Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX PTX QFX running Junos Evolved Software
Alert Description
Junos Software Service Release version 21.4R3-S5-EVO is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 21.4R3-S5-EVO is now available.
21.4R3-S5-EVO - List of Fixed issues
PR Number
Synopsis
Category: EVO platform software
1725823
Random link flap is observed on the ports connected to re-timer
Product-Group=evo
On Junos OS Evolved QFX5220-32CD/QFX5220-128C/PTX10001-36MR/JNP10K-LC1202/PTX10K-LC1202 platforms and Junos MPC11 linecards, if SNR (Signal to Noise) is high on the re-timer ports then a random link flap on the ports connected to re-timer will be observed.
PR Number
Synopsis
Category: MX Layer 2 Forwarding Module
1743032
FPC cards restart unexpectedly
Product-Group=evo
On Junos based MX platforms with MPC7E, FPC(Flexible PIC Concentrator) crashes and core would be observed causing traffic loss. This is a rare issue.
PR Number
Synopsis
Category: Bi Directional Forwarding Detection (BFD)
1624085
Aggregated Ethernet interface might send/receive traffic through child link though BFD status is "client in hold-down state"
Product-Group=evo
On all Junos OS and Junos OS Evolved devices, traffic might continue to forward on the aggregated Ethernet member link even if MicroBFD status is in a hold-down state. There is no traffic loss due to this issue.
PR Number
Synopsis
Category: Border Gateway Protocol
1626717
Junos OS and Junos OS Evolved: An rpd crash may occur when BGP is processing newly learned routes (CVE-2023-44197)
Product-Group=evo
An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA73163
[juniper.net]
for more information.
1670715
The rpd process crash is observed when running BGP-LS EPE configuration with RIB sharding enabled
Product-Group=evo
The rpd process crash is observed when running BGP-LS (Border Gateway Protocol - Link-State) EPE (Egress Peer Traffic Engineering) configuration with RIB sharding enabled since the label allocation is only allowed in the main thread. But the shards thread was trying to allocate the label during EPE configuration parsing.
1673160
The routes with an independent resolution can trigger an rpd crash when the last BGP peer is down
Product-Group=evo
On all Junos and Junos Evolved platforms, Independent resolution routes imported from another table (i.e. VRFs with color routes that need resolution) can trigger an rpd crash when the last BGP peer is down.
1679950
BGP auto-discovery sessions does not work any more after an interface flap
Product-Group=evo
On all Junos and Junos Evolved platforms, BGP (Border Gateway Protocol) having peer-auto-discovery configured, these sessions will not get established again in case the interface for the BGP session goes down and comes back up. There will be a service impact when the BGP peer remains down and to recover from the issue the BGP peer-auto-discovery has to be disabled and BGP peering to be reconfigured.
1696870
BGP scheduler slips during sub-optimal prefix-walk while deleting selected prefixes from a large set.
Product-Group=evo
On all Junos and Junos Evolved platforms, you might see the BGP scheduler slip while deleting a large set of prefixes.
1699233
The BGP Auto-discovered neighborship is not formed after a reboot
Product-Group=evo
On MX-Series/PTX10000/PTX10008/QFX5120-32C/QFX5200/QFX5210/QFX10008 platforms, the BGP(Border Gateway Protocol) Auto-discovered neighborship when it is formed using IPv6 Neighbor Discovery Protocol (ND), fails to come up after the device reboot.
1705938
The BGP sessions will flap after the RE switchover
Product-Group=evo
On all Junos and Junos OS Evolved platforms with dual RE (Routing Engine) or VC (Virtual Chassis) with NSR enabled scenarios, in some rare BGP scaled scenarios upon RE switchover the new Master RE will send out a route refresh message to all the peers, which is not expected. This will eventually lead to the BGP session flap.
1709837
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=evo
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA72510
[juniper.net]
for more information.
1728455
The rpd process crashes when BGP is cleaned up
Product-Group=evo
On Junos and Junos OS Evolved platforms, if static default RT-C (Route Target -Constrain) is configured when Border Gateway Protocol (BGP) is cleaned up (whole BGP is cleaned up), the routing process will crash.
1731803
Junos OS and Junos OS Evolved: The rpd will crash upon receiving a malformed BGP UPDATE message (CVE-2023-44204)
Product-Group=evo
An Improper Check or Handling of Exceptional Conditions vulnerability in Routing Protocol Daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA73170
[juniper.net]
for more information.
