Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX EX MX NFX PTX QFX SRX vSRX running Junos software
Alert Description
Junos Software Service Release version 22.2R3-S2 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 22.2R3-S2 is now available.
22.2R3-S2 - List of Fixed issues
PR Number
Synopsis
Category: EX4300 Layer 2 implementation
1739730
In EVPN-VXLAN scenario DHCP does not work for clients connected on the dot1x port
Product-Group=junos
On EX4300-48MP, in case of dot1x EVPN-VXLAN dynamic VLAN due to a HW setting which is used to assign VLAN to the authenticated dynamic VLAN, causes the DHCP offer to get tagged.
PR Number
Synopsis
Category: EX2300/3400 platform
1725078
The entPhysicalSoftwareRev MIB object returns Junos OS version value for components which do not run Junos OS
Product-Group=junos
The entPhysicalSoftwareRev MIB object returns Juniper OS version value for connected transceivers. This implies that the transceivers run Junos OS which is not in compliance with RFC 6933. For transceivers, entPhysicalSoftwareRev MIB object should return a zero-length string. PR1725078 introduces this fix.
PR Number
Synopsis
Category: JUNOS kernel/ukernel changes for ACX
1735843
Crash on all Junos VMhost platforms due to deadlock panic
Product-Group=junosvae
On all Junos VMhost based platforms, due to heavy disk input/output (I/O) operations, a crash was observed.
PR Number
Synopsis
Category: ACX MPLS
1726711
[ACX5048] L2circuit might drop forwarding traffic after flaps although it's in UP state; acx_rt_ccc_eth_vpws_vpn_uni_port_add:UNI VPWS port_add failed AC-IFL: <> VPN: <> (-15:Invalid configuration)
Product-Group=junos
- Upon multiple operations of deactive/active of the interface, pfe related mpls uni port stale entry might be created with invalid match vid due to which tagged traffic start dropping. - If the system is in the issued state, then the problematic l2circuit might be identified with the error logs seen below upon l2circuit flaps. fpc0 acx_bcm_mpls_uni_port_delete: VPWS port_del failed VPN: 12443 (-7:Entry not found) fpc0 acx_bcm_mpls_uni_port_add: NNI VPWS port_add failed (-15:Invalid configuration) fpc0 acx_rt_ccc_eth_vpws_vpn_uni_port_add:UNI VPWS port_add failed AC-IFL: 715 VPN: 12443 (-15:Invalid configuration) - Upon the l2circuit hits the issue, even if it's up and running after the flap, it might drop all traffic forwarded.
PR Number
Synopsis
Category: Application Quality of Experience
1743107
flowd process crash observed in Junos branch SRX platforms
Product-Group=junos
This issue is observed on Junos SRX platforms supporting SD-WAN (Software-defined Wide Area Network) like SRX300, SRX320, SRX340, SRX345, SRX380, SRX550, SRX1500, SRX4100, SRX4200, SRX4600, SRX5600, SRX5800, cSRX and vSRX in AppQoE (Application Quality of Experience) scenario where the passive probe session of SD-WAN is not closed gracefully. This results in flowd crash and impacts user traffic.
PR Number
Synopsis
Category: MX Layer 2 Forwarding Module
1743032
FPC cards restart unexpectedly
Product-Group=junos
On Junos based MX platforms with MPC7E, FPC(Flexible PIC Concentrator) crashes and core would be observed causing traffic loss. This is a rare issue.
PR Number
Synopsis
Category: A15 specific issue
1738188
Failover can be seen on SRX5K cluster with SPC2 cards while executing RSI
Product-Group=junos
On all SRX5000 series platforms with SPC2 cards configured in a chassis cluster, when RSI is being collected which has the command 'i2csc fpc' in the script, an interrupt storm generates a CB (Control Board) alarm which triggers a failover. Intermittent traffic disruption could be seen till the failover is complete.
PR Number
Synopsis
Category: australia related kernel issue
1670772
22.2R1:FIPSCC:L2HA:After RG0 failover, node priority are set to zero for node0 with Relinquish monitoring failure.
Product-Group=junos
After RG0 failover, node priorities are set to zero for both nodes with Relinquish monitoring failure. Expected behaviour is, RG0 Failover should happen gracefully without node priority being disturbed. Issue is seen after image upgrade and perform RG0 failover to node1 and/or fallback to node0. Issue is seen on latest 22.2R1.6 and 22.2R1.7 build. Issue is seen only when HA Link encryption feature is enabled to secure communication between primary and backup node Issue is not seen during fresh bringup of L2HA cluster Issue not seen in 22.3 releases L2HA device here is combination of RE3+SCB4+SPC3+IOC4.
PR Number
Synopsis
Category: dynamic vlan creation and associated processing
1743903
If more than 32 vlan ranges are configured under the dynamic-profile then login issue and traffic impact can be seen with subscribers of random VLANs
Product-Group=junos
On all Junos platforms that support subscriber services, when more than 32 VLAN ranges are configured, random VLAN (Virtual Local Area Network) traffic is impacted and subscribers are unable to login.
PR Number
Synopsis
Category: BBE network stack related issues
1729913
DHCP subscribers are stuck in DHCP-Renew state when 'overrides always-write-giaddr' is enabled
Product-Group=junos
On all Junos platforms supporting DHCP (Dynamic Host Configuration Protocol), when 'overrides always-write-giaddr' option is enabled on the DHCP relay, checksum is not computed properly causing the DHCP renew to fail and subscribers getting stuck in 'Requesting' state.
PR Number
Synopsis
Category: Border Gateway Protocol
1728604
Traffic impact is seen when there is a single peer in the proxy BGP group connected to the BGP route reflector
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if the proxy BGP (Border Gateway Protocol) route reflector is connected to the only peer present in the BGP group then it stops advertising the routes coming from the remote cluster and that leads to proxy route-target routes not getting added which causes traffic disruption.
1738074
BFD session for BGP remains down in a specific scenario
Product-Group=junos
On all Junos and Junos Evolved platforms supporting BFD (Bi-directional Forwarding and Detection) for BGP (Border Gateway Protocol) multi-hop BFD sessions can remain in a down state. This issue is seen when the multi-hop BFD session endpoints are in the same subnet but the interface addresses on which the BFD is configured are not directly connected.
1739335
The rpd process crash will be observed when the prefix-limit exceeds on the backup RE
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with BGP (Border Gateway Protocol), NSR (Nonstop Active Routing), and prefix-limit with idle-timeout, when the prefix-limit exceeds on the backup RE (Routing Engine) and switchover is performed the rpd process crash will be observed on the new backup RE.
1739919
Junos OS and Junos OS Evolved: A BGP session will flap upon receipt of a specific, optional transitive attribute (CVE-2023-0026)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA71542
[juniper.net]
for more details.
1742222
Partial application of BGP import policy with BMP configuration and after back-to-back commits changes BGP import policy
Product-Group=junos
When BMP is configured and sessions are established, if a back-to-back commit is made that alters a BGP peers import policy, then the import evaluation job is not re-run after the 2nd commit. This can lead to partial application of the desired policy, resulting in missing values that need to take effect with second policy (eg: missing communities).
