Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX (exclude EX4400s) MX NFX PTX QFX SRX vSRX For EX4400 see TSB88017 [juniper.net]

Alert Description


Junos Software Service Release version 24.2R1-S1 is now available from the Junos software download site. This SRN applies to all platforms - except the EX4400s (see TSB88017 [juniper.net] for EX4400s)

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution


Junos Software service Release version 24.2R1-S1 is now available.

24.2R1-S1 - List of Fixed issues 

PR NumberSynopsisCategory: NFX Series Platform Software
1799045VNF OVS Interface failure with high memory
Product-Group=junosvae
Severity=Major
On all NFX platforms with LTS19 image, the VNF (Virtual Network Function) OVS (Open vSwitch) interfaces fail to come up when more than 4 GB of memory is allocated to the VNF. This affects the traffic flow.
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1820001Multiple processes on both the REs are crashing
Product-Group=junos
Severity=Critical
On Junos MX platforms, when a Stats DB corrupt entry in encountered, several processes related to subscriber management were high like CPU/Memory and statsd and authd both continuously crashing in both REs. As a result subscribers stuck in terminating.
PR NumberSynopsisCategory: BBE Remote Access Server
1818321authd process crashes when radius-server-name is configured
Product-Group=junos
Severity=Major
On EX platforms, authd process will crash if 'radius-server-name' knob configuration is present.
PR NumberSynopsisCategory: QFX Access Control related
1819462Switch port status is changed to unauthorized, when a supplicant client attempts to authenticate using 802.1X standard with EAP-TLS certificate
Product-Group=junos
Severity=Major
In all Junos platforms supporting 802.1X authentication, when a supplicant client attempts to authenticate using an EAP (Extensible Authentication Protocol) - TLS (Transport Layer Security) certificate, and the user-name is left empty on the client's configuration, the authenticator receives an EAP-Response/Identity message with an empty user-name and the authd process rejects this message setting the port status to HELD, preventing access to network.
PR NumberSynopsisCategory: Platform PR for 1G/10G LC
1816506JNP10K-LC480 Linecard fails to come online after restart due to CM Errors
Product-Group=junos
Severity=Major
On Junos MX10004 & MX10008 platforms with Switch Fabric Board 2 and MX10K-LC480, the CM Errors will be seen on the restart of the MX10K-LC480. As a result, the Fabric links for MX10K-LC480 will go into a 'check' state, and the PIC (Physical Interface Card) will fail to come online, resulting in traffic loss.
PR NumberSynopsisCategory: CASB feature on SRX platform
1823224Junos SRX Series device might boot in amnesiac mode and configuration commit might fail with 'error: Check-out failed for CASB process'
Product-Group=junos
Severity=Minor
During upgrade of Junos SRX Series devices to 24.2R1 release or newer, device might boot in amnesiac mode and configuration commits might fail with 'error: Check-out failed for CASB process'.
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1800966Application identification failure observed post reboot of a node in redundancy group
Product-Group=junos
Severity=Major
On Junos SRX1600 and SRX2300 configured as chassis cluster, when a node is rebooted, priority values are observed to take long time (~10 minutes) to populate and application identification version will be reflecting 0 post reboot.
PR NumberSynopsisCategory: EX4400 PFE software
1816445DHCP snooping issue Observed on Access Ports with IRB and VXLAN Configuration
Product-Group=junos
Severity=Major
On all Junos EX and QFX Series switches, DHCP-Snooping fails on access ports when the distribution layer is an L2 VXLAN (Virtual Extensible Lan) and the core is an L3 VXLAN gateway with configurations combining IRB (Integrated Routing and Bridging) and VXLAN. Enabling DHCP snooping via the MIST UI prevents DHCP binding.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1808353Traffic drop is seen when "monitor traffic interface" command is issued for an interface on Junos SRX platforms
Product-Group=junosvae
Severity=Major
On Junos SRX4100/SRX4200 platform, starting and stopping the "monitor traffic interface", causes the VPN tunnel or tagged traffic to be dropped. However, keeping the "monitor traffic interface" running, ensures that traffic will function properly. Issue occurs when monitor interface command on an interface is performed on devices that has vlan-tagging configured.
PR NumberSynopsisCategory: MX LC4800 Interface software
1814101With 24.2R1 software release, some of the 100G and 400G links may remain DOWN after LC4800 FPC restart
Product-Group=junos
Severity=Major
With 24.2R1 software release, some of the 100G and 400G links may remain DOWN after LC4800 FPC restart. Check workaround for recovery.
PR NumberSynopsisCategory: jdhcpd daemon
1817227DHCP asymmetric-lease-time is slow processing large scale requests to terminate 64K subscribers.
Product-Group=junos
Severity=Major
DHCP asymmetric-lease-time code has been optimized to increase the processing speed from 20 client requests per second to 100 client requests per second.
1818919jdhcpd core dumps may be seen on ALQ setups when subscriber synchronization is done
Product-Group=junos
Severity=Major
DHCP ALQ (Active Leasequery) Sessions go down due to core dumps in jdhcpd (Juniper DHCP Daemon). These jdhcpd core dumps may be seen on ALQ setups when subscriber synchronization happens after the TCP (Transmission Control Protocol) connection comes up.
PR NumberSynopsisCategory: Juniper Device Manager User Interface includes cli, mgmt
1819466JUNOS_REG:DVAITA:INCHASSIS: Jns-jdm-vmhost-rpm package installation is getting failed as there is a change in rpm package string name .
Product-Group=junosvae
Severity=Major
Jns-jdm-vmhost-rpm package installation is getting failed as there is a change in rpm package string name. The fix cannot be committed to 24.2R1 since commit window is closed
PR NumberSynopsisCategory: Platform infra to support jvision
1817967Product annotation is missing for sensors on the MX, PTX, and EX92XX platforms
Product-Group=junos
Severity=Major
Product annotation files with correct product support/exclude information for specific sensors with respect to platform MX, PTX and EX92XX products. Request customer to enable CLI "set services analytics product-path-check no-path-check" configure to override product annotation issue.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1812482Persistent MAC getting stuck in the SRP state results in traffic loss in the EVPN-VxLAN scenario
