Alert Type
PSN - Product Support Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX EX MX NFX PTX QFX SRX vSRX
Alert Description
Alert Description
Junos Software Service Release version 21.2R3-S6 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 21.2R3-S6 is now available.
21.2R3-S6 - List of Fixed issues
PR Number
Synopsis
Category: EX4300 PFE
1722284
Native VLAN traffic is getting dropped in the Q-in-Q scenario on EX4300
Product-Group=junos
On Junos EX4300-24T/24P when the native CVLAN (Customer Virtual Local Area Network) ID is configured for Q-in-Q setup, the traffic for that particular VLAN gets dropped even if the knob "input-native-vlan-push" is configured. This issue is encountered when the when inner-tag matches 'native-vlan-id' irrespective of the outer tag.
1729636
Traffic loss is seen after configuration changes related to VSTP are committed
Product-Group=junos
On EX4300 platforms, when RSTP (Rapid Spanning Tree Protocol) and VSTP(VLAN Spanning Tree Protocol) are configured on two different interfaces which are part of the same VLAN (Virtual LAN), the RSTP-enabled interface will drop traffic after doing a configuration change in VSTP for the specified VLAN.
PR Number
Synopsis
Category: EX2300/3400 platform
1737524
VC on EX3400 platforms will not form with 40GBASE-BXSR optics
Product-Group=junos
On Junos EX3400 platforms, the Virtual Chassis will not form if 40GBASE-BXSR optics are used on VCPs (Virtual Chassis ports).
PR Number
Synopsis
Category: SRX DNS DGA and tunneling related
1717503
The srxpfe core has been seen on secondary SRX during ISSU
Product-Group=junos
On all Junos SRX platforms, when in-service software upgrade (ISSU) is in progress and if any traffic received by DNSF plugin leads to the srxpfe core.
PR Number
Synopsis
Category: Fireall support for ACX
1737999
Transit VPN traffic towards local CE failed in ARP resolution due to VRF lo0.x RE filter in place
Product-Group=junos
On ACX1K/2K platforms, when a lo0.x filter is configured under a vrf type routing-instance, any IPv4 transit traffic that makes ARP request to generate to the CE-facing interfaces will fail in ARP resolution due to the ARP request packets are discard by lo0.x filter if no specific term to accept the IPv4 packets
PR Number
Synopsis
Category: ACX L3 IPv4, IPv6 support
1707932
L2VPN traffic is dropped as the default MTU is less by 4 bytes
Product-Group=junos
On Junos ACX platforms, due to Maximum Transmission Unit (MTU) mismatch, L2VPN (Layer 2 Virtual Private Network) traffic will be dropped on the egress interface facing Customer Edge (CE).
PR Number
Synopsis
Category: ACX MPLS
1720827
The Forwarding Engine Board (FEB 0) crashes and impacts traffic when the L2circuit IGP primary path port is down
Product-Group=junos
On Junos ACX1000, ACX1100, ACX2000, ACX2100, ACX2200, and ACX4000 platforms, the Forwarding Engine Board (FEB 0) will crash when the L2circuit Interior Gateway Protocol (IGP) primary path port on the local device is down. Sub-minute traffic loss is seen when FEB 0 crashes. This issue is seen only when 'hot-standby' mode is in place for L2circuit and not seen with just 'standby' mode.
1726711
[ACX5048] L2circuit might drop forwarding traffic after flaps although it's in UP state; acx_rt_ccc_eth_vpws_vpn_uni_port_add: UNI VPWS port_add failed AC-IFL: <> VPN: <> (-15:Invalid configuration)
Product-Group=junos
- Upon multiple operations of deactive/active of the interface, pfe related mpls uni port stale entry might be created with invalid match vid due to which tagged traffic start dropping. - If the system is in the issued state, then the problematic l2circuit might be identified with the error logs seen below upon l2circuit flaps. fpc0 acx_bcm_mpls_uni_port_delete: VPWS port_del failed VPN: 12443 (-7:Entry not found) fpc0 acx_bcm_mpls_uni_port_add: NNI VPWS port_add failed (-15:Invalid configuration) fpc0 acx_rt_ccc_eth_vpws_vpn_uni_port_add:UNI VPWS port_add failed AC-IFL: 715 VPN: 12443 (-15:Invalid configuration) - Upon the l2circuit hits the issue, even if it's up and running after the flap, it might drop all traffic forwarded.
PR Number
Synopsis
Category: ACX Services feature
1612212
On Junos platforms, cfmd core dumps might be seen in the logs if CCM configuration is changed from AE IFL to the physical IFL in a single commit
Product-Group=junos
On Junos platforms, when CCM configuration is changed from the AE IFL to the physical IFL which is a part of the AE bundle, cfmd core dumps might be seen in the logs.
PR Number
Synopsis
Category: "agentd" software daemon
1715377
The agentd would become unresponsive on all Junos platforms
Product-Group=junos
When using Junos Telemetry Interface (JTI) with subscriptions to Packet Forwarding Engine (PFE) based sensors, agentd might slowly leak memory. After prolonged runtime agentd may stop functioning properly, which will affect JTI data export. This will affect telemetry services.
PR Number
Synopsis
Category: MPC Fusion SW
1744883
100G interfaces will flap due to RE switchover on Junos MX platforms with MPC3E-3D-NG/ MPC-3E-3D-NG-Q linecards
Product-Group=junos
On Junos MX platforms with MPC3E-3D-NG/MPC-3E-3D-NG-Q linecards, 100G interfaces will flap due to RE (Routing Engine) switchover.
PR Number
Synopsis
Category: Application Quality of Experience
1743107
flowd process crash observed in Junos branch SRX platforms
Product-Group=junos
This issue is observed on Junos SRX platforms supporting SD-WAN (Software-defined Wide Area Network) like SRX300, SRX320, SRX340, SRX345, SRX380, SRX550, SRX1500, SRX4100, SRX4200, SRX4600, SRX5600, SRX5800, cSRX and vSRX in AppQoE (Application Quality of Experience) scenario where the passive probe session of SD-WAN is not closed gracefully. This results in flowd crash and impacts user traffic.
PR Number
Synopsis
Category: A15 specific issue
1738188
Failover can be seen on SRX5K cluster with SPC2 cards while executing RSI
Product-Group=junos
On all SRX5000 series platforms with SPC2 cards configured in a chassis cluster, when RSI is being collected which has the command 'i2csc fpc' in the script, an interrupt storm generates a CB (Control Board) alarm which triggers a failover. Intermittent traffic disruption could be seen till the failover is complete.
PR Number
Synopsis
Category: dynamic vlan creation and associated processing
1743903
If more than 32 vlan ranges are configured under the dynamic-profile then login issue and traffic impact can be seen with subscribers of random VLANs
Product-Group=junos
On all Junos platforms that support subscriber services, when more than 32 VLAN ranges are configured, random VLAN (Virtual Local Area Network) traffic is impacted and subscribers are unable to login.
PR Number
Synopsis
Category: BBE OS Infrastructure library
1732216
'max-db-size' configuration is optional in routers having DRAM greater than or equals to 32GB
Product-Group=junos
On Junos MX platforms, to enable Enhanced Subscriber Management feature without 'max-db-size' configuration on router >=32GB DRAM(Dynamic Random Access Memory), router needs to be rebooted only once instead of rebooting twice.
PR Number
Synopsis
Category: BBE packet trigger access model issues
1726136
PTSP subscribers are stuck in 'configured' state
Product-Group=junos
On MX platforms supporting packet-triggered subscribers and policy control (PTSP) feature, a high percentage of packet triggered subscribers are getting stuck in 'Configured' state due to an authentication failure.
PR Number
Synopsis
Category: Bi Directional Forwarding Detection (BFD)
1725971
Multiple flaps of the interface will cause the BFD session to be down
Product-Group=junos
On all Junos and Junos Evolved platforms, the IPv4 static route BFD (Bidirectional Forwarding Detection) session may stay down if the corresponding interface flaps multiple times.
PR Number
Synopsis
Category: Border Gateway Protocol
1643665
The BGP route may still be present in the multi-path route after increased IGP cost
Product-Group=junos
On all Junos and EVO platforms, when color-only is used and the igp-cost of the active path is high, then the BGP route may still be present in the multi-path route after increased IGP cost.
1670715
The rpd process crash is observed when running BGP-LS EPE configuration with RIB sharding enabled
Product-Group=junos
The rpd process crash is observed when running BGP-LS (Border Gateway Protocol - Link-State) EPE (Egress Peer Traffic Engineering) configuration with RIB sharding enabled since the label allocation is only allowed in the main thread. But the shards thread was trying to allocate the label during EPE configuration parsing.
