Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 21.4R3-S7 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.4R3-S7 is now available.

21.4R3-S7 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 PFE
1737587DDOS log messages will be observed when high traffic is seen
Product-Group=junos
The issue is observed on EX4300-24T/EX4300-24P/EX4300-48T/EX4300-48P/EX4300-MP/EX4300-VC platforms when high traffic is seen. There will be no service impact.When this issue occurs, the following log messages can be seen-c17-44 jddosd[9001]: DDOS_PROTOCOL_VIOLATION_SET: Warning: Host-bound traffic for protocol/exception Virtual-Chassis:aggregate exceeded its allowed bandwidth at fpc 0 for 184 times, PDTc17-44 jddosd[9001]: DDOS_PROTOCOL_VIOLATION_CLEAR: INFO: Host-bound traffic for protocol/exception Virtual-Chassis:aggregate has returned to normal. Its allowed bandwith was exceeded at fpc 0 for 184 times.
PR NumberSynopsisCategory: EX4300 Platform
1779410The pfex process crash is observed when PIC is removed
Product-Group=junos
On EX4300 or EX4300-VC, removal of a Physical Interface Card (PIC), or if the software fails to detect a PIC that is installed, it can cause a crash in the pfex process. This crash can lead to high CPU usage and potentially disrupt network traffic.
PR NumberSynopsisCategory: EX4300 Layer 2 implementation
1797422DHCP IP assignment will fail on VoIP phone connected to a VXLAN access port
Product-Group=junos
On EX4300-48MP platform, in Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, Dynamic Host Configuration Protocol (DHCP) IP assignment for a Voice over IP (VoIP) phone connected to a VXLAN enabled access port will not work.
PR NumberSynopsisCategory: EX2300/3400 platform
1781317Error is shown on system when pvidb variable is accessed
Product-Group=junos
On Junos EX platforms, when pvidb variable which is unkown is tried to access from a device, pvidb error messages will be seen, There is no impact on service due to this.
1789272Watchdog SPI transaction is causing the interface flap in the system
Product-Group=junos
On EX2300-MP platforms, when the SPI (Serial Peripheral Interface) bus is accessed by multiple processes simultaneously results in watchdog reset due to the lack of lock-unlock operations. Consequently, this can lead to interface flaps affecting the traffic flow.
PR NumberSynopsisCategory: QFX Control Plane Analyzer related
1705015Port-mirroring state remains down on Junos QFX5K platforms
Product-Group=junos
For the QFX5K series, while applying the ERSPAN configuration along with the ERSPAN output/egress INET interface configuration sometimes leads to the analyzer not getting created in the HW.
PR NumberSynopsisCategory: ChassisD changes specific for ACX series
1794939Port goes down after adding interface configuration and changing the port from 1g copper to 10g fiber
Product-Group=junos
On all Junos platforms, port goes down after unplugging the 1g copper and plugging 10g fiber and adding interface configuration because after unplugging the 1g copper (where autoneg is supported) , the auto-negotiationg structure does not get cleared and is still gets applied after plugging in the 10g fiber (where auto-negotiation is not supported).
PR NumberSynopsisCategory: MPC Fusion SW
1777534On MX and EX platform replacing the line-cards may trigger FPC to be offlined due to unreachable destinations
Product-Group=junos
On Junos MX and EX9200 platforms when replacing MPC2E-NG and EX9200-40XS with MPC3E-NG, SCBE3 and EX9200-MPC cards, inserting the new MPC may cause new and other line cards to go offline due to unreachable destinations. This happens due to some registers on the fabric card is not properly updated once the fabric channel bonding has changed and impacts the traffic.
PR NumberSynopsisCategory: a20a40 specific issue
1761928E2E packet capture will be corrupted
Product-Group=junos
On SRX platforms, when services-offload is enabled, End-to-end (E2E) packet capture will be corrupted.
1784775The chassis cluster failover is seen post ISSU
Product-Group=junos
On SRX5K platforms with SPC3, chassis cluster failover is seen post ISSU. The SPC3 connects to the wrong Routing Engine which impacts all the PICs affecting the complete traffic.
1787219Insufficient power alarm observed in SRX5K platforms
Product-Group=junos
On Junos SRX5600 and SRX5800 platforms, FPC (Flexible PIC Concentrator) will not come online due to insufficient power, leading to service disruption.
1793262FPC reboot seen on SRX platforms with SPC3 card post RG failover
Product-Group=junos
On SRX5K platforms with SPC3 card, the FPC (Flexible PIC Concentrator) card reboots when a RG0 failover (in chassis cluster scenario) is performed. Due to this, traffic impact can be seen.
PR NumberSynopsisCategory: common or misc area for SRX product
1779749Traffic loss due to PPM not offloading LACP
Product-Group=junos
On SRX5K platforms, the LACP (Link Aggregation Control Protocol) packets are reaching the RE (Routing Engine) instead of ppm (Periodic packet management) which is causing extra strain on RE leading to dcpfe core dumps and causing LACP connections to go down or flap.
PR NumberSynopsisCategory: BBE CPM/UPM
1659175JSD crash is seen during cBNG container startup
Product-Group=junos
On MX Platforms in BNG scenario, the telemetry collector connections will terminate when JSD (Juniper Extension Toolkit (JET) service process) crashes, creating a core dump due to startup of a cBNG (Containerized Broadband Network Gateway) container or when JSD is restarted from the CLI in a cBNG container. It is rare timing issue.
