Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX MX NFX PTX SRX vSRX

Alert Description

Junos Software Service Release version 22.3R3-S3 is now available for download from the Junos software download site.

The Junos software version 22.3R3-S3 is not available for EX and QFX platforms running Junos Software

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 22.3R3-S3 is now available.

22.3R3-S3 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 Layer 2 implementation
1797422DHCP IP assignment will fail on VoIP phone connected to a VXLAN access port
Product-Group=junos
On EX4300-48MP platform, in Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, Dynamic Host Configuration Protocol (DHCP) IP assignment for a Voice over IP (VoIP) phone connected to a VXLAN enabled access port will not work.
PR NumberSynopsisCategory: EX2300/3400 platform
1772477Turning port beacon LED on or OFF may not change the LED status
Product-Group=junos
On EX2300, turning port beacon LED on or OFF may not change the LED status. There is no service impact due to this.
1781317Error is shown on system when pvidb variable is accessed
Product-Group=junos
On Junos EX platforms, when pvidb variable which is unkown is tried to access from a device, pvidb error messages will be seen, There is no impact on service due to this.
1789272Watchdog SPI transaction is causing the interface flap in the system
Product-Group=junos
On EX2300-MP platforms, when the SPI (Serial Peripheral Interface) bus is accessed by multiple processes simultaneously results in watchdog reset due to the lack of lock-unlock operations. Consequently, this can lead to interface flaps affecting the traffic flow.
PR NumberSynopsisCategory: JNP10K-LC9600 hardware Category
1677757LC9600 line card not booting-up [BIOS corruption].
Product-Group=junos
On very rare cases after reboot or power cycle of LC9600 line card, BIOS 25.1.0 on the line card may corrupt. Once the problem happens the line card will remain present state. BIOS version 29.1.0 has resolved this issue. 
PR NumberSynopsisCategory: SPC3 HW and SW Issues
1780282Unexpected failover will be seen when there is communication loss between CP and SPU on SRX platforms with web-authentication or web-redirect is configured
Product-Group=junos
On all SRX series firewall with web-authentication or web-redirect configured, with continuous traffic from different IPs for which authentication needs to be done in such scenarios firewall authentication entries are out of sync between Central Point (CP) and Services Processing Units (SPU) modules caused attempt to delete same firewall authentication entry twice, that causes invalid memory access resulting into the core-dump followed by failover. Traffic impact will be seen during the fail over.
PR NumberSynopsisCategory: SRX ISSU infra related issues
1803376The In-Service Software Upgrade (ISSU) fails in L2HA cluster deployment
Product-Group=junos
On SRX-1500 platforms, In-Service Software Upgrade (ISSU) fails in L2HA cluster deployment.
PR NumberSynopsisCategory: "agentd" software daemon
1665516Na-grpcd process core observed in telemetry services
Product-Group=junos
On all Junos and Junos OS Evolved platforms, due to race condition happening at the time of AFT streaming and simultaneous multiple attempts to subscribe and unsubscribe AFT sensors, followed by modifying firewall filter configurations, na-grpcd can core on rare occasions. This will cause a temporary outage of streaming telemetry services. The service will self-recover upon restart of the process.
PR NumberSynopsisCategory: MPC Fusion SW
1777534On MX and EX platform replacing the line-cards may trigger FPC to be offlined due to unreachable destinations
Product-Group=junos
On Junos MX and EX9200 platforms when replacing MPC2E-NG and EX9200-40XS with MPC3E-NG, SCBE3 and EX9200-MPC cards, inserting the new MPC may cause new and other line cards to go offline due to unreachable destinations. This happens due to some registers on the fabric card is not properly updated once the fabric channel bonding has changed and impacts the traffic.
PR NumberSynopsisCategory: Application Quality of Experience
1790782The srxpfe or flowd process will crash while trying to update the path probe statistics
Product-Group=junos
On Junos SRX300, SRX320, SRX340, SRX345, SRX380, SRX1500, SRX4100, SRX4200, SRX4600, vSRX2, vSRX3, and NFX platforms, while trying to update the path probe statistics the flowd/srxpfe process will crash when APPQOE best path changes to no path selected state. The process crash will restart the PFE affecting the traffic.
1805493IPSEC VPN is getting flapped due to warning messages
Product-Group=junos
On all Junos SRX, vSRX and NFX platforms controlled by Mist Solution , commit after faulty or warning-induced configuration will trigger warning on the console which invoke unstable or unexpected behavior with the system. This causes iked/kmod process to flap of IPsec VPN ( Internet Protocol Security Virtual Private Network ) which results in traffic outage.
PR NumberSynopsisCategory: a20a40 specific issue
1784775The chassis cluster failover is seen post ISSU
Product-Group=junos
On SRX5K platforms with SPC3, chassis cluster failover is seen post ISSU. The SPC3 connects to the wrong Routing Engine which impacts all the PICs affecting the complete traffic.
1787219Insufficient power alarm observed in SRX5K platforms
Product-Group=junos
On Junos SRX5600 and SRX5800 platforms, FPC (Flexible PIC Concentrator) will not come online due to insufficient power, leading to service disruption.
1793262FPC reboot seen on SRX platforms with SPC3 card post RG failover
Product-Group=junos
On SRX5K platforms with SPC3 card, the FPC (Flexible PIC Concentrator) card reboots when a RG0 failover (in chassis cluster scenario) is performed. Due to this, traffic impact can be seen.
PR NumberSynopsisCategory: common or misc area for SRX product
1779749Traffic loss due to PPM not offloading LACP
Product-Group=junos
On SRX5K platforms, the LACP (Link Aggregation Control Protocol) packets are reaching the RE (Routing Engine) instead of ppm (Periodic packet management) which is causing extra strain on RE leading to dcpfe core dumps and causing LACP connections to go down or flap.
PR NumberSynopsisCategory: BBE Layer-2 Bitstream Access
1796125The broadband subscriber (L2BSA subscribers) on the core interface logging out with interface state changes
Product-Group=junos
On all Junos platforms, any configuration changes that involve interface down/up sequence, result in logging-out L2BSA (Layer 2 Broadband Subscriber Access) subscribers associated with that core interface.
PR NumberSynopsisCategory: BBE routing
1781938Access route may get stuck in the routing table after trying to change the prefix length using CoA message
Product-Group=junos
On Junos MX platforms with subscribers management enabled, the access route may get stuck in the routing table failing to update or be removed as expected. This occurs when a user attempts to modify the prefix length associated with this route using a Change of Authorization (CoA) message. This may lead to traffic loss, and if a subscriber goes down following the CoA change, there is a failure to bring that specific subscriber back up.
