Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX running Junos Evolved Software

Alert Description

Junos Software Service Release version 22.1R3-S5-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as needed and follow the prompts

Solution

Junos Software service Release version 22.1R3-S5-EVO is now available.

22.1R3-S5-EVO - List of Fixed issues 

PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1698373A few BFD sessions might flap after FPC reload and stabilization
Product-Group=evo
On all Junos platforms and Junos Evolved with scaled BFD sessions, FPC reload/restart results in few BFD session flap.
PR NumberSynopsisCategory: Border Gateway Protocol
1754935BGP multipath route is not correctly applied after changing the IGP metric
Product-Group=evo
On all Junos and Junos Evolved platforms, multipath route is not correctly applied due to this Equal-cost multi-path (ECMP) will not be formed, when Border Gateway Protocol (BGP) multipath is configured and the Interior Gateway Protocol (IGP) metric of a network is modified and subsequently reverted.
1760885The BGP LU labels can have next-hops pointing to each other in multi-homed PE setup
Product-Group=evo
On all Junos and Junos Evolved platforms the routes received by two multi-homed PE (Provider Edge) routers in the 'inet-unicast' family are advertised in the BGP (Border Gateway Protocol) LU (Labeled Unicast) family to each other. This issue happens when there is no rib.inet3 configured under the address family labeled unicast which causes the routes from 'inet-unicast' and 'inet-labeled-unicast ' tables to get mixed. There will be a traffic impact when this issue is encountered.
1775548The rpd crash can be seen with a scaled BGP sharding setup
Product-Group=evo
On all Junos and Junos OS Evolved platforms the rpd (Routing Protocol Daemon) crash can be seen in scaled setup. The issue will be seen in the BGP (Border Gateway Protocol) RIB (Routing Information Base) sharding scenario. This issue is very unlikely to be encountered.
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1745528Untagged control traffic on L3 interface will be dropped on Junos OS Evolved based PTX platforms
Product-Group=evo
On all Junos OS Evolved based PTX platforms with physical interface/LAG (Link Aggregation Group) interface in L3 mode, the untagged control traffic on L3 interface gets dropped if lport value of L3 interface matches with lport value of L2 aggregated ethernet (AE) interface in trunk mode.
PR NumberSynopsisCategory: DNX platform MPLS FRR features
1768729Unknown unicast IPv4 Traffic received with UDP destination port 8503 will be flooded back to Source PE
Product-Group=evo
On the Junos Evolved ACX7K platform, the split horizon rule is broken when an IPv4 packet with destination UDP port 8503 is received on the system over the Ethernet VPN (EVPN) /Layer-2 network. This will result in the traffic being sent /flooded to the source PE router. The below filter can be seen incrementing during the issue. pfe> show evo-pfemand filter counters filter-name __BfdLspMplsSelfPingTrap_unit0__ Counter-Name Packets BytesBfdLspMplsSelfPingTrap_unit0-rule 125016 99578126
PR NumberSynopsisCategory: ACX VxLAN Issue
1690815Junos OS Evolved: ACX7024, ACX7100-32C and ACX7100-48L: Traffic stops when a specific IPv4 UDP packet is received by the RE (CVE-2024-21602)
Product-Group=evo
A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75743 [juniper.net] for more information.
PR NumberSynopsisCategory: EVO Class of Services
1766873Duplicate code points through code-point-aliases under a classifier results in cosd crash
Product-Group=evo
On all Junos Evolved platforms, the class-of-service (COS) commit validation is missing for classifier when using code-point-aliases. Configuring duplicate code-point-aliases and using them in a classifier will result in the cosd crash. The system can be recovered by correcting the config and applying the "restart class-of-service" command.
PR NumberSynopsisCategory: Issues related to EVO dependency layer including object graphs, incompletes, anomalies and nkdb
1777613[EVO] master-only IP address is missing on mgmt-0 interface after the master RE abnormal shutdown
Product-Group=evo
[EVO] master-only IP address is missing on mgmt-0 interface after the master Routing-Engineering abnormally shutdown, which causes the router is not accessible via mgmt-0.
PR NumberSynopsisCategory: software upgrade infra issues
1776669orchestratord core dump during JSU
Product-Group=evo
If the customer setup has more than 10 nodes (including REs and FPCs), then orchestratord core dump might be seen during JSU upgrade.
1779593[Junos OS Evolved] Committed configuration files are not preserved post software version rollback operation
Product-Group=evo
On all Junos OS Evolved platforms, committed configuration files are not preserved post software version rollback operation. The actual configuration is not affected.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1749191Some of the MAC addresses are not learned in EVPN-VXLAN scenario
