Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 23.4R2-S3 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as needed and follow the prompts

NOTE: Starting August 30th, 2024, we include PR severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Solution

Junos Software service Release version 23.4R2-S3 is now available. For the list of known issues, see TSB91374 [juniper.net]

23.4R2-S3 - List of Fixed issues

PR NumberCategory: EX2300/3400 PFE
1822608
Major
On all Junos QFX5K and EX4K platforms with Layer 2 and Layer 3 logical interfaces (IFL) configured on the physical interface (IFD) enabled with 'encapsulation flexible-ethernet-services', MAC address is not learnt on the port after a reboot. This results in traffic drops.
PR NumberCategory: EX4100 Hardware
1822363
Major
On Junos EX4100 platform, intermittent alarms can occur regarding fan overspeed on the FPCs if they exceed the predefined fan speed threshold. These alarms are regularly activated and deactivated whenever the fan speed crosses the threshold and subsequently falls back below it. There is no service impact due to this
PR NumberCategory: NFX Series Platform Software
1799045
Major
On all NFX platforms with LTS19 image, the VNF (Virtual Network Function) OVS (Open vSwitch) interfaces fail to come up when more than 4 GB of memory is allocated to the VNF. This affects the traffic flow.
PR NumberCategory: "agentd" software daemon
1817267
Major
GNMI telemetry streaming of Decimal64 data types should stream double_val types instead of float_val types. GNMI has decremented the use of float_val and Decimal64 types in favor of double_val types for floating point data.
1820510
Major
On all Junos and Junos Evolved platforms having JTI (Junos Telemetry Interface)/UDP (User Datagram Protocol) based telemetry, unsupported configuration i.e. "gpb-sdm" is showing a possible completion when the command "set services analytics export-profile format gpb-?" is executed.
1820774
Major
When the Dial-Out profile's transport is set as "UDP", Config shall not allow the COMMIT with the profile's format for "gpb-gnmi".Both are the Exclusive, as gnmi is a TCP based transport.
1826196
Major
On Junos and Junos Evolved platforms with telemetry enabled, configuring any native sensor path like "set services analytics sensor interface_stats resource /junos/system/linecard/optics " will not be enabled unless "/" is added at the end. This will not have any traffic impact.
1831841
Major
On Junos and Junos Evolved platforms with analytics sensor resource configured, when the CLI telemetry configure command is accepting the resource path even if there is no leading / which is not a valid path results in telemetry streaming is not happening.
PR NumberCategory: access node control protocol daemon
1814300
Major
On all Junos MX platforms with dual RE (Routing Engine), having ANCP (Access Node Control Protocol ) and L2BSA (Layer 2 Bitstream Access) sessions under a scaled scenario (about 10k subscribers), when ISSU (Unified In-Service Software Upgrade) is performed followed by a GRES (Graceful Routing Engine Switchover), it is observed that the port-up messages from ANCP neighbor are dropped either at PFE (Packet Forwarding Engine) or by the ANCP daemon or BBE (Broadband Edge)/autoconf plugin which causes L2BSA sessions to remain down and as a result traffic over the affected subscriber sessions are dropped.
PR NumberCategory: PTX10000s Diags software
1832769
Major
A minor QoS license alarm warning is expected on PTX10002-36QDD devices with or without QoS configurations. Due to the presence of default QoS configurations, these warnings cannot be cleared and will reappear due to daily license checks. User commit warnings and alarms are expected but should be ignored for now.
PR NumberCategory: BBE interface related issues
1821021
Major
On all Junos MX platforms with enhanced Subscriber services running platforms that support ACI (Agent-Circuit Identifier)/ARI (Agent Remote Identifier) VLANS( Virtual Local Area Network), the 'bbe-smgd' process memory leak can be seen if under certain circumstances the parsing of huge number (~ Millions of Packets) of the ACI VLAN packet fails.
PR NumberCategory: BBE state synchronization issues
1811787
Critical
On all Junos and Junos OS Evolved platforms, in a scaled stack-based Subscriber Management scenario (e.g PPPOE, DHCP, PS over LT interface, etc.), the bbe-smgd process crash will be observed with continuous login/logout of a large number of subscribers over a period.