1745073
CPU in rpd spikes and scheduler slips will be observed when the duplicate community is added
Product-Group=junos
On all Junos and Junos Evolved platforms, when Border Gateway Protocol (BGP) is configured with the existing community member added via another community that is called in import policy and the intermediate router does not support large/extended communities based on scale (route). Due to this, the rpd Central Processing Unit (CPU) stays high and protocols level choking will be seen in adjacent nodes. Scheduler slips are also observed due to the same.
PR Number
Synopsis
Category: Track PRs in BGP BMP area & is part of BGP inside RPD.
1713444
The rpd process will crash when BMP is configured
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd process will crash when BGP Monitoring Protocol (BMP) is configured. This will cause rpd to restart and affect routing protocols.
PR Number
Synopsis
Category: BBE Remote Access Server
1729035
Potential memory leak in authd process
Product-Group=junos
If RADIUS is enabled for subscriber authentication or accounting, the authd process may occasionally leak memory when running at a high scale.
PR Number
Synopsis
Category: Class of Service
1734013
The CoS scheduler map will not get attached to the sub-interface correctly when shaping-rate and scheduler-map are configured on it
Product-Group=junos
On all MX platforms, when shaping-rate and scheduler-map are configured on a sub-interface and a wildcard expression for sub-interfaces is used in the class-of-service interface definition, then the CoS (Class of Service) scheduler map will not get attached as per the configuration to the sub-interface and will not work correctly. Example: set class-of-service interfaces unit * classifiers.
PR Number
Synopsis
Category: Captive Portal
1736937
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables (CVE-2023-36844)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/
JSA72300
[juniper.net]
PR Number
Synopsis
Category: CFM
1682939
Maintenance-domain (MD) and Maintenance-association (MA) configuration display changed to ordered-by-system type
Product-Group=junos
With this the maintenance-domain (MD) configuration and maintenance-association (MA configuration) under the connectivity-fault-management stanza will be ordered by the system and not as per the configuration order.
PR Number
Synopsis
Category: QFX Control Plane VXLAN
1723968
Traffic loss is seen as Type 2 routes are not pushed even after withdrawing Type 5 routes
Product-Group=junos
On all Junos and Junos Evolved platforms with the EVPN (Ethernet VPN) Type 2 and Type 5 Coexistence and when the host route changes from EVPN Type 5 route to non EVPN route in the rpd, traffic loss is observed as Type 2 routes are not getting pushed even after withdrawing Type 5 routes.
PR Number
Synopsis
Category: Device Configuration Daemon
1714267
The interface speed gets set to a lower speed when the interface is disabled and enabled because renegotiation of the interfaces happens at the previously negotiated speed
Product-Group=junos
On Junos platforms with MPC line cards, negotiated interfaces will try to come up with the speed already negotiated instead of using the original interfaces speed even if re-negotiation happens like reinserting cable.
1731190
The lt/vt/ut interfaces may not recover from the disable-pfe (admin down) state if the GRES switchover is done before restarting FPC
Product-Group=junos
On all Junos Platforms when a PFE (Packet Forwarding Engine) gets disabled to a CM (Chassis Manager) error disable-pfe action or any other reason and a GRES (Graceful Routing Engine Switchover) happens, the lt/vt/ut (Logical Tunnel/Virtual Tunnel/Uplink Tunnel) interfaces will not recover after the FPC (Flexible PIC Concentrator) restart even though the error condition is recovered resulting in traffic loss.
PR Number
Synopsis
Category: VPWS, L2 CKT, EVPN-VPWS
1731081
Traffic drops on certain ACX platforms after it is upgraded
Product-Group=junos
On Junos ACX5448 and ACX710 platforms, when the router is upgraded with a new image then the RT (Routing-Table) programming fails in the PFE (Packet Forwarding Engine) with VPWS (Virtual Private Wire Service) configuration which causes traffic drop.
PR Number
Synopsis
Category: Layer 3 forwarding, both v4+v6
1695292
Traffic loss is more than expected with OSPF TI-LFA node- protection enabled and the primary path is down
Product-Group=junos
On ACX710 and ACX5448 platforms, with Open Short Path First Topology-Independent Loop-Free Alternate (OSPF TI-LFA) Node protection, Layer 3 Virtual Private Network (L3VPN) traffic loss will be more than the expected convergence time when the primary path goes down along with the 4 MultiProtocol Label Switching (MPLS) labels to be programmed in the secondary path.
PR Number
Synopsis
Category: BGP MPLS VPN specific issues
1719507
L3VPN traffic loss and PFE errors can be seen after an LSP Flap
Product-Group=junos
On all Junos ACX platforms, when L3VPN (Layer 3 Virtual Private Network) and MPLS-LSP (Multiprotocol Label Switching - Label-Switched Paths) is configured, L3VPN traffic loss and PFE (Packet Forwarding Engine) errors can be seen after an LSP flap.
PR Number
Synopsis
Category: ACX IFL, IFF creation
1691004
The PFE process crashes on ACX5448
Product-Group=junos
On Junos ACX5448 platforms, the PFE (Packet Forwarding Engine) process will crash after continuous IFD (Interface Device) flaps. As a result, all traffic will be lost until the process recovers on its own.
PR Number
Synopsis
Category: EVO L2 Control Plane PRs
1705712
Traffic loss would be seen as prefix gets stuck in Hold state
Product-Group=junos
On Junos OS Evolved platforms with EVPN-VXLAN (Ethernet VPN Virtual Extensible LANs) feature, traffic loss would be observed as host prefix gets stuck in Hold state due to any network event which causes the route to delete and add in a quick succession.
PR Number
Synopsis
Category: Configd, ffp issues
1743038
Commit confirm and commit race condition crashes the firewall functionality
Product-Group=junos
On dual-RE (Routing Engine) Junos Evolved platforms, when the commit is executed during the commit confirm timeout window, it causes the firewalld to stop working.
PR Number
Synopsis
Category: EVPN control plane issues
1746787
The user will be unable to configure the interface having stacked outer VLAN and a list of inner VLANs
Product-Group=junos
On Junos and Junos OS Evolved platforms, the configuration of stacked VLAN on an interface will not allow the user to configure the interface having stacked outer VLAN and a list of inner VLANs. A certain bridge interface configuration will not pass the commit check with JUNOS releases and throw an error message like "EVPN: Interface xe-0/1/0.0 must be added in a bridge-domain/vlan".
PR Number
Synopsis
Category: EVPN Layer-2 Forwarding
1715343
Ping overlay vxlan replies Overlay-segment present even the bridge-domain has been deactivated
Product-Group=junos
The vxlan ping overlay request is recevied for a certain VNI on MX and the bridge-domain associcated with the VNI has been deactivated. However the MX still responses with "Overlay-segment present" sub-code in the reply message.
