Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Alert Description

Junos Software Service Release version 21.2R3-S6 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.2R3-S6 is now available.

21.2R3-S6 - List of Fixed issues 

PR NumberSynopsisCategory: EX4300 PFE
1722284Native VLAN traffic is getting dropped in the Q-in-Q scenario on EX4300
Product-Group=junos
On Junos EX4300-24T/24P when the native CVLAN (Customer Virtual Local Area Network) ID is configured for Q-in-Q setup, the traffic for that particular VLAN gets dropped even if the knob "input-native-vlan-push" is configured. This issue is encountered when the when inner-tag matches 'native-vlan-id' irrespective of the outer tag.
1729636Traffic loss is seen after configuration changes related to VSTP are committed
Product-Group=junos
On EX4300 platforms, when RSTP (Rapid Spanning Tree Protocol) and VSTP(VLAN Spanning Tree Protocol) are configured on two different interfaces which are part of the same VLAN (Virtual LAN), the RSTP-enabled interface will drop traffic after doing a configuration change in VSTP for the specified VLAN.
PR NumberSynopsisCategory: EX2300/3400 platform
1737524VC on EX3400 platforms will not form with 40GBASE-BXSR optics
Product-Group=junos
On Junos EX3400 platforms, the Virtual Chassis will not form if 40GBASE-BXSR optics are used on VCPs (Virtual Chassis ports).
PR NumberSynopsisCategory: SRX DNS DGA and tunneling related
1717503The srxpfe core has been seen on secondary SRX during ISSU
Product-Group=junos
On all Junos SRX platforms, when in-service software upgrade (ISSU) is in progress and if any traffic received by DNSF plugin leads to the srxpfe core.
PR NumberSynopsisCategory: Fireall support for ACX
1737999Transit VPN traffic towards local CE failed in ARP resolution due to VRF lo0.x RE filter in place
Product-Group=junos
On ACX1K/2K platforms, when a lo0.x filter is configured under a vrf type routing-instance, any IPv4 transit traffic that makes ARP request to generate to the CE-facing interfaces will fail in ARP resolution due to the ARP request packets are discard by lo0.x filter if no specific term to accept the IPv4 packets
PR NumberSynopsisCategory: ACX L3 IPv4, IPv6 support
1707932L2VPN traffic is dropped as the default MTU is less by 4 bytes
Product-Group=junos
On Junos ACX platforms, due to Maximum Transmission Unit (MTU) mismatch, L2VPN (Layer 2 Virtual Private Network) traffic will be dropped on the egress interface facing Customer Edge (CE).
PR NumberSynopsisCategory: ACX MPLS
1720827The Forwarding Engine Board (FEB 0) crashes and impacts traffic when the L2circuit IGP primary path port is down
Product-Group=junos
On Junos ACX1000, ACX1100, ACX2000, ACX2100, ACX2200, and ACX4000 platforms, the Forwarding Engine Board (FEB 0) will crash when the L2circuit Interior Gateway Protocol (IGP) primary path port on the local device is down. Sub-minute traffic loss is seen when FEB 0 crashes. This issue is seen only when 'hot-standby' mode is in place for L2circuit and not seen with just 'standby' mode.
1726711[ACX5048] L2circuit might drop forwarding traffic after flaps although it's in UP state; acx_rt_ccc_eth_vpws_vpn_uni_port_add: UNI VPWS port_add failed AC-IFL: <> VPN: <> (-15:Invalid configuration)
Product-Group=junos
- Upon multiple operations of deactive/active of the interface, pfe related mpls uni port stale entry might be created with invalid match vid due to which tagged traffic start dropping. - If the system is in the issued state, then the problematic l2circuit might be identified with the error logs seen below upon l2circuit flaps. fpc0 acx_bcm_mpls_uni_port_delete: VPWS port_del failed VPN: 12443 (-7:Entry not found) fpc0 acx_bcm_mpls_uni_port_add: NNI VPWS port_add failed (-15:Invalid configuration) fpc0 acx_rt_ccc_eth_vpws_vpn_uni_port_add:UNI VPWS port_add failed AC-IFL: 715 VPN: 12443 (-15:Invalid configuration) - Upon the l2circuit hits the issue, even if it's up and running after the flap, it might drop all traffic forwarded.
PR NumberSynopsisCategory: ACX Services feature
1612212On Junos platforms, cfmd core dumps might be seen in the logs if CCM configuration is changed from AE IFL to the physical IFL in a single commit
Product-Group=junos
On Junos platforms, when CCM configuration is changed from the AE IFL to the physical IFL which is a part of the AE bundle, cfmd core dumps might be seen in the logs.
PR NumberSynopsisCategory: "agentd" software daemon
1715377The agentd would become unresponsive on all Junos platforms
Product-Group=junos
When using Junos Telemetry Interface (JTI) with subscriptions to Packet Forwarding Engine (PFE) based sensors, agentd might slowly leak memory. After prolonged runtime agentd may stop functioning properly, which will affect JTI data export. This will affect telemetry services.
PR NumberSynopsisCategory: MPC Fusion SW
1744883100G interfaces will flap due to RE switchover on Junos MX platforms with MPC3E-3D-NG/ MPC-3E-3D-NG-Q linecards
Product-Group=junos
On Junos MX platforms with MPC3E-3D-NG/MPC-3E-3D-NG-Q linecards, 100G interfaces will flap due to RE (Routing Engine) switchover.
PR NumberSynopsisCategory: Application Quality of Experience
1743107flowd process crash observed in Junos branch SRX platforms
Product-Group=junos
This issue is observed on Junos SRX platforms supporting SD-WAN (Software-defined Wide Area Network) like SRX300, SRX320, SRX340, SRX345, SRX380, SRX550, SRX1500, SRX4100, SRX4200, SRX4600, SRX5600, SRX5800, cSRX and vSRX in AppQoE (Application Quality of Experience) scenario where the passive probe session of SD-WAN is not closed gracefully. This results in flowd crash and impacts user traffic.
PR NumberSynopsisCategory: A15 specific issue
1738188Failover can be seen on SRX5K cluster with SPC2 cards while executing RSI
Product-Group=junos
On all SRX5000 series platforms with SPC2 cards configured in a chassis cluster, when RSI is being collected which has the command 'i2csc fpc' in the script, an interrupt storm generates a CB (Control Board) alarm which triggers a failover. Intermittent traffic disruption could be seen till the failover is complete.
PR NumberSynopsisCategory: dynamic vlan creation and associated processing
1743903If more than 32 vlan ranges are configured under the dynamic-profile then login issue and traffic impact can be seen with subscribers of random VLANs
Product-Group=junos
On all Junos platforms that support subscriber services, when more than 32 VLAN ranges are configured, random VLAN (Virtual Local Area Network) traffic is impacted and subscribers are unable to login.
PR NumberSynopsisCategory: BBE OS Infrastructure library
1732216'max-db-size' configuration is optional in routers having DRAM greater than or equals to 32GB
Product-Group=junos
On Junos MX platforms, to enable Enhanced Subscriber Management feature without 'max-db-size' configuration on router >=32GB DRAM(Dynamic Random Access Memory), router needs to be rebooted only once instead of rebooting twice.
PR NumberSynopsisCategory: BBE packet trigger access model issues
1726136PTSP subscribers are stuck in 'configured' state
Product-Group=junos
On MX platforms supporting packet-triggered subscribers and policy control (PTSP) feature, a high percentage of packet triggered subscribers are getting stuck in 'Configured' state due to an authentication failure.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1725971Multiple flaps of the interface will cause the BFD session to be down
Product-Group=junos
On all Junos and Junos Evolved platforms, the IPv4 static route BFD (Bidirectional Forwarding Detection) session may stay down if the corresponding interface flaps multiple times.
PR NumberSynopsisCategory: Border Gateway Protocol
1643665The BGP route may still be present in the multi-path route after increased IGP cost
Product-Group=junos
On all Junos and EVO platforms, when color-only is used and the igp-cost of the active path is high, then the BGP route may still be present in the multi-path route after increased IGP cost.
1670715The rpd process crash is observed when running BGP-LS EPE configuration with RIB sharding enabled
Product-Group=junos
The rpd process crash is observed when running BGP-LS (Border Gateway Protocol - Link-State) EPE (Egress Peer Traffic Engineering) configuration with RIB sharding enabled since the label allocation is only allowed in the main thread. But the shards thread was trying to allocate the label during EPE configuration parsing.
