Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 22.3R2-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 22.3R2-S2 is now available.

22.3R2-S2 - List of Fixed issues 

PR NumberSynopsisCategory: JUNOS bugs found in UAC integration
1692398Connection fails are observed on Junos despite a valid auth entry
Product-Group=junos
On Junos platforms, authentication failures and connection drops are observed for a few users when UAC (Unified Access Control) modules fail to look up the roles.
PR NumberSynopsisCategory: EX4300 Layer 2 implementation
1739730In EVPN-VXLAN scenario DHCP does not work for clients connected on the dot1x port
Product-Group=junos
On EX4300-48MP, in case of dot1x EVPN-VXLAN dynamic VLAN due to a HW setting which is used to assign VLAN to the authenticated dynamic VLAN, causes the DHCP offer to get tagged.
PR NumberSynopsisCategory: MX YT-ZF Linecards Interface Software Category
1706517Delay in an interface on LC9600 to come up due to repeated flaps
Product-Group=junos
There is a delay in an interface on LC9600 to come up sometimes due to SerDes re-initing triggered by repeating flaps. Each plane is made of one or several Fabric ASICs (Application-Specific Integrated Circuits). The Fabric ASIC is connected to all the PFE (Packet Forwarding Engine) with dedicated links called SerDes. The issue caused a delay in turning up the link from 30 seconds to 80 seconds depending on if the link partner undergoes the same delay. Traffic will not pass on the port until the link is up again.
PR NumberSynopsisCategory: MX YT-ZF Linecards Timing software
1697167Time error observed on JNP10K-LC2101
Product-Group=junos
Spikes seen in 2way time error with JNP10K-LC2101 is either PTP slave or master and any switchover is done
PR NumberSynopsisCategory: Border Gateway Protocol
1696870BGP scheduler slips during sub-optimal prefix-walk while deleting selected prefixes from a large set.
Product-Group=junos
On all Junos and Junos Evolved platforms, you might see the BGP scheduler slip while deleting a large set of prefixes.
1739919Junos OS and Junos OS Evolved: A BGP session will flap upon receipt of a specific, optional transitive attribute (CVE-2023-0026)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA71542 [juniper.net] for more details.
PR NumberSynopsisCategory: BGP Openconfig and Sensor
1714087Traffic loss is seen on telemetry streaming in BGP sharding environment
Product-Group=junos
On all Junos and Junos Evolved platforms RPD core is seen on telemetry streaming with BGP sharding enabled.
PR NumberSynopsisCategory: MX304 Chassis specific platform 
1696816After a chassis power cycle the backup RE is in Present state and the "Loss of communication with Backup RE (Routing Engine)" alarm is seen
Product-Group=junosvae
Occassionally on some reboots the communication link to the backup RE does not come up. In such an instance the backup RE remains in Present state (as seen in show chassis routing-engine) and the "Loss of communication with Backup RE" alarm is raised. The Re exhibiting the issue can be rebooted to clear the fault condition (request vmhost reboot)
1719767Major Host 1 Chassis Manager connection down Alarm on MX304
Product-Group=junos
On rare bootups the RE-RE (RE - Routing-Engine)link reaches a wedge condition where broadcast packets are received correctly, but unicast packets are not. The afflicted RE would need to be rebooted for the RE-RE link to resume functionality
PR NumberSynopsisCategory: L2NG Access Security feature
1724933On certain Junos EX and QFX platforms the static ARP entries for DHCP-security are not present
Product-Group=junos
On certain Junos EX series switches, the static MAC (Media Access Control) bindings are not present in certain conditions. This issue will be seen when the static DHCP (Dynamic Host Configuration Protocol)-security ARP(Address Resolution Protocol) bindings are moved from an interface having a higher interface number to an interface with a lower interface number. Due to the binding not happening, there will be impact on the traffic. The workaround when such a binding change is done is to restart the DHCP services after the configuration is committed.
PR NumberSynopsisCategory: ACX IFL, IFF creation
1691004The PFE process crashes on ACX5448
Product-Group=junos
On Junos ACX5448 platforms, the PFE (Packet Forwarding Engine) process will crash after continuous IFD (Interface Device) flaps. As a result, all traffic will be lost until the process recovers on its own.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1714149Junos OS: MX Series: The FPC will crash on receiving a malformed CFM packet (CVE-2023-36848)
Product-Group=junos
An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (ppmd) of Juniper Networks Junos OS on MX Series(except MPC10, MPC11, and LC9600) allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA71659 [juniper.net] for more information.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1705712Traffic loss would be seen as prefix gets stuck in Hold state
