Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 23.2R2-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution


Junos Software service Release version 23.2R2-S2 is now available.

23.2R2-S2 - List of Fixed issues 

PR NumberSynopsisCategory: MPC Fusion SW
1796770Traffic impact during ISSU across FPCs on Junos MX platforms
Product-Group=junos
Severity=Major
On Junos MX platforms traffic loss can be seen across FPC (Flexible PIC Concentrator) during ISSU if an FPC fails and recovers during iSSU (In-Service Software Upgrade). This issue is seen when ISSU is done from a release older than Junos 21.2 to release 21.2 or higher. The issue is due to number of Max PFE (Packet Forwarding Engine) mismatch between releases earlier than Junos 21.2 and releases 21.2 or higher.
PR NumberSynopsisCategory: BBE database related issues
1818781Multiple BBE daemons getting killed automatically on MX platforms
Product-Group=junos
Severity=Major
In a scaled subscriber management router, customers observe authd and Jdhcpd daemons being killed automatically due to block tasks.
PR NumberSynopsisCategory: BBE interface related issues
1821021bbe-smgd memory leak in case of ACI VLAN parsing failure
Product-Group=junos
Severity=Major
In a certain circumstances, if the parsing of packets for ACI VLAN fails, the packet is not freed. This led to bbe-smgd daemon memory leak.
PR NumberSynopsisCategory: Border Gateway Protocol
1789863The rpd crash can be seen when large number of VRF instances are created and bgp peering terminated
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) crash will be observed when BGP (Border Gateway Protocol) is terminated by the user and if large number of VRF instances are created. This happens as some BGP internal data structure is not cleaned up properly. This crash can lead to a temporary traffic drop, but the system will automatically recover.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1796530High CPU utilization due to BMP to be running with the longest and highest run count
Product-Group=junos
Severity=Major
In a rare situation, BMP might falls into a loop processing rib-in RM update messages but none of message being sent out. It can hog CPU for long time until the BMP station state is bounced. Since BMP task has low priority, it will yield CPU if there are other tasks jump in. So BMP will only hog CPU when system is idle and won't block other important tasks.
PR NumberSynopsisCategory: PTX10003 Platform related issues
1748000Prolix-LTS22: log-out-on-disconnect not supported on PTX10003 platforms and console might become unresponsive.
Product-Group=junos
Severity=Major
"log-out-on-disconnect" is not supported on the PTX10003 platforms. Configuring this will make the console unresponsive. The change in this PR is to not allow to configure this on the PTX10003 platforms.
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1784438MX304 not reachable with the power-off failure on the PIC
Product-Group=junos
Severity=Major
When an MX304 LMIC is offline due to a power issue, it may take up to 20 minutes for the LMIC to come back online. You can configure event-options to reduce the time to restart the LMIC. See also: TSB83899 [juniper.net]
1815125JDI-RCT:M/Mx: after unsupported card is offlined during ISSU validation in MX router, fabric planes are stuck in check state
Product-Group=junos
Severity=Major
Issue of this PR is caused by PR1796770 which basically does not offline the fabric during FPC offline in ISSU state. Due to which if there are any ISSU unsupported FPC's in the system during ISSU, fabric planes will be stuck in "check" state.
PR NumberSynopsisCategory: MX Platform SW - ukern core dumps
1806787Partial traffic blackhole will be observed during the time of FPC crash due to interfaces not going down
Product-Group=junos
Severity=Major
On all MX2K platforms with MIC-MACSEC-MRATE MIC (Modular Interfaces Card), during an FPC (Flexible PIC Concentrator) crash, some traffic will be lost as the interfaces might take some time to go down.
PR NumberSynopsisCategory: QFX Access Control related
1814502The dot1x authentication fails for VoIP traffic
Product-Group=junos
Severity=Major
On all Junos platforms that support dot1x MDA (Multi-domain Authentication), when both static and dynamic options are enabled for VoIP VLAN (Voice Over Internet Protocol Virtual local Area Network), the dot1x authentication fails. This failure triggers an MDA limit exceed condition, which prevents any additional data clients from authenticating on the same port, even though the MDA limit has not actually been reached.
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1815823EVPN-VXLAN Egress Link Protection Incompatibility with STP Affecting FRR Performance
Product-Group=junos
Severity=Minor
On all Junos QFX5k platforms, EVPN-VXLAN Egress Link Protection (ELP) is impacted when Spanning Tree Protocol (STP) is enabled, causing MAC address flushes and delays in Fast Reroute (FRR) activation. Traffic recovery occurs within a few seconds, but customers using FRR for rapid failover may experience slight interruptions.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1809956On Junos Evolved and Junos MX platforms with MPC10E/11E/LC9600 line cards traffic drop is seen due to changes in delay measurement profile
Product-Group=junos
Severity=Major
On Junos Evolved and Junos MX240/MX480/MX960/MX2008/MX10008/MX10016/MX2010/MX2020 platforms with MPC10E/11E/LC9600 line cards and MX304 platform, with enhanced-cfm mode enabled and IFL configured with dual tag, when measurement-interval and cycle-time is configured, packets do not get transmitted if there are further changes in the measurement-interval and cycle-time values.
1820187FPC keeps crashing when the OAM connectivity-fault-management sla-iterator-profile data-tlv-size is set to more than 100
Product-Group=junos
Severity=Major
FPC (Flexible PIC Concentrator) will keep crashing on MX platforms with MPC10/MPC11/LC9600/MX304-LMIC line cards and Junos OS Evolved PTX platforms once the OAM (Operation, Administration, and Management) connectivity-fault-management sla-iterator-profile data-tlv-size is set to be larger than 100. Services running on that FPC will be impacted.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1807084The VXLAN traffic drop could be seen after modifying control-word in an EVPN instance
Product-Group=junos
Severity=Major
On MX, QFX and PTX10K line of routers running Junos and Junos OS Evolved with static Virtual Extensible LAN (VXLAN), the Virtual Tunnel Endpoint (VTEP) connections may not work properly after enabling or disabling control-word in the EVPN instance. This could disrupt the connectivity provided by the static VXLAN setup and affect data traffic.
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1808040VRRP multicast packets coming from external hosts connected to the EVPN-VXLAN fabric might get duplicated on QFX10k platforms
Product-Group=junos
Severity=Major
