Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 21.2R3-S8 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.2R3-S8 is now available.

See the attachment for the complete list of Fixed and Known PRs .

21.2R3-S8 - List of Fixed issues 

PR NumberSynopsisCategory: EX4300 PFE
1785058PFE Crash will be seen on EX4300 Platforms
Product-Group=junos
On EX4300 Platforms, Packet Forwarding Engine (PFE) crash will be seen due to an unexpected switchover after committing interface configuration .
PR NumberSynopsisCategory: EX4300 Platform
1747374SFP modules are not detected after upgrade
Product-Group=junos
After an upgrade, the SFP modules are not detected in case of EX4300 platforms and the ports remain down impacting traffic.
PR NumberSynopsisCategory: EX2300/3400 PFE
1710360Certain EX platforms with option-18 configured may hinder the DHCPv6 process
Product-Group=junos
DHCPv6 clients drops DHCP Advertise packets as option-18 enabled specific Junos based EX platforms (EX4400, EX2300, EX3400, EX4300-MP, EX4100) which are sitting between the relay and the client, are sending malformed packets.
PR NumberSynopsisCategory: QFX VC Datapath
1779112After rebooting the VC device with 100G VCP port traffic drop observed on ipv4 and ipv6 streams
Product-Group=junos
When VC is formed with qfx5110-32q and qfx5110-48s, 0.2% traffic drop issue with 40G/100G optics will be seen only with line rate traffic upon reboot
PR NumberSynopsisCategory: SRX Gen-3 RE, leveraged from Point Success Mt.Rainier
1774760RE switchover observed in SRX5K platforms when ethernet switchports failure scenario on SCB
Product-Group=junos
On SRX5K platforms when all ethernet switch ports on Switch Control Board(SCB) fail, it triggers the Routing Engine (RE) switch over and RE0 is stuck in "Disabled" state. As RE0 is disabled and RE1 does have the functionality to coordinate chassis. No PIC will turn up which were failed and triggered the failover and traffic impact will be there for those particular ports and the complete service impact will be there if RE1 had any issue when RE0 is in disable state. RE0 did not recover by its own from the disabled state until manual reboot is done.
PR NumberSynopsisCategory: Fireall support for ACX
1789694ACX1100 PTP(enterprise profile) is stuck at freerun state
Product-Group=junos
ACX1100 PTP(enterprise profile) is stuck at freerun state after upgrading junos to 21.2R3
PR NumberSynopsisCategory: ChassisD changes specific for ACX series
1794939Port goes down after adding interface configuration and changing the port from 1g copper to 10g fiber
Product-Group=junos
On all Junos platforms, port goes down after unplugging the 1g copper and plugging 10g fiber and adding interface configuration because after unplugging the 1g copper (where autoneg is supported) , the auto-negotiationg structure does not get cleared and is still gets applied after plugging in the 10g fiber (where auto-negotiation is not supported).
PR NumberSynopsisCategory: ACX Interfaces IFD, IFL, vlans, and BRCM init
1786687After device upgraded on ACX5048/ACX5096 all interfaces are down
Product-Group=junos
On ACX5048/ACX5096 platform, after the device is upgraded, disabling an interface and then rebooting the device will cause a critical issue. All interfaces will go down, resulting in a complete traffic drop. There is no known workaround to prevent this service interruption during the upgrade process.
PR NumberSynopsisCategory: MPC Fusion SW
1796770Traffic impact during ISSU across FPCs on Junos MX platforms
Product-Group=junos
On Junos MX platforms traffic loss can be seen across FPC (Flexible PIC Concentrator) during ISSU if an FPC fails and recovers during iSSU (In-Service Software Upgrade). This issue is seen when ISSU is done from a release older than Junos 21.2 to release 21.2 or higher. The issue is due to number of Max PFE (Packet Forwarding Engine) mismatch between releases earlier than Junos 21.2 and releases 21.2 or higher.
PR NumberSynopsisCategory: MX Layer 2 Forwarding Module
1700073The device is using the MAC address of the IRB interface even after configuring static MAC for a default gateway
Product-Group=junos
On all Junos platforms supporting evpn-vxlan, on configuring static MAC (Media Access Control) address explicitly for a default gateway, the outer ethernet header of the packets are including the MAC address of the IRB (Integrated Routing and Bridging) interface instead of the configured virtual gateway MAC address.
PR NumberSynopsisCategory: SRX2000/50000 issue
1663839Syslog message CHASSISD_IPC_WRITE_ERR_NULL_ARGS are observed at commit
Product-Group=junos
Syslog message CHASSISD_IPC_WRITE_ERR_NULL_ARGS is observed at commit on SRX5K platforms. This is caused by unsupported chassis component connection on SRX5K platforms during commit checks. This syslog message is informational only for SRX5K, and was removed.
1775880A flowd crash is observed if CP receives the packets due to some hardware memory issue
Product-Group=junos
On SRX5K platforms with SPC3 and SPC2 cards, flowd crash will be observed if CP (Central Point) receives the packets due to some hardware memory issue either on IOC (I/O card) or SPC (Services Processing Card) which requires session lookup.
1787219Insufficient power alarm observed in SRX5K platforms
Product-Group=junos
On Junos SRX5600 and SRX5800 platforms, FPC (Flexible PIC Concentrator) will not come online due to insufficient power, leading to service disruption.
PR NumberSynopsisCategory: COS for australia platform
1596172"show interfaces queue < interface>" command output not correctly displaying bps values for throughput higher than 4.25Gbps
Product-Group=junos
"show interfaces queue < interface>" command output not correctly displaying bps values for throughput higher than 4.25Gbps. This behaviour is only present for throughput higher than 4.25Gbps per interface output queue.
PR NumberSynopsisCategory: PFE issue for flowd on australia SPU
1726888SNMP MIB walk for ipSystemStatsTable takes a long time to dump the output
Product-Group=junos
When polling ip SystemStatsTable, the responses have noticable delay
PR NumberSynopsisCategory: common or misc area for SRX product
1779749Traffic loss due to PPM not offloading LACP
Product-Group=junos
On SRX5K platforms, the LACP (Link Aggregation Control Protocol) packets are reaching the RE (Routing Engine) instead of ppm (Periodic packet management) which is causing extra strain on RE leading to dcpfe core dumps and causing LACP connections to go down or flap.
PR NumberSynopsisCategory: BBE Layer-2 Bitstream Access
1796125The broadband subscriber (L2BSA subscribers) on the core interface logging out with interface state changes
Product-Group=junos
On all Junos platforms, any configuration changes that involve interface down/up sequence, result in logging-out L2BSA (Layer 2 Broadband Subscriber Access) subscribers associated with that core interface.
PR NumberSynopsisCategory: BBE routing
1781938Access route may get stuck in the routing table after trying to change the prefix length using CoA message
Product-Group=junos
On Junos MX platforms with subscribers management enabled, the access route may get stuck in the routing table failing to update or be removed as expected. This occurs when a user attempts to modify the prefix length associated with this route using a Change of Authorization (CoA) message. This may lead to traffic loss, and if a subscriber goes down following the CoA change, there is a failure to bring that specific subscriber back up.
