Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 22.2R3-S4 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

 

Junos Software service Release version 22.2R3-S4 is now available.

22.2R3-S4 - List of Fixed issues 

PR NumberSynopsisCategory: EX4300 Layer 2 implementation
1797422DHCP IP assignment will fail on VoIP phone connected to a VXLAN access port
Product-Group=junos
On EX4300-48MP platform, in Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, Dynamic Host Configuration Protocol (DHCP) IP assignment for a Voice over IP (VoIP) phone connected to a VXLAN enabled access port will not work.
PR NumberSynopsisCategory: EX2300/3400 PFE
1695771Traffic loss is seen when a MAC moves from dot1x port to non-dot1x port
Product-Group=junos
On all Junos and Junos OS Evolved platforms is having dot1x enabled interface. When two or more MAC addresses are learnt on a dot1x port, and if one of them is shifted to a non-dot1x port, the MAC address that was moved is still seen as a MAC-based VLAN entry on the Layer2 Address Learning Manager (l2alm). This could lead to network traffic being lost.
PR NumberSynopsisCategory: EX2300/3400 platform
1772477Turning port beacon LED on or OFF may not change the LED status
Product-Group=junos
On EX2300, turning port beacon LED on or OFF may not change the LED status. There is no service impact due to this.
1781317Error is shown on system when pvidb variable is accessed
Product-Group=junos
On Junos EX platforms, when pvidb variable which is unkown is tried to access from a device, pvidb error messages will be seen, There is no impact on service due to this.
1789272Watchdog SPI transaction is causing the interface flap in the system
Product-Group=junos
On EX2300-MP platforms, when the SPI (Serial Peripheral Interface) bus is accessed by multiple processes simultaneously results in watchdog reset due to the lack of lock-unlock operations. Consequently, this can lead to interface flaps affecting the traffic flow.
1799093[EX2300]"Ethernet Link Down" would not be generated when me0 was down.
Product-Group=junos
On Junos EX2300 device, whenever the Management Interface Link is Down, the alarm was not getting generated as expected.
PR NumberSynopsisCategory: SRX Gen-3 RE, leveraged from Point Success Mt.Rainier
1774760RE switchover observed in SRX5K platforms when ethernet switchports failure scenario on SCB
Product-Group=junos
On SRX5K platforms when all ethernet switch ports on Switch Control Board(SCB) fail, it triggers the Routing Engine (RE) switch over and RE0 is stuck in "Disabled" state. As RE0 is disabled and RE1 does have the functionality to coordinate chassis. No PIC will turn up which were failed and triggered the failover and traffic impact will be there for those particular ports and the complete service impact will be there if RE1 had any issue when RE0 is in disable state. RE0 did not recover by its own from the disabled state until manual reboot is done.
PR NumberSynopsisCategory: SRX ISSU infra related issues
1803376The In-Service Software Upgrade (ISSU) fails in chassis cluster deployment on SRX1500
Product-Group=junos
On SRX1500 platforms, In-Service Software Upgrade (ISSU) fails in chassis cluster deployment with error "timeout waiting for secondary node node1 to sync(error-code: 6.1)".
PR NumberSynopsisCategory: "agentd" software daemon
1715377The agentd would become unresponsive on all Junos platforms
Product-Group=junos
When using Junos Telemetry Interface (JTI) with subscriptions to Packet Forwarding Engine (PFE) based sensors, agentd might slowly leak memory. After prolonged runtime agentd may stop functioning properly, which will affect JTI data export. This will affect telemetry services.
PR NumberSynopsisCategory: MPC Fusion SW
1746643FPC process crash will be observed after performing the ISSU
Product-Group=junos
On Junos MX platforms with MPC2E-3D-NG, MPC3E-3D-NG and MPC2E NG HQoS line cards with MIC -> 10x 1GE(LAN) -E SFP, the Flexible PIC Concentrators (FPCs) process crash will be observed after performing the In-Service Software Upgrade (ISSU).
1777534On MX and EX platform replacing the line-cards may trigger FPC to be offlined due to unreachable destinations
Product-Group=junos
On Junos MX and EX9200 platforms when replacing MPC2E-NG and EX9200-40XS with MPC3E-NG, SCBE3 and EX9200-MPC cards, inserting the new MPC may cause new and other line cards to go offline due to unreachable destinations. This happens due to some registers on the fabric card is not properly updated once the fabric channel bonding has changed and impacts the traffic.
PR NumberSynopsisCategory: Application Quality of Experience
1805493IPsec VPN is getting flapped due to warning messages on MIST controlled devices
Product-Group=junos
On all Junos SRX, vSRX and NFX platforms , commit after deprecated configuration of APPQOE (Application Quality of Experience ) is pushed, will trigger DAX warning on the console which causes iked/kmd process to flap of IPsec VPN ( Internet Protocol Security Virtual Private Network ) and results into traffic outage.
PR NumberSynopsisCategory: SRX2000/50000 issue
1663839Syslog message CHASSISD_IPC_WRITE_ERR_NULL_ARGS are observed at commit
Product-Group=junos
Syslog message CHASSISD_IPC_WRITE_ERR_NULL_ARGS is observed at commit on SRX5K platforms. This is caused by unsupported chassis component connection on SRX5K platforms during commit checks. This syslog message is informational only for SRX5K, and was removed.
1775880A flowd crash is observed if CP receives the packets due to some hardware memory issue
Product-Group=junos
On SRX5K platforms with SPC3 and SPC2 cards, flowd crash will be observed if CP (Central Point) receives the packets due to some hardware memory issue either on IOC (I/O card) or SPC (Services Processing Card) which requires session lookup.
1793262FPC reboot seen on SRX platforms with SPC3 card post RG failover
Product-Group=junos
On SRX5K platforms with SPC3 card, the FPC (Flexible PIC Concentrator) card reboots when a RG0 failover (in chassis cluster scenario) is performed. Due to this, traffic impact can be seen.
PR NumberSynopsisCategory: common or misc area for SRX product
1779749Traffic loss due to PPM not offloading LACP
Product-Group=junos
On SRX5K platforms, the LACP (Link Aggregation Control Protocol) packets are reaching the RE (Routing Engine) instead of ppm (Periodic packet management) which is causing extra strain on RE leading to dcpfe core dumps and causing LACP connections to go down or flap.
PR NumberSynopsisCategory: BBE Layer-2 Bitstream Access
1796125The broadband subscriber (L2BSA subscribers) on the core interface logging out with interface state changes
Product-Group=junos
On all Junos platforms, any configuration changes that involve interface down/up sequence, result in logging-out L2BSA (Layer 2 Broadband Subscriber Access) subscribers associated with that core interface.
PR NumberSynopsisCategory: BBE routing
1781938Access route may get stuck in the routing table after trying to change the prefix length using CoA message
Product-Group=junos
On Junos MX platforms with subscribers management enabled, the access route may get stuck in the routing table failing to update or be removed as expected. This occurs when a user attempts to modify the prefix length associated with this route using a Change of Authorization (CoA) message. This may lead to traffic loss, and if a subscriber goes down following the CoA change, there is a failure to bring that specific subscriber back up.
PR NumberSynopsisCategory: Border Gateway Protocol
1728829In a high scaled environment, high rpd CPU utilization might be observed when a routing related commit is performed
Product-Group=junos
On all platforms, high rpd CPU utilization might be observed when a routing related commit is performed in a high-scaled environment having BGP groups configured with VPN family (inet-vpn, inet6-vpn). No traffic impact or protocol flap will be seen but unexpected high rpd CPU utilisation will raise operational challenges, especially if the system is very scaled.
1781859The rpd process will crash in an EVPN scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, when EVPN-Type 5 (Ethernet VPN-Type 5) and L3VPN (Layer 3 VPN) families are configured and if EVPN routes are advertised to BGP(Internal Border Gateway Protocol) inet-VPN sessions then rpd process crashes. During the rpd crash and restart, the routing protocols will be impacted and traffic disruption will be seen due to the loss of routing information.
1785227Applying aggregate-bandwidth for BGP paths removes all other communities from the advertised routes
Product-Group=junos
On all Junos and Junos Evolved platforms, when load-balancing on BGP is configured with multipath and along with that aggregate-bandwidth knob is enabled, communities are dropped from the routes that are going out. The community attributes are not propagated.
1789863The rpd crash can be seen when large number of VRF instances are created and bgp peering terminated
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) crash will be observed when BGP (Border Gateway Protocol) is terminated by the user and if large number of VRF instances are created. This happens as some BGP internal data structure is not cleaned up properly. This crash can lead to a temporary traffic drop, but the system will automatically recover.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1767785The EOR message is missed for one peer in a scaled BMP scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms with BGP Monitoring Protocol (BMP) enabled in scaled scenario (4K BGP peers, 6 BMP stations), after disabling/enabling BMP, due to timing issues, one out of six BMP stations will not receive End-of-RIB (EOR) message for one peer. This will not impact routing or data forwarding, however will have impact on data collection.
1770976Routes getting stuck in hidden state forever in BMP scenario
Product-Group=junos
On all Junos and Junos Evolved platforms where BMP (BGP Monitoring Protocol) is configured, the routes are not removed from the RIB (Routing Information Base) even when the damping timer expires and they are stuck in the hidden 
PR NumberSynopsisCategory: Track PRs in BGP Flow Spec area & is part of BGP inside RPD.
1740257The inetflow6 routes are not installed on firewall filter table using BGP FlowSpec
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with BGP FlowSpec, ipv6 routes are installed in flow route table but not in firewall filter table. FlowSpec routes are blocked and dropped leading to traffic disruption. This is especially seen when BGP UPDATE Message does not include "Filter: Packet Length filter" within "FLOW_SPEC_NLRI" from BGP flowspec server thereby inetflow6 routes do not have "Action(s)"