On QFX10k platforms having Seamless EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) DCI (Data Center Interconnect) Stitching configured with L2 (Layer 2) Bridged Overlay design, VRRP (Virtual Router Redundancy Protocol) multicast traffic may be flooded to all RNVEs (Regular Network Virtualization Equipment) and Wan-VTEPs (Wide Area Network - Virtual Tunnel Endpoints), irrespective of DF (Designated Forwarder)/NDF (Non-Designated Forwarder) role. This may result in duplicates of VRRP multicast packets.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1798887Traffic drops are observed in the EVPN-VXLAN environment having IPv4 and IPv6 address configured in underlay
Product-Group=junos
Severity=Major
On Junos QFX10002-36Q/QFX10002-72Q/QFX10002-60C and PTX10002-60C platforms, the decapsulate of the VXLAN (Virtual eXtensible Local-Area Network) packet will fail and result in traffic drops due to the tunnel termination table not being programmed in PFE (Packet Forwarding Engine).
PR NumberSynopsisCategory: SRX1500 platform software
1813536Reachability issue observed when trying to ping oversize packet via IRB
Product-Group=junos
Severity=Major
Reachability issue observed when trying to ping oversize packet via IRB
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1808353Traffic drop is seen when "monitor traffic interface" command is issued for an interface on Junos SRX platforms
Product-Group=junosvae
Severity=Major
On Junos SRX4100/SRX4200 platform, starting and stopping the "monitor traffic interface", causes the VPN tunnel or tagged traffic to be dropped. However, keeping the "monitor traffic interface" running, ensures that traffic will function properly. Issue occurs when monitor interface command on an interface is performed on devices that has vlan-tagging configured.
PR NumberSynopsisCategory: idp flow creation, deletion, notification, session mgr intfce
1826377Memory leak will be observed on all SRX platforms when IDP is configured
Product-Group=junos
Severity=Critical
On SRX platforms with IDP (Intrusion Detection and Prevention) enabled, while processing IDP traffic a memory leak can occur which would lead to regular flow processing being affected as memory depletes eventually. This issue affects the following Junos releases: 21.2R3-S8, 21.4R3-S7/8, 22.2R3-S3/4, 22.3R3-S3, 22.4R3-S2/3, 23.2R2, 23.2R2-S1 and 24.2R1. All other releases are not affected by this issue.
PR NumberSynopsisCategory: jdhcpd daemon
1801142The client session is logging out as DHCP renewal is not successful
Product-Group=junos
Severity=Major
On Junos MX platforms, when Wholesale and Retail use case with asymmetric-lease-time option configured under routing-instances and the client session is logging out. There will be a service impact because client session will be re-established. Renew will not succeed after DORA (Discover, Offer, Request, Acknowledgement).
1817227DHCP asymmetric-lease-time is slow processing large scale requests to terminate 64K subscribers.
Product-Group=junos
Severity=Major
DHCP asymmetric-lease-time is slow processing large scale requests to terminate 64K subscribers. This condition applies to both DHCP local server and DHCP relay when asymmetric-lease-time is configured. Regardless of the timer value configured the JDHCPD process will only handle 20 request per second which results in longer than expected time to terminate all DHCP subscribers. In DHCP dual stacked environments the client termination is split between protocol type, 10 clients for DHCPv4 and 10 clients for DHCPv6 are terminated per second. In the example of having 64K dual stacked subscribers with minimum asymmetric-lease-time of 600, after network disruption, there is a 600 second interval for detection JDHCPD takes an approximate addition 53 minutes to terminate all 64K subscribers. The engineering fix for this PR will process 100 client request per second rather than the original 20 requests per second.
1818919jdhcpd core dumps may be seen on ALQ setups when subscriber synchronization is done
Product-Group=junos
Severity=Major
DHCP ALQ (Active Leasequery) Sessions go down due to core dumps in jdhcpd (Juniper DHCP Daemon). These jdhcpd core dumps may be seen on ALQ setups when subscriber synchronization happens after the TCP (Transmission Control Protocol) connection comes up.
PR NumberSynopsisCategory: Flow Module
1785993The flowd process crash is observed in cluster HA mode when there is a route change
Product-Group=junos
Severity=Major
On all SRX and vSRX platforms with cluster high availability configured and route change egress interface then flowd process crashed observed.
1821325Deleting l3vpn (Layer 3 Virtual Private Network) vrf-group (Virtual Routing and Forwarding) configuration causes unrelated bgp neighbor session termination
Product-Group=junos
Severity=Major
When deleting the security l3vpn vrf-group configuration, unrelated bgp (Border Gateway Protocol) neighbor sessions are unexpectedly terminated due to session scans being performed on unrelated sessions. This issue impacts all SRX platforms supporting l3vpn configuration, including SRX4200, SRX4600, and SRX5600. To prevent this issue, avoid using the vrf-group configuration. Symptoms include unexpected termination of bgp sessions unrelated to the deleted vrf-group, leading to high traffic impact.
PR NumberSynopsisCategory: SRX Firewall Authentication
1804149A fwauthd process crash is seen when a user access group name of more than 64 characters is configured
Product-Group=junos
Severity=Major
On all SRX platforms, the fwauthd process crash is seen when it processes a user access group name of size more than 64 characters received from authd process. There is no impact to forwarding traffic due to fwauthd crash.
PR NumberSynopsisCategory: Platform infra to support jvision
1817967Product annotation is missing for sensors on the MX, PTX, and EX92XX platforms
Product-Group=junos
Severity=Major
Product annotation files with correct product support/exclude information for specific sensors with respect to platform MX, PTX and EX92XX products. Request customer to enable CLI "set services analytics product-path-check no-path-check" configure to override product annotation issue.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1812482Persistent MAC getting stuck in the SRP state results in traffic loss in the EVPN-VxLAN scenario
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, traffic loss is observed when the Persistent MAC gets stuck in the SRP (Static, Remote, Pinned) state and not removed during the "clear persistence mac' operation for some MACs that are getting added with an incorrect flag: SRP. The issue happens when MAC learning happens on Multihoming peers where 'persistent-learning' is enabled in an EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) environment. MAC is just marked as Persistent but not installed in the Persistent database.
1816049MAC addresses learnt on interfaces part of VLAN with MAC limiting by interface and "drop-and-log" action configured are cleared after VLAN description is changed
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when "set vlans switch-options interface-mac-limit packet-action drop-and-log" is configured, changing the Virtual Local Area Network (VLAN) description will cause flush of Media Access Control (MAC) addresses learnt on the interfaces part of the VLAN and traffic impact