PR NumberSynopsisCategory: BBE routing
1781938Access route may get stuck in the routing table after trying to change the prefix length using CoA message
Product-Group=junos
On Junos MX platforms with subscribers management enabled, the access route may get stuck in the routing table failing to update or be removed as expected. This occurs when a user attempts to modify the prefix length associated with this route using a Change of Authorization (CoA) message. This may lead to traffic loss, and if a subscriber goes down following the CoA change, there is a failure to bring that specific subscriber back up.
PR NumberSynopsisCategory: Border Gateway Protocol
1448092unexpected delay while running "show route advertising-protocol bgp" for an unconfigured peer in scaled vrf
Product-Group=junos
When we have a large route volume to iterate/display, the show route advertising-protocol bgp takes more time to return for an unconfigured peer.
1709837Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.
1712527The PE advertises incorrect next-hop towards CE although BGP export policy configured with next-hop under policy-statement
Product-Group=junos
The show route advertising-protocol bgp reporting nexthop self rather than IP in the configured policy-statement for next-hop.
1729733BMP leads to prolonged high rpd CPU utilization upon committing the BGP peer import policy configuration
Product-Group=junos
On all Junos and Junos Evolved platforms, with BGP Monitoring Protocol (BMP) configured when a Border Gateway Protocol (BGP) peer import policy configuration change is committed that triggers the BGP reconfiguration job for routes re-evaluation, then high Routing Protocol Daemon (rpd) CPU utilization up to 100% will be observed for a long time which may impact routing as high rpd utilization can starve some processes.
1761627Increase in task memory observed on 'clear validation database'
Product-Group=junos
On all Junos and Junos Evolved platforms, when routing-options session validation is configured, and BGP is configured, task memory usage increases in every iteration on executing 'clear validation database' command.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1770976Routes getting stuck in hidden state forever in BMP scenario
Product-Group=junos
On all Junos and Junos Evolved platforms where BMP (BGP Monitoring Protocol) is configured, the routes are not removed from the RIB (Routing Information Base) even when the damping timer expires and they are stuck in the hidden
PR NumberSynopsisCategory: Track PRs in BGP Flow Spec area & is part of BGP inside RPD.
1740257The inetflow6 routes are not installed on firewall filter table using BGP FlowSpec
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with BGP FlowSpec, ipv6 routes are installed in flow route table but not in firewall filter table. FlowSpec routes are blocked and dropped leading to traffic disruption. This is especially seen when BGP UPDATE Message does not include "Filter: Packet Length filter" within "FLOW_SPEC_NLRI" from BGP flowspec server thereby inetflow6 routes do not have "Action(s)"
PR NumberSynopsisCategory: CFM
1790156Commit error: "Cannot set interface down action on more than one session running on interface et-x/x/x.x rmep x"
Product-Group=junos
Commit error: "Cannot set interface down action on more than one session running on interface et-x/x/x.x rmep x" is seen when the second CFM IFL is deleted on single IFD.
PR NumberSynopsisCategory: QFX Access Control related
1794778Dot1x process crash will be seen in the system with "server-timeout" & "server-fail use-cache" configuration
Product-Group=junos
On all Junos platforms having 802.1x with "server-timeout" & "server-fail use-cache" configuration, 802.1x process crash will be seen. In initial authentication client receives multiple egress-VLANs from radius server and during re-authentication if radius server is unreachable, then clients gets authenticated in server-fail use-cache scenario and the egress VLAN list is deleted. When 802.1x process attempts to access the same egress VLAN list which is deleted then the 802.1x process crash is seen and clients will face traffic drop.
PR NumberSynopsisCategory: Device Configuration Daemon
1696428Adding more than 256 VLANs as name tags on the same interface results in dcd crash
Product-Group=junos
On all Junos platforms, the dcd (device control daemon) process crash is observed when more than 256 VLANs as name tags are added on the same interface.
1742124DCD crash can be seen sometimes while pushing config using API
Product-Group=junos
On all Junos platforms, dcd crash can be seen when interface configuration is added using API and some Junos application (such as vrrpd, jdhcpd etc) send configuration for the same interface using Overlay files. This is because, in dcd the internal data structures are not updated correctly when config source is changed from API to Overlay which eventually leads to corruption. It does not cause any service impact.
PR NumberSynopsisCategory: JUNOS Dynamic Profile Configuration Infrastructure
1797305The KRT queue stuck resulting in subscriber traffic loss
Product-Group=junos
On Junos MX platforms with subscriber dynamic profile versioning, following a commit configuration command, the krt ( Kernel routing table) queue becomes stuck on the master Routing Engine (RE), causing loss of subscriber traffic and subsequent client restarts. This occurs due to a large number of queued entries, resulting in blockage of the KRT queue.
PR NumberSynopsisCategory: EVPN control plane issues
1722102L2alm sends IPv6 NS with IRB link local address even though target IP is global address
Product-Group=junos
On Junos and Junos Evolved platforms configured with EVPN-VXLAN, EVPN-MPLS, it is observed that L2alm sends IPv6 NS(Neighbor Solicitation) with link local address even through target IP is global address.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1691029Packet Loss seen on the EVPN-VXLAN spine router
Product-Group=junos
On all platforms supporting MAC_VRF in a scaled config when continous delete and rollback were performed the OSPF and BFD will go down leading to packet drop.
