Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 20.4R3-S9 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 20.4R3-S9 is now available.

20.4R3-S9 - List of Fixed issues 

PR NumberSynopsisCategory: EX4300 PFE
1720219PFE process crash is observed on Junos EX4300 platforms
Product-Group=junos
In a rare scenario, due to timing issues, the Packet Forwarding Engine (PFE) crash is observed on Junos EX4300 platforms. This causes traffic loss until the PFE comes up.
1725042VRRP peers delay to sync when 'mac-move-limit' is configured on EX switch
Product-Group=junos
On Junos EX series platforms, VRRP (Virtual Router Redundancy Protocol) sync will be delayed impacting the VRRP traffic if the device receives a VRRP packet when setting up the 'mac-move-limit' configuration.
1749406MAC address is learned via LACP defaulted/detached port causing traffic to flow on the port
Product-Group=junos
On all EX4300 platforms, traffic is sent on an AE interface and sent to the removed child interface from AE (Aggregated Ethernet) where the traffic is lost.
PR NumberSynopsisCategory: EX4300 Platform
1749289On EX4300, "Error requesting CMTFPC SET INTEGER" and "Error requesting SET BOOLEAN" logs may be seen after device boot up. There is no functional impact for the error messages
Product-Group=junos
 
PR NumberSynopsisCategory: EX2300/3400 PFE
1742303DHCP packets traversing the switch even though the source mac is not present in accept-source-mac list
Product-Group=junos
In EX2300 & EX3400 devices, even though accept-source-mac knob is configured, DHCP Packets with the MAC address not present in the accept-source-mac list are accepted and traverse in the network.
PR NumberSynopsisCategory: EX-Series VC Infrastructure
1700133One of the Virtual Chassis members on EX4600-VC might be disconnected during VC initialization
Product-Group=junos
On EX4600-VC, when "request system reboot all members" is executed, post-reboot one of the VC member/Flexible PIC Concentrator(FPC) might disconnect and join the VC back due to Packet Forwarding Engine (PFE) restart. Traffic loss is seen when FPC is disconnected.
PR NumberSynopsisCategory: MX/PTX 20A AC power Software Issues
1745299Fans may stop working after removal and insertion of Fan Tray
Product-Group=junosvae
On MX10004/MX10008/MX10016 and Junos-based PTX10004/PTX10008/PTX10016 platforms, some Enhanced fans could not be working after hot-insertion of Fan Tray.
PR NumberSynopsisCategory: "agentd" software daemon
1702250The xmlproxyd process crash is observed in telemetry scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when telemetry services are enabled and the interleaving of telemetry streaming of more than one xmlproxyd sensors can lead to xmlproxyd process crash.
PR NumberSynopsisCategory: PFE issue for flowd on australia SPU
1727027The datapath-debug packet-dump feature is not capturing the transit traffic packets
Product-Group=junos
On SRX5000 platforms with IOC3 card (SRX5K-MPC3-100G10G and SRX5K-MPC3-40G10G), datapath-debug packet-dump will stop capturing the transit traffic packets when datapath-debug packet filters with packet-dump are targeting the traffic on the interface which is configured with firewall filters.
PR NumberSynopsisCategory: dynamic vlan creation and associated processing
1743903If more than 32 vlan ranges are configured under the dynamic-profile then login issue and traffic impact can be seen with subscribers of random VLANs
Product-Group=junos
On all Junos platforms that support subscriber services, when more than 32 VLAN ranges are configured, random VLAN (Virtual Local Area Network) traffic is impacted and subscribers are unable to login.
PR NumberSynopsisCategory: Border Gateway Protocol
1742513When BGP is configured in routing-instance of type virtual-router, default MPLS table is being created for that virtual-router, unexpectedly
Product-Group=junos
On all Junos platform, when BGP is configured in routing-instance of type virtual-router, default MPLS table is being created unexpectedly for VR instance routing table
1745073CPU in rpd spikes and scheduler slips will be observed when the duplicate community is added
Product-Group=junos
On all Junos and Junos Evolved platforms, when Border Gateway Protocol (BGP) is configured with the existing community member added via another community that is called in import policy and the intermediate router does not support large/extended communities based on scale (route). Due to this, the rpd Central Processing Unit (CPU) stays high and protocols level choking will be seen in adjacent nodes. Scheduler slips are also observed due to the same.
PR NumberSynopsisCategory: Class of Service
1760817Change in the cosd behaviour due to the CoS interface specific wildcards
Product-Group=junos
On all Junos platforms, applying the class-of-service (CoS) interface specific wildcards was leading to an inconsistent behaviour of the class-of-service daemon (cosd) at different times.
PR NumberSynopsisCategory: Captive Portal
1736937Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables (CVE-2023-36844)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
PR NumberSynopsisCategory: Device Configuration Daemon
1592071Kernel does not receive IFD change and IFDSPF_AE_MIX_RATE flags when link-speed mixed is configured
Product-Group=junos
In the AE db we have mix_rate_attr and mix_rate_attr_prev to store the current and previous mix_rate params. In the CONFIG_UPDATE phase, while reading the AE attributes the flag "mix_rate_attr -> mix_configured" is set to TRUE. This is done in function parse_ae_parent_ifd(). This flag is set because it doesn't depend on any other attribute. But the mix_rate params are separately read in function parse_mix_rate_parent_ae(). This is done during DEPENDENCY_UPDATE phase. Here after various post processing, mix_rate_attr is copied to mix_rate_attr_prev, and then mix_rate_attr -> mix_configured is set to TRUE. So due to this, mix_configured is set to TRUE in both curr and prev. Due to this during DIFF phase, it is not detecting the difference in this attribute and no CHANGE is triggered on the IFD.