1732493
The rpd process crash will be observed with BMP and independent resolution is enabled for secondary BGP routes
Product-Group=evo
On all Junos and Junos OS Evolved platforms, when BMP (BGP Monitoring Protocol) post-policy and independent resolution is enabled for secondary (route leaked through rib-group) BGP routes, then with the inactive secondary route change the rpd process crash will be observed.
1736029
Junos OS and Junos OS Evolved: RPD crash when attempting to send a very long AS PATH to a non-4-byte-AS capable BGP neighbor (CVE-2023-44186)
Product-Group=evo
An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a BGP update message with an AS PATH containing a large number of 4-byte ASes, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA73150
[juniper.net]
for more information.
1738074
BFD session for BGP remains down in a specific scenario
Product-Group=evo
On all Junos and Junos Evolved platforms supporting BFD (Bi-directional Forwarding and Detection) for BGP (Border Gateway Protocol) multi-hop BFD sessions can remain in a down state. This issue is seen when the multi-hop BFD session endpoints are in the same subnet but the interface addresses on which the BFD is configured are not directly connected.
1739335
The rpd process crash will be observed when the prefix-limit exceeds on the backup RE
Product-Group=evo
On all Junos and Junos OS Evolved platforms configured with BGP (Border Gateway Protocol), NSR (Nonstop Active Routing), and prefix-limit with idle-timeout, when the prefix-limit exceeds on the backup RE (Routing Engine) and switchover is performed the rpd process crash will be observed on the new backup RE.
1742222
Partial application of BGP import policy with BMP configuration and after back-to-back commits changes BGP import policy
Product-Group=evo
When BMP is configured and sessions are established, if a back-to-back commit is made that alters a BGP peers import policy, then the import evaluation job is not re-run after the 2nd commit. This can lead to partial application of the desired policy, resulting in missing values that need to take effect with second policy (eg: missing communities).
PR Number
Synopsis
Category: PTX10003 Platform related issues
1706688
The device will undergo a silent reboot due to disk related failures
Product-Group=evo
On all Junos Evolved platforms, if a disk related failure is detected, a software reboot will be triggered even if the error is a transient or temporary one. A resiliency fix to check the SSD freeze multiple times before triggering the reboot is added.
PR Number
Synopsis
Category: PFE L2 forwarding features on BT based platforms
1723756
In EVPN-VXLAN setup ARP reply packets are not processed properly on Junos OS Evolved based PTX platforms
Product-Group=evo
On Junos OS Evolved based PTX platforms with EVPN-VXLAN setup, Address Resolution Protocol (ARP) requests arriving on the VXLAN Tunnel End Point (VTEP) interfaces are not properly processed because a portion of the interface index is incorrectly modified, resulting in traffic loss.
1736699
Evolved is using old MAC address for forwarding leading to traffic drops
Product-Group=evo
On Junos Evolved platforms with VXLAN (Virtual Extensible LAN) configuration, traffic drops because the ICMP (Internet Control Message Protocol) response is going with old/stale MAC (Media Access Control) address.
1745528
Error observed when configuring AE interface
Product-Group=evo
Untagged control traffic will get dropped on a physical interface with coinciding lport value (1 less) and this physical interface has to be in l3 mode or its part of AE interface which is in l3 mode.
PR Number
Synopsis
Category: Express BT PFE L3 Features
1753394
FPC reboot can cause a crash while UDP streaming of packet usage sensor path
Product-Group=evo
On Junos PTX10008/PTX10016 Evolved platforms, after running longevity test (9 hours or above), when UDP streaming of packet usage sensor path (/junos/system/linecard/packet/usage/), if FPC is restarted the statistics database is not getting reinitialized which leads to FPC crash.
PR Number
Synopsis
Category: CFM
1682939
Maintenance-domain (MD) and Maintenance-association (MA) configuration display changed to ordered-by-system type
Product-Group=evo
With this the maintenance-domain (MD) configuration and maintenance-association (MA configuration) under the connectivity-fault-management stanza will be ordered by the system and not as per the configuration order.
PR Number
Synopsis
Category: EVO Netstack FIB Service Daemon
1703955
SYN-ACK and subsequent TCP session packets generated by RE will have incorrect DSCP value
Product-Group=evo
On all Junos OS Evolved platforms, TCP SYN-ACK packet generated by the Routing Engine(RE) in response to a TCP SYN and subsequent packets of the session will have an erroneous Differentiated Services code point (DSCP) value when "set class-of-service host-outbound-traffic dscp-code-point " is configured.
PR Number
Synopsis
Category: Issues related to evo operations - libevo infra, typeinfo ..
1752267
Traffic blackholes due to next-hops are stuck in the pending-delete in evo-aftmand
Product-Group=evo
On all Junos Evolved platforms, when repeated modifications are done for the routes changing next-hops, because of the non-cleanup of the previous next-hop information, next-hops are stuck in the pending-delete which leads to a traffic blackhole.