PR NumberCategory: BBE Statistics daemon & libraries
1820001
Critical
On Junos MX platforms, when a Stats DB corrupt entry in encountered, several processes related to subscriber management were high like CPU/Memory and statsd and authd both continuously crashing in both REs. As a result subscribers stuck in terminating.
1839200
Major
On MX platforms, in a Subscriber Management scenario, the subscriber sessions will be stuck in a terminated state when the subscriber IFD restarts(FPC or Port restart).
PR NumberCategory: Border Gateway Protocol
1788543
Major
On all Junos and Junos Evolved platforms, when there is a high route churn and the system reboot/restart routing/clear bgp neighbor is done, there are some values stuck in the OutQ counter of one of the peers in a group. This is a cosmetic issue since no missing routes at the BGP peer.
1810617
Major
On all Junos and Junos OS Evolved platforms, BGP (Border Gateway Protocol) routes are not installed on routing table when their next hops are link-local addresses, and unnumbered session and confederation are configured. Missing information in the routing table might cause no route to destination is found or suboptimal path being chosen.
1811862
Major
On all Junos and Junos Evolved platforms limit-bandwidth of policy-statement can only be configured to maximum value 4.2G (4294967295) which is not large enough based on actual maximum capacity. user@router# set policy-options policy-statement test then limit-bandwidth ? Possible completions: Limit advertised aggregate outbound link bandwidth (0...4294967295)
1814289
Major
On all Junos and Junos Evolved platforms, when "local-as alias" configuration knob is used on an IBGP session, it won't be able to get established in the scenario where peers have different global AS, but the same "local-as alias".
1817834
Major
On all Junos and Junos Evolved platforms configured with the "stale-labels-holddown-period" setting and extensive label configurations (such as Multiprotocol Label Switching labels), the Routing Protocol Daemon (RPD) may crash if stale labels are not cleared periodically and keep accumulating. Due this, temporary traffic impact will be seen until the rpd process restarts.
1826686
Major
On all Junos and Junos Evolved platforms, with BMP (BGP Monitoring Protocol) 'exclude-non-eligible' configured, the BGP route gets stuck in a hidden state with the next hop state as 'Next hop type unusable' leading to traffic drop.
PR NumberCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1819305
Critical
On all Junos OS and Junos OS Evolved platforms which supports BMP (BGP Monitoring Protocol), the BMP session stop sending data to an BMP Station. Please refer to TSB83918 [juniper.net] for more details.
PR NumberCategory: MX304 Chassis specific platform
1825417
Major
On Junos MX304 platforms configured for EVPN(Ethernet Virtual Private Network) VPWS (Virtual Private Wire Services) with DHCP-RELAY, VLAN(Virtual Local Area Network) creation fails if FPC0.PIC0 is not installed, even though its not in use. Removing PIC0 causes DHCP packets to be dropped, impacting VLAN auto-configuration for subscriber management.
PR NumberCategory: MX304 interface specific
1830620
Major
On Junos MX304 platform, the FPC (Flexible PIC Concentrators) reboot results in some ports and optics staying in 'Down' state.
PR NumberCategory: PFE COS features on BX based platforms
1806737
Major
On PTX 10008 and PTX-10002-36QDD platforms, rate-limit is un-supported, so ignore "rate-limit" configuration. It is behavior changes.
PR NumberCategory: CFM
1842542
Major
On Junos Evolved PTX platforms, the Connectivity Fault Management (CFM) session flaps continuously upon committing CFM inline mode and CFM sessions related configuration together. If CFM action profiles are configured to mark link-down, it will cause continuous marking of the logical interface as up and down affecting the convergence of routing protocols.
PR NumberCategory: QFX Access Control related
1819462
Major
In all Junos platforms supporting 802.1X authentication, when a supplicant client attempts to authenticate using an EAP (Extensible Authentication Protocol) - TLS (Transport Layer Security) certificate, and the user-name is left empty on the client's configuration, the authenticator receives an EAP-Response/Identity message with an empty user-name and the authd process rejects this message setting the port status to HELD, preventing access to network.