PR NumberSynopsisCategory: Border Gateway Protocol
1742287Junos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crash (CVE-2024-21585)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA75723 [juniper.net] for more information.
1778879Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak (CVE-2024-39549)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83011 [juniper.net] for more information.
1779533The RPD crash is observed on Junos and Junos Evolved platforms in Route Reflector scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, the RPD (Routing Protocol Daemon) crash can be seen in BGP-multipath scenario if it has more than 512 routes for a prefix. The RPD crash will cause a traffic drop but the system will self-recover.
1789863The rpd crash can be seen when large number of VRF instances are created and bgp peering terminated
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) crash will be observed when BGP (Border Gateway Protocol) is terminated by the user and if large number of VRF instances are created. This happens as some BGP internal data structure is not cleaned up properly. This crash can lead to a temporary traffic drop, but the system will automatically recover.
1803120Junos OS and Junos OS Evolved: Receipt of a large RPKI-RTR PDU packet can cause rpd to crash (CVE-2024-39543)
Product-Group=junos
A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to send specific RPKI-RTR packets resulting in a crash, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA83004 [juniper.net] for more information.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1767785The EOR message is missed for one peer in a scaled BMP scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms with BGP Monitoring Protocol (BMP) enabled in scaled scenario (4K BGP peers, 6 BMP stations), after disabling/enabling BMP, due to timing issues, one out of six BMP stations will not receive End-of-RIB (EOR) message for one peer. This will not impact routing or data forwarding, however will have impact on data collection.
PR NumberSynopsisCategory: BBE Remote Access Server
1697447Intermittent authd crash will be seen on Junos platforms in a DHCP subscriber scenario
Product-Group=junos
On Junos platforms, authd (Authentication Daemon) crash can be seen intermittently when 'excluded-address' syntax is used to exclude the same IP address which is already in use by the subscriber and the subscriber which holds the IP address will be logged off.
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1749943Hardware failure on MIC due to clock sync error is not reported with major alarm or log generation to notify the user
Product-Group=junos
On all MX platforms, faulty hardware issue on MIC due to clock sync error generated brings down the interfaces without any major alarm or log notification.
PR NumberSynopsisCategory: Class of Service
1795898COS output-traffic-control-profile is not getting attached to ps transport IFLs on a specific MX platforms that support HCOS
Product-Group=junos
COS output-traffic-control-profile does not get attached to ps (pseudowire service) transport IFLs when ps interfaces are configured over lt/rlt (logical tunnel/redundant logical tunnel) and both - ps transport IFL and ps service IFLs have COS output-traffic-control-profile configured, TCPs have different SMAPs (scheduler-maps) configured and these COS configuration on both these types of IFLs are committed in a single commit. This can impact COS scheduling on ps transport IFL.
PR NumberSynopsisCategory: QFX Access Control related
1776692When dot1x is configured, the eapol-block timer is not triggered for server-reject vlan
Product-Group=junos
On all Junos platforms, when "server-reject-vlan eapol-block block-interval" is configured on Dot1x, it is observed that when authenticating the client with server-reject vlan, eapol-block timer is not triggered and the device only keeps processing the EAP-start message.
PR NumberSynopsisCategory: Platform PR for 1G/10G LC
1739595The FPC will core and crash in a race condition
Product-Group=junos
On all Junos and Junos Evolved platforms, in a rare scenario, the FPC will go down due to core.
PR NumberSynopsisCategory: PMB (AMD) PR for 1G/10G LC
1722823The FPC crash is observed on Junos MX10008 platform when connected to non-Juniper SFP
Product-Group=junos
On Junos MX10008 platform, the FPC (Flexible PIC Concentrator) crash will be observed when connected to non-Juniper SFP (Small Form-factor Pluggable) and it will lead to traffic loss.
PR NumberSynopsisCategory: Device Configuration Daemon
1658016Observed error log "UI_CONFIGURATION_ERROR
Product-Group=junos
Due to the issue, an error log is printed, and the dcd is restarted. But there is no functionality impact for BFD sessions. There may be a slight delay in the new config taking effect as dcd is restarted.
1712800On Junos platforms the dcd will flap the IFLs which are part of EVPN routing-instance
Product-Group=junos
On Junos platform that support VPLS and/or EVPN, on configuring IGMP-Snooping or VPLS, over Bridge-domain (BD), the data-carrier-detect (dcd) will flap the Logical Interface (IFLs) which are part of this EVPN routing-instance.
1742124DCD crash can be seen sometimes while pushing config using API
Product-Group=junos
On all Junos platforms, dcd crash can be seen when interface configuration is added using API and some Junos application (such as vrrpd, jdhcpd etc) send configuration for the same interface using Overlay files. This is because, in dcd the internal data structures are not updated correctly when config source is changed from API to Overlay which eventually leads to corruption. It does not cause any service impact.
1799112EX: DCD core dump is observed when working with Mist
Product-Group=junos
On EX series which is working with Mist, dcd core might be observed.
PR NumberSynopsisCategory: Firewall Filter
1713329Unexpected random behavior will be seen with back-to-back deleting and adding of configuration
Product-Group=junos
On all Junos platforms, unexpected random behavior will be seen with back-to-back deleting and adding of configuration.
1714988The Firewall filter with syslog action will not work when applied on the ingress of a loopback interface
Product-Group=junos
The firewall filter with syslog action on lo0 does not work as expected due to which logs are not seen on the log file.
PR NumberSynopsisCategory: ACX platform interface issues
1747140QSFP interfaces show additional flap during PFE bringup
Product-Group=junos
On Junos ACX5448 platform, the QSFP (Quad Small Form-factor Pluggable) interfaces can possibly see a momentary flap during device or pfe bring up.
1784447ACX710 CFM asynchronous-notification feature driven on CCC-down is not supported
Product-Group=junos
ACX710 CFM asynchronous-notification feature driven on CCC-down is not supported. While this feature is configurable on ACX710, it does not work as expected, in that after the remote PE-CE link flap (ie. down and up) , the local PE does not bring up the CE-facing port.
PR NumberSynopsisCategory: DNX Multicast
1805017Multicast route is reset every 5 mins with igmp receiver on acx2200 with small traffic loss
Product-Group=junos
Multicast route is reset every 5 mins with igmp receiver on acx2200 with small traffic loss. Multicast route that are not active would get reset after 5 minutes due to cahce timeout. This was happening even for active routes that had traffic.
PR NumberSynopsisCategory: JUNOS Dynamic Profile Configuration Infrastructure
1797305The KRT queue stuck resulting in subscriber traffic loss
Product-Group=junos
On Junos MX platforms with subscriber dynamic profile versioning, following a commit configuration command, the krt ( Kernel routing table) queue becomes stuck on the master Routing Engine (RE), causing loss of subscriber traffic and subsequent client restarts. This occurs due to a large number of queued entries, resulting in blockage of the KRT queue.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1807084The VXLAN traffic drop could be seen after modifying control-word in an EVPN instance
Product-Group=junos
On MX, QFX and PTX10K line of routers running Junos OS Evolved with static Virtual Extensible LAN (VXLAN), the Virtual Tunnel Endpoint (VTEP) connections may not work properly after enabling or disabling control-word in the EVPN instance. This could disrupt the connectivity provided by the static VXLAN setup and affect data traffic.