Product-Group=junos
On Junos OS Evolved platforms with EVPN-VXLAN (Ethernet VPN Virtual Extensible LANs) feature, traffic loss would be observed as host prefix gets stuck in Hold state due to any network event which causes the route to delete and add in a quick succession.
PR NumberSynopsisCategory: Configd, ffp issues
1743038Commit confirm and commit race condition crashes the firewall functionality
Product-Group=junos
On dual-RE (Routing Engine) Junos Evolved platforms, when the commit is executed during the commit confirm timeout window, it causes the firewalld to stop working.
PR NumberSynopsisCategory: EX4100 PFE
1728538EAP dot1x authentication stuck in connecting state
Product-Group=junos
EAP (Extensible Authentication Protocol) 802.1x authentication failure is observed on Junos QFX5K and EX4100/EX4300/EX4400 platforms in EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) environment. Authentication gets stuck in the "Connecting" state.
PR NumberSynopsisCategory: EX4400 PFE software
1716902IGMP/MLD queries may get dropped if received on a port on the backup VC member when IGMP/MLD snooping is enabled
Product-Group=junos
On Junos QFX and EX in the VC (Virtual Chassis) scenario, when the switch is acting as pure L2 (Layer 2), and forwarding IGMP (Internet Group Management Protocol)/MLD (Multicast Listener Discovery) query as transit traffic, if IGMP/MLD snooping is enabled then IGMP/MLD queries may get dropped if received on a port on the backup VC member resulting in IGMP/MLD groups to expire.
1731548The fxpc process crashes when the next hop information is not properly maintained in the PFE table
Product-Group=junos
On Junos EX series deployed as a virtual chassis, post switchover/GRES (Graceful Routing Engine Switchover), next hop information for Type 5 route fluctuates which leads to invalid entries in the PFE (Packet Forward Engine) table and causes the fxpc (Packet Forwarding Engine Manager) process to crash.
1732271Filter term dropping VRRP traffic when "then log" is configured
Product-Group=junos
On all Junos platforms, VRRP (Virtual Router Redundancy Protocol) packet goes to a wrong CPU queue when filter is added to match VRRP packet with "then log" action, resulting in VRRP functionality impact.
1736790EX4400 shaping rate not working as expected
Product-Group=junos
On EX platforms shaping rate on 100gig link over 70g not working as expected.
1738384The 'input-vlan-map push' operation will not work on double-tagged frames
Product-Group=junos
On EX4400 platforms, when 'input-vlan-map push' is configured to push an outer VLAN (Virtual Local Area Network) tag on to a double-tagged frame, the egressing frame will be tagged incorrectly. Instead of a push operation, the outer VLAN tag of the ingressing double-tagged frame will be swapped and sent out. This results in unexpected behaviour or traffic loss as the Ethernet frames will not have the expected VLAN tag information.
1747095LLDP will not work on HGoE VC mode with 40G VCP connections
Product-Group=junos
On EX4400/QFX5120 platforms, having High Gigabit over Ethernet (HGoE) Virtual Chassis (VC) mode in the master, when VC members are connected by 40G links, Link Layer Discovery Protocol (LLDP) Bridge Protocol Data Unit (BPDU) from VC master destined to the remote VC members (more than one-hop away) are dropped at VCP interface due to Virtual LANs (VLANs) membership check.
PR NumberSynopsisCategory: EX4400 platform
1720074Port will be down when "no-auto-negotiation" is configured on EX4400-48F platform
Product-Group=junos
On EX4400-48F platform with Small Form Factor Pluggable 100Base-FX Fast Ethernet Optics, when "no-auto-negotiation" is configured on the interface this results in the interface not coming back online even after deleting "no-auto-negotiation" in interface.
1724188EX4400: Flow control shows as disabled at pfe, even after enabling it
Product-Group=junos
Flow control state does not show updated value in pfe cli when flow-control for a port is enabled or disabled. This is a display issue with PFE level flow control status, with no functional impact. Need to hard reboot the device or the dcpfe process restart to show correctly updated value
1728725EX4400 VC: During upgrade/reboot , fxpc core may be seen in a very rare race condition
Product-Group=junos
issues aren't always seen. test cases are pre-provisioned and pfe planned restart conditions are randomly seen due to race conditions. System will auto recover after dcpfe core.
1731345EX4400: Some log messages may get flooded in heavily loaded system.
Product-Group=junos
In rare scenarios in a heavily loaded system when syslog level is set to all, following log messages may get flooded - { ifinfo[72742]: PVIDB: Attribute 'ifinfo.pad_to_minimum_frame_size' not present in Db}. Recommendation is not to set syslog level to all.
