Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX platforms running Junos Evolved software

Alert Description

Junos Software Service Release version 24.2R1-S2-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 24.2R1-S2-EVO is now available.

24.2R1-S2-EVO - List of Fixed issues

PR NumberCategory: PTX10003 Hardware Generic
1797283
Major
Issue is seen when system is rebooted, while coming up during initialization of Peripheral Component Interconnect Express (PCIe) link of Quad Band Advanced Modem Field-Programmable Gate Array (QBAM FPGA). In a rare condition when the FPGA PCIe link could not lock properly, it intermittently did not respond to PCIe requests from the CPU.
PR NumberCategory: PTX10001 diagnostics software related issues.
1822938
Major
On the PTX10001-36MR-K routers, sometimes on a reboot the "Link Mon" app starts before the eth1 links come UP. This results in the major alarm "Host 0 Ethernet Interface Link Down" being raised. The alarm does not clear on its own although the Eth1 link does come up and there is no issue with management port connectivity.
PR NumberCategory: BBE Remote Access Server
1812697
Major
On Junos Evolved platforms, after device has finished booting up with Zero Touch Provisioning (ZTP), authd process will crash and generate a core file.
PR NumberCategory: QFX Access Control related
1819462
Major
In all Junos platforms supporting 802.1X authentication, when a supplicant client attempts to authenticate using an EAP (Extensible Authentication Protocol) - TLS (Transport Layer Security) certificate, and the user-name is left empty on the client's configuration, the authenticator receives an EAP-Response/Identity message with an empty user-name and the authd process rejects this message setting the port status to HELD, preventing access to network.
PR NumberCategory: CoS support on DNX
1813565
Major
On Junos Evolved ACX platform, a CoS module failure is preventing the creation of logical tunnel (LT) interfaces. This leads to complete disruption of any service running over the LT interface until the device is rebooted.
1839055
Major
Junos Evolved ACX7k platforms may experience delays in route programming on handling AE (Aggregated Ethernet) interface down events causing convergence issues.
PR NumberCategory: EVPN ELAN/E-TREE
1820024
Major
On Junos OS Evolved ACX7100 platforms when the HQOS (Hierarchical Quality of Service) scheduler is enabled on a VLAN (Virtual Local Area Network) interface and EVPN (Ethernet Virtual Private Network) FXC (Flexible Cross-Connect) is enabled traffic drop will be seen.
PR NumberCategory: Layer 3 forwarding, both v4+v6
1810357
Major
On Junos Evolved ACX platforms, if the ECMP unilist level changes due to network churn, the Packet Forwarding Engine (PFE) is failing to update this hierarchy change in the hardware. Due to this traffic drop is seen for the affected flows.
PR NumberCategory: EVO MBB infra related issues and enhancements
1820376
Critical
On Junos Evolved PTX platforms, due to quick Aggregated Ethernet (AE) interface flap, Multicast routes can be out of sync between the control plane and the forwarding plane (rpd and Packet Forwarding Engine (PFE)) resulting in traffic drops.
PR NumberCategory: Express ptx-evo PFE L3 Features
1816310
Major
VRRP (Virtual Router Redundancy Protocol) will not work when VRRP group 0 is configured and specific Junos OS Evolved platforms (PTX10001/PTX10003/PTX10004/PTX10008/PTX10016) are working as master.
PR NumberCategory: Express PFE MPLS for EVO platforms
1829924
Major
On Junos Evolved PTX10K platforms, when there is an ECMP to destination, PTX devices in a transit MPLS path do not decrement the TTL value properly, leading to ICMP tunneling failure and incorrect traceroute behavior.
PR NumberCategory: SNMP, mib2d issues
1815524
Major
On Junos OS Evolved platforms, the mib2d process crashes when SNMP get request is performed for duplicate OIDs.
PR NumberCategory: Express PFE CFM
1822526
Critical
On Junos Evolved PTX10K platforms, Bidirectional Forwarding Detection (BFD) protocol sessions will flap continuously and never become stable after this. This exposure is not deterministic and is only exposed if BFD is operating in hardware-assisted inline mode.
PR NumberCategory: Express pfe ddos protection feature
1801290
Major
On PTX EVO platforms, ddos(distributed denial of service) statistics values of "Arrival rate" and "Max arrival rate" on System-wide and FPC show larger values than expected.
PR NumberCategory: Express PFE L2 fwding Features
1815166
Major
On Junos Evolved PTX platforms, if the AE (Aggregated Ethernet) member interfaces are present only on non-zero (PFEs) Packet Forwarding Engine, the evo-cda-bt process crash is observed for releases below 21.4R1-EVO and beyond 21.4R1-EVO releases error logs are observed which have no impact.
PR NumberCategory: ACX7332 & ACX7348 HWD process
1819254
Major
On Junos OS Evolved platforms, Negative values are observed for jnxOperatingUpTime while using this SNMP mib after ~248 days uptime.
PR NumberCategory: MX LC4800 Interface software
1814101
Major
With 24.2R1 software release, some of the 100G and 400G links may remain DOWN after LC4800 FPC restart. Check workaround for recovery.
PR NumberCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1816049
Major
On all Junos and Junos Evolved platforms, when "set vlans switch-options interface-mac-limit packet-action drop-and-log" is configured, changing the Virtual Local Area Network (VLAN) description will cause flush of Media Access Control (MAC) addresses learnt on the interfaces part of the VLAN and traffic impact
PR NumberCategory: lldp sw on MX platform
1811545
Major
When LLDP is configured on interface all and there are AE interfaces configured, to disable LLDP on one of the AE "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, AE is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.
PR NumberCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329
Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberCategory: Ephemeral Database
1839322
Major
On EX-series platforms running Junos Operatin System (OS), configured as a Virtual Chassis (VC) with an ephemeral database (DB) and commit sync enabled, executing the commit-syncd process creates a configuration file that is reused for commits on other VC members. In the problematic scenario, the configuration file is missing during the second iteration, leading to a commit-syncd core without impacting the device.
PR NumberCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1842518
Major
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.
PR NumberCategory: Virtual Router Redundancy Protocol
1822867
Major
On all Junos and Junos Evolved platforms configured with VRRP (Virtual Router Redundancy Protocol) and NSR (Non-Stop Routing), after RE switchover or GRES (Graceful Routing Engine Switchover) the master router would starts sending VRRP advertisements with a different priority value. As a result, both the master and backup VRRP routers will begin operating as the master which results in inconsistent traffic routing or packet loss as the system fails to establish a single master node.
PR NumberCategory: ACX7000 hwd/chassisd software related issues.
1801225
Major
On ACX platforms running Junos OS Evolved, the device gets powered down due to incorrect reading of a temperature sensor, impacting all the services running on the box.