1679495RV task replication will be stuck in the "NotStarted" state when routing-options validation is deactivated/activated
Product-Group=junos
On all Junos and Junos Evolved platforms with Non-Stop Routing (NSR) enabled, in a rare case, Route Validation (RV) task replication will be stuck in the "NotStarted" state when routing-options validation is deactivated/activated.
1687887More than expected traffic loss is seen with ECMP FRR enabled during link down scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, in a link down/BFD (Bidirectional Forwarding Detection) down event traffic loss is seen to occur more than the expected with ECMP (Equal-Cost Multipath) FRR (Fast Reroute) or BGP PIC (Prefix-Independent Convergence) configured.
1712527The PE advertises incorrect next-hop towards CE although BGP export policy configured with next-hop under policy-statement
Product-Group=junos
The show route advertising-protocol bgp reporting nexthop self rather than IP in the configured policy-statement for next-hop.
1728455The rpd process crashes when BGP is cleaned up
Product-Group=junos
On Junos and Junos OS Evolved platforms, if static default RT-C (Route Target -Constrain) is configured when Border Gateway Protocol (BGP) is cleaned up (whole BGP is cleaned up), the routing process will crash.
1728604Traffic impact is seen when there is a single peer in the proxy BGP group connected to the BGP route reflector
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if the proxy BGP (Border Gateway Protocol) route reflector is connected to the only peer present in the BGP group then it stops advertising the routes coming from the remote cluster and that leads to proxy route-target routes not getting added which causes traffic disruption.
1732833RPD core files might be seen when BGP RIB sharding is used
Product-Group=junos
RPD might stop responding and generate core files (or dump files) when BGP RIB sharding is used.
1739335The rpd process crash will be observed when the prefix-limit exceeds on the backup RE
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with BGP (Border Gateway Protocol), NSR (Nonstop Active Routing), and prefix-limit with idle-timeout, when the prefix-limit exceeds on the backup RE (Routing Engine) and switchover is performed the rpd process crash will be observed on the new backup RE.
1739919Junos OS and Junos OS Evolved: A BGP session will flap upon receipt of a specific, optional transitive attribute (CVE-2023-0026)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA71542 [juniper.net] for more details.
1742416RPD scheduler slip is observed when the BGP session flaps and subsequent configuration changes for the same peer
Product-Group=junos
On all Junos and Junos Evolved platforms, high CPU (RPD scheduler slips) leads to session timeouts/flaps for other protocols running in the system.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1653130The rpd might crash when BMP rib-out monitoring is configured for flow-spec route
Product-Group=junos
On all Junos and Evolved platforms, rpd crash might be seen when BGP monitoring protocol (BMP) rib-out monitoring is configured for the flow-spec route. Since there is no next-hop for flow-spec route core might be seen while generating rib-out feed. Traffic loss might be seen due to this crash.
PR NumberSynopsisCategory: BBE Remote Access Server
1729035Potential memory leak in authd process
Product-Group=junos
If RADIUS is enabled for subscriber authentication or accounting, the authd process may occasionally leak memory when running at a high scale.
PR NumberSynopsisCategory: MX Platform SW - Power Management
1703566Alarms for PEMs are still seen when PEM are removed from the chassis
Product-Group=junos
Alarms for PEMs are still seen when PEM are removed from the chassis
PR NumberSynopsisCategory: Chotu platform software
1720407Reachability loss between Master and backup RE in certain condition on MX2008 platform
Product-Group=junos
On the Junos MX2008 platform, the synchronization will be lost between the master RE (Routing Engine) and the backup RE when the AE (Aggregated Ethernet) configuration is being applied. This issue is seen after the node reboot or backup RE is rebooted and is because the control interface ixlv0 of the RE is not established during the AE configuration. This issue is self-recoverable.
PR NumberSynopsisCategory: Class of Service
1734013The CoS scheduler map will not get attached to the sub-interface correctly when shaping-rate and scheduler-map are configured on it
Product-Group=junos
On all MX platforms, when shaping-rate and scheduler-map are configured on a sub-interface and a wildcard expression for sub-interfaces is used in the class-of-service interface definition, then the CoS (Class of Service) scheduler map will not get attached as per the configuration to the sub-interface and will not work correctly. Example: set class-of-service interfaces unit * classifiers.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for cos
1713968Subscribers connectivity is lost due to multiple MIC restart on all Junos MX platforms with MPC5E and BBE configuration
Product-Group=junos
On all Junos MX platforms with MPC5E and BBE (Broadband Edge) configuration, subscribers connectivity will be lost due to multiple MIC (Modular Interface Card) restart.
PR NumberSynopsisCategory: CFM
1682939Maintenance-domain (MD) and Maintenance-association (MA) configuration display changed to ordered-by-system type
Product-Group=junos
With this the maintenance-domain (MD) configuration and maintenance-association (MA configuration) under the connectivity-fault-management stanza will be ordered by the system and not as per the configuration order.
PR NumberSynopsisCategory: L2NG Access Security feature
1724933On certain Junos EX and QFX platforms the static ARP entries for DHCP-security are not present
Product-Group=junos
On certain Junos EX series switches, the static MAC (Media Access Control) bindings are not present in certain conditions. This issue will be seen when the static DHCP (Dynamic Host Configuration Protocol)-security ARP(Address Resolution Protocol) bindings are moved from an interface having a higher interface number to an interface with a lower interface number. Due to the binding not happening, there will be impact on the traffic. The workaround when such a binding change is done is to restart the DHCP services after the configuration is committed.
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1723968Traffic loss is seen as Type 2 routes are not pushed even after withdrawing Type 5 routes
Product-Group=junos
On all Junos and Junos Evolved platforms with the EVPN (Ethernet VPN) Type 2 and Type 5 Coexistence and when the host route changes from EVPN Type 5 route to non EVPN route in the rpd, traffic loss is observed as Type 2 routes are not getting pushed even after withdrawing Type 5 routes.
PR NumberSynopsisCategory: Device Configuration Daemon
1714267The interface speed gets set to a lower speed when the interface is disabled and enabled because renegotiation of the interfaces happens at the previously negotiated speed
Product-Group=junos
On Junos platforms with MPC line cards, negotiated interfaces will try to come up with the speed already negotiated instead of using the original interfaces speed even if re-negotiation happens like reinserting cable.
1731190The lt/vt/ut interfaces may not recover from the disable-pfe (admin down) state if the GRES switchover is done before restarting FPC
Product-Group=junos
On all Junos Platforms when a PFE (Packet Forwarding Engine) gets disabled to a CM (Chassis Manager) error disable-pfe action or any other reason and a GRES (Graceful Routing Engine Switchover) happens, the lt/vt/ut (Logical Tunnel/Virtual Tunnel/Uplink Tunnel) interfaces will not recover after the FPC (Flexible PIC Concentrator) restart even though the error condition is recovered resulting in traffic loss.
PR NumberSynopsisCategory: CoS support on DNX
1704589Traffic drops seen after making COS configuration change on ACX710
Product-Group=junos
On Junos ACX710 platforms, when CoS (Class-of-Service) scheduler changes are done for buffer usage and when traffic is flowing which involves bursty traffic, traffic drops are seen.
PR NumberSynopsisCategory: EVPN ELAN/E-TREE
1689267FPC crashes and goes into down or unknown state in a scaled EVPN setup
Product-Group=junos
On Junos ACX5448 and ACX710 platforms with scaled EVPN (Ethernet Virtual Private Network) setup, a 'restart routing' can trigger the PFE (Packet Forwarding Engine) crash and the FPC (Flexible PIC Concentrator) will get stuck either in down or unknown state resulting in a total traffic impact.
PR NumberSynopsisCategory: BGP MPLS VPN specific issues
1719507L3VPN traffic loss and PFE errors can be seen after an LSP Flap
Product-Group=junos
On all Junos ACX platforms, when L3VPN (Layer 3 Virtual Private Network) and MPLS-LSP (Multiprotocol Label Switching - Label-Switched Paths) is configured, L3VPN traffic loss and PFE (Packet Forwarding Engine) errors can be seen after an LSP flap.