PR NumberSynopsisCategory: Border Gateway Protocol
1781859The rpd process will crash in an EVPN scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, when EVPN-Type 5 (Ethernet VPN-Type 5) and L3VPN (Layer 3 VPN) families are configured and if EVPN routes are advertised to BGP(Internal Border Gateway Protocol) inet-VPN sessions then rpd process crashes. During the rpd crash and restart, the routing protocols will be impacted and traffic disruption will be seen due to the loss of routing information.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1767785The EOR message is missed for one peer in a scaled BMP scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms with BGP Monitoring Protocol (BMP) enabled in scaled scenario (4K BGP peers, 6 BMP stations), after disabling/enabling BMP, due to timing issues, one out of six BMP stations will not receive End-of-RIB (EOR) message for one peer. This will not impact routing or data forwarding, however will have impact on data collection.
PR NumberSynopsisCategory: Track PRs in BGP Flow Spec area & is part of BGP inside RPD.
1740257The inetflow6 routes are not installed on firewall filter table using BGP FlowSpec
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with BGP FlowSpec, ipv6 routes are installed in flow route table but not in firewall filter table. FlowSpec routes are blocked and dropped leading to traffic disruption. This is especially seen when BGP UPDATE Message does not include "Filter: Packet Length filter" within "FLOW_SPEC_NLRI" from BGP flowspec server thereby inetflow6 routes do not have "Action(s)"
PR NumberSynopsisCategory: PFE COS features on BT based platforms
1797592More than 8 forwarding-classes cannot be configured with CBF
Product-Group=junos
On PTX10001-36MR, error will be displayed when we commit more than 8 forwarding-classes (FCs) which are configured with Class Based Forwarding (CBF) even though the product supports upto 16 forwarding-classes configured with CBF.
PR NumberSynopsisCategory: MX304 Chassis specific platform
1731237MX304 Major Alarm " Host 0 detected AER correctable error" after RE switchover.
Product-Group=junos
MX304 Major Alarm " Host 0 detected AER correctable error" after RE switchover.
1755788LT sub-interfaces which are not on the same PIC as the RLT interface goes down after activating RLT interface
Product-Group=junos
On MX304 platforms and MX platforms with LC9600 cards supporting RLT (Redundant Logical Tunnel) interfaces, when a RLT interface is activated which has member interfaces across PICs, the LT (Logical Tunnel) sub-interfaces which are not part of the RLT and not on the same PIC (Physical Interface Card) as the RLT interface, goes down. The LT sub-interfaces come up once the RLT interface is deactivated. Since the LT sub-interfaces are not part of the RLT, there is no impact for the same RLT.
1760982The spmbpfe crash is observed in back up RE during the system reboot
Product-Group=junos
On MX304 platforms, with multiple feature configurations when the system is rebooted the spmbfe crash will be seen in the backup RE.
PR NumberSynopsisCategory: MX304 line card platform software
1734132The MX304 stops forwarding traffic on channelized 1*N G ports after the GRES is performed
Product-Group=junos
On MX304 platforms with dual Routing-Engine(RE), if the ports are channelized into 1*N Gigabitethernet(G) mode, where N can be 1/10/25 G and the Graceful Routing Engine switchover (GRES) is performed, the ports go into the down state and traffic through these ports will be impacted.
PR NumberSynopsisCategory: Virtual-chassis platform/chassisd infrastructure PRs for MX
1798681CHASSISD_IFDEV_RTSLIB_FAILURE: ifdev_create: rtslib_ifdm_add failed (No such file or directory) after creating a virtual interface tunnel
Product-Group=junos
The error messages in question are not-service affecting and would not be noticed by regression scripts.
PR NumberSynopsisCategory: Class of Service
1795898COS output-traffic-control-profile is not getting attached to ps transport IFLs on a specific MX platforms that support HCOS
Product-Group=junos
COS output-traffic-control-profile does not get attached to ps (pseudowire service) transport IFLs when ps interfaces are configured over lt/rlt (logical tunnel/redundant logical tunnel) and both - ps transport IFL and ps service IFLs have COS output-traffic-control-profile configured, TCPs have different SMAPs (scheduler-maps) configured and these COS configuration on both these types of IFLs are committed in a single commit. This can impact COS scheduling on ps transport IFL.
PR NumberSynopsisCategory: QFX Access Control related
1794778Dot1x process crash will be seen in the system with "server-timeout" & "server-fail use-cache" configuration
Product-Group=junos
On all Junos platforms having 802.1x with "server-timeout" & "server-fail use-cache" configuration, 802.1x process crash will be seen. In initial authentication client receives multiple egress-VLANs from radius server and during re-authentication if radius server is unreachable, then clients gets authenticated in server-fail use-cache scenario and the egress VLAN list is deleted. When 802.1x process attempts to access the same egress VLAN list which is deleted then the 802.1x process crash is seen and clients will face traffic drop.
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1777635Traffic loss for few seconds will be observed after restarting l2-learning process on L3 VxLAN gateway
Product-Group=junos
On all Junos and Junos Evolved platforms, in the EVPN-VXLAN( Ethernet Virtual Private Network- Virtual Extensible Local Area Network) scenario, traffic loss for few seconds would be observed when a user restart l2-learning process on a Layer-3 VXLAN gateway. This happens because of timing issues in the kernel, which mistakenly delete MAC routes of its associated devices instead of updating them in the table. The traffic from devices with those MAC addresses won't flow until the system is back on track and syncing properly.
PR NumberSynopsisCategory: CoS support on DNX
1770491Traffic convergence is longer than usual after the CoS rewrite
Product-Group=junos
On ACX5448 and ACX710 platforms, traffic convergence takes more time than the expected 50ms i.e. traffic loss is more than expected observed for CoS (Class-of-service) rewrite change after a link failover in the MPLS (Multiprotocol Label Switching) scenario with FRR (Fast Reroute) and LSP (Label-Switched Path) link-protection configured.
PR NumberSynopsisCategory: DNX VPLS
1692400dc-pfe: HEAP malloc(0) detected! when a VPLS instance is deactivated in ACX5048.
Product-Group=junos
dc-pfe: HEAP malloc(0) detected! when a VPLS instance is deactivated in ACX5048. This are informational messages and the fix of this PR hides the messages from console output.
