Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 22.2R3-S5 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

 

Solution

Junos Software service Release version 22.2R3-S5 is now available.

22.2R3-S5 - List of Fixed issues

PR NumberCategory: Interface related area
1809220On Junos SRX5400/5600/5800 platforms in cluster, with 40G interface in layer 2 (L2) transparent mode, when the chassis failovers, the interfaces on node0 will remain in a down state and will not come up. The same issue can also occur when node1 failovers to node0.
PR NumberCategory: BBE state synchronization issues
1811787On all Junos and Junos OS Evolved platforms, in a scaled stack-based Subscriber Management scenario (e.g PPPOE, DHCP, PS over LT interface, etc.), the bbe-smgd process crash will be observed with continuous login/logout of a large number of subscribers over a period.
PR NumberCategory: Border Gateway Protocol
1692320On all Junos and Junos Evolved platforms deletion and addition of transport-class on top of BGP CT configuration and NSR configuration the rpd crash seen. commit synchronization process during config commit doesn't work for auto-created routing instances, created by BGP-CT transport classes.
1778879A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83011 [juniper.net] for more information.
1793714On all Junos and Junos Evolved platforms, when 'delay-route-advertisements always-wait-for-krt-drain' is configured, the EoR (End of Record) from the source peer of the routes is not received in the BGP (Border Gateway Protocol) peer which is sent by a BGP speaker to indicate the end of a record or a sequence of updates. This is due to the BGP router advertiser being stuck in the wait-for-inbound-convergence state, which may cause the KRT (Kernel Routing Table) queue to get stuck, thereby halting the advertisement of BGP routes.
1814083An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA88099 [juniper.net] for more information.
1815222An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue only affects systems with BGP traceoptions enabled. Please refer to https://supportportal.juniper.net/JSA88100 [juniper.net] for more information.
PR NumberCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1819305On all Junos OS and Junos OS Evolved platforms which supports BMP (BGP Monitoring Protocol), the BMP session stop sending data to an BMP Station. Please refer to TSB83918 [juniper.net] for more details.
PR NumberCategory: EVO Layer-2 switching for BCM XGS Platforms
1705911An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88128 [juniper.net] for more information.
PR NumberCategory: MX Platform SW - FRU Management
1784438When an MX304 LMIC is offline due to a power issue, it may take up to 20 minutes for the LMIC to come back online. You can configure event-options to reduce the time to restart the LMIC. See also: TSB83899 [juniper.net]
PR NumberCategory: OpenSSL and related subsystems
1815253The OpenSSL project has published security advisories for multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA88107 [juniper.net] for more information.
PR NumberCategory: Firewall Filter
1818988On all Junos and Junos Evolved platforms, when user tries to commit configuration an empty commit is behaving as commit full. Without any change, all daemons is notified to check and read the configuration as part of commit process. There is no service impact.
PR NumberCategory: EVO MACSEC Platform Independent Implementation
1811300On Junos MX2010/MX2020 platforms with MX2K-MPC11E line cards, and MACSec (IEEE 802.1AE standard) configured on line card ports. When the line card comes online for the first time, it is seen that ports are not being mapped correctly (port group value mismatch between picd and security) resulting in MACSec not working on some ports.
PR NumberCategory: EVPN Layer-2 Forwarding
1807084On MX, QFX and PTX10K line of routers running Junos and Junos OS Evolved with static Virtual Extensible LAN (VXLAN), the Virtual Tunnel Endpoint (VTEP) connections may not work properly after enabling or disabling control-word in the EVPN instance. This could disrupt the connectivity provided by the static VXLAN setup and affect data traffic.
PR NumberCategory: PFE EVPN / VxLAN related issues on EX platforms
1823764On Junos virtual-chassis specifically on EX4400, EX4100, EX4650, QFX5120, and QFX5110 platforms, EVPN VxLAN type 5 routes will not pass traffic after a routing-engine switchover.
