Alert Type
PCN - Product Change Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX EX MX NFX PTX QFX SRX vSRX
Alert Description
Junos Software Service Release version 22.4R3-S3 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 22.4R3-S3 is now available.
22.4R3-S3 - List of Fixed issues
PR Number
Synopsis
Category: EX2300/3400 platform
1799093
[EX2300]"Ethernet Link Down" would not be generated when me0 was down.
Product-Group=junos
On Junos EX2300 device, whenever the Management Interface Link is Down, the alarm was not getting generated as expected.
PR Number
Synopsis
Category: SRX ISSU infra related issues
1803376
The In-Service Software Upgrade (ISSU) fails in chassis cluster deployment on SRX1500
Product-Group=junos
On SRX1500 platforms, In-Service Software Upgrade (ISSU) fails in chassis cluster deployment with error "timeout waiting for secondary node node1 to sync(error-code: 6.1)".
PR Number
Synopsis
Category: "agentd" software daemon
1808259
Openconfig data type value is streaming in gnmi update as float_val instead of bytes_val
Product-Group=junos
On all Junos Evolved platforms configured with Openconfig telemetry, when streaming the GNMI leaves updates for data type value "ieeefloat32"will be seen streaming as type "float_val" instead of "bytes_val". There is no traffic impact due to this, and just a display issue.
PR Number
Synopsis
Category: BBE database related issues
1810817
On Junos SRX platforms upgrade fails for older JUNOS version to 22.4R3-S1 or 22.4R3-S2 version
Product-Group=junos
On Junos SRX5600 and vSRX3 platforms while upgrading from an older JUNOS version to 22.4R3-S1 or 22.4R3-S2, the upgrade process can fail as the RPD crashes as part of validation process. This is seen if the router config has Multicast/Internet Group Management Protocol (IGMP) or Broadband Edge configuration. Bug has been fixed in 22.4R3-S3.
PR Number
Synopsis
Category: Border Gateway Protocol
1778879
Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak (CVE-2024-39549)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA83011
[juniper.net]
for more information.
1787290
Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP update causes the session to reset (CVE-2024-39555)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA83015
[juniper.net]
for more information.
1789863
The rpd crash can be seen when large number of VRF instances are created and bgp peering terminated
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) crash will be observed when BGP (Border Gateway Protocol) is terminated by the user and if large number of VRF instances are created. This happens as some BGP internal data structure is not cleaned up properly. This crash can lead to a temporary traffic drop, but the system will automatically recover.
PR Number
Synopsis
Category: MX304 Chassis specific platform
1798511
RE switchover will cause multiple issues on MX304
Product-Group=junos
On MX304 platforms with dual Routing Engine (RE) and configured with Graceful Routing Engine Switchover (GRES), after RE switchover, Packet Forwarding Engine (PFE) information on the secondary RE is not getting properly updated as that on primary RE. This may result in issues like interface flap, protocol flap etc.
PR Number
Synopsis
Category: Configd, ffp issues
1802837
DHCP relay functionality is broken on Junos OS Evolved platforms when 'prefix-list' with 'apply-path' for DHCP relay is used
Product-Group=junos
On all Junos OS Evolved platforms the DHCP (Dynamic Host Configuration Protocol) relay will not work as expected when two consecutive wildcards are used in prefix-list apply-path in the loopback filter and "set policy-options prefix-list pf-dhcp-servers apply-path "forwarding-options dhcp-relay server-group <*> <*>" is configured.
PR Number
Synopsis
Category: EX interfaces issues
1789617
On EX2300/EX3400 series SFP-SX interface is not come up due to auto-negotiation failure
Product-Group=junos
On EX2300/EX3400 series with SFP-SX interface is not coming up due to auto-negotiation failure.
1805370
Interfaces remain down on EX4400-48F platform after replacing a 100MB SFP with 1GB SFP
Product-Group=junos
On Junos EX4400-48F platform only after replacing a 100 MB SFP endpoint device for a 1 GB SFP the switch port doesn't come up.