1700196Traffic drop would be observed due to the VTEP tunnels not being established in the EVPN-VxLAN scenario
Product-Group=junos
On Junos and Junos Evolved QFX platforms, in the Ethernet Virtual Private Network-Virtual extensible LAN (EVPN-VxLAN) scenario Virtual Tunnel End Point (VTEP) tunnels are not established due to the timing of events and show up as next-hop set to zero which causes the traffic loss. It is a rare case and this issue will be observed in a scaling scenario or multiple mac-vrf routing-instances.
PR NumberSynopsisCategory: EX4400 PFE software
1752898In Q-in-Q push/pop configuration for double tagged protocol traffic it is seen that the third VLAN tag is getting swapped instead of getting pushed onto the stack
Product-Group=junos
On Junos EX4350/EX4650-48Y/QFX5120/QFX5120-32C/QFX5120-48Y/QFX5120-48T/EX4400/EX4100 platforms, it is observed that during Q-in-Q push/pop configuration when double tagged protocol traffic like BGP (Border Gateway Protocol) /RIP (Routing Information Protocol) /OSPF (Open Shortest Path First) etc. packets are send towards UNI (User to Network Interface), the third tag is not getting added using firewall rule instead a swap operation is being done and the packet is forwarded as double-tagged. As a result, next device drops the traffic because expectation on that node is triple tagged frames.
1790316The access port is dropping a VLAN-tagged packet of which the interface is a VLAN-member
Product-Group=junos
On all Junos EX and QFX5K platforms supporting Virtual Extensible LAN protocol (VXLAN), the access ports drop Virtual Local Area Network (VLAN) tagged traffic of the same VLAN for which the interface is configured. Though ideally, the access port should be accepting only untagged traffic, because of customer requests the access ports were made to accept tagged packets of which the interface is a VLAN member along with untagged traffic.
1791053Warning message 'Too many VLAN-IDs on untagged interface' is seen when more than 1025 vlans on the same LAG interface are configured
Product-Group=junos
On EX platforms, when more than 1025 vlans on the same LAG interface are configured, a warning message 'Too many VLAN-IDs on untagged interface' at commit operation will be seen.
1795545On all Junos EX platforms rewrite rules does not work properly when multiple interfaces are configured
Product-Group=junos
On all EX Junos platforms enabled with CoS, if there is rewrite-rule applied to the multiple interfaces, the rewrite-rule which is present for only one of the logical interfaces might work as expected due to this issue.
PR NumberSynopsisCategory: EX4400 platform
1759351EX4400:PSM is not detected in "show chassis hardware" until AC feed is connected to it
Product-Group=junos
The Power Entry Module (PEM) after insertion will not be detected/displayed in the show chassis hardware CLI output , until the power feed is connected .
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1788573Traffic loss after PIC restart if the packet has a VLAN tag of 4095
Product-Group=junos
On EX4400, EX4100, EX4650, and QFX5120 platforms in the EVPN-VXLAN (Ethernet VPN - Virtual Extensible LAN) IPv6 (Internet Protocol Version 6) underlay environment, after the PIC (Physical Interface Card) restart few AE (Aggregated Ethernet) member interfaces go down and comes back up traffic loss is observed if the packet has a VLAN tag of 4095. The issue happens because PFE (Packet Forwarding Engine) will not receive any new next-hop addition to PFE as the AE interface is already present in PFE as next-hop.
PR NumberSynopsisCategory: Express PFE CoS Features
1738981DSCP classifier is not created on IP interfaces
Product-Group=junos
On Junos QFX10k platforms, on configuring diffServ code point (DSCP) classifier and when inet or inet6 is configured with custom dot1p on interface, default dscp classifiers are not getting removed properly.
PR NumberSynopsisCategory: Express PFE L3 Multicast
1774562PIM join are not learnt for multicast IPs
Product-Group=junos
On Junos PTX platforms, with PIM BIDR (Protocol Independent Multicast- Bidirectional) mode with "set protocols pim rp bidirectional address <> group-ranges <>" configuration, PIM/MLD joins will not be learnt for multicast IPs other than link local IP and MY IP which will lead to traffic impact. Also, lo0 filter which were introduced with PR 1701756 for IGMP and MLD will be applied only for MY IPs and Link local IPs. For any other IPs other than above, lo0 filter will not work.
PR NumberSynopsisCategory: SRX1500 platform software
1751496On SRX1500 PEM Alarms are displayed due to hardware limitations to read I2C
Product-Group=junosvae
On SRX1500 Hardware Limitation leads to PEM I2C Failure Alarm triggered as result of failure in I2C reading operations.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1739559SRX4100/4200 accepts the datapath-debug configuration although it does not support it
Product-Group=junos
It is possible to set and commit the datapath-debug configuration on platforms SRX4100/SRX4200 although datapath debugging is not supported on those platforms. because of this unsupported configuration being accepted the RE (Routing Engine) load can go high and cause traffic outage. The workaround is to remove the datapath-debug configuration and perform a commit.
PR NumberSynopsisCategory: IDP policy
1786822The flowd process crash is observed when the device is rebooted
Product-Group=junos
On all Junos SRX platforms, flowd crash is seen when the device is rebooted and a CLI request for Intrusion Detection and Prevention (IDP) counters reaches the Packet Forwarding Engine (PFE) before the IDP memory module is initialized (even if IDP is not configured). The flowd process restarts affecting the traffic.
PR NumberSynopsisCategory: ISIS routing protocol
1749850The device will not be reachable over the loopback interface for the IS-IS nodes even though the neighborship may exist
Product-Group=junos
On all Junos and Junos OS Evolved platforms, multiple simultaneous Command Line Interface (CLI) sessions will lead to high Management Daemon (mgd) CPU utilization, impacting the device's reachability over the loopback interface from IS-IS nodes.
