not as expected. The issue is due to batching when one batch has multiple entries with the same sid.

Resolved In: evo:20.4R2-EVO evo:20.4X50-EVO evo:21.1R2-EVO evo:21.2R1-EVO junos:20.4R2 junos:21.1R2 junos:21.2R1
1616841Protected LSP goes down with strict hops and link protection configured
Product-Group=junos
On all Junos and all EVO platforms, the sub-LSP of a Point-to-Multipoint Label Switched Path(P2MP LSP) with link-protection and having strict hops goes down when a protected link on more than one sub-LSP goes down simultaneously and TED(Traffic Engineering Database) notification or RSVP tunnel local repair message not received before the CSPF(Constrained Shortest Path First) computation. As a result, the sub-LSP fails and traffic drop is seen.

Resolved In: evo:21.1R3-EVO evo:21.2R2-S2-EVO evo:21.2R3-EVO evo:21.3R2-EVO evo:21.4R1-EVO evo:22.1R1-EVO junos:19.3R2-S3-J4 junos:19.4R3-S10 junos:20.2R3-S3-J6 junos:20.3R3-S6 junos:20.4R3-S5 junos:21.1R3 junos:21.2R2-S2 junos:21.2R3 junos:21.3R1-J1 junos:21.3R2 junos:21.4R1 junos:22.1R1
1655031The rpd core is seen due to IGP database and BGP LS database out of sync
Product-Group=junos
On all Junos and Junos OS Evolved platforms, rpd core is hit when the events for deleting prefixes, sids, links and nodes come in out of order which occasionally leads to IGP database and BGP LS database out of sync.

Resolved In: evo:20.4R3-S5-EVO evo:21.4R3-S2-EVO evo:22.1R3-EVO evo:22.2R2-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:20.3X75-D36 junos:20.4R3-S5 junos:21.2R3-S3 junos:21.3R3-S4 junos:21.4R3-S1 junos:22.1R3 junos:22.2R2 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: MX Timing software
1690135The secondary clock doesn't work in Synchronous Ethernet Feature with G.8275.1 profile configuration
Product-Group=junos
On Junos MX240/MX480/MX960 devices with Switch Control Boards Enhanced 3 (SCBE3), the Device Under Test (DUT) will not be able to recover the clock when the primary is not available for clock recovery and the basic functionality doesn't work when configured in hybrid mode (PTP and Sync-E) in G.8275.1 profile. It will cause packets to drop if the frequency error is high.

Resolved In: junos:20.4R3-S4-J10 junos:20.4R3-S6 junos:21.1R3-S5 junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1
1723644configuration commit error while adding secondary interface for PTP redundancy feature
Product-Group=junos
For MX960, MX480, MX240, and on MX2020, MX2010, MX2008 chassis. Configuring slave or stateful ports on more than two-line cards is not supported by BMCA while the user is configuring the line card redundancy feature.

Resolved In: 
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1671649Traffic loss may be seen due to SPC3's packets getting stuck
Product-Group=junos
On Junos MX960, MX480 and SRX5000 series platforms with SPC3 card, Flowd restart or PIC (Physical Interface Card) going offline/online may cause SPC3's sending of packets to get stuck.

Resolved In: evo:22.1R3-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S3 junos:21.4R3-S1 junos:22.1R2-S1 junos:22.1R3 junos:22.2R1-S2 junos:22.2R2 junos:22.2R3 junos:22.3R1-S1 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: Kernel MPLS / Tag / P2MP Infrastructure
1702220LDP flaps will be observed having LT interface with VLAN and LDP running between the logical-system instance and global instance
Product-Group=junos
On Junos platforms, when the LT (Logical Tunnel) interface with VLAN and LDP (Label Distribution Protocol) is configured between the logical-system instance and global instance LDP flaps are observed.

Resolved In: junos:20.4R3-S6 junos:21.1R3-S5 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: Phone-Home-Client Infrastructure
1709822JDI-RCT : EX3400 VC : Device CPU spike after loading phone home server config
Product-Group=junos
When customer loads operational config manually or using other means like Jweb, they must ensure that unwanted config is not present in router. For example, set chassis auto-image-upgrade and set system phone-home config is used for auto-provisioning of system. When system is provisioned via other mode, these configs should be deleted by those other modes.

Resolved In: 
PR NumberSynopsisCategory: JRR - VRR running on SRX4200
1677503Junos OS: JRR200: Kernel crash upon receipt of a specific packet (CVE-2023-28970)
Product-Group=junos
An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing on the network interfaces of Juniper Networks Junos OS on JRR200 route reflector appliances allows an adjacent, network-based attacker sending a specific packet to the device to cause a kernel crash, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA70594 [juniper.net] for more information.