1679495
RV task replication will be stuck in the "NotStarted" state when routing-options validation is deactivated/activated
Product-Group=junos
On all Junos and Junos Evolved platforms with Non-Stop Routing (NSR) enabled, in a rare case, Route Validation (RV) task replication will be stuck in the "NotStarted" state when routing-options validation is deactivated/activated.
1687887
More than expected traffic loss is seen with ECMP FRR enabled during link down scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, in a link down/BFD (Bidirectional Forwarding Detection) down event traffic loss is seen to occur more than the expected with ECMP (Equal-Cost Multipath) FRR (Fast Reroute) or BGP PIC (Prefix-Independent Convergence) configured.
1712527
The PE advertises incorrect next-hop towards CE although BGP export policy configured with next-hop under policy-statement
Product-Group=junos
The show route advertising-protocol bgp reporting nexthop self rather than IP in the configured policy-statement for next-hop.
1728455
The rpd process crashes when BGP is cleaned up
Product-Group=junos
On Junos and Junos OS Evolved platforms, if static default RT-C (Route Target -Constrain) is configured when Border Gateway Protocol (BGP) is cleaned up (whole BGP is cleaned up), the routing process will crash.
1728604
Traffic impact is seen when there is a single peer in the proxy BGP group connected to the BGP route reflector
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if the proxy BGP (Border Gateway Protocol) route reflector is connected to the only peer present in the BGP group then it stops advertising the routes coming from the remote cluster and that leads to proxy route-target routes not getting added which causes traffic disruption.
1732833
RPD core files might be seen when BGP RIB sharding is used
Product-Group=junos
RPD might stop responding and generate core files (or dump files) when BGP RIB sharding is used.
1739335
The rpd process crash will be observed when the prefix-limit exceeds on the backup RE
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with BGP (Border Gateway Protocol), NSR (Nonstop Active Routing), and prefix-limit with idle-timeout, when the prefix-limit exceeds on the backup RE (Routing Engine) and switchover is performed the rpd process crash will be observed on the new backup RE.
1739919
Junos OS and Junos OS Evolved: A BGP session will flap upon receipt of a specific, optional transitive attribute (CVE-2023-0026)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA71542
[juniper.net]
for more details.
1742416
RPD scheduler slip is observed when the BGP session flaps and subsequent configuration changes for the same peer
Product-Group=junos
On all Junos and Junos Evolved platforms, high CPU (RPD scheduler slips) leads to session timeouts/flaps for other protocols running in the system.
PR Number
Synopsis
Category: Track PRs in BGP BMP area & is part of BGP inside RPD.
1653130
The rpd might crash when BMP rib-out monitoring is configured for flow-spec route
Product-Group=junos
On all Junos and Evolved platforms, rpd crash might be seen when BGP monitoring protocol (BMP) rib-out monitoring is configured for the flow-spec route. Since there is no next-hop for flow-spec route core might be seen while generating rib-out feed. Traffic loss might be seen due to this crash.
PR Number
Synopsis
Category: BBE Remote Access Server
1729035
Potential memory leak in authd process
Product-Group=junos
If RADIUS is enabled for subscriber authentication or accounting, the authd process may occasionally leak memory when running at a high scale.
PR Number
Synopsis
Category: MX Platform SW - Power Management
1703566
Alarms for PEMs are still seen when PEM are removed from the chassis
Product-Group=junos
Alarms for PEMs are still seen when PEM are removed from the chassis
PR Number
Synopsis
Category: Chotu platform software
1720407
Reachability loss between Master and backup RE in certain condition on MX2008 platform
Product-Group=junos
On the Junos MX2008 platform, the synchronization will be lost between the master RE (Routing Engine) and the backup RE when the AE (Aggregated Ethernet) configuration is being applied. This issue is seen after the node reboot or backup RE is rebooted and is because the control interface ixlv0 of the RE is not established during the AE configuration. This issue is self-recoverable.
PR Number
Synopsis
Category: Class of Service
1734013
The CoS scheduler map will not get attached to the sub-interface correctly when shaping-rate and scheduler-map are configured on it
Product-Group=junos
On all MX platforms, when shaping-rate and scheduler-map are configured on a sub-interface and a wildcard expression for sub-interfaces is used in the class-of-service interface definition, then the CoS (Class of Service) scheduler map will not get attached as per the configuration to the sub-interface and will not work correctly. Example: set class-of-service interfaces unit * classifiers.
PR Number
Synopsis
Category: Enhanced Broadband Edge support for cos
1713968
Subscribers connectivity is lost due to multiple MIC restart on all Junos MX platforms with MPC5E and BBE configuration
Product-Group=junos
On all Junos MX platforms with MPC5E and BBE (Broadband Edge) configuration, subscribers connectivity will be lost due to multiple MIC (Modular Interface Card) restart.
PR Number
Synopsis
Category: CFM
1682939
Maintenance-domain (MD) and Maintenance-association (MA) configuration display changed to ordered-by-system type
Product-Group=junos
With this the maintenance-domain (MD) configuration and maintenance-association (MA configuration) under the connectivity-fault-management stanza will be ordered by the system and not as per the configuration order.
PR Number
Synopsis
Category: L2NG Access Security feature
1724933
On certain Junos EX and QFX platforms the static ARP entries for DHCP-security are not present
Product-Group=junos
On certain Junos EX series switches, the static MAC (Media Access Control) bindings are not present in certain conditions. This issue will be seen when the static DHCP (Dynamic Host Configuration Protocol)-security ARP(Address Resolution Protocol) bindings are moved from an interface having a higher interface number to an interface with a lower interface number. Due to the binding not happening, there will be impact on the traffic. The workaround when such a binding change is done is to restart the DHCP services after the configuration is committed.
PR Number
Synopsis
Category: QFX Control Plane VXLAN
1723968
Traffic loss is seen as Type 2 routes are not pushed even after withdrawing Type 5 routes
Product-Group=junos
On all Junos and Junos Evolved platforms with the EVPN (Ethernet VPN) Type 2 and Type 5 Coexistence and when the host route changes from EVPN Type 5 route to non EVPN route in the rpd, traffic loss is observed as Type 2 routes are not getting pushed even after withdrawing Type 5 routes.
PR Number
Synopsis
Category: Device Configuration Daemon
1714267
The interface speed gets set to a lower speed when the interface is disabled and enabled because renegotiation of the interfaces happens at the previously negotiated speed
Product-Group=junos
On Junos platforms with MPC line cards, negotiated interfaces will try to come up with the speed already negotiated instead of using the original interfaces speed even if re-negotiation happens like reinserting cable.
1731190
The lt/vt/ut interfaces may not recover from the disable-pfe (admin down) state if the GRES switchover is done before restarting FPC
Product-Group=junos
On all Junos Platforms when a PFE (Packet Forwarding Engine) gets disabled to a CM (Chassis Manager) error disable-pfe action or any other reason and a GRES (Graceful Routing Engine Switchover) happens, the lt/vt/ut (Logical Tunnel/Virtual Tunnel/Uplink Tunnel) interfaces will not recover after the FPC (Flexible PIC Concentrator) restart even though the error condition is recovered resulting in traffic loss.
PR Number
Synopsis
Category: CoS support on DNX
1704589
Traffic drops seen after making COS configuration change on ACX710
Product-Group=junos
On Junos ACX710 platforms, when CoS (Class-of-Service) scheduler changes are done for buffer usage and when traffic is flowing which involves bursty traffic, traffic drops are seen.
PR Number
Synopsis
Category: EVPN ELAN/E-TREE
1689267
FPC crashes and goes into down or unknown state in a scaled EVPN setup
Product-Group=junos
On Junos ACX5448 and ACX710 platforms with scaled EVPN (Ethernet Virtual Private Network) setup, a 'restart routing' can trigger the PFE (Packet Forwarding Engine) crash and the FPC (Flexible PIC Concentrator) will get stuck either in down or unknown state resulting in a total traffic impact.
PR Number
Synopsis
Category: BGP MPLS VPN specific issues
1719507
L3VPN traffic loss and PFE errors can be seen after an LSP Flap
Product-Group=junos
On all Junos ACX platforms, when L3VPN (Layer 3 Virtual Private Network) and MPLS-LSP (Multiprotocol Label Switching - Label-Switched Paths) is configured, L3VPN traffic loss and PFE (Packet Forwarding Engine) errors can be seen after an LSP flap.
PR Number
Synopsis
Category: ACX VxLAN Issue
1665828
MAC-IP bindings for IPv4 (ARP) and IPv6 (ND) may not be processed for IRB interfaces in an EVPN scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, when EVPN (Ethernet Virtual Private Network) related configuration is introduced from baseline, due to a rare timing issue between the IRB (Integrated Routing and Bridging) interfaces coming up and an attempt is made by the 'l2ald' (l2 address learning) daemon to process the corresponding MAC-IP entries, this issue may occur. This may also occur when IRB logical units are activated and deactivated.