PR Number
Synopsis
Category: software upgrade infra issues
1731877
Auto-sw-sync doesn't trigger upgrade/restart of routing engine
Product-Group=evo
On Junos Evolved PTX10008 and PTX10016 platforms, on releases after 21.2R1-EVO, on enabling auto-sw-sync with no user groups configuration, routing engine 1 (RE1) after joining the cluster, can not sync the versions present in master RE0.
1755616
automatic software synchronization mechanism doesn't function as expected
Product-Group=evo
On all Junos Evolved platforms, the auto-sw-sync mechanism doesn't function as expected. When Routing Engine is out of cluster and attempts to rejoin the cluster, synchronization fails to occur. Consequently, the current version from the master does not sync to the backup Routing Engine, resulting in new Routing Engine continuous reboot that denies access to break the cycle.
PR Number
Synopsis
Category: Interface PRs defect & enhancement requests
1743461
Changing speed and adding to AE in the same commit fails
Product-Group=evo
On all Junos OS Evolved platforms, If the changing of the speed and the creation of the ae interfaces is in the same commit, the commit fails with "Interface aeX with child links of mixed speed but link-speed mixed is not configured".
PR Number
Synopsis
Category: EVO Netstack Juniper Tunnel Driver Module
1593816
Jtd stats are becoming far too voluminous and hard to decipher
Product-Group=evo
On all EVO platforms, Jtd stats are becoming far too voluminous and hard to decipher.
PR Number
Synopsis
Category: EVO L2 Control Plane PRs
1713640
On PTX10001-36MR the VXLAN tunnel termination functionality impacted with global configuration not enabled
Product-Group=evo
On Junos Evolved PTX10001-36MR platform, the VXLAN (Virtual Extensible LAN) tunnel termination functionality will be impacted when configuration is not enabled for tunnel termination. As the tunnel will not get terminated this will impact the packet forwarding process.
PR Number
Synopsis
Category: Category to track runtime issues during package install
1705229
Every second and further system snapshots will raise a Disk Labelled Alarm for a brief moment
Product-Group=evo
Upon executing "request system snapshot" there might be a brief Disk Labelled incorrectly Alarm raised for a few seconds. There is no operational impact.
PR Number
Synopsis
Category: EVO Socket replication
1594082
The IPv6 BGP session convergence will be slow
Product-Group=evo
On all Junos Evolved platforms, the IPv6 BGP session convergence will be slow however there is not any traffic impact due to this issue.
1736428
BGP session flaps due to hold time expiration
Product-Group=evo
On all Junos Evolved platforms which supports dual RE (Routing Engine), BGP (Border Gateway Protocol) session flaps due to hold time expiration when BGP and NSR (Nonstop Active Routing) are enabled and the peers exchange routes at same time.
PR Number
Synopsis
Category: eventd, syslog infra issues
1726925
Syslog filter not functioning with generating /etc/syslog.conf+ file after syslog config is deactivated and re-activated
Product-Group=evo
On Junos Evolved platforms, after syslog config is deactivated and re-activated, syslog filter does not function because /etc/syslog.conf file is not updated with generating /etc/syslog.conf+ file.
PR Number
Synopsis
Category: SNMP, mib2d issues
1732325
The snmpd-subagent crash seen upon upgrading or rebooting
Product-Group=evo
On all Junos Evolved platforms, snmpd-subagent core will be seen when snmp query is in progress and system got rebooted. There is no service impact due to this issue.
PR Number
Synopsis
Category: EVPN control plane issues
1716663
RPD process crash may be observed when routing or evo-pfemand process is restarted and multicast snooping process adds a route to inetmcsn.1 table
Product-Group=evo
On Junos OS Evolved platforms, a routing process crash may be observed when "restart routing" or "restart evo-pfemand" is applied and multicast snooping process adds a route to inetmcsn.1 table at the same time. When the issue is hit, the core file of rpd will be generated. This is a timing issue and it may be observed when both the events happen at the same time.
1746787
The user will be unable to configure the interface having stacked outer VLAN and a list of inner VLANs
Product-Group=evo
On Junos and Junos OS Evolved platforms, the configuration of stacked VLAN on an interface will not allow the user to configure the interface having stacked outer VLAN and a list of inner VLANs. A certain bridge interface configuration will not pass the commit check with JUNOS releases and throw an error message like "EVPN: Interface xe-0/1/0.0 must be added in a bridge-domain/vlan".
