Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX EX MX NFX PTX QFX SRX vSRX
Alert Description
Junos Software Service Release version 20.2R3-S8 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 20.2R3-S8 is now available.
20.2R3-S8 - List of Fixed issues
PR Number
Synopsis
Category: JUNOS bugs found in UAC integration
1692398
Connection fails are observed on Junos despite a valid auth entry
Product-Group=junos
On Junos platforms, authentication failures and connection drops are observed for a few users when UAC (Unified Access Control) modules fail to look up the roles.
PR Number
Synopsis
Category: EX4300 PFE
1722284
Native VLAN traffic is getting dropped in the Q-in-Q scenario on EX4300
Product-Group=junos
On Junos EX4300-24T/24P when the native CVLAN (Customer Virtual Local Area Network) ID is configured for Q-in-Q setup, the traffic for that particular VLAN gets dropped even if the knob "input-native-vlan-push" is configured. This issue is encountered when the when inner-tag matches 'native-vlan-id' irrespective of the outer tag.
PR Number
Synopsis
Category: australia related kernel issue
1714002
vmcores can be seen on SRX5k platforms when the fxp0 interface is configured under management-instance
Product-Group=junos
On Junos SRX5K series platforms, when the 'set system management-instance' command is committed on the secondary node, continuous VMcores are observed on the secondary node leading to the kernel crash. The secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until management-instance knob is removed using "delete system management-instance".
PR Number
Synopsis
Category: Control Plane and Infrastructure for the Junos Fusion Enterprise
1577977
There might be memory leak observed in Junos Fusion satellite device for cpd process
Product-Group=junosvae
On Junos Fusion Enterprise setup, the cpd daemon running on SD (Satellite Device) attempts to establish connection with scpd (which is not present). This results in cpd memory utilization piling up on the SD node. Since the memory leak appears to be small, the impact of leak is noticed only on prolonged run.
PR Number
Synopsis
Category: BBE dynamic profile related issues
1714778
PPPoE and DHCP subscriber connection on dynamic VLAN can fail on Junos MX platforms
Product-Group=junos
On Junos MX platforms supporting subscriber services, cleanup of a dynamic VLAN (Virtual Local Area Network) session may fail if SDB (Subscriber Database) becomes briefly unavailable. The dynamic VLANs will stay in an active state, but all PPPoE (Point to Point Over Ethernet) and DHCP (Dynamic Host Configuration Protocol) subscriber connection attempts over this VLAN will fail.
PR Number
Synopsis
Category: Border Gateway Protocol
1669716
The rpd crash is observed while making configurational changes
Product-Group=junos
On all Junos and Junos Evolved platforms, which supports protocol BGP (Border Gateway Protocol), RPD (Routing Protocol daemon) crash is seen when a eBGP peering interface is moved to a "no-forwarding" instance and resetting the BGP peer.
1679646
The AGGREGATOR attribute will not be set correctly when the independent-domain is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in BGP(Border Gateway Protocol) deployments with the "independent-domain" and aggregate routes configured under routing-instance, the AGGREGATOR attribute encapsulated within the ATTR_SET will not be populated correctly. This can result in unintended behavior or service impact because the BGP neighbors receiving this update may discard it as it is not RFC complaint.
PR Number
Synopsis
Category: Enhanced Broadband Edge support for cos
1713968
Subscribers connectivity is lost due to multiple MIC restart on all Junos MX platforms with MPC5E and BBE configuration
Product-Group=junos
On all Junos MX platforms with MPC5E and BBE (Broadband Edge) configuration, subscribers connectivity will be lost due to multiple MIC (Modular Interface Card) restart.
PR Number
Synopsis
Category: Device Configuration Daemon
1682271
Node Slicing: In a rare scenario, the FPC/SLC will get stuck in the ready state after a restart
Product-Group=junos
On Junos MX platforms, in a rare scenario, FPC/SLC (Flexible PIC Concentrator/Sub Line Card) may get stuck in the ready state after restarting it and the error message of 'Device busy' will be observed in Syslog.
PR Number
Synopsis
Category: Firewall Filter
1697959
Deactivating and activating the GRES causes churn in dfwd filter addition/deletion
Product-Group=junos
On all Junos dual-RE platforms, when performing activate/deactivate Graceful Routing Engine Switchover (GRES) multiple times synchronization issues are observed between the master and backup dfwd process.
PR Number
Synopsis
Category: EA chip ( MQSS SW issues )
1591905
The subscribers might not come online after interface flaps on MX platforms
Product-Group=junos
On MX platforms in BNG scenario, all subscribers under the interface of MPC3D 16x10GE/MPC1/MPC2 line cards might not be able to login after interface flaps.
PR Number
Synopsis
Category: EVPN control plane issues
1723832
The rpd core is seen in the long-running devices with EVPN enabled
Product-Group=junos
On Junos and Junos Evolved platforms, BGP (Border Gateway Protocol) community object reference count is not handled properly during the process of remote BGP peer routes update event. The community reference count is increasing during the increment function. However, decrement functions are not called in one of the places after processing the routes update. This will lead to a disturbance of the continuity reference count, which will cause an rpd crash.