PR NumberSynopsisCategory: Firewall Filter
1749092High CPU utilization of the mib2d process will be observed with error messages due to stale SNMP requests
Product-Group=junos
On all Junos platforms, high CPU utilization, up to 100%, of the mib2d process will be observed with error messages and this may also result in a crash/core when memory gets exhausted due to a gradual increase in stale SNMP (Simple Network Management Protocol) requests.
PR NumberSynopsisCategory: ACX IFL, IFF creation
1691004The PFE process crashes on ACX5448
Product-Group=junos
On Junos ACX5448 platforms, the PFE (Packet Forwarding Engine) process will crash after continuous IFD (Interface Device) flaps. As a result, all traffic will be lost until the process recovers on its own.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1754637Out of range "Near-end loss" percentage or jnxSoamLmCurrentStatsBackwardAvgFlr
Product-Group=junos
On platforms like mx204, in case of near-end loss in SLM, "Near-end loss" percentage in CLI or jnxSoamLmCurrentStatsBackwardAvgFlr in SNMP will show very high, out of range values.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1758677Traffic flooding for MAC addresses programming failure
Product-Group=junos
Issue 1: On QFX5K and EX platforms, traffic flooding will be observed for MAC addresses not getting programmed in hardware in the VXLAN (Virtual Extensible LAN) environment with VPLAG (Virtual Chassis Port Link Aggregation) configured and BGP (Border Gateway Protocol) flaps. This issue happens when hardware write by L2ALM to PFE fails, and during re-sync, SVLBNH (shared VXLAN load balancing next hop) info is not sent to PFE/hardware. Issue 2: On all Junos platforms, l2alm sends a delete request for control MAC addresses to l2ald after multiple hardware sync failures.
PR NumberSynopsisCategory: EX4100 PFE
1738404[QFX5/EX] Error message like 'BRCM-VIRTUAL,brcm_vxlan_port_discard_set(),13034:Failed to set bcm_port_discard_set to 0 for port (61) err(Invalid unit)
Product-Group=junos
You might see the error message like 'BRCM-VIRTUAL,brcm_vxlan_port_discard_set(),13034:Failed to set bcm_port_discard_set to 0 for port (61) err(Invalid unit)' in a Virtual Chassis. The Error is no functional impact.
PR NumberSynopsisCategory: EX4400 PFE software
1701546The BFD session will remain in init/down state in the Virtual Chassis scenario
Product-Group=junos
On Junos EX and QFX Virtual Chassis platforms configured with Bidirectional Forwarding Detection (BFD) over the Aggregate Ethernet (AE) interface, when the BFD control plane traffic is received on the lag member port which is present as non-anchor FPC of the BFD session, the BFD session will be stuck in the Init/down state. Only single-hop BFD sessions will be impacted.
1731522The traffic drop will be observed after changing the VSTP VLAN configuration
Product-Group=junos
On Junos EX4400, EX4100, EX2300, EX3400, and QFX5K platforms, traffic drop would happen on RSTP (Rapid Spanning Tree Protocol) enabled port attached to a VLAN (Virtual Local Area Network) when the same VLAN has VSTP (VLAN Spanning Tree Protocol) enabled on a different port and there is a configuration change done on VSTP for that VLAN.
1757431Whenever IGMP leave request is initiated by receiver unicast traffic to the host IP on the switch port is non-responsive
Product-Group=junos
On Junos EX series and QFX5K platforms, having VC (virtual-chassis) when IGMP (Internet Group Management Protocol) snooping is enabled and when there is an mrouter (multicast router) interface present in a non master VC (virtual-chassis) member, IGMP leave packets are sent back to the source interface which impacts the unicast traffic of the end host.
PR NumberSynopsisCategory: EX POE
1751868POE Log "Thread 22 (PoE Periodic) ran for <> ms without yielding" may be seen
Product-Group=junosvae
In the EX4300-MP platform, POE Log "Thread 22 (PoE Periodic) ran for <> ms without yielding" may be seen may be seen in some cases. Usually, this should not cause any service impact but during the high load; this may lead to BFD or LACP flap.
PR NumberSynopsisCategory: Express PFE Services including JTI, TOE, HostPath, Jflow
1617932Performance of JFlow service might be impacted on PTX Series routers
Product-Group=junos
On Junos PTX Series routers with inline JFlow configured, when fragmented traffic related to different families are sampled in an interleaved fashion (for example, one packet related to IPv4 followed by packet related to IPv6 followed by packet related to IPv4), then logs will get generated. Based on the traffic packets per second rate, the logs generated might bombard the messages file. Other important logs might be lost. This might impact the performance of JFlow service.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1739258The ksyncd process crash would be seen on backup RE
Product-Group=junos
On QFX10008 and QFX10016 platforms with IRB(Integrated Routing and Bridging), EVPN-VxLAN(Ethernet VPN-Virtual Extensible LAN) and enhanced-arp feature enabled, high availability will be impacted as backup RE(Routing Engine) will remain down due to ksyncd (kernel synchronization process) failure. In case of switchover, if backup become the new master, then traffic drop will happen.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1719427The subscribers will be stuck in a terminated state when an FPC is taken offline
Product-Group=junos
On MX platforms, If a Flexible PIC Concentrator (FPC) is taken offline while it has Broadband Edge (BBE) subscribers over it, due to timing issues a few subscribers state on the FPC may not get properly cleaned up and will be stuck in a terminated state. This can adversely affect subsequent subscriber logins which fail with an "orphaned filter" error.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1747289VRRP traffic will drop when the member link from the AE bundle is deleted, even if there are active members in the AE bundle