1759728The rpd process crashes after clearing ISIS database or restarting the rpd process
Product-Group=junos
On all Junos and Junos Evolved platforms, in scenarios where segment routing (SR) is configured, prefix-segment is used in a clause of policy associated to Intermediate System to Intermediate System (ISIS) protocol and Label Distribution Protocol (LDP) stitching in use, the routing process daemon (rpd) process will try to access freed memory after clearing ISIS database or restarting routing process, which leads the rpd process to crash.
1782887Traffic blackhole due to Flex-algo not removing stale entries from ISIS database
Product-Group=junos
On all Junos and Junos Evolved platforms, in an ISIS scenario using Flex-algo , the system does not remove the stale (outdated) entries from the ISIS database causes traffic blackholing. This issue could lead to some traffic loss, as the routing information stored in the ISIS database does not get properly updated.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1781379The SIP UDP register packet will be dropped on MX and SRX platforms
Product-Group=junos
On all MX and SRX platforms, SIP (Session Initiation Protocol) UDP (User Datagram protocol) register packet will be dropped by ALG (Application Layer Gateway) when the USER-AGENT is filed with some unknown language
PR NumberSynopsisCategory: Flow Module
1760545The srxpfe process crashes when interface attributes are modified
Product-Group=junos
On Junos SRX platforms except for SRX3xx, the 'srxpfe' (packet forwarding engine) crash can be seen which causes traffic loss. This rare issue can be encountered while changing interface configuration with PMI (PowerMode IPsec) enabled.
1779260ISSU upgrade to 21.4+ on SRX5k or SRX4600 may lead to a flowd coredump
Product-Group=junos
On SRX5000 series and SRX4600, performing ISSU (In-Service Software Upgrade) to Junos version 21.4 and higher from earlier Junos versions can lead to a flowd coredump occurring during the ISSU process. The coredump would occur on the already upgraded node while the sessions are getting synchronized from the node which is not upgraded yet.
1783595PMI sends packets to the wrong destination
Product-Group=junos
On SRX platform, when the next-hop changes, the PowerMode Ipsec (PMI) induces the packets to be sent to the wrong destination, causing packet drops.
1798041On Juniper SRX platforms GTP-U packets source and destination ports gets swapped to further drop reply packet.
Product-Group=junos
On Juniper SRX devices with GTP-U distribution feature enabled, GTP-U source and destination ports may get swapped and blocked by the security policy. Due to this, all reverse GTP-U packets will be discarded.
PR NumberSynopsisCategory: l2 flow module
1780182SRX with transparent mode may fail to create a new flow session for multicast traffic when vlan has l3-interface
Product-Group=junos
On all SRX platforms, when transparent mode is used, flow session does not create for the first few multicast packets due to which traffic drop occurs when l3-interface is used. The issue only happen in flow session creation process for Multicast traffic and the unicast traffic is unaffected. Once the flow session is created, multicast traffic will not be dropped.
PR NumberSynopsisCategory: Firewall Policy
1783249Security policies may go out of sync during ISSU
Product-Group=junos
On all SRX platforms, performing ISSU (In-Service Software Upgrade) to or from an affected release can lead to policies going out of sync between control plane and forwarding plane. Affected releases are 19.4R3-S13, 20.4R3-S8/9/10, 21.2R3-S6/7; 21.4R3-S5/6; 22.2R3-S2; 22.4R3; 22.4R3-S1; 23.4R1. To recover, use the CLI command "request security policies resync".
PR NumberSynopsisCategory: User Firewall related issues
1758332Junos OS: SRX Series and EX Series: Multiple vulnerabilities in J-Web can be combined to allow a preAuth Remote Code Execution (CVE-2023-36851)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity and access confidential information. Please refer to https://supportportal.juniper.net/JSA72300 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1783738The kmd/iked process crashes under rare circumstances
Product-Group=junos
On Junos SRX/MX platforms, VPNs (Virtual Private Network) that employ the use of KMD (ipsec-key-management) or IKED (ike-key-management) may inadvertently crash while generating the random number used by IPSec services which can cause the device to become very busy.
1784752High RE CPU observed on both nodes in chassis cluster due to jsrpd
Product-Group=junosvae
High RE (Routing Engine) CPU caused is caused by jsrpd (Junos stateful redundancy protocol daemon) on both the nodes in a chassis cluster configured with control link Encryption (Internal SA) after upgrading the cluster.
PR NumberSynopsisCategory: Security platform jweb support
1789466Jweb does not display address book entries properly after certain operations.
Product-Group=junos
On SRX platform, Jweb does not display address book entries properly after certain operations.
PR NumberSynopsisCategory: Layer 2 Control Module
1770053xSTP configured interface will remains in discarding state
Product-Group=junos
On all Junos and Junos OS Evolved Platforms, when an interface is added inside RSTP (Rapid Spanning Tree Protocol), VSTP (VLAN Spanning Tree Protocol), MSTP (Multiple Spanning Tree Protocol) or STP (Spanning Tree Protocol), because of STP port creation fail from l2cpd (Layer 2 control protocol daemon), port will remains in discarding state. This leads to traffic impact.