PR Number
Synopsis
Category: Express ASIC platform
1683562
On PTX5000 platforms when a command is issued to power off an FPC, it gets stuck in the 'Announce Offline' state
Product-Group=junos
When an FPC (Flexible PIC Concentrator) on PTX5000 platforms is shut down by issuing a request command (request chassis offline slot ) or by FPC power off configuration (set chassis fpc x power off), it gets stuck in the 'Announce Offline' state since the associated timer (fru_graceful_offline_timer) doesn't increment and expire as it is supposed to.
PR Number
Synopsis
Category: ISIS routing protocol
1677567
Label traffic will be dropped at the one-hop LSP stitching node if the packet has more than one label
Product-Group=junos
On all Junos and Junos Evolved platforms supporting the Segment Routing (SR) feature, when segment routing and Label Distribution Protocol (LDP) stitching are configured, the label traffic drop is observed at the one-hop Label Switched Path (LSP) stitching node when the labeled packet is received with more than one label.
PR Number
Synopsis
Category: jl2tpd daemon
1667950
VMcore or RE crash might be triggered due to the memory corruption when the FPC is restarted for LNS subscribers
Product-Group=junos
On all MX platforms, when Flexible PIC Concentrators (FPCs) restart for L2TP network server (LNS) subscribers stacked over aggregated service interface (asi) and LNS subscribers belong to more than one routing instance causes the VMcore or Routing Engine (RE) crash and brings down all the traffic.
PR Number
Synopsis
Category: jpppd daemon
1686940
Subscribers will fail to negotiate the PPP session and be unable to login post-software upgrade
Product-Group=junos
On MX platforms with Subscriber Management configured, the subscribers will fail to negotiate the PPP (Point-to-Point Protocol) session and be unable to login when jpppd transitions from Backup to Master and does not receive all the Routing Table events from Kernel post upgrade.
PR Number
Synopsis
Category: Security platform jweb support
1712454
[Jweb] "address-book attach zone" is unexpectedly removed when address-book entry is added or removed by Jweb
Product-Group=junos
On SRX platform series, when address-book entry is added or removed by Jweb, "address-book attach zone" might be unexpectedly removed at configuration commit.
PR Number
Synopsis
Category: PFE infra to support jvision
1485739
Subscribing to /linecard/packet/usage and triggering the UDP decoder, the hardware statistics are exported with improper hierarchy
Product-Group=junos
The wrong hardware stats might be seen when enabling CLI for hardware sensors along with telemetry.
PR Number
Synopsis
Category: Key Management Daemon
1719216
A stale nat-long-route entry is present in the device causing incoming packets to be dropped
Product-Group=junos
On all MX platforms with MS-MPC cards, When there is an active NAT (Network Address Translation) enabled IPSec (IP security) tunnel already present for a particular service-set, any change in the outside logical interface (IFL) becomes a stale entry in the forwarding table causing IKE (Internet Key Exchange) control and data traffic to drop.
PR Number
Synopsis
Category: Layer 2 Circuit issues
1691295
Post FPC restart CCC status is getting wrongly updated on the local interface
Product-Group=junos
On all Junos and Junos Evolved platforms in the L2VPN (Layer 2 Virtual Private Network) scenario, the CCC (Circuit Cross-Connect) link status will remain up after the FPC (Flexible PIC Concentrators) restart, when the CCC status is down between the local PE-CE link.
PR Number
Synopsis
Category: Layer 2 Control Module
1717267
Traffic loop is seen due to incorrect root bridge ID
Product-Group=junos
On all Junos and Junos Evolved platforms, in VSTP (Virtual Spanning-Tree Protocol) topology, whenever a new vlan is added in between previously configured vlan group followed by configuring the system-identifier, the bridge priority will change for existing vlans which might give incorrect system ID or bridge ID creating a traffic loop.
PR Number
Synopsis
Category: lacp protocol
1609618
LACP Member interfaces might get stuck in out of sync state.
Product-Group=junos
When sync-reset feature is enabled on the device then few member interfaces might stay in out of sync state even when number of available child interfaces is greater than minimum-links configured for the Lag interface. This will affect the overall capacity of the lag interface .
PR Number
Synopsis
Category: SW PRs for MPC10E Interfaces
1678716
'show interfaces diagnostics optics ' shows all 0 on 100/400G port on MPC10E card.
Product-Group=junos
On MPC10E card, the port 4 can operation in either 100G or 400G speed. In certain scenario a stale QSFP56 identifier is left in PFE. It can cause the "show interfaces diagnostics optics " shows all 0 even if 100G QSFP-28 is inserted and the port is up.
PR Number
Synopsis
Category: Track Mt Rainier SPMB platform software issues
1637950
SPMB might crash immediately after a switchover
Product-Group=junos
On the PTX5000 line of routers with dual Routing Engines and equipped with SPMB type PTX5K CB PMB, immediately after a switchover, if the new primary Switch Processor Mezzanine Board (SPMB) finds any CB-to-SIB PCI (Control Board - Switch Interface Board Peripheral Component Interconnect) link down error, then the new primary SPMB might crash. This causes the device to silently discard packets for about 2-3 minutes while the Switch Interface Boards (SIBs) are re-initialized.