1826621
Major
On all Junos and Junos OS Evolved platforms configured with a dot1x authentication in single/single-secure supplicant mode, client authentication fails when the dot1x protocol is deactivated and activated back while having active authenticated sessions with Dynamic VLAN and VOIP (Voice Over IP).
1830067
Major
On all Junos platforms configured with a dot1x authentication, when a dot1x client is authenticated in single/single-secure supplicant mode with dynamic VLAN and later if a new dot1x profile is assigned along with a newly created VLAN, the dot1x client does not get authenticated and gets stuck in the connecting state. The users will be stuck in a connecting state and will not be able to authenticate hence losing access to the network.
PR NumberCategory: QFX Control Plane VXLAN
1815823
Minor
On all Junos QFX5k platforms, EVPN-VXLAN Egress Link Protection (ELP) is impacted when Spanning Tree Protocol (STP) is enabled, causing MAC address flushes and delays in Fast Reroute (FRR) activation. Traffic recovery occurs within a few seconds, but customers using FRR for rapid failover may experience slight interruptions.
PR NumberCategory: Platform PR for 1G/10G LC
1696186
Major
On MX10004/MX10008/MX10016 chassis running Junos LC480 may reboot when "request system firmware" CLI command is executed to get the firmware information.
PR NumberCategory: Segment Routing PFE part for v4 + SR-TE
1816807
Major
On Junos ACX2K, ACX5448, and ACX710 platforms in an l2circuit (Layer 2 Circuit) scenario with MPLS (Multiprotocol Label Switching) or any other labeling protocols configured as transport, when a non-active path is shut/disabled the l2circuit traffic blackholing will be observed.
PR NumberCategory: Ethernet OAM (LFM)
1811734
Major
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.
PR NumberCategory: EVO L2 Control Plane PRs
1817677
Critical
On MX and ACX platforms with Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN), symmetric route stitching between data center networks enables the Control Word (CW) flag changes, which will cause traffic disruption in the Packet Forwarding Engine (PFE).
PR NumberCategory: AAA, auditd issues
1825303
Major
In all Junos and Junos Evolved platforms, if the full name of the local user's account is configured with a very long character string, then the user is logged out with a "connection closed" message when attempting to authenticate against the local account. No other user will be able to authenticate using the local account database. Issue has been seen with character string with length 1659.Users already logged in when the issue arises are not affected.
PR NumberCategory: mgd, ddl, odl infra issues
1825793
Minor
"show system configuration rescue" may show strange "Last changed" timestamp. It may happen under any time zone potentially and looks like there are some patterns. In case of "Asia/Tokyo", Last changed timestamp may show "1970-01-01 08:59:59 JST".
PR NumberCategory: EVPN control plane issues
1826772
Major
On all Junos platforms with EVPN-VXLAN configured, Continuous kernel log messages are observed once EVPN-VXLAN fabric is up.
PR NumberCategory: EVPN Layer-2 Forwarding
1806660
Major
Due to a timing issue, errors occur on Junos platforms with IPv4/IPv6 and EVPN configuration after changing a VLAN name. This is caused by the IRB update before the Bridge-Domain delete and EVPN flag reset, causing the PFE to receive incorrect flags and throw errors. The observed error messages include PFE_ERROR_INVALID_STATE and Explicit kernel operation disallowed on child nh, nh_id=43328.
PR NumberCategory: EX Chassis Interface Handling
1833698
Major
On Junos EX4100 and EX4400 platforms, at commit time to configure device to ignore a PEM (Power Entry Module) alarm, switch core dump due to an error on Chassis control process (chassisd).
PR NumberCategory: EX4100 PFE
1802455
Major
On EX4400/EX4100 Platforms for VXLAN (Virtual extensible Local Area Network) configuration the interface is expected to accept untagged and member vlan tagged packet on deleting VOIP (Voice over IP) configuration on an access interface. But the access interface is not allowing member vlan tagged packets and only untagged packets are allowed.
PR NumberCategory: EX interfaces issues
1805370
Major
On Junos EX4400-48F platform only after replacing a 100 MB SFP endpoint device for a 1 GB SFP the switch port doesn't come up.