Product-Group=evo
On all Junos and Junos Evolved platforms configured with EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible Local Area Network) when network events such as interface flap/BFD (Bidirectional Forwarding Detection) flap etc. leads to overlay BGP (Border Gateway Protocol) / EVPN flap and results in VTEPs (VXLAN Tunnel Endpoint), IFLs (Logical Interface), IFFs (Interface Family) and IFBDs (Interface Family Bridge Domain) corresponding to remote MH (Multi Home) peers to be deleted and causes new ones to be recreated, it is observed that even though MAC address is received it is not being programmed which results in missing entries of MAC addresses in the MAC table.
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1745190Junos OS Evolved: IPython privilege escalation vulnerability (CVE-2022-21699)
Product-Group=evo
IPython, shipped with Juniper Networks Junos OS Evolved, is subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same system. Please refer to https://supportportal.juniper.net/JSA75721 [juniper.net] for more information.
PR NumberSynopsisCategory: EVPN control plane issues
1673157The rpd crash would be observed when activating or deactivating the EVPN routing-instances
Product-Group=evo
On all Junos Evolved platforms with Ethernet VPN (EVPN) enabled, when EVPN or other routing-instances are activated or deactivated, the rpd crash will be triggered. It will impact the traffic and it is a very rare case.
1718534L2ALD core at l2ald_vxlan_ifl_create_msg_build
Product-Group=evo
During network churn(or during provision- when RVTEP are being discovered/created, network events), it is possible to l2ald cores @ l2ald_vxlan_ifl_create_msg_build.
1761852The rpd can crash on all Junos platforms in Seamless DCI scenario
Product-Group=evo
On all Junos platforms, a crash can be seen for the rpd (routing process daemon) in EVPN (Ethernet Virtual Private Network) seamless DCI (Data Center Interconnect) scenario when the 'evpn interconnect' and the BD (Bridge Domain) configuration are deleted in the same commit. There will be traffic loss when the rpd crashes but the system will self-recover.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1700196Traffic drop would be observed due to the VTEP tunnels not being established in the EVPN-VxLAN scenario
Product-Group=evo
On Junos and Junos Evolved QFX platforms, in the Ethernet Virtual Private Network-Virtual extensible LAN (EVPN-VxLAN) scenario Virtual Tunnel End Point (VTEP) tunnels are not established due to the timing of events and show up as next-hop set to zero which causes the traffic loss. It is a rare case and this issue will be observed in a scaling scenario or multiple mac-vrf routing-instances.
1718165ARP learning issues are observed post-execution of the CLI command 'clear bridge mac-table' or 'clear ethernet-switching table' in the EVPN-MPLS over IRB environment
Product-Group=evo
On all Junos and Junos Evolved platforms, L3 (Layer 3) traffic will be impacted when ARP (Address Resolution Protocol) entries get deleted for the MAC (Media Access Control) address having a bad state post execution of the CLI 'clear bridge mac-table' or 'clear ethernet-switching table' command in the EVPN-MPLS (Ethernet VPN - Multiprotocol Label Switching) over IRB (Integrated routing and bridging) environment.
1758677MAC addresses programming failure resulting in traffic flooding
Product-Group=evo
Issue 1: On QFX5K and EX platforms in the VXLAN (Virtual Extensible LAN) environment, traffic flooding will be observed for MAC addresses not getting programmed in the hardware with VPLAG (Virtual Chassis Port Link Aggregation) configured and BGP (Border Gateway Protocol) flaps. This issue happens when hardware programming by L2ALM to PFE fails, and during re-sync, SVLBNH (shared VXLAN load balancing next hop) info is not sent to PFE/hardware. Issue 2: On all Junos and Junos Evolved platforms, l2alm sends a delete request for control MAC addresses to l2ald after multiple hardware sync failures.
1773734Traffic flooding is observed due to MAC-IP deletion by l2alm in the EVPN-VXLAN / EVPN-MPLS environment
Product-Group=evo
On Junos and Junos Evolved platforms, in the EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) / EVPN-MPLS (Ethernet VPN-Multiprotocol Label Switching) environment when l2alm (Layer 2 Address Learning Manager) deletes the MAC-IP (Media Access Control - Internet Protocol Address) entry but doesn't re-add the MAC-IP entry right away leads to traffic flooding i.e. might result in congestion, packet looping, and packet drops.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1707878Mac entry not ageout in RTG in EX4600-VC after VCP port reconnect
Product-Group=evo
EX4600 with Redundant Trunk Group (RTG) configured, after VCP port between members of EX4600 disconnect and connect again. Mac address entry created in RTG cannot ageout.
PR NumberSynopsisCategory: lacp protocol