PR Number
Synopsis
Category: Ethernet OAM (LFM)
1714149
Junos OS: MX Series: The FPC will crash on receiving a malformed CFM packet (CVE-2023-36848)
Product-Group=junos
An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (ppmd) of Juniper Networks Junos OS on MX Series(except MPC10, MPC11, and LC9600) allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA71659
[juniper.net]
for more information.
PR Number
Synopsis
Category: ESIS routing protocol
1720303
The ES-IS route is not getting installed in the .iso.0 routing table
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when the protocol ES-IS (End System to Intermediate System) is configured under routing-instance (non-master instances) then upon upgrading the device to releases 21.1R1 onwards the ES-IS route will not get installed in the .iso.0 route table leading to a service outage.
PR Number
Synopsis
Category: EVPN Layer-2 Forwarding
1646010
IRB might not send out arp-reply if "no-arp-suppression" is configured
Product-Group=junos
On all Junos platforms, when "no-arp-suppression" is configured, the Layer 2 Address Learning Manager (L2ALM) will not respond to Address Resolution Protocol (ARP) request for Integrated Routing and Bridging (IRB) IP, and traffic to IRB will be lost.
1669811
BUM traffic might be blackholed for ESI configured CE interface flap
Product-Group=junos
On Junos MX/QFX5K/QFX10K platforms and Junos Evolved ACX/MX platforms, on interface up/down event loop prevention might not work resulting in BUM traffic being blackholed.
1700170
In EVPN-VXLAN scenario, whenever there is any interface flap, this issue might be hit.
Product-Group=junos
In EVPN-VXLAN scenario, whenever there is any interface flap, this issue might be hit.
PR Number
Synopsis
Category: EX4400 PFE software
1716902
IGMP/MLD queries may get dropped if received on a port on the backup VC member when IGMP/MLD snooping is enabled
Product-Group=junos
On Junos QFX and EX in the VC (Virtual Chassis) scenario, when the switch is acting as pure L2 (Layer 2), and forwarding IGMP (Internet Group Management Protocol)/MLD (Multicast Listener Discovery) query as transit traffic, if IGMP/MLD snooping is enabled then IGMP/MLD queries may get dropped if received on a port on the backup VC member resulting in IGMP/MLD groups to expire.
1718286
DHCP services are impacted as DHCP binding will not work as expected
Product-Group=junos
On all Junos and Junos Evolved platforms, all the DHCP (Dynamic Host Configuration Protocol) security services will be impacted as the DHCP-security binding will not work if the DHCP server-facing interface is a VTEP (VXLAN tunnel endpoint) interface.
1731522
The traffic drop will be observed after changing the VSTP VLAN configuration
Product-Group=junos
On Junos EX4400, EX4100, EX2300, EX3400, and QFX5K platforms, traffic drop would happen on RSTP (Rapid Spanning Tree Protocol) enabled port attached to a VLAN (Virtual Local Area Network) when the same VLAN has VSTP (VLAN Spanning Tree Protocol) enabled on a different port and there is a configuration change done on VSTP for that VLAN.
1732271
Filter term dropping VRRP traffic when "then log" is configured
Product-Group=junos
On all Junos platforms, VRRP (Virtual Router Redundancy Protocol) packet goes to a wrong CPU queue when filter is added to match VRRP packet with "then log" action, resulting in VRRP functionality impact.
1733365
Error logs are seen with a non-vxlan dot1x enabled port
Product-Group=junos
In a heaviliy loaded system in a specific scenario (Dot1x in multiple supplicant mode & dynamic vlan from radius server & non vxlan access port) following log message may be captured in the syslog - {brcm_as_dot1x_vxlan_set_mac_learning_mode:1168 dot1x bd_get failed for bd index 0}. This log is not impacting any funtionality.
1736790
EX4400 shaping rate not working as expected
Product-Group=junos
On EX platforms shaping rate on 100gig link over 70g not working as expected.
PR Number
Synopsis
Category: EX4400 platform
1707762
BFD/LACP flaps will be seen on EX4400 platforms
Product-Group=junos
On EX4400 platforms, BFD (Bidirectional Forwarding Detection) will flap randomly along with LACP (Link Aggregation Control Protocol) flaps or VC (Virtual Chassis) connection loss.
1720074
Port will be down when "no-auto-negotiation" is configured on EX4400-48F platform
Product-Group=junos
On EX4400-48F platform with Small Form Factor Pluggable 100Base-FX Fast Ethernet Optics, when "no-auto-negotiation" is configured on the interface this results in the interface not coming back online even after deleting "no-auto-negotiation" in interface.
PR Number
Synopsis
Category: Express PFE CoS Features
1719956
Convergence delay is seen when FPC is offlined under heavy traffic and scaled scenario
Product-Group=junos
On Junos PTX3000, PTX5000, PTX10008, and PTX10016 routers, when the Flexible PIC Concentrator (FPC) is offlined with scale configuration and heavy traffic, a delay in convergence (into tens of minutes) is seen on all the live FPCs in the chassis other than the offlined one. This impacts traffic.
1738981
DSCP classifier is not created on IP interfaces
Product-Group=junos
On Junos QFX10k platforms, on configuring diffServ code point (DSCP) classifier and when inet or inet6 is configured with custom dot1p on interface, default dscp classifiers are not getting removed properly.
PR Number
Synopsis
Category: Express PFE FW Features
1727067
FPC crashes when the firewall filter is configured with above 65k prefixes in a single filter
Product-Group=junos
On the below PTX platforms ( PTX1000, PTX3000 (NextGen), PTX5000, PTX10008, PTX10016 and QFX10002), when prefixes above 65K are configured in a single firewall filter, FPC (Flexible PIC Concentrator) crash would be observed.
PR Number
Synopsis
Category: Express PFE including evpn, vxlan
1701636
Aggregated Ethernet interface member with vlan-id-list configured not forwarding traffic
Product-Group=junos
On Junos QFX10002, QFX10008 and QFX10016 platforms, AE(aggregated-ethernet) interface member with vlan-id-list configured does not forward traffic thus leading to traffic loss.
PR Number
Synopsis
Category: ISIS routing protocol
1719033
The rpd process crashes when TI-LFA is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd is seen to crash when TI-LFA (Topology-Independent Loop-Free Alternate) is enabled and there are ECMP (Equal-Cost Multipath) routes present.
1725686
Unnecessary SPF calculation is causing high CPU utilization
Product-Group=junos
On all Junos and Junos Evolved platforms, very frequent SPF (Shortest Path First) calculation, being caused by leaking multiple prefixes across the IS-IS areas, is causing high CPU utilization.
PR Number
Synopsis
Category: jdhcpd daemon
1722082
DHCP binding is not happening in EVPN VXLAN topology with DHCP stateless relay (forward-only)
Product-Group=junos
In EVPN VXLAN topology with DHCP stateless relay (forward-only) configured at layer 3 gateways, Jdhcpd broadcasts snooped unicast offer packets. That leads to the offer getting dropped on its way to the client and then the IP negotiation fails.
1731784
Dhcp security bindings may not happen when DHCP security is enabled on multiple vlans along with dhcp stateless relay
Product-Group=junos
When DHCP security is enabled on multiple vlans along with dhcp stateless relay enabled at that time, dhcp security bindings may not happen.
PR Number
Synopsis
Category: JFlow bug tracker for SRX platforms
1716707
J-flow sends wrong IP in sampling records when NAT is configured for traffic along with input sampling
Product-Group=junos
When NAT (Network Address Translation) is configured on interfaces along with sampling, the J-flow record will contain NAT'ed IP as opposed to the original IP.
PR Number
Synopsis
Category: Adresses ALG issues found in JSF
1722877
Device crashed while processing H323 traffic in SRX and MX
Product-Group=junos
The SRX Device and MX with MS-MPC and MX-SPC3 service cards, crashes due to a timing issue, while processing H323 traffic.
1728638
SIP ALG not working for SIP traffic with MIME header and traffic is dropped
Product-Group=junos
On all MX and SRX platforms, SIP ALG (Session Initiation Protocol Application Layer Gateway) not working as SIP (Session Initiation Protocol) packets with MIME (Multipurpose Internet Mail Extensions) header causes traffic to be dropped.
PR Number
Synopsis
Category: Flow Module
1624707
Flowd may core if route change or delete in PMI mode
Product-Group=junos
Flowd may core if route change or delete and do IPSEC encap in PMI mode in SRX5K with SPC3 platform, please upgrade to version with this fix if using PMI mode in SRX5K with SPC3.