PR Number
Synopsis
Category: EVPN Layer-2 Forwarding
1758677
Traffic flooding for hardware programming failure
Product-Group=evo
Issue 1: On QFX5K and EX platforms, SVLBNH (shared VXLAN load balancing next hop) info is not getting programmed in PFE during re-sync attempts when hardware programming by l2alm to PFE fails initially resulting in traffic flooding when VPLAG is configured, and BGP flaps.Issue 2: On all Junos platforms, l2alm sends a delete request for control MAC addresses to l2ald after multiple hardware sync failures resulting in traffic flooding.
PR Number
Synopsis
Category: ISIS routing protocol
1713008
Stale entries present in the lsdist table after ISO address change
Product-Group=evo
On all Junos and Junos OS Evolved platforms configured with IS-IS and MPLS traffic engineering database (TED), if there is an ISO address change on another Intermediate System (IS), there will be stale entries being present in the link-state distribution (lsdist) table even though they might have been deleted in IS-IS and TED. This has an impact on the routes, and thus the services, related to the stale entries present in the lsdist.
1746349
Traffic loss observed in SR-LDP stitch scenario when ECMP is enabled on PTX platforms
Product-Group=evo
On PTX platforms, ISIS SR-LDP stitching using mapping server could result in traffic drops on some legs of an ECMP if there are more than 8 ECMP paths and not all paths are via the same neighbor node.
PR Number
Synopsis
Category: jdhcpd daemon
1722082
DHCP binding is not happening in EVPN VXLAN topology with DHCP stateless relay (forward-only)
Product-Group=evo
In EVPN VXLAN topology with DHCP stateless relay (forward-only) configured at layer 3 gateways, Jdhcpd broadcasts snooped unicast offer packets. That leads to the offer getting dropped on its way to the client and then the IP negotiation fails.
PR Number
Synopsis
Category: Layer 2 VPN related issues
1654516
The Integrated Routing and Bridging (IRB) interface might flap when a static route is added or deleted in a custom routing instance
Product-Group=evo
On all Junos platforms, when a static route is added or deleted in a user defined routing instance, the IRB interface associated with the routing-instance might flap which will impact any services or protocols running over it.
PR Number
Synopsis
Category: Layer 2 Control Module
1739975
Layer 2 traffic will be dropped on VSTP disabled interface
Product-Group=evo
On Junos platforms, Whenever an interface is disabled under VSTP (VLAN Spanning Tre Protocol) configuration, the issue will be seen in the following cases. 1. When interface, IFBD (Interface Family Bridge Domain) and VSTP, configured via single commit. (In case of new configuration) 2. When VSTP configurations are present and chassisd restarts/device reboots, then issue will be seen. (During ifd delete and add, issue will be seen)
1763053
LLDP neighborship will not be formed on all Junos devices
Product-Group=evo
On Junos and Junos OS Evolved platforms, LLDP (Link Layer Discovery protocol) neighborship will not come up on local device if the local device is using Junos version lower than 21.4R3-S2 or lower than 22.3 and remote device is using Junos version higher than 21.4R3-S2 or 22.3.
PR Number
Synopsis
Category: Layer2 forwarding on EX/NTF/PTX/QFX
1680242
The l2ald is treating mac as a duplicate causing traffic loss
Product-Group=evo
On all Junos and Junos Evolved platforms, with EVPN-VXLAN (Ethernet Virtual Private Network -Virtual Extensible Local Area Network) multihoming scenario, l2ald (Layer two Address Learning Daemon) considers the mac as duplicate, and traffic drop will be observed.
1743282
The l2ald crashes when there is recursive deletion of IFBD or when BGP neighborship is cleared in EVPN-VXLAN multi-homed configuration
Product-Group=evo
On all Junos and Junos OS Evolved platforms, in a rare scenario, due to timing issue, the l2ald (Layer 2 Address Learning Daemon) crashes and traffic is being blackholed due to recursive deletion of IFBD (Interface Family Bridge Domain) or when BGP (Border Gateway Protocol) neighborship is cleared when EVPN (Ethernet Virtual Private Network) - VXLAN (Virtual Extensible Local Area Network) with multi-homed is configured.
PR Number
Synopsis
Category: Multiprotocol Label Switching
1649565
The error severity of the syslog message "ted_client reset" generated during the commit is incorrect
Product-Group=evo
On all Junos and Junos evolved platforms, the severity of the syslog message "ted_client reset" that is generated by the rpd process during the commit is incorrect. It only generates an error message in the syslog.