1814093
Major
On all EX4100 and EX4400 platforms with mge ports, the mge (multi rate gigabit ethernet) port shows up but does not allow traffic to pass through after port initialization or port flap.
1836616
Major
10G capable MGig ports will face auto-negotiation issues for lower speed than the default speed ( 10GB)
PR NumberCategory: Issues related to EX MACsec
1830395
Major
On all Junos and Junos Evolved platforms, when authentication-key-chain-name is configured with more than 31 characters, commit error is seen due to which MACSEC will not work with the configuration.
PR NumberCategory: EX optics issues
1794986
Major
On Junos 22.4R2 swapping 100m LX/FX modules will lead to those interfaces not coming UP, even if the interfaces are configured with the correct speed.
PR NumberCategory: PFE EVPN / VxLAN related issues on EX platforms
1823764
Major
On Junos virtual-chassis specifically on EX4400, EX4100, EX4650, QFX5120, and QFX5110 platforms, EVPN VxLAN type 5 routes will not pass traffic after a routing-engine switchover.
PR NumberCategory: EX Entry Level Access VC platform
1806262
Major
On all EX4100 and EX4400 platforms configured in virtual-chassis mode and set to HGOE (HiGig over Ethernet), changing the port type from vc-port to network port causes the network port to stay down and traffic loss is observed.
PR NumberCategory: Express PFE including evpn, vxlan
1814387
Major
In the EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) scenario on Junos QFX10K platforms, if the Layer 3 unicast and VTEP (VXLAN Tunnel Endpoint) next hops are both enabled for the same destination, traffic drop will be observed.
PR NumberCategory: SRX4100/SRX4200 platform software
1808353
Major
On Junos SRX4100/SRX4200 platform, starting and stopping the "monitor traffic interface", causes the VPN tunnel or tagged traffic to be dropped. However, keeping the "monitor traffic interface" running, ensures that traffic will function properly. Issue occurs when monitor interface command on an interface is performed on devices that has vlan-tagging configured.
PR NumberCategory: Integrated Routing & Bridging (IRB) module
1834886
Major
On MX304 platform, IRB (Integrated Routing and Bridging) interface units above 16385 cannot be configured using dot (.) command. The knob 'unit' has to be used for a successful configuration of IRB interface units above 16385.
PR NumberCategory: ISIS routing protocol
1828209
Major
Leaks gets introduced when SPF run for SRv6 routes which has additional sids, ie In the backup path. While building SID list for route next-hop, socket memory allocated which is not freed result in memory leak.
1830989
Major
On all Junos and Junos OS Evolved platforms, if graceful restart (GR) is not disabled for ISIS (Intermediate System to Intermediate System) multi-instance (MI), ISIS adjacency part of the igp-instance could get stuck in 'Initializing' state after rpd/protocol restart.
PR NumberCategory: Flow Module
1798672
Major
On all SRX platforms with Multinode High Availability (MnHA) configuration, some packets will be dropped when traffic traverses the Inter Chassis Datapath (ICD) link.
PR NumberCategory: Firewall Network Address Translation
1829549
Major
On all SRX platforms the use of address set (IP address) and address book (FQDN - Fully qualified domain name) in the same NAT (Network Address Translation) rule causes a nsd process crash.
PR NumberCategory: IPSEC/IKE VPN
1815800
Major
Small memory leak in ikemd process when deleting vpn tunnel.
1817228
Major
On all Junos platforms that run kmd process, IPsec VPN tunnels experience traffic disruption after a change of authentication protocol (ESP is change to AH or vice versa).
PR NumberCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1816049
Major
On all Junos and Junos Evolved platforms, when "set vlans switch-options interface-mac-limit packet-action drop-and-log" is configured, changing the Virtual Local Area Network (VLAN) description will cause flush of Media Access Control (MAC) addresses learnt on the interfaces part of the VLAN and traffic impact
1817705
Critical
On Junos platforms, if disk is full, when scaling configuration is moved to baseline configuration and move back to scaling configuration, l2ald try to create a source VTEP, but old VTEP is still in the middle of deletion, so kernel return EBUSY and l2ald will retry. If retry too many times, l2ald insist and core.