PR Number
Synopsis
Category: Express PFE L2 fwding Features
1792128
Configuring multiple IFL of different families on Junos QFX10K SP style interfaces leads to traffic loss
Product-Group=junos
On Junos QFX 10K platforms, traffic drop is seen when multiple interface logical (IFLs) of different families are configured on the same interface physical (IFD) with Service Provide (SP) style configuration and layer 2 (L2) ILF is the first IFL to be created.
1798887
Traffic drops are observed in the EVPN-VXLAN environment having IPv4 and IPv6 address configured in underlay
Product-Group=junos
On Junos QFX10002-36Q/QFX10002-72Q/QFX10002-60C and PTX10002-60C platforms, the decapsulate of the VXLAN (Virtual eXtensible Local-Area Network) packet will fail and result in traffic drops due to the tunnel termination table not being programmed in PFE (Packet Forwarding Engine).
1802615
VRRP Gateway IP Unreachability
Product-Group=junos
Unreachability to VRRP gateway IP causes end host connectivity issues. This issue impacts unicast packets addressed to the VRRP gateway IP on QFX10002-36Q, QFX10002-72Q, QFX10008, and QFX10016 platforms. It is triggered by VRRP configuration and unicast traffic to the gateway IP. It impacts both IPv4 and IPv6 traffic.
PR Number
Synopsis
Category: BSDX Software installation issues
1783119
Delays can be seen while the upgrading process runs due to the status of UFS set to mode enable.
Product-Group=junos
In USF mode enabled router, While upgrading router having scaled services AMS config with "load-balancing-options disable-hash", Router continuously dumps "'disable-hash' knob is only allowed in USF mode" error. This delays the bootup time with scaled config.
PR Number
Synopsis
Category: jdhcpd daemon
1778876
DHCP Server in ALQ redundancy: DHCP ACK on renew does not include option 1 subnet mask after failover
Product-Group=junos
With DHCP Local Server with Active Lease Query, the DHCP ACK on the DHCP Renew after failover to the back-up server does not provide a response for option 1 subnet mask
PR Number
Synopsis
Category: Flow Module
1798041
On Juniper SRX platforms GTP-U packet destination port gets duplicated to the source port and subsequently discarded by policy.
Product-Group=junos
On Juniper SRX devices with GTP-U distribution feature enabled, GTP-U source port will get duplicated as same as the destination port in the traffic from the server back to the source and blocked by the security policy. Due to this, all impacted reverse GTP-U packets will be discarded.
PR Number
Synopsis
Category: SRX Firewall Authentication
1804149
A fwauthd process crash is seen when a user access group name of more than 64 characters is configured
Product-Group=junos
On all SRX platforms, the fwauthd process crash is seen when it processes a user access group name of size more than 64 characters received from authd process. There is no impact to forwarding traffic due to fwauthd crash.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1794895
High CPU on SPU might lead to FPC reboot and VPN traffic impact by not failing over to the backup node
Product-Group=junos
On Junos SRX platforms with a cluster, when a high volume of traffic is observed, high CPU (Central Processing Unit) usage might be seen from the SPUs (Security Processing Units). The FPC (Flexible PIC Concentrator) may reboot, and the IKE SAs (Internet Key Exchange Security Associations) may be cleared and timed out, preventing the VPNs (Virtual Private Networks) from failing over and causing a traffic impact.
PR Number
Synopsis
Category: Multicast for L3VPNs
1747703
The MVPN traffic starts dropping after RE switchover
Product-Group=junos
On all Junos and Junos Evolved platforms with Dual RE and MVPN ((Multicast Virtual Private Network) enabled, when the user initiates a GRES ( Graceful Routing Engine Switchover) switchover, it triggers a route change from the MVPN . During this process, there's a gap where traffic loss is observed because the flood next hop pointed to by the route gets deleted.
PR Number
Synopsis
Category: Track Mt Rainier RE platform software issues
1782062
The interface fxp0 deactivation or activation is not captured due to improper date format
Product-Group=junos
On all VMhost platforms, the interface fxp0 state is not captured since the script to bring up the interface is not parsing the output from the date field.
PR Number
Synopsis
Category: PFE Peer Infra
1801535
CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log
Product-Group=junos
On all Junos platforms, CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log. This log is not an error log but still printed under LOG_ERROR and flooded with default log level. This causes restart which will impact normal user traffic.