Product-Group=junos
On Junos using afeb/tfeb way of communication to PFE that is MX80/MX104 platforms with Virtual Router Redundancy Protocol (VRRP) configured, deleting a member link from the Aggregated Ethernet (AE) bundle removes the VRRP filter entry in the Packet Forwarding Engine (PFE) which causes VRRP traffic to get dropped even though other active member links in the AE bundle exists.
PR NumberSynopsisCategory: ISIS routing protocol
1746349Traffic loss observed in SR-LDP stitch scenario when ECMP is enabled on PTX platforms
Product-Group=junos
On PTX platforms, ISIS SR-LDP stitching using mapping server could result in traffic drops on some legs of an ECMP if there are more than 8 ECMP paths and not all paths are via the same neighbor node.
PR NumberSynopsisCategory: jdhcpd daemon
1740822DHCP ALQ no-advertise-routes-on-backup functionality does not work in VRF for Framed-Route.
Product-Group=junos
DHCP ALQ no-advertise-routes-on-backup functionality does not work in VRF for Framed-Route.
PR NumberSynopsisCategory: JFlow bug tracker for SRX platforms
1749830SPC3 PIC crash
Product-Group=junos
SPC3 PIC will crash when the SPU is in dedicated Cp mode "SPU Cp" and Jflow information is queried by vty command. This fix will prevent jflow related queries from vty when the SPC3 SPU is in dedicated CP mode and jflow is initialized on SPU ins this mode.
PR NumberSynopsisCategory: Issues related to Junos Kernel Debug Streaming Daemon (jkdsd
1734718Junos OS: jkdsd crash due to multiple telemetry requests (CVE-2023-44188)
Product-Group=junos
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in telemetry processing of Juniper Networks Junos OS allows a network-based authenticated attacker to flood the system with multiple telemetry requests, causing the Junos Kernel Debugging Streaming Daemon (jkdsd) process to crash, leading to a Denial of Service (DoS). Continued receipt and processing of telemetry requests will repeatedly crash the jkdsd process and sustain the Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA73152 [juniper.net] for more information.
PR NumberSynopsisCategory: jl2tpd daemon
1720994L2TP tunnels may time out if creation of bbe-smgd core dump takes a long time.
Product-Group=junos
In a subscriber-management environment, L2TP tunnels may time out if bbe-smgd crashes with core dump if creation of the core dump takes longer than the effective L2TP timeout.
PR NumberSynopsisCategory: Flow Module
1704623Core dump will be seen when user is changing interface configuration
Product-Group=junos
On SRX platforms with ALG (Application Layer Gateways) configured, frequent interface configuration changes will generate one or more core dumps after the flowd process crashes.
PR NumberSynopsisCategory: Security platform jweb support
1736942Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
PR NumberSynopsisCategory: Layer 2 Control Module
1739975Layer 2 traffic will be dropped on VSTP disabled interface
Product-Group=junos
On Junos platforms, Whenever an interface is disabled under VSTP (VLAN Spanning Tre Protocol) configuration, the issue will be seen in the following cases. 1. When interface, IFBD (Interface Family Bridge Domain) and VSTP, configured via single commit. (In case of new configuration) 2. When VSTP configurations are present and chassisd restarts/device reboots, then issue will be seen. (During ifd delete and add, issue will be seen)
1763053LLDP neighborship will not be formed on all Junos devices
Product-Group=junos
On Junos and Junos OS Evolved platforms, LLDP (Link Layer Discovery protocol) neighborship will not come up on local device if the local device is using Junos version lower than 22.3 (except 21.4R3-S2 and its subsequent service releases) and remote device is using Junos version 21.4R3-S2 and its subsequent service releases or version higher than 22.3.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1724489Help string "Display information for a specified VLAN" is changed to "Display information for a specified bridge domain"
Product-Group=junos
On Junos MX platforms, the help string for CLI command "show mac-vrf forwarding flood ?" vlan-name is changed from "Display information for a specified VLAN" to "Display information for a specified bridge domain"
1743282The l2ald crashes when there is recursive deletion of IFBD or when BGP neighborship is cleared in EVPN-VXLAN multi-homed configuration
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in a rare scenario, due to timing issue, the l2ald (Layer 2 Address Learning Daemon) crashes and traffic is being blackholed due to recursive deletion of IFBD (Interface Family Bridge Domain) or when BGP (Border Gateway Protocol) neighborship is cleared when EVPN (Ethernet Virtual Private Network) - VXLAN (Virtual Extensible Local Area Network) with multi-homed is configured.
PR NumberSynopsisCategory: MX Timing software
1750316SyncE stuck in holdover upon PTP slot switchover without change in PTP phase align state
Product-Group=junos
SyncE stuck in holdover upon PTP slot switchover without change in PTP phase align state.
PR NumberSynopsisCategory: MX104 Software - Chassis Daemon
1747532The PFE crash will be observed when configuring the 'per-unit-scheduler' on the MACSEC MIC interface
Product-Group=junos
On MX104 platform with MACSEC MIC, the 'per-unit-scheduler' configuration on the MACSEC MIC interface results in the PFE crash leading to traffic impact.
PR NumberSynopsisCategory: Kernel MPLS / Tag / P2MP Infrastructure
1723145Routing Engine initiated PING failed over MPLS interface
Product-Group=junos
The RE-generated packets that have MTU size greater than the inet MTU size get dropped when going out on an interface with MPLS chain-composite-next-hop.
PR NumberSynopsisCategory: Express Chip L3 software
1761579The FPC will crash on Junos PTX platforms in a rare timing issue
Product-Group=junos