PR NumberSynopsisCategory: Label Distribution Protocol
1772904The rpd process crashes when LDP telemetry streaming xpath is enabled
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms, the rpd process crash when LDP telemetry for xpath "/network-instances/network-instance/mpls/signaling-protocols/ldp/neighbors/neighbor/hello-adjacencies/hello-adjacency/hello-holdtime/state/hello-expiration" is enabled.
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1798780The system goes into a bad state when an SFB ungraceful offline happens due to a fatal Interrupt
Product-Group=junos
Severity=Critical
On MX platforms with SFB, in case of a fatal error encountered during SFB reboot ( due to hardware issue or ungrateful power restart ), SPMB will try to offline this SFB during bootup. At the same time, the system is busy training the fabric links to begin it online. This may cause a system-wide traffic impact due to the fabric not being consistent.
PR NumberSynopsisCategory: For multicast snooping on MX
1710565In a scaled setup mcsnoopd is taking high CPU causing traffic drop
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, whenever a commit is done, that involves mcsnoopd daemon config parsing such as (VLAN creation/deletion, interface add/delete to VLAN, interface enable/disable, IGMP (Internet Group Management Protocol) snooping/MLD (Multicast Listener Discovery) snooping related config commands) mcsnoopd will consume CPU. In less scaled setup (few IGMP snooping enabled VLANs and few hundred IGMP snooping memberships), the CPU time taken is less. In a more scaled setup (many IGMP snooping-enabled VLANs and a few thousand IGMP snooping memberships), the CPU may reach >90%. Since mcsnoopd is taking high CPU, it may affect other daemons like rpd. It may affect all the protocols if the CPU is not available to the protocols/daemons. This can impact route entries expiring and cause traffic drop.
PR NumberSynopsisCategory: OSPF routing protocol
1793148LDP label advertisement is stopped for approximately 25 seconds when micro loop avoidance is enabled in SR over OSPF
Product-Group=junos
Severity=Major
On all Junos platforms that support MLA (Microloop Avoidance), the LDP (Label Distribution Protocol) label advertisement gets stopped for approximately 25 seconds when MLA is enabled in SR (Segment Routing) over OSPF (Open Shortest Path First) and the interface between LDP (Label Distribution Protocol) domain and SR domain is down and coming up.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1813841Local repair does not happen if BFD is configured on MX platforms with MPC7E line card
Product-Group=junos
Severity=Major
On MX Series platforms with MPC7E line card, the BFD (Bidirectional Forwarding Detection) local repair does not work. As a result of this, traffic does not move to the backup path causing traffic blackhole. This issue could be seen after any action that triggers a BFD failover, for example: PFE (Packet Forwarding Engine) shutdown.
PR NumberSynopsisCategory: QFX L2 PFE
1811701Multiple services and protocols does not work on the backup member with 100G port used as VC interconnect port on QFX5110-48S
Product-Group=junos
Severity=Major
On QFX5110-48S platforms in VC (Virtual Chassis), when 100G port is used as VC interconnect, multiple protocols and services do not work on the backup member when the VC port related configurations are deleted and added back on the backup member. The issue is also seen when the PFE process on the backup member is restarted. LACP (Link Aggregation Control Protocol) interfaces from backup switch goes into detached/defaulted mode which causes major connectivity and traffic disruptions.
1824023Restricted Proxy ARP feature does not work as expected
Product-Group=junos
Severity=Major
On all Junos QFX5K and EX4K platforms supporting restricted 'proxy-arp' feature, when restricted 'proxy-arp' is enabled on IRB (Integrated Routing and Bridging) interface, hosts within the same subnet will not be able to reach each other.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1813250IPv6 transit traffic is getting impacted in a rare scenario with Longest Prefix Match (LPM) profile configuration
Product-Group=junos
Severity=Critical
On Junos devices SRX, EX, QFX, ACX series that use Broadcom chipset, an IPv6 route within range :: /1 to :: /120 remains configured in the PFE even after the route has been withdrawn
PR NumberSynopsisCategory: QFX analyzer, sflow
1808041The dcpfe process crash is seen in case of inline sampling
Product-Group=junos
Severity=Major
On Junos QFX5K and EX4K platforms that support inline sampling, if the sFlow collector is reachable through a unilist next-hop with an indirect child when configuring inline sampling, the dcpfe process crashes.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1798684On Junos QFX5K, EX4100, EX4300, EX4400 and EX4650, Type 5 tunnel traffic loss observed when all IRB interfaces are deleted
Product-Group=junos
Severity=Minor
On all Junos QFX5K, EX4100, EX4300, EX4400 and EX4650 platforms with EVPN-VxLAN (Ethernet Virtual Private Network-Virtual Extensible LAN), deleting the all IRB (Integrated Routing and Bridging) interfaces while still having Type 5 tunnels installed results in Type 5 tunnel traffic loss when Type 5 tunnel MAC (Media Access Control ) is same as global/chassis IRB MAC.
1808816The L3 Multicast traffic will be dropped in an OISM scenario when an egress interface is configured with native-vlan /Access mode
Product-Group=junos
Severity=Critical
On Junos QFX5120, EX4400, EX4100, and EX4650 platforms, L3 Multicast traffic will be dropped in an Optimized Intersubnet Multicast (OISM) scenario when an egress interface is configured with native-vlan /Access mode and the join is coming for the same VLAN as Native/Access VLAN.
1821549Traffic loss is seen in an EVPN-VXLAN scenario when an L2 underlay interface is configured using a service provider style
Product-Group=junos
Severity=Major
On Junos QFX5120, EX4650, EX4100, and EX400, in an EVPN-VXLAN scenario when an underlay L2 interface is configured using the service provider style, the Leaf sends the Ethernet VPN (EVPN) packet with the wrong VLAN-ID to Spine. The spine drops the packet received with the wrong VLAN ID leading to the traffic loss.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1797996BGP learning or convergence performance degradation.
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms configured with BGP (Border Gateway Protocol), when there are scaled routes (greater than 1M routes) the BGP learning or convergence performance degradation is observed.
PR NumberSynopsisCategory: Resource Reservation Protocol
1800034Traffic drop observed after graceful restart event
Product-Group=junos
Severity=Major
If a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in longer than expected traffic blackholing on the router that is at the downstream end of the flapping link.
1820893Detour path is not coming up when detour hop-limit is set to 255 or high value