1738535On certain EX platforms when 25G DAC in 4x25G is plugged into PIC port does not come up when used as VC
Product-Group=junos
On EX4400, 25G (Gigabits) DAC (Direct Attach Copper) in 4x25G in PIC2 (Physical Interface Cards) when used as VC (Virtual Chassis) ports, link is not coming up and complete traffic block is observed. On EX4100, 25G DAC with 4x25G in PIC 1, link is coming up with 10G but only with partial traffic.
1740579On EX4400-48F, After phc commit in VC, default storm control config has extra xe port config for 0-11 ports and extra ge port config for 37-48 ports. This has no functionality impact
Product-Group=junos
On EX4400-48F, After phc commit in VC, default storm control config has extra xe port config for 0-11 ports and extra ge port config for 37-48 ports. This has no functionality impact
1753576Runt frames generate excessive traffic statistics on EX4100/EX4400 platforms
Product-Group=junos
On EX4100/EX4400 platforms with Multi-rate gigabit ethernet (MGE) ports , incorrect register is read for the runt counter and the calculation logic generates a big value. As these bytes are part of input octets, it displays incorrect value.
PR NumberSynopsisCategory: EX POE
1713545The LLDP negotiation response is not sent back to PD when perpetual Power over Ethernet (PoE) is enabled on EX4400
Product-Group=junos
On the EX4400 platform, perpetual Power over Ethernet (PoE) is enabled, and when a device is connected to more than 10 Link Layer Discovery Protocol (LLDP) Power Devices (PD) and PD restarted while perpetual PoE is enabled, the LLDP negotiation response is not sent back to PD.
1743547EX Series: Removal of notice about the availability of new POE firmware and the prompt to upgrade the same
Product-Group=junos
When there is newer POE firmware version available in the Junos Software, "show poe controller" command output displays the availability details to upgrade
1744343Enhancement of PoE Controller Firmware upgrade procedure
Product-Group=junos
PoE firmware upgrade gets stuck in an incompatible controller scenario leading to POE not working.
1745088Enhancement of PoE controller firmware files into Junos Software
Product-Group=junos
Junos Software version package does not have sufficient PoE firmware files, leading to incompatible firmware version upgrade
PR NumberSynopsisCategory: MX Inline Jflow
1716505Memory initialization of large blocks causes traffic congestion in PFE or feature configuration fails
Product-Group=junos
Memory initialization of large blocks of PFE (Packet Forwarding Engine) memory such as hash table initialization expands memory which fails due to over-utilization and causes traffic congestion or feature configuration failure.
PR NumberSynopsisCategory: ISIS routing protocol
1719033The rpd process crashes when TI-LFA is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd is seen to crash when TI-LFA (Topology-Independent Loop-Free Alternate) is enabled and there are ECMP (Equal-Cost Multipath) routes present.
PR NumberSynopsisCategory: jdhcpd daemon
1713619A jdhcpd process crash is observed on all Junos platforms
Product-Group=junos
On all Junos platforms with DHCP relay/server/client configured, the jdhcpd process crashes when the Flexible PIC Concentrator (FPC) is restarted or rebooted. The DHCP functionality could be impacted.
PR NumberSynopsisCategory: Flow Module
1692885Packet loss is observed for IPSec sessions when PMI is enabled
Product-Group=junos
On SRX4k series, and vSRX platforms with PMI (Power-mode) enabled, when using IPSec tunnels, IPSec packets sent out by SRX which contain a small IP packet (less than 64 bytes) may be dropped by a non-Juniper IPSec VPN peer. Power-mode is enabled by default in Junos 21.3R1 and higher.
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1716776Security log missing space between timestamp and hostname
Product-Group=junos
JunOS upgrade to the 22.2R3, 21.3R3-S3, 22.4R1, 21.4R3-S3, 22.3R2, 22.4R2, 21.2R3-S4 , 22.1R3 the security log space between the timestamps and site-name is removed Eg. 2023-08-14T12:04:31.273-07:00device_host-name RT_FLOW - RT_FLOW_SESSION_CREATE_LS [[email protected] logical-system-name="JTAC-LSYS" source-address="10.10.10.10" source-port="29279" destination-address="10.10.30.20" destination-port="1603" connection-tag="0" service-name="icmp" nat-source-address="10.10.10.10" nat-source-port="29279" nat-destination-address="10.10.30.20" nat-destination-port="1603" nat-connection-tag="0" src-nat-rule-type="N/A" src-nat-rule-name="N/A" dst-nat-rule-type="N/A" dst-nat-rule-name="N/A" protocol-id="1" policy-name="ONE" source-zone-name="JTAC-Trust" destination-zone-name="JTAC-dmz" session-id="3207" username="N/A" roles="N/A" packet-incoming-interface="ge-0/0/12.0" application="UNKNOWN" nested-application="UNKNOWN" encrypted="UNKNOWN" application-category="N/A" application-sub-category="N/A" application-risk="-1" application-characteristics="N/A" src-vrf-grp="N/A" dst-vrf-grp="N/A" tunnel-inspection="Off" tunnel-inspection-policy-set="root" source-tenant="N/A" destination-service="N/A"]