1694957
The rpd process crash is seen when PCCD is deactivated
Product-Group=evo
On all Junos and Junos Evolved platforms, deactivating PCCD (Path Computation Client Process) from MPLS (Multiprotocol Label Switching) Container LSP (Label Switched Path) might result in the rpd core. When the container LSPs are removed from the tag external controller, the cleanup of the members does not happen which results in the core.
1705964
Member LSPs of a container LSP will be torn down unexpectedly
Product-Group=evo
On all Junos and Junos Evolved platforms, in a rare sequence of events, member LSPs will be unexpectedly torn down with no change in traffic rate. The issue happens when normalization is triggered in shorter intervals when Patherr failure/auto bandwidth adjustment fails on member LSPs and enough valid samples are not received before normalization could occur during failover. Traffic drop will be seen if the new set of LSPs after the deletion is not able to accommodate a larger required bandwidth.
1738774
Traffic blackhole due to an additional label when CCNH is toggled
Product-Group=evo
On all Junos and Junos Evolved platforms, with scaled Border Gateway Protocol (BGP) routes, when Chained Composite Next Hops (CCNH) is toggled, a few next-hops end up creating additional labels causing a traffic blackhole.
1740226
LSP with auto bandwidth enabled is not updating its Max AvgBW value, preventing the LSP from being resized
Product-Group=evo
On all Junos and Junos OS Evolved platforms, when there is no underflow limit configured under auto-bandwidth for an RSVP (Resource Reservation Protocol) LSP (Label Switched Paths), and if the traffic across the LSP is reduced and there is an underflow, the LSPs continue to be signaled with a higher bandwidth without being adjusted even after multiple adjustment intervals. The issue is observed only when there is a secondary standby path present. The MaxAvgBw (Maximum Average Bandwidth) value continues to stay at a higher value and is not being set based on the underflow Max Avg. This will eventually lead to bandwidth starvation for other LSPs.
PR Number
Synopsis
Category: For multicast snooping on MX
1636261
Message 'Initialize libjtask-license first! for mcsnoopd' is seen after committing configuration
Product-Group=evo
On all Junos platforms, a harmless message is observed on the terminal output after committing the multicast snooping configuration.
PR Number
Synopsis
Category: OS IPv4/ARP/ICMPv4
1647331
arp-retries knob needs to be unhidden for EVO ISSU ARP RLI.
Product-Group=evo
arp-retries knob needs to be unhidden
1662297
Enabling "arp-retries" knob on Junos platforms
Product-Group=evo
This CLI was hidden. This is made unhidden for ISSU feature.
PR Number
Synopsis
Category: OSPF routing protocol
1702456
Junos prefers SRMS advertised label over IS-IS/OSPF SID label advertised via opaque-AS Extended-Prefix
Product-Group=evo
On all Junos and Junos Evolved platforms, when IPv4 prefix advertisement received by an IS-IS/OSPF router in the Extended IP reachability TLV and SR mapping server (SRMS) advertisement for the same prefix received through the segment identifier (SID) label Binding TLV, then SRMS advertised label preferred over IS-IS/OSPF SID label advertised via opaque-AS Extended-Prefix. Traffic will be sent via wrong path due to this issue.
PR Number
Synopsis
Category: Path computation client daemon
1687885
On Junos and Junos Evolved platforms delegated LSP control will not be returned to the PCC in a specific scenario
Product-Group=evo
On all Junos and Junos Evolved platforms where multiple PCEs (Path Computation Element) are provisioned and connected to Junos PCC (Path Computation Client) and when all the PCEP (Path Computation Element Protocol) sessions are down, LSP (Label Switched Path) control will not be returned to the PCC. As a result, if existing EROs (Explicit Route Object) becomes invalid, new ERO will not be computed by PCC and there will be traffic loss.
PR Number
Synopsis
Category: Issues related to PKI daemon
1739342
Memory leak in PKID
Product-Group=evo
PKID process shows memory usage increase over time after a larger number of certificate verifications. The issue can be recovered by the CLI command "restart pki-service".
PR Number
Synopsis
Category: QFX5100 Interface related issues
1688023
The LLDP output packets are not transmitting on the em0 interface of Junos and Junos OS Evolved platforms
Product-Group=evo
On Junos and Junos OS Evolved platforms, if a management Ethernet interface(em0) has an inet or inet6 family configured and "delete interfaces em0" is issued, the Link Layer Discovery Protocol (LLDP) output packets will stop transmitting, causing the LLDP neighborship to remain down in peer router.