On Junos PTX platforms with with FPC3, JNP10K-LC1101, JNP10K-LC1102, JNP10K-LC1104, JNP10K-LC1105 and PTX10000, during a rare race condition in hostbound packet handler thread, the FPC (Flexible PIC Concentrator) might crash leading to all the interfaces going down. The exact trigger for this issue is unknown.
PR NumberSynopsisCategory: Express Paradise PFE Sflow
1741461Enabling sflow triggers ddos-protection violation of protocol group resolve
Product-Group=junos
On all Junos based QFX platforms, when sflow is enabled with ECMP, ddos-protection violation of protocol group resolve is triggered. Sampled packets will be dropped and sflow will stop sending packets to the collector. This is a non-service impacting issue, however sflow will be impacted.
PR NumberSynopsisCategory: analyzer on QFX 5100,5200, 5110
1590829[Junos] [Onyx] l3gw_EP:Mirroring is not working when input ingress is vxlan enabled Vlan
Product-Group=junos
When RSPAN is used to mirror the VXLAN enabled BDs with ESI traffic mirror will not work.
PR NumberSynopsisCategory: DHCP related Issues
1711525DHCPv6 packets could not be forwarded if it contains the trailer or extra bytes out of the IP stack
Product-Group=junos
On all Junos QFX5K and EX platforms with DHCPv6 (Dynamic Host Configuration Protocol) relay configuration, IPV6 (Internet Protocol) assignment could not take place as the DHCPv6 solicit packets containing extra bytes in DHCPv6 header trailer are not getting forwarded to the DHCP server.
PR NumberSynopsisCategory: QFX L2 PFE
1702551Multiple DCPFE cores seen on QFX5200 followed with continuous FPC reboot
Product-Group=junos
On all Junos platform, the DCPFE process might core due to heap memory allocation issue. This issue might be seen more frequently when there is a high rate of control packets going to the CPU.
1730076Packets received on a port that is in "LACP Detached" state is getting forwarded
Product-Group=junos
On all Junos EX46xx/QFX5k (except QFX5100) platforms, child links that are in LACP (Link Aggregation Control Protocol) detached state are up and accepting incoming traffic, expecting it to drop.
1741316The traffic drop is observed due to the MAC source address being learned from the wrong direction
Product-Group=junos
On Junos EX4300/QFX5100/QFX5110/QFX5200/QFX5210 platforms with VXLAN (Virtual Extensible Local Area Network) enabled, when the ARP (Address Resolution Protocol) request is sent from the device, the MAC (Media Access Control) address is learned from the wrong direction which results in the traffic drop.
1759875Generate an empty file whose name is secondary_vlan when executing RSI.
Product-Group=junos
After executing "request support infomation | save " command, unexpected file will be generated.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1709664BFD sessions flap on EX and QFX platforms
Product-Group=junos
On all EX and QFX platforms, BFD(Bidirectional Forwarding Detection) sessions are flapped with VLAN configuration change on LAG interface.
1714701Traffic blackhole after reboot
Product-Group=junos
On all Junos platforms, traffic drops observed when RH (Resilient-Hashing) is configured on a LAG (Link Aggregation Group) interface.
1742763Traffic drop will be observed after extended-vni-list configuration change with EVPN-VXLAN scenario
Product-Group=junos
On Junos QFX5100/QFX5110/QFX5120/QFX5200/QFX5210/EX4100/EX4300-MP/EX4400-XX platforms having Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) configured if extended-vni-list configuration is deleted, the network interface is flapped and when extended-vni-list is added back due to this traffic using the Flood NH (BUM) on the device will be lost.
PR NumberSynopsisCategory: QFX MPLS PFE
1731291Traffic for VLAN-id 2 gets dropped in Ethernet-CCC L2 Circuit on QFX5k/EX4650 platforms
Product-Group=junos
On Junos QFX5k and EX4650 platforms traffic drop for VLAN (Virtual Local Area Network) having id 2 will be seen in the Ethernet-CCC (Circuit Cross Connect) L2 circuit. This happens because the VLAN-id is getting stripped at the egress PE (Provider Edge Router) hence causing a traffic drop at the CE (Customer Edge) Router.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1712175The dcpfe process crash is seen on QFX5k platforms due to stale vtep entry
Product-Group=junos
On all QFX5000 platforms, with VXLAN (Virtual Extensible LAN) configured and due to a stale next hop entry of vtep (vxlan tunnel end point) interface, dcpfe (Dense Concentrator Packet Forwarding Engine) process crash was observed.
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1729067Traffic loss will be observed due to CRC errors with QSFP+-40G-ACU10M plugged
Product-Group=junos
On QFX5K platforms with QSFP+-40G-ACU10M and Virtual Chassis configured, traffic loss will be observed due to CRC (Cyclic redundancy check) errors.
1746788[QFX5K]When RSI(request support information) is executed in the VC configuration, some errors output
Product-Group=junos
On QFX5K platform, "request pfe execute ... target fpc" in RSI is always executed on master role in the VC configuration.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1728452[EX/QFX ] debugging command "show aq107 xxx" on VTY may generate an error on 10GBASE-T SFP if AQ index exceeds 48.
Product-Group=junos
This is a debugging VTY command as you may be asked to issue the command by JTAC engineer during Trouble shooting. "show aq107 xxx" command may generate an error on 10GBASE-T SFP Xcvr 0 REV XX 740-083295 XXXXXXXXXXXXXXX 10GBASE-T FPC7(vty)# show aq107 all Index fpc/pic/port phy_addr status duplex speed ================================================================================== 1 7/0/0 0 ON FULL 1G snip0 .... 52 7/0/41 41 ON FULL 1G 53 7/0/10 10 ON FULL 1G FPC7(vty)# show aq107 52 an-status ^ Syntax error at `52'. <<<<<<<<<<<<<<<<<<<< FPC7(vty)#
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1746439Route-distinguisher change leads to the route being present in rpd, but not installed in kernel/PFE
Product-Group=junos