PR NumberCategory: Express PFE FW Features
1830706On all Junos platforms, when a filter instance is modified or deleted, there should not be any old Packet Forwarding Engine (PFE) instances. However, during these operations, old PFE instances are being incorrectly assigned, resulting in incorrect memory address allocation. This leads to an Flexible PIC Concentrator (FPC) crash after committing the configuration, causing traffic loss.
PR NumberCategory: Express PFE including evpn, vxlan
1814387In the EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) scenario on Junos QFX10K platforms, if the Layer 3 unicast and VTEP (VXLAN Tunnel Endpoint) next hops are both enabled for the same destination, traffic drop will be observed.
PR NumberCategory: SRX4100/SRX4200 platform software
1808353On Junos SRX4100/SRX4200 platform, starting and stopping the "monitor traffic interface", causes the VPN tunnel or tagged traffic to be dropped. However, keeping the "monitor traffic interface" running, ensures that traffic will function properly. Issue occurs when monitor interface command on an interface is performed on devices that has vlan-tagging configured.
PR NumberCategory: idp flow creation, deletion, notification, session mgr intfce
1826377On SRX platforms with IDP (Intrusion Detection and Prevention) enabled, while processing IDP traffic a memory leak can occur which would lead to regular flow processing being affected as memory depletes eventually. This issue affects the following Junos releases: 21.2R3-S8, 21.4R3-S7/8, 22.2R3-S3/4, 22.3R3-S3, 22.4R3-S2/3, 23.2R2, 23.2R2-S1 and 24.2R1. All other releases are not affected by this issue.
PR NumberCategory: Integrated Routing & Bridging (IRB) module
1827648On all Junos QFX series platforms in an EVPN (Ethernet Virtual Private Network) VXLAN (Virtual Extensible Local Area Network) setup with CRB (Centralized Routing Bridge) architecture, ARP packets are not being learned, leading to traffic forwarding issues. This problem arises when ARP packets are sent from the firewall to the spine switches. The issue is linked to IRB (Integrated Routing and Bridging) handling and bridge domain re-incarnation, which triggers ARP request failures and impacts L3 forwarding.
PR NumberCategory: ISIS routing protocol
1746349On PTX platforms, ISIS SR-LDP stitching using mapping server could result in traffic drops on some legs of an ECMP if there are more than 8 ECMP paths and not all paths are via the same neighbor node.
1749850On all Junos and Junos OS Evolved platforms, multiple simultaneous Command Line Interface (CLI) sessions will lead to high Management Daemon (mgd) CPU utilization, impacting the device's reachability over the loopback interface from IS-IS nodes.
PR NumberCategory: jdhcpd daemon
1818919DHCP ALQ (Active Leasequery) Sessions go down due to core dumps in jdhcpd (Juniper DHCP Daemon). These jdhcpd core dumps may be seen on ALQ setups when subscriber synchronization happens after the TCP (Transmission Control Protocol) connection comes up.
PR NumberCategory: Flow Module
1719594An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to the https://supportportal.juniper.net/JSA83195 [juniper.net] for more information.
1820291An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88133 [juniper.net] for more information.
1821325When deleting the security l3vpn vrf-group configuration, unrelated bgp (Border Gateway Protocol) neighbor sessions are unexpectedly terminated due to session scans being performed on unrelated sessions. This issue impacts all SRX platforms supporting l3vpn configuration, including SRX4200, SRX4600, and SRX5600. To prevent this issue, avoid using the vrf-group configuration. Symptoms include unexpected termination of bgp sessions unrelated to the deleted vrf-group, leading to high traffic impact.
PR NumberCategory: SRX Firewall Authentication
1829894On all SRX platforms, when a user tries to authenticate to a captive portal to get access to resources, the authentication is successful, but the user is rerouted back to the captive portal with no resources access.
PR NumberCategory: High Availability/NSRP/VRRP
1821452An Improper Validation of Specific Type of Input vulnerability in the packet forwarding engine (PFE) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, network based attacker to cause a Denial of Service (Dos). Please refer to https://supportportal.juniper.net/JSA88134 [juniper.net] for more information.