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1669072
Junos OS: NFX Series: 'set system ports console insecure' allows root password recovery (CVE-2023-28972)
Product-Group=junos
An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. Please refer to https://supportportal.juniper.net/
JSA70596
[juniper.net]
for more information.
1704032
VM process crashes if a file is shared between the host operating system and the guest operating system using virtFS
Product-Group=junos
On Virtual Machines (VM) based platforms running Junos images, files are not shared between the host operating system and guest operating system via Virtual Filesystem (virtFS). When this issue happens, the device will be restarted.
PR Number
Synopsis
Category: QFX PFE Class of Services
1641572
Traffic failure with error message 'Buffers are stuck on queue' after removing and attaching 100G QSFP
Product-Group=junos
On QFX5110, traffic failure may be observed after removing and attaching 100G QSFP.
PR Number
Synopsis
Category: QFX5K hostpath
1723465
PFE crash is seen on Junos when file-logging is disabled
Product-Group=junos
On Junos QFX5K platforms, when file-logging is enabled for ukern_trace handle and the logs are written continuously to the corresponding buffer due to a network issue, disabling file-logging for that handle will cause a PFE crash and will lead to a complete traffic loss.
PR Number
Synopsis
Category: QFX L2 PFE
1694076
PFE crash is seen on all Junos QFX5K and EX46xx platforms with L2PT configuration
Product-Group=junos
PFE (Packet Forwarding Engine) crashes on all Junos QFX5K and EX46xx platforms when L2PT (Layer 2 Protocol Tunneling) is configured on the interface having flexible-vlan-tagging with encapsulation extended-vlan-bridge. It causes a traffic impact.
1705853
Tracking PR to add the null check for list_get_head if magic is NULL.
Product-Group=junos
On all Junos platforms, as list_get_head function is called in multiple places in pfe we needed previous 3 functions on the stack which had called list_get_head, so we could debug why 'list_get_head list has bad magic' this error has occured.
PR Number
Synopsis
Category: QFX L3 data-plane/forwarding
1666260
Traffic loss might be seen when l2circuit configurations are deactivated and activated on QFX5110
Product-Group=junosvae
On QFX5110 platforms with more than one l2circuit configured, deactivating and activating the l2circuit configurations successively might cause traffic drop on one or more l2circuits.
1724675
Traffic loss will be observed with vlan tagging and/or vlan normalisation in a specific design (using a looped cable)
Product-Group=junos
Upon upgrade to Junos versions (junos:20.3R2, 20.3R3, 20.3X75-D20, 20.4R2, 21.1R1, 21.2R1), network connectivity is lost for traffic requiring vlan normalization and having DMAC one of the switch's MAC addresses. For example, incoming traffic has two vlans (S-vlan, C-vlan) ingressing on an interface and switch uses a looped link to provide routing via an IRB. --- (S-vlan|C-vlan) -- -> SW_X --- C-vlan -- -> SW_X_irb ARP and L2 learning occurs as expected but upon receiving the frame with DMAC of a local interface, switch takes a route lookup action instead of bridging and vlan normalization due to the frame having DMAC as the MAC of one of its interfaces. Hence, the traffic is not sent via looped cable to the L3 interface.
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1712405
VXLAN traffic gets dropped after new L3 VLANs are created
Product-Group=junos
Traffic black-holing in EVPN (Ethernet VPN) fabric when performing configuration of new VLANs, it is found that L3 VLANs are having IPV4 bits disabled.
PR Number
Synopsis
Category: QFX5100 Interface related issues
1665800
Ports with SFP-T 1G plugged in may go to hung state on QFX5100 platforms
Product-Group=junos
When the remote end server/system reboots, QFX5100 platform ports with SFP-T 1G inserted may go into a hung state and remain in that state even after the reboot is complete. This may affect traffic after the remote end system comes online and resumes traffic transmission.
PR Number
Synopsis
Category: QFX5100 Virtual Chassis
1679919
PFE process crash might be observed on QFX5100 platforms
Product-Group=junosvae
On QFX5100 platforms (both stand-alone and VC scenario) running Junos, occasionally during the normal operation of the device, PFE (Packet Forwarding Engine) can crash resulting in total loss of traffic. The PFE reboots itself following the crash.
PR Number
Synopsis
Category: RPD infrastructure issues related to NSR, GRES, switchover,
1701146
The rpd crash will be observed when any commit is performed
Product-Group=junos
On all Junos and Evolved platforms with RSVP auto-mesh dynamic tunnel configuration, whenever a commit is done the rpd (Routing Process Daemon) crash will be seen. This happens due to null pointer access in the memory.
PR Number
Synopsis
Category: RPD Next-hop issues including indirect, CNH, and MCNH
1645296
Traffic drop with EBGP multipath and EBGP paths equal to the maximum-ecmp limit
Product-Group=junos
On all Junos and Junos Evolved platforms configured with EBGP multipath and bgp-protect-core under the routing instance, if the number of external paths along with the BGP Prefix-Independent Convergence (PIC) backup paths reaches the maximum ECMP limit, then all the traffic towards the destination is dropped on the Packet Forwarding Engine with the exception of "sw error".