PR Number
Synopsis
Category: RPD infrastructure issues related to NSR, GRES, switchover,
1727957
The traffic drop is observed during the Graceful restart on Junos and Junos Evolved platforms
Product-Group=evo
On all Junos and Junos Evolved platforms, during the time of Graceful restart(GR), the routes in the Multiprotocol Label Switching(mpls).0 table will be updated even when the routing protocols are in the process of re-convergence and have not yet come out of GR. This causes inaccurate routes in the routing table and traffic drop is observed during GR.
PR Number
Synopsis
Category: RPD Interfaces related issues
1709629
RPD CPU utilization is 100% when configured with virtual router-advertisement for AE interface
Product-Group=evo
On all Junos and Junos OS Evolved platforms rpd ( Routing protocol daemon) CPU utilisation reaches 100% when configured with virtual router-advertisement for AE interface due to which AE member link flaps.
PR Number
Synopsis
Category: KRT Queue issues within RPD
1738820
An rpd crash will be observed due to inconsistency between rpd and kernel
Product-Group=evo
On Junos and Junos Evolved platforms, an rpd crash will be observed when rpd tries to add composite next-hop with the same parameters as in the kernel existing composite next-hop which is marked deleted but not deleted due to some reference.
PR Number
Synopsis
Category: Issue related to mcnh routing infrastructure within RPD
1749431
PTX10K EVO - rpdagent may core after FMBB knob is enabled and deleted then system is rebooted
Product-Group=evo
On PTX10K EVO platforms, rpdagent may core after FMBB knob is enabled and deleted then system is rebooted.
1757635
Synchronization issue between RIB and FIB tables leads to the P2MP LSP traffic outage
Product-Group=evo
On all Junos Evolved PTX platforms, RIB (Routing Information Base) and FIB (Forwarding Information Base) tables are not synchronized properly, causing the P2MP (Point-to-Multipoint) LSP (label-switched-path) traffic outage when executing the CLI command "clear rsvp session".
PR Number
Synopsis
Category: RPD policy options
1744449
Policy change to a rib-group import-policy configured with global routing-options interface-routes causes the rpd issue on all platforms with EVPN-VXLAN configuration
Product-Group=evo
When a user configures "set routing-options interface-routes rib-group " along with an import policy for that particular rib-group, it will result in an unexpected behavior. It could disrupt the rpd or result in the rpd running at 100%. This issue is only related the "interface-routes" being configured in the global routing-options hierarchy with EVPN-VXLAN configuration. This issue won't be seen when routing-options configurations can have "interface-routes" enabled under specific routing instance.
PR Number
Synopsis
Category: RPD route tables, resolver, routing instances, static routes
1692484
Configuration check-out failed when applying "irb with inet and inet6" and "inet6.0 static route"
Product-Group=evo
commit check for overlapping prefix will fail to commit when :: /0 static route is configured with qualified next-hop and irb interface.
1742147
Memory leak observed when reconfiguring the flow routes
Product-Group=evo
On all Junos and Junos OS Evolved platforms, if the nexthop of a flow route is the same as it was before when reconfiguring flow routes, memory leak occurs. High memory use of routing process daemon(rpd) is seen as a result of this leak. A kernel out of memory message is observed which results BGP flap.
PR Number
Synopsis
Category: Resource Reservation Protocol
1723229
The rpd process crash is observed when RSVP LSP at Juniper transit/ingress router receives RESV message with RESVCONF object in multi vendor deployment
Product-Group=evo
On all Junos and Junos OS Evolved platforms (For QFX5100, only in Virtual Chassis-VC setup) with RSVP (Resource Reservation Protocol) LSP (Label-Switched Path) configured in multi vendor deployment and Juniper router is acting as a transit/ingress router and RESV (Reservation Request) message is received with RESVCONF object from other vendors, rpd process crash will be observed.
PR Number
Synopsis
Category: PTX10008 EVO Resiliency Improvement
1621360
To raise a persistent alarm to be raised to indicate that a PFE is in a Fault state when a fatal error occurs
Product-Group=evo
When PFE is in a fault state in the event of a fatal error, a persistent alarm should be raised.
PR Number
Synopsis
Category: PTX10K specific platform PRs
1720259
System calls for shutdown after RE switchover
Product-Group=evo
When Routing Engine (RE) mastership switchover is performed, CoolingApp from the new backup Routing Engine might incorrectly interpret the temperature sensor reading and initiates a system shutdown request.
1734752
The "Fan Tray 0 Failure" alarm is raised post GRES RE revert on Junos OS Evolved PTX10K platforms
Product-Group=evo
On Junos OS Evolved PTX10K platforms, "Fan Tray 0 Failure" alarm could be raised after GRES (Graceful Routing Engine Switchover) RE (Routing Engine) revert (RE1 -> RE0) is done.