PR NumberSynopsisCategory: ACX VxLAN Issue
1665828MAC-IP bindings for IPv4 (ARP) and IPv6 (ND) may not be processed for IRB interfaces in an EVPN scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, when EVPN (Ethernet Virtual Private Network) related configuration is introduced from baseline, due to a rare timing issue between the IRB (Integrated Routing and Bridging) interfaces coming up and an attempt is made by the 'l2ald' (l2 address learning) daemon to process the corresponding MAC-IP entries, this issue may occur. This may also occur when IRB logical units are activated and deactivated.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1714149Junos OS: MX Series: The FPC will crash on receiving a malformed CFM packet (CVE-2023-36848)
Product-Group=junos
An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (ppmd) of Juniper Networks Junos OS on MX Series(except MPC10, MPC11, and LC9600) allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA71659 [juniper.net] for more information.
PR NumberSynopsisCategory: ESIS routing protocol
1720303The ES-IS route is not getting installed in the .iso.0 routing table
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when the protocol ES-IS (End System to Intermediate System) is configured under routing-instance (non-master instances) then upon upgrading the device to releases 21.1R1 onwards the ES-IS route will not get installed in the .iso.0 route table leading to a service outage.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1646010IRB might not send out arp-reply if "no-arp-suppression" is configured
Product-Group=junos
On all Junos platforms, when "no-arp-suppression" is configured, the Layer 2 Address Learning Manager (L2ALM) will not respond to Address Resolution Protocol (ARP) request for Integrated Routing and Bridging (IRB) IP, and traffic to IRB will be lost.
1669811BUM traffic might be blackholed for ESI configured CE interface flap
Product-Group=junos
On Junos MX/QFX5K/QFX10K platforms and Junos Evolved ACX/MX platforms, on interface up/down event loop prevention might not work resulting in BUM traffic being blackholed.
1700170In EVPN-VXLAN scenario, whenever there is any interface flap, this issue might be hit.
Product-Group=junos
In EVPN-VXLAN scenario, whenever there is any interface flap, this issue might be hit.
PR NumberSynopsisCategory: EX4400 PFE software
1716902IGMP/MLD queries may get dropped if received on a port on the backup VC member when IGMP/MLD snooping is enabled
Product-Group=junos
On Junos QFX and EX in the VC (Virtual Chassis) scenario, when the switch is acting as pure L2 (Layer 2), and forwarding IGMP (Internet Group Management Protocol)/MLD (Multicast Listener Discovery) query as transit traffic, if IGMP/MLD snooping is enabled then IGMP/MLD queries may get dropped if received on a port on the backup VC member resulting in IGMP/MLD groups to expire.
1718286DHCP services are impacted as DHCP binding will not work as expected
Product-Group=junos
On all Junos and Junos Evolved platforms, all the DHCP (Dynamic Host Configuration Protocol) security services will be impacted as the DHCP-security binding will not work if the DHCP server-facing interface is a VTEP (VXLAN tunnel endpoint) interface.
1731522The traffic drop will be observed after changing the VSTP VLAN configuration
Product-Group=junos
On Junos EX4400, EX4100, EX2300, EX3400, and QFX5K platforms, traffic drop would happen on RSTP (Rapid Spanning Tree Protocol) enabled port attached to a VLAN (Virtual Local Area Network) when the same VLAN has VSTP (VLAN Spanning Tree Protocol) enabled on a different port and there is a configuration change done on VSTP for that VLAN.
1732271Filter term dropping VRRP traffic when "then log" is configured
Product-Group=junos
On all Junos platforms, VRRP (Virtual Router Redundancy Protocol) packet goes to a wrong CPU queue when filter is added to match VRRP packet with "then log" action, resulting in VRRP functionality impact.
1733365Error logs are seen with a non-vxlan dot1x enabled port
Product-Group=junos
In a heaviliy loaded system in a specific scenario (Dot1x in multiple supplicant mode & dynamic vlan from radius server & non vxlan access port) following log message may be captured in the syslog - {brcm_as_dot1x_vxlan_set_mac_learning_mode:1168 dot1x bd_get failed for bd index 0}. This log is not impacting any funtionality.
1736790EX4400 shaping rate not working as expected
Product-Group=junos
On EX platforms shaping rate on 100gig link over 70g not working as expected.
PR NumberSynopsisCategory: EX4400 platform
1707762BFD/LACP flaps will be seen on EX4400 platforms
Product-Group=junos
On EX4400 platforms, BFD (Bidirectional Forwarding Detection) will flap randomly along with LACP (Link Aggregation Control Protocol) flaps or VC (Virtual Chassis) connection loss.
1720074Port will be down when "no-auto-negotiation" is configured on EX4400-48F platform
Product-Group=junos
On EX4400-48F platform with Small Form Factor Pluggable 100Base-FX Fast Ethernet Optics, when "no-auto-negotiation" is configured on the interface this results in the interface not coming back online even after deleting "no-auto-negotiation" in interface.
PR NumberSynopsisCategory: Express PFE CoS Features
1719956Convergence delay is seen when FPC is offlined under heavy traffic and scaled scenario
Product-Group=junos
On Junos PTX3000, PTX5000, PTX10008, and PTX10016 routers, when the Flexible PIC Concentrator (FPC) is offlined with scale configuration and heavy traffic, a delay in convergence (into tens of minutes) is seen on all the live FPCs in the chassis other than the offlined one. This impacts traffic.
1738981DSCP classifier is not created on IP interfaces
Product-Group=junos
On Junos QFX10k platforms, on configuring diffServ code point (DSCP) classifier and when inet or inet6 is configured with custom dot1p on interface, default dscp classifiers are not getting removed properly.
PR NumberSynopsisCategory: Express PFE FW Features
1727067FPC crashes when the firewall filter is configured with above 65k prefixes in a single filter
Product-Group=junos
On the below PTX platforms ( PTX1000, PTX3000 (NextGen), PTX5000, PTX10008, PTX10016 and QFX10002), when prefixes above 65K are configured in a single firewall filter, FPC (Flexible PIC Concentrator) crash would be observed.
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1701636Aggregated Ethernet interface member with vlan-id-list configured not forwarding traffic
Product-Group=junos
On Junos QFX10002, QFX10008 and QFX10016 platforms, AE(aggregated-ethernet) interface member with vlan-id-list configured does not forward traffic thus leading to traffic loss.
PR NumberSynopsisCategory: ISIS routing protocol
1719033The rpd process crashes when TI-LFA is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd is seen to crash when TI-LFA (Topology-Independent Loop-Free Alternate) is enabled and there are ECMP (Equal-Cost Multipath) routes present.
1725686Unnecessary SPF calculation is causing high CPU utilization
Product-Group=junos
On all Junos and Junos Evolved platforms, very frequent SPF (Shortest Path First) calculation, being caused by leaking multiple prefixes across the IS-IS areas, is causing high CPU utilization.
PR NumberSynopsisCategory: jdhcpd daemon
1722082DHCP binding is not happening in EVPN VXLAN topology with DHCP stateless relay (forward-only)
Product-Group=junos
In EVPN VXLAN topology with DHCP stateless relay (forward-only) configured at layer 3 gateways, Jdhcpd broadcasts snooped unicast offer packets. That leads to the offer getting dropped on its way to the client and then the IP negotiation fails.
1731784Dhcp security bindings may not happen when DHCP security is enabled on multiple vlans along with dhcp stateless relay
Product-Group=junos
When DHCP security is enabled on multiple vlans along with dhcp stateless relay enabled at that time, dhcp security bindings may not happen.
PR NumberSynopsisCategory: JFlow bug tracker for SRX platforms
1716707J-flow sends wrong IP in sampling records when NAT is configured for traffic along with input sampling
Product-Group=junos
When NAT (Network Address Translation) is configured on interfaces along with sampling, the J-flow record will contain NAT'ed IP as opposed to the original IP.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1722877Device crashed while processing H323 traffic in SRX and MX
Product-Group=junos
The SRX Device and MX with MS-MPC and MX-SPC3 service cards, crashes due to a timing issue, while processing H323 traffic.
1728638SIP ALG not working for SIP traffic with MIME header and traffic is dropped
Product-Group=junos
On all MX and SRX platforms, SIP ALG (Session Initiation Protocol Application Layer Gateway) not working as SIP (Session Initiation Protocol) packets with MIME (Multipurpose Internet Mail Extensions) header causes traffic to be dropped.
PR NumberSynopsisCategory: Flow Module
1624707Flowd may core if route change or delete in PMI mode
Product-Group=junos
Flowd may core if route change or delete and do IPSEC encap in PMI mode in SRX5K with SPC3 platform, please upgrade to version with this fix if using PMI mode in SRX5K with SPC3.