On Junos and Junos Evolved platforms, traffic impact will be observed when route-distinguisher change is performed for which route will be present in rpd, but not installed in kernel/PFE. This issue happens when the aggregate route is configured.
PR NumberSynopsisCategory: Resource Reservation Protocol
1685182RSVP path tear is not encapsulated by the MPLS header when bypass is configured
Product-Group=junos
On all Junos and Junos Evolved platforms, RSVP(Resource Reservation Protocol) path tear is not encapsulated by the MPLS(Multiprotocol Label Switching ) header, when "no-enhanced-frr-bypass" is configured on the routers that undertake FRR(fast re-route) procedures after the failure.
PR NumberSynopsisCategory: SW PRs for SCBE3 chassisd
1667226The hyper-mode might be set incorrectly after power cycle on MX platforms
Product-Group=junos
The hyper-mode can be set incorrectly after power cycle on MX platforms when either BBE and/or MX VC is configured and hyper-mode is not configured.
PR NumberSynopsisCategory: SW PRs for SCBE3 fabric
1724007Complete traffic blackhole from one PFE to another on fabric links after injecting/reporting CRC errors on fabric links of MX10008
Product-Group=junos
On the MX10008 platform, the low-priority stream might be marked as a destination error and as a result, the low-priority stream is stuck and all traffic might get dropped. Complete traffic blackhole is observed from one PFE to another.
PR NumberSynopsisCategory: SRX5XX platform
16209828-Port Gigabit Ethernet SFP XPIM not passing traffic after software upgrade
Product-Group=junos
On SRX550 platform, after doing a software upgrade, 8-Port Gigabit Ethernet SFP XPIM is not passing traffic
PR NumberSynopsisCategory: MX10002 Platform SW - Platform s/w defects
1721714BFD session failed when configured on the loopback sub interface
Product-Group=junos
On the MX10003 and MX304 platforms, BFD (Bidirectional Forward Detection) session failed to come up when configured on the loopback sub interface.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1748971SRX4600 misleading Fan speed syslog output after removing or inserting one Fan tray unit
Product-Group=junos
On SRX4600, misleading Fan speed syslog is generated after removing or inserting one Fan tray unit.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1697404FPC crash will be observed when firewall filter is unconfigured and reconfigured with same index
Product-Group=junos
On Junos platforms with MPC10E/MPC11E/LC-9600 cards, Flexible PIC Concentrators (FPC) crash will be seen when frequent ADD/DELETE operations of filter are performed.
1743930Traffic drop is observed after the addition or removal of the "filter-specific" knob under the policer
Product-Group=junos
On MX platforms with MPC10, MPC11 and JNP10K-LC9600 linecards, when both regular & hierarchical/tricolor policer is configured on the logical interface (ifl), after the addition or removal of "filter-specific" knob under this combination of policer traffic drop is observed.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1737615MPC1 to MPC13E/LC2101,LC2103,LC480/T4000-FPC5/MPC built-in Trio based line card reboots when subscriber management services are configured
Product-Group=junos
When Junos EX, MX, SRX, T platforms with Modular Port Concentrators from MPC1 to MPC13E/LC2101,LC2103,LC480/T4000-FPC5/MPC built-in Trio based line cards are configured with subscriber management services with interface name that exceeds 19 characters, it leads to line card reboot causing service impact.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1659783The configuration might roll back after performing "commit confirmed" and then reboot
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, the configuration might roll back after performing "commit confirmed" and then a reboot.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1740289The 'load replace' operation might result in mustd and mgd crash
Product-Group=junos
On Junos and Junos Evolved platforms with apply-group configured, mustd and mgd crash might be observed when the 'load replace' operation is performed due to which all the apply-groups will get deleted internally, and respective hierarchies will not be notified.
1745565The mgd process crash is observed when 'show' is executed from the configuration mode
Product-Group=junos
On all Junos platforms, when 'show' is executed from the configuration mode, a mgd process crash is observed which has no functionality impact.
PR NumberSynopsisCategory: Junos Fusion Satellite Device Infrastructure
1682680The Junos Fusion Satellite device will be stuck in the SyncWait state
Product-Group=junos
On Junos MX, EX, and QFX platforms, post rebooting the device the Junos Fusion Satellite devices are trying to generate the ssh keys before clearing the old keys. The Satellite devices will not be responsive as they are stuck in the SyncWait state leading to traffic loss.
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1750634Traffic transfer/receive is impacted for SPC3 CPU cores connected to the affected PCIe bus when the SPC3 card boots up
Product-Group=junos
On MX and SRX platforms with SPC3 card, SPC3 (Services Processing Card 3) CPU cores connected to the affected PCIe (Peripheral Component Interconnect) bus (7 CPU cores) getting into a bad state will not transfer any traffic i.e. traffic loss during SPC3 card bootup due to incorrect register settings.
PR NumberSynopsisCategory: usf nat related issues
1692525ALG child session will not be transported through the DS-Lite tunnel which might lead to traffic failures in absence of a direct route to the host
Product-Group=junos
On Junos MX240/MX480/MX960 platform with MX-SPC3, a tunnel ID of the control session is not updated properly on the gate created for Session Initiation Protocol (SIP) Application Layer Gateway (ALG), which is leading to the gate hit session not mapping back to the Dual-Stack Lite (DS-Lite) tunnel. This might result in traffic failure if the client does not have a direct route to the host.
 