PR Number
Synopsis
Category: QFX L2 PFE
1811701
Multiple services and protocols does not work on the backup member with 100G port used as VC interconnect port on QFX5110-48S
Product-Group=junos
On QFX5110-48S platforms in VC (Virtual Chassis), when 100G port is used as VC interconnect, multiple protocols and services do not work on the backup member when the VC port related configurations are deleted and added back on the backup member. The issue is also seen when the PFE process on the backup member is restarted. LACP (Link Aggregation Control Protocol) interfaces from backup switch goes into detached/defaulted mode which causes major connectivity and traffic disruptions.
PR Number
Synopsis
Category: QFX analyzer, sflow
1808041
The dcpfe process crash is seen in case of inline sampling
Product-Group=junos
When configuring inline sampling, if the sFlow collector is reachable through a unilist next-hop with an indirect child, the dcpfe process crashes.
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1806114
Multicast nexthop delete causes nexthop stale entries which fail when the same nexthop is reused in VXLAN VLAN creation
Product-Group=junos
On all Junos QFX5K and EX4K platforms, when L3 multicast nexthop entries are deleted when configured with IRB or switched from non-default to default VRF, stale entries from the multicast NH (NextHop) delete cause reusing of stale nexthop in VXLAN (Virtual Extensible LAN) and subsequent creation of VXLAN VLAN fails.
1813454
On qfx5110 switches in the EVPN-VxLAN environment, multiple vlan-id-list on an interface might not program all the VLANs
Product-Group=junos
On qfx5110 switches in the EVPN-VxLAN environment, multiple vlan-id-list on an interface might not program all the VLANs. This will lead to traffic drops for the vlans which are not programmed.
PR Number
Synopsis
Category: QFX10008/16 QFX10002 linecard, serdes and uboot
1797453
QFX-10002-36q||SFP+-10G-CU3M SFP are not coming up post upgrade from 18.2X75-D12.6 to 20.4R3-S7.2
Product-Group=junos
DAC modules were not recognized as DAC was not supported in older releases when recognition/Support is enabled in the software for all the SFP/QSFPs speeds like 40GE/100GE/10GE, for 10GE-DAC support got missed for QFX10002. Due to this, only this SFPP_10GE-CUxx stopped working in QFX10002. That is why when Optics was unknown (DAC was unsupported) earlier, Optics was working and after the SW upgrade to a REL where SFP -DAC is supported, SFP+ got recognized but did not work due to support missing.
PR Number
Synopsis
Category: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1797511
[JDI-RCT-EVPNVXLAN-L2Stitching]: DCPFE core observed on QFX10k while running profile baseline in 22.2R3-S3.18 image
Product-Group=junos
In very rare instances of a large config commit, on the QFX10002-36Q routers, the dcpfe can core due to watchdog timeout. After the core, the dcpfe respawns and the system functions normally without any manual intervention.
PR Number
Synopsis
Category: RPD policy options
1795263
Performance degrades when learning BGP routes with communities
Product-Group=junos
On all Junos and Junos OS Evolved platforms, degraded performance occurs when BGP routes with communities are learned.
PR Number
Synopsis
Category: Shard routing infrastructure within RPD
1797996
BGP learning or convergence performance degradation.
Product-Group=junos
Addresses delays in processing millions of routes by optimizing memory usage and improving learning/deleting route operations, reducing few-second delays.
PR Number
Synopsis
Category: Resource Reservation Protocol
1800034
Label Switched Path (LSP) traffic drop observed on a transit router with graceful-restart configured after a brief outgoing link flap
Product-Group=junos
If a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in longer than expected traffic blackholing on the router that is at the downstream end of the flapping link.
PR Number
Synopsis
Category: Scuba fabric software
1807812
XMCHIP PFEs could run into XMCHIP_CMERROR_CPQ_INT_REG_QSYS_QUEUE_UNDRN_ERROR during ungraceful SIB or Peer-FPC power off event or due to bad fabric links
Product-Group=junos
During ungraceful Peer-SFB/Peer-FPC offline or due to a bad fabric link XM ASIC based FPCs can hit CPQ Underrun Major error on an unused queue resulting in PFE Disable action. This PR fixes the underlying reason for the CPQ Underrun error and prevents PFE from being disabled.