PR NumberSynopsisCategory: IPSEC/IKE VPN
1690921The tunnel went down because the IKE exchange failed
Product-Group=junos
On all Junos platform Sometimes after manual failover, IKE-SA rekey does not succeed.
PR NumberSynopsisCategory: Security platform jweb support
1735387Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files (CVE-2023-36847)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
1735389Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files (CVE-2023-36846)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
1736942Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
PR NumberSynopsisCategory: Platform infra to support jvision
1661423Continuous error logs and Telemetry data might not be populated
Product-Group=junos
On all Junos platforms, error logs are observed and telemetry data related to the transceiver does not get correctly populated for PICs (Physical Interface Cards). This is a non-service impacting issue.
PR NumberSynopsisCategory: lacp protocol
1706224On all Junos MX Series and PTX Series routers, multiple LACP timeouts cause traffic loss due to ppman resource starvation
Product-Group=junos
On all MX Series and PTX Series routers running Junos OS, during congestion, the periodic packet manager (ppman) runs short of resources and fails to send protocol data units (PDUs). This could cause LACP timeout and aggregated Ethernet interface flap, leading to traffic loss.
PR NumberSynopsisCategory: For multicast snooping on MX
1699784The mcscnoopd process will be stuck in resync state after snooping configuration is deleted and added again immediately
Product-Group=junos
On all Junos platforms, when the multicast snooping configuration is deleted and added again immediately, the mcscnoopd (multicast-snooping process daemon) process will be stuck in the resync state, impacting the multicast traffic.
PR NumberSynopsisCategory: OSPF routing protocol
1702456Junos prefers SRMS advertised label over IS-IS/OSPF SID label advertised via opaque-AS Extended-Prefix
Product-Group=junos
On all Junos and Junos Evolved platforms, when IPv4 prefix advertisement received by an IS-IS/OSPF router in the Extended IP reachability TLV and SR mapping server (SRMS) advertisement for the same prefix received through the segment identifier (SID) label Binding TLV, then SRMS advertised label preferred over IS-IS/OSPF SID label advertised via opaque-AS Extended-Prefix. Traffic will be sent via wrong path due to this issue.
1704521On all Junos and Junos OS Evolved platforms, the TI-LFA and Legacy LFA are mutually exclusive, and the commit check will fail and blocks LFA on one instance
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if configuring LFA (Loop-Free Alternate)/RLFA (Remote LFA)/PPLFA (Per-prefix LFA) in the routing-instance and TI-LFA (topology independent LFA) in the master instance, along with Segment Routing and node-link-protection with post-convergence, the commit check fails and blocks LFA on one instance.
1732500The adjacent PE Node SID label will drop from routing table when MicroLoop-Avoidance is enabled in OSPF-SR
Product-Group=junos
On all Junos and Junos OS Evolved platforms when OSPF MicroLoop-Avoidance(MLA) is enabled on Segment Routing(SR) speaking node connected to LDP speaking node and this same SR node has to do SR-LDP stitching, the LDP route on the LDP facing interface will be withdrawn and eventually withdraws the node SID label if there has either LDP speaking node facing link flapping or the rpd is restarted.
PR NumberSynopsisCategory: QFX PFE Class of Services
1641572Traffic drop would be observed along with the error message 'Buffers are stuck on queue' when performing the OIR in the 100G QSFP interface
Product-Group=junos
On QFX5110-32Q platforms, the traffic drop along with the error message "Buffers are stuck on queue" will be seen when the Online Insertion and Removal (OIR) is performed with 100G QSFPs on continuous ports 28, 29, 30, 31 at the same time.
PR NumberSynopsisCategory: QFX5K hostpath
1723465PFE crash is seen on Junos when file-logging is disabled
Product-Group=junos
On Junos QFX5K platforms, when file-logging is enabled for ukern_trace handle and the logs are written continuously to the corresponding buffer due to a network issue, disabling file-logging for that handle will cause a PFE crash and will lead to a complete traffic loss.
PR NumberSynopsisCategory: QFX L2 PFE
1705853Tracking PR to add the null check for list_get_head if magic is NULL.
Product-Group=junos
