Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX running Junos Evolved software

Alert Description


Junos Software Service Release version 21.2R3-S7-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.2R3-S7-EVO is now available.

21.2R3-S7-EVO - List of Fixed issues 

PR NumberSynopsisCategory: "agentd" software daemon
1600974ifmand, firewalld, mgd-api not working after upgrade from 20.3R2.14 -- -> 20.4R2.14
Product-Group=evo
Configuring IP address which does not belongs to any interface under "system services extension-service request-response grpc clear-text address" can cause ifmand, firewalld, mgd-api to become unresponsive.
PR NumberSynopsisCategory: Border Gateway Protocol
1709837Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=evo
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.
1732493The rpd process crash will be observed with BMP and independent resolution is enabled for secondary BGP routes
Product-Group=evo
On all Junos and Junos OS Evolved platforms, when BMP (BGP Monitoring Protocol) post-policy and independent resolution is enabled for secondary (route leaked through rib-group) BGP routes, then with the inactive secondary route change the rpd process crash will be observed.
1742513When BGP is configured in routing-instance of type virtual-router, default MPLS table is being created for that virtual-router, unexpectedly
Product-Group=evo
On all Junos platform, when BGP is configured in routing-instance of type virtual-router, default MPLS table is being created unexpectedly for VR instance routing table
1775548The rpd crash can be seen with a scaled BGP sharding setup
Product-Group=evo
On all Junos and Junos OS Evolved platforms the rpd (Routing Protocol Daemon) crash can be seen in scaled setup. The issue will be seen in the BGP (Border Gateway Protocol) RIB (Routing Information Base) sharding scenario. This issue is very unlikely to be encountered.
PR NumberSynopsisCategory: Issues related to EVO dependency layer including object graphs, incompletes, anomalies and nkdb
1777613Lost connectivity to management IP address after abnormal Routing Engine (RE) shuts down, and new Master RE won't own the IP either.
Product-Group=evo
Master-only IP address is missing on mgmt-0 interface after the master Routing-Engine abnormally shuts down, which causes the router not be accessible remotely via mgmt-0 IP address.
PR NumberSynopsisCategory: OFP related issues
1714333Junos OS Evolved: Specific TCP traffic causes OFP core and restart of RE (CVE-2024-21612)
Product-Group=evo
An Improper Handling of Syntactically Invalid Structure vulnerability in Object Flooding Protocol (OFP) service of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75753 [juniper.net] for more information.
PR NumberSynopsisCategory: software upgrade infra issues
1731877Auto-sw-sync doesn't trigger upgrade/restart of routing engine
Product-Group=evo
On Junos Evolved PTX10008 and PTX10016 platforms, on releases after 21.2R1-EVO, on enabling auto-sw-sync with no user groups configuration, routing engine 1 (RE1) after joining the cluster, can not sync the versions present in master RE0.
PR NumberSynopsisCategory: PRs related to tunnels like GRE, IPIP in EVO control plane
1717782Traffic loss is observed with FTI over IRB as underlay.
Product-Group=evo
In case of FTI (Flexible Tunnel Interface) over IRB (Integrated Routing and Bridging) over ethernet, underlay ifl (logical interface) was pointing to IRB instead of ethernet interface leading to packet loss.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1752374Subsequent commits hang will be seen, when transfer-on-commit fails
Product-Group=evo
On all Junos Evolved platforms, When transfer-on-commit is configured and it fails as the destination is unreachable or invalid, commit lock taken by automatic rollback commit is not released. Due to this, subsequent commits result in a hung state.
PR NumberSynopsisCategory: EVPN control plane issues
1747706Intermittent packet loss can be observed in evpn-vpws local switching scenario
Product-Group=evo
When evpn-vpws local switching is configured, RPD is setting the user flags on the ccc ucast next hop, which is being interpreted as MPLS_OAM_FILTER and leading to traffic dropThe packet loss is random, the pattern is still to be analyzedThe issue can be seen regardless of control word and vlan configuration on the instance and interfaces
1767914Migrating from L2 Circuit to EVPN results in rpd crash
Product-Group=evo
On Junos and Junos Evolved platforms, when migration from Layer 2 Circuit to EVPN (Ethernet Virtual Private Network) is performed in a single commit, segmentation fault and rpd (Routing Protocol Process) crash will be observed resulting in traffic loss.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1758677MAC addresses programming failure resulting in traffic flooding