1787892Interface configured with BPDU-disable goes down during VC mastership switchover
Product-Group=junos
On Junos EX3400/EX4300/EX2300 platforms configured with VC (Virtual Chassis) and NSB (Nonstop-Bridging) enabled, when VC mastership switchover is triggered, the configuration under 'set protocols layer2-control bpdu-block interface ' will not take effect due to which the interface will go down and will impact the traffic. The configuration 'set protocols layer2-control bpdu-block interface all' will not have any impact.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1666700RLI-47857: Traffic loss seen with CRB config after adding RI protocol evpn extended-vni-list
Product-Group=junos
Traffic loss seen with CRB config after adding RI protocol evpn extended-vni-list. Issue is observed because in EVO SVTEP ifl is not deleted when ifl index is zero.
1772424Connectivity between static and LDP signaled pseudowires broken in VPLS after upgrade and results in VPLS traffic drop
Product-Group=junos
On all Junos and Junos OS Evovled platforms, when there is a upgrade and also when one mesh group of routing instance is substring of other, the connection between static and LDP (Label Distribution Protocol) signaled psuedowires is broken will lead to traffic drop.
1776991ARP resolution issues will be observed in the H-VPLS environment
Product-Group=junos
On Junos and Junos Evolved platforms, traffic impact will be observed due to ARP (Address Resolution Protocol) resolution issues when multiple mesh-group is configured under the same routing-instance and the name of each mesh-group is not unique i.e. substring of another mesh-group in the H-VPLS (Hierarchical Virtual Private LAN Service) environment.
1790064The l2ald process will crash, with rapid configuration changes followed by rpd and l2ald restart process
Product-Group=junos
On all Junos and Junos OS Evolved platforms with EVPN -VXLAN and high scaling configuration, rapid configuration changes followed by restart of rpd and l2ald will result in l2ald process crash and traffic drop will be observed.
PR NumberSynopsisCategory: lacp protocol
1773827The LAG with member interface enabled with 'force-up' can flap after switchover
Product-Group=junos
On Junos and Junos Evolved QFX/EX platforms if the member link of an AE (Aggregation Ethernet) interface is configured with force-up, the LAG (Link Aggregation Group) can flap after switchover through GRES (Graceful Routing Engine Switchover) or during ISSU (In Service Software Upgrade). Traffic that goes through the LAG will be dropped when the interface flaps.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1737035BGP sessions flap due to license updates
Product-Group=junos
On all Junos platforms, a BGP flap is observed when a license key is upgraded or a new license is added resulting in traffic loss.
1759618License-service crash is seen on Junos OS Evolved platforms
Product-Group=junos
On Junos OS Evolved platforms, when license with unknown feature ID/platform reserved feature ID is added via configuration set system license keys key and then if License-service is restarted or system is rebooted or software upgrade is done then license service crashes and crash files are seen. This is a non service impacting issue.
1775463The RE goes into amnesiac mode upon license check validation failure
Product-Group=junos
On all Junos Platforms, the RE (Routing Engine) goes into amnesiac mode upon reboot if node locked license is configured via the "set system license keys key <>".
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1729467MACsec interoperability issue between Juniper and non Juniper platforms
Product-Group=junos
On all Junos and Junos Evolved platforms with MACsec (Media Access Control security) configured , frequent SAK (Secure Association Key) rollover is observed when the peer device is a non-Juniper box and the Juniper device is acting as the key-server. This results in unstable MACsec sessions between the juniper device and the non Juniper device.
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1719682LACP interface will be down after aggressive link flaps with 100ms interval
Product-Group=junos
When link flaps repeatedly within a very short time frame on 100G interface on MPC10E line card supported platforms(MX240, MX480, MX960, MX2010, MX2020), traffic stops egressing the affected interface and report syslog messages during link down event. When there are continous flaps and if those flaps are very fast under 1 second and continuous then this issue will be seen.
PR NumberSynopsisCategory: SW PRs for MPC10E PMB
1731258MPC10 and MPC11 line cards experiencing unexpected reboots
Product-Group=junos
Line cards such as MPC10 and MPC11 experience unexpected reboots because of CPU C-states which are enabled by default thus impacting the customer production traffic.
PR NumberSynopsisCategory: For multicast snooping on MX
1711153A crash can be observed for 'mcsnoopd' process when the VLAN name for igmp-snooping has certain characters
Product-Group=junos
On all Junos and Junos Evolved platforms, a crash can be observed for the 'mcsnoopd' process. This issue is seen when the devices support the VLAN (Virtual Local Area Network) style of igmp-snooping (internet group messaging protocol configuration (set protocols igmp-snooping vlan ) and the VLAN name begins with the word all and has certain other characters. The workaround is not to enable the snooping for such VLANs.
PR NumberSynopsisCategory: MX10K platform
1719915Removing a PEM that doesn't have power feed does not generate the SNMP TRAP for "Power Supply Removed"
Product-Group=junos
If a display power entry module (PEM) doesn't have power feed by turning the power switch OFF, removing the PEM physically will not generate the SNMP TRAP "Power Supply Removed."
PR NumberSynopsisCategory: TCP/UDP transport layer
1738361tcp md5 authentication mismatch logs are not seen in /var/log/messages [tcp_auth_ok: Packet from X.X.X.X:XXXXX wrong MD5 digest]
Product-Group=junos
from 21.3R2 release onwards these are logs not seen in /var/log/messages.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1753191ARP resolution failure for lt interfaces is observed after cluster failover on Junos SRX platforms
Product-Group=junos
On Junos SRX platforms in cluster, Address Resolution Protocol (ARP) resolution fails for logical tunnel interfaces when the logical tunnel interfaces are toggled and the cluster switchovers.