PR NumberCategory: User Firewall related issues
1805233Multiple vulnerabilities have been resolved in nginx software included with Juniper Networks Junos OS by upgrading nginx to version 1.22.1 or by applying specific fixes. Please refer to https://supportportal.juniper.net/JSA88135 [juniper.net] for more information.
PR NumberCategory: IPSEC/IKE VPN
1817228On all Junos platforms that run kmd process, IPsec VPN tunnels experience traffic disruption after a change of authentication protocol (ESP is change to AH or vice versa).
PR NumberCategory: Platform infra to support jvision
1769294A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the AgentD process during telemetry polling, to move the AgentD process into a state where AgentD attempts to reap an already destroyed sensor. This reaping attempt then leads to memory corruption causing the FPC to crash which is a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88121 [juniper.net] for more information.
PR NumberCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1800944On all Junos and Junos OS Evolved platforms in the EVPN-VXLAN scenario, ipv4 and ipv6 traffic flooding will be seen due to the missing destination MAC address.
1812482On Junos and Junos Evolved platforms, traffic loss is observed when the Persistent MAC gets stuck in the SRP (Static, Remote, Pinned) state and not removed during the "clear persistence mac' operation for some MACs that are getting added with an incorrect flag: SRP. The issue happens when MAC learning happens on Multihoming peers where 'persistent-learning' is enabled in an EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) environment. MAC is just marked as Persistent but not installed in the Persistent database.
1816049On all Junos and Junos Evolved platforms, when "set vlans switch-options interface-mac-limit packet-action drop-and-log" is configured, changing the Virtual Local Area Network (VLAN) description will cause flush of Media Access Control (MAC) addresses learnt on the interfaces part of the VLAN and traffic impact
1822911On all Junos platforms configured in EVPN (Ethernet Virtual Private Network) scenario with AE (Aggregated Ethernet) interface and esi "auto-derive type-3-system-mac" knob, if an IRB (Integrated Routing and Bridging) interface is activated or deactivated the link aggregation interfaces ( IFL) will get flapped due to which interface traffic gets impacted.
PR NumberCategory: Port-based link layer security services and protocols that a
1757100On all Junos MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16, the statistics for MACSEC (MAC Security) are not displayed properly and lead to memory not getting freed. In a scaled environment of IFLs with MACSEC configured, eventually leads to AFTd-Trio daemon crash due to memory exhaustion.
PR NumberCategory: For multicast snooping on MX
1710565On all Junos and Junos Evolved platforms, whenever a commit is done, that involves mcsnoopd daemon config parsing such as (VLAN creation/deletion, interface add/delete to VLAN, interface enable/disable, IGMP (Internet Group Management Protocol) snooping/MLD (Multicast Listener Discovery) snooping related config commands) mcsnoopd will consume CPU. In less scaled setup (few IGMP snooping enabled VLANs and few hundred IGMP snooping memberships), the CPU time taken is less. In a more scaled setup (many IGMP snooping-enabled VLANs and a few thousand IGMP snooping memberships), the CPU may reach >90%. Since mcsnoopd is taking high CPU, it may affect other daemons like rpd. It may affect all the protocols if the CPU is not available to the protocols/daemons. This can impact route entries expiring and cause traffic drop.
PR NumberCategory: "ifstate" infrastructure
1780149Under unusual circumstances L2ALD process may get stuck in an infinite loop leading to high CPU, this is not a timing issue.
PR NumberCategory: Kernel Multicast Infrastructure
1740390On vPTX platforms, the PFE (packet forwarding engine) receives an invalid token from RPD (Routing Engine daemon) for composites next-hops due to which the PFE will crash leading to traffic drop.
PR NumberCategory: OSPF routing protocol
1827435On all Junos and Junos OS Evolved platforms, when the LSA (Link State Advertisement) count exceeds the maximum number configured under 'database-protection' feature in OSPFV2 (Open Shortest Path First Version 2), the OSPF database (DB) enters into 'ignore' state. When the DB is recovered, OSPF LSA flooding is stopped on some interfaces.