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, traffic loss is observed when the Persistent MAC gets stuck in the SRP (Static, Remote, Pinned) state and not removed during the "clear persistence mac' operation for some MACs that are getting added with an incorrect flag: SRP. The issue happens when MAC learning happens on Multihoming peers where 'persistent-learning' is enabled in an EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) environment. MAC is just marked as Persistent but not installed in the Persistent database.
1816049MAC addresses learnt on interfaces part of VLAN with MAC limiting by interface and "drop-and-log" action configured are cleared after VLAN description is changed
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when "set vlans switch-options interface-mac-limit packet-action drop-and-log" is configured, changing the Virtual Local Area Network (VLAN) description will cause flush of Media Access Control (MAC) addresses learnt on the interfaces part of the VLAN and traffic impact
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1802259SFB ungraceful offline followed by master SPMB reboot results in traffic drops due to fabric Link errors
Product-Group=junos
Severity=Critical
On MX2020/MX2010/MX2008 platforms having SPMB (Switch Processor Mezzanine Board) and SFB (Switch Fabric Board), traffic drops will be observed due to multiple PFEs (Packet Forwarding Engine) getting disabled or blackholing traffic. This issue happens when SFB comes up online after an ungraceful offline followed by a master SPMB reboot leading to fabric Link errors.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1819356mlx5 VFs stop forwarding traffic after a little while on vSRX 3.0 with Junos OS version 24.2R1
Product-Group=junos
Severity=Critical
When using mlx5 VFs on vSRX 3.0 with Junos OS version 24.2R1, the interfaces will come up but stop forwarding traffic after some time. There will also be some error logfiles generated in /var/log starting with "dpdk_mlx5_port_". This is due to an upstream bug in FreeBSD 15's kernel causing memory corruption in DPDK. This has been fixed for all future releases and will be fixed in the next service release of 24.2R1.
PR NumberSynopsisCategory: SRX branch platforms
1819054The ~root/.ssh directory contents is deleted on every reboot
Product-Group=junos
Severity=Major
On all SRX platforms the contents of ~root/.ssh directory is deleted on every reboot. This can cause issues with SSH issues as locally stored public and private keys are deleted (stored on ~root/.ssh by default)
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1788669Traffic drop due to mac-validate failure on MX platforms
Product-Group=junos
Severity=Major
On Junos MX platforms, when subscriber management is enabled and mac-validate is configured on interfaces, traffic drop is seen while attempting to add a new link to an existing AE (Aggregate Ethernet) bundle from a different FPC.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1816378XQSS_CMERROR errors will be seen which might disable PFE
Product-Group=junos
Severity=Major
On MX204, MX10003 and MX platforms with MPC7, MPC8, MPC9, LC480, LC2101, LC2103, MPC10 and MPC11 line cards or EX92xx platforms with EX9200-40XS, EX9200-12QS, EX9253-6Q12C, EX9253-6Q12C-M line cards, SRX5400, SRX5600, SRX5800 platforms with SRX5K-IOC4-10G, SRX5K-IOC4-MRAT line cards, in a scenario where there could be fabric drops because of over-subscription or CRC errors, there could be case when the same tail entry get re-used across packets leading to packet corruption and CM error. This is a corner case and might lead to PFE(Packet Forwarding Engine) disable resulting in traffic loss.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1826666Console login fails when authentication-order is configured under 'system services' hierarchy on all Junos platforms
Product-Group=junos
Severity=Major
On all Junos platforms, the console login doesn't work when authentication-order is configured under 'system services' hierarchy.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1818692Core dumps in mustd seen commiting a change to a large prefix-list used by BGP
Product-Group=junos
Severity=Major
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1821845The system scripts refresh will fail when using load CLI option
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms when the 'edit system scripts' hierarchy configuration is changed using loading a configuration from a file or the terminal using 'load' option, the scripts refresh will fail.
1825728The mgd process crashes while using an FQDN in conjunction with the ephemeral configuration database
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.
1827506PDT: MGD core upon startup followed by endless flood of 'could not add xml command' messages
Product-Group=junos
Severity=Major
MGD core upon startup followed by flood of 'could not add xml command' messages when upgrading to 24.2R1-S1 if "system configuration-database extend-size" knob is used
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1795952The eventd crashes if eventd traceoptions is enabled
Product-Group=junos
Severity=Major
When traceoptions is enabled for event-options, eventd crash may be observed.
PR NumberSynopsisCategory: Issues related to NETCONF
1800859Configuration push to device using RPC resulted in incorrect policy order
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms,  RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.
1811327Union replace operation fails if the configuration being replaced doesn't exist on the device
Product-Group=junos
Severity=Major
Union replace operation fails if the configuration being replaced doesn't exist on the device
1819656In all Junos and Junos OS Evolved platforms, with Multinode High Availability configured, node configuration on primary might differ from backup due to configuration synchronization failure at the time of commit
Product-Group=junos
Severity=Major
In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.
PR NumberSynopsisCategory: Track Windriver Linux issues
1631579A few line cards will be stuck in the 'Present' state and later go 'Offline'
Product-Group=junos
Severity=Critical
A system equipped with specific line cards, the line cards will be stuck in the 'Present' state and later go 'Offline' after the line card or router is rebooted. Ideally, the Line Card should go 'Online' instead it goes 'Offline'.
 