PR Number
Synopsis
Category: RPD route tables, resolver, routing instances, static routes
1687884
The traffic drops are seen for the static route after VRRP failover when VRRP VIP is set as next-hop for that static route
Product-Group=junos
On all Junos and Junos OS Evolved platforms, the next-hop for a static route does not refresh at PFE (Packet Forwarding Engine) after VRRP (Virtual Router Redundancy Protocol) failover when VRRP VIP (Virtual-IP) address is used as the next-hop for the static route.
PR Number
Synopsis
Category: Resource Reservation Protocol
1657872
Memory utilization keeps incrementing due to the path error message
Product-Group=junos
On all Junos and Junos Evolved platforms, when a no-cspf Label Switched Path (LSP) with strict Explicit Route Object (ERO) is configured and the egress device is disconnected, a high rate of Path Error (PathErr) messages are observed which is leading to high memory utilization and triggering the chassisd crash that causes the device to be out of control, either it can not be accessible via console/ssh or it will not trigger Routing Engine (RE) switchover as well if it is dual-RE. So this would cause an outage.
PR Number
Synopsis
Category: Secure Web Proxy functionality on Junos
1719703
The flowd process crash is observed when the web proxy packet reinjection fails
Product-Group=junos
On SRX-branch series, SRX4100, SRX4200, and vSRX platforms, packet reinjection fails if the load on the system is high and the web proxy tries to reinject the packet.
PR Number
Synopsis
Category: IPSEC functionality on M/MX/T ser
1630070
The kmd process might crash with core files every few minutes on MX Series routers
Product-Group=junos
On MX Series routers in the IPSEC VPN scenario, the kmd process might crash every few minutes due to a timing issue in the establishment phase, which leads to IPSEC VPN flapping.
PR Number
Synopsis
Category: SRX branch platforms
1658276
The reth member interface does not come up due to speed mismatch after RG0 failover
Product-Group=junos
On SRX series platform with chassis cluster enabled, the reth (Redundant Ethernet) interface might not come up due to speed mismatch when the reth interface speed is changed after RG0 (redundancy group) failover.
PR Number
Synopsis
Category: Stout cards (MPC7, MPC8, MPC9) microkernel issues
1727427
FPC crash observed when the ASIC usage is high
Product-Group=junos
On platforms with MS-MPC/MPC1/2/3/4/5/6/7/8/9 line cards and EX9200/EX9204/EX9208/EX9214/EX9251/EX9253 series devices, route churn (add or deletes) when the ASIC usage crosses a threshold (ASIC usage is high) which leads to a FPC crash.
PR Number
Synopsis
Category: SRX-1RU platfom related protocol, QoS, filtering features et
1712727
Continuous vmcores observed on the secondary node when committing set system management-instance command
Product-Group=junos
On Junos SRX4600 device, when the "set system management-instance" command is synced to the secondary node, continuous VMcores are observed on primary and secondary nodes. The secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until management-instance knob is removed using "delete system management-instance"
PR Number
Synopsis
Category: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1703910
The line card abruptly reboots when ISSU is performed
Product-Group=junos
On platforms supporting MPC3E/MPC4E/T4000-FPC5/EX9200-4QS/EX9200-2C-8XS/EX9200-MPC/EX9200-32XS/SRX5K-SPC-4-15-320/SRX5K-MPC, the line card abruptly rebooted with a process crash when ISSU (In-Service Software Upgrade) is performed without properly disabling Jflow.
1718595
Subscribers disruption is seen on the AE interface after the "disable-pfe" action
Product-Group=junos
On all MX platforms with MPC7/8/9/LC2101/LC2103 line cards, when a "disable-pfe" action is executed for major cmerrors, there will be improper flagging of timeouts and incorrect logging out for all subscribers in scenarios where an AE(Aggregated Ethernet) interface is present on the disabled PFE(Packet Forwarding Engine).
PR Number
Synopsis
Category: Junos Automation, Commit/Op/Event and SLAX
1717425
Junos platform device unable to commit configuration in recovery mode
Product-Group=junos
On all Junos platforms where snapshot is supported, when a device is rebooted from recovery mode it fails to commit configuration due to problems with slax import and device might go into amnesiac mode due commit fail.
20.2R3-S8 - List of Known issues
PR Number
Synopsis
Category: EX2300/3400 platform
1555487
The console might hang up with the knob 'set system ports console log-out-on-disconnect' configured
Product-Group=junos
On EX2300/EX3400 platforms, with the knob 'set system ports console log-out-on-disconnect' configured, the console might hang up when configuring the password for the root-level user by 'set system root-authentication plain-text-password'.
Resolved In:
junos:20.4R2 junos:21.1R1
PR Number
Synopsis
Category: Anything related to Multicast
1461339
Mcast traffic drops is observed with the following error message: brcm_rt_ip_mc_ipmc_install.