Product-Group=junos
Severity=Major
detour might not form when hop-limit is set to be high value
PR NumberSynopsisCategory: Issues related to control plane security
1780283Junos OS and Junos OS Evolved: Loading a malicious certificate from the CLI may result in a stack-based overflow (CVE-2024-39556)
Product-Group=junos
Severity=Critical
A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos OS Evolved may allow a local, low-privileged attacker with access to the CLI the ability to load a malicious certificate file, leading to a limited Denial of Service (DoS) or privileged code execution. Please refer to https://supportportal.juniper.net/JSA83016 [juniper.net] for more information.
PR NumberSynopsisCategory: Track usability related J-Web PR, like UI layout, workflow
1823264Unable to Define NAT Policy Address Names Containing Dots or Slashes in J-Web
Product-Group=junos
Severity=Major
On all SRX series platforms enabled with J-Web, NAT (Network Address Translation) policies cannot be edited/added using J-Web if the destination address name contains '.' dot or '/' slash.
PR NumberSynopsisCategory: SRX branch platforms
1811858Monitored-Status keeps Up after CTL link down in branch model SRX HA
Product-Group=junos
Severity=Major
After CTL link down, Monitored-Status in "show chassis cluster interfaces" keeps showing "Up" state.
PR NumberSynopsisCategory: MPC7/8/9 chassis issues
1814801Faulty MPC8 or MPC9 line cards can lead to spontaneous chassisd crash on certain Junos MX platforms
Product-Group=junos
Severity=Major
On Junos MX2008, MX2010, MX2020 platforms, if a faulty MPC8 or MPC9 line card is present in the chassis, chassisd process may crash and triggers routing-engine switchover.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1819376SRX4600 1G interface down after upgrading to Junos 23.2R2.
Product-Group=junos
Severity=Major
On SRX4600 platform, 1G interfaces are down after upgrading to Junos 23.2R2.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1802202CoS rewrite functionality not working when having BBE subscriber on Static Vlan interface
Product-Group=junos
Severity=Major
On MX platforms with MPC10, MPC11, LC9600, and MX304, CoS (Class of Service) rewrite functionality will not work when having a BBE (Broadband Edge) subscriber on Static Vlan interface, causing rewrite rules to not be applied to traffic outgoing interface.
1814341The aftd process crash is seen on certain MX platforms with subscriber management enabled
Product-Group=junos
Severity=Major
On MX platforms with MPC10/11/LC9600 and MX304 platforms with subscriber management enabled, the aftd process crash is seen. The line card reboots due to crash and subscribers will be logged off.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1795940The ARP resolution will fail on the interface when the default ARP policer fails to program.
Product-Group=junos
Severity=Major
On AFT(Advanced Forwarding Toolkit) based MX platforms, default ARP(Address Resolution Protocol) policer fails because of which ARP resolution fails on the interface and hence the traffic gets impacted.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1783821L2VPN: On AFT-based cards, Using Core facing IRB, l2vpn datapath broken.
Product-Group=junos
Severity=Minor
L2VPN: Using Core facing IRB, l2vpn datapath broken. As part of this code changes PushLabels Feature is added to IRB NH egress feature list. All the AFT-based cards, are impacted by this.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1788669Traffic drop due to mac-validate failure on MX platforms
Product-Group=junos
Severity=Major
On Junos MX platforms, when subscriber management is enabled and mac-validate is configured on interfaces, traffic drop is seen while attempting to add a new link to an existing AE (Aggregate Ethernet) bundle from a different FPC.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1814521Traffic drop is observed after any add/change/delete event on IRB interfaces inside a VPLS deployment
Product-Group=junos
Severity=Major
On MX platforms using MPC3/5/7/9 line cards, traffic drops is seen after any add/change/delete of next hop on an IRB interface that is used to communicate between different VLANs (Virtual Local Area Network) in a VPLS (Virtual Private LAN Service) deployment while using LACP (Link Aggregation Control Protocol).
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1804263Traffic loss is observed along with error messages on Junos MX platforms with MPC1 to MPC9, LC2101, LC480 (including MX204, MX10003) during any transport LSP change operation
Product-Group=junos
Severity=Major
On Junos MX platforms with MPC1 to MPC9, LC2101, LC480 (including MX204, MX10003) having linecards with more than one PFE (Packet Forwarding Engine) instance in FPC (Flexible PIC Concentrators) and "chained-composite-next-hop" knob OR "preserve-nexthop-hierarchy" knob OR SR-MPLS (Segment Routing - Multiprotocol Label Switching ) OR EVPN (Ethernet Virtual Private Network) over MPLS configuration, traffic loss will be seen due to any transport LSP (Label-switched Path) change operation including interface flaps.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1821845The system scripts refresh will fail when using load CLI option
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms when the 'edit system scripts' hierarchy configuration is changed using loading a configuration from a file or the terminal using 'load' option, the scripts refresh will fail.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1795952The eventd crashes if eventd traceoptions is enabled
Product-Group=junos
Severity=Major
When traceoptions is enabled for event-options, eventd crash may be observed.
PR NumberSynopsisCategory: Issues related to NETCONF
1792362RPC request for file copy with routing instances is failing
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms configured with routing instances, RPC (Remote Procedure Call) request for file copy using routing instance fails. There is no service/traffic impact due to this issue.
PR NumberSynopsisCategory: web filterig issues
1806786UTM Web filtering does not work for HTTPS traffic sent from Google Chrome browser or MS Edge v124
Product-Group=junos
Severity=Major
On SRX platforms, Unified Threat Management (UTM) web filtering does not work for Hypertext transfer protocol secure (HTTPS) traffic sent from Google Chrome browser or MS Edge v124.
PR NumberSynopsisCategory: VCCP related PRs for virtual-chassis in MX
1801522AE child links in back member is in detached state
Product-Group=junos
Severity=Major
On Junos MX platforms with MPC10E-10C card platforms, the issue is observed during a VC(Virtual Chassis) sequential upgrade , where AE child links in backup member is in detached state after auto reboot. Hence redundancy is lost
PR NumberSynopsisCategory: usf ams related issues
1804616NSD validation failure results into upgrade failure for Junos MX platforms
Product-Group=junos
Severity=Major
On Junos MX240, MX480, MX960 platforms, the Network Security Daemon (nsd) validation fails during upgrades.
 