Product-Group=evo
Issue 1: On QFX5K and EX platforms in the VXLAN (Virtual Extensible LAN) environment, traffic flooding will be observed for MAC addresses not getting programmed in the hardware with VPLAG (Virtual Chassis Port Link Aggregation) configured and BGP (Border Gateway Protocol) flaps. This issue happens when hardware programming by L2ALM to PFE fails, and during re-sync, SVLBNH (shared VXLAN load balancing next hop) info is not sent to PFE/hardware. Issue 2: On all Junos and Junos Evolved platforms, l2alm sends a delete request for control MAC addresses to l2ald after multiple hardware sync failures.
PR NumberSynopsisCategory: ISIS routing protocol
1753003The rpd crashes on all Junos and Junos Evolved platforms with IS-IS, segment routing and flex algo configured
Product-Group=evo
On all Junos and Junos Evolved platforms, with IS-IS, segment routing and flex algorithm enabled, when the route from ribgroup is deleted due to interface flap, it leads to crash of the infra module as route entry table does not match with the rtbit table (which is passed from IS-IS).
PR NumberSynopsisCategory: jdhcpd daemon
1727624ALQ for DHCPv6 relay agent will not work on MX104 platforms
Product-Group=evo
On MX104 platforms, when ALQ (Active-Lease Query) enabled with DHCPv6 (Dynamic Host Configuration Protocol ) relay agent configuration, ALQ syncing for DHCPv6 TCP (Transmission Control Protocol) connection will not work due to issues while processing the ALQ messages and TCP handshake messages at peer.
PR NumberSynopsisCategory: Layer 2 Control Module
1763053LLDP neighborship will not be formed on all Junos devices
Product-Group=evo
On Junos and Junos OS Evolved platforms, LLDP (Link Layer Discovery protocol) neighborship will not come up on local device if the local device is using Junos version lower than 22.3 and remote device is using Junos version 21.4R3-S2 and its subsequent service releases or version higher than 22.3.
PR NumberSynopsisCategory: Multicast Routing
1663271Multicast upstream interface does not change to back up link when PIM neighbor is removed or flapped and causes a traffic impact
Product-Group=evo
On all Junos and Junos Evolved platforms, upstream interface of multicast routes points to old active RPF (Reverse Path Forwarding) instead of new active RPF even though old active interface is not available when PIM (Protocol Independent Multicast)/ multicast neighbor is removed/flapped. This issue impacts forwarding plane and causes a traffic loss as multicast route in the rpd (Routing Protocol Daemon) and PFE (Packet Forwarding Engine) goes out of sync. This issue is observed because multicast route is not updated due to MBB (Make Before Break).
PR NumberSynopsisCategory: Protocol Independant Multicast
1675212High CPU utilization is seen when chassisd is down during dynamic IFL creation
Product-Group=evo
On all Junos platforms, in a very rare cases, while creating the specific dynamic IFls (PE-PIM (Protocol Independent Multicast) Encapsulation or PD-PIM Decapsulation), if the chassisd is down, the stuck entries in the Kernel Routing table (KRT) queue results in a high CPU utilization. The high CPU might hamper the rpd process functionality in rare cases and also device responsiveness will be slow.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1752133System reboot or IPSEC restart causes routes with incorrect next hop interface to be installed in the routing table
Product-Group=evo
Any flap in the IPSEC (Internet Protocol Security) services or a system reboot causes interfaces in other VRFs (Virtual routing and forwarding) to get associated with the routes in a given VRF, in a topology where routes and next hops prefixes are identical across VRFs. This causes traffic loss and impacts user connectivity in IPSEC VPN scenario.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1656565Commit and commit check fails when the knob "interface-range" is configured
Product-Group=evo
On all Junos and Junos Evolved platforms, when the knob "interface-range" is configured commit and commit check fails.
1718063After deleting commit scripts with transient changes, the changes do not take effect
Product-Group=evo
On Junos OS Evolved ACX7100-32C / ACX7100-48L / ACX7509 / PTX10001-36MR / PTX10003 / PTX10004 / PTX10008 / PTX10016 platforms, when a commit script with transient configurations is deleted, daemon does not see the change after commit.
1772201unexpected commit error - error: VLAN-ID must be specified on tagged ethernet interfaces
Product-Group=evo
unexpected commit error like 'error: VLAN-ID must be specified on tagged ethernet interfaces', due to 'commit check' reset internal flag incorrectly after load overide configuration in rare condition.
 