PR NumberSynopsisCategory: OSPF routing protocol
1774715OSPF route flap might be observed
Product-Group=junos
On all Junos and Junos OS Evolved platforms OSPF (Open Shortest Path First) route flaps can be observed which will cause a traffic drop. This is a rare timing issue happening after an OSPF adjacency flap.
PR NumberSynopsisCategory: Protocol Independant Multicast
1792886The rpd crash is observed when PIM SSM mode with RPF-Vector and MoFRR is configured
Product-Group=junos
On Junos and Junos Evolved platforms , when PIM SSM (PIM Source-Specific Multicast) with RPF (Reverse Path Forwarding)-Vector and MoFRR (Multicast-only fast reroute) is configured , rpd crash if the device receives PIM Prune message for (S, G) state with RPF vector TLV. interface is freed for the (S, G) from the outgoing interface list i.e. RPF-Vector TLV (Type, Length, and Value) having (S, G) is getting freed but that same (S, G) is still used by MoFRR. The issue happens when MoFRR Backup upstream interface is also listed at the outgoing interface list for the (S, G)
PR NumberSynopsisCategory: vMX Platform Infrastructure related issue tracking
1729152The FPC crash or flap in protocols will be seen as soon as port-mirroring or firewall filters with syslog action is enabled
Product-Group=junos
On MX150 platform, when port-mirroring or firewall with syslog configuration is enabled, there will be a memory leak which will cause depletion of buffer memory which will lead to flap in the protocols or the (Flexible PIC Concentrators) FPC crash. This will impact the traffic.
PR NumberSynopsisCategory: QFX access control list
1754929[QFX5120]Egress filter does not work properly on vlan pop configuration
Product-Group=junos
On QFX5120 platform if it sets egress filter on vlan pop configuration, filter does not work properly
PR NumberSynopsisCategory: QFX L2 PFE
1739048Q-in-Q for access port to access port through VxLAN bridge-domain does not work on all Junos QFX5K platforms
Product-Group=junos
Q-in-Q for access port to access port is not working on all Junos QFX5K platforms when it is configured with VxLAN local switching (bridge-domain). The traffic is working in only one direction and the packet is getting dropped in reverse direction because the packet is coming in as single tagged VLAN.
1781955A few AE interfaces will drop traffic when a large number of AE interfaces are deleted and added back
Product-Group=junos
On EX4100, EX4100 Multigigabit, EX4100-F, EX4400, EX4400 Multigigabit, EX4650-48Y, QFX5120-48Y, QFX5120-32C, QFX5120-48T, QFX5110 and QFX5120-48YM platforms with Ethernet VPN-Virtual Extensible LAN (EVPN-VxLAN) configured, a few AE interfaces will drop traffic when a large number of Aggregated Ethernet (AE) interfaces are deleted and added back. When this issue happens AE interfaces will be UP but traffic would be dropped.
1797516DCPFE process crash occurs in EVPN-VXLAN scenario
Product-Group=junos
When a vport, which is a memory pointer, is a member of an itable list, the entry in the itable should be removed before freeing the vport. For some corner case, the vport is not removed from the itable when freeing the vport. The freed memory or the reused memory corrupts the itable list and it crashes when performing some operation on the corrupted list.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1771630Family ethernet-switching policer per-sub-unit interface breaks after dcpfe/device restarts
Product-Group=junos
On all Junos QFX and EX platforms, on dcpfe/device reboot, the firewall filters will not be processed affecting the filters applied on subunits of the LAG interfaces.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1773676The tagged traffic drop will be seen with vlan-id-list and native-vlan-id configured on one IFL.
Product-Group=junos
On QFX5120, EX4650, and EX4400 platforms, when vlan-id-list and native-vlan-id are configured on one IFL, the packets will drop and will impact the tagged traffic.
1774366The dcpfe process crash due to stale memory
Product-Group=junos
On Junos QFX platforms, stale memory references are causing dcpfe crashes triggering PFE (Packet Forwarding Engine) to restart resulting in traffic disruptions.
1775672The untagged packets get dropped in transparent EVPN-VXLAN on the ingress PE-CE port of SP style on certain Junos EX/QFX platforms
Product-Group=junos
On Junos QFX5k/EX4650/4400/4100 platforms with SP (Service Provider)-style configuration and in the EVPN (Ethernet Virtual Private Network)-VXLAN (virtual Extensible Local Area Network) scenario at the ingress port of the CE (Customer Edge) host, untagged packets are getting dropped when native VLAN (Virtual Local Area Network) is configured. These packets should be flooded into the VLAN (Virtual Local Area Network) including intra-VLAN ports and remote VTEP (Virtual Tunnel Endpoint).
1778725Traffic drop is observed when VIPs become unreachable due to GARP sent on VLANs to which the VIP does not belong
Product-Group=junos
Under a rare scenario, on all Junos and Junos Evolved platforms configured with EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible Local Area Network) type 5 routes, Bridge-Domain, IRB (Integrated Routing and Bridging) and having L4 (Layer 4 device like an application load balancer) devices as single-homed with each border leaf and when VIP (Virtual Internet Protocol) entries are learnt on a leaf and L4 failover happens, it is observed that the VIPs announced by GARP (Gratuitous Address Resolution Protocol) is sent on VLANs that the VIP does not belong to and the incorrect GARP is not handled as per the expectation.
1783397The fxpc process crash and the device reboots after deleting Aggregated Ethernet (AE) Interface along with its associated physical interface and then applying new interface configuration on the associated physical interface in an EVPN-VXLAN scenario
Product-Group=junos
On an Ethernet Virtual Private Network (EVPN) / Virtual eXtensible Local-Area Network (VXLAN) scenario, after removing an Aggregated Ethernet (AE) Interface along with its associated physical interface on a QFX5k series device and then applying any configuration to the physical interface, the fxpc process crashes and the device undergoes an automatic reboot.