PR Number
Synopsis
Category: EX4100 PFE
1728538
EAP dot1x authentication stuck in connecting state
Product-Group=junos
EAP (Extensible Authentication Protocol) 802.1x authentication failure is observed on Junos QFX5K and EX4100/EX4300/EX4400 platforms in EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) environment. Authentication gets stuck in the "Connecting" state.
PR Number
Synopsis
Category: EX4400 PFE software
1716902
IGMP/MLD queries may get dropped if received on a port on the backup VC member when IGMP/MLD snooping is enabled
Product-Group=junos
On Junos QFX and EX in the VC (Virtual Chassis) scenario, when the switch is acting as pure L2 (Layer 2), and forwarding IGMP (Internet Group Management Protocol)/MLD (Multicast Listener Discovery) query as transit traffic, if IGMP/MLD snooping is enabled then IGMP/MLD queries may get dropped if received on a port on the backup VC member resulting in IGMP/MLD groups to expire.
1732271
Filter term dropping VRRP traffic when "then log" is configured
Product-Group=junos
On all Junos platforms, VRRP (Virtual Router Redundancy Protocol) packet goes to a wrong CPU queue when filter is added to match VRRP packet with "then log" action, resulting in VRRP functionality impact.
1736790
EX4400 shaping rate not working as expected
Product-Group=junos
On EX platforms shaping rate on 100gig link over 70g not working as expected.
1747095
LLDP will not work on HGoE VC mode with 40G VCP connections
Product-Group=junos
On EX4400/QFX5120 platforms, having High Gigabit over Ethernet (HGoE) Virtual Chassis (VC) mode in the master, when VC members are connected by 40G links, Link Layer Discovery Protocol (LLDP) Bridge Protocol Data Unit (BPDU) from VC master destined to the remote VC members (more than one-hop away) are dropped at VCP interface due to Virtual LANs (VLANs) membership check.
1747878
Packet drop will be observed due to ARP resolution failure in EVPN-VXLAN scenario
Product-Group=junos
On Junos Evolved ACX/SRX/QFX/EX (BROADCOM based) platforms, ARP (Address Resolution Protocol) resolution is unsuccessful and packet drop will be seen, when interface mode - access is configured in EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) ERB (Edge Routed Bridging) scenario.
PR Number
Synopsis
Category: EX4400 platform
1714116
EX4400 Link/Activity LED is not lit when it transits to the factory default configuration by pressing the Factory Reset/Mode button
Product-Group=junos
Press the Factory Reset/Mode button on the far right side of the front panel for 10 seconds. EX4400 transitions into factory-default configuration and the Link/Activity LEDs on the network ports and the QSFP28 ports should be lit steadily in green color but were off.
1720074
Port will be down when "no-auto-negotiation" is configured on EX4400-48F platform
Product-Group=junos
On EX4400-48F platform with Small Form Factor Pluggable 100Base-FX Fast Ethernet Optics, when "no-auto-negotiation" is configured on the interface this results in the interface not coming back online even after deleting "no-auto-negotiation" in interface.
1740579
On EX4400-48F, After phc commit in VC, default storm control config has extra xe port config for 0-11 ports and extra ge port config for 37-48 ports. This has no functionality impact
Product-Group=junos
On EX4400-48F, After phc commit in VC, default storm control config has extra xe port config for 0-11 ports and extra ge port config for 37-48 ports. This has no functionality impact
1753576
Runt frames generate excessive traffic statistics on EX4100/EX4400 platforms
Product-Group=junos
On EX4100/EX4400 platforms with Multi-rate gigabit ethernet (MGE) ports , incorrect register is read for the runt counter and the calculation logic generates a big value. As these bytes are part of input octets, it displays incorrect value.
PR Number
Synopsis
Category: EX POE
1743547
EX Series: Removal of notice about the availability of new POE firmware and the prompt to upgrade the same
Product-Group=junos
When there is newer POE firmware version available in the Junos Software, "show poe controller" command output displays the availability details to upgrade
1744343
Enhancement of PoE Controller Firmware upgrade procedure
Product-Group=junos
PoE firmware upgrade gets stuck in an incompatible controller scenario leading to POE not working.
1745088
Enhancement of PoE controller firmware files into Junos Software
Product-Group=junos
Junos Software version package does not have sufficient PoE firmware files, leading to incompatible firmware version upgrade
PR Number
Synopsis
Category: Express PFE CoS Features
1738981
DSCP classifier is not created on IP interfaces
Product-Group=junos
On Junos QFX10k platforms, on configuring diffServ code point (DSCP) classifier and when inet or inet6 is configured with custom dot1p on interface, default dscp classifiers are not getting removed properly.
PR Number
Synopsis
Category: Express PFE including evpn, vxlan
1720527
L2 Multicast traffic drops when PIM is configured without IGMP Snooping enabled
Product-Group=junos
On Junos QFX10002 and QFX10008 platforms, L2 (Layer 2) Multicast traffic drop is observed when PIM (Protocol Independent Multicast) is configured without IGMP (Internet Group Management Protocol) Snooping enabled in the EVPN-VXLAN scenario.
PR Number
Synopsis
Category: SRX4100/SRX4200 platform software
1739559
SRX4100/4200 accepts the datapath-debug configuration although it does not support it
Product-Group=junos
It is possible to set and commit the datapath-debug configuration on platforms SRX4100/SRX4200 although datapath debugging is not supported on those platforms. because of this unsupported configuration being accepted the RE (Routing Engine) load can go high and cause traffic outage. The workaround is to remove the datapath-debug configuration and perform a commit.
PR Number
Synopsis
Category: Signature Database
1741887
Multiple network issues are seen after the upgrade with lower IDP packet-log total-memory percentage
Product-Group=junos
On Junos SRX platforms, before the upgrade, if the IDP 'packet-log total-memory percentage/packet-log max-sessions' is configured lower than the default value of 10% then while upgrading, the boot time commit will fail and the device will go to an amnesiac state causing multiple issues.
PR Number
Synopsis
Category: ISIS routing protocol
1699076
The rpd process might crash when SPF is recalculated
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) process can crash due to periodic SPF (Shortest Path first) recalculation when ISIS (Intermediate System to Intermediate System) connected or direct routes get deleted.
1719033
The rpd process crashes when TI-LFA is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd is seen to crash when TI-LFA (Topology-Independent Loop-Free Alternate) is enabled and there are ECMP (Equal-Cost Multipath) routes present.
1725686
Unnecessary SPF calculation is causing high CPU utilization
Product-Group=junos
On all Junos and Junos Evolved platforms, very frequent SPF (Shortest Path First) calculation, being caused by leaking multiple prefixes across the IS-IS areas, is causing high CPU utilization.
PR Number
Synopsis
Category: jdhcpd daemon
1713619
A jdhcpd process crash is observed on all Junos platforms
Product-Group=junos
On all Junos platforms with DHCP relay/server/client configured, the jdhcpd process crashes when the Flexible PIC Concentrator (FPC) is restarted or rebooted. The DHCP functionality could be impacted.