On all Junos platforms, as list_get_head function is called in multiple places in pfe we needed previous 3 functions on the stack which had called list_get_head, so we could debug why 'list_get_head list has bad magic' this error has occured.
1730076Packets received on a port that is in "LACP Detached" state is getting forwarded
Product-Group=junos
On all Junos EX46xx/QFX5k (except QFX5100) platforms, child links that are in LACP (Link Aggregation Control Protocol) detached state are up and accepting incoming traffic, expecting it to drop.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1704489High CPU utilization causes a latency/slowness issue on QFX platforms
Product-Group=junos
On QFX5110 and QFX5120 platforms, latency or slowness issue is observed when the traffic is passing through a layer 3 interface configured with just family inet/family inet6 due to unwarranted MAC lookup. This could lead to traffic loss on that interface.
1709664BFD sessions flap on EX and QFX platforms
Product-Group=junos
On all EX and QFX platforms, BFD(Bidirectional Forwarding Detection) sessions are flapped with VLAN configuration change on LAG interface.
1713133The dcpfe crashes after restarting l2-learning process on QFX and EX series Junos platforms
Product-Group=junos
The dcpfe process crash is observed on EX and QFX Junos platforms after restarting the l2-learning process when flex-hash is configured. It will be recovered automatically after the dcpfe restart
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1686539The dcpfe process crashes on QFX5k and EX4k platforms
Product-Group=junos
On QFX5k, EX4100, EX4300, EX4400, and EX4650 platforms, the dcpfe process crash will be seen when EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) is configured.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1738077Link down due to FEC mismatch on EX4650, EX4400 and Junos based QFX5K platforms using 25G-LR optics
Product-Group=junos
In a combination of EX4650 connected to EX4400 and Junos based QFX5K platforms connected to EX4400 using 25G-LR(Long Range) optics, FEC(Forward Error Correction) value mismatch between directly connected devices would cause the link to go down on Junos release version 20.4R3-S8 and above and leads to complete traffic loss.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1710952No alarm is raised when PSU is inserted with different airflow directions
Product-Group=junosvae
On QFX5100/QFX5110/QFX5120/QFX5200 platforms, no alarm would be raised even though inserted PSU module which has a different airflow.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1716153Multipath route is not getting compute and skip the multipath eligibility check
Product-Group=junos
On all Junos platforms, multipath route will not be formed correctly when a BGP route is received from RR (Route Reflector) and preference decided based on cluster list length.
PR NumberSynopsisCategory: SW PRs for SCBE3 fabric
1724007Complete traffic blackhole from one PFE to another on fabric links after injecting/reporting CRC errors on fabric links of MX10008
Product-Group=junos
On the MX10008 platform, the low-priority stream might be marked as a destination error and as a result, the low-priority stream is stuck and all traffic might get dropped. Complete traffic blackhole is observed from one PFE to another.
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1732746nsd crash impacting remote access vpn on SRX devices
Product-Group=junos
nsd crash can be observed on SRX platforms when the SSL certificate does not have the common name (CN), Organization Unit (OU) and Organization field, this leads to break in remote access connectivity.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1693630In JUNOS EVO "show | display inheritance" does not work correctly for LSPs with whitespace in the name
Product-Group=junos
An LSP with whitespace in the name does not display correctly when viewing the configuration using 'show | display inheritance'
1730336The rpd crashes and the commit operation fails while pushing a large configuration with the "extend-size" knob enabled
Product-Group=junos
On all Junos platforms, when the 'extend-size' knob is configured and a scaled configuration is committed, the rpd daemon crash is seen and the commit operation fails.
1745565The mgd process crash is observed when 'show' is executed from the configuration mode
Product-Group=junos
On all Junos platforms, when 'show' is executed from the configuration mode, a mgd process crash is observed which has no functionality impact.
PR NumberSynopsisCategory: Issues related to NETCONF
1585855< ok/> response is getting generated along with < rpc-error>
Product-Group=junos
When maximum-password-length is configured and the user tries to configure password whose length exceeds configured maximum-password-length, there is an error and the '' tag is emitted. (Ideally '' tag should not be emitted in an error scenario.) The configuration does not get committed.
 