 

24.2R1-S1 - List of Known issues 

PR NumberSynopsisCategory: NFX Series Platform Software
1807738The dcpfe crashes during shutdown in NFX350
Product-Group=junos
On Junos NFX350 platforms, the dcpfe process crashes when the device goes for a shutdown or reboot.

Resolved In: junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: BBE database related issues
1818781Multiple BBE daemons getting killed automatically on MX platforms
Product-Group=junos
In a scaled subscriber management router, customers observe authd and Jdhcpd daemons being killed automatically due to block tasks.

Resolved In: junos:23.2R2-S2 junos:23.2R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1814017Extensible Subscriber Services Manager (ESSM) sessions gets disconnected when PFE encounters an issue for any service or subscriber session
Product-Group=junos
On all Junos and Junos OS Evolved platforms, where subscriber-management is configured and if PFE encounters an issue for any service or subscriber session then it sends an error for anyone of the session in bulk response which results in the subscriber services to be disconnected.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1815125JDI-RCT:M/Mx: after unsupported card is offlined during ISSU validation in MX router, fabric planes are stuck in check state
Product-Group=junos
Issue of this PR is caused by PR1796770 which basically does not offline the fabric during FPC offline in ISSU state. Due to which if there are any ISSU unsupported FPC's in the system during ISSU, fabric planes will be stuck in "check" state.