PR NumberSynopsisCategory: EX4400 PFE software
1738384The 'input-vlan-map push' operation will not work on double-tagged frames
Product-Group=junos
On EX4400 platforms, when 'input-vlan-map push' is configured to push an outer VLAN (Virtual Local Area Network) tag on to a double-tagged frame, the egressing frame will be tagged incorrectly. Instead of a push operation, the outer VLAN tag of the ingressing double-tagged frame will be swapped and sent out. This results in unexpected behaviour or traffic loss as the Ethernet frames will not have the expected VLAN tag information.
1752898In Q-in-Q push/pop configuration for double tagged protocol traffic it is seen that the third VLAN tag is getting swapped instead of getting pushed onto the stack
Product-Group=junos
On Junos EX4350/EX4650-48Y/QFX5120/QFX5120-32C/QFX5120-48Y/QFX5120-48T/EX4400/EX4100 platforms, it is observed that during Q-in-Q push/pop configuration when double tagged protocol traffic like BGP (Border Gateway Protocol) /RIP (Routing Information Protocol) /OSPF (Open Shortest Path First) etc. packets are send towards UNI (User to Network Interface), the third tag is not getting added using firewall rule instead a swap operation is being done and the packet is forwarded as double-tagged. As a result, next device drops the traffic because expectation on that node is triple tagged frames.
PR NumberSynopsisCategory: EX4400 platform
1754931The transceiver fails to get detected after the system reboot
Product-Group=junos
On certain EX platforms, when the device is rebooted, transceivers will not be detected. Failing to detect the transceiver results in no IFD.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1774202The DHCP client will not be able to get the IP address
Product-Group=junos
On Junos EX4300MP platforms, in the Virtual Extensible LAN Layer 3 Gateway (VXLAN L3GW ) environment with Dynamic Host Configuration Protocol (DHCP ) security configured, the offer packets going towards client-facing interfaces are coming out with an additional vlan tag due to which DHCP bindings will not work.
PR NumberSynopsisCategory: EX POE
1782445PoE interfaces will not come up on EX4300-xxP switch after a reboot when part of a Virtual Chassis
Product-Group=junos
After rebooting a mixed Virtual Chassis (VC) of EX4300-xxP and EX4300-MP switches or rebooting a EX4300-xxP member, interfaces with Power over Ethernet (PoE) configured will not come up on EX4300-xxP members.
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1779890On QFX10002-60c platforms, during system reboot and fpc reboot time, some non functional error logs are displayed.
Product-Group=junos
On QFX10002-60c express based Junos platform the error logs are seen during boot time. These errors are not impacting any functionality. The table is getting programmed correctly. These are seen during system reboot and fpc reboot time. We will be emitting the logs for non default routing instances and not for default routing instance.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1770678Incorrect IFL value resulting in the PFE crash
Product-Group=junos
On Junos QFX10K platforms, the PFE crash is observed resulting in traffic loss due to an incorrect IFL (Logical Interface) value while static MAC address programming.
1779527At the interface level, only half of the traffic is policed when applying a policer
Product-Group=junos
On QFX10002-36q, QFX10002-72Q, QFX10008 and QFX10016 platforms, when applying a policer at the interface level only half of the traffic is policed.
PR NumberSynopsisCategory: Express PFE L3 Multicast
1774562PIM join are not learnt for multicast IPs
Product-Group=junos
On Junos PTX platforms, with PIM BIDR (Protocol Independent Multicast- Bidirectional) mode with "set protocols pim rp bidirectional address <> group-ranges <>" configuration, PIM/MLD joins will not be learnt for multicast IPs other than link local IP and MY IP which will lead to traffic impact. Also, lo0 filter which were introduced with PR 1701756 for IGMP and MLD will be applied only for MY IPs and Link local IPs. For any other IPs other than above, lo0 filter will not work.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1739559SRX4100/4200 accepts the datapath-debug configuration although it does not support it
Product-Group=junosvae
It is possible to set and commit the datapath-debug configuration on platforms SRX4100/SRX4200 although datapath debugging is not supported on those platforms. because of this unsupported configuration being accepted the RE (Routing Engine) load can go high and cause traffic outage. The workaround is to remove the datapath-debug configuration and perform a commit.
PR NumberSynopsisCategory: IDP policy
1786822The flowd process crash is observed when the device is rebooted
Product-Group=junos
On all Junos SRX platforms, flowd crash is seen when the device is rebooted and a CLI request for Intrusion Detection and Prevention (IDP) counters reaches the Packet Forwarding Engine (PFE) before the IDP memory module is initialized (even if IDP is not configured). The flowd process restarts affecting the traffic.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1787707The KRT queue will be stuck on Junos ACX710 platform
Product-Group=junos
On Junos ACX710 platform with BGP (Border Gateway Protocol) configuration, the response message will be lost and it will lead to element being stuck in the KRT (Kernel Routing Table) queue.
PR NumberSynopsisCategory: BSDX Software installation issues
1783119Delays can be seen while the upgrading process runs due to the status of UFS set to mode enable.
Product-Group=junos
In USF mode enabled router, While upgrading router having scaled services AMS config with "load-balancing-options disable-hash", Router continuously dumps "'disable-hash' knob is only allowed in USF mode" error. This delays the bootup time with scaled config.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1747289VRRP traffic will drop when the member link from the AE bundle is deleted, even if there are active members in the AE bundle
Product-Group=junos
On Junos using afeb/tfeb way of communication to PFE that is MX80/MX104 platforms with Virtual Router Redundancy Protocol (VRRP) configured, deleting a member link from the Aggregated Ethernet (AE) bundle removes the VRRP filter entry in the Packet Forwarding Engine (PFE) which causes VRRP traffic to get dropped even though other active member links in the AE bundle exists.
PR NumberSynopsisCategory: ISIS routing protocol
1782887Traffic blackhole due to Flex-algo not removing stale entries from ISIS database
Product-Group=junos
On all Junos and Junos Evolved platforms, in an ISIS scenario using Flex-algo , the system does not remove the stale (outdated) entries from the ISIS database causes traffic blackholing. This issue could lead to some traffic loss, as the routing information stored in the ISIS database does not get properly updated.