1796210In the EVPN-VxLAN scenario traffic blackholes on spine reboot
Product-Group=junos
On all Junos QFX5K and some specific EX4K in EVPN-VxLAN (Ethernet VPN-Virtual extensible LAN) environment with underlay connections using Virtual Chassis Port Link Aggregation with AE (Aggregated Ethernet) interface and during one of the spine reboot, traffic will not be immediately switched to another spine and traffic blackholes.
1802958ECMP programming issue on Junos QFX5K/EX4K in EVPN-VXLAN
Product-Group=junos
In rare scenarios on Junos QFX5K/EX4K platforms that are part of Ethernet VPN - Virtual extensible LANs (EVPN-VXLAN) Fabric topology and employing ECMP (Equal Cost Multi-path) routing on the underlay interfaces between the Leaf and Spine, if one or more of these physical underlay interfaces flaps or their associated underlay protocol adjacency flaps and this time aligns precisely with the associated unicast next-hop deletion process, a race condition may occur, resulting in the potential failure to program the associated ECMP interface next-hop entry correctly in the hardware table.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1795339FPC crash and traffic drop occurred due to "Err Detect Register" and "Data Cache Parity Error"
Product-Group=junosvae
With some HW memory failure in QFX10008/16 Linecards, the PFE process gets stuck in bad state which takes 2-3min for detection causing traffic drops for that time.
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
139362810G copper link flapping might happen during TISSU operation of QFX5100-48T switches
Product-Group=junos
On QFX5100-48T switches, when doing TISSU (Topology Independent In-Service Software Upgrade) operation, link flaps on 10G copper interfaces might be observed on the peer device. These flaps might cause unexpected failover of the connected PC/servers, which results in service impact.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1779624On the QFX5110-48S platform the virtual chassis port goes down when the VC is upgraded or the VC ports are deleted and added back
Product-Group=junos
One of the virtual chassis ports in a VC of QFX5110-48S goes down either by deleting or adding the port or by upgrading the virtual chassis thereby causing a loss of redundancy for the virtual chassis ports. The ways to recover are by re-creating the VC or by doing soft removal and insertion of the port (please contact JTAC for the same).
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1747992The memory consumption increases due to memory leak
Product-Group=junos
On all Junos and Junos OS Evolved platforms, a continuous memory leak is observed due to an allocated socket memory not being freed. This is a minor leak but can lead to significant memory usage on highly scaled setups leading to performance and functional impact including system crash beyond a certain point.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1687884The traffic drop will be observed for the static route after VRRP failover when VRRP VIP is set as next-hop for that static route
Product-Group=junos
On all Junos and Junos OS Evolved platforms, the next-hop for a static route does not refresh at PFE (Packet Forwarding Engine) after VRRP (Virtual Router Redundancy Protocol) failover when VRRP VIP (Virtual-IP) address is used as the next-hop for the static route.
1761232Memory spike will be observed on the system with BFD enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when Bidirectional Forwarding Detection (BFD) is enabled with any routing protocols (ex - IS-IS/OSPF), memory spikes will be observed in the system.
PR NumberSynopsisCategory: PTX10K specific platform PRs
1766097PTX10008: When NSR Enabled and FMBB Knobs are configured and if SIB is Offline/Online casue resiliencyd core
Product-Group=junos
PTX10008: When NSR Enabled and FMBB Knobs are configured and if SIB is Offline/Online casue resiliencyd core
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1691986Consistent high CPU usage is seen on the device post reboot
Product-Group=junos
On all Junos and Junos Evolved platforms consistent high CPU usage in snmpd immediately after reboot.
PR NumberSynopsisCategory: Cover Logical System Infrastrcuture Development
1694449The process srxpfd/ flowd will crash on SRX devices
Product-Group=junos
On all SRX platforms (except branch SRX series) configured with chassis cluster redundancy group, when numerous logical interfaces or IFLs (> 1K) are deleted and traffic is running for those IFLs, or if the RG failover then the process srxpfed/ flowd will crash.
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1766594After the device reboot JSC stops accepting user connections
Product-Group=junos
On all SRX platforms, when Juniper Secure Connect (JSC) configuration is done on Point-to-Point Protocol over Ethernet (PPPoE) interface then after the device reboot, JSC clients couldn't connect.
PR NumberSynopsisCategory: SRX branch platforms
1738271"Minor Autorecovery information needs to be saved" alarm is not displayed after zeroize
Product-Group=junos
On SRX Branch platform, "Minor Autorecovery information needs to be saved" alarm is not displayed after running zeroize command
1744108Commit panic reboot observed after implementing system processes watchdog timeout 180 on SRX hardware platforms
Product-Group=junos
On SRX hardware platforms, configuring set system processes watchdog related command causes commit panic reboot. Watchdog related commands are unsupported on SRX hardware platforms.
1776400The Wifi MPIM card will be down upon upgrading the device
Product-Group=junos
Upon upgrading the Junos SRX platform which is acting as a WAP (wireless access point) or WLAN (wireless LAN) installed with a Wi-Fi MPIM (Mini Physical Interface Module) card, the card is not working. This will tear down the Wi-Fi client sessions, impacting the services.
1780326IP Monitoring fail to install route after SRX cluster reboot
Product-Group=junos
On Junos SRX branch series platforms in cluster, the IP Monitoring fails to install route after the SRX cluster reboots.