Resolved In: junos:23.2R2-S2 junos:23.4R2 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Device Configuration Daemon
1827981EX4400: Continous messages might get printed in the logs 'DCD_CONFIG_WRITE_FAILED: IFL me0.0 configuration write failed for an IFL ADD: File exists'
Product-Group=junos
DCD_CONFIG_WRITE_FAILED: IFL me0.0 configuration write failed for an IFL ADD: File exists - On some rare occurence, the aforementioned message might get filled up in logs after an upgrade to 24.2R1-S1 image.

Resolved In:
PR NumberSynopsisCategory: Firewall Filter
1829614config rollback fails with commit error: Invalid XML from dfwd
Product-Group=junos
after switchover in MX2010 platform , test config is removed with load update and then rollbacked. during rollback commit , config commit failed with below error: error: commit-check-daemon : Invalid XML from dfwd error: configuration check-out failed

Resolved In:
PR NumberSynopsisCategory: Category to track runtime issues during package install
1803205JDI-RCT:M/Mx: during ISSU , MPC11 cards are stuck in "Reboot" phase of FRU upgrade stage (mpc11 rebooting continuously) leading to ' ISSU RECONNECT TIMEOUT ' (segfault at 80 ip 00007fcf1d867c9c sp 00007fffbdaaf158 error 6 in libc.so.6)
Product-Group=junos
MPC11 In-Service-Software-Upgrade command fails from release 24.1R1 to 24.2R1 and causes MPC11 linux crash. The issue only applies to ULC image.

Resolved In:
PR NumberSynopsisCategory: EX interfaces issues
1805370Interfaces remain down on EX4400-48F platform after replacing a 100MB SFP with 1GB SFP
Product-Group=junos
On Junos EX4400-48F platform only after replacing a 100 MB SFP endpoint device for a 1 GB SFP the switch port doesn't come up.

Resolved In: junos:23.4R2 junos:24.2R2 junos:24.4R1
1812891When frames above 9080bytes are sent across interfaces with 10m/100m speed between Lonewolf-4300-48MP, then we start seeing traffic loss even at 6M to 8Mbps rate
Product-Group=junos
When packets above size of 9080 are sent across 1G links which are configured to operate in 100MB/10MB, traffic loss will be loss with higher traffic rate (more than 40% of line rate). This issue is specific to EX4300-MP platform.

Resolved In:
1820086EX4400:TDR diagnostic test does not execute intermittently on random ports.
Product-Group=junos
Time Domain Reflectometry (TDR) support for detecting cable breaks and shorts aborts intermittently on some random ports.

Resolved In:
1823097EX4400: fxpc core seen during offline/online of 1x100GE Uplink Module
Product-Group=junos
An FXPC core might be generated when an offline and online activity is performed on a 1x100GE Uplink module. The system resumes in normal fashion after the core

Resolved In:
1823394EX4400-48MXP/48XP CPU hog by Thread CMQFX & Task ACQUIRE_FP_LOCK during PIC offline and online
Product-Group=junos
On the EX4400-48MXP/48XP devices with 1x100G or 4x25G Uplink Module(ULM) in PIC slot 2, when we perform a PIC offline/online operation, we may see messages related to CPU hog by the threads CMQFX or Task ACQUIRE_FP_LOCK. These will be seen only during the operation and does not affect the offline or online operation of the PIC

Resolved In:
1823743EX440 series: While performing a 4x25g channelization configuration on the 1x100GE PIC, certain error logs are printed multiple times
Product-Group=junos
While performing a 4x25g channelization configuration on the 1x100GE PIC, following error logs are printed multiple times momentarily. They are transient log messages. <. . . . > "qsfp_tk_cdr_control: qsfp-0/2/0 channelization not yet supported" <. . . .> These message will appear while applying the below configuration #set chassis fpc 0 pic 2 port 0 channel-speed 25g #commit These are harmless logs and can be ignored. There is no functional impact due to these logs

Resolved In:
1826147EX4400 series: Offline and then an online of PIC 2 installed with a 1x100GE Uplink module configured for Virtual-chassis link causes the link to remain down
Product-Group=junos
EX4400 series: When an offline and an online command is issued for a PIC 2 installed with a 1x100GE Uplink module configured for Virtual-chassis operation, the link may not come back to operational state and remains down.