PR NumberSynopsisCategory: MX304 Chassis specific platform 
1742483Change of date/time on RE does not sync to FPC
Product-Group=junos
On MX304 platforms, the change of date/time on Routing Engine (RE) does not sync to Flexible PIC Concentrators (FPC).
1798511RE switchover will cause multiple issues on MX304
Product-Group=junos
On MX304 platforms with dual Routing Engine (RE) and configured with Graceful Routing Engine Switchover (GRES), after RE switchover, Packet Forwarding Engine (PFE) information on the secondary RE is not getting properly updated as that on primary RE. This may result in issues like interface flap, protocol flap etc.
PR NumberSynopsisCategory: MX304 virtual platform issues
1794396The upgrade will fail and command will hang when the ISSU is issued
Product-Group=junosvae
On MX304 platform, the In-Service Software Upgrade (ISSU) is not supported but the command to upgrade the image using ISSU is enabled. Hence on executing, the upgrade will fail and command will hang.
PR NumberSynopsisCategory: Virtual-chassis platform/chassisd infrastructure PRs for MX
1798681CHASSISD_IFDEV_RTSLIB_FAILURE: ifdev_create: rtslib_ifdm_add failed (No such file or directory) after creating a virtual interface tunnel
Product-Group=junos
The error messages in question are not-service affecting and would not be noticed by regression scripts.
PR NumberSynopsisCategory: Class of Service
1795898COS output-traffic-control-profile is not getting attached to ps transport IFLs on a specific MX platforms that support HCOS
Product-Group=junos
COS output-traffic-control-profile does not get attached to ps (pseudowire service) transport IFLs when ps interfaces are configured over lt/rlt (logical tunnel/redundant logical tunnel) and both - ps transport IFL and ps service IFLs have COS output-traffic-control-profile configured, TCPs have different SMAPs (scheduler-maps) configured and these COS configuration on both these types of IFLs are committed in a single commit. This can impact COS scheduling on ps transport IFL.
PR NumberSynopsisCategory: QFX Access Control related
1794778Dot1x process crash will be seen in the system with "server-timeout" & "server-fail use-cache" configuration
Product-Group=junos
On all Junos platforms having 802.1x with "server-timeout" & "server-fail use-cache" configuration, 802.1x process crash will be seen. In initial authentication client receives multiple egress-VLANs from radius server and during re-authentication if radius server is unreachable, then clients gets authenticated in server-fail use-cache scenario and the egress VLAN list is deleted. When 802.1x process attempts to access the same egress VLAN list which is deleted then the 802.1x process crash is seen and clients will face traffic drop.
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1777635Traffic loss for few seconds will be observed after restarting l2-learning process on L3 VxLAN gateway
Product-Group=junos
On all Junos and Junos Evolved platforms, in the EVPN-VXLAN( Ethernet Virtual Private Network- Virtual Extensible Local Area Network) scenario, traffic loss for few seconds would be observed when a user restart l2-learning process on a Layer-3 VXLAN gateway. This happens because of timing issues in the kernel, which mistakenly delete MAC routes of its associated devices instead of updating them in the table. The traffic from devices with those MAC addresses won't flow until the system is back on track and syncing properly.
PR NumberSynopsisCategory: Device Configuration Daemon
1725168Traffic impact will be seen with mismatched speeds on the LAG interface and member interface
Product-Group=junos
On all Junos platforms, if a speed mismatch happens in the LAG (Link Aggregation) & member interface then a traffic drop will be seen.
PR NumberSynopsisCategory: JUNOS Dynamic Profile Configuration Infrastructure
1797305The KRT queue stuck resulting in subscriber traffic loss
Product-Group=junos
On Junos MX platforms with subscriber dynamic profile versioning, following a commit configuration command, the krt ( Kernel routing table) queue becomes stuck on the master Routing Engine (RE), causing loss of subscriber traffic and subsequent client restarts. This occurs due to a large number of queued entries, resulting in blockage of the KRT queue.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1769086Data center interconnect configuration addition needs to be non-catastrophic.
Product-Group=junos
Adding interconnect configuration can be catastrophic behaviour which means BD (Bridge domain) and routing instance object will be deleted and added back, during this window there will be traffic drop.
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1759541Upon kernel panic on a dual RE system mastership relinquishment will take longer than 5 seconds causing FPC restart
Product-Group=junos
On all Junos OS Evolved platforms, with dual Routing Engine (RE) and Nonstop active Routing (NSR), during kernel panic, the switchover will get delayed (more than 5 seconds) causing a potential Flexible PIC Concentrator (FPC) restart.
PR NumberSynopsisCategory: EX4400 PFE software
1795545On all Junos EX platforms rewrite rules does not work properly when multiple interfaces are configured
Product-Group=junos
On all EX Junos platforms enabled with CoS, if there is rewrite-rule applied to the multiple interfaces, the rewrite-rule which is present for only one of the logical interfaces might work as expected due to this issue.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1788573Traffic loss after PIC restart if the packet has a VLAN tag of 4095
Product-Group=junos
On EX4400, EX4100, EX4650, and QFX5120 platforms in the EVPN-VXLAN (Ethernet VPN - Virtual Extensible LAN) IPv6 (Internet Protocol Version 6) underlay environment, after the PIC (Physical Interface Card) restart few AE (Aggregated Ethernet) member interfaces go down and comes back up traffic loss is observed if the packet has a VLAN tag of 4095. The issue happens because PFE (Packet Forwarding Engine) will not receive any new next-hop addition to PFE as the AE interface is already present in PFE as next-hop.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1792128Configuring multiple IFL of different families on Junos QFX10K SP style interfaces leads to traffic loss
Product-Group=junos
On Junos QFX 10K platforms, traffic drop is seen when multiple interface logical (IFLs) of different families are configured on the same interface physical (IFD) with Service Provide (SP) style configuration and layer 2 (L2) ILF is the first IFL to be created.
1793335Nexthop resolution will fail in high scale ARP on QFX10K Platforms
Product-Group=junos
On QFX10K platforms, at high scale Address Resolution Protocol (ARP) which is more than 90K that includes ARP learnt on local interfaces and learnt from remote Provider Edges(PEs) on the device in that situation if there is a network event in place such as Flap in access ports or Flap in Datacenter Interconnect links or following network operational commands "clear bgp neighbors" or "restart routing" or "clear ethernet-switching table" or "clear ethernet-switching mac-ip-table" are executed in the device which will create a problem in nexthop token allocation as system reaches maximum token limit. This results a traffic impact for ongoing and upcoming traffic flows.
1798887Traffic drops are observed in the EVPN-VXLAN environment having IPv4 and IPv6 address configured in underlay
Product-Group=junos
On Junos QFX10002-36Q/QFX10002-72Q/QFX10002-60C and PTX10002-60C platforms, the decapsulate of the VXLAN (Virtual eXtensible Local-Area Network) packet will fail and result in traffic drops due to the tunnel termination table not being programmed in PFE (Packet Forwarding Engine).
PR NumberSynopsisCategory: Express PFE L3 Multicast
1774562PIM join are not learnt for multicast IPs
Product-Group=junos
On Junos PTX platforms, with PIM BIDR (Protocol Independent Multicast- Bidirectional) mode with "set protocols pim rp bidirectional address <> group-ranges <>" configuration, PIM/MLD joins will not be learnt for multicast IPs other than link local IP and MY IP which will lead to traffic impact. Also, lo0 filter which were introduced with PR 1701756 for IGMP and MLD will be applied only for MY IPs and Link local IPs. For any other IPs other than above, lo0 filter will not work.
PR NumberSynopsisCategory: SRX1500 platform software
1751496On SRX1500 PEM Alarms are displayed due to hardware limitations to read I2C
Product-Group=junosvae
On SRX1500 Hardware Limitation leads to PEM I2C Failure Alarm triggered as result of failure in I2C reading operations.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1739559SRX4100/4200 accepts the datapath-debug configuration although it does not support it
Product-Group=junos
It is possible to set and commit the datapath-debug configuration on platforms SRX4100/SRX4200 although datapath debugging is not supported on those platforms. because of this unsupported configuration being accepted the RE (Routing Engine) load can go high and cause traffic outage. The workaround is to remove the datapath-debug configuration and perform a commit.
PR NumberSynopsisCategory: IDP policy
1786822The flowd process crash is observed when the device is rebooted
Product-Group=junos
On all Junos SRX platforms, flowd crash is seen when the device is rebooted and a CLI request for Intrusion Detection and Prevention (IDP) counters reaches the Packet Forwarding Engine (PFE) before the IDP memory module is initialized (even if IDP is not configured). The flowd process restarts affecting the traffic.
PR NumberSynopsisCategory: BSDX Software installation issues
1783119Delays can be seen while the upgrading process runs due to the status of UFS set to mode enable.
Product-Group=junos
In USF mode enabled router, While upgrading router having scaled services AMS config with "load-balancing-options disable-hash", Router continuously dumps "'disable-hash' knob is only allowed in USF mode" error. This delays the bootup time with scaled config.
PR NumberSynopsisCategory: ISIS routing protocol
1690231The rpd process crashes on a system running with IGP shortcuts
Product-Group=junos
On all Junos and Junos Evolved platforms, if interior gateway protocol (IGP) shortcuts are used, the rpd process crashes if an IGP tunnel route is installed over a RSVP label-switched path (LSP) that has next-hop gateway flags.