PR Number
Synopsis
Category: IPSEC functionality on M/MX/T ser
1801201
IKE is not coming up with dhgroup19 and dhgroup20
Product-Group=junos
IKE is not coming up with dhgroup19 and dhgroup20. The below Junos releases are impacted. junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3-S1 junos:24.1R1. So previous to these releases dhgroup19 and dhgroup20 should be working.
PR Number
Synopsis
Category: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1783745
The mspmand process might crash on the MS-MPC during deletion of service-sets configuration
Product-Group=junos
On Junos MX platforms with MS-MPC(Multiservices Modular Port Concentrator) line cards, with Network Address Translation (NAT) and PBA(Port Block Allocation) enabled, multiple times deletion of service-sets configuration, will lead to PFE (Packet Forwarding Engine) may restart due to which mspmand cores and MPC goes offline and during this interval, there is a drop in traffic.
PR Number
Synopsis
Category: Stout card (MPC7) fabric issues
1808923
Traffic loss occurs if persistent link error is seen on a fabric plane to PFE, after restarting or rebooting another FPC in a different slot
Product-Group=junos
On all MX platforms, if there is persistent link error or training failure at fabric link between Switch Fabric Boards/ Switch Control Board (SFB/SCB) and a Packet Forwarding Engine (PFE) at one Flexible PIC concentrator (FPC) in some fabric plane then once another FPC in a different slot comes online, it will be sending traffic to the PFE over that link with error for a short period of time and then the FPC which is just brought online will declare destination errors towards that PFE and the Fabric plane with error will be removed from fabric spraying masks. This can result in temporary traffic loss.
PR Number
Synopsis
Category: ZT/YT pfe qos software issues
1805343
Host loopback wedge observed when oversubscribing queues and flapping subscribers
Product-Group=junos
On Junos MX-Series using MPC10, MPC11, LC9600 line cards, host loopback wedge can be observed in a scenario of 15k-20k subscribers, with subscribers are flapping and class of service queues are over-subscribed. This can lead to a FPC (Flexible PIC Concentrator) restart and can impact traffic.
PR Number
Synopsis
Category: ZT/YTpfe bridging, learning, stp, oam, irb software
1792736
Transit traffic does not get forwarded in EVPN-VxLAN scenario on Junos MX/EX platforms
Product-Group=junos
On Junos MX240/MX480/MX960/MX2008/MX10004/MX10008/MX2010/MX2020 platforms with MPC10E/11E/LC9600 line cards and MX304 platform and EX9204/EX9208/EX92014 with EX9200-15C line card, in Ethernet Virtual Private Network-Virtual Extensible LAN (EVPN-VxLAN) scenario the transit traffic does not get forwarded due to incorrect inner ethernet header.
PR Number
Synopsis
Category: ZT/YT pfe l3 forwarding issues
1803578
MPLSoUDP route issue preventing LSP establishment
Product-Group=junos
On all MX platforms, the discrepancy is seen when attempting to establish LSP (Label Switched Paths) using MPLSoUDP (MPLS over UPD) routes due to the mishandling of IP options during tunnel processing.
PR Number
Synopsis
Category: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1797496
Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
Product-Group=junos
Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
PR Number
Synopsis
Category: Issues related to NETCONF
1792362
RPC request for file copy with routing instances is failing
Product-Group=junos
On Junos OS and Junos OS Evolved platforms configured with routing instances, RPC (Remote Procedure Call) request for file copy using routing instance fails. There is no service/traffic impact due to this issue.
PR Number
Synopsis
Category: web filterig issues
1806786
UTM Web filtering does not work for HTTPS traffic sent from Google Chrome browser or MS Edge v124
Product-Group=junos
On SRX platforms, Unified Threat Management (UTM) web filtering does not work for Hypertext transfer protocol secure (HTTPS) traffic sent from Google Chrome browser or MS Edge v124.