Resolved In:
1826410EX4400 series: Virtual chassis auto-conversion fails in a 4x25G Uplink module along with 10G-SFPP-T tranceivers
Product-Group=junos
Virtual chassis auto-conversion is attempted for 4x25G Uplink modules when inserted with 10G-SFPP-T transceivers. Auto-conversion fails and links remain down

Resolved In:
1827455EX4400-48MP, EX4400-48MXP: Intermittently some of the PIC 0 interfaces (between 0 to 35) might stop receiving traffic even when the link is operational (UP).
Product-Group=junos
When a EX4400-48MP/ EX4400-48MXP is rebooted, sometimes the multirate gigabit ethernet (mge- ) interface fails to receive traffic after booting up. However, the interface remains operational at the time of issue. The link is up.

Resolved In:
1829037Virtual Chassis Port (VCP) port on PIC 2 Uplink module might go down after a reboot or a routing-engine switch-over
Product-Group=junos
In a EX4400 Virtual chassis with multiple member stacked together with PIC 2 as VC Port, a reboot or a routing-engine switch-over might result in a VC Port going down specifically operating on a 4x25GE Uplink module. The aforementioned problem might be seen intermittently.

Resolved In:
1831409On an EX4400 device with 4x25G Uplink module configured in 1GE or 25G speed, peer side of an interface with 10GBASE-T transceiver may remain up even when the IFD(xe-x/2/y) is not created
Product-Group=junos
On an EX4400 device with 4x25G Uplink module configured in 1GE or 25G speed, peer side of an interface with 10GBASE-T transceiver may remain up even when the IFD(xe-x/2/y) is not created. For this to happen, a speed mismatched configuration is needed, where a 1G speed or a 25G speed is configured on the PIC 2.

Resolved In:
PR NumberSynopsisCategory: EX4400 PFE software
1817034EX4400: Post NSSU, loading a factory default configuration or any baseline configuration and then, applying a LAG, IRB & OSPF configuration, causes OSPF neighborship to stuck at exstart state
Product-Group=junos
In a specific configuration change after NSSU, i.e. delete and add sequence of link aggregation bundles (LAG) done via load baseline configuration and re-apply original configuration, OSPF session might get stuck in EXSTART state.

Resolved In:
PR NumberSynopsisCategory: EX4400 platform
1812514The output of "show chassis routing-engine" does not show the standard documented outputs after a reboot event or a GRES event
Product-Group=junos
On EX platforms, after reboot or GRES, the "show chassis routing engine" command shows incorrect output. The 5 seconds, 1, 5 and 10 minute CPU average utilization is not shown in the output. Its a display issue and there is no functional impact due to this issue.

Resolved In: junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1814463EX4400: MIST: Wrong PSU state is updating in the mist
Product-Group=junos
Unsupported PEM/PSU is shown as online (green)in the MIST Dashboard and the output of "show chassis environment" for that PSU shows the status as present/OK. No functional impact.

Resolved In:
PR NumberSynopsisCategory: NSSU
183683524.2R2-Hardening: EX4100: NSSU: NSSU for EX4100 VC fails from 23.4R2-S1.3 to 24.2I-20240909.0.1028 with chassisd core
Product-Group=junos
In case of Virtual Chassis NSSU upgrade to 24.3R1/23.4R2/24.2R1, there is chassisd core which causes VC break and leads to NSSU failure. Work-around:- Perform a normal software upgrade instead of using NSSU procedure.

Resolved In: junos:23.4R2-S3 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1823764, EX series: EVPN VxLAN: Some Type 5 routes will not forward traffic after a routing-engine switchover with NSR/NSB
Product-Group=junos
In EX platforms, some EVPN VxLAN T5 routes will not pass traffic after a routing-engine switchover (GRES)

Resolved In: junos:22.2R3-S5 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1815250ARP resolution issues might happen when VxLAN and non-VxLAN are both configured on the same ifd but different ifl
Product-Group=junos
Due to a conflict in the config between the VXLAN (Virtual Extensible LAN) hardware token and the VLAN (Virtual Local Area Network) traffic loss could happen as consequence of wrong path for ARP (Address Resolution Protocol)

Resolved In: junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Juniper Device Manager VM Mgmt and infrastructure function
1774177Performance degradation on NFX platform running WRL LTS19
Product-Group=junosvae
Degradation on all NFX platform running Wind River Linux (WRL) Long Term Support (LTS) 19, due to several components in LTS19 taking up more CPU/memory and reducing performance.

Resolved In:
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1797468FIPSCC - SRX5k (L2HA) - node1 went to disabled state with SPC3 going to Announce offline and IOC4 to Present state
Product-Group=junos
On SRX5K HA cluster in FIPS mode, repeated manual failovers of redundancy groups can result in SPC3 or IOC4 or both the cards going offline.