1683334Packet loss on GRE Tunnel due to improper route look-up for tunnel destination
Product-Group=junos
On SRX platforms, due to improper route look-up for the tunnel destination if the GRE tunnel is configured in a virtual routing-instance for which packet loss is observed.
1719437The traffic will fail when accessing the routing instance interface IP from external IP
Product-Group=junos
On all SRX platforms, the flow will not jump the route from one routing instance to another, causing the traffic to fail when accessing one routing instance interface IP from external IP.
1733819The inet6 packet mode drops traffic significantly
Product-Group=junos
On the SRX branch series, inet6 packet mode (packet-based) throughput drops significantly. Traffic will be fine until the CPU reaches 100% and random traffic will be dropped.
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1708116Log streaming Hosts configured as FQDN may fail when DNS re-query is performed
Product-Group=junos
On SRX platforms, log streaming using FQDN requiring DNS name resolution may fail to re-query resulting in FQDN resolution to fail
1716776Security log missing space between timestamp and hostname
Product-Group=junos
JunOS upgrade to the 22.2R3, 21.3R3-S3, 22.4R1, 21.4R3-S3, 22.3R2, 22.4R2, 21.2R3-S4 , 22.1R3 the security log space between the timestamps and site-name is removed Eg. 2023-08-14T12:04:31.273-07:00device_host-name RT_FLOW - RT_FLOW_SESSION_CREATE_LS [[email protected] logical-system-name="JTAC-LSYS" source-address="10.10.10.10" source-port="29279" destination-address="10.10.30.20" destination-port="1603" connection-tag="0" service-name="icmp" nat-source-address="10.10.10.10" nat-source-port="29279" nat-destination-address="10.10.30.20" nat-destination-port="1603" nat-connection-tag="0" src-nat-rule-type="N/A" src-nat-rule-name="N/A" dst-nat-rule-type="N/A" dst-nat-rule-name="N/A" protocol-id="1" policy-name="ONE" source-zone-name="JTAC-Trust" destination-zone-name="JTAC-dmz" session-id="3207" username="N/A" roles="N/A" packet-incoming-interface="ge-0/0/12.0" application="UNKNOWN" nested-application="UNKNOWN" encrypted="UNKNOWN" application-category="N/A" application-sub-category="N/A" application-risk="-1" application-characteristics="N/A" src-vrf-grp="N/A" dst-vrf-grp="N/A" tunnel-inspection="Off" tunnel-inspection-policy-set="root" source-tenant="N/A" destination-service="N/A"]
PR NumberSynopsisCategory: Firewall Network Address Translation
1706541ICMP based traceroute is not showing any hops after SRX when SRX is configured with NAT64
Product-Group=junos
For all SRX platforms, ICMP based traceroute does not show any hops after SRX when SRX is configured with NAT64.
PR NumberSynopsisCategory: Firewall Policy
1725567Traffic impact is observed when the security policy is configured with a huge number of addresses and on addition/deletion of these policies
Product-Group=junos
On SRX platforms configured with security policies, having a huge number (approx. 15K) of addresses and performing addition/deletion of such policies in short intervals of time might result in srxpfe process crash and hence, data path traffic gets impacted.
PR NumberSynopsisCategory: User Firewall related issues
1683420SRX Branch models are unable to connect to domain controller on installing Microsoft KB update
Product-Group=junos
On SRX300 series and SRX550M, when the User Identification feature is used with Active Directory, after the Domain Controller server installs updates related to Microsoft's KB article KB5004442 [juniper.net], SRX is no longer able to connect to it. The PR1637548 did not fix this issue for these specific SRX platforms.
1701990The user-id entries will not be synced with secondary node
Product-Group=junos
On Junos platforms, user-id process doesn't work properly (user-id ?process also sync users primary and second node). As a result, active directory user-ip-mapping entries were not synced to the secondary node and due to that user connection will drop. When the issue happens, storage space eventually go full and the user may notice the issue at that time.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1745174IPSEC VPN does not come up in NAT-T scenario
Product-Group=junos
On all SRX platforms with IPSEC (Internet Protocol Security) VPN (Virtual Private Network) configured with main mode, if SRX is the VPN initiator and NAT-T (Network Address Translation-Traversal) is configured (which is by default), the IPsec VPN tunnel does not come up. This is a timing issue and occurs when a tunnel delete or rekey occurs.
PR NumberSynopsisCategory: Security platform jweb support
1668013J-Web page will not load properly
Product-Group=junos
On all Junos platforms, the J-Web page will not load properly for a user, if the username contains a hyphen. Due to this, users will not be able to log in via J-Web.
1735314Editing security policy configuration via J-web is enabling "Exclude Selected" unexpectedly
Product-Group=junos
On Junos platforms, when you cancel editing source/destination address in security policy using J-web, "Exclude selected" is unexpectedly enabled.
1735387Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files (CVE-2023-36847)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
1735389Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files (CVE-2023-36846)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
1748078Cannot add custom defined security address-book under Security Policies & Objects > Security Policies > Create > Source Zone > Select Sources.
Product-Group=junos
In the J-Web UI for SRX Series Firewall, when you configure the source zone for addresses in the security policy rule, the customized address-book entries are not displayed. J-Web displays only any-ipv4 and any-ipv6.
PR NumberSynopsisCategory: Junos Selective Update infrastructure
1732878The Junos Selective Upgrade (JSU) version is not removed post a major Junos upgrade/downgrade
Product-Group=junos
There is no functional impact but the previously installed JSU will show up even though it is deleted during major upgrade. This PR will fix that issue. Workaround is to remove /packages/sets/active/junos-version file.
PR NumberSynopsisCategory: Layer 2 Control Module
1739975Layer 2 traffic will be dropped on VSTP disabled interface
Product-Group=junos
On Junos platforms, Whenever an interface is disabled under VSTP (VLAN Spanning Tre Protocol) configuration, the issue will be seen in the following cases. 1. When interface, IFBD (Interface Family Bridge Domain) and VSTP, configured via single commit. (In case of new configuration) 2. When VSTP configurations are present and chassisd restarts/device reboots, then issue will be seen. (During ifd delete and add, issue will be seen)
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1680242The l2ald is treating mac as a duplicate causing traffic loss
Product-Group=junos
On all Junos and Junos Evolved platforms, with EVPN-VXLAN (Ethernet Virtual Private Network -Virtual Extensible Local Area Network) multihoming scenario, l2ald (Layer two Address Learning Daemon) considers the mac as duplicate, and traffic drop will be observed.
1723400Unable to commit configs interface-mac-limit on sub-interfaces with vlan-tagging / flexible-vlan-tagging
Product-Group=junos
On QFX10K platforms unable to configure interface-mac-limit on sub-interfaces with vlan-tagging / flexible-vlan-tagging.
1727954On all Junos and Junos Evolved platforms the l2ald process memory usage is seen to increase over time
Product-Group=junos
On all Junos and Junos Evolved platforms service impact is seen due to a consistent increase in l2ald (Layer 2 Address Learning Daemon) memory usage.
1743282The l2ald crashes when there is recursive deletion of IFBD or when BGP neighborship is cleared in EVPN-VXLAN multi-homed configuration
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in a rare scenario, due to timing issue, the l2ald (Layer 2 Address Learning Daemon) crashes and traffic is being blackholed due to recursive deletion of IFBD (Interface Family Bridge Domain) or when BGP (Border Gateway Protocol) neighborship is cleared when EVPN (Ethernet Virtual Private Network) - VXLAN (Virtual Extensible Local Area Network) with multi-homed is configured.
PR NumberSynopsisCategory: lacp protocol
1609618LACP Member interfaces might get stuck in out of sync state
Product-Group=junos
When sync-reset feature is enabled on the device then few member interfaces might stay in out of sync state even when number of available child interfaces is greater than minimum-links configured for the Lag interface. This will affect the overall capacity of the lag interface.
PR NumberSynopsisCategory: Label Distribution Protocol
1635863An rpd core is seen post graceful switchover
Product-Group=junos
An rpd (Routing Protocol Daemon) crash is seen when dual transport LDP (Label distribution protocol) is configured along with NSR (Nonstop routing).
PR NumberSynopsisCategory: MPC11 ULC interface software related issues.