Product-Group=junos
Following two Failure messages seen brcm_rt_ip_mc_ipmc_install:2455 Failed (Invalid parameter:-4) This message is due to IPMC Group being used is not created, when RE tried to add this check indicates there is a parameter mis-match. brcm_rt_ip_mc_ipmc_install:2455 Failed (Internal error:-1) This message is due to Failure to read IPMC Table or any memory/register
Resolved In:
PR Number
Synopsis
Category: BBE OS Infrastructure library
1732216
'max-db-size' configuration is optional in routers having DRAM greater than or equals to 32GB
Product-Group=junos
On Junos MX platforms, to enable Enhanced Subscriber Management feature without 'max-db-size' configuration on router >=32GB DRAM(Dynamic Random Access Memory), router needs to be rebooted only once instead of rebooting twice.
Resolved In:
evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:20.2R3-S4-J9 junos:21.2R3-S5-J3 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1
PR Number
Synopsis
Category: Border Gateway Protocol
1565762
RPD can core when BGP session is flapping multiple times in quick succession with deletion of the associated BGP neighbor object happening simultaneously
Product-Group=junos
When BGP session with a peer flaps multiple times in quick succession and in parallel (1) catastrophic configuration change of BGP parameters of the BGP session is done or (2) the BGP peer object gets deleted due to the BGP peer being an 'allow' peer (dynamically created based on connection request from the peer it is possible for BGP to access stale freed/reallocated memory as part of clean-up processing of the prior associated I/O session object leading to RPD coredump.
Resolved In:
evo:20.4R2-EVO evo:21.1R1-EVO evo:21.2R1-EVO junos:20.3R2 junos:20.3R3 junos:20.4R2 junos:21.1R1 junos:21.2R1
1690213
BMP will not send EOR message
Product-Group=junos
On all Junos and Junos Evolved platforms, BMP(BGP Monitoring Protocol) will not send EOR(End of RIB) message for some releases. This will impact some data collections.
Resolved In:
evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:22.2R3 junos:22.3R2 junos:22.4R2 junos:23.1R1 junos:23.2R1 junos:23.3R1
1705938
The BGP sessions will flap after the RE switchover
Product-Group=junos
On all Junos and Junos OS Evolved platforms with dual RE (Routing Engine) or VC (Virtual Chassis) with NSR enabled scenarios, in some rare BGP scaled scenarios upon RE switchover the new Master RE will send out a route refresh message to all the peers, which is not expected. This will eventually lead to the BGP session flap.
Resolved In:
evo:22.3R3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.2R3-S5 junos:22.2R3-S1 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR Number
Synopsis
Category: PTX10003 Interface related issues
1580113
JVISION optics sensor's alarm data type changed from " bool_val" to "str_val"
Product-Group=junos
it changes the format specifier of alarms from string to boolean for following leafs. lane_tx_loss_of_signal_alarm lane_rx_loss_of_signal_alarm lane_tx_laser_disabled_alarm
Resolved In:
evo:20.4R2-EVO evo:21.2R2-EVO evo:21.3R1-EVO evo:21.4R1-EVO junos:20.4R3 junos:21.2R2 junos:21.3R1 junos:21.4R1
PR Number
Synopsis
Category: BBE Remote Access Server
1697392
A few subscriber sessions will not be up post RE switchover
Product-Group=junos
On MX platforms, in a high scale subscriber scenario with close to 100% address pool utilization, when the session table and the IP pool database are out of sync and a switchover is performed, authd assigns an in-used IP address to the new subscriber session. This issue doesn't have an impact on existing subscribers but is not able to keep the new sessions up.
Resolved In:
evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.4R3-S8 junos:21.2R3-S2-J23 junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S2-J4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
1723183
Subscriber sessions will fail to login post GRES and scaled subscriber scenario
Product-Group=junos
On MX platforms in a scaled subscriber scenario (8K subscribers) and post GRES (Graceful Routing Engine Switchover), the session database and IP pool database can get out of sync on the backup RE if there is a subscriber churn. After the RE switchover, this condition will lead to the immediate termination of new subscriber sessions if the assigned IP address is still in use by an existing subscriber.
Resolved In:
evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:20.4R3-S8 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S2-J4 junos:22.1R3-S3 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1
PR Number
Synopsis
Category: QFX52xx platforms Interface running EVO
1545455
The chip on FPC line card might crash when the system reboots.
Product-Group=junos
On the FPCs with Broadcom chip, if the jinsightD (health-mon) is not disabled ("set system processes health-mon disable"), the FPC might crash during the system booting. Traffic loss is seen during the FPC crash and restart.
Resolved In:
evo:20.1R3-EVO evo:20.2R3-EVO evo:20.3R2-EVO junos:18.3R3-S4 junos:18.4R2-S9 junos:19.1R3-S4 junos:19.2R3-S2 junos:19.3R3-S2 junos:19.4R3 junos:20.1R2 junos:20.1R3 junos:20.2R2 junos:20.2R3 junos:20.3R1-S1 junos:20.3R2 junos:20.3X75-D10 junos:20.4R1 junos:21.1R1
PR Number
Synopsis
Category: MX Platform SW - FRU Management
1676008
FPC stuck in present state with log " graceful offline in progress, returning false" flooding
Product-Group=junos
In an over-temperature situation, there will be a 10s timer before the device brings the FPC down. However in some situation due to high temperature, an FPC offline action will be triggered before the 10s timer expires. Then the FPC will stuck in the Present/Announce offline state. Cli offline/online or physical reseat will not be able to recover the issue.