1746557Stale IP prefixes when issuing "show isis route flex-algorithm-id"
Product-Group=junos
The Flex algorithm in IS-IS does not install IP (v4/v6) routes into the RIB. However, when using the current IS-IS show CLI command, "show isis route flex-algorithm-id <>", it still displays certain IPv4/IPv6 IS-IS routes in the output, even though these routes are not actually being placed in the RIB. After implementing the fix, the IPv4/IPv6 IS-IS routes will no longer be displayed in the output of the CLI for the flex-algorithm.
1760334Routing loop will be observed during ISIS-FRC implementation
Product-Group=junos
On Junos and Junos Evolved platforms, routing loop will be observed, when configuring FRC (Flood-Reflector Client) and processing anycast Layer 2 prefix advertisements, it leads to the installation of ISIS routes with incorrect nexthops .
1781103Gradual memory leak seen in the rpd process on Junos based PTX and QFX10002/10008 platforms
Product-Group=junos
On Junos based PTX and QFX10002/10008 platforms configured as Intermediate System to Intermediate System (ISIS) Flood-Reflectors (FR client/servers) and running images between 20.3X75-D44.4 and 20.3X75-D44.8, the Routing Protocol Daemon (rpd) process shows gradual and consistent increase in memory utilisation which eventually leads to swap memory exhaustion and the rpd process restarts impacting service. The leak is caused due to special handling of ISIS-FR routes during installation.
PR NumberSynopsisCategory: jdhcpd daemon
1775108DHCP ALQ subscribers may not logged out after TCP connection is removed on all Junos platforms
Product-Group=junos
On all Junos platforms with ALQ (Active-Lease Query) enabled with DHCP(Dynamic Host Configuration Protocol ) relay agent configuration, with inflight subscribers login & logout and TCP connection reset, the DHCP subscribers may not properly release their IP address leases from a backup DHCP Relay, leading to inaccurate IP address management and allocation for the subscribers. This can lead to traffic impact for subscribers who are not released.
PR NumberSynopsisCategory: Flow Module
1719594Junos OS: SRX Series: Specific traffic leads to a PFE crash (CVE-2024-21586)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to the https://supportportal.juniper.net/JSA83195 [juniper.net] for more information.
1762568Unable to download a file completely from SaaS server to LAN
Product-Group=junos
TCP sessions are not refreshed when enabled the "set security flow gre-perf-acceleration" is configured.
1779260ISSU upgrade to 21.4+ on SRX5k or SRX4600 may lead to a flowd coredump
Product-Group=junos
On SRX5000 series and SRX4600, performing ISSU (In-Service Software Upgrade) to Junos version 21.4 and higher from earlier Junos versions can lead to a flowd coredump occurring during the ISSU process. The coredump would occur on the already upgraded node while the sessions are getting synchronized from the node which is not upgraded yet.
1783595PMI sends packets to the wrong destination
Product-Group=junos
On SRX platform, when the next-hop changes, the PowerMode Ipsec (PMI) induces the packets to be sent to the wrong destination, causing packet drops.
1791633Packets over GRE or IPIP or GRE(PMI) will not reach destination
Product-Group=junos
On Junos platforms with GRE or GRE(PMI) or IPIP tunnels, when tunnel TTL(Time To Live) is set to 1 in the CLI, the traffic sent over GRE or IPIP or GREoIPSec tunnel does not reach its destination.
1798041On Juniper SRX platforms GTP-U packet destination port gets duplicated to the source port and subsequently discarded by policy.
Product-Group=junos
On Juniper SRX devices with GTP-U distribution feature enabled, GTP-U source port will get duplicated as same as the destination port in the traffic from the server back to the source and blocked by the security policy. Due to this, all impacted reverse GTP-U packets will be discarded.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1736498In SRX MNHA cluster setup the RSI takes long time to generate
Product-Group=junos
In SRX MNHA cluster setup the RSI takes long time to generate on the MNHA backup node. The RSI includes the command "show security flow session session-state warm" which will collect all the sessions in warm state on the MNHA backup node - this output can be extensive and RSI is being generated an extended period of time, in known instances this was 1-2 hours.
PR NumberSynopsisCategory: l2 flow module
1780182SRX with transparent mode may fail to create a new flow session for multicast traffic when vlan has l3-interface
Product-Group=junos
On all SRX platforms, when transparent mode is used, flow session does not create for the first few multicast packets due to which traffic drop occurs when l3-interface is used. The issue only happen in flow session creation process for Multicast traffic and the unicast traffic is unaffected. Once the flow session is created, multicast traffic will not be dropped.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1784752High RE CPU observed on both nodes in chassis cluster due to jsrpd
Product-Group=junosvae
High RE (Routing Engine) CPU caused is caused by jsrpd (Junos stateful redundancy protocol daemon) on both the nodes in a chassis cluster configured with control link Encryption (Internal SA) after upgrading the cluster.
PR NumberSynopsisCategory: Security platform jweb support
1789466Jweb does not display address book entries properly after certain operations.
Product-Group=junos
On SRX platform, Jweb does not display address book entries properly after certain operations.
PR NumberSynopsisCategory: Layer 2 Circuit issues
1768323JUNOS and JUNOS EVO-RPD process crash under High Availability Route Engine (RE) scenarios when L2circuits are enabled
Product-Group=junos
Routing Protocol Daemon (RPD) process crash when l2circuits are enabled in scenarios with backup Route Engine (RE).
PR NumberSynopsisCategory: Layer 2 Control Module
1770053xSTP configured interface will remains in discarding state
Product-Group=junos
On all Junos and Junos OS Evolved Platforms, when an interface is added inside RSTP (Rapid Spanning Tree Protocol), VSTP (VLAN Spanning Tree Protocol), MSTP (Multiple Spanning Tree Protocol) or STP (Spanning Tree Protocol), because of STP port creation fail from l2cpd (Layer 2 control protocol daemon), port will remains in discarding state. This leads to traffic impact.
1787892Interface configured with BPDU-disable goes down during VC mastership switchover
Product-Group=junos
On Junos EX3400/EX4300/EX2300 platforms configured with VC (Virtual Chassis) and NSB (Nonstop-Bridging) enabled, when VC mastership switchover is triggered, the configuration under 'set protocols layer2-control bpdu-block interface ' will not take effect due to which the interface will go down and will impact the traffic. The configuration 'set protocols layer2-control bpdu-block interface all' will not have any impact.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1772424Connectivity between static and LDP signaled pseudowires broken in VPLS after upgrade and results in VPLS traffic drop
Product-Group=junos
On all Junos and Junos OS Evovled platforms, when there is a upgrade and also when one mesh group of routing instance is substring of other, the connection between static and LDP (Label Distribution Protocol) signaled psuedowires is broken will lead to traffic drop.
1776991ARP resolution issues will be observed in the H-VPLS environment
Product-Group=junos
On Junos and Junos Evolved platforms, traffic impact will be observed due to ARP (Address Resolution Protocol) resolution issues when multiple mesh-group is configured under the same routing-instance and the name of each mesh-group is not unique i.e. substring of another mesh-group in the H-VPLS (Hierarchical Virtual Private LAN Service) environment.
1803898Traffic flooding occurs when deactivating and activating interfaces in EVPN scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms, while deactivating/activating the interface, the first control MAC for a BD and IFL combination can get lost when L2alm'd ifbd Mac sequence num is different from what is sent by L2ald. This will lead to traffic flooding for the MAC which will be impacted.
PR NumberSynopsisCategory: lacp protocol
1783793All AEs bundles configured in Active-Standby mode for EVPN-MPLS routing-instances will flap on the first commit post a fresh system reboot
Product-Group=junos
On all Junos MX and EX platforms with MPC family of line cards, all the Aggregated-Ethernet (AEs) bundles configured in Active-Standby mode for Ethernet Virtual Private Network-Multiprotocol Label Switching (EVPN-MPLS) routing-instances on the system will flap on the first commit after a fresh system reboot.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1737035BGP sessions flap due to license updates
Product-Group=junos
On all Junos platforms, a BGP flap is observed when a license key is upgraded or a new license is added resulting in traffic loss.
1792672License is lost on NG-RE platforms after device/routing-engine reboot
Product-Group=junos
On NG-RE (Next Generation Routing Engine) platforms, license is lost after restarting device/routing-engine. If any service depends on that license, that service will be impacted.
PR NumberSynopsisCategory: PTX1000 platform
1770739Reboot on PTX1k with image 22.3x60 causes fpc to reboot with "Fatal ASIC initialization error, Offlining FPC" Error message
Product-Group=junosvae
Reboot on PTX1k with image 22.3x60 causes fpc to reboot with "Fatal ASIC initialization error, Offlining FPC" Error message times
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1729467MACsec interoperability issue between Juniper and non Juniper platforms
Product-Group=junos
On all Junos and Junos Evolved platforms with MACsec (Media Access Control security) configured , frequent SAK (Secure Association Key) rollover is observed when the peer device is a non-Juniper box and the Juniper device is acting as the key-server. This results in unstable MACsec sessions between the juniper device and the non Juniper device.
PR NumberSynopsisCategory: SW PRs for MPC10E PMB
1731258MPC10 and MPC11 line cards experiencing unexpected reboots
Product-Group=junos
Line cards such as MPC10 and MPC11 experience unexpected reboots because of CPU C-states which are enabled by default thus impacting the customer production traffic.
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1762114Linecard loses all fabric planes when another linecard is powered off ungracefully
Product-Group=junos