1683334
Packet loss on GRE Tunnel due to improper route look-up for tunnel destination
Product-Group=junos
On SRX platforms, due to improper route look-up for the tunnel destination if the GRE tunnel is configured in a virtual routing-instance for which packet loss is observed.
1719437
The traffic will fail when accessing the routing instance interface IP from external IP
Product-Group=junos
On all SRX platforms, the flow will not jump the route from one routing instance to another, causing the traffic to fail when accessing one routing instance interface IP from external IP.
1733819
The inet6 packet mode drops traffic significantly
Product-Group=junos
On the SRX branch series, inet6 packet mode (packet-based) throughput drops significantly. Traffic will be fine until the CPU reaches 100% and random traffic will be dropped.
PR Number
Synopsis
Category: all logging related bugs on srx platforms
1708116
Log streaming Hosts configured as FQDN may fail when DNS re-query is performed
Product-Group=junos
On SRX platforms, log streaming using FQDN requiring DNS name resolution may fail to re-query resulting in FQDN resolution to fail
1716776
Security log missing space between timestamp and hostname
Product-Group=junos
JunOS upgrade to the 22.2R3, 21.3R3-S3, 22.4R1, 21.4R3-S3, 22.3R2, 22.4R2, 21.2R3-S4 , 22.1R3 the security log space between the timestamps and site-name is removed Eg. 2023-08-14T12:04:31.273-07:00device_host-name RT_FLOW - RT_FLOW_SESSION_CREATE_LS [
[email protected]
logical-system-name="JTAC-LSYS" source-address="10.10.10.10" source-port="29279" destination-address="10.10.30.20" destination-port="1603" connection-tag="0" service-name="icmp" nat-source-address="10.10.10.10" nat-source-port="29279" nat-destination-address="10.10.30.20" nat-destination-port="1603" nat-connection-tag="0" src-nat-rule-type="N/A" src-nat-rule-name="N/A" dst-nat-rule-type="N/A" dst-nat-rule-name="N/A" protocol-id="1" policy-name="ONE" source-zone-name="JTAC-Trust" destination-zone-name="JTAC-dmz" session-id="3207" username="N/A" roles="N/A" packet-incoming-interface="ge-0/0/12.0" application="UNKNOWN" nested-application="UNKNOWN" encrypted="UNKNOWN" application-category="N/A" application-sub-category="N/A" application-risk="-1" application-characteristics="N/A" src-vrf-grp="N/A" dst-vrf-grp="N/A" tunnel-inspection="Off" tunnel-inspection-policy-set="root" source-tenant="N/A" destination-service="N/A"]
PR Number
Synopsis
Category: Firewall Network Address Translation
1706541
ICMP based traceroute is not showing any hops after SRX when SRX is configured with NAT64
Product-Group=junos
For all SRX platforms, ICMP based traceroute does not show any hops after SRX when SRX is configured with NAT64.
PR Number
Synopsis
Category: Firewall Policy
1725567
Traffic impact is observed when the security policy is configured with a huge number of addresses and on addition/deletion of these policies
Product-Group=junos
On SRX platforms configured with security policies, having a huge number (approx. 15K) of addresses and performing addition/deletion of such policies in short intervals of time might result in srxpfe process crash and hence, data path traffic gets impacted.
PR Number
Synopsis
Category: User Firewall related issues
1683420
SRX Branch models are unable to connect to domain controller on installing Microsoft KB update
Product-Group=junos
On SRX300 series and SRX550M, when the User Identification feature is used with Active Directory, after the Domain Controller server installs updates related to Microsoft's KB article
KB5004442
[juniper.net]
, SRX is no longer able to connect to it. The PR1637548 did not fix this issue for these specific SRX platforms.
1701990
The user-id entries will not be synced with secondary node
Product-Group=junos
On Junos platforms, user-id process doesn't work properly (user-id ?process also sync users primary and second node). As a result, active directory user-ip-mapping entries were not synced to the secondary node and due to that user connection will drop. When the issue happens, storage space eventually go full and the user may notice the issue at that time.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1745174
IPSEC VPN does not come up in NAT-T scenario
Product-Group=junos
On all SRX platforms with IPSEC (Internet Protocol Security) VPN (Virtual Private Network) configured with main mode, if SRX is the VPN initiator and NAT-T (Network Address Translation-Traversal) is configured (which is by default), the IPsec VPN tunnel does not come up. This is a timing issue and occurs when a tunnel delete or rekey occurs.
PR Number
Synopsis
Category: Security platform jweb support
1668013
J-Web page will not load properly
Product-Group=junos
On all Junos platforms, the J-Web page will not load properly for a user, if the username contains a hyphen. Due to this, users will not be able to log in via J-Web.
1735314
Editing security policy configuration via J-web is enabling "Exclude Selected" unexpectedly
Product-Group=junos
On Junos platforms, when you cancel editing source/destination address in security policy using J-web, "Exclude selected" is unexpectedly enabled.
1735387
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files (CVE-2023-36847)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/
JSA72300
[juniper.net]
1735389
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files (CVE-2023-36846)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/
JSA72300
[juniper.net]
1748078
Cannot add custom defined security address-book under Security Policies & Objects > Security Policies > Create > Source Zone > Select Sources.
Product-Group=junos
In the J-Web UI for SRX Series Firewall, when you configure the source zone for addresses in the security policy rule, the customized address-book entries are not displayed. J-Web displays only any-ipv4 and any-ipv6.
PR Number
Synopsis
Category: Junos Selective Update infrastructure
1732878
The Junos Selective Upgrade (JSU) version is not removed post a major Junos upgrade/downgrade
Product-Group=junos
There is no functional impact but the previously installed JSU will show up even though it is deleted during major upgrade. This PR will fix that issue. Workaround is to remove /packages/sets/active/junos-version file.
PR Number
Synopsis
Category: Layer 2 Control Module
1739975
Layer 2 traffic will be dropped on VSTP disabled interface
Product-Group=junos
On Junos platforms, Whenever an interface is disabled under VSTP (VLAN Spanning Tre Protocol) configuration, the issue will be seen in the following cases. 1. When interface, IFBD (Interface Family Bridge Domain) and VSTP, configured via single commit. (In case of new configuration) 2. When VSTP configurations are present and chassisd restarts/device reboots, then issue will be seen. (During ifd delete and add, issue will be seen)
PR Number
Synopsis
Category: Layer2 forwarding on EX/NTF/PTX/QFX
1680242
The l2ald is treating mac as a duplicate causing traffic loss
Product-Group=junos
On all Junos and Junos Evolved platforms, with EVPN-VXLAN (Ethernet Virtual Private Network -Virtual Extensible Local Area Network) multihoming scenario, l2ald (Layer two Address Learning Daemon) considers the mac as duplicate, and traffic drop will be observed.
1723400
Unable to commit configs interface-mac-limit on sub-interfaces with vlan-tagging / flexible-vlan-tagging
Product-Group=junos
On QFX10K platforms unable to configure interface-mac-limit on sub-interfaces with vlan-tagging / flexible-vlan-tagging.
1727954
On all Junos and Junos Evolved platforms the l2ald process memory usage is seen to increase over time
Product-Group=junos
On all Junos and Junos Evolved platforms service impact is seen due to a consistent increase in l2ald (Layer 2 Address Learning Daemon) memory usage.
1743282
The l2ald crashes when there is recursive deletion of IFBD or when BGP neighborship is cleared in EVPN-VXLAN multi-homed configuration
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in a rare scenario, due to timing issue, the l2ald (Layer 2 Address Learning Daemon) crashes and traffic is being blackholed due to recursive deletion of IFBD (Interface Family Bridge Domain) or when BGP (Border Gateway Protocol) neighborship is cleared when EVPN (Ethernet Virtual Private Network) - VXLAN (Virtual Extensible Local Area Network) with multi-homed is configured.
PR Number
Synopsis
Category: lacp protocol
1609618
LACP Member interfaces might get stuck in out of sync state
Product-Group=junos
When sync-reset feature is enabled on the device then few member interfaces might stay in out of sync state even when number of available child interfaces is greater than minimum-links configured for the Lag interface. This will affect the overall capacity of the lag interface.
PR Number
Synopsis
Category: Label Distribution Protocol
1635863
An rpd core is seen post graceful switchover
Product-Group=junos
An rpd (Routing Protocol Daemon) crash is seen when dual transport LDP (Label distribution protocol) is configured along with NSR (Nonstop routing).
PR Number
Synopsis
Category: MPC11 ULC interface software related issues.
1698135
XQSS_CMERROR_DSTAT_INT_REG_DROP0_QDEPTH_UNDRN alarm is seen on MX2K platforms with MPC11E line cards upon aggregate interface down/flap event
Product-Group=junos
On MX2010 or MX2020 platforms with MPC11E line cards, if a member link of an aggregate interface goes down or flaps, it might trigger "XQSS_CMERROR_DSTAT_INT_REG_DROP0_QDEPTH_UNDRN" alarm and disable-pfe action is executed. The affected PFE (Packet Forwarding Engine) will be disabled and no traffic will pass through it.