Resolved In:
evo:22.1R3-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:19.2R3-S5-J2 junos:20.2R3-S3-J9 junos:20.2R3-S5-J5 junos:20.4R3-S5 junos:21.2R3-S3 junos:21.3R3-S3 junos:21.4R3 junos:21.4R3-S4 junos:22.1R3 junos:22.2R1-S2 junos:22.2R2 junos:22.2R3 junos:22.3R2 junos:22.4R1
PR Number
Synopsis
Category: SRX4100/SRX4200 platform software
1630981
BGP down due to BFD expired; failover restored services
Product-Group=junos
All VPN traffic may internally drop during encryption / decryption processing in HW engine requiring PFE plane reset.
Resolved In:
junos:20.4R3-S7 junos:21.4R3-S3 junos:23.2R1 junos:23.3R1
PR Number
Synopsis
Category: ISIS routing protocol
1723172
The rpd process crash is observed when TI-LFA feature is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms with TI-LFA (Topology-Independent Loop-Free Alternate) feature enabled, when IP address is removed from one interface and is assigned to another interface in the same commit, the rpd process crashes affecting routing control plane.
Resolved In:
evo:23.3R1-EVO junos:23.3R1
PR Number
Synopsis
Category: SW PRs for MPC10E Interfaces
1642584
MPC10E: Quick 100G link-flaps has still some race conditions which can cause MQSS stream drain failures and xqss_sched_flush_queue failures
Product-Group=junos
On MPC10E cards upon many very quick link down and up events in msec range might not always able to drain all traffic in the queue. This causes lost of traffic going through the interface. Traffic volume and class-of-service configuration does influence the exposure. See also PR1638410.
Resolved In:
evo:22.1R3-EVO evo:22.2R2-EVO evo:22.2R3-EVO evo:22.3R1-EVO junos:20.2R2-S2-J2 junos:20.4R3-S6 junos:21.1R3-S5 junos:21.2R3-S1 junos:21.4R3-S2-J6 junos:21.4R3-S3 junos:22.1R2 junos:22.1R3 junos:22.2R2 junos:22.2R3 junos:22.3R1
1688972
PFE wedge will be seen due to fast link flaps
Product-Group=junos
When the 10/40/100G links of the same PFE (Packet Forwarding Engine) on MPC10E/MPC11E/LC2301/MX10K-LC9600 line cards flap continuously, the whole PFE can wedge and all the links in that PFE will be affected.
Resolved In:
evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S2-J8 junos:21.2R3-S3-J10 junos:21.2R3-S4 junos:21.4R3-S3 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR Number
Synopsis
Category: Odin Timing software
1632761
ACX710 running G.8275.2 stuck at PTP Acquiring state if the connection is through some timing unaware nodes
Product-Group=junos
On the ACX710 platform, in Precision Time Protocol (PTP) with G.8275.2 profile scenario where topology has some intermediate non-PTP aware nodes, the clock might be stuck in ACQUIRING state.
Resolved In:
junos:21.2R2-S1 junos:21.2R3 junos:21.3R2 junos:21.4R2 junos:22.1R1
PR Number
Synopsis
Category: Category for tracking Olympus-MX issues
1671649
Traffic loss may be seen due to SPC3's packets getting stuck
Product-Group=junos
On Junos MX960, MX480 and SRX5000 series platforms with SPC3 card, Flowd restart or PIC (Physical Interface Card) going offline/online may cause SPC3's sending of packets to get stuck.
Resolved In:
evo:22.1R3-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S3 junos:21.4R3-S1 junos:22.1R2-S1 junos:22.1R3 junos:22.2R1-S2 junos:22.2R2 junos:22.2R3 junos:22.3R1-S1 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1568757
The image validation is not supported during upgrading from Pre 21.2 to 21.2 and onward
Product-Group=junos
When upgrading from releases before Junos OS Release 21.2 to Release 21.2 and onward, validation and upgrade might fail. The upgrade requires using the 'no-validate' option to complete successfully. https://kb.juniper.net/
TSB18251
[juniper.net]
Resolved In:
PR Number
Synopsis
Category: vMX Data Plane Issues
1669261
vMX crashes due to MBUF leaks
Product-Group=junos
vMX platforms (MX150) will crash as a result of the MBUF (Memory Buffer) leak.
Resolved In:
junos:20.3X75-D43 junos:20.3X75-D46 junos:20.4R3-S5 junos:21.4R3 junos:22.1R3 junos:22.3R1 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:23.1R1
PR Number
Synopsis
Category: Issues related to PKI daemon
1509250
The PKI key-pair and certification might not be synchronized to the new RE
Product-Group=junos
In IPsec VPN with PKI (Public Key Infrastructure) scenario, if the hardware of RE is replaced with the new same model or zeroized, the PKI certificate/key-pair might not be synchronized to this RE, because some appropriate files related to certificate/key-pair might not be replicated correctly. Then the IPsec VPN tunnel might be failed.