 

23.2R2-S2 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 platform
1799093[EX2300]"Ethernet Link Down" would not be generated when me0 was down.
Product-Group=junos
On Junos EX2300 device, whenever the Management Interface Link is Down, the alarm was not getting generated as expected.

Resolved In: junos:22.2R3-S4 junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: MPC10/11/LC9600 Chassis Category
1715831MX reports continuous PLL Access Failures for LC9600
Product-Group=junos
For platforms which are designed with Junos and EVO there could be the repetition of PLL Access Failure logs which are cleared after 5 seconds

Resolved In: evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.4R2-S2 junos:22.4R3 junos:22.4R3-J4 junos:22.4R3-S2 junos:23.2R1 junos:23.2R2 junos:23.3R1
1769560LC4800 and LC2301/MX10K-LC9600 linecards stuck in present state
Product-Group=junos
On Junos MX10008 and MX10004 platforms with linecards LC2301/MX10K-LC9600 or LC4800, when out of range Packet Forwarding Engine (PFE) is configured, after the PFE is powered on/off, the linecards are stuck in present state, are out of service offline.

Resolved In: junos:24.1R1
PR NumberSynopsisCategory: MPC Fusion SW
1823373Interface will flap intermittently on MX platform with MPC2 or MPC3 during FPC restart or router boot up
Product-Group=junos
During the FPC restart or router boot up on the Junos MX devices with MPC2 or MPC3 used with CMIC_10X10GE_SFPP, the interface flaps intermittently. Traffic drop will be observed on the impacted interface.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Interface related area
180922040G interfaces on Junos SRX5K cluster will go down after cluster failover
Product-Group=junos
On Junos SRX5400/5600/5800 platforms in cluster, with 40G interface in layer 2 (L2) transparent mode, when the chassis failovers, the interfaces on node0 will remain in a down state and will not come up. The same issue can also occur when node1 failovers to node0.