PR NumberSynopsisCategory: JUNOS Dynamic Profile Configuration Infrastructure
1797305The KRT queue stuck resulting in subscriber traffic loss
Product-Group=junos
On Junos MX platforms with subscriber dynamic profile versioning, following a commit configuration command, the krt ( Kernel routing table) queue becomes stuck on the master Routing Engine (RE), causing loss of subscriber traffic and subsequent client restarts. This occurs due to a large number of queued entries, resulting in blockage of the KRT queue.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1752374Subsequent commits hang will be seen, when transfer-on-commit fails
Product-Group=junos
On all Junos Evolved platforms, When transfer-on-commit is configured and it fails as the destination is unreachable or invalid, commit lock taken by automatic rollback commit is not released. Due to this, subsequent commits result in a hung state.
1783888[Junos OS Evolved] Traceoptions log sometimes shows UTC timestamp, although non UTC time-zone is configured
Product-Group=junos
On all Junos OS Evolved platforms, traceoptions log sometimes shows UTC timestamp, although non UTC time-zone is configured.
PR NumberSynopsisCategory: EX4100 RE, Platform Infra, Drivers
1775479Peer device ports connected to Gigabit Physical ports of EX4100 transition to up state momentarily during reboot of EX4100
Product-Group=junosvae
When Junos EX4100 undergoes reboot or power cycle, peer device ports connected to GPHY (Gigabit Physical) ports of EX4100 transition to up state momentarily and can impact traffic on the peer device.
PR NumberSynopsisCategory: EX4400 PFE software
1790316The access port is dropping a VLAN-tagged packet of which the interface is a VLAN-member
Product-Group=junos
On all Junos EX and QFX5K platforms supporting Virtual Extensible LAN protocol (VXLAN), the access ports drop Virtual Local Area Network (VLAN) tagged traffic of the same VLAN for which the interface is configured. Though ideally, the access port should be accepting only untagged traffic, because of customer requests the access ports were made to accept tagged packets of which the interface is a VLAN member along with untagged traffic.
1795545On all Junos EX platforms rewrite rules does not work properly when multiple interfaces are configured
Product-Group=junos
On all EX Junos platforms enabled with CoS, if there is rewrite-rule applied to the multiple interfaces, the rewrite-rule which is present for only one of the logical interfaces might work as expected due to this issue.
PR NumberSynopsisCategory: EX4400 platform
1759351EX4400:PSM is not detected in "show chassis hardware" until AC feed is connected to it
Product-Group=junos
The Power Entry Module (PEM) after insertion will not be detected/displayed in the show chassis hardware CLI output , until the power feed is connected .
PR NumberSynopsisCategory: EX Entry Level Access VC platform
1778873In Virtual-Chassis mode, the EX4100 switch might not boot up upon triggering a manual reboot
Product-Group=junos
On all EX4100 Virtual-Chassis, any Virtual-Chassis member might not boot up if one of the Virtual-Chassis members was Power-off by CLI ?request system power-off member ? in past.
PR NumberSynopsisCategory: Express PFE CoS Features
1789302Traffic loss observed with line rate jumbo frames
Product-Group=junos
On Junos QFX10K platforms, during throughput/latency test, 30% traffic loss is observed when loading a line rate traffic with jumbo frames.
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1677422QFX10000 series platforms generates error messages constantly and IPv6 routing is not performed when configured rpf-check and inet6 on VXLAN enabled interface and trying to resolve arp ndp
Product-Group=junos
With rpf-check (enabling reverse-path forwarding) and ipv6 configured on VXLAN (Virtual Extensible LAN) enabled interface, trying to resolve arp ndp nexthop, error messages are constantly observed and ipv6 routing failed. For the ipv6 routes which point to the IPv6 ndp (Neighbor Discovery Protocol) nexthop, the fdb entry needed more space than the allocated space. As a result, PFE was unable to add this entry into fdb and IPv6 routing was not performed.
1779890On QFX10002-60c platforms, during system reboot and fpc reboot time, some non functional error logs are displayed.
Product-Group=junos
On QFX10002-60c express based Junos platform the error logs are seen during boot time. These errors are not impacting any functionality. The table is getting programmed correctly. These are seen during system reboot and fpc reboot time. We will be emitting the logs for non default routing instances and not for default routing instance.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1772126Firewall filters will not work if IRB interface and layer 2 filter attached to BD is configured in SP style on QFX10K platforms
Product-Group=junos
On Junos based QFX10002/10008/10016 platforms running 22.3R1 and higher releases with policers configured in firewall filter and Interface Routing and Bridging (IRB) interface and Layer 2 filters attached to Broadcast Domain (BD) has Service Provider (SP) style Interface logical (IFL) configuration, firewall filter fails to filter traffic.
1779527At the interface level, only half of the traffic is policed when applying a policer
Product-Group=junos
On QFX10002-36q, QFX10002-72Q, QFX10008 and QFX10016 platforms, when applying a policer at the interface level only half of the traffic is policed.
PR NumberSynopsisCategory: Express PFE L3 Multicast
1774562PIM join are not learnt for multicast IPs
Product-Group=junos
On Junos PTX platforms, with PIM BIDR (Protocol Independent Multicast- Bidirectional) mode with "set protocols pim rp bidirectional address <> group-ranges <>" configuration, PIM/MLD joins will not be learnt for multicast IPs other than link local IP and MY IP which will lead to traffic impact. Also, lo0 filter which were introduced with PR 1701756 for IGMP and MLD will be applied only for MY IPs and Link local IPs. For any other IPs other than above, lo0 filter will not work.
PR NumberSynopsisCategory: SRX1500 platform software
1751496On SRX1500 PEM Alarms are displayed due to hardware limitations to read I2C
Product-Group=junosvae
On SRX1500 Hardware Limitation leads to PEM I2C Failure Alarm triggered as result of failure in I2C reading operations.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1739559SRX4100/4200 accepts the datapath-debug configuration although it does not support it
Product-Group=junos
It is possible to set and commit the datapath-debug configuration on platforms SRX4100/SRX4200 although datapath debugging is not supported on those platforms. because of this unsupported configuration being accepted the RE (Routing Engine) load can go high and cause traffic outage. The workaround is to remove the datapath-debug configuration and perform a commit.
PR NumberSynopsisCategory: IDP policy
1786822The flowd process crash is observed when the device is rebooted
Product-Group=junos
On all Junos SRX platforms, flowd crash is seen when the device is rebooted and a CLI request for Intrusion Detection and Prevention (IDP) counters reaches the Packet Forwarding Engine (PFE) before the IDP memory module is initialized (even if IDP is not configured). The flowd process restarts affecting the traffic.