Resolved In:
junos:20.3R2 junos:20.4R1
PR Number
Synopsis
Category: JRR - VRR running on SRX4200
1677503
Junos OS: JRR200: Kernel crash upon receipt of a specific packet (CVE-2023-28970)
Product-Group=junos
An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing on the network interfaces of Juniper Networks Junos OS on JRR200 route reflector appliances allows an adjacent, network-based attacker sending a specific packet to the device to cause a kernel crash, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/
JSA70594
[juniper.net]
for more information.
Resolved In:
junos:21.2R3-S4 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R2-S2 junos:22.2R3 junos:22.3R1-S2 junos:22.3R2 junos:22.3R2-S1 junos:22.3R3 junos:22.4R1-S1 junos:22.4R2 junos:23.1R1
PR Number
Synopsis
Category: Periodic Packet Management Daemon
1619886
BFD sessions flaps are observed on scaled setups if PFE restarts
Product-Group=junos
BFD sessions flap can be seen on a scaled setup when a PFE is restarted. The issue state can be confirmed if the peer IPs are observed more than once on the ppm entries, each IP should appear only once per routing instance.
Resolved In:
evo:21.1R3-EVO evo:21.2R3-EVO evo:21.3R2-EVO evo:21.4R1-EVO evo:22.1R1-EVO junos:20.2R3-S4-J13 junos:21.1R3 junos:21.2R2 junos:21.2R2-S1 junos:21.2R3 junos:21.3R2 junos:21.4R1 junos:22.1R1
PR Number
Synopsis
Category: PPPoE functional plugin for bbe-smgd
1685070
Multiple bbe-smgd cores might be observed resulting in subscribers being lost or failing to login in the Enhanced subscriber scenario
Product-Group=junos
On MX platforms, multiple bbe-smgd cores might be observed due to out-of-bound memory access in the Enhanced subscriber scenario when bringing up PPPoE (Point-to-Point Protocol over Ethernet) subscribers and ACI (agent circuit identifier)/ARI (agent remote identifier) are part of the payload.
Resolved In:
evo:22.1R3-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:19.4R3-S10 junos:19.4R3-S5-J1 junos:20.2R3-S4-J9 junos:20.2R3-S6 junos:20.3R3-S6 junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S3 junos:21.4R3-S1 junos:22.1R3 junos:22.2R2 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR Number
Synopsis
Category: QFX L2 PFE
1712114
On QFX5K-VC or EX46x0-VC BFD sessions flap, after reboot/power cycle of master and other FPCs
Product-Group=junos
On QFX5K-VC or EX46x0-VC running BFD over lag interface in distributed mode, if we reboot Master FPC and other FPCs then BFD hello packets Tx/Rx may be impacted. This might cause BFD session flap and downtime of BFD session may be upto 100 secs. Prerequisite: QFX5K-VC or EX46x0-VC running BFD over lag interface in distributed mode. Trigger: Reboot of Master RE + Anchor FPCs, where the Anchor FPC is the FPC in which a BFD session is sourced and maintained
Resolved In:
PR Number
Synopsis
Category: QFX L3 data-plane/forwarding
1695943
JUNOS_REG:: QFX5110-32Q:VC:: :After loading "20.4R3-S5.3" dcpfe core is observed and device is unstable
Product-Group=junos
On QFX5K VCF platform, the PFE core will be seen due to invalid usage of snprintf (PR 1688206).
Resolved In:
junos:20.2R3-S6 junos:20.4R3-S5 junos:20.4R3-S7 junos:21.1R3-S4 junos:21.2R3-S4 junos:21.2R3-S5 junos:21.3R3-S3 junos:21.3R3-S5 junos:21.4R3-S2 junos:22.1R3 junos:22.1R3-S3 junos:22.2R2-S1 junos:22.2R3 junos:22.2R3-S1 junos:22.3R2 junos:22.3R3 junos:22.4R1 junos:22.4R2 junos:23.1R1
PR Number
Synopsis
Category: KRT Queue issues within RPD
1578111
The KRT queue might get stuck during GRES RE switchover
Product-Group=junos
The KRT queue might get stuck during the GRES RE switchover. This issue will occur when rpd gets rtm_change for a next-hop from the kernel while switchover is in progress when rpd (task) has become master, but KRT is still in backup state.