On MX2020/MX2010/MX10K4/MX10K8 platforms and MPC11E, LC9600, LC4800 line cards , linecard loses all fabric planes (no links active) and takes all interfaces down when another linecard is powered off ungracefully .
PR NumberSynopsisCategory: Multiprotocol Label Switching
1743957When MPLS is configured with in-place-lsp-bandwidth-update command, an incorrect error message and traffic loss are observed after the make-before-break failure
Product-Group=junos
On all Junos and Junos Evolved platforms, when in-place-lsp-bandwidth-update knob is configured in MPLS (Multi Procotol Label System), the auto-bandwidth adjust timer expires, when make-before-break is undergoing, an incorrect error message is seen in the "show mpls lsp" command, and in some cases where MBB takes more time to complete or aborted, it also results in traffic loss.
1744584Traffic loss will be observed whenever a soft preemption reroute request arrives
Product-Group=junos
On all Junos and Junos OS Evolved platforms, whenever a soft preemption reroute request arrives in the middle of the ongoing make-before-break, traffic loss would be observed which is still referring to the old instance.
PR NumberSynopsisCategory: Track Mt Rainier RE platform software issues
1782062The interface fxp0 deactivation or activation is not captured due to improper date format
Product-Group=junos
On all VMhost platforms, the interface fxp0 state is not captured since the script to bring up the interface is not parsing the output from the date field.
PR NumberSynopsisCategory: PFE Peer Infra
1801535CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log
Product-Group=junos
On all Junos platforms, CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log. This log is not an error log but still printed under LOG_ERROR and flooded with default log level. This causes restart which will impact normal user traffic.
PR NumberSynopsisCategory: TCP/UDP transport layer
1790049The BGP TCP output queue remains full
Product-Group=junos
On all Junos platforms, after upgrading to 24.2 and above, a BGP TCP output queue (outQ) may remain full until the TCP session is clear.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1753191ARP resolution failure for lt interfaces is observed after cluster failover on Junos SRX platforms
Product-Group=junos
On Junos SRX platforms in cluster, Address Resolution Protocol (ARP) resolution fails for logical tunnel interfaces when the logical tunnel interfaces are toggled and the cluster switchovers.
PR NumberSynopsisCategory: OSPF routing protocol
1774715OSPF route flap might be observed
Product-Group=junos
On all Junos and Junos OS Evolved platforms OSPF (Open Shortest Path First) route flaps can be observed which will cause a traffic drop. This is a rare timing issue happening after an OSPF adjacency flap.
PR NumberSynopsisCategory: Protocol Independant Multicast
1792886The rpd crash is observed when PIM SSM mode with RPF-Vector and MoFRR is configured
Product-Group=junos
On Junos and Junos Evolved platforms , when PIM SSM (PIM Source-Specific Multicast) with RPF (Reverse Path Forwarding)-Vector and MoFRR (Multicast-only fast reroute) is configured , rpd crash if the device receives PIM Prune message for (S, G) state with RPF vector TLV. interface is freed for the (S, G) from the outgoing interface list i.e. RPF-Vector TLV (Type, Length, and Value) having (S, G) is getting freed but that same (S, G) is still used by MoFRR. The issue happens when MoFRR Backup upstream interface is also listed at the outgoing interface list for the (S, G)
PR NumberSynopsisCategory: vMX Platform Infrastructure related issue tracking
1729152The FPC crash or flap in protocols will be seen as soon as port-mirroring or firewall filters with syslog action is enabled
Product-Group=junos
On MX150 platform, when port-mirroring or firewall with syslog configuration is enabled, there will be a memory leak which will cause depletion of buffer memory which will lead to flap in the protocols or the (Flexible PIC Concentrators) FPC crash. This will impact the traffic.
PR NumberSynopsisCategory: for all ipv6 related issues
1775394EX/QFX: fails to ping ipv6 link local address in routing instance if there is a default route in the same instance.
Product-Group=junos
On QFX5K, EX4300-MP, EX4400 or EX4100 series switch with VXLAN, ping to ipv6 link local address in routing instance would be failed. This issue affects only to the traffic which is sent to Link Local IPV6 Interfaces when the interface is an IRB along with VXLAN configuration.
PR NumberSynopsisCategory: QFX L2 PFE
1797516DCPFE process crash occurs in EVPN-VXLAN scenario
Product-Group=junos
When a vport, which is a memory pointer, is a member of an itable list, the entry in the itable should be removed before freeing the vport. For some corner case, the vport is not removed from the itable when freeing the vport. The freed memory or the reused memory corrupts the itable list and it crashes when performing some operation on the corrupted list.
1811701Multiple services and protocols does not work on the backup member with 100G port used as VC interconnect port on QFX5110-48S
Product-Group=junos
On QFX5110-48S platforms in VC (Virtual Chassis), when 100G port is used as VC interconnect, multiple protocols and services do not work on the backup member when the VC port related configurations are deleted and added back on the backup member. The issue is also seen when the PFE process on the backup member is restarted. LACP (Link Aggregation Control Protocol) interfaces from backup switch goes into detached/defaulted mode which causes major connectivity and traffic disruptions.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1778725Traffic drop is observed when VIPs become unreachable due to GARP sent on VLANs to which the VIP does not belong
Product-Group=junos
Under a rare scenario, on all Junos and Junos Evolved platforms configured with EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible Local Area Network) type 5 routes, Bridge-Domain, IRB (Integrated Routing and Bridging) and having L4 (Layer 4 device like an application load balancer) devices as single-homed with each border leaf and when VIP (Virtual Internet Protocol) entries are learnt on a leaf and L4 failover happens, it is observed that the VIPs announced by GARP (Gratuitous Address Resolution Protocol) is sent on VLANs that the VIP does not belong to and the incorrect GARP is not handled as per the expectation.
1796210In the EVPN-VxLAN scenario traffic blackholes on spine reboot
Product-Group=junos
On all Junos QFX5K and some specific EX4K in EVPN-VxLAN (Ethernet VPN-Virtual extensible LAN) environment with underlay connections using Virtual Chassis Port Link Aggregation with AE (Aggregated Ethernet) interface and during one of the spine reboot, traffic will not be immediately switched to another spine and traffic blackholes.
1802958ECMP programming issue on Junos QFX5K/EX4K in EVPN-VXLAN
Product-Group=junos
In rare scenarios on Junos QFX5K/EX4K platforms that are part of Ethernet VPN - Virtual extensible LANs (EVPN-VXLAN) Fabric topology and employing ECMP (Equal Cost Multi-path) routing on the underlay interfaces between the Leaf and Spine, if one or more of these physical underlay interfaces flaps or their associated underlay protocol adjacency flaps and this time aligns precisely with the associated unicast next-hop deletion process, a race condition may occur, resulting in the potential failure to program the associated ECMP interface next-hop entry correctly in the hardware table.
1806114Multicast nexthop delete causes nexthop stale entries which fail when the same nexthop is reused in VXLAN VLAN creation
Product-Group=junos
On all Junos QFX5K and EX4K platforms, when L3 multicast nexthop entries are deleted when configured with IRB or switched from non-default to default VRF, stale entries from the multicast NH (NextHop) delete cause reusing of stale nexthop in VXLAN (Virtual Extensible LAN) and subsequent creation of VXLAN VLAN fails.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1797511[JDI-RCT-EVPNVXLAN-L2Stitching]: DCPFE core observed on QFX10k while running profile baseline in 22.2R3-S3.18 image
Product-Group=junos
In very rare instances of a large config commit, on the QFX10002-36Q routers, the dcpfe can core due to watchdog timeout. After the core, the dcpfe respawns and the system functions normally without any manual intervention.
PR NumberSynopsisCategory: RPD Interfaces related issues
1798801MPLS/RSVP LSP self-ping behaviour differs from expected behaviour causing self-ping time out
Product-Group=junos
On Junos OS Platforms, configured with Multiprotocol Label Switching (MPLS)/Resource Reservation Protocol(RSVP) Label Switched Path(LSP) and firewall filter applied on the loopback with prefix list that does not include the interface address of local router, self-ping time out is observed.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1745509rpd core at #2 0x00007f9b2512742c in __assert_fail_base (fmt=0x7f9b2528bae8 "%s%s%s:%u: %s%sAssertion `%s' failed.\n%n", assertion=0x55be37507a48 "nh_idx_t_getval(nhid) == nh_idx_t_getval(rt_nexthops_nhid(rtnh))", file=0x55be375077e8 "../../../../../../../../src/layer3/usr.sbin/rpd/lib/krt/common/krt_ack.c", line=1306, function=) at assert.c:92
Product-Group=junos
RPD core is sometimes seen if there are many unilist nexthop with identical key values but different metric in Evo, esp when ACK is requested for those nexthops
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1777068Policy Evaluation causing unrelated route flaps in Dynamic Tunnel setup
Product-Group=junos
On all Junos and Junos Evolved platforms that support Dynamic tunnels, a policy evaluation of the routing policy causes flaps for unrelated tunnel routes. The route flap for the tunnel route will cause traffic loss.
1785884The rpd crash is observed due to segment fault
Product-Group=junos
On Junos OS Evolved platforms, when no acknowledgment is received from PFE (Packet Forwarding Engine) within timeout results in the rpd (Routing Process Daemon) crash. This issue happens when routes requesting acknowledgment do not receive acknowledgment leading to segment fault.
1793196Multicast traffic black-holing upon MoFRR primary link went down
Product-Group=junos
On all Junos and Junos Evolved platforms, when MoFRR (Multicast-only fast reroute) is configured with NSR (Non-stop routing) while interface flapping or RE switchover, there is a next-hop leak and the next-hop in RIB (Routing Information Base) is different from the next-hop in FIB (Forwarding information base) due to that multicast traffic will be impacted.