PR NumberSynopsisCategory: MX Inline Jflow
1798466With scaled routes and flex-flow-sizing configured memory exhaustion will lead to an FPC crash
Product-Group=junos
On all Junos MX platforms with LC(Linecard) MPC (Modular Port Concentrator)4-9 installed, the Linecard crash can be seen in the corner case. This issue will be seen when Jflow is configured with the inline-services flex-flow-sizing enabled and 'flow-table-size' near the total capacity is configured. There will be a traffic impact due to the crash.
PR NumberSynopsisCategory: BSDX Software installation issues
1783119Delays can be seen while the upgrading process runs due to the status of UFS set to mode enable.
Product-Group=junos
In USF mode enabled router, While upgrading router having scaled services AMS config with "load-balancing-options disable-hash", Router continuously dumps "'disable-hash' knob is only allowed in USF mode" error. This delays the bootup time with scaled config.
PR NumberSynopsisCategory: ISIS routing protocol
1782887Traffic blackhole due to Flex-algo not removing stale entries from ISIS database
Product-Group=junos
On all Junos and Junos Evolved platforms, in an ISIS scenario using Flex-algo , the system does not remove the stale (outdated) entries from the ISIS database causes traffic blackholing. This issue could lead to some traffic loss, as the routing information stored in the ISIS database does not get properly updated.
PR NumberSynopsisCategory: jdhcpd daemon
1743611DNS received through DHCP is lost after a commit and not able to ping internet
Product-Group=junos
If name-server information is changed via CLI after the DHCP subscribers are up, DNS obtained from DHCP server is overwritten by local config. This may result in DNS look up failures in some cases.
1769598The jdhcpd prcoess crash will be observed due to double free of memory allocation when DHCP ALQ is configured
Product-Group=junos
On MX platforms , when DHCP ALQ ( Dynamic Host Configuration Protocol Active Lease Query ) is configured and subscriber management is enabled, the jdhcpd process crash will be observed due to double free of memory allocation. The DHCP services will be down and it will restore once jdhcpd process is restarted.
1775108DHCP ALQ subscribers may not logged out after TCP connection is removed on all Junos platforms
Product-Group=junos
On all Junos platforms with ALQ (Active-Lease Query) enabled with DHCP(Dynamic Host Configuration Protocol ) relay agent configuration, with inflight subscribers login & logout and TCP connection reset, the DHCP subscribers may not properly release their IP address leases from a backup DHCP Relay, leading to inaccurate IP address management and allocation for the subscribers. This can lead to traffic impact for subscribers who are not released.
1778876DHCP Server in ALQ redundancy: DHCP ACK on renew does not include option 1 subnet mask after failover
Product-Group=junos
With DHCP Local Server with Active Lease Query, the DHCP ACK on the DHCP Renew after failover to the back-up server does not provide a response for option 1 subnet mask
PR NumberSynopsisCategory: Flow Module
1762568Unable to download a file completely from SaaS server to LAN
Product-Group=junos
TCP sessions are not refreshed when enabled the "set security flow gre-perf-acceleration" is configured.
1777565Packet drops will be observed in GRE scenarios on SRX and vSRX platforms
Product-Group=junos
On SRX and vSRX platforms, when Generic Routing Encapsulation (GRE) tunnels are configured, packet drops will be observed when packets enter to a tunnel.
1779260ISSU upgrade to 21.4+ on SRX5k or SRX4600 may lead to a flowd coredump
Product-Group=junos
On SRX5000 series and SRX4600, performing ISSU (In-Service Software Upgrade) to Junos version 21.4 and higher from earlier Junos versions can lead to a flowd coredump occurring during the ISSU process. The coredump would occur on the already upgraded node while the sessions are getting synchronized from the node which is not upgraded yet.
1783595PMI sends packets to the wrong destination
Product-Group=junos
On SRX platform, when the next-hop changes, the PowerMode Ipsec (PMI) induces the packets to be sent to the wrong destination, causing packet drops.
1791633Packets over GRE or IPIP or GRE(PMI) will not reach destination
Product-Group=junos
On Junos platforms with GRE or GRE(PMI) or IPIP tunnels, when tunnel TTL(Time To Live) is set to 1 in the CLI, the traffic sent over GRE or IPIP or GREoIPSec tunnel does not reach its destination.
1798041On Juniper SRX platforms GTP-U packet destination port gets duplicated to the source port and subsequently discarded by policy.
Product-Group=junos
On Juniper SRX devices with GTP-U distribution feature enabled, GTP-U source port will get duplicated as same as the destination port in the traffic from the server back to the source and blocked by the security policy. Due to this, all impacted reverse GTP-U packets will be discarded.
PR NumberSynopsisCategory: SRX Firewall Authentication
1804149The sxrpfe and fwauthd crash will be seen
Product-Group=junos
On all SRX platforms, the sxrpfe and fwauthd crash will be seen. The srxpfe crash is caused from the fwauth plugin in the PFE side of SRX and the fwauthd crash is caused by the fwauthd daemon running on RE side of SRX due to buffer overflow.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1759738ADVPN connection-limit shortcut limitation not working as expected
Product-Group=junos
On all SRX series platforms, the number of shortcut VPN tunnels exceeds the connection-limit configured for an ADVPN partner in the IKE gateway configuration
1783738The kmd/iked process crashes under rare circumstances
Product-Group=junos
On Junos SRX/MX platforms, VPNs (Virtual Private Network) that employ the use of KMD (ipsec-key-management) or IKED (ike-key-management) may inadvertently crash while generating the random number used by IPSec services which can cause the device to become very busy.
1784752High RE CPU observed on both nodes in chassis cluster due to jsrpd
Product-Group=junosvae
High RE (Routing Engine) CPU caused is caused by jsrpd (Junos stateful redundancy protocol daemon) on both the nodes in a chassis cluster configured with control link Encryption (Internal SA) after upgrading the cluster.
PR NumberSynopsisCategory: Security platform jweb support
1788364J-Web default session limits has been aligned with CLI default values
Product-Group=junos
If session limit not configured in cli, default value of session limit will be 7 for Seige models and 1024 for other models
PR NumberSynopsisCategory: Layer 2 Control Module
1770053xSTP configured interface will remains in discarding state
Product-Group=junos
On all Junos and Junos OS Evolved Platforms, when an interface is added inside RSTP (Rapid Spanning Tree Protocol), VSTP (VLAN Spanning Tree Protocol), MSTP (Multiple Spanning Tree Protocol) or STP (Spanning Tree Protocol), because of STP port creation fail from l2cpd (Layer 2 control protocol daemon), port will remains in discarding state. This leads to traffic impact.