Resolved In:
PR NumberSynopsisCategory: Platform infra to support jvision
1817964/interfaces/interface/subinterfaces/subinterface/state sensors are not working on 24.2R1
Product-Group=junos
/interfaces/interface/subinterfaces/subinterface/state sensors are not working due to product annotation missing. Request customer to enable CLI "set services analytics product-path-check no-path-check" configure to override product annotation issue.

Resolved In:
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1822911Aggregated ethernet interface flaps can be seen when IRB interface is activated or deactivated
Product-Group=junos
On all Junos platforms configured in EVPN (Ethernet Virtual Private Network) scenario with AE (Aggregated Ethernet) interface and esi "auto-derive type-3-system-mac" knob, if an IRB (Integrated Routing and Bridging) interface is activated or deactivated the link aggregation interfaces ( IFL) will get flapped due to which interface traffic gets impacted.

Resolved In: junos:22.2R3-S5 junos:22.4R3-S5 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1805723post GRES , smid is stuck at 100% and device doesn't become switchover ready
Product-Group=junos
We've noticed that we are experiencing 100% CPU utilization during GRES in the smid and alarmd daemons. After investigating, we discovered that the gRPC client (feature daemon) was sending RPC requests and waiting for responses while the gRPC server (license-check daemon) was down during GRES. If the client doesn't receive a response within the specified deadline time (30 seconds), it should return a GRPC_QUEUE_TIMEOUT type and success value as 0. But, it got stuck in getting "grpc_core:: Timestamp:: Now ()" API.

Resolved In: junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: lldp sw on MX platform
1811545The LLDP neighborship does not recover on AE interfaces
Product-Group=junos
When LLDP is configured on interface all and there are AE interfaces configured, to disable LLDP on one of the AE "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, AE is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.

Resolved In: evo:22.3X50-EVO evo:23.4R2-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S7-J17 junos:21.2R3-S8-J2 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: MX Timing software
1738532[Clocking Solution]:MX480:PTP state went to Freerun and acquiring upon SyncE ESMC is disabled/downgraded from GM or the upstream node one hop above the parent node
Product-Group=junos
PTP state went to Freerun and acquiring before phase-aligning again when the SyncE ESMC is disabled or downgraded from GM or the upstream node one hop above the parent node

Resolved In:
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1827102EX4400-48XP and EX4400-48MXP: vmcore and ksyncd cores observed while upgrading the junos image on EX4400-48XP and EX4400-48MXP.
Product-Group=junos
A vmcore and a ksyncd core might be generated during junos image upgrade.

Resolved In:
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 ISSU Infrastructure
1703229JDI_REG:: QFX5200:: After ISSU upgrade, device is hanged and not able to perform any operations until USB recovery done on device
Product-Group=junos
When TISSU upgrade is done from 22.4 release onwards, the box come up as backup RE.

Resolved In:
PR NumberSynopsisCategory: KRT Queue issues within RPD
1805427The rpd process crashes during rpd restart on Junos and Junos Evolved platforms
Product-Group=junos
On all Junos and Junos Evolved platforms, due to timing issue during the restart of the rpd process may cause it to crash. This can temporarily impacts traffic until the process recovers.

Resolved In: evo:22.4R3-S5-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.4R3-S5 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1761191Memory leak in rpd due to deactivation and activation of routing-instances, interfaces and protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Border Gateway Protocol (BGP) rib-sharding enabled and NSR(Nonstop Active Routing) configured, upon deactivation and activation of routing-instances, interfaces and protocols together, memory leak in rpd is observed. There will be no traffic impact at this time because memory leak is very slow.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
1771344Leaked routes via BGP rib-group remains in hidden state even though "loops" is configured with any value greater than one
Product-Group=junos
On all Junos and Junos Evolved platforms having BGP (Border Gateway protocol) configured, when route is leaked via rib-group from one routing instance to another having the same AS (Autonomous System) number and one of the routing-instances has BGP configured with local-as, it is observed that even after configuring "loops" with any value greater than one as the number of loops option, the route still remains hidden instead of being active which results in traffic drop.

Resolved In: evo:24.4R1-EVO junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: SRX branch platforms
1811858Monitored-Status keeps Up after CTL link down in branch model SRX HA
Product-Group=junos
After CTL link down, Monitored-Status in "show chassis cluster interfaces" keeps showing "Up" state.