PR NumberCategory: Express Paradise PFE Sflow
1803542Recurring logs -ppcfpc-multi-svcs.elf: FDB :: Ipv4 route operation 2 failed. Rt_index are seen in PTX10008 after upgrade
PR NumberCategory: QFX PFE Class of Services
1786119On QFX5k virtual-chassis platforms working with 5e image, the pps rate display output for the egress interface would become zero after removing one of the VCP ports. The traffic is received as expected and it is only not displayed in the output.
PR NumberCategory: QFX L2 PFE
1824023On all Junos QFX5K and EX4K platforms supporting restricted 'proxy-arp' feature, when restricted 'proxy-arp' is enabled on IRB (Integrated Routing and Bridging) interface, hosts within the same subnet will not be able to reach each other.
PR NumberCategory: QFX L3 data-plane/forwarding
1789507On all Junos QFX5120 and EX4650 platforms the NH(Next-Hops) are not getting uninstalled from the FPC(Flexible PIC Concengrator) L3(Layer 3) Next Hop table. This issue applies to both standalone and VC (Virtual Chassis) setups and can been in MPLS(Multiple Protocol Labeled Switching) setup with Node/Link protection enabled and is triggered by network churn which causes a change in LSP (Labeled Switch Path).
PR NumberCategory: QFX analyzer, sflow
1808041On Junos QFX5K and EX4K platforms that support inline sampling, if the sFlow collector is reachable through a unilist next-hop with an indirect child when configuring inline sampling, the dcpfe process crashes.
PR NumberCategory: QFX EVPN / VxLAN
1798684On all Junos QFX5K, EX4100, EX4300, EX4400 and EX4650 platforms with EVPN-VxLAN (Ethernet Virtual Private Network-Virtual Extensible LAN), deleting the all IRB (Integrated Routing and Bridging) interfaces while still having Type 5 tunnels installed results in Type 5 tunnel traffic loss when Type 5 tunnel MAC (Media Access Control ) is same as global/chassis IRB MAC.
1818022On Junos Evolved platforms, when ELP (Egress link protection) is present on one device and not present on it's connected device(s), causing the rpd to generate VTEP (VXLAN Tunnel end Point) create notification. As there is no ELP present on the other node, ELP iff creation event gets stuck in the event queue. This blocks l2ald ( layer 2 addressing learning daemon) event queue. This impacts the L2 functionality of the other node where ELP is not configured. However, this doesn't impact the forwarding traffic as anything that is already programmed to hardware will not be impacted. Any update or new configuration will not take effect once the setup gets into this state.
1819073On Junos QFX5120/EX4650/EX4400/EX4100 platforms with pure EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) Type-5 tunnel (i.e. no type-2 tunnels), the VXLAN encapsulated packets received over Type-5 tunnel will be dropped, which will impact the traffic.
1820318On Junos EX and QFX platforms, when IGMP (Internet Gateway Monitoring Protocol)/MLD (Multicast Listener Discovery) snooping is configured on AE (Aggregated Ethernet) for which FRR (Fast Rerouting) is enabled, the snooping functionality breaks.
PR NumberCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1795339With some HW memory failure in QFX10008/16 Linecards, the PFE process gets stuck in bad state which takes 2-3min for detection causing traffic drops for that time.
PR NumberCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1777336On Junos QFX5120-48T devices, interface flap occurred unexpectedly. 1G/10GBT interfaces flaps due to Electro Magnetic Interference (EMI).
1799073On all QFX platforms, auto-channelization failure is seen due to faults on any channels of breakout channels, leading to link downtime and traffic disruption.
PR NumberCategory: QFX5200/5110/5120/5210 Platfom issues
1800862Due to a the disk failure reboot support was not added for dual disk scenario, hence system was not booting in case of disk failure on sdb (the other disk) on QFX platform.
PR NumberCategory: show route table commands, tracing, and syslog facilities
1812009On all Junos and Junos OS Evolved platforms, when there is any catastrophic changes made in the configuration without deactivating a particular routing instance will lead to the rpd process crash.