1787892Interface configured with BPDU-disable goes down during VC mastership switchover
Product-Group=junos
On Junos EX3400/EX4300/EX2300 platforms configured with VC (Virtual Chassis) and NSB (Nonstop-Bridging) enabled, when VC mastership switchover is triggered, the configuration under 'set protocols layer2-control bpdu-block interface ' will not take effect due to which the interface will go down and will impact the traffic. The configuration 'set protocols layer2-control bpdu-block interface all' will not have any impact.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1757692The ksyncd and vmcore core will be seen on backup RE when GRES is configured
Product-Group=junos
This issue is seen on all Junos platforms when MAC-limit/storm-control feature is configured with action shutdown, and after interface shutdown action has taken effect. When the customer issues "clear ethernet-switching recovery-timeout" or interface recovery timeout expires and recovery time is configured via "set interfaces unit family ethernet-switching recovery-timeout ". After the interface recovers, if the customer configures GRES, the ksyncd and vmcore core will be seen on backup RE.
1772424Connectivity between static and LDP signaled pseudowires broken in VPLS after upgrade and results in VPLS traffic drop
Product-Group=junos
On all Junos and Junos OS Evovled platforms, when there is a upgrade and also when one mesh group of routing instance is substring of other, the connection between static and LDP (Label Distribution Protocol) signaled psuedowires is broken will lead to traffic drop.
1776991ARP resolution issues will be observed in the H-VPLS environment
Product-Group=junos
On Junos and Junos Evolved platforms, traffic impact will be observed due to ARP (Address Resolution Protocol) resolution issues when multiple mesh-group is configured under the same routing-instance and the name of each mesh-group is not unique i.e. substring of another mesh-group in the H-VPLS (Hierarchical Virtual Private LAN Service) environment.
1790064The l2ald process will crash, with rapid configuration changes followed by rpd and l2ald restart process
Product-Group=junos
On all Junos and Junos OS Evolved platforms with EVPN -VXLAN and high scaling configuration, rapid configuration changes followed by restart of rpd and l2ald will result in l2ald process crash and traffic drop will be observed.
PR NumberSynopsisCategory: lacp protocol
1783793All AEs bundles configured in Active-Standby mode for EVPN-MPLS routing-instances will flap on the first commit post a fresh system reboot
Product-Group=junos
On all Junos MX and EX platforms with MPC family of line cards, all the Aggregated-Ethernet (AEs) bundles configured in Active-Standby mode for Ethernet Virtual Private Network-Multiprotocol Label Switching (EVPN-MPLS) routing-instances on the system will flap on the first commit after a fresh system reboot.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1755735EX4650 flex license: After expiry the number of licenses installed increases to 1000
Product-Group=junos
Ensure the License Key has the correct capacity value for non-capacity features.
1792672License is lost on NG-RE platforms after device/routing-engine reboot
Product-Group=junos
On NG-RE (Next Generation Routing Engine) platforms, license is lost after restarting device/routing-engine. If any service depends on that license, that service will be impacted.
PR NumberSynopsisCategory: PTX1000 platform
1770739Reboot on PTX1k with image 22.3x60 causes fpc to reboot with "Fatal ASIC initialization error, Offlining FPC" Error message
Product-Group=junosvae
Reboot on PTX1k with image 22.3x60 causes fpc to reboot with "Fatal ASIC initialization error, Offlining FPC" Error message times
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1729467MACsec interoperability issue between Juniper and non Juniper platforms
Product-Group=junos
On all Junos and Junos Evolved platforms with MACsec (Media Access Control security) configured , frequent SAK (Secure Association Key) rollover is observed when the peer device is a non-Juniper box and the Juniper device is acting as the key-server. This results in unstable MACsec sessions between the juniper device and the non Juniper device.
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1762114Linecard loses all fabric planes when another linecard is powered off ungracefully
Product-Group=junos
On MX2020/MX2010/MX10K4/MX10K8 platforms and MPC11E, LC9600, LC4800 line cards , linecard loses all fabric planes (no links active) and takes all interfaces down when another linecard is powered off ungracefully .
PR NumberSynopsisCategory: MX Timing software
1781161After a GRES the MX external clock is stuck in a Holdover State
Product-Group=junos
After a GRES the MX external clock is stuck in a Holdover State
PR NumberSynopsisCategory: Track Mt Rainier RE platform software issues
1782062The interface fxp0 deactivation or activation is not captured due to improper date format
Product-Group=junos
On all VMhost platforms, the interface fxp0 state is not captured since the script to bring up the interface is not parsing the output from the date field.
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1717843JUNOS - FILE COPY - Secure file copy using VRF succeeds even on disabling VRF
Product-Group=junos
JUNOS - FILE COPY - Secure file copy using VRF succeeds even on disabling VRF
PR NumberSynopsisCategory: PFE Peer Infra
1801535CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log
Product-Group=junos
On all Junos platforms, CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log. This log is not an error log but still printed under LOG_ERROR and flooded with default log level. This causes restart which will impact normal user traffic.
PR NumberSynopsisCategory: TCP/UDP transport layer
1700438The TCP sessions for BGP are closed on the backup RE
Product-Group=junos
On all Junos Platforms, if the interface configuration is altered to switch from one routing instance to another it might result in the closing of BGP session on the Backup Routing Engine.
1738361tcp md5 authentication mismatch logs are not seen in /var/log/messages [tcp_auth_ok: Packet from X.X.X.X:XXXXX wrong MD5 digest]
Product-Group=junos
from 21.3R2 release onwards these are logs not seen in /var/log/messages.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1753191ARP resolution failure for lt interfaces is observed after cluster failover on Junos SRX platforms
Product-Group=junos
On Junos SRX platforms in cluster, Address Resolution Protocol (ARP) resolution fails for logical tunnel interfaces when the logical tunnel interfaces are toggled and the cluster switchovers.
PR NumberSynopsisCategory: OSPF routing protocol
1793148LDP label advertisement is stopped for approximately 25 seconds when micro loop avoidance is enabled in SR over OSPF
Product-Group=junos
On all Junos platforms that support MLA (Microloop Avoidance), the LDP (Label Distribution Protocol) label advertisement gets stopped for approximately 25 seconds when MLA is enabled in SR (Segment Routing) over OSPF (Open Shortest Path First) and the interface between LDP (Label Distribution Protocol) domain and SR domain is down and coming up.