PR NumberSynopsisCategory: jdhcpd daemon
1763336The backup BNG device has an incorrect IPv6 neighbor link-layer address when OLT is using a virtual MAC-address
Product-Group=junos
On MX platforms in the ALQ (Active Leasequery) EVPN-VPWS (Ethernet VPN - Virtual Private Wire Service) without topology-discover scenario, traffic impact will be observed for subscribers due to DHCPv6 binding with the incorrect MAC-address at the time of fail-over from Master BNG (Broadband Network Gateway) to Backup BNG device. This issue results in the backup BNG device having an incorrect IPv6 (Internet Protocol Version 6) neighbor link-layer address when OLT (Optical Line Termination) is using a virtual MAC-address. The issue happens when an OLT device with virtual MAC is configured in the transit path to DHCPv6 (Dynamic Host Configuration Protocol version 6) Relay/Server ALQ Master.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1781379The SIP UDP register packet will be dropped on MX and SRX platforms
Product-Group=junos
On all MX and SRX platforms, SIP (Session Initiation Protocol) UDP (User Datagram protocol) register packet will be dropped by ALG (Application Layer Gateway) when the USER-AGENT is filed with some unknown language
PR NumberSynopsisCategory: Flow Module
1742739Virtual Routing Instance configured on ingress interface will drop the icmp traffic
Product-Group=junos
On all Junos platforms, when routing instance of type "virtual router" is configured on the interface the ping response packets will get dropped and no ping response will be received on the ingress interface.
1776940Junos OS: SRX4600, SRX5000 Series: TCP packets with SYN/FIN or SYN/RST are transferred after enabling no-syn-check with Express Path (CVE-2024-39561)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an attacker to send TCP packets with SYN/FIN or SYN/RST flags, bypassing the expected blocking of these packets. Please refer to https://supportportal.juniper.net/JSA83021 [juniper.net] for more information.
1783101The srxpfe process crash when SkyATP turned on
Product-Group=junos
On all SRX series devices, when SkyATP feature is used, the srxpfe process may unexpectedly crash causing the device to reboot automatically
1783595PMI sends packets to the wrong destination
Product-Group=junos
On SRX platform, when the next-hop changes, the PowerMode Ipsec (PMI) induces the packets to be sent to the wrong destination, causing packet drops.
1791633Packets over GRE or IPIP or GRE(PMI) will not reach destination
Product-Group=junos
On Junos platforms with GRE or GRE(PMI) or IPIP tunnels, when tunnel TTL(Time To Live) is set to 1 in the CLI, the traffic sent over GRE or IPIP or GREoIPSec tunnel does not reach its destination.
1802089The commit will not go through when more than 128 vrf-groups for l3vpn configuration are configured
Product-Group=junosvae
On SRX4x00 and SRX5x00 platforms, the commit will not go through and the traffic will get impacted when more than 128 vrf-groups for l3vpn configuration are configured.
PR NumberSynopsisCategory: SRX Firewall Authentication
1804149The sxrpfe and fwauthd crash will be seen
Product-Group=junos
On all SRX platforms, the sxrpfe and fwauthd crash will be seen. The srxpfe crash is caused from the fwauth plugin in the PFE side of SRX and the fwauthd crash is caused by the fwauthd daemon running on RE side of SRX due to buffer overflow.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1638794Post a series of actions MNHA functionality might not be available despite the configuration presence
Product-Group=junos
On specific SRX platforms (SRX5400/SRX5600/SRX5800/vSRX3.0) with Multinode High Availability (MNHA) configured, when the chassis high-availability configuration is deleted but not committed, if the device reboots it considers high-availability mode as not configured despite the configuration being in place, in turn impacting MNHA functionality.
1702763The secure tunnel interface does not work properly in SRX standalone mode
Product-Group=junos
On Junos SRX5400/5600/5800/4100/4200/4600/1500/vSRX3.0 platforms, when the secure tunnel interface (st0) st0.16000-st0.16385 is defined in standalone mode, st0.16000-st0.16385 does not work properly which leads to a traffic impact. From 20.4R1 onwards, st0.16000-st0.16385 is hardcoded to be added to a high-availability zone, so it will not work in other zones.
1726753Traffic loss after RG1 failover
Product-Group=junos
On vSRX3.0, after an Redundancy Group (RG1+) failover, packets may be sent from the SRX physical interface's MAC address instead of the Redundant Ethernet interface (reth's) virtual MAC which can result in traffic loss.
1736498In SRX MNHA cluster setup the RSI takes long time to generate
Product-Group=junos
In SRX MNHA cluster setup the RSI takes long time to generate on the MNHA backup node. The RSI includes the command "show security flow session session-state warm" which will collect all the sessions in warm state on the MNHA backup node - this output can be extensive and RSI is being generated an extended period of time, in known instances this was 1-2 hours.
PR NumberSynopsisCategory: l2 flow module
1780182SRX with transparent mode may fail to create a new flow session for multicast traffic when vlan has l3-interface
Product-Group=junos
On all SRX platforms, when transparent mode is used, flow session does not create for the first few multicast packets due to which traffic drop occurs when l3-interface is used. The issue only happen in flow session creation process for Multicast traffic and the unicast traffic is unaffected. Once the flow session is created, multicast traffic will not be dropped.
PR NumberSynopsisCategory: Firewall Policy
1783249Security policies may go out of sync during ISSU
Product-Group=junos
On all SRX platforms, performing ISSU (In-Service Software Upgrade) to or from an affected release can lead to policies going out of sync between control plane and forwarding plane. Affected releases are 19.4R3-S13, 20.4R3-S8/9/10, 21.2R3-S6/7; 21.4R3-S5/6; 22.2R3-S2; 22.4R3; 22.4R3-S1; 23.4R1. To recover, use the CLI command "request security policies resync".
PR NumberSynopsisCategory: IPSEC/IKE VPN
1716092Junos OS: SRX Series, MX Series with SPC3 and NFX350: When VPN tunnels parameters are not configured in specific way the iked process will crash (CVE-2024-39545)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on SRX Series, MX Series with SPC3 and NFX350 allows an unauthenticated, network-based attacker sending specific mismatching parameters as part of the IPsec negotiation to trigger an iked crash leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83007 [juniper.net] for more information.
1773276IPsec tunnels will not be established due to memory leak
Product-Group=junos
On all SRX platforms, due to a memory leak (304 bytes) happening with every Diffie-Hellman (DH) key exchange operation, after some time when QuickAssist (QAT) crypto memory hits the maximum capacity, then the Internet Protocol Security (IPsec)tunnels will fail to establish the connection with peers.
1783738The kmd/iked process crashes under rare circumstances
Product-Group=junos
On Junos SRX/MX platforms, VPNs (Virtual Private Network) that employ the use of KMD (ipsec-key-management) or IKED (ike-key-management) may inadvertently crash while generating the random number used by IPSec services which can cause the device to become very busy.
1784752High RE CPU observed on both nodes in chassis cluster due to jsrpd
Product-Group=junosvae
High RE (Routing Engine) CPU caused is caused by jsrpd (Junos stateful redundancy protocol daemon) on both the nodes in a chassis cluster configured with control link Encryption (Internal SA) after upgrading the cluster.
PR NumberSynopsisCategory: Security platform jweb support
1779376Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS (CVE-2024-21620)
Product-Group=junos
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. Please refer to https://supportportal.juniper.net/JSA76390 [juniper.net] for more information.
1786296Junos OS: SRX Series, EX Series: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device
Product-Group=junos
An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to execute remote commands on the target device. Please refer to https://supportportal.juniper.net/JSA83023 [juniper.net] for more information.