1773702MC-LAG will not work as expected on all platforms
Product-Group=evo
On all Junos and Junos OS Evolved platforms, due to mis-wiring or unexpected design in MC-LAG topology, when all the Multi-Chassis Link Aggregation (MC-LAG) nodes including Customer Edge (CE) devices are rebooted at once, MC-LAG will not work as expected.
PR NumberSynopsisCategory: Interface PR for LC1202 LC
1768453PCS errors on Ethernet interface on certain PTX platforms running Junos Evolved
Product-Group=evo
On certain PTX10001-36MR and PTX10K4/8/16 with LC1201/LC1202 platforms running Junos Evolved 21.2R1-S1, 21.2R2, 21.3R1 or later releases, PCS (Physical Coding Sublayer) errors and framing errors would be seen on 10/100GE interfaces and the high rate of PCS error could lead to interface flap.
PR NumberSynopsisCategory: Multicast Routing
1769782The rpd crash is observed when mvpn-mode is configured as "rpt-spt" and multicast snooping is enabled
Product-Group=evo
On Junos OS Evolved platforms, when mvpn-mode (Multicast Virtual Private Network) is configured as "rpt-spt" (Rendezvous-point tree - Shortest-path tree) and multicast snooping is enabled, the rpd crash is observed. The issue happens when the routing process tries to obtain the source address on processing the multicast <*, g> route.
1777774The rpd process crash is observed when MVPN PE receives PIM join messages from the remote peers
Product-Group=evo
On all Junos Evolved platforms, when MVPN (Multicast Virtual Private Network) configured device receives PIM join or IGMP report from the remote peer installs route in next-hop and not in multicast composite next-hop, causing the rpd process to crash.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1774975Features utilizing inactive routes will not work properly after the device reboot
Product-Group=evo
On all Junos and Junos OS Evolved platforms, due to some software issue, after the device reboot features utilizing inactive routes in the routing table will not work properly. This will cause issues like some inactive routes not being advertised when selected as the best path, features like advertise-inactive not working properly as it utilizes an inactive route flash, high Routing Protocol Daemon (rpd) Central Processing Unit (CPU) utilization, etc.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1716431Memory leak will be observed in rpd after performing restart routing
Product-Group=evo
On all Junos OS and Junos OS Evolved platforms with rib-sharding enabled, memory leak will be observed in rpd when restart routing is performed. If system is up from long time and restart routing performed multiple times can exhaust system memory that causes to process crash or configuration are not effective/applied because of lack of memory then it is possible that it will impact traffic.
PR NumberSynopsisCategory: RPD API infrastructure
1710274Next Hop counts are not as expected
Product-Group=evo
Next Hop counts are not as expected
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1763406LDP traffic to destination route might be lost when TI-LFA is configured
Product-Group=evo
On all Junos and Junos OS Evolved platforms, when LDP tunnel over SR-TE route or over RSVP and LFA/rLFA/TI-LFA backup path for the same destination is configured, or if rLFA/LFA with L-ISIS as backup path is configured, the route to the destination is missing. LDP route for the destination is deleted because SR-TE LSP next hop is deleted by processing L-ISIS route with the backup path. Due to this LDP route gets deleted, LDP traffic to destination route is lost.
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1764457Traffic drop observed at the source pfe when the destination line card has fabric link error
Product-Group=evo
On all Junos and Junos Evolved platforms, when data traffic is sourced from line cards like MPC1-9 and there is a link error at the destination PFE (Packet Forwarding Engine) end, traffic is dropped at the source PFE end.
PR NumberSynopsisCategory: Stout cards (MPC8, MPC9) fabric issues
1747893MX2k Platform: frequent fabric plane Check state reported due to remote destination timeouts
Product-Group=evo
Upon some crc errors on fabric links, fabric destination timeouts are reported more frequent. Once there is a fabric request timeout, the system will attempt auto recovery. Since the periodic detection logic ran twice for 500msec period and 60msec period, it reported fabric destination timeout too aggressive. The additional 60msec period is targeted to detect a condition if user removed SFB board ungracefully. This exposure is specific to MX2K Platforms only
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1768610FPC offline causes PTX10003-160C to reboot
Product-Group=evo
On PTX10003-160C platforms, an FPC (Flexible PIC Concentrator) offline via the command "request chassis fpc slot offline" triggers the evo-aftmand process crash as the FPC goes offline. This causes a system reboot. Services will be resumed normally after reboot.
 