PR NumberSynopsisCategory: Protocol Independant Multicast
1792886The rpd crash is observed when PIM SSM mode with RPF-Vector and MoFRR is configured
Product-Group=junos
On Junos and Junos Evolved platforms , when PIM SSM (PIM Source-Specific Multicast) with RPF (Reverse Path Forwarding)-Vector and MoFRR (Multicast-only fast reroute) is configured , rpd crash if the device receives PIM Prune message for (S, G) state with RPF vector TLV. interface is freed for the (S, G) from the outgoing interface list i.e. RPF-Vector TLV (Type, Length, and Value) having (S, G) is getting freed but that same (S, G) is still used by MoFRR. The issue happens when MoFRR Backup upstream interface is also listed at the outgoing interface list for the (S, G)
1795964The rpd process crash is seen when routing-instances name length is greater than 60 characters
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Protocol Independent Multicast (PIM) enabled under Routing-instance, the Routing Protocol Daemon (rpd) process crash is seen when the routing instance (RI) name length is greater than 60 characters. Due to the rpd process crash, protocols will be impacted and traffic loss will be seen.
PR NumberSynopsisCategory: vMX Platform Infrastructure related issue tracking
1729152The FPC crash or flap in protocols will be seen as soon as port-mirroring or firewall filters with syslog action is enabled
Product-Group=junos
On MX150 platform, when port-mirroring or firewall with syslog configuration is enabled, there will be a memory leak which will cause depletion of buffer memory which will lead to flap in the protocols or the (Flexible PIC Concentrators) FPC crash. This will impact the traffic.
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1782239After Routing Engine switchover PPPoE subscribers may fail to login
Product-Group=junos
On all Junos OS on MX Platforms, after Routing Engine (RE) switchover using BNG for PPPoE (Point-to-Point Protocol over Ethernet) subscribers, may impacting customers authentication or failing to connect.
PR NumberSynopsisCategory: for all ipv6 related issues
1775394EX/QFX: fails to ping ipv6 link local address in routing instance if there is a default route in the same instance.
Product-Group=junos
On QFX5K, EX4300-MP, EX4400 or EX4100 series switch with VXLAN, ping to ipv6 link local address in routing instance would be failed. This issue affects only to the traffic which is sent to Link Local IPV6 Interfaces when the interface is an IRB along with VXLAN configuration.
PR NumberSynopsisCategory: QFX L2 PFE
1781955A few AE interfaces will drop traffic when a large number of AE interfaces are deleted and added back
Product-Group=junos
On EX4100, EX4100 Multigigabit, EX4100-F, EX4400, EX4400 Multigigabit, EX4650-48Y, QFX5120-48Y, QFX5120-32C, QFX5120-48T, QFX5110 and QFX5120-48YM platforms with Ethernet VPN-Virtual Extensible LAN (EVPN-VxLAN) configured, a few AE interfaces will drop traffic when a large number of Aggregated Ethernet (AE) interfaces are deleted and added back. When this issue happens AE interfaces will be UP but traffic would be dropped.
1797516DCPFE process crash occurs in EVPN-VXLAN scenario
Product-Group=junos
When a vport, which is a memory pointer, is a member of an itable list, the entry in the itable should be removed before freeing the vport. For some corner case, the vport is not removed from the itable when freeing the vport. The freed memory or the reused memory corrupts the itable list and it crashes when performing some operation on the corrupted list.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1782762MTU Adjustment on Junos QFX5K platforms with GRE Causes FPC and Link Partner FPC Reboots
Product-Group=junos
On Junos QFX platforms with Generic Routing Encapsulation (GRE) tunnels enabled, when attempting to adjust the MTU (Maximum Transmission Unit) configuration of a physical interface, a reboot of the FPC is triggered which would leads to crash and impacts the traffic.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1774366The dcpfe process crash due to stale memory
Product-Group=junos
On Junos QFX platforms, stale memory references are causing dcpfe crashes triggering PFE (Packet Forwarding Engine) to restart resulting in traffic disruptions.
1778725Traffic drop is observed when VIPs become unreachable due to GARP sent on VLANs to which the VIP does not belong
Product-Group=junos
Under a rare scenario, on all Junos and Junos Evolved platforms configured with EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible Local Area Network) type 5 routes, Bridge-Domain, IRB (Integrated Routing and Bridging) and having L4 (Layer 4 device like an application load balancer) devices as single-homed with each border leaf and when VIP (Virtual Internet Protocol) entries are learnt on a leaf and L4 failover happens, it is observed that the VIPs announced by GARP (Gratuitous Address Resolution Protocol) is sent on VLANs that the VIP does not belong to and the incorrect GARP is not handled as per the expectation.
1783397The fxpc process crash and the device reboots after deleting Aggregated Ethernet (AE) Interface along with its associated physical interface and then applying new interface configuration on the associated physical interface in an EVPN-VXLAN scenario
Product-Group=junos
On an Ethernet Virtual Private Network (EVPN) / Virtual eXtensible Local-Area Network (VXLAN) scenario, after removing an Aggregated Ethernet (AE) Interface along with its associated physical interface on a QFX5k series device and then applying any configuration to the physical interface, the fxpc process crashes and the device undergoes an automatic reboot.
1802958ECMP programming issue on Junos QFX5K/EX4K in EVPN-VXLAN
Product-Group=junos
In rare scenarios on Junos QFX5K/EX4K platforms that are part of Ethernet VPN - Virtual extensible LANs (EVPN-VXLAN) Fabric topology and employing ECMP (Equal Cost Multi-path) routing on the underlay interfaces between the Leaf and Spine, if one or more of these physical underlay interfaces flaps or their associated underlay protocol adjacency flaps and this time aligns precisely with the associated unicast next-hop deletion process, a race condition may occur, resulting in the potential failure to program the associated ECMP interface next-hop entry correctly in the hardware table.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1797511[JDI-RCT-EVPNVXLAN-L2Stitching]: DCPFE core observed on QFX10k while running profile baseline in 22.2R3-S3.18 image
Product-Group=junos
In very rare instances of a large config commit, on the QFX10002-36Q routers, the dcpfe can core due to watchdog timeout. After the core, the dcpfe respawns and the system functions normally without any manual intervention.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1779624On the QFX5110-48S platform the virtual chassis port goes down when the VC is upgraded or the VC ports are deleted and added back
Product-Group=junos
One of the virtual chassis ports in a VC of QFX5110-48S goes down either by deleting or adding the port or by upgrading the virtual chassis thereby causing a loss of redundancy for the virtual chassis ports. The ways to recover are by re-creating the VC or by doing soft removal and insertion of the port (please contact JTAC for the same).