1822911
Major
On all Junos platforms configured in EVPN (Ethernet Virtual Private Network) scenario with AE (Aggregated Ethernet) interface and esi "auto-derive type-3-system-mac" knob, if an IRB (Integrated Routing and Bridging) interface is activated or deactivated the link aggregation interfaces ( IFL) will get flapped due to which interface traffic gets impacted.
1824739
Major
On platforms with MPC10, MPC11, LC9600 and MX304-LMIC line cards, during a transition from VPLS (Virtual Private LAN Services) to EVPN (Ethernet Virtual Private Network) or when the MAC (Media Access Control Address) addresses move from a local to a remote state, control MAC addresses are incorrectly programmed in the hardware, leading to traffic duplication and unresolved destination errors.
PR NumberCategory: Port-based link layer security services and protocols that a
1757100
Major
On all Junos MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16, the statistics for MACSEC (MAC Security) are not displayed properly and lead to memory not getting freed. In a scaled environment of IFLs with MACSEC configured, eventually leads to AFTd-Trio daemon crash due to memory exhaustion.
PR NumberCategory: MPC11 ULC fabric software related issues.
1798780
Critical
On MX platforms with SFB, in case of a fatal error encountered during SFB reboot ( due to hardware issue or ungrateful power restart ), SPMB will try to offline this SFB during bootup. At the same time, the system is busy training the fabric links to begin it online. This may cause a system-wide traffic impact due to the fabric not being consistent.
1802259
Critical
On MX2020/MX2010 platforms having SFB3, traffic drops will be observed due to multiple PFEs (Packet Forwarding Engine) getting disabled or blackholing traffic. This issue happens when an SFB3 comes up online after an ungraceful offline followed by a master SPMB reboot leading to fabric Link errors.
PR NumberCategory: Multiprotocol Label Switching
1814358
Major
On Junos and Junos Evolved platforms with RSVP-TE (Reservation Protocol-Traffic Engineering) configured, when IGP (Interior Gateway Protocol) "overload" is configured on the transit router, the traffic should move away from the transit router. But in the issue scenario, the LSP (Label Switched Path) continues to stay across the transit router which has been marked as overload and traffic continues across the transit router resulting in traffic drops or using the suboptimal path for the LSP. The issue happens when Patherr is received for the re-optimized path and CSPF (Constrained Shortest Path First) computation is triggered before the backoff timer.
PR NumberCategory: Phone-Home-Client Infrastructure
1828735
Major
As PHC is expected to be run before onboarding, it is assumed, no user would run "ping" in CLI. So as a cleanup mechanism, the PHC script which is part of the factory default configuration kills all ping processes before it can check connectivity with its gateway.
PR NumberCategory: QFX L2 PFE
1822251
Major
On QFX5100, EX4600, QFX5110, QFX5200, QFX5210 platforms (VC and standalone), MAC address may get into stuck in hardware. As a result, traffic is black-holed.
1824023
Major
On all Junos QFX5K and EX4K platforms supporting restricted 'proxy-arp' feature, when restricted 'proxy-arp' is enabled on IRB (Integrated Routing and Bridging) interface, hosts within the same subnet will not be able to reach each other.
PR NumberCategory: QFX L3 data-plane/forwarding
1789507
Major
On all Junos QFX5120 and EX4650 platforms the NH(Next-Hops) are not getting uninstalled from the FPC(Flexible PIC Concengrator) L3(Layer 3) Next Hop table. This issue applies to both standalone and VC (Virtual Chassis) setups and can been in MPLS(Multiple Protocol Labeled Switching) setup with Node/Link protection enabled and is triggered by network churn which causes a change in LSP (Labeled Switch Path).
1818740
Major
On Junos QFX5K series products enabled with multicast service, multicast forwarding traffic abruptly ceases after rebooting the device due to routes get in discard state. It affects multicast forwarding traffic because of the loss of multicast packets.