 


 

24.2R1-S2-EVO - List of Known issues

PR NumberCategory: "agentd" software daemon
1817267
Major
GNMI telemetry streaming of Decimal64 data types should stream double_val types instead of float_val types. GNMI has decremented the use of float_val and Decimal64 types in favor of double_val types for floating point data.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:22.4R0-J0-EVO evo:22.4R3-S4-EVO evo:23.2R2-S2-EVO evo:23.4R2-S2-EVO evo:24.2R2-EVO junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.2R2-S2 junos:23.4R2-S2 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.4R1
PR NumberCategory: MX304 Chassis specific platform
1802195
Major


Resolved In: evo:22.3X80-D47-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberCategory: CoS support on DNX
1793256
Major
ACX7509 :: Observing Error messages are populating "getQosRewriteHwMapIdFromIflIndex" and verify interface ifd queue stats traffic is going to wrong queue"

Resolved In: evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO
PR NumberCategory: Manageability for Node Virtualization
1842451
Major
When trying to console into the GNF using a non-root user in Juniper Device Manager JDM users are not able to console

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberCategory: management ethernet related issues - mgmt-ethd daemon
1799681
Critical
On all Junos Evolved platforms with DHCP (Dynamic Host Configuration Protocol) configuration, if a user enable DHCP on the management interface, dhcp-managerd process crashes and creates a core dump while trying to set up the default route. This can affect accessing the router through the management interface. However, it does not disrupt traffic on the WAN ports.