1808463CPU utilization of the rpd process stays high on all Junos and Junos OS Evolved platforms
Product-Group=junos
On all Junos and Junos OS Evolved platforms in a corner case, the Routing Protocol Daemon (rpd) CPU utilization will be seen high in scenarios where recursive route resolution is involved. The rpd process will be continuously spinning in the re-resolution job which could impact scheduling of other jobs and re-resolution of other routes impacting traffic.
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1737594Traffic drop can be seen in the MPLS traffic Engineering scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, traffic drop can be seen in MPLS (Multi-Protocol Label Switching) traffic engineering with IGP-FRR (Interior Gateway Protocol Fast Reroute) and preserve next-hop hierarchy. This issue happens when the BGP (Border Gateway Protocol) routes are resolving over BGP and there is a change in the active route. The session ID for the IGP-FRR is assigned to the new active route and the old active route is withdrawn, while the above processing is done the session ID is associated with both the old and new active route, and the old active route, the route gets deleted which triggers the IGP-FRR session ID to be down and the unilist (ECMP)path get stuck causing traffic impact.
PR NumberSynopsisCategory: PTX10K specific platform PRs
1766097PTX10008: When NSR Enabled and FMBB Knobs are configured and if SIB is Offline/Online casue resiliencyd core
Product-Group=junos
PTX10008: When NSR Enabled and FMBB Knobs are configured and if SIB is Offline/Online casue resiliencyd core
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1801201IKE is not coming up with dhgroup19 and dhgroup20
Product-Group=junos
IKE is not coming up with dhgroup19 and dhgroup20. The below Junos releases are impacted. junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3-S1 junos:24.1R1. So previous to these releases dhgroup19 and dhgroup20 should be working.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1691986Consistent high CPU usage is seen on the device post reboot
Product-Group=junos
On all Junos and Junos Evolved platforms consistent high CPU usage in snmpd immediately after reboot.
1804856Warning messages seen while Custom Yang Package Deletion
Product-Group=junos
Warning message is displayed when custom yang package is deleted.
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1766594After the device reboot JSC stops accepting user connections
Product-Group=junos
On all SRX platforms, when Juniper Secure Connect (JSC) configuration is done on Point-to-Point Protocol over Ethernet (PPPoE) interface then after the device reboot, JSC clients couldn't connect.
PR NumberSynopsisCategory: SRX branch platforms
1714620High latency will be observed while pinging to peer device
Product-Group=junos
On Branch SRX Platforms, The delay will be observed while pinging to peer device due to high latency when VLAN(Virtual Local Area Network) tagged DHCP(Dynamic Host Configuration Protocol) packets arrive at IRB (Integrated Routing and Bridging) interface.
1780326IP Monitoring fail to install route after SRX cluster reboot
Product-Group=junos
On Junos SRX branch series platforms in cluster, the IP Monitoring fails to install route after the SRX cluster reboots.
PR NumberSynopsisCategory: SSL Proxy functionality on JUNOS
1788673The flowd crash will be observed when the TLS 1.3 session ticket is received on SSL-I
Product-Group=junos
On SRX platforms with SSL (Secure Sockets Layer) Proxy configured, due to timing synchronization issues, while doing multiple session tickets check on SSL_I [initiator on the server side], and SSL_T [terminator on the client side] updating the session cache and releasing the session cache resources resulting in proxy session info cleared & causing the flowd crash at SSL_I. The issue happens when the SSL_I (Server) is using TLS1.3 and SSL_T (Client) using TLS1.2.
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1768592The SFB3 will go offline during during SFB3 < -> ADC < -> MPC7E link initialization
Product-Group=junos
On MX2020 and MX2010 platforms with Switch Fabric Boards (SFB) 3 and Modular Port Concentrators (MPCs) MPC7E-10G or MPC7E-MRATE inserted via Adapter Card (ADC) MX2000-LC, SFB3 will go offline during SFB3 < -> ADC < -> MPC7E link initialization with a fatal error. This is a timing issue and will not be seen with every SFB3 < -> ADC < -> MPC7E link initialization. It happens because of a race condition between certain events occurring during MPC initialization.
PR NumberSynopsisCategory: MX10002 Platform SW - Platform s/w defects
1727985A panic reboot will be observed due to deadlock on VMhost platforms
Product-Group=junosvae
On Junos based VMhost platforms due to disk access issue a panic reboot will be observed with core files. This is a rare issue and traffic will be impacted as the system reboots unexpectedly.
PR NumberSynopsisCategory: SRX-1RU infrastructure SW defects
1784983Chassis alarm not present for if /var partition usage exceeds 100%
Product-Group=junos
When /var partition disk space is greater than 100%, "RE 0 /var partition usage is high" chassis alarm gets cleared
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1795940The ARP resolution will fail on the interface when the default ARP policer fails to program.
Product-Group=junos
On AFT(Advanced Forwarding Toolkit) based MX platforms, default ARP(Address Resolution Protocol) policer fails because of which ARP resolution fails on the interface and hence the traffic gets impacted.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1766694802.1p priority is preserved when traffic is sent from AFT with irb
Product-Group=junos
In AFT with IRB config, post the mpls decapsulation, irb egress processing is done which adds an L2encap in which the cos bits that are preserved are also copied.
1792736Transit traffic does not get forwarded in EVPN-VxLAN scenario on Junos MX/EX platforms
Product-Group=junos
On Junos MX240/MX480/MX960/MX2008/MX10004/MX10008/MX2010/MX2020 platforms with MPC10E/11E/LC9600 line cards and MX304 platform and EX9204/EX9208/EX92014 with EX9200-15C line card, in Ethernet Virtual Private Network-Virtual Extensible LAN (EVPN-VxLAN) scenario the transit traffic does not get forwarded due to incorrect inner ethernet header.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1738672FPC crashes due to back-to-back GRES
Product-Group=junos
On line cards such as MPC5E/MPC7E/LC480/MPC10E/11E/LC9600 and MX304 platforms, when multiple times Graceful Routing Engine Switchover (GRES) is performed, all the FPCs crashed.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1781673L2 control packets may be dropped on JUNOS devices in VPLS scenario on certain MX platforms
Product-Group=junos
On certain Junos MX platforms, in the VPLS (Virtual Private LAN Service ) scenario, the L2 (Layer 2) control packets with a multicast destination MAC (Media Acess Control) address are dropped if they arrive on the VPLS core-facing interface placed on MPC (Modular PIC Concentrator)10/MPC11 linecards or MX304 router
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1797496Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
Product-Group=junos
Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1736976qfx goes into amnesiac after a power outage and commit errors for scripts prevent recovery
Product-Group=junos
Reported on QFX only /etc/backup/group and /var/etc/group file are corrupt leading to mgd init failure when box boots up. Rare Issue Suspect that abrupt power outage when file was being written might have led to file corruption. 8067 -rw-r--r-- 1 root 0 358 Dec 9 17:33 /etc/backup/group Box goes to amnesiac mode mgd: error: commit-script mgd: error: FAIL: grp fail mgd: error: commit-script mgd: error: unable to release privileges root@:RE:0% file -i /etc/backup/group /etc/backup/group: application/octet-stream; charset=binary >>>> Output in Non-working case root@:RE:0% root@:RE:0% root@:RE:0% file -i /etc/backup/group /etc/backup/master.passwd: text/plain; charset=us-ascii >>>> Output in Working case root@:RE:0%
1770643RPD core seen when groups is activated before corresponding 'apply-groups' in configuration
Product-Group=junos
On all Junos and Junos Evolved platforms, when the group is activated after the corresponding 'apply-groups' statement configuration, rpd core is seen.
1794536The device goes into configuration locked state due to stale mgd
Product-Group=junos
The device is went into config locked state due to stale mgd. For netconf sessions with , if ungraceful exit happens, the lock is not released. There is auto cleanup supported for such cases, But it is not triggered under problem conditions as faced in this PR. This leads to device remain in locked state due to stale entry. "request system logout pid " can be used for cleanup and to recover from this state.
PR NumberSynopsisCategory: web filterig issues
1772232[SRX] Flowd core is generated by UTM web-filtering
Product-Group=junos
On SRX platform, flowd core might be generated when when TCP flow session for HTTP traffic is in error state due to some reason and UTM WF trying to apply fallback action.
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1787147The sdp process crashes when trying to add a new satellite device to the network
Product-Group=junos
In the Junos Fusion setup, the sdp (Satellite Discovery and Provisioning Daemon) process crashes repeatedly when trying to add a new satellite device to the network. This issue happens when the MD5 encrypted data is read as a string, in which the string validation code throws errors when the first byte of MD5 encrypted data is 0.
PR NumberSynopsisCategory: VMHOST platforms software
1726621Root user is unable to login using public key authentication after reboot or upgrade
Product-Group=junos
On all MX & EX92XX series platforms with NG-RE running Junos OS 21.4R1 or higher releases, the root user is unable to login using public key authentication (RSA Keys) after reboot or upgrade and prompts for a password even when password less authentication is configured.
PR NumberSynopsisCategory: usf nat related issues
1776355Internet traffic destined for the NAT pool address (Network Address Translation) will loop after configuration changes
Product-Group=junos
On Junos MX platforms, with MS-MPC and SPC3 service cards, Change in "interim-logging-interval" configuration can lead to UDP traffic get looped and it will impacting CPU utilisation and traffic drop can be seen.