 

22.3R2-S2 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 PFE
1695771Traffic loss is seen when a MAC moves from dot1x port to non-dot1x port
Product-Group=junos
On all Junos and Junos OS Evolved platforms is having dot1x enabled interface. When two or more MAC addresses are learnt on a dot1x port, and if one of them is shifted to a non-dot1x port, the MAC address that was moved is still seen as a MAC-based VLAN entry on the Layer2 Address Learning Manager (l2alm). This could lead to network traffic being lost.

Resolved In: evo:21.4R3-S4-EVO evo:22.3R2-S1-EVO junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S5 junos:21.3R3-S4 junos:21.4R3-S4 junos:22.1R3-S2 junos:22.2R3 junos:22.3R2-S1 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: HW Board, FPGA, CPLD issues
1688214Dcpfe core will be observed when we upgrade from 22.4I to 22.4R2.x
Product-Group=junos
dcpfe core will be observed when we upgrade from 22.4I to 22.4R2.x due to PCIe address corruption during bootup time. The device can be recovered by rebooting it.

Resolved In: junos:23.3R1
PR NumberSynopsisCategory: AFT l2lam
1722102QFX5130 EVO vxlan: QFX5130 always sends NS(Neighbor Solicitation) with link local address
Product-Group=junos
On QFX platform series which is working on EVO and vxlan function, it sends IPv6 NS(Neighbor Solicitation) with link local address even through target IP is global address.

Resolved In: evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:23.1R2 junos:23.2R2 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: Border Gateway Protocol
1709837Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.

Resolved In: evo:22.1R3-S4-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: Captive Portal
1736937Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables (CVE-2023-36844)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:20.4R3-S9 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Device Configuration Daemon
1758050If mixed speed members are part of a AE bundle, the AE goes down post GRES
Product-Group=junos
This scenario arises when a interface of a non-existent VC member is made part of the AE bundle during pre-configuration.

Resolved In: 
PR NumberSynopsisCategory: DNX VPLS
1722919Intermittent MAC move is observed in VPLS environment when ACX5448 or ACX710 is acting as a PE device
Product-Group=junos
On Junos ACX5448 and ACX710 platforms acting as a PE (Provider Edge) device in a VPLS (Virtual Private LAN Services) environment and multiple CE (Customer Edge) interfaces are bound to a single routing instance, intermittent MAC move is observed. This is a corner case scenario and the MAC move can be triggered due to various reasons and not limiting to mac address time out, L2 loop on the extended network or a congested backbone link connecting the PE devices. The split horizon rule in VPLS fails and the traffic received from VPLS LSI (Label-Switched Interface) is forwarded back towards the MPLS core through the LSI.

Resolved In: junos:20.4R3-S8 junos:21.3R3-S5 junos:21.4R3-S4 junos:22.1R3-S4 junos:22.2R3-S1 junos:22.3R2-S1 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1705712Traffic loss would be seen as prefix gets stuck in Hold state
Product-Group=junos
On Junos OS Evolved platforms with EVPN-VXLAN (Ethernet VPN Virtual Extensible LANs) feature, traffic loss would be observed as host prefix gets stuck in Hold state due to any network event which causes the route to delete and add in a quick succession.

Resolved In: evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: EX4400 PFE software
1731522The traffic drop will be observed after changing the VSTP VLAN configuration
Product-Group=junos
On Junos EX4400, EX4100, EX2300, EX3400, and QFX5K platforms, traffic drop would happen on RSTP (Rapid Spanning Tree Protocol) enabled port attached to a VLAN (Virtual Local Area Network) when the same VLAN has VSTP (VLAN Spanning Tree Protocol) enabled on a different port and there is a configuration change done on VSTP for that VLAN.