1722082
DHCP binding is not happening in EVPN VXLAN topology with DHCP stateless relay (forward-only)
Product-Group=junos
In EVPN VXLAN topology with DHCP stateless relay (forward-only) configured at layer 3 gateways, Jdhcpd broadcasts snooped unicast offer packets. That leads to the offer getting dropped on its way to the client and then the IP negotiation fails.
1742696
Address allocation for DHCP client will fail if 'force-discover' configuration is enabled on client
Product-Group=junos
Junos based platforms operating as DHCP-client with 'force-discover' knob enabled, will get stuck in requesting state when DHCP-Server is not responding. Client will face login failure and thus traffic would be impacted.
1744162
ALQ bulklease not working for ipv6 DHCP local server
Product-Group=junos
ALQ bulklease not working for ipv6 DHCP local server
PR Number
Synopsis
Category: JFlow bug tracker for SRX platforms
1716707
J-flow sends wrong IP in sampling records when NAT is configured for traffic along with input sampling
Product-Group=junos
When NAT (Network Address Translation) is configured on interfaces along with sampling, the J-flow record will contain NAT'ed IP as opposed to the original IP.
PR Number
Synopsis
Category: jpppd daemon
1686940
Subscribers will fail to negotiate the PPP session and be unable to login post-software upgrade
Product-Group=junos
On MX platforms with Subscriber Management configured, the subscribers will fail to negotiate the PPP (Point-to-Point Protocol) session and be unable to login when jpppd transitions from Backup to Master and does not receive all the Routing Table events from Kernel post upgrade.
PR Number
Synopsis
Category: Flow Module
1693767
On SRX platforms, tunnel fails to come up when tunnel destination routing instance is configured
Product-Group=junos
On all Junos SRX platforms, when tunnel destination routing instance is configured, the tunnel fails to come up since route lookup for the tunnel destination is performed in the ifp routing instance instead of the tunnel destination routing instance. This results in tunnel not coming up.
1742739
Virtual Routing Instance configured on ingress interface will drop the icmp traffic
Product-Group=junos
On all Junos platforms, If the Virtual Routing Instance is set on the ingress interface, the incoming packet will not be forwarded correctly.
PR Number
Synopsis
Category: Firewall Policy
1724777
The nsd process crash is seen when ISSU is performed on the cluster
Product-Group=junos
The nsd (Network Security Daemon) process crash is observed when ISSU (In Service Software Upgrade) is performed on HA (High Availability) clusters using Destination NAT (Network Address Translator).
PR Number
Synopsis
Category: User Firewall related issues
1683420
SRX Branch models are unable to connect to domain controller on installing Microsoft KB update
Product-Group=junos
On SRX300 series and SRX550M, when the User Identification feature is used with Active Directory, after the Domain Controller server installs updates related to Microsoft's KB article
KB5004442
[juniper.net]
, SRX is no longer able to connect to it. The PR1637548 did not fix this issue for these specific SRX platforms.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1745174
IPSEC VPN does not come up in NAT-T scenario
Product-Group=junos
On all SRX platforms with IPSEC (Internet Protocol Security) VPN (Virtual Private Network) configured with main mode, if SRX is the VPN initiator and NAT-T (Network Address Translation-Traversal) is configured (which is by default), the IPsec VPN tunnel does not come up. This is a timing issue and occurs when a tunnel delete or rekey occurs.
PR Number
Synopsis
Category: Security platform jweb support
1735389
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files (CVE-2023-36846)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/
JSA72300
[juniper.net]
1736942
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/
JSA72300
[juniper.net]
1748078
Cannot add custom defined security address-book under Security Policies & Objects > Security Policies > Create > Source Zone > Select Sources.
Product-Group=junos
In the J-Web UI for SRX Series Firewall, when you configure the source zone for addresses in the security policy rule, the customized address-book entries are not displayed. J-Web displays only any-ipv4 and any-ipv6.
PR Number
Synopsis
Category: Layer 2 Control Module
1739975
Layer 2 traffic will be dropped on VSTP disabled interface
Product-Group=junos
On Junos platforms, Whenever an interface is disabled under VSTP (VLAN Spanning Tre Protocol) configuration, the issue will be seen in the following cases. 1. When interface, IFBD (Interface Family Bridge Domain) and VSTP, configured via single commit. (In case of new configuration) 2. When VSTP configurations are present and chassisd restarts/device reboots, then issue will be seen. (During ifd delete and add, issue will be seen)
1745102
BPDU Protection with packet-action drop support on QFX10002-60C
Product-Group=junos
BPDU Protection with packet-action drop support on QFX10002-60C
1746244
clear error command support for qfx10002-60c
Product-Group=junos
"clear error bpdu interface" command support for qfx10002-60c.
PR Number
Synopsis
Category: Layer2 forwarding on EX/NTF/PTX/QFX
1727954
On all Junos and Junos Evolved platforms the l2ald process memory usage is seen to increase over time
Product-Group=junos
On all Junos and Junos Evolved platforms service impact is seen due to a consistent increase in l2ald (Layer 2 Address Learning Daemon) memory usage.
1733543
Traffic loss is seen when "lacp force-up" knob is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic destined to the core is getting dropped when "lacp force-up" knob is configured on ae interface under EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) scenario.
1743282
The l2ald crashes when there is recursive deletion of IFBD or when BGP neighborship is cleared in EVPN-VXLAN multi-homed configuration
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in a rare scenario, due to timing issue, the l2ald (Layer 2 Address Learning Daemon) crashes and traffic is being blackholed due to recursive deletion of IFBD (Interface Family Bridge Domain) or when BGP (Border Gateway Protocol) neighborship is cleared when EVPN (Ethernet Virtual Private Network) - VXLAN (Virtual Extensible Local Area Network) with multi-homed is configured.
PR Number
Synopsis
Category: Issues related to Junos licensing infrastructure
1686654
Subscribers are not able to connect to the device after the device reboot
Product-Group=junos
Due to a rare timing issue all subscribers may fail to connect and get suck in init state after reboot of MX broadband network gateway (BNG).
PR Number
Synopsis
Category: Multiprotocol Label Switching
1740226
LSP with auto bandwidth enabled is not updating its Max AvgBW value, preventing the LSP from being resized
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when there is no underflow limit configured under auto-bandwidth for an RSVP (Resource Reservation Protocol) LSP (Label Switched Paths), and if the traffic across the LSP is reduced and there is an underflow, the LSPs continue to be signaled with a higher bandwidth without being adjusted even after multiple adjustment intervals. The issue is observed only when there is a secondary standby path present. The MaxAvgBw (Maximum Average Bandwidth) value continues to stay at a higher value and is not being set based on the underflow Max Avg. This will eventually lead to bandwidth starvation for other LSPs.
PR Number
Synopsis
Category: For multicast snooping on MX
1699784
The mcscnoopd process will be stuck in resync state after snooping configuration is deleted and added again immediately
Product-Group=junos
On all Junos platforms, when the multicast snooping configuration is deleted and added again immediately, the mcscnoopd (multicast-snooping process daemon) process will be stuck in the resync state, impacting the multicast traffic.