 

20.4R3-S9 - List of Known issues 

PR NumberSynopsisCategory: EX4300 PFE
1610408The pfex core might be seen after the device is running for a while
Product-Group=junos
In a Virtual chassis. the pfex core could be seen after the device is running for a while and due to PFE restart, VC may split and drop packets in forwarding plane. There is no specific time frame as well as any trigger.

Resolved In: junos:19.4R3-S6 junos:20.1R3-S2 junos:20.2R3-S3 junos:20.3R3-S1 junos:20.4R3 junos:21.1R3 junos:21.2R2 junos:21.3R1 junos:21.4R1
PR NumberSynopsisCategory: Class of Service
1504287ARP resolution issues are observed when moving an interface out of AE bundle
Product-Group=junos
If you have to take an interface out of AE bundle and configure it to operate in stand-alone mode, then doing this in a single commit may render the operation ineffective and could lead to connectivity issues. There is a known issue around this and this is seen due to a race condition between RE daemons (COSD, DCD/chassisd), PFE and kernel. The below document link speaks of this issue when there is explicit COS configuration to be made on the interface - https://www.juniper.net/documentation/en_US/junos/topics/concept/schedulers-cos-ae-sdh-limits-cos-config-guide.html. However, the problem can be seen without explicit COS too, as there is default COS that is always present. In some cases, it is possible that a single shot commit will send out multiple operational messages down to kernel and might confuse the kernel to do unintended optimization that could lead to a message being consumed at kernel and not being sent to PFE. The result is the same even in this case.

Resolved In:
PR NumberSynopsisCategory: DNX VPLS
1722919Intermittent MAC move is observed in VPLS environment when ACX5448 or ACX710 is acting as a PE device
Product-Group=junos
On Junos ACX5448 and ACX710 platforms acting as a PE (Provider Edge) device in a VPLS (Virtual Private LAN Services) environment and multiple CE (Customer Edge) interfaces are bound to a single routing instance, intermittent MAC move is observed. This is a corner case scenario and the MAC move can be triggered due to various reasons and not limiting to mac address time out, L2 loop on the extended network or a congested backbone link connecting the PE devices. The split horizon rule in VPLS fails and the traffic received from VPLS LSI (Label-Switched Interface) is forwarded back towards the MPLS core through the LSI.

Resolved In: junos:20.4R3-S8 junos:21.3R3-S5 junos:21.4R3-S4 junos:22.1R3-S4 junos:22.2R3-S1 junos:22.3R2-S1 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1718165ARP learning issues are observed post-execution of the CLI command 'clear bridge mac-table' or 'clear ethernet-switching table' in the EVPN-MPLS over IRB environment
Product-Group=junos
On all Junos and Junos Evolved platforms, L3 (Layer 3) traffic will be impacted when ARP (Address Resolution Protocol) entries get deleted for the MAC (Media Access Control) address having a bad state post execution of the CLI 'clear bridge mac-table' or 'clear ethernet-switching table' command in the EVPN-MPLS (Ethernet VPN - Multiprotocol Label Switching) over IRB (Integrated routing and bridging) environment.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:21.2R3-S7 junos:22.2R3-S3 junos:22.3R3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: ISIS routing protocol
1699076The rpd process might crash when SPF is recalculated
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) process can crash due to periodic SPF (Shortest Path first) recalculation when ISIS (Intermediate System to Intermediate System) connected or direct routes get deleted.

Resolved In: evo:21.4R3-S4-EVO evo:22.2R3-S2-EVO evo:22.3R3-EVO evo:22.4R1-S2-EVO evo:22.4R2-S2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:19.2R3-S6-J1 junos:19.2R3-S7 junos:20.4R3-S6-J6 junos:20.4R3-S7 junos:21.2R3-S7 junos:21.4R3-S5 junos:22.2R3-S2 junos:22.3R3 junos:22.4R1-S2 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1707878Mac entry not ageout in RTG in EX4600-VC after VCP port reconnect
Product-Group=junos
EX4600 with Redundant Trunk Group (RTG) configured, after VCP port between members of EX4600 disconnect and connect again. Mac address entry created in RTG cannot ageout.

Resolved In: evo:21.4R3-S4-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:21.4R3-S4 junos:23.4R1 junos:23.4R2
PR NumberSynopsisCategory: lacp protocol
1635935Traffic loss might be seen on QFX10K due to congestion
Product-Group=junos
During congestion on the QFX1000 line of switches, the periodic packet manager (ppman) runs short of resources and fails to send protocol data units (PDUs). Due to ppman queue starvation across TX/RX path, LACP sessions might not get a chance to transmit PDUs. This can further lead to peer LACP timeout, aggregated Ethernet interface flap and traffic loss.