PR Number
Synopsis
Category: Multiprotocol Label Switching
1649565
The error severity of syslog message "ted_client reset" generated during the commit is incorrect
Product-Group=junos
On all Junos and Junos evolved platforms, the severity of syslog message "ted_client reset" that is generated by rpd process during the commit is incorrect. It only generates an error message in the syslog .
1698889
The rpd process will crash when rpd is restarted
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when MPLS (Multiprotocol Label Switching) statistics is configured without LSP (Label-Switched Path) configuration, the rpd process will crash and impact the routing protocols. This leads to traffic disruption due to the loss of routing information.
1738774
Traffic blackhole due to an additional label when CCNH is toggled
Product-Group=junos
On all Junos and Junos Evolved platforms, with scaled Border Gateway Protocol (BGP) routes, when Chained Composite Next Hops (CCNH) is toggled, a few next-hops end up creating additional labels causing a traffic blackhole.
PR Number
Synopsis
Category: MX l2ng access security
1627611
DHCP clients might not go to BOUND state when the AE bundle is enabled between DHCP server and snooping device
Product-Group=junos
On Junos platforms with MPC10E line cards, when AE under the IRB interface is enabled between the snooping device and the DHCP server, the DHCP bindings can be seen in snooping device and DHCP server, but the DHCP client might not go to BOUND state, it might be stuck at discovering/requesting state.
PR Number
Synopsis
Category: MX Timing software
1652275
PTP Playback Engine reset error is reported sporadically with PTP FPGA Firmware version A4 7
Product-Group=junos
On Junos MX platforms, the PTP Playback Engine reset error is reported sporadically with PTP FPGA Firmware version A4 7. It has No functionality impact.
1664569
Switch Fabric Board information for supporting PTP on MX10k8 with MX10K-LC2101 LC(s)
Product-Group=junos
MX10k8 with MX10K-LC2101 Linecard(s) supports *PTP* only with JNP10008-SF Switch Fabric Board(s), *PTP* currently doesn't work with JNP10008-SF2 Switch Fabric Board(s).
1704633
Interface flaps are seen after PTP GM changes to a different FPC slot
Product-Group=junos
On MX platforms, when PTP (Precision Time Protocol) is configured, the interfaces will flap after the PTP GM (Grand Master) is changed to a different FPC (Flexible PIC Concentrators) slot. The flaps can last for several seconds. Chassis-SyncE clock is also influenced by PTP phase change.
1704644
Software improvement for PTP nbr-update || lcinfo_bmc || utc_arrival_time || lcinfo_msg || utc_arrival_time
Product-Group=junos
Enhancement needed on PTP nbr-update to improve user experiences.
1724254
On certain Junos MX platforms with SCB3 SyncE fails after enabling PTP
Product-Group=junos
On Junos MX platforms having SCB3 (Switch Control Board), the SyncE (Synchronous Ethernet) can be stuck in "Clock_Aborted" state. This issue is seen in release 20.4R3 onwards when PTP (Precision Time Protocol) is operated in hybrid mode, the SyncE failure will hinder the operation of applications like G.8275.1 deployment will fail. There is a fix in 20.4R3-S4 with JSU (Juniper Selective Upgrade) J10.2. Below are the important notes to consider regarding the verification of the fix. - -> JSU upgrade can be performed to replace the clksyncd with fix to address this issue. - -> However, if the system is already in a problem state before the JSU upgrade, a one-time deactivate and activate of "protocols PTP" and "chassis synchronization" configuration is needed to recover from the current problem state after the JSU upgrade of clksyncd is performed.
1750316
SyncE stuck in holdover upon PTP slot switchover without change in PTP phase align state
Product-Group=junos
SyncE stuck in holdover upon PTP slot switchover without change in PTP phase align state.
PR Number
Synopsis
Category: MX10K platform
1674322
SNMP traps "Power Supply failed" and "Power Supply OK" are not generated
Product-Group=junos
On all Junos MX10k and PTX10k platforms, when a PSU with no feeds connected, but the DIP switch at the back of the PSU is set in a position where it expects the feeds to be connected, then POWER FAILED TRAPs might not get generated as expected.
PR Number
Synopsis
Category: OS IPv4/ARP/ICMPv4
1722708
ksyncd core with dhcp subscribers
Product-Group=junos
In a very rare scenario, when subscriber-management and NSR is enabled, there could be a temporary transition state where one subscriber prefix has 2 nexthop referred. In that state if a deletion happened for that particular prefix, the nexthop deletion is successfully done one master RE but the deletion is failed on the backup RE. This eventually causes nh index inconsistency and then ksyncd core on backup RE. The fix is to make sure the deletion on the backup can be done successfully.
1735686
The message "kernel: %KERN-6: ARP UNICAST MODE 0; retrans_timer - 8" might be seen when commit command is run for configuration which is not related to ARP
Product-Group=junos
"kernel: %KERN-6: ARP UNICAST MODE 0; retrans_timer - 8" message might be seen when commit command is run for configuration which is not related to ARP
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1712855
Unicast packets are received on the management interface even though the destination MAC is not local
Product-Group=junos
On all platforms supporting em driver for their ethernet interface, promiscuous mode is enabled by default and hence traffic storm is noticed on the management interface.
PR Number
Synopsis
Category: Kernel MPLS / Tag / P2MP Infrastructure
1723145
Routing Engine initiated PING failed over MPLS interface
Product-Group=junos
The RE-generated packets that have MTU size greater than the inet MTU size get dropped when going out on an interface with MPLS chain-composite-next-hop.
PR Number
Synopsis
Category: OSPF routing protocol
1737978
OSPFv3 using the VIP address on the IRB interface will not form adjacencies between peers
Product-Group=junos
OSPFv3 may not form adjacencies on IRB interfaces with VRRP configuration.
PR Number
Synopsis
Category: Express Chip L3 software
1713279
Next-hop programming issue at PFE on Junos PTX and QFX10k platforms when the member of unilist is in hold state
Product-Group=junos
On PTX Series routers and the QFX10000 line of switches, traffic going over unilist is dropped when unilist member goes from next-hop hold state to unicast/aggregate state.
1738541
Traffic drop observed when next-hop installation fails in a high-scale multicast/unicast scenario
Product-Group=junos
On Junos PTX and QFX10K platforms, when the Flabel (Fabric Label) memory exhaustion occurs due to the scaled unicast/multicast next-hops and interface flapping i.e. downstream interfaces of multicast flapping, traffic drop is observed for next-hop installation failure in a high-scale multicast/unicast scenario.
PR Number
Synopsis
Category: Provider Backbone (PBB) EVPN PFE functionality on MX
1529940
PBB-EVPN PE cannot learn remote CE MAC address due to ARP suppression enabled
Product-Group=junos
In PBB-EVPN (Provider Backbone Bridging - Ethernet VPN) environment, ARP suppression feature which is not supported by PBB might be enabled unexpectedly. This could cause MAC addresses of remote CEs not to be learned and hence traffic loss.
PR Number
Synopsis
Category: Protocol Independant Multicast
1720708
Slow convergence of PIM joins causes temporary traffic loss with scaled downstream interfaces
Product-Group=junos
On all Junos and Junos Evolved platforms with PIM (Protocol Independent Multicast), MVPN (Multicast Virtual Private Network) configured and when the number of downstream interfaces is more than three thousand, slow convergence of PIM joins is seen to take up more of the time and CPU, causing traffic loss for some time.
PR Number
Synopsis
Category: Periodic Packet Management Daemon
1739860
The IPv6 link local based BFD session over an AE interface will be stuck in Init state
Product-Group=junos
On all MX platforms, when chassis network-services is set in IP mode, the IPv6 Link Local based BFD session over an AE interface will be stuck in init due to the next-hop misprogramming in the PFE.
PR Number
Synopsis
Category: QFX platform fabric mgmt for Express ASIC chip
1734735
Packet drop is observed due to SIB ASIC issue on fabric
Product-Group=junos
On all inserted FPCs of Junos based QFX10K8/QFX10K16 platforms, due to SIB (Switch Interface Board) ASIC (Application-Specific Integrated Circuit) issue on fabric, packets are getting dropped and major errors "PECHIP_CMERROR_EPW_MISC_INT_EVENTS_CRC_ERR (0x2101aa)" are reported. These errors are not auto-cleared on a couple of FPCs.