PR Number
Synopsis
Category: MX Timing software
1652275
PTP Playback Engine reset error is reported sporadically with PTP FPGA Firmware version A4 7
Product-Group=junos
On Junos MX platforms, the PTP Playback Engine reset error is reported sporadically with PTP FPGA Firmware version A4 7. It has No functionality impact.
1704633
Interface flaps are seen after PTP GM changes to a different FPC slot
Product-Group=junos
On MX platforms, when PTP (Precision Time Protocol) is configured, the interfaces will flap after the PTP GM (Grand Master) is changed to a different FPC (Flexible PIC Concentrators) slot. The flaps can last for several seconds. Chassis-SyncE clock is also influenced by PTP phase change.
1738458
PTP time sync issues after release upgrade or rebooting the device
Product-Group=junos
On all MX platforms with 20x1GE MICs (Modular Interface Card), PTP (Precision Time Protocol) downstream client cannot receive an accurate clock from the router after an upgrade or FPC restart which impacts the PTP functionality.
PR Number
Synopsis
Category: MX10K platform
1719915
Removing a PEM that doesn't have power feed does not generate the SNMP TRAP for "Power Supply Removed"
Product-Group=junos
If a display power entry module (PEM) doesn't have power feed by turning the power switch OFF, removing the PEM physically will not generate the SNMP TRAP "Power Supply Removed."
PR Number
Synopsis
Category: Track Mt Rainier RE platform software issues
1655935
Images older than 22.2R1S2 can be installed on RE-S-X6-128G-K. This will result in system booting to Linux prompt
Product-Group=junos
Currently User can install images older that the minimum supported image on RE-S-X6-128G-K. System comes up in Linux prompt in such cases.
PR Number
Synopsis
Category: OS IPv4/ARP/ICMPv4
1735686
The message "kernel: %KERN-6: ARP UNICAST MODE 0; retrans_timer - 8" might be seen when commit command is run for configuration which is not related to ARP
Product-Group=junos
"kernel: %KERN-6: ARP UNICAST MODE 0; retrans_timer - 8" message might be seen when commit command is run for configuration which is not related to ARP
PR Number
Synopsis
Category: "ifstate" infrastructure
1714785
Back to back GRES causes the vmcore to crash
Product-Group=junos
On all Junos platforms, vmcore crashes will be seen in a rare scenario after performing back to back GRES (Graceful Route Engine Switchover).
1735685
Control plane flap, data drop, unexpected behavior of PFE or device is observed when file storage is impacted in a continuous ksyncd process crash scenario
Product-Group=junos
On all Junos platforms configured with GRES (Graceful Routing Engine Switchover), file storage in the system will get affected when the ksyncd process crashes continuously and result in control plane flap, data drop or unexpected behavior of PFE (Packet Forwarding Engine) or device.
PR Number
Synopsis
Category: OSPF routing protocol
1741480
The rpd crashes when repeated routing-instance and interface is flapped
Product-Group=junos
The rpd is seen to crash when OSPF (Open Shortest Path First) is configured and repeated routing-instance and interface is flapped. The rpd crash leads to traffic impact.
PR Number
Synopsis
Category: Express Chip L3 software
1713279
Next-hop programming issue at PFE on Junos PTX and QFX10k platforms when the member of unilist is in hold state
Product-Group=junos
On PTX Series routers and the QFX10000 line of switches, traffic going over unilist is dropped when unilist member goes from next-hop hold state to unicast/aggregate state.
PR Number
Synopsis
Category: Phone-Home-Client Infrastructure
1687926
Unable to onboard the VC members after performing ZTP due to the phone-home process sending a blank in the device serial number field while connecting to the redirect server
Product-Group=junos
When EX4100/EX4400 devices are first powered on, the Zero Touch Provisioning (ZTP) by phone home will provision the devices. In rare situations where the powered devices are already connected with Virtual Chassis Port (VCP) cables to form a Virtual Chassis (VC), the ZTP using the phone home will keep retrying to connect the redirect server and unable to onboard VC because of the blank serial number sent by the phone home due to the memory corruption.
1726603
Memory leak is observed on all Junos platforms during ZTP
Product-Group=junos
On all Junos platforms where ZTP (Zero Touch Provisioning) is supported, memory leak will be seen when system is zeroized for long and left for couple of days.
1736982
Phone-Home redirect config missing for EX4650 after zeroize
Product-Group=junosvae
Phone-Home redirect config missing for EX4650 after zeroize
PR Number
Synopsis
Category: Protocol Independant Multicast
1720240
RPD process crashes on all Junos and Junos OS Evolved platforms after adding static route to the VRF in some scenarios
Product-Group=junos
When static route is added to the VRF (Virtual Routing and Forwarding), and mc-ip (multicast-ip) and the PIM (Protocol Independent Multicast) instance get deleted in some scenarios, the RPD process crash is seen on all Junos and Junos OS Evolved platforms.
PR Number
Synopsis
Category: Periodic Packet Management Daemon
1739860
The IPv6 link local based BFD session over an AE interface will be stuck in Init state
Product-Group=junos
On all MX platforms, when chassis network-services is set in IP mode, the IPv6 Link Local based BFD session over an AE interface will be stuck in init due to the next-hop misprogramming in the PFE.
PR Number
Synopsis
Category: QFX platform fabric mgmt for Express ASIC chip
1734735
Packet drop is observed due to SIB ASIC issue on fabric
Product-Group=junos
On all inserted FPCs of Junos based QFX10K8/QFX10K16 platforms, due to SIB (Switch Interface Board) ASIC (Application-Specific Integrated Circuit) issue on fabric, packets are getting dropped and major errors "PECHIP_CMERROR_EPW_MISC_INT_EVENTS_CRC_ERR (0x2101aa)" are reported. These errors are not auto-cleared on a couple of FPCs.
PR Number
Synopsis
Category: QFX PFE Class of Services
1726124
The class of service subsystem crashed after the device is restarted or the switchover is performed
Product-Group=junos
On Junos QFX5100 and QFX5110 platforms in virtual chassis, the cosd crash is observed when the GRES (Graceful Routing Engine Switchover) is performed or the device is restarted, due to which the Class of Service (CoS) functionality will not work. It is a rare issue.
PR Number
Synopsis
Category: QFX L2 PFE
1705853
Tracking PR to add the null check for list_get_head if magic is NULL.
Product-Group=junos
On all Junos platforms, as list_get_head function is called in multiple places in pfe we needed previous 3 functions on the stack which had called list_get_head, so we could debug why 'list_get_head list has bad magic' this error has occured.
1730076
Packets received on a port that is in "LACP Detached" state is getting forwarded
Product-Group=junos
On all Junos EX46xx/QFX5k (except QFX5100) platforms, child links that are in LACP (Link Aggregation Control Protocol) detached state are up and accepting incoming traffic, expecting it to drop.