1698135XQSS_CMERROR_DSTAT_INT_REG_DROP0_QDEPTH_UNDRN alarm is seen on MX2K platforms with MPC11E line cards upon aggregate interface down/flap event
Product-Group=junos
On MX2010 or MX2020 platforms with MPC11E line cards, if a member link of an aggregate interface goes down or flaps, it might trigger "XQSS_CMERROR_DSTAT_INT_REG_DROP0_QDEPTH_UNDRN" alarm and disable-pfe action is executed. The affected PFE (Packet Forwarding Engine) will be disabled and no traffic will pass through it.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1649565The error severity of syslog message "ted_client reset" generated during the commit is incorrect
Product-Group=junos
On all Junos and Junos evolved platforms, the severity of syslog message "ted_client reset" that is generated by rpd process during the commit is incorrect. It only generates an error message in the syslog .
1698889The rpd process will crash when rpd is restarted
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when MPLS (Multiprotocol Label Switching) statistics is configured without LSP (Label-Switched Path) configuration, the rpd process will crash and impact the routing protocols. This leads to traffic disruption due to the loss of routing information.
1738774Traffic blackhole due to an additional label when CCNH is toggled
Product-Group=junos
On all Junos and Junos Evolved platforms, with scaled Border Gateway Protocol (BGP) routes, when Chained Composite Next Hops (CCNH) is toggled, a few next-hops end up creating additional labels causing a traffic blackhole.
PR NumberSynopsisCategory: MX l2ng access security
1627611DHCP clients might not go to BOUND state when the AE bundle is enabled between DHCP server and snooping device
Product-Group=junos
On Junos platforms with MPC10E line cards, when AE under the IRB interface is enabled between the snooping device and the DHCP server, the DHCP bindings can be seen in snooping device and DHCP server, but the DHCP client might not go to BOUND state, it might be stuck at discovering/requesting state.
PR NumberSynopsisCategory: MX Timing software
1652275PTP Playback Engine reset error is reported sporadically with PTP FPGA Firmware version A4 7
Product-Group=junos
On Junos MX platforms, the PTP Playback Engine reset error is reported sporadically with PTP FPGA Firmware version A4 7. It has No functionality impact.
1664569Switch Fabric Board information for supporting PTP on MX10k8 with MX10K-LC2101 LC(s)
Product-Group=junos
MX10k8 with MX10K-LC2101 Linecard(s) supports *PTP* only with JNP10008-SF Switch Fabric Board(s), *PTP* currently doesn't work with JNP10008-SF2 Switch Fabric Board(s).
1704633Interface flaps are seen after PTP GM changes to a different FPC slot
Product-Group=junos
On MX platforms, when PTP (Precision Time Protocol) is configured, the interfaces will flap after the PTP GM (Grand Master) is changed to a different FPC (Flexible PIC Concentrators) slot. The flaps can last for several seconds. Chassis-SyncE clock is also influenced by PTP phase change.
1704644Software improvement for PTP nbr-update || lcinfo_bmc || utc_arrival_time || lcinfo_msg || utc_arrival_time
Product-Group=junos
Enhancement needed on PTP nbr-update to improve user experiences.
1724254On certain Junos MX platforms with SCB3 SyncE fails after enabling PTP
Product-Group=junos
On Junos MX platforms having SCB3 (Switch Control Board), the SyncE (Synchronous Ethernet) can be stuck in "Clock_Aborted" state. This issue is seen in release 20.4R3 onwards when PTP (Precision Time Protocol) is operated in hybrid mode, the SyncE failure will hinder the operation of applications like G.8275.1 deployment will fail. There is a fix in 20.4R3-S4 with JSU (Juniper Selective Upgrade) J10.2. Below are the important notes to consider regarding the verification of the fix. - -> JSU upgrade can be performed to replace the clksyncd with fix to address this issue. - -> However, if the system is already in a problem state before the JSU upgrade, a one-time deactivate and activate of "protocols PTP" and "chassis synchronization" configuration is needed to recover from the current problem state after the JSU upgrade of clksyncd is performed.
1750316SyncE stuck in holdover upon PTP slot switchover without change in PTP phase align state
Product-Group=junos
SyncE stuck in holdover upon PTP slot switchover without change in PTP phase align state.
PR NumberSynopsisCategory: MX10K platform
1674322SNMP traps "Power Supply failed" and "Power Supply OK" are not generated
Product-Group=junos
On all Junos MX10k and PTX10k platforms, when a PSU with no feeds connected, but the DIP switch at the back of the PSU is set in a position where it expects the feeds to be connected, then POWER FAILED TRAPs might not get generated as expected.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1722708ksyncd core with dhcp subscribers
Product-Group=junos
In a very rare scenario, when subscriber-management and NSR is enabled, there could be a temporary transition state where one subscriber prefix has 2 nexthop referred. In that state if a deletion happened for that particular prefix, the nexthop deletion is successfully done one master RE but the deletion is failed on the backup RE. This eventually causes nh index inconsistency and then ksyncd core on backup RE. The fix is to make sure the deletion on the backup can be done successfully.
1735686The message "kernel: %KERN-6: ARP UNICAST MODE 0; retrans_timer - 8" might be seen when commit command is run for configuration which is not related to ARP
Product-Group=junos
"kernel: %KERN-6: ARP UNICAST MODE 0; retrans_timer - 8" message might be seen when commit command is run for configuration which is not related to ARP
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1712855Unicast packets are received on the management interface even though the destination MAC is not local
Product-Group=junos
On all platforms supporting em driver for their ethernet interface, promiscuous mode is enabled by default and hence traffic storm is noticed on the management interface.
PR NumberSynopsisCategory: Kernel MPLS / Tag / P2MP Infrastructure
1723145Routing Engine initiated PING failed over MPLS interface
Product-Group=junos
The RE-generated packets that have MTU size greater than the inet MTU size get dropped when going out on an interface with MPLS chain-composite-next-hop.
PR NumberSynopsisCategory: OSPF routing protocol
1737978OSPFv3 using the VIP address on the IRB interface will not form adjacencies between peers
Product-Group=junos
OSPFv3 may not form adjacencies on IRB interfaces with VRRP configuration.
PR NumberSynopsisCategory: Express Chip L3 software
1713279Next-hop programming issue at PFE on Junos PTX and QFX10k platforms when the member of unilist is in hold state
Product-Group=junos
On PTX Series routers and the QFX10000 line of switches, traffic going over unilist is dropped when unilist member goes from next-hop hold state to unicast/aggregate state.
1738541Traffic drop observed when next-hop installation fails in a high-scale multicast/unicast scenario
Product-Group=junos
On Junos PTX and QFX10K platforms, when the Flabel (Fabric Label) memory exhaustion occurs due to the scaled unicast/multicast next-hops and interface flapping i.e. downstream interfaces of multicast flapping, traffic drop is observed for next-hop installation failure in a high-scale multicast/unicast scenario.
PR NumberSynopsisCategory: Provider Backbone (PBB) EVPN PFE functionality on MX
1529940PBB-EVPN PE cannot learn remote CE MAC address due to ARP suppression enabled
Product-Group=junos
In PBB-EVPN (Provider Backbone Bridging - Ethernet VPN) environment, ARP suppression feature which is not supported by PBB might be enabled unexpectedly. This could cause MAC addresses of remote CEs not to be learned and hence traffic loss.
PR NumberSynopsisCategory: Protocol Independant Multicast
1720708Slow convergence of PIM joins causes temporary traffic loss with scaled downstream interfaces
Product-Group=junos
On all Junos and Junos Evolved platforms with PIM (Protocol Independent Multicast), MVPN (Multicast Virtual Private Network) configured and when the number of downstream interfaces is more than three thousand, slow convergence of PIM joins is seen to take up more of the time and CPU, causing traffic loss for some time.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1739860The IPv6 link local based BFD session over an AE interface will be stuck in Init state
Product-Group=junos
On all MX platforms, when chassis network-services is set in IP mode, the IPv6 Link Local based BFD session over an AE interface will be stuck in init due to the next-hop misprogramming in the PFE.
PR NumberSynopsisCategory: QFX platform fabric mgmt for Express ASIC chip
1734735Packet drop is observed due to SIB ASIC issue on fabric
Product-Group=junos
On all inserted FPCs of Junos based QFX10K8/QFX10K16 platforms, due to SIB (Switch Interface Board) ASIC (Application-Specific Integrated Circuit) issue on fabric, packets are getting dropped and major errors "PECHIP_CMERROR_EPW_MISC_INT_EVENTS_CRC_ERR (0x2101aa)" are reported. These errors are not auto-cleared on a couple of FPCs.