PR NumberCategory: QFX EVPN / VxLAN
1771445
Major
On Junos QFX5110 platforms, and while having configured 'native-vlan-id' and 'vlan-id-list' combined under an interface , untagged traffic gets dropped
1818022
Major
On Junos OS Evolved platforms, when ELP (Egress link protection) is present on one device and not present on it's connected device(s), it causes any new L2 (Layer 2) functionality (e.g. new VLAN creation, updating L2 message, etc.) to not work. As there is no ELP configuration on the other device, it blocks l2ald ( layer 2 addressing learning daemon) event queue. This impacts the L2 functionality of the other node where ELP is not configured.
1819073
Major
On Junos QFX5120/EX4650/EX4400/EX4100 platforms with pure EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) Type-5 tunnel (i.e. no type-2 tunnels), the VXLAN encapsulated packets received over Type-5 tunnel will be dropped, which will impact the traffic.
1820318
Major
On Junos EX and QFX platforms, when IGMP (Internet Gateway Monitoring Protocol)/MLD (Multicast Listener Discovery) snooping is configured on AE (Aggregated Ethernet) for which FRR (Fast Rerouting) is enabled, the snooping functionality breaks.
1821549
Major
On Junos QFX5K, EX4650, EX4100, and EX4400, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario when an underlay L2 interface is configured using the service provider style, the Leaf sends the Ethernet VPN (EVPN) packet with the wrong VLAN-ID to Spine. The spine drops the packet received with the wrong VLAN ID leading to the traffic loss.
1834627
Major
On all Junos QFX5K platforms, configuring a native VLAN on an underlay Network-to-Network Interface (NNI) that carries VxLAN (Virtual Extensible LAN) traffic results in the VLAN tag not being stripped as expected.Instead of treating the native VLAN traffic as untagged, the interface adds the VLAN tag, leading to packet drops at the remote end.
PR NumberCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1777336
Critical
On Junos QFX5120-48T devices, interface flap occurred unexpectedly. 1G/10GBT interfaces flaps due to Electro Magnetic Interference (EMI).
1799073
Major
On all QFX platforms, auto-channelization failure is seen due to faults on any channels of breakout channels, leading to link downtime and traffic disruption.
PR NumberCategory: QFX5200/5110/5120/5210 Platfom issues
1758868
Major
The Port interface is set wrong on 100G optics on QFX5200-32C platform.
PR NumberCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1810866
Major
On Junos OS Evolved platforms, the rpd (Routing Process Daemon) crash i.e. traffic impact is observed due to a segmentation fault. The issue happens when the rpd sends an add request for the same next-hop ID for multiple routes/unicast next-hops with the same prefix and points to a discard interface. The rpd doesn't expect the same next-hop ID for multiple routes/unicast next-hops.
PR NumberCategory: Issues related route resolution routing infrastructure
1818978
Major
On all Junos and Junos Evolved platforms, "preserve-nexthop-hierarchy" knob configured with Virtual Private LAN Service (VPLS), causes the Layer-3 (L3) control packets like that of Border Gateway Protocol (BGP) / Open Shortest Path First (OSPF) running over Integrated Routing and Bridging (IRB) interface to be dropped and brings down the protocol sessions.
PR NumberCategory: all ipv6 flow bugs on srx platforms
1807541
Major
If a bundled member link is removed either physically (cable disconnection) or by configuration (admin down), it may be observed that ipv6 traffic is continuing to send out that downed link.
PR NumberCategory: Track usability related J-Web PR, like UI layout, workflow
1823264
Major
On all SRX series platforms enabled with J-Web, NAT (Network Address Translation) policies cannot be edited/added using J-Web if the destination address name contains '.' dot or '/' slash.
PR NumberCategory: SRX branch platforms
1811858
Major
After CTL link down, Monitored-Status in "show chassis cluster interfaces" keeps showing "Up" state.
1819054
Major
On Branch SRX platforms the contents of ~root/.ssh directory is deleted on every reboot. This can cause issues with SSH issues as locally stored public and private keys are deleted (stored on ~root/.ssh by default)
1821344
Major
On branch SRX 300, 320, 340, 345, 380 platforms an upgrade/downgrade from Junos OS 22.4R3 or above versions, may fail to boot OS and get a loader prompt when via CLI command and with using partition option.