PR Number
Synopsis
Category: VCCP related PRs for virtual-chassis in MX
1801522
AE child links in back member is in detached state
Product-Group=junos
On Junos MX platforms with MPC10E-10C card platforms, the issue is observed during a VC(Virtual Chassis) sequential upgrade , where AE child links in backup member is in detached state after auto reboot. Hence redundancy is lost
PR Number
Synopsis
Category: usf flow and datapath issue on SPC3
1799512
Traffic impact on SPC3-PIC due to high throughput and bursty traffic
Product-Group=junosvae
On Junos MX platforms equipped with SPC3 (Services Processing Card 3), when running on Talus 0x215 version and each SPC3-PIC (Physical Interface Card) handling significantly high throughput along with bursty traffic, will lead to tx_NoDp_drop' to be hit leading to packet drop.
PR Number
Synopsis
Category: usf ipsec related issues
1808207
The IPsec tunnel traffic is dropped after ipsec tunnel soft reset on MX platforms
Product-Group=junos
On Junos MX platforms with SPC3 card and IPsec configuration, traffic loss is seen in existing service sessions following a tunnel flap when the "clear security ipsec security-associations" command is executed. After clearing the security associations (SA), the expected transition of data traffic to the new tunnel does not occur. Instead, the tunnel continues to drop traffic of the existing session. A new traffic session initiated after the new tunnel establishment works fine with no issue.
22.4R3-S3 - List of Known issues
PR Number
Synopsis
Category: BBE database related issues
1818781
sdbsts_lock_holder caused multile BBE daemon being killed automatically
Product-Group=junos
In a scaled subscriber management routers, customer might obsrve daemons being killed automatically due to sdbsts_lock_holder deadlock.
Resolved In:
junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: the replication daemon (repd) for Shared Memory-base
1797189
We may observe repd core (in the "from" release) during ISSU. There are no functional impact due to this repd core
Product-Group=junos
On all Junos and Junos Evolved platforms, repd core observed (in the "from" release) during ISSU.
Resolved In:
evo:24.2R2-EVO junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: Border Gateway Protocol
1760885
The BGP LU labels can have next-hops pointing to each other in multi-homed PE setup
Product-Group=junos
On all Junos and Junos Evolved platforms the routes received by two multi-homed PE (Provider Edge) routers in the 'inet-unicast' family are advertised in the BGP (Border Gateway Protocol) LU (Labeled Unicast) family to each other. This issue happens when there is no rib.inet3 configured under the address family labeled unicast which causes the routes from 'inet-unicast' and 'inet-labeled-unicast ' tables to get mixed. There will be a traffic impact when this issue is encountered.
Resolved In:
evo:22.1R3-S5-EVO evo:22.2R3-S3-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:21.2R3-S7 junos:22.1R3-S5 junos:22.2R3-J6 junos:22.2R3-S3 junos:22.4R3-J1 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR Number
Synopsis
Category: Issues related to Common BIOS on x86 based designs
1608045
LTS19: MX960: 000: [Firmware Bug]: TSC_DEADLINE disabled due to Errata; please update microcode to version: 0x3a (or later) seen upon upgrade to 21.4
Product-Group=junos
Please upgrade BIOS for releases containing LTS19 i.e. Junos 21.4R1 and later. This fix is not relevant to the secure BIOS RE-S-2X00x6. PR :1820715 would address .
Resolved In:
junos:22.2R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: EX4100 RE, Platform Infra, Drivers
1802614
Emerald:Rampur:set chassis config-button no-clear support not added on ex4100
Product-Group=junos
Please check if it has to be release noted for previous releases on Emerald
Resolved In:
junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: EX interfaces issues
1492605
runt, fragment and jabber counters are not incrementing on EX4300-MPs
Product-Group=junos
runt, fragment and jabber counters are not incrementing on EX4300-MPs
Resolved In:
1789617
On EX2300/EX3400 series SFP-SX interface is not come up due to auto-negotiation failure
Product-Group=junosvae
On EX2300/EX3400 series with SFP-SX interface is not coming up due to auto-negotiation failure.