PR NumberSynopsisCategory: QFX PFE Class of Services
1641572Traffic drop would be observed along with the error message 'Buffers are stuck on queue' when performing the OIR in the 100G QSFP interface
Product-Group=junos
On QFX5110-32Q platforms, the traffic drop along with the error message "Buffers are stuck on queue" will be seen when the Online Insertion and Removal (OIR) is performed with 100G QSFPs on continuous ports 28, 29, 30, 31 at the same time.
1726124The class of service subsystem crashed after the device is restarted or the switchover is performed
Product-Group=junos
On Junos QFX5100 and QFX5110 platforms in virtual chassis, the cosd crash is observed when the GRES (Graceful Routing Engine Switchover) is performed or the device is restarted, due to which the Class of Service (CoS) functionality will not work. It is a rare issue.
PR NumberSynopsisCategory: QFX5K hostpath
1721318Error message "%PFE-3: fpc0 Failed to get ifl for ifl index = XXX" is generated when receives DHCP packet via remote vtep.
Product-Group=junos
You may see the following error message in VXLAN environment. This can happen when the device receives DHCP packet via a remote vtep and L3 interface (IRB) is not assiged on the egress interface. Even though there is no DHCP configuration, the packet injection happens and it fails to get IFL index as there is no IRB interface on the egress interface. Oct 7 16:31:51.137 2022 d16-25 : %PFE-3: fpc0 Failed to get ifl for ifl index = 640
PR NumberSynopsisCategory: QFX L2 PFE
1705853Tracking PR to add the null check for list_get_head if magic is NULL.
Product-Group=junos
On all Junos platforms, as list_get_head function is called in multiple places in pfe we needed previous 3 functions on the stack which had called list_get_head, so we could debug why 'list_get_head list has bad magic' this error has occured.
1730076Packets received on a port that is in "LACP Detached" state is getting forwarded
Product-Group=junos
On all Junos EX46xx/QFX5k (except QFX5100) platforms, child links that are in LACP (Link Aggregation Control Protocol) detached state are up and accepting incoming traffic, expecting it to drop.
1741316The traffic drop is observed due to the MAC source address being learned from the wrong direction
Product-Group=junos
On Junos EX4300/QFX5200/QFX5210 platforms with VXLAN (Virtual Extensible Local Area Network) enabled, when the ARP (Address Resolution Protocol) request is sent from the device, the MAC (Media Access Control) address is learned from the wrong direction which results in the traffic drop.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1666260Traffic is not restored when l2circuit configurations are deleted and added back on QFX5K
Product-Group=junosvae
On Junos QFX5K platforms, flapping the Layer 2 circuit ports or removing and re-adding the configuration on the l2circuit ports, the re-configuration of the access side port fails and traffic ingressing or egressing out of that port gets dropped.
1704489High CPU utilization causes a latency/slowness issue on QFX platforms
Product-Group=junos
On QFX5110 and QFX5120 platforms, latency or slowness issue is observed when the traffic is passing through a layer 3 interface configured with just family inet/family inet6 due to unwarranted MAC lookup. This could lead to traffic loss on that interface.
1724675Traffic loss will be observed with vlan tagging and/or vlan normalisation in a specific design (using a looped cable)
Product-Group=junos
Upon upgrade to Junos versions (junos:20.3R2, 20.3R3, 20.3X75-D20, 20.4R2, 21.1R1, 21.2R1), network connectivity is lost for traffic requiring vlan normalization and having DMAC one of the switch's MAC addresses. For example, incoming traffic has two vlans (S-vlan, C-vlan) ingressing on an interface and switch uses a looped link to provide routing via an IRB. --- (S-vlan|C-vlan) -- -> SW_X --- C-vlan -- -> SW_X_irb ARP and L2 learning occurs as expected but upon receiving the frame with DMAC of a local interface, switch takes a route lookup action instead of bridging and vlan normalization due to the frame having DMAC as the MAC of one of its interfaces. Hence, the traffic is not sent via looped cable to the L3 interface.
1725375DCPFE process crash can be seen on all Junos EX and QFX5K platforms with MACSEC enabled
Product-Group=junos
On all Junos platforms supporting MACSEC (Media Access Layer Security), the DCPFE (Dense Concentrator Packet Forwarding Engine) process might crash in a rare scenario when the configuration of MACSEC is deleted from the interface and the PFE is trying to access the memory location of the interface. The DCPFE process crash will lead to the FPC (Flexible PIC Concentrator) reboot but the system will self-recover.
1732708SNMP polling Timeout due to OID 1.3.6.1.2.1.31.1.1.1.10.514 ( ifInOctets.514 )
Product-Group=junos
When trying to poll information via SNMP, the device stops reponding causing a SNMP timeout, the issue is due to sxe-0/0/0 private interface that is marked as public interfaces which causes it to query kernel for statistics.
PR NumberSynopsisCategory: QFX MPLS PFE
1742364Traffic dropped is observed in the MPLS LDP scenario when the peer device MAC address is changing
Product-Group=junos
On Junos QFX5100 and EX4600 platforms when there is MAC (Media Access Control) change for the LDP (Label Distribution Protocol) neighbor and IP remains the same, the ARP (Address Resolution Protocol) update is proper but MPLS LDP may still use the stale MAC address of the neighbor. If there is any application/service such as MP-BGP using LDP as next-hop, all transit traffic pointing to the stale MAC address will be dropped.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1665306On QFX5K series platforms, duplicate packets might be seen in the multihomed scenario in an EVPN-VxLAN fabric when unicast ARP packets are received
Product-Group=junos
On QFX5K series platforms, when unicast ARP (Address Resolution Protocol) is received for a MAC address that is already learned in an EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) environment, the ARP request is flooded and duplicate packets might be seen on leaf devices. We might see some service impact where split-horizon might not work or continuous mac-move might be seen. This issue is rare and very unlikely to occur in a production environment due to presence of intermediate switches which might resolve the unicast ARP query.
1686539The dcpfe process crashes on QFX5k and EX4k platforms
Product-Group=junos
On QFX5k, EX4100, EX4300, EX4400, and EX4650 platforms, the dcpfe process crash will be seen when EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) is configured.
1730771Traffic is impacted due to high CPU and dcpfe/fxpc crash (in some cases) in EVPN-VXLAN scenario
Product-Group=junos
On Junos QFX5k and EX platforms, a high CPU and dcpfe/fxpc crash (in some cases) is seen in the EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) scenario.
1731583Traffic drops when any of the VXLAN VLAN is deleted
Product-Group=junos
On Junos QFX5100, EX4600, QFX5200 and QFX5210 platforms whenever any of the EVPN (Ethernet Virtual Private network) - VXLAN (Virtual Extensible LAN) VLAN (Virtual Local Area Network) is removed from the interface having multiple VXLAN VLANs configured, then the VXLAN traffic for all the other VLANs within that interface is seen to get dropped.
1738276High convergence time in the EVPN-VxLAN uplink failover scenario
Product-Group=junos
On Junos QFX5K platforms in the EVPN-VxLAN scenario, due to high convergence time, traffic loss is more than expected when the uplink to the spine disabled (CLI initiated uplink failover).
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1734734Online SIBs will go down due to a faulty SIB that triggers spmbpfe crash
Product-Group=junos
On all the QFX10000 line of switches and PTX Series routers running Junos OS, due to initialization failure of a faulty Switch Interface Board (SIB) in the device, the Switch Processor Mezzanine Board (SPMB) status process, also known as the spmbpfe process, crashes and online SIBs go down.
1742186SPMB process will crash and PICs will not come online
Product-Group=junos
On the QFX10000 line of switches running Junos OS, due to initialization failure of a faulty Switch Interface Board (SIB) in the device, the Switch Processor Mezzanine Board (SPMB) status process, also known as the spmbpfe process, crashes and online SIBs go down. Traffic cannot flow through the line card when this happens.
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1718062VCP ports on 10G not coming up after reboot
Product-Group=junos
In a VC of QFX5100-24Q with an expansion module EX4600-EM-8F, if VC is formed on 10G ports then after the reboot of VC, the 10G connections will be lost and the line card will show as not present. This will impact traffic on the 10G ports after connection is lost.
1746788[QFX5K]When RSI(request support information) is executed in the VC configuration, some errors output.