22.2R3-S4 - List of Known issues 

PR NumberSynopsisCategory: EX4300 HA (GRES, NSR, NSB)
1665562NSSU aborted with Backup RE in an inconsistent state
Product-Group=junosvae
On EX4300-48MP platform during NSSU (Nonstop Software Upgrade) operation, configured in VC (Virtual Chassis) mode with NSR (Nonstop-Routing) and GRES (Graceful-Switchover) configured, the Backup RE (Routing Engine) will be in an inconsistent state generating error messages and NSSU operation gets aborted.

Resolved In: junos:20.4R3-S4 junos:21.2R3-S7 junos:21.3R3-S1 junos:21.3R3-S5 junos:21.4R3 junos:21.4R3-S4 junos:21.4R3-S5 junos:21.4R3-S6 junos:22.1R2 junos:22.1R3 junos:22.1R3-S5 junos:22.2R1 junos:22.2R2 junos:22.3R1 junos:22.4R1
PR NumberSynopsisCategory: EX4300 Platform implementation
1789999[interfaces]:Ex-Hardening:Local/Remote fault insertion from TG is failing
Product-Group=junos
Ex-Hardening:Local/Remote fault insertion from TG is failing

Resolved In:
PR NumberSynopsisCategory: EX2300/3400 PFE
1695771Traffic loss is seen when a MAC moves from dot1x port to non-dot1x port
Product-Group=junos
On all Junos and Junos OS Evolved platforms is having dot1x enabled interface. When two or more MAC addresses are learnt on a dot1x port, and if one of them is shifted to a non-dot1x port, the MAC address that was moved is still seen as a MAC-based VLAN entry on the Layer2 Address Learning Manager (l2alm). This could lead to network traffic being lost.

Resolved In: evo:21.4R3-S4-EVO evo:22.2R3-S4-EVO evo:22.3R2-S1-EVO junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S5 junos:21.3R3-S4 junos:21.4R3-S4 junos:22.1R3-S2 junos:22.2R3 junos:22.3R2-S1 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: HW Board, FPGA, CPLD issues
1640307QFX5120-32C might reboot randomly with the last reboot reason:- "0x2000:hypervisor reboot"
Product-Group=junos
This issue is applicable to QFX5210-64c, QFX5120-32c, QFX5200-48Y, QFX5120-48Y, EX4650-48Y, QFX5120-48T, and EX4300-48MP platforms. Due to catastrophic error (caterr) which happens when CPU temperature crosses its threshold, the CPU gets overheated or environmental factors could cause the catastrophic error. This causes Host OS to reboot on the device. The fix requires a BIOS upgrade. Please reach out to JTAC for details.

Resolved In: junos:19.1R3-S9 junos:20.2R3-S4 junos:20.2R3-S6 junos:20.4R3-S5 junos:22.3R3-S3 junos:22.4R1
PR NumberSynopsisCategory: Fireall support for ACX
1789694ACX1100 PTP(enterprise profile) is stuck at freerun state
Product-Group=junos
ACX1100 PTP(enterprise profile) is stuck at freerun state after upgrading junos to 21.2R3

Resolved In: junos:21.2R3-S8
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1698373A few BFD sessions might flap after FPC reload and stabilization
Product-Group=junos
On all Junos platforms and Junos Evolved with scaled BFD sessions, FPC reload/restart results in few BFD session flap.

Resolved In: junos:20.3X75-D44 junos:20.4R3-S10 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R1 junos:23.4R2
PR NumberSynopsisCategory: Border Gateway Protocol
1669514The rpd process might crash on removing the BGP-LU configuration
Product-Group=junos
On PTX Series routers enabled with BGP Labeled Unicast family, the rpd process might crash if the IBGP-LU peer is enabled before the EBGP-LU peer, and in the same sequence, the BGP-LU configuration is removed.

Resolved In: evo:22.4R1-EVO junos:20.3X75-D42 junos:22.4R1
1710627Traffic loss is seen when 'no-vrf-propagate-ttl' is configured
Product-Group=junos
On all Junos and Junos Evolved platforms, when 'no-vrf-propagate-ttl' is configured, the routes in a routing instance are unresolved as the routing instance points to itself for resolving its routes. This makes the route hidden as next-hop points to none and causes traffic loss.

Resolved In: evo:21.2R3-S5-EVO junos:21.2R3-S5 junos:23.3R1
PR NumberSynopsisCategory: Issues related to Common BIOS on x86 based designs
1608045LTS19: MX960: 000: [Firmware Bug]: TSC_DEADLINE disabled due to Errata; please update microcode to version: 0x3a (or later) seen upon upgrade to 21.4
Product-Group=junos
Please upgrade BIOS for releases containing LTS19 i.e. Junos 21.4R1 and later. This fix is not relevant to the secure BIOS RE-S-2X00x6. PR :1820715 would address .

Resolved In: junos:22.2R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Device Configuration Daemon
1785035Scaled interface configs not getting deleted through openconfig delete
Product-Group=junos
On Junos and Junos OS Evolved platform, In a system with scaled interface config, when deleting entire config via openconfig at interfaces hierarchy, changes got fails because translation module takes more time to process to delete the entire configuration.

Resolved In: evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: CoS support on DNX
1732509The IPv4 classification and EXP remarking might not work as expected in the IP-MPLS scenario
Product-Group=junos
On Junos ACX710 and AX5448, Multi-protocol label switching Experimental (MPLS EXP) marking will not work as expected with IPv4 traffic which causes the traffic to be wrongly classified.