PR NumberCategory: Resource Reservation Protocol
1785214On Junos platforms, the rpd (Routing Protocol Process Daemon) crash is observed when LSP (Label-Switched-Path) terminates on the incorrect outgoing interface. The issue happens because RSVP (Resource Reservation Protocol) incorrectly determines the outgoing interface that the ResvTear applies to.
PR NumberCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1827806On Junos MX with MS-MPC/MS-MIC cards, when clear service sessions are executed from multiple windows (approx 5 terminals), the PIC reboots and eventually all the service traffic will be impacted.
PR NumberCategory: SRX Argon module
1815751An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of protected files on the file system. Please refer to https://supportportal.juniper.net/JSA88104 [juniper.net] for more information.
PR NumberCategory: Track usability related J-Web PR, like UI layout, workflow
1823264On all SRX series platforms enabled with J-Web, NAT (Network Address Translation) policies cannot be edited/added using J-Web if the destination address name contains '.' dot or '/' slash.
PR NumberCategory: SRX branch platforms
1819054On Branch SRX platforms the contents of ~root/.ssh directory is deleted on every reboot. This can cause issues with SSH issues as locally stored public and private keys are deleted (stored on ~root/.ssh by default)
PR NumberCategory: Stout card (MPC7) fabric issues
1812276On MX2010/MX2020 platforms with non-native LCs installed with an ADC, if a non-native LC PFE erroneously starts sending the traffic to a remote PFE using some fabric plane with link error towards that remote PFE, then this traffic will build up at the sending LC ADC, which cause the traffic blackholing to the remote PFE over all fabric planes.
PR NumberCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1819376On SRX4600 platform, upgrading from any earlier release to Junos 23.2R2 or later whether via ISSU (in-service software upgrade) or a standard upgrade process can cause the 1G interfaces to go down when the speed is changed from 10G to 1G. As a result, the port fails to activate properly at 1G, remaining down and unable to transmit any traffic.
PR NumberCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1788669On Junos MX platforms, when subscriber management is enabled and mac-validate is configured on interfaces, traffic drop is seen while attempting to add a new link to an existing AE (Aggregate Ethernet) bundle from a different FPC.
PR NumberCategory: Trio pfe l3 forwarding issues
1784593A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88123 [juniper.net] for more information.
PR NumberCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberCategory: Configuration mgmt, ffp, load-action, commit processing
1818692Core dumps in mustd seen commiting a change to a large prefix-list used by BGP
PR NumberCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1825728On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.
PR NumberCategory: Issues related to NETCONF
1819656In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.
PR NumberCategory: web filterig issues
1806786On SRX platforms, Unified Threat Management (UTM) web filtering does not work for Hypertext transfer protocol secure (HTTPS) traffic sent from Google Chrome browser or MS Edge v124.
PR NumberCategory: VCCP related PRs for virtual-chassis in MX
1801522On Junos MX platforms with MPC10E-10C card platforms, the issue is observed during a VC(Virtual Chassis) sequential upgrade , where AE child links in backup member is in detached state after auto reboot. Hence redundancy is lost
PR NumberCategory: video monitoring feature
1822738On all Junos MX platforms with MPC2E, MPC3E, MPC4, MPC5 and MPC6 line cards and video monitoring configuration enabled, the Packet Forwarding Engine(PFE) goes in to disabled state when multicast traffic with more than 10 downstream interfaces. This leads to traffic loss.
PR NumberCategory: Virtual Router Redundancy Protocol
1822867On all Junos and Junos Evolved platforms configured with VRRP (Virtual Router Redundancy Protocol) and NSR (Non-Stop Routing), after RE switchover or GRES (Graceful Routing Engine Switchover) the master router would starts sending VRRP advertisements with a different priority value. As a result, both the master and backup VRRP routers will begin operating as the master which results in inconsistent traffic routing or packet loss as the system fails to establish a single master node.
PR NumberCategory: usf flow and datapath issue on SPC3
1799512On Junos MX platforms equipped with SPC3 (Services Processing Card 3), when running on Talus 0x215 version and each SPC3-PIC (Physical Interface Card) handling significantly high throughput along with bursty traffic, will lead to tx_NoDp_drop' to be hit leading to packet drop.