Resolved In: junos:23.2R2-S2 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
1821344On branch SRX 300, 320, 340, 345, 380 platforms upgrade/downgrade from Junos OS 22.4R3 or above versions, may fail.
Product-Group=junos
On branch SRX 300, 320, 340, 345, 380 platforms an upgrade/downgrade from Junos OS 22.4R3 or above versions, may fail to boot OS and get a loader prompt when via CLI command and with using partition option.

Resolved In: junos:22.4R3-S4 junos:23.2R2-S2 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1800967JDI-RCT:AlfaRomeo:Observing PPE trap @ Sync XTXN Err PPE/Context 140/16 @ PC 0x114d: fw_flt_launch
Product-Group=junos
Under scaled configurations with interfaces, FW filters, routing protocols etc certain script based config/unconfig automated operations, in the presence of continuous traffic, can encounter one or more PPE traps that momentarily cause traffic drops. These momentary traffic drops happen at the tail end of the time the business configuration is removed and a baseline configuration is loaded in a single commit. These do not cause any service or functionality impact.

Resolved In:
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1815922"Possible out-of-order deletion of AftNode" error messages will be seen after ifconfig down/up
Product-Group=junos
"Possible out-of-order deletion of AftNode" error messages will be seen after ifconfig down/up. Issue is seen due to out-of-order IPCs received for IRB MACs. This causes the MAC entry not to be deleted from the s/w MAC table which prevents the deletion of associated NH token. 30 minutes post the ifconfig down/up, the error messages will be seen.

Resolved In:
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1799286JDI-RCT:M/Mx: during ISSU (FRU upgrade stage - Blob Resync) , observed RSVP flap due to neighbor timeout / neighbor seq number change
Product-Group=junos
While performing ISSU if you have RSVP session scale, with ukern based MPCs you can experience few of the RSVP session protocols flap due to combined effect of ~12 secs dark window followed high utilization of CPU resource utilization by the local ttp rx thread (for ~13 secs). This problem can be avoided by the workaround provided.

Resolved In:
1816396Deletion/deactivation of a logical-system with scaled config may trigger rpd core in logical-system
Product-Group=junos
With logical-systems configured with a big scale of routing-instances and interfaces in each. During deactivation/deletion of some or all of the logical-systems, it is possible that in a rare event a logical-system could not be cleaned-up gracefully within the timeout of 10 minutes and subsequently the logical-system RPD cores. This core does not have any impact on the already running default RPD or any of the other logical-systems.

Resolved In:
PR NumberSynopsisCategory: MX10K linecard
1809511Ethernet interfaces configured with loopback option remains down after multiple iteration of line card boot is performed
Product-Group=junos
On MX platforms with LC2101 line cards and 10-gigabit ethernet interfaces configured in loopback mode, when Line card is booted multiple times, the ethernet interfaces on line card remains down and traffic on those interfaces will be impacted.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: MX10004 Software Diagnostic
1801778SFB PCIE switch temp sensors yellow alarm falsely reported at high altitude and high temp operating conditions
Product-Group=junos
When LC4800 is operated in the worst case operating corner, i.e. all ports running at full line rate, NEBS ambient temperature = 55C, high altitude, there is a possibility that the PCIe switch temp sensor on the SIB8 (JNP10008-SF2) can falsely report a yellow alarm for over temperature. This issue is applicable to Junos 24.2R1 and 24.2R1-S1 releases. Hardware Symptoms tracking signature: cli show system alarms Alarm time Class Description 2024-03-07 02:28:45 PST Minor SFB 2 PCIe Switch Temp Sensor Warm

Resolved In:
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1822867After RE switchover the VRRP master and backup router will start functioning as master routers
Product-Group=junos
On all Junos and Junos Evolved MX platforms configured with VRRP (Virtual Router Redundancy Protocol) and NSR (Non-Stop Routing), after RE switchover or GRES (Graceful Routing Engine Switchover) the master router would starts sending VRRP advertisements with a different priority value. As a result, both the master and backup VRRP routers will begin operating as the master which results in inconsistent traffic routing or packet loss as the system fails to establish a single master node.

Resolved In: evo:21.4R3-S9-EVO evo:22.2R3-S5-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.2R3-S5 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1

 

Modification History

First publication 2024-10-03