1732718
On router reboot an interface in SP style blocks all packets on "family inet/inet6" interfaces if VSTP is configured on vlan-bridge encapsulated VLANs
Product-Group=junos
On Junos QFX5K and EX platforms that support Enhanced Layer 2 Software (ELS), VLAN Spanning Tree Protocol (VSTP) on vlan-bridge(L2) blocks all packets on "family inet/inet6"(L3) interfaces configured in SP style when the device reboots. All the L3 interfaces on the specific port will be impacted.
1741316
The traffic drop is observed due to the MAC source address being learned from the wrong direction
Product-Group=junos
On Junos EX4300/QFX5200/QFX5210 platforms with VXLAN (Virtual Extensible Local Area Network) enabled, when the ARP (Address Resolution Protocol) request is sent from the device, the MAC (Media Access Control) address is learned from the wrong direction which results in the traffic drop.
PR Number
Synopsis
Category: QFX L3 data-plane/forwarding
1704489
High CPU utilization causes a latency/slowness issue on QFX platforms
Product-Group=junos
On QFX5110 and QFX5120 platforms, latency or slowness issue is observed when the traffic is passing through a layer 3 interface configured with just family inet/family inet6 due to unwarranted MAC lookup. This could lead to traffic loss on that interface.
1709664
BFD sessions flap on EX and QFX platforms
Product-Group=junos
On all EX and QFX platforms, BFD(Bidirectional Forwarding Detection) sessions are flapped with VLAN configuration change on LAG interface.
1725375
DCPFE process crash can be seen on all Junos EX and QFX5K platforms with MACSEC enabled
Product-Group=junos
On all Junos platforms supporting MACSEC (Media Access Layer Security), the DCPFE (Dense Concentrator Packet Forwarding Engine) process might crash in a rare scenario when the configuration of MACSEC is deleted from the interface and the PFE is trying to access the memory location of the interface. The DCPFE process crash will lead to the FPC (Flexible PIC Concentrator) reboot but the system will self-recover.
PR Number
Synopsis
Category: QFX MPLS PFE
1742364
Traffic dropped is observed in the MPLS LDP scenario when the peer device MAC address is changing
Product-Group=junos
On Junos QFX5100 and EX4600 platforms when there is MAC (Media Access Control) change for the LDP (Label Distribution Protocol) neighbor and IP remains the same, the ARP (Address Resolution Protocol) update is proper but MPLS LDP may still use the stale MAC address of the neighbor. If there is any application/service such as MP-BGP using LDP as next-hop, all transit traffic pointing to the stale MAC address will be dropped.
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1688323
Traffic loss is observed in IP fabric when there is a change in the underlay network
Product-Group=junos
On Junos QFX5K series, EX4400 platforms, configuration-change/protocol flapping/port flapping in Ethernet Virtual private network (EVPN) Virtual Extensible LAN (VXLAN) can cause traffic loss (changes related to the underlay network).
1727119
The EVPN-VXLAN proxy-arp will respond with the wrong MAC when no-mac-learning is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms in the EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) scenario, when the knob "switch-options no-mac-learning" is configured, the mac-ip entry will still be learned even though the MAC learning is disabled due to which the proxy ARP (Address Resolution Protocol) will not work properly on the leaf device and it will respond with a wrong MAC address for the ARP request.
1736954
Unexpected VLAN tagging behavior would be observed in the EVPN-VXLAN scenario
Product-Group=junos
On Junos QFX5K/EX4650/EX4400/EX4100 platforms, in Ethernet VPN - Virtual Extensible Local Area Network (EVPN-VXLAN) scenario when multiple access ports with different VLAN (Virtual LAN) Ids in the same BD-VNI (Bridge-Domain VXLAN Network Identifiers) domain, the ingress VLAN is retained while the packet is egressing on other ports. This is seen when the knob 'encapsulate-inner-vlan' is configured and the IFD is configured with 'flexible-vlan-tagging'.
1738205
Traffic drop observed when encapsulation ethernet-bridge is configured on the AE interface associated with VxLAN VLAN
Product-Group=junos
On Junos QFX5K and EX4650 platforms, no mac-learning on the interface results in traffic drop due to hardware programming not being updated for the child interface under AE (Aggregated Ethernet) when encapsulation ethernet-bridge is configured on the AE interface associated with VxLAN (Virtual Extensible LAN) VLAN.
1738276
High convergence time in the EVPN-VxLAN uplink failover scenario
Product-Group=junos
On Junos QFX5K platforms in the EVPN-VxLAN scenario, due to high convergence time, traffic loss is more than expected when the uplink to the spine disabled (CLI initiated uplink failover).
1740327
The loop-detect is not working in the VXLAN scenario
Product-Group=junos
The loop-detect functionality is not working in the Virtual Extensible LAN protocol(VXLAN) scenario enabled with knob "encapsulate-inner-vlan" on Junos QFX5110/QFX5120/QFX5200/QFX5210 platforms. This prevents any loop detection in the looped topology and causes the traffic impact.
PR Number
Synopsis
Category: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1734734
Online SIBs will go down due to a faulty SIB that triggers spmbpfe crash
Product-Group=junos
On all the QFX10000 line of switches and PTX Series routers running Junos OS, due to initialization failure of a faulty Switch Interface Board (SIB) in the device, the Switch Processor Mezzanine Board (SPMB) status process, also known as the spmbpfe process, crashes and online SIBs go down.
1742186
SPMB process will crash and PICs will not come online
Product-Group=junos
On the QFX10000 line of switches running Junos OS, due to initialization failure of a faulty Switch Interface Board (SIB) in the device, the Switch Processor Mezzanine Board (SPMB) status process, also known as the spmbpfe process, crashes and online SIBs go down. Traffic cannot flow through the line card when this happens.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Platform optics related issues
1738077
Link down due to FEC mismatch on EX4650, EX4400 and Junos based QFX5K platforms using 25G-LR optics
Product-Group=junos
In a combination of EX4650 connected to EX4400 and Junos based QFX5K platforms connected to EX4400 using 25G-LR(Long Range) optics, FEC(Forward Error Correction) value mismatch between directly connected devices would cause the link to go down on Junos release version 20.4R3-S8 and above and leads to complete traffic loss.
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 Platfom issues
1707094
The FPC crash can be seen on QFX5k platforms during simultaneous soft and hard OIR of SFP
Product-Group=junos
On all Junos QFX5k platforms, the FPC (Flexible PIC Concentrator) crash can be seen. This is a timing issue when soft OIR (Online Insertion and Removal) and hard OIR of the SFP (Small form-factor pluggable) is done at the same time, this triggers the PFE (Packet Forwarding Engine) crash, and consequently, the FPC restarts. There will loss to data plane traffic when the FPC restarts.
1720884
Interface with QSFP+-40G-CU50CM will be down
Product-Group=junosvae
The interface will be down on EX and QFX platforms with QSFP+-40G-CU50CM (740-044512) resulting in traffic loss. In the VCP (Virtual Chassis port) scenario if connected with QSFP+-40G-CU50CM it does not come up and break the VC (Virtual Chassis) environment when upgrading or rebooting the device.