PR NumberSynopsisCategory: RPD Interfaces related issues
1798801MPLS/RSVP LSP self-ping behaviour differs from expected behaviour causing self-ping time out
Product-Group=junos
On Junos OS Platforms, configured with Multiprotocol Label Switching (MPLS)/Resource Reservation Protocol(RSVP) Label Switched Path(LSP) and firewall filter applied on the loopback with prefix list that does not include the interface address of local router, self-ping time out is observed.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1761667The rpd process and chassisd process crash is seen
Product-Group=junos
On Junos and Junos Evolved platforms configuring BGP causes the rpd to crash abnormally and later chassisd crashes too.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1785884The rpd crash is observed due to segment fault
Product-Group=junos
On Junos OS Evolved platforms, when no acknowledgment is received from PFE (Packet Forwarding Engine) within timeout results in the rpd (Routing Process Daemon) crash. This issue happens when routes requesting acknowledgment do not receive acknowledgment leading to segment fault.
1793196Multicast traffic black-holing upon MoFRR primary link went down
Product-Group=junos
On all Junos and Junos Evolved platforms, when MoFRR (Multicast-only fast reroute) is configured with NSR (Non-stop routing) while interface flapping or RE switchover, there is a next-hop leak and the next-hop in RIB (Routing Information Base) is different from the next-hop in FIB (Forwarding information base) due to that multicast traffic will be impacted.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1746439Route-distinguisher change leads to the route being present in rpd, but not installed in kernel/PFE
Product-Group=junos
On Junos and Junos Evolved platforms, traffic impact will be observed when route-distinguisher change is performed for which route will be present in rpd, but not installed in kernel/PFE. This issue happens when the aggregate route is configured.
PR NumberSynopsisCategory: PTX10K specific platform PRs
1766097PTX10008: When NSR Enabled and FMBB Knobs are configured and if SIB is Offline/Online casue resiliencyd core
Product-Group=junos
PTX10008: When NSR Enabled and FMBB Knobs are configured and if SIB is Offline/Online casue resiliencyd core
PR NumberSynopsisCategory: SW PRs for SCBE3 chassisd
1745442Traffic impact is observed on Junos MX platforms due to the chassisd crash
Product-Group=junos
On Junos MX240/MX480/MX960 platforms with SCBE3 (Enhanced Switch Control Board), when RE (Routing Engine) is switched over by any event, the chassisd crash is seen on the new master RE due to which all the line cards will reset and the traffic will be impacted.
PR NumberSynopsisCategory: Issues related to control plane security
1781732Junos OS and Junos OS Evolved: Impact of Terrapin SSH Attack (CVE-2023-48795)
Product-Group=junos
An Improper Validation of Integrity Check Value vulnerability in OpenSSH before 9.6 of Juniper Networks Junos OS and Junos OS Evolved allows a remote attacker to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka the Terrapin Attack. Please refer to https://supportportal.juniper.net/JSA76462 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1801201IKE is not coming up with dhgroup19 and dhgroup20
Product-Group=junos
IKE is not coming up with dhgroup19 and dhgroup20. The below Junos releases are impacted. junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3-S1 junos:24.1R1. So previous to these releases dhgroup19 and dhgroup20 should be working.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1691986Consistent high CPU usage is seen on the device post reboot
Product-Group=junos
On all Junos and Junos Evolved platforms consistent high CPU usage in snmpd immediately after reboot.
PR NumberSynopsisCategory: SRX branch platforms
1714620High latency will be observed while pinging to peer device
Product-Group=junos
On Branch SRX Platforms, The delay will be observed while pinging to peer device due to high latency when VLAN(Virtual Local Area Network) tagged DHCP(Dynamic Host Configuration Protocol) packets arrive at IRB (Integrated Routing and Bridging) interface.
1770303Inter and intra VLAN traffic drop can be seen on the SRX branch series
Product-Group=junos
On all Junos SRX branch series devices, intra and inter-VLAN (Virtual Local Area Network) traffic drop will be seen when the devices are running in ethernet-switching mode and STP(Spanning Tree Protocol) is configured on the respective interface for the VLANs.
1776656Interfaces stay down when 1G SFP fiber transceiver connected to SRX380 platform
Product-Group=junos
Ports are staying down on SRX380 platform with 1G SFP fiber transceiver while trying to connect to a device that doesn't support auto-negotiation and/or having hard-coded speed and duplex setting
1780326IP Monitoring fail to install route after SRX cluster reboot
Product-Group=junos
On Junos SRX branch series platforms in cluster, the IP Monitoring fails to install route after the SRX cluster reboots.
PR NumberSynopsisCategory: SSL Proxy functionality on JUNOS
1788673The flowd crash will be observed when the TLS 1.3 session ticket is received on SSL-I
Product-Group=junos
On SRX platforms with SSL (Secure Sockets Layer) Proxy configured, due to timing synchronization issues, while doing multiple session tickets check on SSL_I [initiator on the server side], and SSL_T [terminator on the client side] updating the session cache and releasing the session cache resources resulting in proxy session info cleared & causing the flowd crash at SSL_I. The issue happens when the SSL_I (Server) is using TLS1.3 and SSL_T (Client) using TLS1.2.
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1768592The SFB3 will go offline during during SFB3 < -> ADC < -> MPC7E link initialization
Product-Group=junos
On MX2020 and MX2010 platforms with Switch Fabric Boards (SFB) 3 and Modular Port Concentrators (MPCs) MPC7E-10G or MPC7E-MRATE inserted via Adapter Card (ADC) MX2000-LC, SFB3 will go offline during SFB3 < -> ADC < -> MPC7E link initialization with a fatal error. This is a timing issue and will not be seen with every SFB3 < -> ADC < -> MPC7E link initialization. It happens because of a race condition between certain events occurring during MPC initialization.
1769983At MX2020 with SFB3 and MPC7+ADC in FPC slot 11, link errors in fabric planes 1, 4, 7, 10 will be seen upon MPC7/ADC restart in FPC slot 11
Product-Group=junos
On the Junos MX2020 with SFB3 and MPC7+ADC in FPC slot 11, link errors in fabric planes 1, 4, 7, and 10 will be seen upon MPC7/ADC restart in FPC slot 11. The link errors will come along with the 'failed word alignment' syslog message logged by hsl2_channel_train_hsl2_rx(). In the rare scenario, the traffic impact will be observed as some of the fabric links do not come online.
PR NumberSynopsisCategory: SRX-1RU infrastructure SW defects
1784983Chassis alarm not present for if /var partition usage exceeds 100%
Product-Group=junos
When /var partition disk space is greater than 100%, "RE 0 /var partition usage is high" chassis alarm gets cleared
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1775083Traffic drop observed right after boot up on Junos SRX 4600 platforms
Product-Group=junosvae
On SRX 4600 platforms running the Field Programmable Gate Array (FPGA) firmware versions 163, 165, 171, 175 the Packet Forwarding Engine (PFE) may experience a 25% drop in performance after bootup.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1795940The ARP resolution will fail on the interface when the default ARP policer fails to program.