PR NumberSynopsisCategory: Layer 2 Control Module
1770053xSTP configured interface will remains in discarding state
Product-Group=junos
On all Junos and Junos OS Evolved Platforms, when an interface is added inside RSTP (Rapid Spanning Tree Protocol), VSTP (VLAN Spanning Tree Protocol), MSTP (Multiple Spanning Tree Protocol) or STP (Spanning Tree Protocol), because of STP port creation fail from l2cpd (Layer 2 control protocol daemon), port will remains in discarding state. This leads to traffic impact.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1743737The switch-options settings on the logical-system will be not reflected after RE rebooting or RE switchover or restart of l2-learning
Product-Group=junos
The switch-options settings on logical-system will be not reflected after RE (Routing Engine) rebooting or RE switchover or l2-learning. This issue is seen only with logical-system and with the default instance, this behavior is not seen.
1772424Connectivity between static and LDP signaled pseudowires broken in VPLS after upgrade and results in VPLS traffic drop
Product-Group=junos
On all Junos and Junos OS Evovled platforms, when there is a upgrade and also when one mesh group of routing instance is substring of other, the connection between static and LDP (Label Distribution Protocol) signaled psuedowires is broken will lead to traffic drop.
1776991ARP resolution issues will be observed in the H-VPLS environment
Product-Group=junos
On Junos and Junos Evolved platforms, traffic impact will be observed due to ARP (Address Resolution Protocol) resolution issues when multiple mesh-group is configured under the same routing-instance and the name of each mesh-group is not unique i.e. substring of another mesh-group in the H-VPLS (Hierarchical Virtual Private LAN Service) environment.
1803898Traffic flooding occurs when deactivating and activating interfaces in EVPN scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms, while deactivating/activating the interface, the first control MAC for a BD and IFL combination can get lost when L2alm'd ifbd Mac sequence num is different from what is sent by L2ald. This will lead to traffic flooding for the MAC which will be impacted.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1729467MACsec interoperability issue between Juniper and non Juniper platforms
Product-Group=junos
On all Junos and Junos Evolved platforms with MACsec (Media Access Control security) configured , frequent SAK (Secure Association Key) rollover is observed when the peer device is a non-Juniper box and the Juniper device is acting as the key-server. This results in unstable MACsec sessions between the juniper device and the non Juniper device.
PR NumberSynopsisCategory: MX Timing software
1742266PLL Core Frozen alarm may be seen in very rare occasion
Product-Group=junos
There are remote possibility of hitting PLL core hardware issue. PLL_CMERROR_MPC_CORE_FREEZE alarm would be seen if this issue is hit on an MPC A major alarm "PLL Core Frozen" would be raised, if this issue is hit on SCBE3, Example outputs below. ===== regress@# run show chassis errors active detail fpc-slot 0 Slot 0 command: show chassis errors active detail -------------------------------------------------- Location : FPC 0 Identifier : /fpc/0/pfe/0/cm/0/PLL_Core_Error/0/PLL_CMERROR_MPC_CORE_FREEZE Error : PLL_CMERROR_MPC_CORE_FREEZE Scope : board Category : functional Severity : Major Details : pll core Error Count : 1 Support : No help info provided ***Command executed successfully*** Addressed Enhancing Alarm with RE to indiacte slot regress@# run show chassis alarms 1 alarm currently active Alarm time Class Description 2024-02-12 20:02:16 PST Major RE 0: PLL Core Frozen ===== MPC need to be power cycled to cover from this alarm Chassis need to be power cycled to recover SCBE3 in the problem state.
1772138DUT is sending same source-port-id for two PTP master links connected to downstream node with multiline card scenarios
Product-Group=junos
On Junos MX240/480/960/2010/2020/2008 Distributed Precision Time Protocol (PTP) platforms, When PTP master/slave/stateful is configured across multiple linecards and allocated with same port-number in the line cards, then the packets generated from both the ports, shall contain the same source-port-id. It shall create Baseboard Management Controller (BMC) issues in G.8275.1 deployment and passive port monitoring deployments.
1781161After a GRES the MX external clock is stuck in a Holdover State
Product-Group=junos
After a GRES the MX external clock is stuck in a Holdover State
1800134Clksyncd core dump observed when performing snmp mib walk
Product-Group=junos
On Junos MX80 platform, post upgrade to 21.2R3-S6.11 from 21.2R3-S4.8, when snmp mib walk is done clksyncd core dump can be seen, however there is no service impact due to this issue.
PR NumberSynopsisCategory: Track Mt Rainier RE platform software issues
1778324The FPC connection times out and reboots post mastership switchover
Product-Group=junos
On Junos MX and PTX with VMHost MT-RE (NG-RE), when the RE< -> CB link down triggers the Routing Engine (RE) switchover, the switchover will be successful but Flexible PIC Concentrators (FPC) will not reconnect to the new master RE. The FPCs reboot and then connect to the new master RE automatically.
PR NumberSynopsisCategory: Odin Timing software
1783632SyncE clock get stuck in 'none' or 'abort' state and impact PTP performance
Product-Group=junos
On Junos ACX710 platform, with chassis restart, after SyncE port flaps or SyncE config changes between primary and secondary source, leads SyncE(Synchronous Ethernet) clock get stuck in 'none' or 'abort' state and impact PTP(Precision Time Protocol) performance.
1800385ACX710 PTP master port gives wrong PTP flag values in Announce messages
Product-Group=junos
In rare condition after PTP protocol or interface flaps, some PTP master port would carry the PTP flag 0x08 in Announce message, which means FREQUENCY_TRACEABLE, TIME_TRACEABLE, and PTP_UTC_REASONABLE all set to 0, ie. False. Moreover, The 'localStepsRemoved' value carried in this same Announce message will set to '0', which leads to the downstream slave node calculate the hop counts toward GMC starting as '1'
PR NumberSynopsisCategory: PFE Peer Infra
1747077Due to timing issues, PFE/PICs will be slow and traffic will be impacted on all Junos platforms
Product-Group=junos
On all Junos platforms, due to timing issues the PFE (Packet Forwarding Engine) /PICs (Physical Interface Card) will be slow and services will face slowness issue and error message: 'Minor potential slow peers are: X' will be seen. This is rare timing issue.
PR NumberSynopsisCategory: TCP/UDP transport layer
1761242TCP window scaling may be not applied to the first TCP packet sent to the client after the three-way handshake, leading to unnecessary segmentation.
Product-Group=junos
On all JUNOS platforms, the first TCP packet sent by Junos to the client after the three-way handshake may be unnecessarily segmented due to TCP window scaling option being not applied even if it was negotiated.
1790049The BGP TCP output queue remains full
Product-Group=junos
On all Junos platforms, after upgrading to 24.2 and above, a BGP TCP output queue (outQ) may remain full until the TCP session is clear.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1743306FTI interface status (up/down) does not sync between master and backup RE.
Product-Group=junos
FTI IFD's and IFL's are not cleaned up on new backup in a switchover where graceful-switchover is not configured. This leads to mismatch between interface status or even commit error.However, with gres config "set chassis redundancy graceful-switchover", no issue is seen.