PR Number
Synopsis
Category: QFX PFE Class of Services
1641572
Traffic drop would be observed along with the error message 'Buffers are stuck on queue' when performing the OIR in the 100G QSFP interface
Product-Group=junos
On QFX5110-32Q platforms, the traffic drop along with the error message "Buffers are stuck on queue" will be seen when the Online Insertion and Removal (OIR) is performed with 100G QSFPs on continuous ports 28, 29, 30, 31 at the same time.
1726124
The class of service subsystem crashed after the device is restarted or the switchover is performed
Product-Group=junos
On Junos QFX5100 and QFX5110 platforms in virtual chassis, the cosd crash is observed when the GRES (Graceful Routing Engine Switchover) is performed or the device is restarted, due to which the Class of Service (CoS) functionality will not work. It is a rare issue.
PR Number
Synopsis
Category: QFX5K hostpath
1721318
Error message "%PFE-3: fpc0 Failed to get ifl for ifl index = XXX" is generated when receives DHCP packet via remote vtep.
Product-Group=junos
You may see the following error message in VXLAN environment. This can happen when the device receives DHCP packet via a remote vtep and L3 interface (IRB) is not assiged on the egress interface. Even though there is no DHCP configuration, the packet injection happens and it fails to get IFL index as there is no IRB interface on the egress interface. Oct 7 16:31:51.137 2022 d16-25 : %PFE-3: fpc0 Failed to get ifl for ifl index = 640
PR Number
Synopsis
Category: QFX L2 PFE
1705853
Tracking PR to add the null check for list_get_head if magic is NULL.
Product-Group=junos
On all Junos platforms, as list_get_head function is called in multiple places in pfe we needed previous 3 functions on the stack which had called list_get_head, so we could debug why 'list_get_head list has bad magic' this error has occured.
1730076
Packets received on a port that is in "LACP Detached" state is getting forwarded
Product-Group=junos
On all Junos EX46xx/QFX5k (except QFX5100) platforms, child links that are in LACP (Link Aggregation Control Protocol) detached state are up and accepting incoming traffic, expecting it to drop.
1741316
The traffic drop is observed due to the MAC source address being learned from the wrong direction
Product-Group=junos
On Junos EX4300/QFX5200/QFX5210 platforms with VXLAN (Virtual Extensible Local Area Network) enabled, when the ARP (Address Resolution Protocol) request is sent from the device, the MAC (Media Access Control) address is learned from the wrong direction which results in the traffic drop.
PR Number
Synopsis
Category: QFX L3 data-plane/forwarding
1666260
Traffic is not restored when l2circuit configurations are deleted and added back on QFX5K
Product-Group=junosvae
On Junos QFX5K platforms, flapping the Layer 2 circuit ports or removing and re-adding the configuration on the l2circuit ports, the re-configuration of the access side port fails and traffic ingressing or egressing out of that port gets dropped.
1704489
High CPU utilization causes a latency/slowness issue on QFX platforms
Product-Group=junos
On QFX5110 and QFX5120 platforms, latency or slowness issue is observed when the traffic is passing through a layer 3 interface configured with just family inet/family inet6 due to unwarranted MAC lookup. This could lead to traffic loss on that interface.
1724675
Traffic loss will be observed with vlan tagging and/or vlan normalisation in a specific design (using a looped cable)
Product-Group=junos
Upon upgrade to Junos versions (junos:20.3R2, 20.3R3, 20.3X75-D20, 20.4R2, 21.1R1, 21.2R1), network connectivity is lost for traffic requiring vlan normalization and having DMAC one of the switch's MAC addresses. For example, incoming traffic has two vlans (S-vlan, C-vlan) ingressing on an interface and switch uses a looped link to provide routing via an IRB. --- (S-vlan|C-vlan) -- -> SW_X --- C-vlan -- -> SW_X_irb ARP and L2 learning occurs as expected but upon receiving the frame with DMAC of a local interface, switch takes a route lookup action instead of bridging and vlan normalization due to the frame having DMAC as the MAC of one of its interfaces. Hence, the traffic is not sent via looped cable to the L3 interface.
1725375
DCPFE process crash can be seen on all Junos EX and QFX5K platforms with MACSEC enabled
Product-Group=junos
On all Junos platforms supporting MACSEC (Media Access Layer Security), the DCPFE (Dense Concentrator Packet Forwarding Engine) process might crash in a rare scenario when the configuration of MACSEC is deleted from the interface and the PFE is trying to access the memory location of the interface. The DCPFE process crash will lead to the FPC (Flexible PIC Concentrator) reboot but the system will self-recover.
1732708
SNMP polling Timeout due to OID 1.3.6.1.2.1.31.1.1.1.10.514 ( ifInOctets.514 )
Product-Group=junos
When trying to poll information via SNMP, the device stops reponding causing a SNMP timeout, the issue is due to sxe-0/0/0 private interface that is marked as public interfaces which causes it to query kernel for statistics.
PR Number
Synopsis
Category: QFX MPLS PFE
1742364
Traffic dropped is observed in the MPLS LDP scenario when the peer device MAC address is changing
Product-Group=junos
On Junos QFX5100 and EX4600 platforms when there is MAC (Media Access Control) change for the LDP (Label Distribution Protocol) neighbor and IP remains the same, the ARP (Address Resolution Protocol) update is proper but MPLS LDP may still use the stale MAC address of the neighbor. If there is any application/service such as MP-BGP using LDP as next-hop, all transit traffic pointing to the stale MAC address will be dropped.
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1665306
On QFX5K series platforms, duplicate packets might be seen in the multihomed scenario in an EVPN-VxLAN fabric when unicast ARP packets are received
Product-Group=junos
On QFX5K series platforms, when unicast ARP (Address Resolution Protocol) is received for a MAC address that is already learned in an EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) environment, the ARP request is flooded and duplicate packets might be seen on leaf devices. We might see some service impact where split-horizon might not work or continuous mac-move might be seen. This issue is rare and very unlikely to occur in a production environment due to presence of intermediate switches which might resolve the unicast ARP query.
1686539
The dcpfe process crashes on QFX5k and EX4k platforms
Product-Group=junos
On QFX5k, EX4100, EX4300, EX4400, and EX4650 platforms, the dcpfe process crash will be seen when EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) is configured.
1730771
Traffic is impacted due to high CPU and dcpfe/fxpc crash (in some cases) in EVPN-VXLAN scenario
Product-Group=junos
On Junos QFX5k and EX platforms, a high CPU and dcpfe/fxpc crash (in some cases) is seen in the EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) scenario.
1731583
Traffic drops when any of the VXLAN VLAN is deleted
Product-Group=junos
On Junos QFX5100, EX4600, QFX5200 and QFX5210 platforms whenever any of the EVPN (Ethernet Virtual Private network) - VXLAN (Virtual Extensible LAN) VLAN (Virtual Local Area Network) is removed from the interface having multiple VXLAN VLANs configured, then the VXLAN traffic for all the other VLANs within that interface is seen to get dropped.
1738276
High convergence time in the EVPN-VxLAN uplink failover scenario
Product-Group=junos
On Junos QFX5K platforms in the EVPN-VxLAN scenario, due to high convergence time, traffic loss is more than expected when the uplink to the spine disabled (CLI initiated uplink failover).
PR Number
Synopsis
Category: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1734734
Online SIBs will go down due to a faulty SIB that triggers spmbpfe crash
Product-Group=junos
On all the QFX10000 line of switches and PTX Series routers running Junos OS, due to initialization failure of a faulty Switch Interface Board (SIB) in the device, the Switch Processor Mezzanine Board (SPMB) status process, also known as the spmbpfe process, crashes and online SIBs go down.
1742186
SPMB process will crash and PICs will not come online
Product-Group=junos
On the QFX10000 line of switches running Junos OS, due to initialization failure of a faulty Switch Interface Board (SIB) in the device, the Switch Processor Mezzanine Board (SPMB) status process, also known as the spmbpfe process, crashes and online SIBs go down. Traffic cannot flow through the line card when this happens.
PR Number
Synopsis
Category: QFX5100 Virtual Chassis
1718062
VCP ports on 10G not coming up after reboot
Product-Group=junos
In a VC of QFX5100-24Q with an expansion module EX4600-EM-8F, if VC is formed on 10G ports then after the reboot of VC, the 10G connections will be lost and the line card will show as not present. This will impact traffic on the 10G ports after connection is lost.
1746788
[QFX5K]When RSI(request support information) is executed in the VC configuration, some errors output.
Product-Group=junos
On QFX5K platform, "request pfe execute ... target fpc" in RSI is always executed on mater role in the VC configuration and you can see some errors
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Platfom issues
1710952
No alarm is raised when PSU is inserted with different airflow directions
Product-Group=junosvae
On QFX5100/QFX5110/QFX5120/QFX5200 platforms, no alarm would be raised even though inserted PSU module which has a different airflow.