Resolved In: junos:21.4R3-S6 junos:22.1R3-S5 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1
1770491Traffic convergence is longer than usual after the CoS rewrite
Product-Group=junos
On ACX5448 and ACX710 platforms, traffic convergence takes more time than the expected 50ms i.e. traffic loss is more than expected observed for CoS (Class-of-service) rewrite change after a link failover in the MPLS (Multiprotocol Label Switching) scenario with FRR (Fast Reroute) and LSP (Label-Switched Path) link-protection configured.

Resolved In: junos:21.4R3-S6 junos:22.3R3-S3 junos:22.4R3 junos:22.4R3-S2 junos:23.2R2 junos:23.4R1-S1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: DNX VPLS
1692400dc-pfe: HEAP malloc(0) detected! when a VPLS instance is deactivated in ACX5048.
Product-Group=junos
dc-pfe: HEAP malloc(0) detected! when a VPLS instance is deactivated in ACX5048. This are informational messages and the fix of this PR hides the messages from console output.

Resolved In: junos:20.4R3-S6 junos:21.2R3-S7 junos:22.1R3-S5 junos:22.3R3-S3 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Dynamic rendering infrastructure
1690598VMX :: Incorrect data encoding format is used for the parameter ISIS extended reachability TLV - max link bandwidth when passed to Influx DB server via GNMI
Product-Group=junos
For leaves of data type ieeefloat32, the value will be encoded in bytes while being streamed to collector. The value contained in such leaves may not be completely accurate.

Resolved In: evo:23.3R1-EVO junos:23.3R1
PR NumberSynopsisCategory: EX4400 PFE software
1738156DHCP security bindings will not work over VXLAN scenario
Product-Group=junos
On Junos EX4100/EX4300MP/EX4400 and QFX platforms, in the VXLAN L3GW (Virtual Extensible LAN Layer 3 Gateway) environment with DHCP (Dynamic Host Configuration Protocol) snooping enabled, the offer packets going towards client-facing access non-trunk interfaces are coming out as tagged packets due to which DHCP bindings will not work.

Resolved In: junos:21.4R3-S7 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: EX Entry Level Access VC platform
1778873In Virtual-Chassis mode, the EX4100 switch might not boot up upon triggering a manual reboot
Product-Group=junos
On all EX4100 Virtual-Chassis, any Virtual-Chassis member might not boot up if one of the Virtual-Chassis members was Power-off by CLI ?request system power-off member ? in past.

Resolved In: junos:22.3R3-S3 junos:22.4R3 junos:22.4R3-S1 junos:22.4R3-S2 junos:23.2R2 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: Express PFE FW Features
1711521EVO | COS classification is not working as expected
Product-Group=junos
CoS classification is not working as expected.

Resolved In: evo:22.2R3-S4-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D35-EVO evo:22.3X80-D36-EVO evo:22.3X80-D44-EVO evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R1-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-S1-EVO junos:22.4R3
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1793772QFX10002-60C - L3 multicast traffic (V4 and V6) does not work when IRB is acting as the source.
Product-Group=junos
QFX10002-60C : When the ingress interface is IRB for L3 multicast traffic, the traffic gets dropped and does not get forwarded to the interested receivers(with igmp/mld snooping is enabled in source vlan) or does not get flooded in the vlan(without igmp/mld snooping enabled in the source vlan).

Resolved In: junos:23.4R2 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: SRX1500 platform software
1729671When there is a power outage happens after the first upgrade, the reboot device gets stuck at volume booting
Product-Group=junos
SRX1500 devices get stuck at volume booting after an upgrade and reboot, followed by a power outage. The device is stuck in this state and continues to boot.

Resolved In: junos:21.4R3-S6 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.2R3-S3 junos:22.3R3 junos:22.3R3-S3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1689990Minor alarm "FPC Inefficient Port Mapping" won't be cleared
Product-Group=junos
In SRX4100/4200 platform, even assigning ports are balanced, minor alarm "FPC Inefficient Port Mapping" might not be cleared.

Resolved In: junos:20.4R3-S10 junos:21.2R3-S4 junos:21.3R3-S3 junos:21.4R3-S4 junos:22.1R3 junos:22.1R3-S3 junos:22.2R3 junos:22.3R2 junos:22.3R2-S1 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1787707The KRT queue will be stuck on Junos ACX710 platform
Product-Group=junos
On Junos ACX710 platform with BGP (Border Gateway Protocol) configuration, the response message will be lost and it will lead to element being stuck in the KRT (Kernel Routing Table) queue.

Resolved In: junos:21.2R3-S8 junos:22.4R3-S2 junos:23.4R2
PR NumberSynopsisCategory: MX Inline Jflow
1708195Monitoring services are impacted due to SRRD crashes and restarts
Product-Group=junos
On all Junos Evolved platforms, SRRD (Sampling Route Record Daemon) cores and restarts impacting the monitoring services.

Resolved In: evo:21.4R3-S3-EVO evo:22.2R3-S4-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.4R3-S7 junos:21.2R3-S5 junos:21.4R3-S3 junos:22.2R3-J8 junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: ISIS routing protocol
1667575When the SPF algorithm for IS-IS in Segment Routing use case is triggered frequently, CPU usage might increase
Product-Group=junos
On all Junos and Junos Evolved platforms, when the shortest-path-first (SPF) algorithm for IS-IS is triggered frequently, CPU usage might increase and impact the device performance and traffic.

Resolved In: evo:22.4R1-EVO junos:22.4R1
1704924Traffic loss happens when ISIS LSP size of more than 8500 bytes
Product-Group=junos
On all Junos and Junos Evolved platforms, when the LSP(Link State Protocol Data Unit) size in ISIS(Intermediate System to Intermediate System) is more than 8500 bytes, traffic loss will happen with a checksum error.

Resolved In: evo:23.1R1-EVO evo:23.2R1-EVO junos:23.1R1 junos:23.2R1
1723172The rpd process crash is observed when TI-LFA feature is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms with TI-LFA (Topology-Independent Loop-Free Alternate) feature enabled, when IP address is removed from one interface and is assigned to another interface in the same commit, the rpd process crashes affecting routing control plane.

Resolved In: evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.4R3 junos:22.4R3-S1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: jdhcpd daemon
1743611DNS received through DHCP is lost after a commit and not able to ping internet
Product-Group=junos
If name-server information is changed via CLI after the DHCP subscribers are up, DNS obtained from DHCP server is overwritten by local config. This may result in DNS look up failures in some cases.

Resolved In: junos:21.4R3-S6 junos:22.1R3-S6 junos:22.2R3-S3 junos:22.3R3-S3 junos:22.4R3 junos:22.4R3-S1 junos:22.4R3-S2 junos:23.2R2 junos:23.4R1-S1 junos:23.4R2 junos:24.1R1
1790508EX4400VC : DHCP discover packets will be sent from me0 interface when FPC comes online
Product-Group=junos
On EX4400 device, you may observe DHCP discover packets from me0 even though DHCP is not enabled on that interface. The issue could be seen when EX4400 comes up.

Resolved In:
PR NumberSynopsisCategory: Application aware Quality-of-Service
1720517Junos OS and Junos OS Evolved: Multiple Vulnerabilities in CLI command (CVE-2023-44176)
Product-Group=junos
A Stack-based Buffer Overflow vulnerability in the CLI command of Juniper Networks Junos OS allows a low privileged attacker to execute a specific CLI commands leading to Denial of Service. Repeated actions by the attacker will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA73140 [juniper.net] for more information.

Resolved In: evo:22.3X50-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:20.3X75-D36 junos:20.4R3-S8 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S6 junos:22.1R3-S3 junos:22.2R3-S3 junos:22.3R3 junos:22.4R3 junos:23.1R1-S1 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1592495Recovery snapshot creation fails due to a lack of storage on the OAM partition
Product-Group=junos
On EX2300/EX3400/EX2300-48MP platforms, the recovery snapshot creation fails due to a lack of storage on the Operations, Administration, and Management (OAM) partition.

Resolved In: junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: Kernel Stats Infrastructure
1766061MPC7E Stout PMB requires C-state, Power-Save, to be disable to prevent crash
Product-Group=junos
MPC7E (MPC7E-10G and MPC7E-MRATE) may experience unexpected reset with or without memory single bit correctable error. It is typically seen on an FPC where CPU can be idle , so the fix is to disable C-state( Power-Save) in order to prevent MPC from rebooting.

Resolved In: junos:21.4R3-S7 junos:22.2R3-S3 junos:22.4R3-S2 junos:23.2R2
PR NumberSynopsisCategory: Protocol Independant Multicast
1795964The rpd process crash is seen when routing-instances name length is greater than 60 characters
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Protocol Independent Multicast (PIM) enabled under Routing-instance, the Routing Protocol Daemon (rpd) process crash is seen when the routing instance (RI) name length is greater than 60 characters. Due to the rpd process crash, protocols will be impacted and traffic loss will be seen.