1753191ARP resolution failure for lt interfaces is observed after cluster failover on Junos SRX platforms
Product-Group=junos
On Junos SRX platforms in cluster, Address Resolution Protocol (ARP) resolution fails for logical tunnel interfaces when the logical tunnel interfaces are toggled and the cluster switchovers.
PR NumberSynopsisCategory: OSPF routing protocol
1774715OSPF route flap might be observed
Product-Group=junos
On all Junos and Junos OS Evolved platforms OSPF (Open Shortest Path First) route flaps can be observed which will cause a traffic drop. This is a rare timing issue happening after an OSPF adjacency flap.
PR NumberSynopsisCategory: PFE COS features on PE based platforms
1725833Traffic drop and error message observed during boot time on certain QFX platforms
Product-Group=junos
On Junos QFX10002, QFX10008, QFX10016 platforms, it is observed that that during upgrade when device is booted, the error message " dc-t10qfx10002-4-q fpc0 PFE_ERROR_FAIL_OPERATION: IFD:xe-0/0/22:3 chip0: is_pvq:0 vpfe12 state lookup failed forpvq_offset:0 vpfe12=17" is observed and there is traffic drop.
PR NumberSynopsisCategory: Protocol Independant Multicast
1792886The rpd crash is observed when PIM SSM mode with RPF-Vector and MoFRR is configured
Product-Group=junos
On Junos and Junos Evolved platforms , when PIM SSM (PIM Source-Specific Multicast) with RPF (Reverse Path Forwarding)-Vector and MoFRR (Multicast-only fast reroute) is configured , rpd crash if the device receives PIM Prune message for (S, G) state with RPF vector TLV. interface is freed for the (S, G) from the outgoing interface list i.e. RPF-Vector TLV (Type, Length, and Value) having (S, G) is getting freed but that same (S, G) is still used by MoFRR. The issue happens when MoFRR Backup upstream interface is also listed at the outgoing interface list for the (S, G)
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1480648Junos OS and Junos OS Evolved: Flaps of BFD sessions with authentication cause a ppmd memory leak (CVE-2024-39536)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the Periodic Packet Management Daemon (ppmd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA82996 [juniper.net] for more information.
1687395On single PFE with Fusion satellite, LACP is not sending PDUs
Product-Group=junos
On platforms supporting Fusion technology, LACP (Link Aggregation Control Protocol) is not up on the aggregate ethernet interfaces when a satellite device is connected to an aggregate device with a single PFE (Packet Forwarding Engine) and is upgraded to a software version 19.4 and above.
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1782239After Routing Engine switchover PPPoE subscribers may fail to login
Product-Group=junos
On all Junos OS on MX Platforms, after Routing Engine (RE) switchover using BNG for PPPoE (Point-to-Point Protocol over Ethernet) subscribers, may impacting customers authentication or failing to connect.
PR NumberSynopsisCategory: QFX PFE Class of Services
1667879Shaping-rate is not taking 20bytes of overhead into account.
Product-Group=junos
During shaping-rate, 20 byte of Layer 1 overhead was not taken into account.
PR NumberSynopsisCategory: QFX L2 PFE
1736348BFD session remains stuck in INIT state on certain QFX and EX platforms
Product-Group=junos
On Junos QFX5120-48Y/EX4650-48Y/QFX5120-32C platforms, when the MAC (Media Access control) address corresponding to a next hop is updated, the BFD (Bidirectional Forwarding Detection) endpoints that are using this Next hop/egress is not picking up the updated MAC address and as result BFD session remains in INIT state and causes traffic impact.
1771183Memory leak observed on non-local FPC for Junos QFX5K and EX platforms
Product-Group=junos
On Junos QFX5K and EX platforms in virtual chassis (VC), memory leak happens for non-local Flexible PIC Concentrators (FPC) when delete/detach of interface is performed.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1796210In the EVPN-VxLAN scenario traffic blackholes on spine reboot
Product-Group=junos
On all Junos QFX5K and some specific EX4K in EVPN-VxLAN (Ethernet VPN-Virtual extensible LAN) environment with underlay connections using Virtual Chassis Port Link Aggregation with AE (Aggregated Ethernet) interface and during one of the spine reboot, traffic will not be immediately switched to another spine and traffic blackholes.
1802958ECMP programming issue on Junos QFX5K/EX4K in EVPN-VXLAN
Product-Group=junos
In rare scenarios on Junos QFX5K/EX4K platforms that are part of Ethernet VPN - Virtual extensible LANs (EVPN-VXLAN) Fabric topology and employing ECMP (Equal Cost Multi-path) routing on the underlay interfaces between the Leaf and Spine, if one or more of these physical underlay interfaces flaps or their associated underlay protocol adjacency flaps and this time aligns precisely with the associated unicast next-hop deletion process, a race condition may occur, resulting in the potential failure to program the associated ECMP interface next-hop entry correctly in the hardware table.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1640813Junos OS and Junos OS Evolved: RPD crash when CoS-based forwarding (CBF) policy is configured (CVE-2024-30382)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to memory corruption, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79174 [juniper.net] for more information.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1793196Multicast traffic black-holing upon MoFRR primary link went down
Product-Group=junos
On all Junos and Junos Evolved platforms, when MoFRR (Multicast-only fast reroute) is configured with NSR (Non-stop routing) while interface flapping or RE switchover, there is a next-hop leak and the next-hop in RIB (Routing Information Base) is different from the next-hop in FIB (Forwarding information base) due to that multicast traffic will be impacted.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1716431Memory leak will be observed in rpd after performing restart routing
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms with rib-sharding enabled, memory leak will be observed in rpd when restart routing is performed. If system is up from long time and restart routing performed multiple times can exhaust system memory that causes to process crash or configuration are not effective/applied because of lack of memory then it is possible that it will impact traffic.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1740028Junos OS and Junos OS Evolved: Concurrent deletion of a routing-instance and receipt of an SNMP request cause an RPD crash (CVE-2024-39528)
Product-Group=junos
A Use After Free vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA82987 [juniper.net] for more information.
PR NumberSynopsisCategory: Resource Reservation Protocol
1785214RSVP incorrectly determines the outgoing interface resulting in the rpd crash
Product-Group=junos
On Junos platforms, the rpd (Routing Protocol Process Daemon) crash is observed when LSP (Label-Switched-Path) terminates on the incorrect outgoing interface. The issue happens because RSVP (Resource Reservation Protocol) incorrectly determines the outgoing interface that the ResvTear applies to.
PR NumberSynopsisCategory: jflow/monitoring services
1656885The srrd process might crash in a high route churns or process flap scenario
Product-Group=junos
On all Junos OS platforms with inline Jflow enabled, the sampled route reflector process (srrd) might crash at times due to unavailability of memory resource during high route churns or flaps scenario.
1725360Continuous route flaps in short interval will cause the srrd to restart
Product-Group=junos
On all Junos platforms continuous route flaps in short interval will cause the srrd (Sampling Route-Record Daemon) to restart and core-dump could be observed.