1720884
Interface with QSFP+-40G-CU50CM will be down
Product-Group=junosvae
The interface will be down on EX and QFX platforms with QSFP+-40G-CU50CM (740-044512) resulting in traffic loss. In the VCP (Virtual Chassis port) scenario if connected with QSFP+-40G-CU50CM it does not come up and break the VC (Virtual Chassis) environment when upgrading or rebooting the device.
1725116
The 100G interface will remain down post rebooting the device
Product-Group=junosvae
On the Junos QFX5200 platform, sometimes upon restarting the device the 100G link will not come up and will remain down, impacting the traffic flowing through it.
PR Number
Synopsis
Category: RPD infrastructure issues related to NSR, GRES, switchover,
1701146
The rpd crash will be observed when any commit is performed
Product-Group=junos
On all Junos and Evolved platforms with RSVP auto-mesh dynamic tunnel configuration, whenever a commit is done the rpd (Routing Process Daemon) crash will be seen. This happens due to null pointer access in the memory.
PR Number
Synopsis
Category: KRT Queue issues within RPD
1721032
Local route is not added in the secondary FIB on all Junos SRX platforms and routes will be permanently stuck in KRT queue
Product-Group=junos
On all Junos SRX platforms when ST (Secure-Tunnel) interface with P2MP (Point-to-Multipoint) is configured and interface routes are leaked via RIB-group (Routing Information Base), local route of the ST interface will not be leaked into forwarding-table of the secondary-RIB and it will be stuck in the KRT (Kernel Routing Table) queue.
PR Number
Synopsis
Category: RPD policy options
1706143
Issue in committing more than 23, 4-byte AS on Junos and Junos Evolved platforms
Product-Group=junos
On all Junos and Junos Evolved platforms, when a 4 byte autonomous system (AS) number is committed with more than 23 as-path in as-path-prepend policy it gives "rpd string" error and the configuration commit fails.
1744449
Policy change to a rib-group import-policy configured with global routing-options interface-routes causes the rpd issue on all platforms with EVPN-VXLAN configuration
Product-Group=junos
When a user configures "set routing-options interface-routes rib-group " along with an import policy for that particular rib-group, it will result in an unexpected behavior. It could disrupt the rpd or result in the rpd running at 100%. This issue is only related the "interface-routes" being configured in the global routing-options hierarchy with EVPN-VXLAN configuration. This issue won't be seen when routing-options configurations can have "interface-routes" enabled under specific routing instance.
PR Number
Synopsis
Category: RPD route tables, resolver, routing instances, static routes
1716153
Multipath route is not getting compute and skip the multipath eligibility check
Product-Group=junos
On all Junos platforms, multipath route will not be formed correctly when a BGP route is received from RR (Route Reflector) and preference decided based on cluster list length.
1742147
Memory leak observed when reconfiguring the flow routes
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if the nexthop of a flow route is the same as it was before when reconfiguring flow routes, memory leak occurs. High memory use of routing process daemon(rpd) is seen as a result of this leak. A kernel out of memory message is observed which results BGP flap.
PR Number
Synopsis
Category: Secure Web Proxy functionality on Junos
1623738
Secure Web Proxy with Custom App required HTTP_PROXY
Product-Group=junos
Secure Web Proxy with Custom Application won't function after upgrading into Junos 20.1.
PR Number
Synopsis
Category: SNMP Infrastructure (snmpd, mib2d)
1691986
Consistent high CPU usage is seen on the device post reboot
Product-Group=junos
On all Junos and Junos Evolved platforms consistent high CPU usage in snmpd immediately after reboot.
PR Number
Synopsis
Category: SRX Argon module
1737442
Intermittent core-dumps is received when SMB protocol is enabled on AAMW policy and PFE memory is exhausted
Product-Group=junos
On SRX platforms, When Server Message Block(SMB) protocol is enabled on advanced anti-malware(AAMW) policy and PFE memory is exhausted in that condition, SMB and SMTP is calling the same fallback API results high memory utilization. There are two types of cores is generated one is from AAMW plugin and the other is from DNS plugin. Both of them are because memory is exhausted and these high memory utilization can cause PFE process crash which results network outage for a while.
PR Number
Synopsis
Category: SRX branch platforms
1713759
Continuous vmcores observed on the secondary node when committing the "set system management-instance" command
Product-Group=junos
On Junos SRX3xx series platforms, when the "set system management-instance" command is committed on the secondary node, continuous vmcores are observed on primary and secondary nodes. No recovery action is needed for the primary node and the secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until the management-instance knob is removed using the "delete system management-instance".
1715247
Interface speed stays 100Mbps when removing speed and duplex command separately
Product-Group=junos
On SRX branch series, when the interface speed is set to 100Mbps and the link-mode is set to full-duplex, the interface speed remains at 100Mbps even the speed and duplex commands are removed separately.
1719108
OAM not working with flexible-vlan-tagging
Product-Group=junos
OAM is not working when flexible-vlan-tagging is enabled
PR Number
Synopsis
Category: Stout cards (MPC7, MPC8, MPC9) microkernel issues
1727427
FPC crash observed when the ASIC usage is high
Product-Group=junos
On platforms with MS-MPC/MPC1/2/3/4/5/6/7/8/9/JNP10K-LC2101/JNP10003-LC2103/JNP10K-LC480 line cards and EX9200/EX9204/EX9208/EX9214/EX9251/EX9253 series devices, route churn (add or deletes) when the ASIC usage crosses a threshold (ASIC usage is high) which leads to a FPC crash.
PR Number
Synopsis
Category: SRX-1RU platfom related protocol, QoS, filtering features et
1729284
L2 channel error counter increases when unknown family packets received by interfaces
Product-Group=junos
On SRX4600 and SRX5K platforms, the L2 channel error counter will increase when some unknown family packets received by interfaces.
1737721
Junos OS installation using USB can fail on SRX4600
Product-Group=junos
On SRX4600 platforms, Junos OS installation using USB can fail due to slow USB detection.
PR Number
Synopsis
Category: ZT/YT pfe qos software issues
1715149
DSCP field in IPv4 header is incorrectly re-written
Product-Group=junos
On Junos platforms that support MPC10/MPC11/LC9600 line cards, whenever there is a rewrite rule configured to rewrite the DSCP bits on transit router in core network, packet loss are observed in the destination due to incorrectly re-written DSCP field in IPv4 header.
1729747
Egress CoS rewrites won't work and that may lead to QoS specific issues downstream
Product-Group=junos
On Junos platforms, when the Preserve Next Hop routing knob is enabled, MPLS (Multiprotocol Label Switching) EXP rewrites on the transit router do not work. CoS (Class of Service) behaviour seen for the packets downstream of this node may not be on expected lines . There could be drops where it is not expected.
PR Number
Synopsis
Category: ZT/YT pfe firewall software
1692781
The FPC crash is observed with out-of-bound access to the filter action table
Product-Group=junos
On all Junos platforms with MPC10 and above line cards, the FPC crashed due to out-of-bound filter access observed during back-to-back GRES operations.
PR Number
Synopsis
Category: ZT/YTpfe bridging, learning, stp, oam, irb software
1628270
EVPN flood filter might not work for MPC10/MPC11 line cards
Product-Group=junos
On all MX platforms equipped with MPC10/MPC11 line cards, when the flood filter is configured in EVPN(Ethernet Virtual Private Network) family on the PFE(Packet Forwarding Engine), the line card might fail to program the filter.
1668837
EVPN PE router might respond traceroute with unexpected source IP address to remote CE
Product-Group=junos
In EVPN inter-subnet forwarding(type-5 route) scenario, when user performs end-to-end traceroute across provider network, destination PE responds with lowest IP address instead of the IP address from CE-facing interface. /// Example. /// CE1 = .2 10.aa.aa.0/30 .1 = PE1 = P = PE2 = .2 10.cc.cc.0/30 .1 = CE2 * PE2 also has another interface with address 10.bb.bb.1 in the routing-instance connecting to CE2. user@CE1> traceroute 10.cc.cc.2 no-resolve traceroute to 10.cc.cc.2 (10.cc.cc.2), 30 hops max, 52 byte packets 1 10.aa.aa.1 37.732 ms 17.871 ms 22.005 ms 2 10.bb.bb.1 66.004 ms 55.093 ms 66.200 ms <<<===== Should be 10.cc.cc.1 3 10.cc.cc.2 54.561 ms 55.107 ms 55.191 ms.
PR Number
Synopsis
Category: ZT/YT pfe l3 forwarding issues
1719763
L2 circuit connection not working with flow-label knob
Product-Group=junos
On Junos MX platforms, packet drop is seen in Layer 2 circuit when flow-label is enabled along with control-word and the egress Provider Edge (PE) core facing interface is on MPC10E/11E/LC9600/MX304-LMIC16. Certain flows will get punted to RE (Routing Engine) instead of getting forwarded.