1821368
Major
On SRX380 platform, when a DAC interface is admin disabled, the DAC interface does not send a fault signal to a peer device and on peer device it will reflect as up.
PR NumberCategory: Stout card (MPC7) fabric issues
1812276
Critical
On MX2010/MX2020 platforms with non-native LCs installed with an ADC, if a non-native LC PFE erroneously starts sending the traffic to a remote PFE using some fabric plane with link error towards that remote PFE, then this traffic will build up at the sending LC ADC, which cause the traffic blackholing to the remote PFE over all fabric planes.
PR NumberCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1819376
Major
On SRX4600 platform, upgrading from any earlier release to Junos 23.2R2 or later whether via ISSU (in-service software upgrade) or a standard upgrade process can cause the 1G interfaces to go down when the speed is changed from 10G to 1G. As a result, the port fails to activate properly at 1G, remaining down and unable to transmit any traffic.
PR NumberCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1814341
Major
On MX platforms with MPC10/11/LC9600 and MX304 platforms with subscriber management enabled, the aftd process crash is seen. The line card reboots due to crash and subscribers will be logged off.
PR NumberCategory: ZT/YT pfe firewall software
1795940
Major
On AFT(Advanced Forwarding Toolkit) based MX platforms, default ARP(Address Resolution Protocol) policer fails because of which ARP resolution fails on the interface and hence the traffic gets impacted.
PR NumberCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329
Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
1826666
Major
On all Junos platforms, the console login doesn't work when authentication-order is configured under 'system services' hierarchy.
1826678
Critical
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of cRPD platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberCategory: Configuration mgmt, ffp, load-action, commit processing
1818692
Major
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP
PR NumberCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1794536
Minor
The device is went into config locked state due to stale mgd. For netconf sessions with , if ungraceful exit happens, the lock is not released. There is auto cleanup supported for such cases, But it is not triggered under problem conditions as faced in this PR. This leads to device remain in locked state due to stale entry. "request system logout pid " can be used for cleanup and to recover from this state.
1825728
Critical
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.
PR NumberCategory: Issues related to NETCONF
1800859
Major
On all Junos and Junos OS Evolved platforms, RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.
1819656
Major
In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.
PR NumberCategory: VCCP related PRs for virtual-chassis in MX
1801522
Major
On Junos MX platforms with MPC10E-10C card platforms, the issue is observed during a VC(Virtual Chassis) sequential upgrade , where AE child links in backup member is in detached state after auto reboot. Hence redundancy is lost
PR NumberCategory: Virtual Private LAN Services
1793342
Major
With VPLS service having NSR+GRES configured it may be seen that post RE switchover few of the VPLS sessions that were undergoing changes during transition to new RE may not come up, due to LSI IFL not getting created. This will impact the traffic flowing over that VPLS session
PR NumberCategory: Virtual Router Redundancy Protocol
1822867
Major
On all Junos and Junos Evolved platforms configured with VRRP (Virtual Router Redundancy Protocol) and NSR (Non-Stop Routing), after RE switchover or GRES (Graceful Routing Engine Switchover) the master router would starts sending VRRP advertisements with a different priority value. As a result, both the master and backup VRRP routers will begin operating as the master which results in inconsistent traffic routing or packet loss as the system fails to establish a single master node.
PR NumberCategory: usf ams related issues
1804616
Major
On Junos MX240, MX480, MX960 platforms, the Network Security Daemon (nsd) validation fails during upgrades.
PR NumberCategory: usf nat related issues
1829633
Critical
On MX240, MX480 , MX960 with Services Processing Card (MX-SPC3 ) and "jflow-log" configured , high memory consumption is seen in scaled setup and flowd process crashes when subscriber received through Endpoint Independent Filtering (EIF) reaches "max-sessions-per-subscriber" limit for Network Address and Port Translation(NAPT44). The Services Processing Unit(SPU) reboots and services self-recover if this issue is hit.

 

Modification History

2025-01-23 Update to add a reference to TSB91374 - List of Known Issues [juniper.net]

First publication 2024-11-25