1735224
Junos OS Evolved: PTX10001, PTX10004, PTX10008, PTX10016: MAC address validation bypass vulnerability (CVE-2023-44190)
Product-Group=evo
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10001, PTX10004, PTX10008, and PTX10016 devices allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router will start forwarding traffic if a valid route is present in forwarding-table, causing a loop and congestion in the downstream layer-2 domain connected to the device. Please refer to https://supportportal.juniper.net/
JSA73154
[juniper.net]
for more information.
1739842
FTC X FTC FPGA minimum supported firmware version mismatch alarm raised by OIR FTC
Product-Group=evo
On all Junos Evolved platforms which use fan tray and fan tray controllers both, FTC X FTC FPGA minimum supported firmware version mismatch alarm raised with FTC OIR.
1745749
The hwdre application restarted due to memory leak
Product-Group=evo
On all Junos Evolved platforms, the hwdre application restarted due to a memory leak.
PR Number
Synopsis
Category: PTX10K RE EVO Issues
1486688
PTX10K4/8/16 - Online/Offline button on RCB front panel not working
Product-Group=evo
On PTX10K4/8/16 platforms, front panel Online/Offline button press on backup RE brings backup CB status to Fault Standby state.
1747567
Control board is stuck in Present state
Product-Group=evo
On PTX10008, PTX10016 and PTX10004 platforms, the Routing Engine mated on the Control Board are one FRU(Field Replaceable Unit). Upon Routing-Engine replacement the Control-board might be stuck in State 'Present' while the Routing Engine is fully operational and online. To get the Control Board back online, execute the following command. 'request chassis cb slot online'
PR Number
Synopsis
Category: Bug and Review Tracking for Segment routing traffic eng
1737119
The traffic blackhole will be observed when the SRTE shortcut is configured
Product-Group=evo
On Junos platforms, when the MPLS (Multiprotocol Label Switching) packet reaches the destination router, it will have a label that is unknown to the destination router due to a label POP operation miss at the ingress router resulting in the traffic black hole in the scenario SR-MPLS (Segment Routing With Multiprotocol Label Switching) + traffic engineering shortcut is configured.
PR Number
Synopsis
Category: Configuration mgmt, ffp, load-action, commit processing
1663590
Commit failure might be observed on reactivation or commit of specific configurations after the upgrade of the device
Product-Group=evo
On all Junos and Junos Evolved platforms, reactivation or commit of specific configurations fails after the upgrade of the device.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1740289
The 'load replace' operation might result in mustd and mgd crash
Product-Group=evo
On Junos and Junos Evolved platforms with apply-group configured, mustd and mgd crash might be observed when the 'load replace' operation is performed due to which all the apply-groups will get deleted internally, and respective hierarchies will not be notified.
PR Number
Synopsis
Category: X-Men interface software related issues.
1678504
The QDD-400G-ZR optics firmware upgrade fails on all Junos OS Evolved platforms
Product-Group=evo
Optics firmware upgrade for QDD-400G-ZR optics will be unsuccessful on all Junos OS Evolved platforms.
PR Number
Synopsis
Category: PFE COS features on ZX based platforms
1733509
In TCP flow, the initial SYN+ACK packet will not be marked with specified CoS related action on Junos Evolved platforms
Product-Group=evo
On all Junos Evolved platforms the first SYN+ACK packet in the TCP (Transmission Control Protocol) flow will not be marked with the action of the CoS (Class of Service) configuration. This issue is seen when the firewall filter is configured on the loopback outbound interface. Ideally there is no impact on data traffic because of this issue, but in rare cases peer device can drop the SYN + ACK packet.
21.4R3-S5-EVO - List of Known issues
PR Number
Synopsis
Category: "agentd" software daemon
1695980
rpc error when resource name exceeding 255 character.
Product-Group=evo
Junos and Junos Evolved has a limitation of 255 characters for resource names. Increasing the limit will have implications on the CLI output and same changes will needed to be propagated to lower layers where the resources are served from.
Resolved In:
evo:21.2X80-D28-EVO evo:22.3X80-D30-EVO evo:22.3X80-D31-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:23.2R1 junos:23.3R1
PR Number
Synopsis
Category: Border Gateway Protocol
1712406
IPv4 routes learnt over a link-local BGP session not advertised ahead to other BGP peers
Product-Group=evo
When rib (Routing Information Base) contains IPv4 routes with IPv6 next-hops, these routes do not get re-advertised by IPv4 EBGP sessions unless export policy is configured to change it to IPv4 next-hop.