Product-Group=junos
On QFX5K platform, "request pfe execute ... target fpc" in RSI is always executed on mater role in the VC configuration and you can see some errors
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1710952No alarm is raised when PSU is inserted with different airflow directions
Product-Group=junosvae
On QFX5100/QFX5110/QFX5120/QFX5200 platforms, no alarm would be raised even though inserted PSU module which has a different airflow.
1720884Interface with QSFP+-40G-CU50CM will be down
Product-Group=junosvae
The interface will be down on EX and QFX platforms with QSFP+-40G-CU50CM (740-044512) resulting in traffic loss. In the VCP (Virtual Chassis port) scenario if connected with QSFP+-40G-CU50CM it does not come up and break the VC (Virtual Chassis) environment when upgrading or rebooting the device.
1725116The 100G interface will remain down post rebooting the device
Product-Group=junosvae
On the Junos QFX5200 platform, sometimes upon restarting the device the 100G link will not come up and will remain down, impacting the traffic flowing through it.
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover, 
1701146The rpd crash will be observed when any commit is performed
Product-Group=junos
On all Junos and Evolved platforms with RSVP auto-mesh dynamic tunnel configuration, whenever a commit is done the rpd (Routing Process Daemon) crash will be seen. This happens due to null pointer access in the memory.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1721032Local route is not added in the secondary FIB on all Junos SRX platforms and routes will be permanently stuck in KRT queue
Product-Group=junos
On all Junos SRX platforms when ST (Secure-Tunnel) interface with P2MP (Point-to-Multipoint) is configured and interface routes are leaked via RIB-group (Routing Information Base), local route of the ST interface will not be leaked into forwarding-table of the secondary-RIB and it will be stuck in the KRT (Kernel Routing Table) queue.
PR NumberSynopsisCategory: RPD policy options
1706143Issue in committing more than 23, 4-byte AS on Junos and Junos Evolved platforms
Product-Group=junos
On all Junos and Junos Evolved platforms, when a 4 byte autonomous system (AS) number is committed with more than 23 as-path in as-path-prepend policy it gives "rpd string" error and the configuration commit fails.
1744449Policy change to a rib-group import-policy configured with global routing-options interface-routes causes the rpd issue on all platforms with EVPN-VXLAN configuration
Product-Group=junos
When a user configures "set routing-options interface-routes rib-group " along with an import policy for that particular rib-group, it will result in an unexpected behavior. It could disrupt the rpd or result in the rpd running at 100%. This issue is only related the "interface-routes" being configured in the global routing-options hierarchy with EVPN-VXLAN configuration. This issue won't be seen when routing-options configurations can have "interface-routes" enabled under specific routing instance.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1716153Multipath route is not getting compute and skip the multipath eligibility check
Product-Group=junos
On all Junos platforms, multipath route will not be formed correctly when a BGP route is received from RR (Route Reflector) and preference decided based on cluster list length.
1742147Memory leak observed when reconfiguring the flow routes
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if the nexthop of a flow route is the same as it was before when reconfiguring flow routes, memory leak occurs. High memory use of routing process daemon(rpd) is seen as a result of this leak. A kernel out of memory message is observed which results BGP flap.
PR NumberSynopsisCategory: Secure Web Proxy functionality on Junos
1623738Secure Web Proxy with Custom App required HTTP_PROXY
Product-Group=junos
Secure Web Proxy with Custom Application won't function after upgrading into Junos 20.1.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1691986Consistent high CPU usage is seen on the device post reboot
Product-Group=junos
On all Junos and Junos Evolved platforms consistent high CPU usage in snmpd immediately after reboot.
PR NumberSynopsisCategory: SRX Argon module
1737442Intermittent core-dumps is received when SMB protocol is enabled on AAMW policy and PFE memory is exhausted
Product-Group=junos
On SRX platforms, When Server Message Block(SMB) protocol is enabled on advanced anti-malware(AAMW) policy and PFE memory is exhausted in that condition, SMB and SMTP is calling the same fallback API results high memory utilization. There are two types of cores is generated one is from AAMW plugin and the other is from DNS plugin. Both of them are because memory is exhausted and these high memory utilization can cause PFE process crash which results network outage for a while.
PR NumberSynopsisCategory: SRX branch platforms
1713759Continuous vmcores observed on the secondary node when committing the "set system management-instance" command
Product-Group=junos
On Junos SRX3xx series platforms, when the "set system management-instance" command is committed on the secondary node, continuous vmcores are observed on primary and secondary nodes. No recovery action is needed for the primary node and the secondary node of the cluster reboots automatically to recover from the error. The cluster redundancy is not restored until the management-instance knob is removed using the "delete system management-instance".
1715247Interface speed stays 100Mbps when removing speed and duplex command separately
Product-Group=junos
On SRX branch series, when the interface speed is set to 100Mbps and the link-mode is set to full-duplex, the interface speed remains at 100Mbps even the speed and duplex commands are removed separately.
1719108OAM not working with flexible-vlan-tagging
Product-Group=junos
OAM is not working when flexible-vlan-tagging is enabled
PR NumberSynopsisCategory: Stout cards (MPC7, MPC8, MPC9) microkernel issues
1727427FPC crash observed when the ASIC usage is high
Product-Group=junos
On platforms with MS-MPC/MPC1/2/3/4/5/6/7/8/9/JNP10K-LC2101/JNP10003-LC2103/JNP10K-LC480 line cards and EX9200/EX9204/EX9208/EX9214/EX9251/EX9253 series devices, route churn (add or deletes) when the ASIC usage crosses a threshold (ASIC usage is high) which leads to a FPC crash.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1729284L2 channel error counter increases when unknown family packets received by interfaces
Product-Group=junos
On SRX4600 and SRX5K platforms, the L2 channel error counter will increase when some unknown family packets received by interfaces.
1737721Junos OS installation using USB can fail on SRX4600
Product-Group=junos
On SRX4600 platforms, Junos OS installation using USB can fail due to slow USB detection.
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1715149DSCP field in IPv4 header is incorrectly re-written
Product-Group=junos
On Junos platforms that support MPC10/MPC11/LC9600 line cards, whenever there is a rewrite rule configured to rewrite the DSCP bits on transit router in core network, packet loss are observed in the destination due to incorrectly re-written DSCP field in IPv4 header.
1729747Egress CoS rewrites won't work and that may lead to QoS specific issues downstream
Product-Group=junos
On Junos platforms, when the Preserve Next Hop routing knob is enabled, MPLS (Multiprotocol Label Switching) EXP rewrites on the transit router do not work. CoS (Class of Service) behaviour seen for the packets downstream of this node may not be on expected lines . There could be drops where it is not expected.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1692781The FPC crash is observed with out-of-bound access to the filter action table
Product-Group=junos
On all Junos platforms with MPC10 and above line cards, the FPC crashed due to out-of-bound filter access observed during back-to-back GRES operations.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1628270EVPN flood filter might not work for MPC10/MPC11 line cards
Product-Group=junos
On all MX platforms equipped with MPC10/MPC11 line cards, when the flood filter is configured in EVPN(Ethernet Virtual Private Network) family on the PFE(Packet Forwarding Engine), the line card might fail to program the filter.
1668837EVPN PE router might respond traceroute with unexpected source IP address to remote CE
Product-Group=junos
In EVPN inter-subnet forwarding(type-5 route) scenario, when user performs end-to-end traceroute across provider network, destination PE responds with lowest IP address instead of the IP address from CE-facing interface. /// Example. /// CE1 = .2 10.aa.aa.0/30 .1 = PE1 = P = PE2 = .2 10.cc.cc.0/30 .1 = CE2 * PE2 also has another interface with address 10.bb.bb.1 in the routing-instance connecting to CE2. user@CE1> traceroute 10.cc.cc.2 no-resolve traceroute to 10.cc.cc.2 (10.cc.cc.2), 30 hops max, 52 byte packets 1 10.aa.aa.1 37.732 ms 17.871 ms 22.005 ms 2 10.bb.bb.1 66.004 ms 55.093 ms 66.200 ms <<<===== Should be 10.cc.cc.1 3 10.cc.cc.2 54.561 ms 55.107 ms 55.191 ms.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1719763L2 circuit connection not working with flow-label knob
Product-Group=junos
On Junos MX platforms, packet drop is seen in Layer 2 circuit when flow-label is enabled along with control-word and the egress Provider Edge (PE) core facing interface is on MPC10E/11E/LC9600/MX304-LMIC16. Certain flows will get punted to RE (Routing Engine) instead of getting forwarded.