Resolved In: evo:21.2R3-EVO evo:21.3R2-EVO evo:21.4R2-EVO evo:22.1R1-EVO evo:22.2R1-EVO junos:19.1R3-S8 junos:19.3R3-S7 junos:19.4R3-S9 junos:20.2R3-S5 junos:20.3R3-S5 junos:20.3X75-D36 junos:20.4R3-S4 junos:21.1R3-S3 junos:21.2R3 junos:21.3R2 junos:21.4R2 junos:22.1R1 junos:22.2R1
PR NumberSynopsisCategory: MX104 Software - Chassis Daemon
1103870On the MX104 router, if you use snmpbulkget or snmpbulkwalk (for example, used by the SNMP server) on a chassisd-related component (for example, jnxOperatingEntry), high CPU usage and slow response of the chassis process (chassisd) might be observed because of a hardware limitation, which might also lead to a query timeout on the SNMP client. This issue might not be observed while using an SNMP query.
Product-Group=junos
On the MX104 platform, when using snmpbulkget or snmpbulkwalk (for example, used by the SNMP server) on a chassisd-related component (for example, jnxOperatingEntry), chassis process (chassisd) high CPU usage and slow response might be seen because of a hardware limitation, which might also lead to a query timeout on the SNMP client. In addition, the issue might not be seen while using an SNMP query for interface statistics. As a workaround, to avoid the issue, use either of the following approaches: Use snmpget or snmpwalk instead of snmpbulkget or snmpbulkwalk and include the -t 30 option when doing the SNMP query. For example, snmpget -v2c -c XX -t 30. Use the -t 30 option with snmpbulkget or snmpbulkwalk. For example, snmpbulkget -v2c -c XX -t 30.

Resolved In:
1604901Chassisd CPU raise up to 70% when do SNMP walk on mib like jnxOperatingTable on MX104..
Product-Group=junos
When do a snmpwalk on chassisd-related mib (for example: jnxOperatingTable) on MX104, the chassisd cpu may go up to 70%. In MX104 device total number of entries fetched during this walk is about 1000 entries and above. This snmpwalk takes more time to complete the SNMP polling. Due to MX104 available memory & processor we could see chassisd spike during snmpwalk.

Resolved In:
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1495307The ps crash might be seen after executing 'request system snapshot recovery routing-engine both' command
Product-Group=junos
Multiple ps (process status) utility crash might be observed after executing 'request system snapshot recovery routing-engine both' command on platforms running 17.4 or higher releases.

Resolved In: junos:17.4R2-S11 junos:17.4R2-S12 junos:17.4R3-S2 junos:17.4R3-S3 junos:18.1R3-S10 junos:18.1R3-S11 junos:18.2R2-S7 junos:18.2R3-S5 junos:18.2X75-D34 junos:18.2X75-D53 junos:18.2X75-D60 junos:18.2X75-D70 junos:18.3R2-S4 junos:18.3R3-S2 junos:18.3R3-S3 junos:18.4R1-S7 junos:18.4R2-S4 junos:18.4R2-S5 junos:18.4R3-S2 junos:18.4R3-S3 junos:18.4R3-S4 junos:19.1R1-S5 junos:19.1R2-S2 junos:19.1R3-S1 junos:19.1R3-S2 junos:19.2R1-S5 junos:19.2R2 junos:19.2R3 junos:19.3R2-S3 junos:19.3R3 junos:19.4R1-S2 junos:19.4R2 junos:19.4R2-S1 junos:19.4R3 junos:20.1R1-S1 junos:20.1R1-S2 junos:20.1R2 junos:20.2R1 junos:20.2R2 junos:20.3R1 junos:20.3X75-D10
1561463"show system memory" doesn't display all fields.
Product-Group=junos
When running the CLI command "show system memory" you may run into an issue where not all of the fields will be displayed. The command walks the list of all processes and some may have large number of entries for their virtual memory maps which causes the symptom reported in the PR. This limitation is fixed with the fix available starting 21.2 release.

Resolved In:
1667534Memory leak causing crash with vmcore
Product-Group=junos
Memory leak is causing kernel crash and generate vmcore core-dump.

Resolved In: junos:19.1R3-S10 junos:19.2R3-S7 junos:19.3R3-S7 junos:19.4R2-S8 junos:19.4R3-S9 junos:20.2R3-S6 junos:20.3R3-S5 junos:20.3X75-D35 junos:20.3X75-D43 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S4 junos:21.1R3-S4 junos:21.2R3-S2 junos:21.2R3-S3 junos:21.3R3-S2 junos:21.4R3 junos:22.1R1-S2 junos:22.1R2-S1 junos:22.1R3 junos:22.2R2 junos:22.3R1 junos:22.4R1
PR NumberSynopsisCategory: PFE Peer Infra
1747077Error message: 'Minor potential slow peers are: X' seen on Junos based platforms
Product-Group=junos
On all Junos platforms with dual RE, error message: 'Minor potential slow peers are: X' will be seen. Due to some reason the PFE/PIC will be slow and services will face latency issue. the peerbuf list gets full, peer proxy could not enqueue further IPCs (ifstate chain/peer update to backup gets stalled ) causing pfe/pics to be a slow consumer, this impacts service on the device.

Resolved In: junos:22.2R3-S3
PR NumberSynopsisCategory: DHCP related Issues
1711644QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging (CVE-2023-44191)
Product-Group=junos
An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA73155 [juniper.net] for more information.

Resolved In: junos:21.2R3-S5 junos:21.3R3-S5 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R2-S2 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: QFX L2 PFE
1696428Adding more than 256 VLANs as name tags on the same interface results in dcd crash
Product-Group=junos
On all Junos platforms, the dcd (device control daemon) process crash is observed when more than 256 VLANs as name tags are added on the same interface.