PR NumberSynopsisCategory: Issues related to control plane security
1780283Junos OS and Junos OS Evolved: Loading a malicious certificate from the CLI may result in a stack-based overflow (CVE-2024-39556)
Product-Group=junos
A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos OS Evolved may allow a local, low-privileged attacker with access to the CLI the ability to load a malicious certificate file, leading to a limited Denial of Service (DoS) or privileged code execution. Please refer to https://supportportal.juniper.net/JSA83016 [juniper.net] for more information.
1781732Junos OS and Junos OS Evolved: Impact of Terrapin SSH Attack (CVE-2023-48795)
Product-Group=junos
An Improper Validation of Integrity Check Value vulnerability in OpenSSH before 9.6 of Juniper Networks Junos OS and Junos OS Evolved allows a remote attacker to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka the Terrapin Attack. Please refer to https://supportportal.juniper.net/JSA76462 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1801201IKE is not coming up with dhgroup19 and dhgroup20
Product-Group=junos
IKE is not coming up with dhgroup19 and dhgroup20. The below Junos releases are impacted. junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3-S1 junos:24.1R1. So previous to these releases dhgroup19 and dhgroup20 should be working.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1775593Junos OS and Junos OS Evolved: Multiple vulnerabilities resolved in net-SNMP 5.9.4
Product-Group=junos
Multiple vulnerabilities have been resolved in net-SNMP software included with Juniper Networks Junos OS and Junos OS Evolved by upgrading net-SNMP to version 5.9.4, or by fixing vulnerabilities found during internal testing. Please refer to https://supportportal.juniper.net/JSA82973 [juniper.net] for more information.
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1766594After the device reboot JSC stops accepting user connections
Product-Group=junos
On all SRX platforms, when Juniper Secure Connect (JSC) configuration is done on Point-to-Point Protocol over Ethernet (PPPoE) interface then after the device reboot, JSC clients couldn't connect.
PR NumberSynopsisCategory: SRX branch platforms
1611400VPLS interface fails to forward traffic on SRX platform
Product-Group=junos
On all Junos SRX platforms, VPLS(Virtual Private LAN Service) interface configured output filter with policer action may stop forwarding the traffic. The VPLS interface shows output bytes as 0, although the input packets and bytes are incremented.
1714620High latency will be observed while pinging to peer device
Product-Group=junos
On Branch SRX Platforms, The delay will be observed while pinging to peer device due to high latency when VLAN(Virtual Local Area Network) tagged DHCP(Dynamic Host Configuration Protocol) packets arrive at IRB (Integrated Routing and Bridging) interface.
1738271"Minor Autorecovery information needs to be saved" alarm is not displayed after zeroize
Product-Group=junos
On SRX Branch platform, "Minor Autorecovery information needs to be saved" alarm is not displayed after running zeroize command
1744108Commit panic reboot observed after implementing system processes watchdog timeout 180 on SRX hardware platforms
Product-Group=junos
On SRX hardware platforms, configuring set system processes watchdog related command causes commit panic reboot. Watchdog related commands are unsupported on SRX hardware platforms.
1746202Kernel CPU temperature becomes high and the flowd process crashes with dual VLAN tag configured
Product-Group=junos
On all SR3xx platforms having Q-in-Q tunnelling on VPLS (Virtual Private Local Area Network Service) over GRE (Generic Routing Encapsulation) tunnel, it is seen that due to dual VLAN (Virtual Local Area Network) tag configuration, the kernel CPU (Central Processing Unit) temperature becomes high along with the flowd process getting crashed.
1780326IP Monitoring fail to install route after SRX cluster reboot
Product-Group=junos
On Junos SRX branch series platforms in cluster, the IP Monitoring fails to install route after the SRX cluster reboots.
PR NumberSynopsisCategory: SRX5XX platform
1514925Junos OS: An unauthenticated attacker with local access to the device can create a backdoor with root privileges (CVE-2023-44194)
Product-Group=junos
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS allows an unauthenticated attacker with local access to the device to create a backdoor with root privileges. Please refer to https://supportportal.juniper.net/JSA73158 [juniper.net] for more information.
PR NumberSynopsisCategory: SSL Proxy functionality on JUNOS
1753540The flowd process will crash due to memory stress
Product-Group=junos
On Junos based SRX platforms in a low memory condition, the flowd process will crash because of memory corruption and crash files will be observed. Traffic flow will be impacted till the time flowd restarts.
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1764457Traffic drop observed at the source pfe when the destination line card has fabric link error
Product-Group=junos
On all Junos and Junos Evolved platforms, when data traffic is sourced from line cards like MPC1-9 and there is a link error at the destination PFE (Packet Forwarding Engine) end, traffic is dropped at the source PFE end.
PR NumberSynopsisCategory: Stout cards (MPC8, MPC9) fabric issues
1747893MX2k Platform: frequent fabric plane Check state reported due to remote destination timeouts
Product-Group=junos
Upon some crc errors on fabric links, fabric destination timeouts are reported more frequent. Once there is a fabric request timeout, the system will attempt auto recovery. Since the periodic detection logic ran twice for 500msec period and 60msec period, it reported fabric destination timeout too aggressive. The additional 60msec period is targeted to detect a condition if user removed SFB board ungracefully. This exposure is specific to MX2K Platforms only
PR NumberSynopsisCategory: MX10003/MX204 Platform SW - Chassisd s/w defects
1743379The chassisd crash is observed on Junos MX204 platforms due to Fabric request timeout
Product-Group=junos
On Junos MX204 platforms, the chassid crash will be observed when the destination PFE (Packet Forwarding Engine) is not sending the grant within the specified time and Fabric request time out is observed. The traffic will be impacted during the time of crash.
PR NumberSynopsisCategory: MX10003/MX204 Linux issues (including driver issues)
1753908Device crash and control plane traffic gets impacted on Junos platforms
Product-Group=junos
On all Junos platforms, due to a timing issue, when monitor traffic is enabled on loopback interface (for debug purpose), in the presence of local TCP (Transmission Control Protocol) packet flow, it is observed that the device crashes and traffic gets impacted.
PR NumberSynopsisCategory: MX10002 Platform SW - Platform s/w defects
1727985A panic reboot will be observed due to deadlock on VMhost platforms
Product-Group=junosvae
On Junos based VMhost platforms due to disk access issue a panic reboot will be observed with core files. This is a rare issue and traffic will be impacted as the system reboots unexpectedly.
PR NumberSynopsisCategory: SRX-1RU infrastructure SW defects
1784983Chassis alarm not present for if /var partition usage exceeds 100%
Product-Group=junos
When /var partition disk space is greater than 100%, "RE 0 /var partition usage is high" chassis alarm gets cleared
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1775083Traffic drop observed right after boot up on Junos SRX 4600 platforms
Product-Group=junosvae
On SRX 4600 platforms running the Field Programmable Gate Array (FPGA) firmware versions 163, 165, 171, 175 the Packet Forwarding Engine (PFE) may experience a 25% drop in performance after bootup.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1689921Error messages are observed when L2TP packets are received through MPC10E
Product-Group=junos
%PFE-x: fpcx user.err ppman: [Error] PPM:PROCESSOR_L2TP_SF: PpmProcProtoL2tpSf:: processPkt: No tunnel entry found for received L2TP tunnel control packet. LocalAddr: x.x.x.x LocalTunnelId: 0 Timestamp xx:xx:xx device fpcX user.err ppman: [Error] PPM:PROCESSOR_L2TP_SF: PpmProcProtoL2tpSf:: processPkt: Received packet Ipv4 header parsing failed. PacketSize:xx
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1795940The ARP resolution will fail on the interface when the default ARP policer fails to program.