PR NumberSynopsisCategory: ZT/YT pfe mpls- lsps, rsvp, vpns- ccc, tcc software
1653562BGP PIC Edge might cause traffic Black-holing after selector corruption
Product-Group=junos
On MX series platform when chained-composite-next-hop ingress L3VPN knob is used along with internal and external BGP paths used and if IGP or BGP sessions flap BGP multi-path may not select appropriate next-hop (BGP multipath may select old stale session-id) that result into traffic drop.
PR NumberSynopsisCategory: ZT/YT pfe, vpls, mesh group software
1695438The BUM packets are getting dropped on MX platforms during egress processing due to PFE mismatch
Product-Group=junos
The BUM (Broadcast, Unknown Unicast, and Multicast) packets are getting dropped at egress processing on all MX platforms due to an interoperability issue of MPC1/MPC2/MPC3/MPC4/MPC5/MPC6/MPC7/MPC8/MPC9 with MPC10/MPC11/LC9600 line card. It is observed when equal-cost multipath (ECMP) is enabled for the load-sharing data for an incoming traffic destined to the neighbours. It can be seen with any ECMP traffic distribution configuration.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1718595Subscribers disruption is seen on the AE interface after the "disable-pfe" action
Product-Group=junos
On all MX platforms with MPC7/8/9/LC2101/LC2103 line cards, when a "disable-pfe" action is executed for major cmerrors, there will be improper flagging of timeouts and incorrect logging out for all subscribers in scenarios where an AE(Aggregated Ethernet) interface is present on the disabled PFE(Packet Forwarding Engine).
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1742123Inline-monitoring will not work as expected when more than one instances are configured
Product-Group=junos
On all Junos MX and EX9200 platforms, when more than one instances of the "inline-monitoring" service are placed under firewall filter, all prefixes point to the firewall filter first term regardless of the match condition which results in inline-monitoring not working as expected.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1643416RE switchover may result in traffic loss in a certain scenario
Product-Group=junos
On all Junos platforms that support MPLS with GRES and NSR enabled, on RE switchover through CLI or system reboot, traffic loss may happen.
1720772VLAN rewrite will not work for traffic egressing on IRB over L2 AE IFL
Product-Group=junos
On Junos MX and EX92XX with specific line cards, VLAN rewrites will not happen for traffic egressing from IRB(Integrated Routing and Bridging) interface over an L2 AE (Aggregated Ethernet) IFL (Interface Logical), if the L2 AE IFL is configured to perform VLAN rewrites on the frames. This happens when the IRB is configured as a routing-interface on EVPN (Ethernet Virtual Private LAN) or VXLAN (Virtual Extensible LAN) routing instances and the traffic has to egress on IRB over an L2 AE IFL. As a result, the frames are forwarded with incorrect VLAN tag information.
1727049Multiple CFM sessions are down when vlan rewrite feature is configured on AE interfaces
Product-Group=junos
On MX platforms, in Aggregate Ethernet (AE) interfaces having the member links in MPC1 to MPC9 line cards with Circuit Cross-Connect (CCC) when Maintenance Association End Point(MEP) is configured a new Virtual Local Area Network (VLAN) rewrite feature has been added before punting the Cross-connect Continuity Check Message (CCM) packets. This feature is derived from the AE member interfaces where the Packet Forwarding Engine (PFE) instance of the member is wrongly updated causing the Connectivity Fault Management (CFM) sessions down.
1731564VPLS traffic gets blackholed by qualified-bum-pruning mode
Product-Group=junos
On all MX and EX9K platforms, qualified-bum-pruning-mode completely blackholes VPLS (Virtual Private LAN Service) traffic with network-services configured in enhanced-ip mode.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1714656Incorrect Destination MAC and Source MAC addresses while processing transit packets over LT IFL
Product-Group=junos
On MX platforms with MPC10, MPC11, LC9600, and MX304-LMIC16, while processing transit packets over LT IFL (logical interface) incorrect Destination MAC and Source MAC addresses are observed when the Ethernet encapsulation type is configured on the LT interface.
1739854Major alarms will be observed on the FPC when ALB is enabled under AE interface
Product-Group=junos
On Junos MX platforms with MPC2-MPC9 line cards configured with ALB (Adaptive Load Balancing) under AE (Aggregate Ethernet) interface and Network-Services IP mode, when the AE interface comes up initially or activating AE after deactivating, the error logs of "Bad JNH Write to unilist-selector" and "LUCHIP Uncorrectable ECC" would be observed. These errors will lead to major alarms on the FPC (Flexible PIC Concentrators) causing traffic impact.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1638847The mustd process crash might be observed with persist-group-inheritance
Product-Group=junos
On all Junos and Junos Evolved platforms configured with persist-group-inheritance, which is enabled by default from 19.4R3 onwards, might lead to mustd process crash in highly scaled configuration.
1648744JDI-RCT:M/Mx: While removing VRRP configs and adding them back, mgd process stuck at 100% and router hangs forever.
Product-Group=junos
While removing VRRP configs and adding them back, the mgd process stuck at 100% and the router hangs forever.
1693630In JUNOS EVO "show | display inheritance" does not work correctly for LSPs with whitespace in the name
Product-Group=junos
An LSP with whitespace in the name does not display correctly when viewing the configuration using 'show | display inheritance'
1730336The rpd crashes and the commit operation fails while pushing a large configuration with the "extend-size" knob enabled
Product-Group=junos
On all Junos platforms, when the 'extend-size' knob is configured and a scaled configuration is committed, the rpd daemon crash is seen and the commit operation fails.
1745565The mgd process crash is observed when 'show' is executed from the configuration mode
Product-Group=junos
On all Junos platforms, when 'show' is executed from the configuration mode, a mgd process crash is observed which has no functionality impact.
PR NumberSynopsisCategory: web filterig issues
1715260utmd core has seen at commit when *.* or *.*.* is configured at url-pattern
Product-Group=junos
When url-pattern contains '*.*' or '*.*.*', utmd core is generated and commit fails .
PR NumberSynopsisCategory: Virtual Private LAN Services
1680687The rpd crash is seen due to the creation of a new logical interface
Product-Group=junos
On all Junos Evolved and Junos MX platforms, when a new logical interface(LSI) is created, but the configuration was deleted as the kernel failed to add the interface will lead to rpd crash.
PR NumberSynopsisCategory: usf url filtering related issue
1737670URL-Filtering few HTTP sites are getting bypassed and redirect is not happening
Product-Group=junos
On Junos MX series platforms with service card (SPC3, MS-MPC and MS-MIC), when the contents in the url-filter-database file are in upper case, the URL (Uniform Resource Locator) filtering fails to filter those HTTP (Hypertext Transfer Protocol) URIs (Uniform Resource Identifier) which are meant to be redirected.
PR NumberSynopsisCategory: usf ipsec related issues
1744601With multiple Traffic Selectors having same remote-ip, the traffic works only for first tunnel on MX platforms with SPC3 cards
Product-Group=junos
In MX-SPC3 IPSec deployments, if multiple traffic selectors are configured with same remote-ip (different local-ip), the traffic works only for one of the tunnels.
PR NumberSynopsisCategory: usf logging and reporting function related issues
1744563[USF - SPC3 - LOGGING] "log-tag" is not populated in the cgnat syslogs intermittently
Product-Group=junos
Sometimes, the log-tag within a stream is not used in syslog generation.
PR NumberSynopsisCategory: usf nat related issues
1598382The TCP keepalive does not reach host on the private Network
Product-Group=junos
On all MX platforms with SPC3 cards where tcp-tickle knob is enabled under services-options in DS-lite (Dual-Stack lite) with NAT scenario , TCP keepalive sent by AFTR (Address Family Transition Router) will not be properly encapsulated by IPv6 addresses.
1729801Traffic drops are observed on MX Platform configured with PCP mapping along with NAT
Product-Group=junos
On all MX platforms with SPC3 cards and PCP (Port Control Protocol) with NAT (Network Address Translation) configured, the PCP client should renew the mapping before its expiry time to keep the PCP mapping always active. The sessions are not refreshed with the received PCP mapping refresh. The issue is seen if the traffic from outside the network (public network) toward B4 (softwire initiator) was suspended for sometime. When traffic started again toward B4 from outside the network, it will be dropped and service will be impacted.

List of Known Issues is attached to this SRN.


Modification History

First Publication 2023-08-24