PR Number
Synopsis
Category: Issues related to dynamic-tunnels routing infrastructure
1695236
The rpd process crash is observed when dynamic tunnel deletes composite next-hop
Product-Group=junos
On all Junos OS Evolved platforms, the rpd process crash is observed when dynamic tunnel deletes composite next-hop.
PR Number
Synopsis
Category: Indirect nexthop routing infrastructure
1692776
The rpd crash will be observed when there is a temporary recursion loop and routes are flapping
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd process crashes when a temporary recursive loop forms. This happens when a BGP route flaps and while the options 'multipath-resolve' and 'preserve-nexthop-hierarchy' are configured.
PR Number
Synopsis
Category: RPD Next-hop issues including indirect, CNH, and MCNH
1716436
Traffic loss due to incorrect route resolution and KRT queue getting stuck with 'EINVAL -- Bad parameter in request' error
Product-Group=junos
On all Junos and Junos OS Evolved platforms, due to a bug in route resolution over specific types of next hops, the route can resolve over itself and the nexthop chain keeps expanding. Due to this issue, the depth of recursion gets higher than supported and the KRT (Kernel Routing table) queue returns errors for nexthops. As a result, there will be incorrect route resolution, traffic loss and occasionally, the rpd (routing protocol deamon) crashes. The necessary configurations and conditions that will result in this issue are below 1. BGP (Border Gateway Protocol) Prefix-Independent Convergence (PIC) ("protect core") is configured and BGP receives same prefix from EBGP and IBGP neighbors 2. BGP LU (Labeled Unicast) with "protection" to create backup path to protect the active and BGP receives same prefix from EBGP and IBGP neighbors 3. Mutually recursive Route resolvability situations like Resolving using Default-route (not having proper resolution config)
PR Number
Synopsis
Category: RPD policy options
1706143
Issue in committing more than 23, 4-byte AS on Junos and Junos Evolved platforms
Product-Group=junos
On all Junos and Junos Evolved platforms, when a 4 byte autonomous system (AS) number is committed with more than 23 as-path in as-path-prepend policy it gives "rpd string" error and the configuration commit fails.
1744449
Policy change to a rib-group import-policy configured with global routing-options interface-routes causes the rpd issue on all platforms with EVPN-VXLAN configuration
Product-Group=junos
When a user configures "set routing-options interface-routes rib-group " along with an import policy for that particular rib-group, it will result in an unexpected behavior. It could disrupt the rpd or result in the rpd running at 100%. This issue is only related the "interface-routes" being configured in the global routing-options hierarchy with EVPN-VXLAN configuration. This issue won't be seen when routing-options configurations can have "interface-routes" enabled under specific routing instance.
PR Number
Synopsis
Category: Shard routing infrastructure within RPD
1716431
Memory leak will be observed in rpd after performing restart routing
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms with rib-sharding enabled, memory leak will be observed in rpd when restart routing is performed. If system is up from long time and restart routing performed multiple times can exhaust system memory that causes to process crash or configuration are not effective/applied because of lack of memory then it is possible that it will impact traffic.
PR Number
Synopsis
Category: RPD route tables, resolver, routing instances, static routes
1742147
Memory leak observed when reconfiguring the flow routes
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if the nexthop of a flow route is the same as it was before when reconfiguring flow routes, memory leak occurs. High memory use of routing process daemon(rpd) is seen as a result of this leak. A kernel out of memory message is observed which results BGP flap.
PR Number
Synopsis
Category: Resource Reservation Protocol
1723229
The rpd process crash is observed when RSVP LSP at Juniper transit/ingress router receives RESV message with RESVCONF object in multi vendor deployment
Product-Group=junos
On all Junos and Junos OS Evolved platforms (For QFX5100, only in Virtual Chassis-VC setup) with RSVP (Resource Reservation Protocol) LSP (Label-Switched Path) configured in multi vendor deployment and Juniper router is acting as a transit/ingress router and RESV (Reservation Request) message is received with RESVCONF object from other vendors, rpd process crash will be observed.
PR Number
Synopsis
Category: jflow/monitoring services
1656885
The srrd process might crash in a high route churns or process flap scenario
Product-Group=junos
On all Junos OS platforms with inline Jflow enabled, the sampled route reflector process (srrd) might crash at times due to unavailability of memory resource during high route churns or flaps scenario.
PR Number
Synopsis
Category: SW PRs for SCBE3 fabric
1724007
Complete traffic blackhole from one PFE to another on fabric links after injecting/reporting CRC errors on fabric links of MX10008
Product-Group=junos
On the MX10008 platform, the low-priority stream might be marked as a destination error and as a result, the low-priority stream is stuck and all traffic might get dropped. Complete traffic blackhole is observed from one PFE to another.
PR Number
Synopsis
Category: SRX Argon module
1737442
Intermittent core-dumps is received when SMB protocol is enabled on AAMW policy and PFE memory is exhausted
Product-Group=junos
On SRX platforms, When Server Message Block(SMB) protocol is enabled on advanced anti-malware(AAMW) policy and PFE memory is exhausted in that condition, SMB and SMTP is calling the same fallback API results high memory utilization. There are two types of cores is generated one is from AAMW plugin and the other is from DNS plugin. Both of them are because memory is exhausted and these high memory utilization can cause PFE process crash which results network outage for a while.
1738656
Traffic drop caused by PFE memory leak on SRX platforms
Product-Group=junos
On Junos SRX platforms enrolled into ATP (Advanced Threat Prevention) cloud, memory leak is observed in the PFE (Packet Forwarding Engine) while deletion of few of the signatures which have no hash value. This memory leak results in traffic loss.
PR Number
Synopsis
Category: Remote Access VPN issues on SRX
1732746
nsd crash impacting remote access vpn on SRX devices
Product-Group=junos
nsd crash can be observed on SRX platforms when the SSL certificate does not have the common name (CN), Organization Unit (OU) and Organization field, this leads to break in remote access connectivity.
PR Number
Synopsis
Category: SRX branch platforms
1715247
Interface speed stays 100Mbps when removing speed and duplex command separately
Product-Group=junos
On SRX branch series, when the interface speed is set to 100Mbps and the link-mode is set to full-duplex, the interface speed remains at 100Mbps even the speed and duplex commands are removed separately.
1719108
OAM not working with flexible-vlan-tagging
Product-Group=junos
OAM is not working when flexible-vlan-tagging is enabled
1744108
Commit panic reboot observed after implementing system processes watchdog timeout 180 on SRX hardware platforms
Product-Group=junos
On SRX hardware platforms, configuring set system processes watchdog related command causes commit panic reboot. Watchdog related commands are unsupported on SRX hardware platforms.
PR Number
Synopsis
Category: SRX5XX platform
1620982
8-Port Gigabit Ethernet SFP XPIM not passing traffic after software upgrade
Product-Group=junos
On SRX550 platform, after doing a software upgrade, 8-Port Gigabit Ethernet SFP XPIM is not passing traffic
PR Number
Synopsis
Category: SRX-1RU platfom related protocol, QoS, filtering features et
1729284
L2 channel error counter increases when unknown family packets received by interfaces
Product-Group=junos
On SRX4600 and SRX5K platforms, the L2 channel error counter will increase when some unknown family packets received by interfaces.