Resolved In:
junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
1801072
LACP flap seen in the lagavulin device with PDT PROFILE CONFIGS
Product-Group=junos
Dev to update
Resolved In:
PR Number
Synopsis
Category: PFE EVPN / VxLAN related issues on EX platforms
1801237
ARP won't be forwarded in VLAN associated VNI in VxLAN Fabric
Product-Group=junos
On EX4100/EX4400/QFX5120 platforms where dot1x is configured with multiple supplicant mode, if the MAC (Media Access Control )+IP (Internet Protocol ) is not in the EVPN (Ethernet Virtual Private Network) database, there will be an ARP (Address Resolution Protocol ) and it will not work as the ARP is suppressed. It will be generated to specific VLAN in VxLAN and it is suppressed due to arp suppression.This issue is seen due to dot1x configured on the interfaces. This can be restored by restarting the FPC.
Resolved In:
junos:23.4R2 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: jdhcpd daemon
1790508
EX4400VC : DHCP discover packets will be sent from me0 interface when FPC comes online
Product-Group=junos
On EX4400 device, you may observe DHCP discover packets from me0 even though DHCP is not enabled on that interface. The issue could be seen when EX4400 comes up.
Resolved In:
PR Number
Synopsis
Category: Flow Module
1761542
In a chassis cluster setup the flowd crashes and SPC cards will fail
Product-Group=junos
On SRX platforms, in a chassis cluster setup configured in Active/Active mode, the fabric forward packet enters the flow module causing the flow processing daemon (flowd) to crash, impacting the traffic forwarding and failing the Services Processing Card (SPC).
Resolved In:
junos:21.4R3-S8 junos:23.4R2 junos:24.2R2 junos:24.3R1
1791633
Packets over GRE or IPIP or GRE(PMI) will not reach destination
Product-Group=junos
On Junos platforms with GRE or GRE(PMI) or IPIP tunnels, when tunnel TTL(Time To Live) is set to 1 in the CLI, the traffic sent over GRE or IPIP or GREoIPSec tunnel does not reach its destination.
Resolved In:
junos:21.2R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: IPSEC/IKE VPN
1758785
Encap/Decap may not work correctly when PMI is enabled and while using life-sizes
Product-Group=junos
On all SRX/vSRX platforms, if PMI (Power Mode IPSec) is enabled while using IPSec tunnels and if life-sizes are configured as part of the proposal, encapsulation / decapsulation may not work correctly.
Resolved In:
junos:23.4R2 junos:24.1R1 junos:24.2R1
PR Number
Synopsis
Category: Security platform jweb support
1810991
Display issue is observed when range option is used to configure destination/source port range in custom application
Product-Group=junos
On Junos SRX platform, J-web shows error message "The maximum length for this field is 9", when range option is used to configure destination/source port range in custom application and if the value is more than 10 characters.
Resolved In:
junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: Issues related to Junos licensing infrastructure
1792672
License is lost on NG-RE platforms after device/routing-engine reboot
Product-Group=junos
On NG-RE (Next Generation Routing Engine) platforms, license is lost after restarting device/routing-engine. If any service depends on that license, that service will be impacted.
Resolved In:
evo:22.2R3-S4-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:22.2R3-S4 junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: lldp sw on MX platform
1811545
The LLDP neighborship does not recover on ae interfaces
Product-Group=junos
When LLDP is configured on interface all and there are ae interfaces configured, to disable LLDP on one of the ae "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, ae is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.
Resolved In:
evo:23.4R2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S7-J17 junos:21.2R3-S8-J2 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1592495
Recovery snapshot creation fails due to a lack of storage on the OAM partition
Product-Group=junos
On EX2300/EX3400/EX2300-48MP platforms, the recovery snapshot creation fails due to a lack of storage on the Operations, Administration, and Management (OAM) partition.
Resolved In:
junos:23.4R2 junos:24.1R1 junos:24.2R1
PR Number
Synopsis
Category: Kernel Tunnel Interface Infrastructure
1760684
DNS proxy feature not working on logical tunnel interfaces
Product-Group=junos
DNS proxy feature does not process DNS queries that are received on logical tunnel interface
Resolved In:
junos:23.4R2 junos:24.1R1 junos:24.2R1
PR Number
Synopsis
Category: Protocol Independant Multicast
1795964
The rpd process crash is seen when routing-instances name length is greater than 60 characters
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Protocol Independent Multicast (PIM) enabled under Routing-instance, the Routing Protocol Daemon (rpd) process crash is seen when the routing instance (RI) name length is greater than 60 characters. Due to the rpd process crash, protocols will be impacted and traffic loss will be seen.