 

21.2R3-S7-EVO - List of Known issues 

PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1698373A few BFD sessions might flap after FPC reload and stabilization
Product-Group=evo
On all Junos platforms and Junos Evolved with scaled BFD sessions, FPC reload/restart results in few BFD session flap.

Resolved In: evo:20.4R3-S10-EVO evo:21.4R3-S6-EVO evo:22.1R3-S5-EVO evo:22.4R3-EVO junos:20.3X75-D44 junos:20.4R3-S10 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R1 junos:23.4R2
PR NumberSynopsisCategory: Border Gateway Protocol
1742287Junos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crash (CVE-2024-21585)
Product-Group=evo
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA75723 [juniper.net] for more information.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3R3-S1-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R2-S2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:19.1R3-S11 junos:19.2R3-S8 junos:19.3R3-S9 junos:19.4R3-S13 junos:20.2R3-S9 junos:20.4R3-S9 junos:21.2R3-S5-J13 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S2-J2 junos:22.2R3-S3 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: EVO L3 routing for BCM XGS Platforms
1771209PFE crash seen on Junos OS Evolved platforms due to upstream interface change
Product-Group=evo
On all Junos OS Evolved platforms, PFE (Packet Forwarding Engine) process crashes when the upstream interface for a multicast route changes from L3 (Layer 3) interface to another L3 interface or from L3 to an IRB (Integrated Routing and Bridging) interface. This can happen when the RPF (Reverse Path Forwarding) to the source changed due to an interface going down in the upstream path. A complete loss of traffic is observed till the PFE process restarts post the crash.

Resolved In: evo:22.2R3-S2-J5-EVO evo:22.2R3-S3-EVO evo:22.3R3-S2-EVO evo:22.4R3-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: Express BT PFE L3 Features
1764775Transit traffic loss during P2MP LSP change
Product-Group=evo
On all Junos Evolved PTX platforms, when Point-to-Multipoint (P2MP) sub-lsps are pruned/grafted, traffic will get dropped on different P2MP LSP(label-switched-path) tunnels.

Resolved In: evo:21.4R3-S4-J5-EVO evo:21.4R3-S6-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO
1770859MPLS traffic flow might not be as expected after PFE restart
Product-Group=evo
On specific platforms, PTX10001-36MR and PTX10004/PTX10008/PTX10016 with LC1201/LC1202, once PFE gets restarted with "request chassis fpc slot pfe-instance restart" via cli command or automatically with the cmerror configuration, mpls transit traffic will not be forwarded since mpls labels are not re-installed into PFE.

Resolved In: evo:22.2R3-S3-EVO evo:22.3X50-EVO evo:23.2R2-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: DNX L2 related features
1782190Traffic disruption is seen when IRB is present within ERPS protected bridge domain
Product-Group=evo
On Junos Evolved ACX7K platforms, whenever ARP (Address Resolution Protocol) refresh takes place, ARP packet will flood on both blocked (backup path) and unblocked (working path) ports in a ring node. ARP packet is being allowed in the block port, causing traffic disruption.

Resolved In: evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: VPWS, L2 CKT, EVPN-VPWS
1775809In the scaled L2circuit configured with L2circuit redundancy configuration traffic drops may be observed
Product-Group=evo
On Junos OS Evolved ACX platforms, in the scaled L2circuit (Layer 2 Circuit) configured (200+ L2circuits) with L2circuit redundancy configuration traffic drops may be observed on a few instances only when deactivating/activating IGP (Interior Gateway Protocol) protocol or restart routing.

Resolved In: evo:22.4R3-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: Application controller related issues
1629823anomalies/leaks might be seen for some of the DDX objects upon switchover
Product-Group=evo
anomalies/leaks might be seen for some of the DDX objects upon switchover.

Resolved In: evo:21.4R3-S6-EVO evo:22.1R1-EVO
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1737938On QFX Series platforms running Junos OS Evolved that support EVPN, on which EVPN feature support was introduced with MAC-VRF EVPN instances, you configure EVPN-VXLAN features using MAC-VRF instances only
Product-Group=evo
On QFX Series platforms running Junos OS Evolved that support EVPN, on which EVPN feature support was introduced with MAC-VRF EVPN instances, you configure EVPN-VXLAN features using MAC-VRF instances only

Resolved In: evo:21.4R3-S7-EVO evo:22.2R3-S3-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1562848The mustd process may crash on all platforms
Product-Group=evo
With a large-scale configuration, in rare cases, the mustd process might crash. The mustd process, which is responsible for configuration constraint checks, might crash on commit, leading to commit failure.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-S4-J5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S2-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.4R2-S2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO junos:20.3X75-D44 junos:20.3X75-D52 junos:21.2R3-S7 junos:21.2X32-D20 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1740289The 'load replace' operation might result in mustd and mgd crash
Product-Group=evo
On Junos and Junos Evolved platforms with 'apply-group' configured, the mustd and mgd processes might crash when the 'load replace' operation is performed. When this happens, 'apply-groups' will get deleted internally and the respective hierarchies will not be notified.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-S4-J5-EVO evo:21.4R3-S5-EVO evo:21.4X1-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.3X80-D40-EVO evo:22.4R3-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:20.3X75-D36 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S7 junos:21.2X32-D20 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.2R1-S1 junos:23.2R1-S2 junos:23.2R2 junos:23.3R1 junos:23.4R1

 

Modification History

First publication 2024-03-01