Product-Group=junos
On AFT(Advanced Forwarding Toolkit) based MX platforms, default ARP(Address Resolution Protocol) policer fails because of which ARP resolution fails on the interface and hence the traffic gets impacted.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1759899The system crashes due to the deletion of the basic IP configuration
Product-Group=junos
On Junos MX devices with MPC10, MPC11, LC9600 line cards and MX304 platforms, the deletion of the basic Internet Protocol (IP) configuration was resulting in the system crash. Apart from this, any rollback/configuration delete that results in a receive next-hop (NH) free/delete have the possibility of ending up in a system crash scenario.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1675316DHCP OFFER not received at the client for DHCP packets that have extra padding
Product-Group=junos
On Trio chipset based platforms, when Dynamic Host Configuration Protocol (DHCP) packets have extra padding, DHCP discover packets get discarded resulting in DHCP OFFER not being received at the client.
1740606Host communication does not work in EVPN-L2VPN-CCC setup
Product-Group=junos
On Junos MX platforms, in Ethernet Virtual Private Networks-Layer 2 Virtual Private Networks-Circuit Cross-Connect (EVPN-L2VPN-CCC) setup, the integrated routing and bridging (IRB) interface over access logical tunnel (LT) interface is configured, it is sending vlan tagged packet on the access port and not removing it causing the host communication to break.
1745803During multicast traffic flow , 'sw error' discard count is incrementing continuously
Product-Group=junos
On all MX series platforms, Multicast over IRB with receivers spanning across PFEs then some vty exception counters which keeps incrementing.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1636920[MX10K Chassis]: Exception Reporting Feature is not working
Product-Group=junos
The exception-reporting feature doesn't work on MX10K TVP chassis independent of the MPC Type.
PR NumberSynopsisCategory: Trio LU and LUSS SW driver
1798284Certain MPC line cards goes down and crashes during non-ZPL ISSU upgrade
Product-Group=junos
Under a rare scenario, on all MX platforms having MPC2/3/5/6/7/8/9 line cards such as MPC5E 3D Q 2CGE+4XGE, MPC5E 3D Q 24XGE+6XLGE, MPC6E 3D, MPC NG, MPC2E NG HQoS, MPC2E NG PQ & Flex Q, MPC3E NG HQoS, MPC3E NG PQ & Flex Q, MP7E-10G, MPC7E-MRATE, MX2K-MPC8E, MX2K-MPC9E etc fails non-ZPL (non-Zero packet loss) ISSU (Unified In-service Software Upgrade) upgrade and crashes which causes the FPCs (Flexible PIC Concentrators) to go down followed by memory read errors, LLM wedges and crash. As a result, there is traffic drop.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1689567Translation scripts from new image not being used for validation during upgrade
Product-Group=junos
On all Junos platforms, when performing software add/validation, configuration validation may fail because during validation translation scripts from the old(current) image is used instead of the translation scripts from the new image.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1770643RPD core seen when groups is activated before corresponding 'apply-groups' in configuration
Product-Group=junos
On all Junos and Junos Evolved platforms, when the group is activated after the corresponding 'apply-groups' statement configuration, rpd core is seen.
1794536The device goes into configuration locked state due to stale mgd
Product-Group=junos
The device is went into config locked state due to stale mgd. For netconf sessions with , if ungraceful exit happens, the lock is not released. There is auto cleanup supported for such cases, But it is not triggered under problem conditions as faced in this PR. This leads to device remain in locked state due to stale entry. "request system logout pid " can be used for cleanup and to recover from this state.
PR NumberSynopsisCategory: Web-Management UI
1776688High storage is reported in /var/jail/log due to http.log and http-trace.log on all Junos platforms
Product-Group=junos
Disk usage will be high in /var/jail/log due to http.log and http-trace.log on all Junos platforms. Further install will be blocked until this folder is cleaned up.
PR NumberSynopsisCategory: QFX RCB issues
1763588Warn if insufficient space to save unbundled packages during vm image upgrade
Product-Group=junos
If while preparing for replacement of a vm image, there is insufficient space to save copies of unbundled packages, issue a warning.
PR NumberSynopsisCategory: web filterig issues
1772232[SRX] Flowd core is generated by UTM web-filtering
Product-Group=junos
On SRX platform, flowd core might be generated when when TCP flow session for HTTP traffic is in error state due to some reason and UTM WF trying to apply fallback action.
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1787147The sdp process crashes when trying to add a new satellite device to the network
Product-Group=junos
In the Junos Fusion setup, the sdp (Satellite Discovery and Provisioning Daemon) process crashes repeatedly when trying to add a new satellite device to the network. This issue happens when the MD5 encrypted data is read as a string, in which the string validation code throws errors when the first byte of MD5 encrypted data is 0.
PR NumberSynopsisCategory: MX10K platform
1784080FPC reboot seen on MX platforms with PMB memory correctable errors
Product-Group=junos
On all MX platforms that support MPC7/MPC8/MPC9/MX10k-LC2101/EX9200-40XS/EX9200-12QS, an unexpected FPC (Flexible PIC Concentrator) reboot may be seen along with PMB memory correctable errors. Service impact can be seen till the FPC restart completes.
PR NumberSynopsisCategory: Windsurf interfaces software
1793999The 'no-flow-control' interface configuration not retained post ISSU on MX platforms
Product-Group=junos
Flow-control pause frames will be sent out of the interface even with the knob 'no-flow-control' enabled on Junos MX platforms after the ISSU upgrade. This issue will not be seen with non-ISSU software upgrades.
PR NumberSynopsisCategory: usf ams related issues
1779450The interface cli option "ip-address-owner service-plane" is unhidden for vms interfaces
Product-Group=junos
CLI option "ip-address-owner service-plane" visible in interface hierarchy for vms interfaces. This option defines owner for IP addresses hosted on an ms- interface. This statement is used to specify that the steering of control plane packets to the Multiservices PIC be preserved.
PR NumberSynopsisCategory: usf ipsec related issues
1791196EBGP sessions established over IPSEC tunnels would flap if multihop knob with ttl=1 is configured
Product-Group=junos
On all MX platforms, External Border Gateway Protocol (EBGP) sessions established over Internet Protocol Security (IPSEC) tunnels will flap, if multihop knob with ttl=1 is configured.
PR NumberSynopsisCategory: usf service set related issues
1779424Junos OS: MX Series with SPC3 line card: Port flaps causes rtlogd memory leak leading to Denial of Service (CVE-2024-39550)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the rtslib or ssamlib of the Juniper Networks Junos OS MX Series with SPC3 allows an unauthenticated, adjacent attacker to trigger internal events ( which can be done by repeated port flaps) to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83012 [juniper.net] for more information.
 

Modification History

First publication 2024-07-10