Resolved In: junos:21.4R3-S8 junos:22.2R3-S5 junos:22.3R3-S4 junos:23.4R2-S1 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1797189We may observe repd core (in the "from" release) during ISSU. There are no functional impact due to this repd core
Product-Group=junos
On all Junos and Junos Evolved platforms, repd core observed (in the "from" release) during ISSU.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: MIBs related to BBE
1824274The jnxSubscriberPortTerminatedCounter shows incorrect values for interfaces
Product-Group=junos
On Junos MX platforms, the jnxSubscriberPortTerminatedCounter no longer shows the correct values for the individual ports. It shows the same value for all ports. These subscribers are enabled over PS interface.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Border Gateway Protocol
1728829In a high scaled environment, high rpd CPU utilization might be observed when a routing related commit is performed
Product-Group=junos
On all platforms, high rpd CPU utilization might be observed when a routing related commit is performed in a high-scaled environment having BGP groups configured with VPN family (inet-vpn, inet6-vpn). No traffic impact or protocol flap will be seen but unexpected high rpd CPU utilisation will raise operational challenges, especially if the system is very scaled.

Resolved In: evo:22.2R3-S4-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:20.3X75-D44 junos:22.2R3-S4 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: Issues related to Common BIOS on x86 based designs
1608045LTS19: MX960: 000: [Firmware Bug]: TSC_DEADLINE disabled due to Errata; please update microcode to version: 0x3a (or later) seen upon upgrade to 21.4
Product-Group=junos


Resolved In: junos:22.2R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1681716The device goes down when an FRU has over-temperature
Product-Group=junos
On MX240, MX480, and MX960, when the temperature for a particular FRU is above the over-temperature condition, the chassisd will start the timer(240 secs). If the over-temperature condition persists after completing 240secs, the chassis will be shut down instead of bringing down the particular FRU. This will impact the whole device traffic.

Resolved In:
1816912RE IIC access error alarms seen on device during commit.
Product-Group=junos
RE IIC access error alarms seen on device during commit.

Resolved In:
PR NumberSynopsisCategory: DNX Multicast
1799619Acx-arm-feb core may be triggered if IGMP snooping is enabled and IGMP Query is received on the same port as IGMP Join
Product-Group=junos
On Junos ACX5448 and ACX710 platforms, if IGMP (Internet Group Management Protocol) snooping is enabled, arrival of IGMP Query packet on a port where IGMP Join packet was previously received may lead to an inconsistency in NHDB (Next-Hop Database) and eventually trigger a core dump of acx-arm-feb process.

Resolved In: junos:21.4R3-S9 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1802464VXLAN/EVPN ip-address for mac-address in forwarding table in hold state
Product-Group=junos
Once receiving the same route as Type 2 and Type 5, the address entry might be stuck in hold state once remote peer restarts. The recovery is simply to clear the mac-ip table on the remote side with 'clear ethernet-switching mac-ip-table or bounce the BGP peer. This race condition is corrected.

Resolved In: evo:22.2R3-S4-EVO evo:22.4R3-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:21.4R3-S8 junos:22.2R3-S4 junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: EX4100 RE, Platform Infra, Drivers
1802614Emerald:Rampur:set chassis config-button no-clear support not added on ex4100
Product-Group=junos
Please check if it has to be release noted for previous releases on Emerald

Resolved In: junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: EX4400 PFE software
1816445DHCP snooping issue Observed on Access Ports with IRB and VXLAN Configuration
Product-Group=junos
On all Junos EX and QFX Series switches, DHCP-Snooping fails on access ports when the distribution layer is an L2 VXLAN (Virtual Extensible Lan) and the core is an L3 VXLAN gateway with configurations combining IRB (Integrated Routing and Bridging) and VXLAN. Enabling DHCP snooping via the MIST UI prevents DHCP binding.

Resolved In: junos:22.4R3-S3 junos:22.4R3-S4 junos:23.4R2 junos:24.2R1 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: EX Timing software
1800949The clksyncd process crash on Junos EX platforms
Product-Group=junos
On Junos and EX4400-VC platforms, the clksyncd process will crash occasionally when FPC(Flexible PIC Concentrators) restarts due to segmentation fault. There is no traffic impact due to this issue and also this issue is seen in a very corner case.

Resolved In: evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S8 junos:22.3R3-S3 junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1814387The traffic loss is observed if both L3 unicast and VTEP next hop are used to reach same destination
Product-Group=junos
In the EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) scenario on Junos QFX10K platforms, if the Layer 3 unicast and VTEP (VXLAN Tunnel Endpoint) next hops are both enabled for the same destination, traffic drop will be observed.

Resolved In: junos:22.2R3-S5 junos:22.4R3-S5 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1792128Configuring multiple IFL of different families on Junos QFX10K SP style interfaces leads to traffic loss
Product-Group=junos
On Junos QFX 10K platforms, traffic drop is seen when multiple interface logical (IFLs) of different families are configured on the same interface physical (IFD) with Service Provide (SP) style configuration and layer 2 (L2) ILF is the first IFL to be created.

Resolved In: evo:21.4R3-S9-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:22.2R3-S4 junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: track re issu control procedure bugs
1740744ISSU doesn't break if INDB crashes
Product-Group=junos
On Junos platforms, when ISSU (in-service software upgrade) is initiated, a process called INDB (Incompatible Database) will be triggered to perform a pre-check on database compatibility. There could be some corner case that causes the INDB crash. If that happens, the ISSU should be aborted.

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO junos:19.4R3-S13 junos:20.2R3-S10 junos:20.2R3-S9 junos:20.4R3-S10 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:23.4R2 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: Flow Module
1761542In a chassis cluster setup the flowd crashes and SPC cards will fail
Product-Group=junos
On SRX platforms, in a chassis cluster setup configured in Active/Active mode, the fabric forward packet enters the flow module causing the flow processing daemon (flowd) to crash, impacting the traffic forwarding and failing the Services Processing Card (SPC).