Resolved In: junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R2-S2 junos:22.2R3 junos:22.3R1-S2 junos:22.3R2 junos:22.3R2-S1 junos:22.3R3 junos:22.4R1-S1 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1685070Multiple bbe-smgd cores might be observed resulting in subscribers being lost or failing to login in the Enhanced subscriber scenario
Product-Group=junos
On MX platforms, multiple bbe-smgd cores might be observed due to out-of-bound memory access in the Enhanced subscriber scenario when bringing up PPPoE (Point-to-Point Protocol over Ethernet) subscribers and ACI (agent circuit identifier)/ARI (agent remote identifier) are part of the payload.

Resolved In: evo:22.1R3-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:19.4R3-S10 junos:19.4R3-S5-J1 junos:20.2R3-S4-J9 junos:20.2R3-S6 junos:20.3R3-S6 junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S3 junos:21.4R3-S1 junos:22.1R3 junos:22.2R2 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: QFX L2 PFE
1499681Junos OS and Junos OS Evolved: QFX5K Series: Underlay network traffic might not be processed upon receipt of high rate of specific genuine overlay packets in VXLAN scenario (CVE-2021-0259)
Product-Group=junos
Due to a vulnerability in DDoS protection in Juniper Networks Junos OS and Junos OS Evolved on QFX5K Series switches in a VXLAN configuration, instability might be experienced in the underlay network as a consequence of exceeding the default ddos-protection aggregate threshold. Refer to https://kb.juniper.net/JSA11150 [juniper.net] for more information.

Resolved In: evo:20.1R3-EVO evo:20.2R3-EVO evo:20.3R2-EVO evo:20.4R1-EVO junos:17.3R3-S11 junos:17.4R3-S5 junos:18.1R3-S13 junos:18.2R2-S8 junos:18.2R3-S8 junos:18.3R3-S5 junos:18.4R1-S8 junos:18.4R2-S6 junos:18.4R3-S6 junos:19.1R3-S4 junos:19.2R1-S6 junos:19.2R3-S2 junos:19.3R2-S6 junos:19.3R3-S2 junos:19.4R2-S4 junos:19.4R3-S1 junos:20.1R2 junos:20.2R2 junos:20.2R3 junos:20.3R1-S2 junos:20.3R2 junos:20.4R1
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1666260Traffic loss might be seen when l2circuit configurations are deactivated and activated on QFX5110
Product-Group=junos
On QFX5110 platforms with more than one l2circuit configured, deactivating and activating the l2circuit configurations successively might cause traffic drop on one or more l2circuits.

Resolved In: 
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1667206Traffic loss between different subnets in IRB VxLAN scenario
Product-Group=junos
On QFX5110 platforms, traffic loss occurs between different subnets if IRB (Integrated Routing and Bridging) is configured on VxLAN (Virtual Extensible LAN) and an untagged packet is routed by the IRB to type-5 or ARP-NDP next-hop.

Resolved In: junos:21.4R3
PR NumberSynopsisCategory: Resource Reservation Protocol
1657872Memory utilization keeps incrementing due to the path error message
Product-Group=junos
On all Junos and Junos Evolved platforms, when a no-cspf Label Switched Path (LSP) with strict Explicit Route Object (ERO) is configured and the egress device is disconnected, a high rate of Path Error (PathErr) messages are observed which is leading to high memory utilization and triggering the chassisd crash that causes the device to be out of control, either it can not be accessible via console/ssh or it will not trigger Routing Engine (RE) switchover as well if it is dual-RE. So this would cause an outage.

Resolved In: evo:21.4R3-EVO evo:22.1R3-EVO evo:22.2R2-EVO evo:22.3R1-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:21.2R3-S4 junos:21.3R3-S3 junos:21.4R3 junos:22.1R3 junos:22.2R2 junos:22.3R1 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1701183Traffic loss is seen due to interface flap when changing speed from 10G and 1G
Product-Group=junos
On Junos MX204/MX10003, traffic loss is seen on 4x10G Channelized interfaces when the speed is changed from 10G to 1G on one lane which causes the other 3 lanes to flap and stay down.

Resolved In: evo:22.2R3-EVO evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:21.1R3-S5 junos:21.2R3-S3-J2 junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1692070The firewall bridge filter policers (attached to AE interface) are not working on all Junos MX platform with MPC10 card upon deactivate-activate a term intended to limit overall traffic
Product-Group=junos
Traffic policing will not work as expected on all Junos MX platform with MPC10 card after doing deactivation-activation of the term intended to limit overall traffic when the firewall and policers are applied to the bridge unit using shared-bandwidth-policers on AE (Aggregated Ethernet) interface.