Resolved In: junos:20.4R3-S9 junos:21.2R3-S6 junos:21.2R3-S7 junos:21.4R3-S4 junos:21.4R3-S5 junos:22.1R3-S3 junos:22.1R3-S4 junos:22.2R3-S1 junos:22.2R3-S2 junos:22.3R3 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1
1747878Packet drop will be observed due to ARP resolution failure in EVPN-VXLAN scenario
Product-Group=junos
On Junos Evolved ACX/SRX/QFX/EX (BROADCOM based) platforms, ARP (Address Resolution Protocol) resolution is unsuccessful and packet drop will be seen, when interface mode - access is configured in EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) ERB (Edge Routed Bridging) scenario.

Resolved In: junos:21.4R3-S5 junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: EX4400 platform
1718825Alarm "PEM is not supported/powered" might be seen after removing the power cable
Product-Group=junos
On EX4400 platform, system alarm 'PEM is not supported/powered' might be seen after removing a power cable from PEM.

Resolved In: junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3 junos:22.3R3-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1
1726532FPC temperature value will be exported incorrectly in Telemetry server
Product-Group=junos
On Junos based platforms with TVP architecture, when data is streamed through telemetry the FPC temperature data is exported as 0. There is no functionality impact due to this issue.

Resolved In: junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3 junos:22.3R3-S1 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1
1733920EX4400: When SFPP-10G-T optics insterted in EX4400, IFD doesnt get created
Product-Group=junos
When SFPP-10G-T transceiver is inserted in PIC0 ports of EX4400-48F, IFD will not be created.

Resolved In: junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1
1740024EX4400 VC : Both mge and ge interfaces are getting created for all ports during master member-id and role swap with Linecard.
Product-Group=junos
In case of role swap along with fpc slot change between master and linecard, the older ifds are retained on master.

Resolved In: 
1759351EX4400:PSM is not detected in "show chassis hardware" until AC feed is connected to it
Product-Group=junos
PEM after insertion will not be detected/displayed in show chassis hardware, until the power feed is connected

Resolved In: 
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1727112Programming of native-vlan-id on the interface fails and MAC is not learned
Product-Group=junos
On all EX4400 and EX4100 devices in virtual-chassis (VC) deployed, in EVPN-VXLAN (Ethernet Virtual Private Network - Virtual Extensible LAN) scenario, with native-vlan-id configured on the interface, MAC (Media Access Control) address is not learned.

Resolved In: junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: Express PFE Services including JTI, TOE, HostPath, Jflow
1730927PDT:Google: DCPFE core found during AE flap test on PTX1k
Product-Group=junos
During heavy network churn (interface flaps, session flaps etc.) PFE crash may be seen when streaming both SR and SRTE stats on PTX JUNOS platforms. Issue is not seen when only SR stats or SRTE stats are enabled.

Resolved In: 
PR NumberSynopsisCategory: jdhcpd daemon
1731784Dhcp security bindings may not happen when DHCP security is enabled on multiple vlans along with dhcp stateless relay
Product-Group=junos
When DHCP security is enabled on multiple vlans along with dhcp stateless relay enabled at that time, dhcp security bindings may not happen.

Resolved In: junos:20.4R3-S8 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S3 junos:22.1R3-S4 junos:22.2R3-S1 junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: Security platform jweb support
1698386Junos OS: J-Web: Multiple Vulnerabilities in PHP software
Product-Group=junos
PHP software included with Junos OS J-Web has been updated from 7.4.30 to 8.2.0 to resolve multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA71653 [juniper.net] for more information.

Resolved In: evo:23.2R1-EVO evo:23.3R1-EVO junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1743282The l2ald crashes when there is recursive deletion of IFBD or when BGP neighborship is cleared in EVPN-VXLAN multi-homed configuration
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in a rare scenario, due to timing issue, the l2ald (Layer 2 Address Learning Daemon) crashes and traffic is being blackholed due to recursive deletion of IFBD (Interface Family Bridge Domain) or when BGP (Border Gateway Protocol) neighborship is cleared when EVPN (Ethernet Virtual Private Network) - VXLAN (Virtual Extensible Local Area Network) with multi-homed is configured.