PR Number
Synopsis
Category: ZT/YT pfe mpls- lsps, rsvp, vpns- ccc, tcc software
1653562
BGP PIC Edge might cause traffic Black-holing after selector corruption
Product-Group=junos
On MX series platform when chained-composite-next-hop ingress L3VPN knob is used along with internal and external BGP paths used and if IGP or BGP sessions flap BGP multi-path may not select appropriate next-hop (BGP multipath may select old stale session-id) that result into traffic drop.
PR Number
Synopsis
Category: ZT/YT pfe, vpls, mesh group software
1695438
The BUM packets are getting dropped on MX platforms during egress processing due to PFE mismatch
Product-Group=junos
The BUM (Broadcast, Unknown Unicast, and Multicast) packets are getting dropped at egress processing on all MX platforms due to an interoperability issue of MPC1/MPC2/MPC3/MPC4/MPC5/MPC6/MPC7/MPC8/MPC9 with MPC10/MPC11/LC9600 line card. It is observed when equal-cost multipath (ECMP) is enabled for the load-sharing data for an incoming traffic destined to the neighbours. It can be seen with any ECMP traffic distribution configuration.
PR Number
Synopsis
Category: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1718595
Subscribers disruption is seen on the AE interface after the "disable-pfe" action
Product-Group=junos
On all MX platforms with MPC7/8/9/LC2101/LC2103 line cards, when a "disable-pfe" action is executed for major cmerrors, there will be improper flagging of timeouts and incorrect logging out for all subscribers in scenarios where an AE(Aggregated Ethernet) interface is present on the disabled PFE(Packet Forwarding Engine).
PR Number
Synopsis
Category: Trio pfe stateless firewall software
1742123
Inline-monitoring will not work as expected when more than one instances are configured
Product-Group=junos
On all Junos MX and EX9200 platforms, when more than one instances of the "inline-monitoring" service are placed under firewall filter, all prefixes point to the firewall filter first term regardless of the match condition which results in inline-monitoring not working as expected.
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1643416
RE switchover may result in traffic loss in a certain scenario
Product-Group=junos
On all Junos platforms that support MPLS with GRES and NSR enabled, on RE switchover through CLI or system reboot, traffic loss may happen.
1720772
VLAN rewrite will not work for traffic egressing on IRB over L2 AE IFL
Product-Group=junos
On Junos MX and EX92XX with specific line cards, VLAN rewrites will not happen for traffic egressing from IRB(Integrated Routing and Bridging) interface over an L2 AE (Aggregated Ethernet) IFL (Interface Logical), if the L2 AE IFL is configured to perform VLAN rewrites on the frames. This happens when the IRB is configured as a routing-interface on EVPN (Ethernet Virtual Private LAN) or VXLAN (Virtual Extensible LAN) routing instances and the traffic has to egress on IRB over an L2 AE IFL. As a result, the frames are forwarded with incorrect VLAN tag information.
1727049
Multiple CFM sessions are down when vlan rewrite feature is configured on AE interfaces
Product-Group=junos
On MX platforms, in Aggregate Ethernet (AE) interfaces having the member links in MPC1 to MPC9 line cards with Circuit Cross-Connect (CCC) when Maintenance Association End Point(MEP) is configured a new Virtual Local Area Network (VLAN) rewrite feature has been added before punting the Cross-connect Continuity Check Message (CCM) packets. This feature is derived from the AE member interfaces where the Packet Forwarding Engine (PFE) instance of the member is wrongly updated causing the Connectivity Fault Management (CFM) sessions down.
1731564
VPLS traffic gets blackholed by qualified-bum-pruning mode
Product-Group=junos
On all MX and EX9K platforms, qualified-bum-pruning-mode completely blackholes VPLS (Virtual Private LAN Service) traffic with network-services configured in enhanced-ip mode.
PR Number
Synopsis
Category: Trio pfe l3 forwarding issues
1714656
Incorrect Destination MAC and Source MAC addresses while processing transit packets over LT IFL
Product-Group=junos
On MX platforms with MPC10, MPC11, LC9600, and MX304-LMIC16, while processing transit packets over LT IFL (logical interface) incorrect Destination MAC and Source MAC addresses are observed when the Ethernet encapsulation type is configured on the LT interface.
1739854
Major alarms will be observed on the FPC when ALB is enabled under AE interface
Product-Group=junos
On Junos MX platforms with MPC2-MPC9 line cards configured with ALB (Adaptive Load Balancing) under AE (Aggregate Ethernet) interface and Network-Services IP mode, when the AE interface comes up initially or activating AE after deactivating, the error logs of "Bad JNH Write to unilist-selector" and "LUCHIP Uncorrectable ECC" would be observed. These errors will lead to major alarms on the FPC (Flexible PIC Concentrators) causing traffic impact.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1638847
The mustd process crash might be observed with persist-group-inheritance
Product-Group=junos
On all Junos and Junos Evolved platforms configured with persist-group-inheritance, which is enabled by default from 19.4R3 onwards, might lead to mustd process crash in highly scaled configuration.
1648744
JDI-RCT:M/Mx: While removing VRRP configs and adding them back, mgd process stuck at 100% and router hangs forever.
Product-Group=junos
While removing VRRP configs and adding them back, the mgd process stuck at 100% and the router hangs forever.
1693630
In JUNOS EVO "show | display inheritance" does not work correctly for LSPs with whitespace in the name
Product-Group=junos
An LSP with whitespace in the name does not display correctly when viewing the configuration using 'show | display inheritance'
1730336
The rpd crashes and the commit operation fails while pushing a large configuration with the "extend-size" knob enabled
Product-Group=junos
On all Junos platforms, when the 'extend-size' knob is configured and a scaled configuration is committed, the rpd daemon crash is seen and the commit operation fails.
1745565
The mgd process crash is observed when 'show' is executed from the configuration mode
Product-Group=junos
On all Junos platforms, when 'show' is executed from the configuration mode, a mgd process crash is observed which has no functionality impact.
PR Number
Synopsis
Category: web filterig issues
1715260
utmd core has seen at commit when *.* or *.*.* is configured at url-pattern
Product-Group=junos
When url-pattern contains '*.*' or '*.*.*', utmd core is generated and commit fails .
PR Number
Synopsis
Category: Virtual Private LAN Services
1680687
The rpd crash is seen due to the creation of a new logical interface
Product-Group=junos
On all Junos Evolved and Junos MX platforms, when a new logical interface(LSI) is created, but the configuration was deleted as the kernel failed to add the interface will lead to rpd crash.
PR Number
Synopsis
Category: usf url filtering related issue
1737670
URL-Filtering few HTTP sites are getting bypassed and redirect is not happening
Product-Group=junos
On Junos MX series platforms with service card (SPC3, MS-MPC and MS-MIC), when the contents in the url-filter-database file are in upper case, the URL (Uniform Resource Locator) filtering fails to filter those HTTP (Hypertext Transfer Protocol) URIs (Uniform Resource Identifier) which are meant to be redirected.
PR Number
Synopsis
Category: usf ipsec related issues
1744601
With multiple Traffic Selectors having same remote-ip, the traffic works only for first tunnel on MX platforms with SPC3 cards
Product-Group=junos
In MX-SPC3 IPSec deployments, if multiple traffic selectors are configured with same remote-ip (different local-ip), the traffic works only for one of the tunnels.
PR Number
Synopsis
Category: usf logging and reporting function related issues
1744563
[USF - SPC3 - LOGGING] "log-tag" is not populated in the cgnat syslogs intermittently
Product-Group=junos
Sometimes, the log-tag within a stream is not used in syslog generation.
PR Number
Synopsis
Category: usf nat related issues
1598382
The TCP keepalive does not reach host on the private Network
Product-Group=junos
On all MX platforms with SPC3 cards where tcp-tickle knob is enabled under services-options in DS-lite (Dual-Stack lite) with NAT scenario , TCP keepalive sent by AFTR (Address Family Transition Router) will not be properly encapsulated by IPv6 addresses.
1729801
Traffic drops are observed on MX Platform configured with PCP mapping along with NAT
Product-Group=junos
On all MX platforms with SPC3 cards and PCP (Port Control Protocol) with NAT (Network Address Translation) configured, the PCP client should renew the mapping before its expiry time to keep the PCP mapping always active. The sessions are not refreshed with the received PCP mapping refresh. The issue is seen if the traffic from outside the network (public network) toward B4 (softwire initiator) was suspended for sometime. When traffic started again toward B4 from outside the network, it will be dropped and service will be impacted.
List of Known Issues is attached to this SRN.
Modification History
First Publication 2023-08-24
21.2R3-S6: Software Release Notification for JUNOS Software