Resolved In: evo:22.3R3-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1674217OSPF state stuck in Init state in IGMP-snooping enabled scenario
Product-Group=junos
On MPC10E and above (MPC11E) line card supported platforms, host injected multicast control packets via IRB (Integrated routing and bridging) will get dropped.

Resolved In: evo:22.1R3-EVO evo:22.2R2-EVO evo:22.3R1-EVO evo:22.4R1-EVO junos:21.4R2-S2 junos:21.4R3 junos:22.1R3 junos:22.2R2 junos:22.3R1 junos:22.4R1
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1713958Unexpected load balancing of packets having GRE header
Product-Group=junos
On all Junos and Junos Evolved platforms, incorrect load balancing of packets is observed when the transit packet with GRE (Generic Routing Encapsulation) header having any header fields (checksum, sequence number, etc) other than GRE key is present.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.2R3-S5 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1522896Egress traffic loss might happen because of PFE MTU feature problem
Product-Group=junos
On MX and EX9200 serial platforms, under Ethernet VPN (EVPN) environment, packets routed using IRB interface could not be fragmented due to media maximum transmission unit (MTU) problem.

Resolved In: junos:18.4R2-S5-J1 junos:20.4R3-S4-J3 junos:21.2R3-S3 junos:21.2R3-S4 junos:21.3R3-S2 junos:21.4R3-S2 junos:22.1R3-S1 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:22.4R2
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1700203DHCP offer requests are dropped while routed towards different VRFs of transit router
Product-Group=junos
On all Junos platforms with route leaking and no-snoop configuration, DHCP (Dynamic Host Configuration Protocol) offer requests could be dropped while traversed to different VRFs (Virtual Routing and Forwarding) from default RI (Routing Instance).

Resolved In: junos:20.4R3-S8 junos:21.4R3-S4 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1717425Junos platform device unable to commit configuration in recovery mode
Product-Group=junos
On all Junos platforms where snapshot is supported, when a device is rebooted from recovery mode it fails to commit configuration due to problems with slax import and device might go into amnesiac mode due commit fail.

Resolved In: junos:20.3X75-D43 junos:22.2R3-S1
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1679794The SDPD crash can be seen in Junos Fusion environment
Product-Group=junos
On all Junos Fusion platforms, SDPD (Satellite Discovery and Provisioning Daemon) crash will be observed on the aggregation device (AD) while sending discovery packets for satellite device(SD) provision. Satellite provisioning will not be completed due to this issue and the SD cannot be managed from the AD.

Resolved In: evo:22.3R3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: MX10K linecard
1688651JUNOS_REG:MX10008:Carrier transition count is more than expected at DUT(mx10008) after flapping the interface at peer non-DUT end.
Product-Group=junos
When laser off and on happens on the remote end, within an interval of less than 500 ms, the local interface undergoes additional flap, before the link comes up. There is no impact of the additional flap, as the link does come up eventually.

Resolved In: 
PR NumberSynopsisCategory: Xellent Platform issues
1636560Channelized ports on QFX10002-60c platforms could drop traffic
Product-Group=junos
On QFX10002-60c Junos based platforms, there is unexpected packet loss if channelized ports et-0/0/32:1 and et-0/0/32:3 are used. Please refer to workaround to prevent this issue from happening.

Resolved In: junos:21.2R2-S1 junos:21.2R3 junos:21.3R2 junos:21.3R3-S4 junos:21.4R2 junos:21.4R3-S4 junos:22.1R1
PR NumberSynopsisCategory: usf nat related issues
1612555The B4 client traffic will be dropped on MX-SPC3 based AFTR in DS-Lite with EIM activated CGNAT scenario
Product-Group=junos
In MX-SPC3 with Dual-Stack Lite (DS-Lite) scenario, the IPv4 client will use Basic Bridging BroadBand (B4) to pass through IPv4-over-IPv6 tunnels to cross an IPv6 access network to reach a Carrier-grade NAT (CGNAT) network behind the Address Family Transition Router (AFTR). In case of the Endpoint independent mapping (EIM) is activated for CGNAT, the DS-Lite encapsulated IPIP packets might not be identified by EIM for some reason, and the NAT rule might not be found properly by MX-SPC3 of AFTR for the mapping traffic. After that, the DS-Lite tunnels/NAT sessions between the B4 and AFTR might not be established successfully since the DS-Lite/NAT packets might be dropped on AFTR, the IP flow from the B4 client will be impacted.

Resolved In: junos:20.2R3-S3 junos:20.4R3-S1 junos:21.1R2-S1 junos:21.1R3 junos:21.2R2 junos:21.2R3 junos:21.3R2 junos:21.4R1 junos:22.1R1

Modification History

First publication 2023-05-08