Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX platforms running Junos Evolved software

Alert Description

Junos Software Service Release version 22.4R3-S5-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 22.4R3-S5-EVO is now available.

22.4R3-S5-EVO - List of Fixed issues

PR NumberSynopsisCategory: Border Gateway Protocol
1807504BGP multipath selects wrong interface with "Multiple Single-Hop EBGP sessions on different links using the same IPv6 Link-Local Address"
Product-Group=evo
Severity=Major
On Junos and Junos Evolved Platforms having BGP (Border Gateway Protocol) Multipath when "Multiple Single-Hop EBGP Sessions on different links using the same IPv6 (Internet Protocol Version 6) Link-Local Address" as over multiple links and one of those links is down, the next-hop information which has the smallest IFL (Logical Interface) index interface will get deleted. Since RIB (Routing Information Base) and FIB (Forwarding Information Base) are not correct network traffic will be lost when one of the peer device is down.
1811862Improper maximum value for limit-bandwidth of policy-statement
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms limit-bandwidth of policy-statement can only be configured to maximum value 4.2G (4294967295) which is not large enough based on actual maximum capacity. user@router# set policy-options policy-statement test then limit-bandwidth ? Possible completions: Limit advertised aggregate outbound link bandwidth (0...4294967295)
1826686Traffic impact due to BGP route stuck in hidden state
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, with BMP (BGP Monitoring Protocol) 'exclude-non-eligible' configured, the BGP route gets stuck in a hidden state with the next hop state as 'Next hop type unusable' leading to traffic drop.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1777759LAG interfaces will take longer than usual to come up in a scaled scenario with ALB
Product-Group=evo
Severity=Major
On PTX10001, PTX10004, PTX10008 and PTX10016 platforms, if Adaptive load balancing (ALB) is configured on LAG interface, the LAG interfaces will take longer than usual to be up if they are all enabled in the same commit. LAG interfaces get stuck in 'attached' state. This issue happens in a scaled Link Aggregation Group (LAG) (~65 ae*) scenario.
1784498Higher AE traffic convergence observed in ALB configured AE interface
Product-Group=evo
Severity=Major
On PTX10001-36MR/PTX10004/PTX10008 and PTX10016 platforms, if Adaptive load balancing (ALB) is configured on AE (Aggregated Ethernet) interface and link up/down, the AE interfaces will take higher traffic convergence during FRR (Fast Reroute) compared to regular AE.
1790095The pfestatsd process may fail to restart when running out of file descriptors
Product-Group=evo
Severity=Major
The pfestatsd process runs out of file descriptors when there are 16 FPCs in the system as the number of concurrent connections exceeded 1024 for Junos EVO Platforms seen on releases 23.2R2-S1-EVO, 23.4R1-S2-EVO, 21.4R3-S7-EVO, and 22.4R3-S2-EVO
PR NumberSynopsisCategory: DNX platform MPLS FRR features
1768729Unknown unicast IPv4 Traffic received with UDP destination port 8503 will be flooded back to Source PE
Product-Group=evo
Severity=Major
On the Junos Evolved ACX7K platform, the split horizon rule is broken when an IPv4 packet with destination UDP port 8503 is received on the system over the Ethernet VPN (EVPN), Layer-2 and VPLS network. This will result in the traffic being sent /flooded to the source PE router. The below filter can be seen incrementing during the issue. pfe> show evo-pfemand filter counters filter-name __BfdLspMplsSelfPingTrap_unit0__ Counter-Name Packets BytesBfdLspMplsSelfPingTrap_unit0-rule 125016 99578126
PR NumberSynopsisCategory: EVO Services Jflow PRs for defect & enhancement requests
1828032The flow record outputs are not displayed correctly on Junos Evolved platforms
Product-Group=evo
Severity=Major
The Jflow record output are not displayed correctly, if the unknown prefix/route hits this sampling interface on Junos Evolved platforms configured with a Default route and Sampling. It has no traffic impact.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1807084The VXLAN traffic drop could be seen after modifying control-word in an EVPN instance
Product-Group=evo
Severity=Major
On MX, QFX and PTX10K line of routers running Junos and Junos OS Evolved with static Virtual Extensible LAN (VXLAN), the Virtual Tunnel Endpoint (VTEP) connections may not work properly after enabling or disabling control-word in the EVPN instance. This could disrupt the connectivity provided by the static VXLAN setup and affect data traffic.
PR NumberSynopsisCategory: Issues related to EX MACsec
1830395Commit error on using more than 31 characters authentication-key-chain-name
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when authentication-key-chain-name is configured with more than 31 characters, commit error is seen due to which MACSEC will not work with the configuration.
PR NumberSynopsisCategory: Express PFE COS AFT software issues
1814641One CoS drop-profile might not work on PTX EVO platforms
Product-Group=evo
Severity=Major
Due to mishandling reserved 'drop-profile" curve index zero, one of "class-of-service drop-profiles" might not get programmed correctly in the ASICs on some FPCs. Curve index zero is reserved for 'default-drop-profile', which disables WRED (for dropping or ECN). If a non-default drop-profile configuration object reaches FPC AFT software first, AFT wrongly assigns curve index zero to that drop-profile. But lower-layer software will not program WRED for curve index zero. It is unpredictable whether this bug occurs for a given FPC reboot, with drop-profiles already configured. Schedulers whose drop-profile-map uses the affected drop-profile might have WRED disabled in hardware, so only Tail-drops will be seen if that queue drops packets for congestion.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1824739The traffic is getting duplicated when VPLS to EVPN transition is performed
Product-Group=evo
Severity=Major
On platforms with MPC10, MPC11, LC9600 and MX304-LMIC line cards, during a transition from VPLS (Virtual Private LAN Services) to EVPN (Ethernet Virtual Private Network) or when the MAC (Media Access Control Address) addresses move from a local to a remote state, control MAC addresses are incorrectly programmed in the hardware, leading to traffic duplication and unresolved destination errors.
PR NumberSynopsisCategory: Label Distribution Protocol
1817712MPLS LDP sessions are not established when container-lsp is configured with an already existing lsp-template
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms Label Distribution Protocol (LDP) sessions are not formed due to the configuration of "container-lsp" with an already existing configured lsp-template which has "ldp-tunneling" knob enabled.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1757100Memory leak observed in AFTd-Trio daemon in PFE with IFL based MACSEC enabled on MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16
Product-Group=evo
Severity=Major
On all Junos MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16, the statistics for MACSEC (MAC Security) are not displayed properly and lead to memory not getting freed. In a scaled environment of IFLs with MACSEC configured, eventually leads to AFTd-Trio daemon crash due to memory exhaustion.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1744584Traffic loss will be observed whenever a soft preemption reroute request arrives
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, whenever a soft preemption reroute request arrives in the middle of the ongoing make-before-break, traffic loss would be observed which is still referring to the old instance.
1814358LSP keep retrying over the transit router marked as "overload" resulting in traffic drops or using the suboptimal path for the LSP
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms with RSVP-TE (Reservation Protocol-Traffic Engineering) configured, when IGP (Interior Gateway Protocol) "overload" is configured on the transit router, the traffic should move away from the transit router. But in the issue scenario, the LSP (Label Switched Path) continues to stay across the transit router which has been marked as overload and traffic continues across the transit router resulting in traffic drops or using the suboptimal path for the LSP. The issue happens when Patherr is received for the re-optimized path and CSPF (Constrained Shortest Path First) computation is triggered before the backoff timer.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1805427The rpd process crashes during rpd restart on Junos and Junos Evolved platforms
Product-Group=evo
Severity=Major
On all Junos platforms, due to timing issue during the restart of the rpd process may cause it to crash. This can temporarily impacts traffic until the process recovers.
PR NumberSynopsisCategory: RPD policy options
1795263Performance degrades when learning BGP routes with communities
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, degraded performance occurs when BGP routes with communities are learned.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1812124The rpd process crash is observed when the label received exceeds the configured maximum-labels 16
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms, the rpd process crash is observed on both REs (Routing Engines) and RE switchover was triggered when maximum-labels under MPLS(Multi Protocol Label System) address family is configured as 16 and an extra label is received.
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1812009The rpd process crash is observed when there are catastrophic changes under the particular routing instance configuration
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, when there is any catastrophic changes made in the configuration without deactivating a particular routing instance will lead to the rpd process crash.
PR NumberSynopsisCategory: Resource Reservation Protocol
1819948LSP re-optimization issue has been observed
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, the LSP (Label Switched Path) re-optimization issue has been observed. LSP bandwidth change is unsuccessful due to bandwidth unavailable RSVP (Resource Reservation Protocol) PathErr.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1820791Per-Segment-list telemetry for colored tunnel doesn't work
Product-Group=evo
Severity=Major
Per-Segment-list telemetry for colored tunnel doesn't work on PTX-Series platform with Junos OS Evolved such as PTX10004, PTX10003, PTX10001, but it works on PTX10008 and PTX10016.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=evo
Severity=Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1818692Configuration commit fails due to mustd process crash
Product-Group=evo
Severity=Major
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP
PR NumberSynopsisCategory: Issues related to NETCONF
1800859Configuration push to device using RPC resulted in incorrect policy order
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.
PR NumberSynopsisCategory: Issues related to YANG Data Models
1826630Annotations are improperly structured in NETCONF after enabling YANG compliance
Product-Group=evo
Severity=Major
When the YANG(Yet Another Next Generation)-compliant knob is configured, annotations containing non-alphanumeric characters are written as-is, instead of being escaped into their corresponding formats.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1822867After RE switchover the VRRP master and backup router will start functioning as master routers
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms configured with VRRP (Virtual Router Redundancy Protocol) and NSR (Non-Stop Routing), after RE switchover or GRES (Graceful Routing Engine Switchover) the master router would starts sending VRRP advertisements with a different priority value. As a result, both the master and backup VRRP routers will begin operating as the master which results in inconsistent traffic routing or packet loss as the system fails to establish a single master node.