Resolved In: evo:22.3X80-D45-EVO evo:23.2R2-S3-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:24.2R2 junos:24.3R1
PR NumberCategory: AAA, auditd issues
1825303
Major
In all Junos and Junos Evolved platforms, if the full name of the local user's account is configured with a very long character string, then the user is logged out with a "connection closed" message when attempting to authenticate against the local account. No other user will be able to authenticate using the local account database. Issue has been seen with character string with length 1659.Users already logged in when the issue arises are not affected.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:23.4R2-S3 junos:24.2R2 junos:24.4R1
PR NumberCategory: SNMP, mib2d issues
1814315
Major
On all Junos Evolved platforms, the routing instance needs to be specified in the snmpv3 query with -n option for the query to be successfully served.

Resolved In: evo:23.2R2-S2-EVO evo:23.2R2-S3-EVO evo:23.4R2-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberCategory: Integrated Routing & Bridging (IRB) module
1834886
Major
On MX304 platform, IRB (Integrated Routing and Bridging) interface units above 16385 cannot be configured using dot (.) command. The knob 'unit' has to be used for a successful configuration of IRB interface units above 16385.

Resolved In: evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:23.4R2-S3 junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1717843
Critical
JUNOS - FILE COPY - Secure file copy using VRF succeeds even on disabling VRF

Resolved In: junos:21.2R3-S9 junos:21.4R3-S10 junos:22.1R3-S6 junos:22.2R3-S3 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R2 junos:23.4R2 junos:24.1R1
PR NumberCategory: Category for QFX5K EVO Platform Software PRs related to Chas
1757471
Major
A "Major" alarm is generated when the input voltage is low. However, the alarm is not cleared when input voltage comes back within the acceptable range and the ower supplies continue to function without any issue.

Resolved In: evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.4R1 junos:25.1R1
PR NumberCategory: Configuration mgmt, ffp, load-action, commit processing
1818692
Major
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP

Resolved In: evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.2X32-D30 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.4R1
PR NumberCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1821845
Major
On all Junos and Junos OS Evolved platforms when the 'edit system scripts' hierarchy configuration is changed using loading a configuration from a file or the terminal using 'load' option, the scripts refresh will fail.

Resolved In: evo:22.4R0-J0-EVO evo:23.2R2-S2-EVO evo:23.4R2-S1-EVO evo:23.4R2-S2-EVO evo:23.4X31-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:22.4R3-S4 junos:23.2R2-S2 junos:23.4R2-S1 junos:24.2R1-S1 junos:24.3R1 junos:24.4R1
1825728
Critical
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.

Resolved In: evo:21.4X9-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:22.4R3-S4-EVO evo:23.2R2-S2-EVO evo:23.4R2-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S2 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.3R2 junos:24.4R1
PR NumberCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1795952
Major
When traceoptions is enabled for event-options, eventd crash may be observed.

Resolved In: evo:23.2R2-S2-EVO evo:24.2R1-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:23.2R2-S2 junos:24.2R1 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberCategory: Issues related to NETCONF
1800859
Major
On all Junos and Junos OS Evolved platforms, RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.2X32-D30 junos:21.4R3-S9 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:25.1R1
1811327
Major
Union replace operation fails if the configuration being replaced doesn't exist on the device

Resolved In: evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1819656
Major
In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.

Resolved In: evo:21.4R3-S9-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:23.2R2-S2-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.4R1
PR NumberCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box

Resolved In:
1826630
Major
When the YANG(Yet Another Next Generation)-compliant knob is configured, annotations containing non-alphanumeric characters are written as-is, instead of being escaped into their corresponding formats.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:25.1R1

Modification History

First publication 2024-12-17