Resolved In: evo:21.2R3-S6-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S2-EVO evo:22.3R3-S1-EVO evo:22.4R2-S2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:21.2R3-S6 junos:21.4R3-S4 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1691036NTP time drift
Product-Group=junos
NTP time drift on the affected Junos releases. Earlier implementation of kvmclock with vDSO (virtual Dynamic Shared Object) which helps avoid the system call overhead for user space applications had problem of time drift, the latest set of changes takes care of initializing the clock after all auxiliary processors are launched so that the clock initialization is accurate.

Resolved In: junos:23.1R2 junos:23.3R1
1742088EX4100/EX4400 device is not able to recover from OAM
Product-Group=junos
OAM snapshot recovery not working as expected, post "request system reboot oam" system should boot OAM recovery mode, but system is rebooting back with current installed image.

Resolved In: junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3
1757281EX4400 OAM snapshot recovery not working as expected
Product-Group=junos
OAM snapshot recovery not working as expected, post "request system reboot oam" system should boot OAM recovery mode, but system is rebooting back with current installed image.

Resolved In: 
PR NumberSynopsisCategory: "ifstate" infrastructure
1735685Control plane flap, data drop, unexpected behavior of PFE or device is observed when file storage is impacted in a continuous ksyncd process crash scenario
Product-Group=junos
On all Junos platforms configured with GRES (Graceful Routing Engine Switchover), file storage in the system will get affected when the ksyncd process crashes continuously and result in control plane flap, data drop or unexpected behavior of PFE (Packet Forwarding Engine) or device.

Resolved In: junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Express Chip L3 software
1710362FPCs crash after performing upgrade to 22.3R2.6 for ptx5k: nh_get_type_handle
Product-Group=junos
when the upgrade happens to new release and config is applied, RPD might create parallel MBBs due to this number of nexthops might increase and on-chip memory exhaustion might happen at FPC. This can lead to FPC crash. Issue should not be seen once system settles down.

Resolved In: 
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1721316The dcpfe process crash will be seen on the system
Product-Group=junos
On Junos specific devices QFX5110/QFX5120/EX4650/EX4400/EX4100, dcpfe crash will be seen during the creation of the network port for VPLAG (virtual port lag).

Resolved In: junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
1733022QFX5120 reboots due to deletion of EP style interface with native vlan configured
Product-Group=junos
QFX5120 will reboot without causing a dcpfe crash upon the deletion of EP style (Enterprise Style), and trunk interfaces with multiple IFLs and native VLAN configured.

Resolved In: junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1725116Sometimes 100G link will go down and will remain down
Product-Group=junosvae
On the Junos QFX5200 platform, sometimes 100G link will go down and will remain down

Resolved In: junos:20.3X75-D43 junos:20.4R3-S8 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3
PR NumberSynopsisCategory: Resource Reservation Protocol
1690110Traffic is not load-balanced when one of the next-hop LSP is down
Product-Group=junos
On all Junos and Junos Evolved platforms, in the multi-LSP next-hop load-balance scenario, in case any one of the label-switched path (LSP) is down, the traffic will not be load-balanced to the rest of the LSPs, due to the weight of LSP next hops not being set correctly.

Resolved In: evo:21.4R3-S4-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D36-EVO evo:22.3X80-D37-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:21.2R3-S5 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1726733Traffic drops with percent policer attached using list
Product-Group=junos
On Junos EX92xx, MX304 and MX series platforms with MPC10, MPC11 and LC9600, traffic drop will happen with the attachment of family filter configured with percent policer (bandwidth-percent) via input-list/output-list.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:20.3X75-D46 junos:21.2R3-S5 junos:21.3R3-S5 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1722945PADT response will not be sent for an incoming PPPoE/PPP data Packet from an unknown session ID
Product-Group=junos
On all MX platforms with line cards before MPC10, when Broadband Network Gateway (BNG) switchover occurs, the new master does not send PPPoE Active Discovery Termination (PADT) packet for an unknown session if the incoming packet is PPPoE/PPP data packet and thus the existing subscribers does not come up on this router.

Resolved In: junos:21.3R3-S5 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: web filterig issues
1725359Memory leak is observed on all Junos SRX platforms with http-persist and http-reassembly configuration
Product-Group=junos
On all Junos SRX platforms with http-persist and http-reassembly configuration when firewall policy is attached with enhanced or redirect WF (Web Filtering) policy, memory leak will be observed in PFE (Packet Forwarding Engine) which leads to traffic drop.

Resolved In: junos:22.2R3-S2 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
 

Modification History

First Publication 2023-09-06