Resolved In:
evo:22.3R3-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1719758
4x25G channelized interfaces are not coming up after optics hot swap
Product-Group=junos
4x25G channelized interfaces are not coming up after optics hot swap
Resolved In:
PR Number
Synopsis
Category: QFX5200/5110/5120/5210 ISSU Infrastructure
1703229
JDI_REG:: QFX5200:: After ISSU upgrade, device is hanged and not able to perform any operations until USB recovery done on device
Product-Group=junos
When TISSU upgrade is done from 22.4 release onwards, the box come up as backup RE.
Resolved In:
PR Number
Synopsis
Category: Category for QFX5K EVO Platform Software PRs related to Chas
1708773
Intermittently Traffic gets blackholed on line side Tx/Rx on certain platforms
Product-Group=junos
On a rare scenario, platforms having Marvell PHY (Alaska 88x7121P ) such as ACX7348, QFX5700, ACX7100-32C, ACX7100-48L etc, intermittently traffic gets blackholed on line side Tx/Rx, when device is is fully loaded/populated with optics/DAC cables and is rebooted.
Resolved In:
evo:23.4R2-EVO evo:24.3R1-EVO junos:23.4R2
PR Number
Synopsis
Category: RPD Next-hop issues including indirect, CNH, and MCNH
1793196
Multicast traffic black-holing upon MoFRR primary link went down
Product-Group=junos
On all Junos and Junos Evolved platforms, when MoFRR (Multicast-only fast reroute) is configured with NSR (Non-stop routing) while interface flapping or RE switchover, there is a next-hop leak and the next-hop in RIB (Routing Information Base) is different from the next-hop in FIB (Forwarding information base) due to that multicast traffic will be impacted.
Resolved In:
evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S3-J31 junos:21.2R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: Shard routing infrastructure within RPD
1727528
The rpd process can crash during a race condition when BGP rib-sharding is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when BGP RIB sharding is configured, the rpd process crashes during a rare race condition where multiple threads try to initialise a single global variable. During the rpd crash and restart, all routing protocols will be impacted and traffic disruption will be seen due to the loss of routing information.
Resolved In:
evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.2R3-S2-J2 junos:22.2R3-S3 junos:23.2R2 junos:23.3R1
PR Number
Synopsis
Category: SRX branch platforms
1750521
Packet drop will be observed if different Native-VLANs are configured on the SRX platform
Product-Group=junos
On SRX380 or SRX550 platforms when different Native-VLANs are configured on the trunk interfaces between devices, there is a packet drop. This happens because the SRX is tagging all the packets for Native VLAN.
Resolved In:
junos:24.3R1
PR Number
Synopsis
Category: ZT/YT pfe infra issues
1796344
PacketIO PFE process will drop small fragments of TCP and UDP packets destined to the routing engine
Product-Group=junos
On platforms running PacketIO PFE process (MPC10E, MPC11E, MX10K-LC9600, MX304 and all Junos OS Evolved platforms), small fragments of TCP and UDP packets destined to the routing engine will be dropped.
Resolved In:
evo:24.2R2-EVO evo:24.3R1-EVO junos:21.4R3-S5-J4 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: ZT/YT pfe firewall software
1802341
Filter will be configured with incorrect vlan-IDs and commit error will not be displayed
Product-Group=junos
On mx10008 platform, filter will be configured with incorrect vlan-IDs and commit error will not be displayed if vlan-ID is not configured in the range of 0-4095 which is syntactically incorrect.
Resolved In:
evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
PR Number
Synopsis
Category: usf nat related issues
1802242
Interim logs for deterministic NAT are not generated as per the modified time interval
Product-Group=junos
On all MX platforms, the configuration change done to interim logging interval for deterministic Network Address Translation (NAT) does not come into effect. Even after modifying the interval value from T1 to T2, logs still get generated at the interval T1.
Resolved In:
junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
Modification History
First Publication 2024-07-18
22.4R3-S3: Software Release Notification for JUNOS Software