Resolved In: junos:21.4R3-S8 junos:23.4R2 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1708116Log streaming Hosts configured as FQDN may fail when DNS re-query is performed
Product-Group=junos
On SRX platforms, log streaming using FQDN requiring DNS name resolution may fail to re-query resulting in FQDN resolution to fail.

Resolved In: junos:21.2R3-S6 junos:21.2X32-D20 junos:22.3R3-S1 junos:23.1R2 junos:23.3R1
PR NumberSynopsisCategory: Security platform jweb support
1810991Display issue is observed when range option is used to configure destination/source port range in custom application
Product-Group=junos
On Junos SRX platform, J-web shows error message "The maximum length for this field is 9", when range option is used to configure destination/source port range in custom application and if the value is more than 10 characters.

Resolved In: junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1820882Traffic drop is seen in an EVPN multihoming scenario when mac-pinning is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms, in Ethernet VPN (EVPN) multihoming scenario with mac-pinning enabled, traffic drop will be seen when the Designated Forwarder role (DF) is changed.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.4R1
1822911Aggregated ethernet interface flaps can be seen when IRB interface is activated or deactivated
Product-Group=junos
On all Junos and Junos evolved platforms configured with AE (Aggregated Ethernet) interface and esi "auto-derive type-3-system-mac" knob configured, if an IRB (Integrated Routing and Bridging) interface is activated or deactivated the link aggregation interfaces ( IFL) will get flapped due to which interface traffic gets impacted.

Resolved In: junos:22.2R3-S5 junos:22.4R3-S5 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1792672License is lost on NG-RE platforms after device/routing-engine reboot
Product-Group=junos
On NG-RE (Next Generation Routing Engine) platforms, license is lost after restarting device/routing-engine. If any service depends on that license, that service will be impacted.

Resolved In: evo:22.2R3-S4-EVO evo:22.4R3-S4-EVO evo:23.2R2-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S4 junos:23.2R2-J12 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1816461MX304 macsec does not honor to MTU config, it drops incoming long frames as "oversized frames" which should be accepted.
Product-Group=junos
? MACSEC built into Juniper YT based ASIC on MX304 platforms o Prior to 23.4, MACSEC was performed in YT ASIC, the MTU was evaluated with the MACSEC overhead. As a result, the maximum packet size can be achieved on the link would be reduced by the length of MACSEC header (24 - 28B) o On 23.4 above version, MACsec is performed in external MACSEC PHY instead of MACEC built into YT ASIC. MTU is evaluated in YT ASIC; thus, with external MACSEC PHY, the YT evaluates MTU without MACsec overhead Please take above into consideration when adjusting MTU on MACSEC enabled links

Resolved In:
PR NumberSynopsisCategory: Odin Timing software
1810429ACX710 PTP ports marked 'passive' instead of 'master' during T-GM selection
Product-Group=junos
In a scenario where two T-GM devices (Telecom Grandmaster clocks) have identical BMCA (Best Master Clock Algorithm) parameters, except for steps removed or grandmaster ID, the ACX710 running the G.8275.1 profile can experience a failure in proper PTP (Precision Time Protocol) clock synchronization. This issue arises because the default BMCA is used instead of the expected Alternate BMCA profile in G.8275.1. This mismatch leads to incorrect PTP clock states, with master ports being marked as 'Passive' instead of 'Master'.

Resolved In: junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: PFE Peer Infra
1801535CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log
Product-Group=junos
On all Junos platforms, CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log. This log is not an error log but still printed under LOG_ERROR and flooded with default log level. This causes restart which will impact normal user traffic.

Resolved In: evo:23.4R2-EVO evo:24.2R1-EVO junos:21.4R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1676154The rpd crash can be seen in MoFRR scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd ( routing protocol daemon) can crash when PIM (Protocol Independent Multicast), MoFRR (Multicast only Fast Reroute) configuration is present and some network churn event such as continuous interface cost changes, resulting in a change of active and backup paths for ECMP (Equal Cost Multi-Path) happens. There will be service impact because of the rpd crash but the system self-recovers until the next crash.

Resolved In: junos:20.2R3-S4-J10 junos:20.3R3-S6 junos:21.2R3-S3 junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:23.4R1-S2 junos:23.4R2 junos:24.1R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.3R2
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1808550Traffic loss occurs when the layer 3 interface is deleted
Product-Group=junos
On all Junos QFX5K platforms, traffic loss happens and the layer 3 interface cannot be deleted when many routes use the same layer 3 interface. QFX5K is encapsulating the packets with the wrong DMAC(destination MAC ) and VNID(virtual network identifier) for a few IP addresses after disabling the interface.

Resolved In: junos:23.2R2-S3 junos:24.3R1
1819806[QFX5120] [EVPN-VXLAN] egress link protection doesn't work when local link is admin disabled
Product-Group=junos
In an EVPN-VXLAN topology built with QFX5120 devices, running Junos 23.2R2 with fast reroute for egress link protection feature configured (ELP - https://www.juniper.net/documentation/us/en/software/junos/evpn-vxlan/topics/topic-map/reroute-elp-for-evpn-mh.html), when one ESI LAG member link goes down (cable disconnect) we see the traffic fast-rerouted to the other egress leaf. However, when performing "set interfaces disable" from the leaf side the fast reroute is not happening. FRR is not meant to be used for planned events such as admin down (CLI command: "set interface disable"). This scenario is considered as invalid use case and it is not supported. In other words, there is no guarantee or minimize loss of traffic for admin disable with FRR for ELP.