Resolved In:
evo:21.4R3-S6-EVO evo:22.2R3-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.4R3-S5 junos:22.1R3-S2 junos:22.1R3-S4 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.1R2 junos:23.2R1
PR Number
Synopsis
Category: PFE COS features on BT based platforms
1732461
Traffic drop under strict-priority queue before low priority queue
Product-Group=evo
On Junos OS Evolved PTX10001-36MR, PTX10004, PTX10008, and PTX10016 platforms, when a strict-high priority queue without transmit-rate is configured on a 10Gig port, it will experience a packet drop before the low priority queue.
Resolved In:
evo:21.4R3-S6-EVO evo:22.3R3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO
PR Number
Synopsis
Category: EVO Class of Services
1766873
[EVO:COSD] Duplicate code points through code-point-aliases under a classifier results in cosd crash.
Product-Group=evo
cos commit validation is missing for classifier when using code-point-aliases. The user can configure duplicate code-point-aliases and use them in a classifier. This will result in a cosd crash. The system can be recovered by correcting the config and applying the "restart class-of-service" command.
Resolved In:
evo:22.3R3-S2-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:23.2R2 junos:23.3R2 junos:23.4R1
PR Number
Synopsis
Category: Interface PRs defect & enhancement requests
1670362
When donor interface is admin down, borrower can't be pinged from local/remote
Product-Group=evo
On all Junos Evolved platforms, in general, the network borrows addresses from lo0 which is not made admin down. When the interface has borrowed the address, need to note when it is down as the down borrowed interface will not receive packets.
Resolved In:
evo:22.3R1-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:22.4R1
PR Number
Synopsis
Category: EVO Netstack Juniper Tunnel Driver Module
1718999
TCP connection will be terminated when sent with incorrect MSS
Product-Group=evo
On all Junos Evolved platforms, Transmission Control Protocol (TCP) packets whose size is larger than its interface Maximum Transmission Unit (MTU) will be dropped impacting TCP connections.
Resolved In:
evo:21.4R3-S6-EVO evo:22.3R2-S1-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D32-EVO evo:22.3X80-D33-EVO evo:22.4R2-S2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO
PR Number
Synopsis
Category: EVO linux defects & enhancement requests
1759541
Upon kernel panic mastership relinquish might take longer the 5 seconds causing FPC restart
Product-Group=evo
During kernel panic execution on systems with dual RE's will perform mastership switch. Depending on the kernel modules involved and the stack trace printed to the console, the switchover might get delayed causing potential FPC restart. The solution is to perform relinquish mastership switch before the stack traces is reported. This applies to JUNOS-EVO platforms PTX10004, PTX10008 and PTX10016
Resolved In:
evo:22.3X80-D40-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:23.2R2 junos:23.4R1
PR Number
Synopsis
Category: Express PFE FW Features
1691365
Adding Alpha Load Balancing on EVO PTX series to get better filter scale.
Product-Group=evo
This is an enhancement. Adding alpha load balancing so that filter can get better scale numbers for some cases.
Resolved In:
evo:21.4R3-S4-EVO evo:21.4X1-EVO evo:22.1R3-S2-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:22.4R2-EVO evo:23.1R1-EVO
PR Number
Synopsis
Category: MX10K platform
1674322
SNMP traps "Power Supply failed" and "Power Supply OK" are not generated
Product-Group=evo
On all Junos MX10k and PTX10k platforms, when a PSU with no feeds connected, but the DIP switch at the back of the PSU is set in a position where it expects the feeds to be connected, then POWER FAILED TRAPs might not get generated as expected.
Resolved In:
evo:22.1R3-EVO evo:22.2R2-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:20.3X75-D36 junos:20.4R3-S5 junos:21.2R3-S6 junos:22.1R3 junos:22.2R2 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR Number
Synopsis
Category: PTX10K specific platform PRs
1738854
The interface goes down and the error message floods due to the FD leak in the picd process
Product-Group=evo
On Junos Evolved PTX10K platforms, the error message 'Too many open files' starts flooding and the interface goes down due to the file descriptor (FD) leak in the picd process.
Resolved In:
evo:23.4R1-EVO junos:23.4R1
PR Number
Synopsis
Category: PTX10K Timing/Sync-E issues tracking
1738022
PTX10K EVO - BITS port LED color of Physical/CLI/MIB do not match
Product-Group=evo
On PTX10K4/8/16 EVO platforms, BITS port LED color of Physical / CLI "show chassis synchronization extensive"/ MIB "jnxLEDState" do not match.
Resolved In:
evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:23.2R2 junos:23.3R2 junos:23.4R1
Modification History
First Publication 2023-10-23
21.4R3-S5-EVO: Software Release Notification for JUNOS Evolved Software