Resolved In:
evo:21.2R2-EVO evo:21.3R1-EVO evo:21.4R1-EVO junos:20.2R3-S5 junos:21.2R2 junos:21.3R1 junos:21.4R1
PR Number
Synopsis
Category: RPD Next-hop issues including indirect, CNH, and MCNH
1716436
Traffic loss due to incorrect route resolution and KRT queue getting stuck with 'EINVAL -- Bad parameter in request' error
Product-Group=junos
On all Junos and Junos OS Evolved platforms, due to a bug in route resolution over specific types of next hops, the route can resolve over itself and the nexthop chain keeps expanding. Due to this issue, the depth of recursion gets higher than supported and the KRT (Kernel Routing table) queue returns errors for nexthops. As a result, there will be incorrect route resolution, traffic loss and occasionally, the rpd (routing protocol deamon) crashes. The necessary configurations and conditions that will result in this issue are below 1. BGP (Border Gateway Protocol) Prefix-Independent Convergence (PIC) ("protect core") is configured and BGP receives same prefix from EBGP and IBGP neighbors 2. BGP LU (Labeled Unicast) with "protection" to create backup path to protect the active and BGP receives same prefix from EBGP and IBGP neighbors 3. Mutually recursive Route resolvability situations like Resolving using Default-route (not having proper resolution config)
Resolved In:
evo:23.2R2-EVO evo:23.3R1-EVO junos:23.2R2 junos:23.3R1
PR Number
Synopsis
Category: SRX branch platforms
1713759
Continuous vmcores observed on the secondary node when committing the "set system management-instance" command
Product-Group=junos
On Junos SRX3xx series platforms, when the "set system management-instance" command is committed on the secondary node, continuous vmcores are observed on primary and secondary nodes. No recovery action is needed for the primary node and the secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until the management-instance knob is removed using the "delete system management-instance".
Resolved In:
junos:20.4R3-S8 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S3 junos:22.1R3-S2 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.1R2 junos:23.2R1
PR Number
Synopsis
Category: MPC7/8/9 chassis issues
1722327
After deactivating an lt interface with units that have CoS the interface cannot be reactivated
Product-Group=junos
After deactivating an lt interface with units that have CoS the interface cannot be reactivated
Resolved In:
PR Number
Synopsis
Category: ZT/YT pfe l3 forwarding issues
1642851
Traffic drop due to incorrect memory allocation for the default route on MPC10E and MPC11E line cards
Product-Group=junos
On MPC10E & MPC11E line cards default route information might be overwritten/lost due to incorrect memory allocation.
Resolved In:
evo:21.3R3-EVO evo:21.4R2-EVO evo:22.1R2-EVO evo:22.2R1-EVO junos:20.2R3-S6 junos:20.4R3-S4 junos:21.2R3 junos:21.3R3 junos:21.4R2 junos:22.1R1 junos:22.1R2 junos:22.2R1
PR Number
Synopsis
Category: Trio pfe multicast software
1686068
Disabling PFE triggers the memory leak which may cause FPC to crash
Product-Group=junos
On Junos MX platforms with specific line cards, when PFE (Packet Forwarding Engine) is disabled, scenarios like multicast receiver join/leave that result in allocation and de-allocation of memory on disabled PFE can cause a memory leak. This is because memory is allocated on the disabled PFE, but not freed.
Resolved In:
evo:22.4R3-EVO evo:23.2R1-EVO junos:21.2R3-S5 junos:22.4R3 junos:23.2R1
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1638847
The mustd process crash might be observed with persist-group-inheritance
Product-Group=junos
On all Junos and Junos Evolved platforms configured with persist-group-inheritance, which is enabled by default from 19.4R3 onwards, might lead to mustd process crash in highly scaled configuration.
Resolved In:
evo:22.3X50-EVO evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R2-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R1-S1 junos:23.1R2 junos:23.2R1
1730336
The rpd crashes and the commit operation fails while pushing a large configuration with the "extend-size" knob enabled
Product-Group=junos
On all Junos platforms, when the 'extend-size' knob is configured and a scaled configuration is committed, the rpd daemon crash is seen and the commit operation fails. root@device> show configuration | match configuration-database | display set set system configuration-database extend-size root@device# load update /var/tmp/New_config.txt load complete root@device# commit error: Check-out pass for Routing protocols process (/usr/sbin/rpd) dumped core (0x86) error: configuration check-out failed
Resolved In:
evo:22.2R3-S1-EVO evo:22.4R3-EVO evo:23.1R1-S1-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R2-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R1-S1 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1
PR Number
Synopsis
Category: usf nat related issues
1612555
The B4 client traffic will be dropped on MX-SPC3 based AFTR in DS-Lite with EIM activated CGNAT scenario
Product-Group=junos
In MX-SPC3 with Dual-Stack Lite (DS-Lite) scenario, the IPv4 client will use Basic Bridging BroadBand (B4) to pass through IPv4-over-IPv6 tunnels to cross an IPv6 access network to reach a Carrier-grade NAT (CGNAT) network behind the Address Family Transition Router (AFTR). In case of the Endpoint independent mapping (EIM) is activated for CGNAT, the DS-Lite encapsulated IPIP packets might not be identified by EIM for some reason, and the NAT rule might not be found properly by MX-SPC3 of AFTR for the mapping traffic. After that, the DS-Lite tunnels/NAT sessions between the B4 and AFTR might not be established successfully since the DS-Lite/NAT packets might be dropped on AFTR, the IP flow from the B4 client will be impacted.
Resolved In:
junos:20.2R3-S3 junos:20.4R3-S1 junos:21.1R2-S1 junos:21.1R3 junos:21.2R2 junos:21.2R3 junos:21.3R2 junos:21.4R1 junos:22.1R1
Modification History
First publication 2023-06-20
20.2R3-S8: Software Release Notification for JUNOS Software