Resolved In: evo:22.3R3-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: QFX analyzer, sflow
1808041The dcpfe process crash is seen in case of inline sampling
Product-Group=junos
On QFX5K and EX4K platforms supporting inline sampling, the dcpfe crash is seen in case of inline sampling when sflow collector is reachable by unilist NH (Next Hop).

Resolved In: junos:21.4R3-S8 junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1783397The fxpc process crash and the device reboots after deleting Aggregated Ethernet (AE) Interface along with its associated physical interface and then applying new interface configuration on the associated physical interface in an EVPN-VXLAN scenario
Product-Group=junos
On an Ethernet Virtual Private Network (EVPN) / Virtual eXtensible Local-Area Network (VXLAN) scenario, after removing an Aggregated Ethernet (AE) Interface along with its associated physical interface on a QFX5k series device and then applying any configuration to the physical interface, the fxpc process crashes and the device undergoes an automatic reboot.

Resolved In: junos:21.4R3-S7 junos:22.1R3-S6 junos:22.2R3-S3 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R2 junos:23.4R1-S1 junos:24.1R1 junos:24.2R1 junos:24.2R2
1801217Traffic drop is observed when an SP style port is added to an existing vlan lag interface
Product-Group=junos
On all Junos QFX5K and EX4K platforms with VxLAN ( Virtual extensible LANs ) configured, while sending the layer 2 traffic on Aggregated ethernet interface when a new subinterface is added to an existing VxLAN VLAN-configured AE interface, it is observed that ingress packets are dropped with local-switching. The drop is very minimal with high traffic rate and the issue will self-recovers.

Resolved In: junos:23.2R2-S1 junos:23.4R2 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1760948Traffic drop will be observed on QFX5120-48YM when LLDP is enabled
Product-Group=junosvae
On Junos QFX5120-48YM platform, the mac interface of jsrv takes precedence over the chassis hardware mac-address while using Link Layer Discovery Protocol (LLDP) due to this traffic impact will be seen on that interface.

Resolved In: junos:20.4R3-S10 junos:22.4R3 junos:23.2R2 junos:23.4R2 junos:24.1R1
1783434In qfx5110-48s-4c and qfx5120 platform when below steps are used to upgrade the system(two member Virtual-Chassis), system can have non deterministic selection of master(i.e. not based on system uptime).
Product-Group=junos
In qfx5110-48s-4c and qfx5120 platform when below steps are used to upgrade the system(two member Virtual-Chassis), system can have non deterministic selection of master(i.e. not based on system uptime). ======= IP-Step1--Disable the uplink and downlinks from FPC-0 Switch. IP-Step2--Break the Virtual Chassis (VC) link between FPC 0 and FPC 1. IP-Step3--Initiate the upgrade process on the backup switch FPC0. IP-Step4--Swap the downlink and uplink ports by disabling them on the primary device[FPC1] and re-enabling those ports on the backup[FPC0] simultaneously. IP-Step5----Initiate the upgrade process on the Switch FPC1. IP-Step6----Bring back the Virtual chassis by enabling the VC ports. The FPC0 should become the Master at the end of STEP6 based on FPC uptime but FPC1 stays as the Master and FPC0 becomes backup. ========

Resolved In:
PR NumberSynopsisCategory: Category for QFX5K EVO Platform Software PRs related to Chas
1708773Intermittently Traffic gets blackholed on line side Tx/Rx on certain platforms
Product-Group=junos
On a rare scenario, platforms having Marvell PHY (Alaska 88x7121P ) such as ACX7348, QFX5700, ACX7100-32C, ACX7100-48L etc, intermittently traffic gets blackholed on line side Tx/Rx, when device is is fully loaded/populated with optics/DAC cables and is rebooted.

Resolved In: evo:23.4R2-EVO evo:24.3R1-EVO junos:23.4R2
PR NumberSynopsisCategory: RPD policy options
1714163The static routes are installed in the routing table even though interface routes are not present
Product-Group=junos
On all Junos and Junos OS Evolved platforms, the static routes are installed in the routing table even though the corresponding interface routes are not present.

Resolved In: evo:23.2R2-EVO evo:23.4R1-EVO junos:22.4R3-S2 junos:23.2R2 junos:23.4R1 junos:23.4R2
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1714416mspmand crashes after loading a new image
Product-Group=junos
Once the device is loaded with the new image, PIC tries to boot up. mspmand is one of the processes inside PIC, crashes sometimes.

Resolved In: evo:23.4R1-EVO junos:23.4R1
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1763406LDP traffic to destination route might be lost when TI-LFA is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when LDP tunnel over SR-TE route or over RSVP and LFA/rLFA/TI-LFA backup path for the same destination is configured, or if rLFA/LFA with L-ISIS as backup path is configured, the route to the destination is missing. LDP route for the destination is deleted because SR-TE LSP next hop is deleted by processing L-ISIS route with the backup path. Due to this LDP route gets deleted, LDP traffic to destination route is lost.

Resolved In: evo:21.4R3-S6-EVO evo:22.1R3-S5-EVO evo:22.3R3-S2-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:21.4R3-S6 junos:22.1R3-S5 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: all ipv6 dhcp bugs on srx platforms
1770332DHCP server not responding to some clients
Product-Group=junos
SRX DHCP server does not respond to some clients after upgrading to 21.4R3-S5.

Resolved In: junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: MX10003/MX204 Platform SW - Chassisd s/w defects
1743379The chassisd crash is observed on Junos MX204 platforms due to Fabric request timeout
Product-Group=junos
On Junos MX204 platforms, the chassid crash will be observed when the destination PFE (Packet Forwarding Engine) is not sending the grant within the specified time and Fabric request time out is observed. The traffic will be impacted during the time of crash.

Resolved In: junos:21.2R3-S8 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1732876Traffic drops will be observed when a BGP session comes up after the network flap
Product-Group=junos
On SRX platforms with BGP (Border Gateway Protocol) multipath and forwarding table policies configured, for the type 5 EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) tunnel routes traffic drops will be observed for a few composite next-hop that are not installed in PFE (Packet Forwarding Engine) when a BGP session comes up after the network flap. The issue can also happen when deactivating/activating OSPF (Open Shortest Path First) in the OSPF environment.

Resolved In: junos:23.2R2 junos:23.2R2-S1 junos:23.4R1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1802341Filter will be configured with incorrect vlan-IDs and commit error will not be displayed
Product-Group=junos
On mx10008 platform, filter will be configured with incorrect vlan-IDs and commit error will not be displayed if vlan-ID is not configured in the range of 0-4095 which is syntactically incorrect.

Resolved In: evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1794023The vlan tag in arp request packet is not getting removed with vlan-id none configured in EVPN scenario
Product-Group=junos
On MX platforms having legacy Junos cards (MPC2, MPC3, MPC5, MPC7 MPC9) and when single PE (Provider Edge) device is connected to multiple CE (Customer Edge) devices and PE to CE interfaces are part of single EVPN (Ethernet Virtual Private Network) routing-instance, the vlan tag in ARP (Address Resolution Protocol) request packet is not getting dropped in the host path and has extra tags in the response packet which gets removed in the CE device. Therefore the BGP (Border Gateway Protocol) sessions on CEs (Customer Edge) does not come up in an EVPN with vlan id none configured and having multiple PS (Pseudowire Subscriber) interfaces with CEs having different vlans in the same EVPN routing instance.

Resolved In: junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1718692Configuration update via python script does not work
Product-Group=junos


Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO junos:22.3R3-S2 junos:22.3R3-S3 junos:22.4R3 junos:23.2R2 junos:23.2R2-S1 junos:23.4R2 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: PTX/QFX100002/8/16 platform software
1642645[resiliency] [cm_infra] PTX10008 :: Verifying error counters failed as they are not in expected count due to an additional row for "OC-category" in "show chassis errors active detail"
Product-Group=junos
.

Resolved In: evo:22.1R1-EVO evo:22.1R2-EVO evo:22.2R1-EVO evo:22.3R1-EVO junos:22.1R1 junos:22.1R2 junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: VMHOST platforms software
1772127After device reboot Swap memory is not displayed in the CLI command output of "show system processes extensive"
Product-Group=junos
On the Junos PTX10008 and PTX10016 platforms, Swap memory is not getting displayed in the CLI command output of "show system processes extensive". The Swap partition is deleted for certain conditions on the Junos side and the external swap partition is not getting created during the boot-up, hence this issue is happening. The issue can be avoided temporarily using a workaround method until reboots. A permanent issue fix is provided for PTX10008 & PTX10016 in the latest release.

Resolved In: junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.4R2 junos:24.1R1