1737721
Junos OS installation using USB can fail on SRX4600
Product-Group=junosvae
On SRX4600 platforms, Junos OS installation using USB can fail due to slow USB detection.
PR Number
Synopsis
Category: SRX-3RU platfom SW defects
1703220
Secondary node goes into disabled state after failover
Product-Group=junos
On certain SRX series platforms in a chassis cluster environment, during redundancy group failover, RE CPU busy can cause JSRPD process slip and the cluster control link to go down. If the control link goes down for more than 3 seconds, the secondary node will move to ineligible and then disabled.
PR Number
Synopsis
Category: ZT/YT pfe, vpls, mesh group software
1695438
The BUM packets are getting dropped on MX platforms during egress processing due to PFE mismatch
Product-Group=junos
The BUM (Broadcast, Unknown Unicast, and Multicast) packets are getting dropped at egress processing on all MX platforms due to an interoperability issue of MPC1/MPC2/MPC3/MPC4/MPC5/MPC6/MPC7/MPC8/MPC9 with MPC10/MPC11/LC9600 line card. It is observed when equal-cost multipath (ECMP) is enabled for the load-sharing data for an incoming traffic destined to the neighbours. It can be seen with any ECMP traffic distribution configuration.
PR Number
Synopsis
Category: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1717621
FPC's will be stuck at maximum CPU utilization when Nextgen statistics thread is hogging the CPU
Product-Group=junos
On all Junos platforms that support subscriber management, the Nextgen statistics thread hogs the Central Processing Unit (CPU). This causes the Flexible PIC Concentrators (FPC's) to get stuck at 100% CPU utilization.
PR Number
Synopsis
Category: Trio pfe qos software
1732690
Heap memory leak on MPCs used for subscriber termination.
Product-Group=junos
Heap memory leak on access MPCs used for subscriber termination may be observed in a subscriber-management environment.
1736890
The CoS rewrite rules will not be working in the EVPN with IRB scenario
Product-Group=junos
On Junos platforms, the Class of Service(CoS) rewrite rules are not working in Ethernet Virtual Private Network(EVPN) with integrated routing and bridging (IRB) scenarios. The packets will not be overwritten as per the rewrite rules and traffic forwarding through an IRB interface will not be working as expected.
PR Number
Synopsis
Category: Trio pfe stateless firewall software
1742123
Inline-monitoring will not work as expected when more than one instances are configured
Product-Group=junos
On all Junos MX and EX9200 platforms, when more than one instances of the "inline-monitoring" service are placed under firewall filter, all prefixes point to the firewall filter first term regardless of the match condition which results in inline-monitoring not working as expected.
PR Number
Synopsis
Category: Trio pfe l3 forwarding issues
1739854
Major alarms will be observed on the FPC when ALB is enabled under AE interface
Product-Group=junos
On Junos MX platforms with MPC2-MPC9 line cards configured with ALB (Adaptive Load Balancing) under AE (Aggregate Ethernet) interface and Network-Services IP mode, when the AE interface comes up initially or activating AE after deactivating, the error logs of "Bad JNH Write to unilist-selector" and "LUCHIP Uncorrectable ECC" would be observed. These errors will lead to major alarms on the FPC (Flexible PIC Concentrators) causing traffic impact.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1693630
In JUNOS EVO "show | display inheritance" does not work correctly for LSPs with whitespace in the name
Product-Group=junos
An LSP with whitespace in the name does not display correctly when viewing the configuration using 'show | display inheritance'
1730336
The rpd crashes and the commit operation fails while pushing a large configuration with the "extend-size" knob enabled
Product-Group=junos
On all Junos platforms, when the 'extend-size' knob is configured and a scaled configuration is committed, the rpd daemon crash is seen and the commit operation fails.
1730442
Device boots up even with incompatible configuration
Product-Group=junos
When 'no-validate' option is used during upgrade, presence of configuration not compatible with target software version leads to the device going into amnesiac state on first reboot. But when the device is rebooted again it boots up with the incompatible configuration and SSH (Secure Socket Shell) is restored.
1745565
The mgd process crash is observed when 'show' is executed from the configuration mode
Product-Group=junos
On all Junos platforms, when 'show' is executed from the configuration mode, a mgd process crash is observed which has no functionality impact.
PR Number
Synopsis
Category: Antivirus UTM issue
1725938
Outlook notification channel connection is not established
Product-Group=junos
On all Junos SRX platforms, When the http traffic is chunked then Outlook notification channel connection is not established due to which, the mail notifications were not received on the browser.
PR Number
Synopsis
Category: web filterig issues
1725359
Memory leak is observed on all Junos SRX platforms with http-persist and http-reassembly configuration
Product-Group=junos
On all Junos SRX platforms with http-persist and http-reassembly configuration when firewall policy is attached with enhanced or redirect WF (Web Filtering) policy, memory leak will be observed in PFE (Packet Forwarding Engine) which leads to traffic drop.
PR Number
Synopsis
Category: Junos Fusion Satellite Device Infrastructure
1733558
Junos Fusion Satellite device will be stuck in the SyncWait state
Product-Group=junos
Post upgrading the Junos Fusion AD (Aggregation Device) to the 21.4 release, the Junos Fusion Satellite devices will be stuck in SyncWait as they are trying to generate the ssh keys before clearing the old keys. The Satellite devices will not be responsive as they are stuck in the SyncWait state leading to traffic loss.
PR Number
Synopsis
Category: usf ipsec related issues
1734212
IPSEC traffic drops when two ARI routes get installed for the same tunnel
Product-Group=junos
On Junos MX and MX-VC devices having Junos-ike (Internet Key Exchange) package installed, the ARI (Auto Route Insertion) route generally gets pushed to the rpd for each config tunnel having traffic selector based on-traffic VPNs (Virtual Private Network). But it has been observed that if the iked process is restarted before the actual tunnel is negotiated, then it will result in two ARI route entries (corresponding to the same config tunnel) and this will impact the IPSEC (Internet Protocol Security) traffic on that tunnel.
1744601
With multiple Traffic Selectors having same remote-ip, the traffic works only for first tunnel on MX platforms with SPC3 cards
Product-Group=junos
In MX-SPC3 IPSec deployments, if multiple traffic selectors are configured with same remote-ip (different local-ip), the traffic works only for one of the tunnels.
PR Number
Synopsis
Category: usf logging and reporting function related issues
1744563
[USF - SPC3 - LOGGING] "log-tag" is not populated in the cgnat syslogs intermittently
Product-Group=junos
Sometimes, the log-tag within a stream is not used in syslog generation.
22.2R3-S2 - List of Known Issues
See -
22.2R2-S2 SRN Attachment
Modification History
First publication 2023-09-07
22.2R3-S2: Software Release Notification for JUNOS Software