1783757Vmcore is seen when websites are accessed via the VPN/ Captive portal
Product-Group=junos
On all SRX and EX platforms, multiple mgd (Management daemon) processes are getting spawned and not getting killed. This causes a reboot of the device and vmcore is seen after the reboot.
PR NumberSynopsisCategory: SRX-1RU infrastructure SW defects
1784983Chassis alarm not present for if /var partition usage exceeds 100%
Product-Group=junos
When /var partition disk space is greater than 100%, "RE 0 /var partition usage is high" chassis alarm gets cleared
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1775083Traffic drop observed right after boot up on Junos SRX 4600 platforms
Product-Group=junosvae
On SRX 4600 platforms running the Field Programmable Gate Array (FPGA) firmware versions 163, 165, 171, 175 the Packet Forwarding Engine (PFE) may experience a 25% drop in performance after bootup.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1784914The backup routing-engine mac address is not resolved on Junos MX platforms with subscriber management configuration
Product-Group=junos
On Junos MX platforms with MPC 3NG, MPC5, MPC7 line cards with subscriber management configuration, when upgrade is performed to Junos 18.4 release or higher, the backup routing-engine (REs) mac address does not get resolved during Flexible PIC Concentrators (FPCs) bootup when the backup RE and the FPC reboot at the same time.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1757074MXVC:PPE loop when AE interface contains member interfaces on the same slot in each Chassis.
Product-Group=junos
In a MXVC (Virtual Chassis) configuration where an AE (Aggregate Interface) has members on the same slot number in each chassis, the member link selection logic could select an Egress member link outside the range of the local PFE (Packet Forwarding Engine) instance. In this case, a default link will be selected, but this default link could also be outside the range for the PFE instance creating a loop in the PPE and causing a trap with a timeout.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1738672FPC crashes due to back-to-back GRES
Product-Group=junos
On line cards such as MPC5E/MPC7E/LC480/MPC10E/11E/LC9600 and MX304 platforms, when multiple times Graceful Routing Engine Switchover (GRES) is performed, all the FPCs crashed.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1729970L2-Trans: pm_soam_frame_rx count is not incrementing as expected
Product-Group=junos
L2-Trans: pm_soam_frame_rx count is not incrementing as expected
1740606Host communication does not work in EVPN-L2VPN-CCC setup
Product-Group=junos
On Junos MX platforms, in Ethernet Virtual Private Networks-Layer 2 Virtual Private Networks-Circuit Cross-Connect (EVPN-L2VPN-CCC) setup, the integrated routing and bridging (IRB) interface over access logical tunnel (LT) interface is configured, it is sending vlan tagged packet on the access port and not removing it causing the host communication to break.
1745803During multicast traffic flow , 'sw error' discard count is incrementing continuously
Product-Group=junos
On all MX series platforms, Multicast over IRB with receivers spanning across PFEs then some vty exception counters which keeps incrementing.
1751846[MX480/MX240] Multicast ping ff02:: 1 cannot perform reply on MX240/480 platform from MX204 via VXLAN
Product-Group=junos
When MX204 and MX240/MX480 connected over static VxLAN with IPv6 underlay and IPv6 configured on IRB interface, Multicast ping with IPv6 address will fail while trying multicast ping with IPv6 address from MX204, ICMP response is not received from MX240/MX480 when other FPC is online.
PR NumberSynopsisCategory: Ephemeral Database
1751141Load replace via XML NetConf will not work
Product-Group=junos
On all Junos and Junos OS Evolved platforms, the load replace operation through XML NetConf will fail.
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1787147The sdp process crashes when trying to add a new satellite device to the network
Product-Group=junos
In the Junos Fusion setup, the sdp (Satellite Discovery and Provisioning Daemon) process crashes repeatedly when trying to add a new satellite device to the network. This issue happens when the MD5 encrypted data is read as a string, in which the string validation code throws errors when the first byte of MD5 encrypted data is 0.
PR NumberSynopsisCategory: For GPRS security features on highend SRX series
1736985Cores are observed on both the nodes of SRX HA cluster setup when it's upgraded to 21.2 and above
Product-Group=junos
On Junos SRX high-end platforms configured with GTP (GPRS Tunneling Protocol), during the upgrade of an SRX High Availability (HA) cluster, a crash occurs on the nodes when processing GTP packet traffic. This persistent crashing prevents the system from restarting and impacts service availability.
PR NumberSynopsisCategory: usf ams related issues
1784696Devices with MXVC+SPC3 service card experience failure in NAT pool allocation when configuration for balancing network traffic (AMS LB) is used
Product-Group=junos
MX platforms with MXVC (Virtual Chassis) and SPC3 service card, when the AMS (Aggregated Multiservices Interface) interface has its member leg on MX virtual-chassis member 1 node, the NAT (Network Address Translation) address pool allocation fails.
PR NumberSynopsisCategory: usf nat related issues
1776355Internet traffic destined for the NAT pool address (Network Address Translation) will loop after configuration changes
Product-Group=junos
On Junos MX platforms, with MS-MPC and SPC3 service cards, Change in "interim-logging-interval" configuration can lead to UDP traffic get looped and it will impacting CPU utilisation and traffic drop can be seen.
 
 

21.4R3-S7 - List of Known issues

Please see the attachment for the list of known issues.

Tip: To search for an entry in the list of Known Issues, please download the attachment and use your PDF reader's search function.

Modification History

First publication 2024-05-09