 

22.1R3-S5-EVO - List of Known issues 

PR NumberSynopsisCategory: EVO L3 routing for BCM XGS Platforms
1771209PFE crash seen on Junos OS Evolved platforms due to upstream interface change
Product-Group=evo
On all Junos OS Evolved platforms, PFE (Packet Forwarding Engine) process crashes when the upstream interface for a multicast route changes from L3 (Layer 3) interface to another L3 interface or from L3 to an IRB (Integrated Routing and Bridging) interface. This can happen when the RPF (Reverse Path Forwarding) to the source changed due to an interface going down in the upstream path. A complete loss of traffic is observed till the PFE process restarts post the crash.

Resolved In: evo:22.2R3-S2-J5-EVO evo:22.2R3-S3-EVO evo:22.3R3-S2-EVO evo:22.4R3-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: VPWS, L2 CKT, EVPN-VPWS
1775809In the scaled L2circuit configured with L2circuit redundancy configuration traffic drops may be observed
Product-Group=evo
On Junos OS Evolved ACX platforms, in the scaled L2circuit (Layer 2 Circuit) configured (200+ L2circuits) with L2circuit redundancy configuration traffic drops may be observed on a few instances only when deactivating/activating IGP (Interior Gateway Protocol) protocol or restart routing.

Resolved In: evo:22.4R3-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1752374Subsequent commits hang will be seen, when transfer-on-commit fails
Product-Group=evo
On all Junos Evolved platforms, When transfer-on-commit is configured and it fails as the destination is unreachable or invalid, commit lock taken by automatic rollback commit is not released. Due to this, subsequent commits result in a hung state.

Resolved In: evo:21.2R3-S7-EVO evo:21.4R3-S6-EVO evo:22.2R3-S3-EVO evo:22.4R3-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:20.4R3-S10 junos:21.2R3-S7 junos:21.2X32-D20 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: SNMP, mib2d issues
175950622.2R2-S2.6-EVO : Incorrect IF-MIB:: ifLastChange Value Polled
Product-Group=evo
Fix - ifLastChange - This takes the system uptime value (show system uptime command output) meaning it takes the time when the interface came up and became operational. Earlier due to the bug - Initially during ifLastChange polling, it was incorrectly reading system up time. Now after fix it will read correct sysUpTime (show system uptime) whenever there is a change in the interface state. This issue was corrected post code changes and now after interface comes up it will populate proper values for ifLastChange.

Resolved In: evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3X80-D36-EVO evo:22.3X80-D42-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.4R2-EVO
PR NumberSynopsisCategory: SW PRs for MPC10E PMB
1731258MPC10 and MPC11 line cards experiencing unexpected reboots
Product-Group=evo
Line cards such as MPC10 and MPC11 experience unexpected reboots because of CPU C-states which are enabled by default thus impacting the customer production traffic.

Resolved In: evo:24.1R1-EVO junos:22.4R3 junos:22.4R3-S1 junos:24.1R1
PR NumberSynopsisCategory: For multicast snooping on MX
1710565In a scaled setup mcsnoopd is taking high CPU causing traffic drop
Product-Group=evo
On all Junos and Junos Evolved platforms, whenever a commit is done, that involves mcsnoopd daemon config parsing such as (VLAN creation/deletion, interface add/delete to VLAN, interface enable/disable, IGMP (Internet Group Management Protocol) snooping/MLD (Multicast Listener Discovery) snooping related config commands) mcsnoopd will consume CPU. In less scaled setup (few IGMP snooping enabled VLANs and few hundred IGMP snooping memberships), the CPU time taken is less. In a more scaled setup (many IGMP snooping-enabled VLANs and a few thousand IGMP snooping memberships), the CPU may reach >90%. Since mcsnoopd is taking high CPU, it may affect other daemons like rpd. It may affect all the protocols if the CPU is not available to the protocols/daemons. This can impact route entries expiring and cause traffic drop.

Resolved In: junos:24.1R1
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1734549Syslog messages modification for SNMPv3 authentication failure
Product-Group=evo
On all Junos and Junos Evolved platforms, a cosmetic change was made to an existing syslog message to print more information. The syslog error message that is logged when a user with wrong auth/privacy password sends a SNMP v3 request to router has been changed to add more information. From: LIBJSNMP_NS_LOG_WARNING: WARNING: Authentication failed for To: LIBJSNMP_NS_LOG_WARNING: WARNING: Authentication failed for , SNMPv3 query from to 

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1774127Memory leak for deactivation/activation of SCU
Product-Group=evo
On MX platforms with MPC10, MPC11, LC9600, and MX304-LMIC16, the heap memory leaks every time the SCU (source-class-usage) policy is removed i.e. removed and re-applied resulting in restart of the line card. Heap leak is proportional to the number of source classes or indices being removed by related policy.

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO junos:20.4R3-S10 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-J9 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1718063After deleting commit scripts with transient changes, the changes do not take effect
Product-Group=evo
On Junos OS Evolved ACX7100-32C / ACX7100-48L / ACX7509 / PTX10001-36MR / PTX10003 / PTX10004 / PTX10008 / PTX10016 platforms, when a commit script with transient configurations is deleted, daemon does not see the change after commit.

Resolved In: evo:21.2R3-S7-EVO evo:22.2R3-S3-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.2R3-S7 junos:22.1R3-S5 junos:22.2R3-S3 junos:23.2R1 junos:23.3R1

 

Modification History

First publication 2024-01-26