Resolved In: junos:21.2R3-S5 junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1688323Traffic loss is observed in IP fabric when there is a change in the underlay network
Product-Group=junos
On Junos QFX5K series, EX4400 platforms, configuration-change/protocol flapping/port flapping in Ethernet Virtual private network (EVPN) Virtual Extensible LAN (VXLAN) can cause traffic loss (changes related to the underlay network).

Resolved In: junos:20.4R3-S7 junos:21.2R3-S5 junos:21.4R3-S4 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R3 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1695183PTX1000 resources exhaustion causing host loopback wedge
Product-Group=junos
Junos PTX1000 platforms will experience resource exhaustion 64 days after the reboot. Due to this the device will drop all the control plane traffic resulting in complete service impact. see https://kb.juniper.net/TSB71154 [juniper.net]

Resolved In: junos:21.4R3-S4 junos:22.2R3-S1 junos:22.4R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: QFX5100 Interface related issues
1665800Ports with SFP-T 1G plugged in may go to hung state on QFX5100 platforms
Product-Group=junos
When the remote end server/system reboots, QFX5100 platform ports with SFP-T 1G inserted may go into a hung state and remain in that state even after the reboot is complete. This may affect traffic after the remote end system comes online and resumes traffic transmission.

Resolved In: junos:20.2R3-S7 junos:20.2R3-S8 junos:20.4R3-S6 junos:20.4R3-S7 junos:21.2R3-S3 junos:21.4R3-S3 junos:21.4R3-S4 junos:22.2R3-S1
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1694522High memory utilization on switch after the code upgrade to 20.4 or later
Product-Group=junos
There is increase in memory footprint across different demons after an image upgrade resulting increase in the system memory.

Resolved In:
PR NumberSynopsisCategory: Inline NAT & 6RD control plane support in SPD
1747483MX204 - INLINE NAT - address-prefix any-ipv4 reporting wrong.
Product-Group=junos
In latest release, its been fixed with address-prefix any-ipv4

Resolved In: junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: PTX1000 platform Issues
1105459misleading syslog message "L2CKT/L2VPN acquiring mastership for primary" though no VPN/L2CKT configured on the router
Product-Group=junos
misleading syslog message "L2CKT/L2VPN acquiring mastership for primary" though no VPN/L2CKT configured on the router

Resolved In:
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1692063PCS errors and framing errors on 100GE interfaces on certain Juniper platforms
Product-Group=junos
On certain Junos platforms having 20.2R1 or later release, with specific PIC (Physical Interface Card)/MIC (Modular Interface Card)/FPC (Flexible PIC Concentrator), PCS (Physical Coding Sublayer) errors and framing errors would be seen on 100GE interfaces with LR4 optics or on its peer device. The framing/CRC (Cyclic Redundancy Check) errors which would be seen when the PCS error rate is high could lead to packet drops hence impacting data services. Enabling FEC (forwarding Error Correction) feature on the impacted interface may reduce the frequency of packet drop.

Resolved In: evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:20.2R3-S2-J6 junos:20.2R3-S3-J8 junos:20.2R3-S5-J3 junos:20.2R3-S5-J4 junos:20.2R3-S7 junos:20.3X75-D46 junos:20.3X75-D46-J2 junos:20.4R3-J10 junos:20.4R3-S2-J22 junos:20.4R3-S4-J11 junos:20.4R3-S4-J6 junos:20.4R3-S5 junos:21.2R3-S2-J20 junos:21.2R3-S3 junos:21.4R1-S2-J1 junos:21.4R2-S1-J2 junos:21.4R2-S1-J5 junos:21.4R3-S2 junos:22.2R2-S1-J2 junos:22.2R3 junos:22.3R2 junos:22.4R1-S2-J1 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1620773SRX4600 - Packet drop or srxpfe coredump might be observed
Product-Group=junos
Packet drop or srxpfe coredump might be observed on SRX 4600 during periods of high traffic

Resolved In: junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.1R1-S1 junos:23.2R1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1738548DHCP offer is dropped at MX and specific EX platforms when an lt interface is used as the transport
Product-Group=junos
On MX and EX92_XX platforms, the DHCP offer will be dropped when LT interface is used to reach the DHCP server. DHCP relay will not work as expected due to this issue.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:20.4R3-S5-J4 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R3-S1 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1562848The mustd process may crash on all platforms
Product-Group=junos
With a large-scale configuration, in rare cases, the mustd may crash. The mustd process, which is responsible for configuration constraint checks, might crash on commit, leading to commit failure.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-S4-J5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S2-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.4R2-S2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO junos:20.3X75-D44 junos:20.3X75-D52 junos:21.2R3-S7 junos:21.2X32-D20 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Xellent Platform issues
1709817Ports with QSA adapter are down
Product-Group=junos
On Junos PTX1000 and PTX10002-60C/QFX10002-60C platforms, ports which use the QSA (QSFP-to-SFP Adapter) may not come up when running software version containing the fix for PR 1620527.

Resolved In: junos:19.4R3-S13 junos:20.3X75-D44 junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S5 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S2 junos:22.2R3 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1732283Junos OS Evolved: PTX10003 Series: MAC address validation bypass vulnerability (CVE-2023-44189)
Product-Group=junos
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router will start forwarding traffic if a valid route is present in forwarding-table, causing a loop and congestion in the downstream layer-2 domain connected to the device.Please refer to https://supportportal.juniper.net/JSA73153 [juniper.net] for more information.

Resolved In: evo:21.4R3-S4-EVO evo:21.4X1-EVO evo:22.1R3-S3-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D35-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1

Modification History

First Publication 2023-11-13