Resolved In:
1820318Egress-link-protection in combination with IGMP/MLD snooping breaks snooping functionality
Product-Group=junos
On Junos EX and QFX platforms, when IGMP (Internet Gateway Monitoring Protocol)/MLD (Multicast Listener Discovery) snooping is configured on AE (Aggregated Ethernet) for which FRR (Fast Rerouting) is enabled, the snooping functionality breaks.

Resolved In: junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: QFX10008/16 QFX10002 linecard, serdes and uboot
1797453QFX-10002-36q||SFP+-10G-CU3M SFP are not coming up post upgrade from 18.2X75-D12.6 to 20.4R3-S7.2
Product-Group=junos
DAC modules were not recognized as DAC was not supported in older releases when recognition/Support is enabled in the software for all the SFP/QSFPs speeds like 40GE/100GE/10GE, for 10GE-DAC support got missed for QFX10002. Due to this, only this SFPP_10GE-CUxx stopped working in QFX10002. That is why when Optics was unknown (DAC was unsupported) earlier, Optics was working and after the SW upgrade to a REL where SFP -DAC is supported, SFP+ got recognized but did not work due to support missing.

Resolved In: junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 ISSU Infrastructure
1703229JDI_REG:: QFX5200:: After ISSU upgrade, device is hanged and not able to perform any operations until USB recovery done on device
Product-Group=junos
When TISSU upgrade is done from 22.4 release onwards, the box come up as backup RE.

Resolved In:
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1793196Multicast traffic black-holing upon MoFRR primary link went down
Product-Group=junos
On all Junos and Junos Evolved platforms, when MoFRR (Multicast-only fast reroute) is configured with NSR (Non-stop routing) while interface flapping or RE switchover, there is a next-hop leak and the next-hop in RIB (Routing Information Base) is different from the next-hop in FIB (Forwarding information base) due to that multicast traffic will be impacted.

Resolved In: evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S3-J31 junos:21.2R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: RPD policy options
1807830OSPF neighbourship with IPsec authentication goes down after RE switchover
Product-Group=junos
On all Junos OS Evolved platforms, the Open Shortest Path First (OSPF) neighbourship configured with Internet Protocol Security (IPsec) authentication will go down during the Routing Engine (RE) switchover.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1807037BGP backup routes are installed as primary routes after enabling 'protect core' feature
Product-Group=junos
On all Junos and Junos OS Evolved platforms when Border Gateway Protocol (BGP) multipath is enabled for Layer 3 Virtual Private Network (L3VPN) routes and 'protect core' is enabled on the Virtual Routing and Forwarding (VRF) instance, the backup BGP path is installed as primary path. The Next hop weight value is not updated correctly, it is weight 0x1 instead of weight 0x4000 for the backup.

Resolved In: evo:23.4R2-S1-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1785214RSVP incorrectly determines the outgoing interface resulting in the rpd crash
Product-Group=junos
On Junos platforms, the rpd (Routing Protocol Process Daemon) crash is observed when LSP (Label-Switched-Path) terminates on the incorrect outgoing interface. The issue happens because RSVP (Resource Reservation Protocol) incorrectly determines the outgoing interface that the ResvTear applies to.

Resolved In: evo:21.2R3-S8-EVO evo:22.2R3-S5-EVO evo:22.4R3-S2-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S8 junos:22.4R3-S2 junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1827806mspmand crash on clear/show services sessions" parallel in high scale on MX platforms
Product-Group=junos
On Junos MX with MS-MPC/MS-MIC cards, when clear service sessions are executed from multiple windows (approx 5 terminals), the PIC reboots and eventually all the service traffic will be impacted.

Resolved In: junos:21.2R3-S6-J16 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.4R3-S4
PR NumberSynopsisCategory: SRX branch platforms
1819054The ~root/.ssh directory contents is deleted on every reboot
Product-Group=junos
On all SRX platforms the contents of ~root/.ssh directory is deleted on every reboot. This can cause issues with SSH issues as locally stored public and private keys are deleted (stored on ~root/.ssh by default)

Resolved In: junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1796344PacketIO PFE process will drop small fragments of TCP and UDP packets destined to the routing engine
Product-Group=junos
On platforms running PacketIO PFE process (MPC10E, MPC11E, MX10K-LC9600, MX304 and all Junos OS Evolved platforms), small fragments of TCP and UDP packets destined to the routing engine will be dropped.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO junos:21.4R3-S5-J4 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1799286JDI-RCT:M/Mx: during ISSU (FRU upgrade stage - Blob Resync) , observed RSVP flap due to neighbor timeout / neighbor seq number change
Product-Group=junos
While performing ISSU if you have RSVP session scale, with ukern based MPCs you can experience few of the RSVP session protocols flap due to combined effect of ~12 secs dark window followed high utilization of CPU resource utilization by the local ttp rx thread (for ~13 secs). This problem can be avoided by the workaround provided.

Resolved In:
PR NumberSynopsisCategory: usf nat related issues
1802242Interim logs for deterministic NAT are not generated as per the modified time interval
Product-Group=junos
On all MX platforms, the configuration change done to interim logging interval for deterministic Network Address Translation (NAT) does not come into effect. Even after modifying the interval value from T1 to T2, logs still get generated at the interval T1.

Resolved In: junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1

Modification History

First publication 2024-09-18