Product-Group=junos
On AFT(Advanced Forwarding Toolkit) based MX platforms, default ARP(Address Resolution Protocol) policer fails because of which ARP resolution fails on the interface and hence the traffic gets impacted.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1792736Transit traffic does not get forwarded in EVPN-VxLAN scenario on Junos MX/EX platforms
Product-Group=junos
On Junos MX240/MX480/MX960/MX2008/MX10004/MX10008/MX2010/MX2020 platforms with MPC10E/11E/LC9600 line cards and MX304 platform and EX9204/EX9208/EX92014 with EX9200-15C line card, in Ethernet Virtual Private Network-Virtual Extensible LAN (EVPN-VxLAN) scenario the transit traffic does not get forwarded due to incorrect inner ethernet header.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1729970L2-Trans: pm_soam_frame_rx count is not incrementing as expected
Product-Group=junos
L2-Trans: pm_soam_frame_rx count is not incrementing as expected
1740606Host communication does not work in EVPN-L2VPN-CCC setup
Product-Group=junos
On Junos MX platforms, in Ethernet Virtual Private Networks-Layer 2 Virtual Private Networks-Circuit Cross-Connect (EVPN-L2VPN-CCC) setup, the integrated routing and bridging (IRB) interface over access logical tunnel (LT) interface is configured, it is sending vlan tagged packet on the access port and not removing it causing the host communication to break.
1743947PFE will wedge for RVTEP connectivity having unilist VENH
Product-Group=junos
On all Junos MX platforms, in a rare scenario when the Remote Virtual Tunnel Endpoint (RVTEP) IP routes are pointing to unilist Virtual Extensible Local Area Network (VXLAN) Encapsulated Nexthop (VENH) and all the underlay ports of the VXLAN tunnel go down, then the Packet Forwarding Engine (PFE) will detect traffic congestion and will wedge with CM_Error alarms.
1745803During multicast traffic flow , 'sw error' discard count is incrementing continuously
Product-Group=junos
On all MX series platforms, Multicast over IRB with receivers spanning across PFEs then some vty exception counters which keeps incrementing.
1751846[MX480/MX240] Multicast ping ff02:: 1 cannot perform reply on MX240/480 platform from MX204 via VXLAN
Product-Group=junos
When MX204 and MX240/MX480 connected over static VxLAN with IPv6 underlay and IPv6 configured on IRB interface, Multicast ping with IPv6 address will fail while trying multicast ping with IPv6 address from MX204, ICMP response is not received from MX240/MX480 when other FPC is online.
1781673L2 control packets may be dropped on JUNOS devices in VPLS scenario on certain MX platforms
Product-Group=junos
On certain Junos MX platforms, in the VPLS (Virtual Private LAN Service ) scenario, the L2 (Layer 2) control packets with a multicast destination MAC (Media Acess Control) address are dropped if they arrive on the VPLS core-facing interface placed on MPC (Modular PIC Concentrator)10/MPC11 linecards or MX304 router
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1797496Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
Product-Group=junos
Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
PR NumberSynopsisCategory: MGD issues being found in cMGD environment
1723551On containerised platforms, change in configuration is not propagated to existing CLI sessions.
Product-Group=junos
When configuration change is committed, this change is not informed to existing CLI sessions on containerised platforms like cRPD. So, user needs to close existing CLI sessions and use new CLI sessions after configuration change is committed.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1718063After deleting commit scripts with transient changes, the changes do not take effect
Product-Group=junos
On Junos OS Evolved ACX7100-32C / ACX7100-48L / ACX7509 / PTX10001-36MR / PTX10003 / PTX10004 / PTX10008 / PTX10016 platforms, when a commit script with transient configurations is deleted, daemon does not see the change after commit.
1718692Configuration update via python script does not work
Product-Group=junos
 
1770643RPD core seen when groups is activated before corresponding 'apply-groups' in configuration
Product-Group=junos
On all Junos and Junos Evolved platforms, when the group is activated after the corresponding 'apply-groups' statement configuration, rpd core is seen.
1772201unexpected commit error - error: VLAN-ID must be specified on tagged ethernet interfaces
Product-Group=junos
unexpected commit error like 'error: VLAN-ID must be specified on tagged ethernet interfaces', due to 'commit check' reset internal flag incorrectly after load overide configuration in rare condition.
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1787147The sdp process crashes when trying to add a new satellite device to the network
Product-Group=junos
In the Junos Fusion setup, the sdp (Satellite Discovery and Provisioning Daemon) process crashes repeatedly when trying to add a new satellite device to the network. This issue happens when the MD5 encrypted data is read as a string, in which the string validation code throws errors when the first byte of MD5 encrypted data is 0.
PR NumberSynopsisCategory: MX10K platform
1784080FPC reboot seen on MX platforms with PMB memory correctable errors
Product-Group=junos
On all MX platforms that support MPC7/MPC8/MPC9/MX10k-LC2101/EX9200-40XS/EX9200-12QS, an unexpected FPC (Flexible PIC Concentrator) reboot may be seen along with PMB memory correctable errors. Service impact can be seen till the FPC restart completes.
PR NumberSynopsisCategory: For GPRS security features on highend SRX series
1736985Cores are observed on both the nodes of SRX HA cluster setup when it's upgraded to 21.2 and above
Product-Group=junos
On Junos SRX high-end platforms configured with GTP (GPRS Tunneling Protocol), during the upgrade of an SRX High Availability (HA) cluster, a crash occurs on the nodes when processing GTP packet traffic. This persistent crashing prevents the system from restarting and impacts service availability.
PR NumberSynopsisCategory: VMHOST platforms software
1726621Root user is unable to login using public key authentication after reboot or upgrade
Product-Group=junos
On all MX & EX92XX series platforms with NG-RE running Junos OS 21.4R1 or higher releases, the root user is unable to login using public key authentication (RSA Keys) after reboot or upgrade and prompts for a password even when password less authentication is configured.
PR NumberSynopsisCategory: usf nat related issues
1776355Internet traffic destined for the NAT pool address (Network Address Translation) will loop after configuration changes
Product-Group=junos
On Junos MX platforms, with MS-MPC and SPC3 service cards, Change in "interim-logging-interval" configuration can lead to UDP traffic get looped and it will impacting CPU utilisation and traffic drop can be seen.
 

 




 

Modification History

First publication 2024-06-03