 


 

22.4R3-S5-EVO - List of Known issues

PR NumberSynopsisCategory: Express PFE MPLS for EVO platforms
1829924PTX devices acting as transit nodes display incorrect MPLS traceroute or TTL
Product-Group=evo
On Junos Evolved PTX10K platforms, when there is an ECMP to destination, PTX devices in a transit MPLS path do not decrement the TTL value properly, leading to ICMP tunneling failure and incorrect traceroute behavior.

Resolved In: evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R1-S2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.4R1
PR NumberSynopsisCategory: All Guardian (ACX7509) timing related issues
1756587in ACX7509, syncE Clock failure is seen on 4x100G channelized interface
Product-Group=evo
in ACX7509, syncE Clock failure is seen on 4x100G channelized interface

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1825728The mgd process crashes while using an FQDN in conjunction with the ephemeral configuration database
Product-Group=evo
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.

Resolved In: evo:21.4X9-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:22.4R3-S4-EVO evo:23.2R2-S2-EVO evo:23.4R2-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.4R2-S2 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.3R2 junos:24.4R1
PR NumberSynopsisCategory: Issues related to NETCONF
1819656In all Junos and Junos OS Evolved platforms, with Multinode High Availability configured, node configuration on primary might differ from backup due to configuration synchronization failure at the time of commit
Product-Group=evo
In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.

Resolved In: evo:21.4R3-S9-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:23.2R2-S2-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.4R1

 

Modification History

First publication 2024-11-07