Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/Notificationsoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

This is a list of KNOWN ISSUES for 22.2R3-S5. See TSB90519 [juniper.net] for the list of FIXED issue for 22.2R3-S5

Junos Software Service Release version 22.2R3-S5 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

22.2R3-S5 - List of Known issues 

PR NumberSynopsisCategory: EX4300 PFE
1794342High CPU after software upgrade of EX4300 from 21.2R3-S4.8 to 21.4R3-S5.4
Product-Group=junos
It is noticed that EX4300 switches after an upgrade of Junos from 21.2R3-SX to 21.4R3-SX may exhibit a higher Cpu. Issue is resulting from fast path thread profiling code. It takes on an average 1 ms more for one fast path thread cycle, cumulatively overall fast path thread usage had increased. Thread profiling code has been optimised and the issue is fixed in the future JUNOS.

Resolved In: junos:21.4R3-S9
PR NumberSynopsisCategory: QFX VC/VCF NSSU
1706892Traffic loss upon switchover during NSSU when unreachable name-server is configured
Product-Group=junos
When NSSU is attempted and an unreachable name-server is configured on the device traffic loss will be observed upon switchover. Back-up FPC takes mastership while previous Master FPC is undergoing reboot and traffic drops are seen due to PIC on new Master FPC going offline.

Resolved In: junos:21.4R3-S7 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R2 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: access node control protocol daemon
1814300L2BSA sessions remain down when port messages from ANCP neighbor are dropped in a scaled scenario after ISSU followed by GRES
Product-Group=junos
On all Junos MX platforms with dual RE (Routing Engine), having ANCP (Access Node Control Protocol ) and L2BSA (Layer 2 Bitstream Access) sessions under a scaled scenario (about 10k subscribers), when ISSU (Unified In-Service Software Upgrade) is performed followed by a GRES (Graceful Routing Engine Switchover), it is observed that the port-up messages from ANCP neighbor are dropped either at PFE (Packet Forwarding Engine) or by the ANCP daemon or BBE (Broadband Edge)/autoconf plugin which causes L2BSA sessions to remain down and as a result traffic over the affected subscriber sessions are dropped.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:23.2R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: BBE Autoconfigured DVLAN related issues
1777139FPC gets stuck at 100% utilization after upgrade from 21.2R1 or below to 21.3R1 or higher release
Product-Group=junos
On Junos MX platforms with PPPoE (point-to-point protocol over ethernet) subscribers over dynamic VLAN (virtual local area network) scenario, FPC (flexible physical interface cards concentrator) gets stuck at 100% after upgrade from 21.2R1 or below to 21.3R1 or higher release. The line card PFE (packet forwarding engine) is busy because of huge punt traffic which is process-switched by the CPU.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:23.4R2-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Border Gateway Protocol
1818545BGP-LU Label is incorrect after convergence
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.

Resolved In: evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:22.4R3-J1 junos:22.4R3-S4 junos:23.2R2-S3 junos:23.4R2-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1826686Traffic impact due to BGP route stuck in hidden state
Product-Group=junos
On all Junos and Junos Evolved platforms, with BMP (BGP Monitoring Protocol) 'exclude-non-eligible' configured, the BGP route gets stuck in a hidden state with the next hop state as 'Next hop type unusable' leading to traffic drop.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S9 junos:22.4R3-S5 junos:23.2R2-S3 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: MX304 Chassis specific platform 
1760982The spmbpfe crash is observed in back up RE during the system reboot
Product-Group=junos
On MX304 platforms, with multiple feature configurations when the system is rebooted the spmbfe crash will be seen in the backup RE.

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO junos:22.3R3-S3 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1811734The LFM session flaps will be observed at random
Product-Group=junos
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.

Resolved In: junos:19.3R3-S11 junos:21.2R3-S9 junos:21.4R3-S9 junos:23.2R2-S3 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1806660Error messages are observed after performing a VLAN name change with EVPN configuration
Product-Group=junos


Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: EX POE
1814715When PDs(power devices) are connected to all the PoE (power over ethernet) ports with LLDP enabled, the last port is not powered up
Product-Group=junos
On EX2300P and EX3400 platforms, when PDs are connected to all the PoE ports with LLDP enabled, the last port is not powered up.

Resolved In: junos:21.4R3-S9 junos:22.4R3-S3 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1793772L3 multicast traffic gets dropped when a BD is configured with IRB as the source interface
Product-Group=junos
On QFX10002-60C, when Bridge Domain (BD) is configured with Integrated Routing and Bridging (IRB) interfaces acting as ingress for Layer 3 multicast traffic and BD is not a part of Virtual Extensible Local Area Network (VXLAN), then Layer 3 multicast traffic is dropped.

Resolved In: junos:23.4R2 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: IDP SSL related bugs
1828462Non Reachable DNS IP, followed by Reachable DNS IP are configured, Outbound SSH intact but Antivirus functionality NOT working as expected
Product-Group=junos
Use valid name-server in system name-server list. First 3 name-servers should be valid.

Resolved In:
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1815250ARP resolution issues might happen when VxLAN and non-VxLAN are both configured on the same ifd but different ifl
Product-Group=junos
Due to a conflict in the config between the VXLAN (Virtual Extensible LAN) hardware token and the VLAN (Virtual Local Area Network) traffic loss could happen as consequence of wrong path for ARP (Address Resolution Protocol)

Resolved In: junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: ISIS routing protocol
1830989ISIS adjacency part of an igp-instance gets stuck in 'Initializing' state after the rpd restart
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if graceful restart (GR) is not disabled for ISIS (Intermediate System to Intermediate System) multi-instance (MI), ISIS adjacency part of the igp-instance could get stuck in 'Initializing' state after rpd/protocol restart.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:23.4R2-S3 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1781379The SIP UDP register packet will be dropped on MX and SRX platforms
Product-Group=junos
On all MX and SRX platforms, SIP (Session Initiation Protocol) UDP (User Datagram protocol) register packet will be dropped by ALG (Application Layer Gateway) when the USER-AGENT is filed with some unknown language

Resolved In: junos:21.2R3-S8 junos:21.4R3-S7 junos:21.4R3-S8 junos:23.2R2 junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: Firewall Policy
1821890On Junos SRX Series platforms traffic will be dropped when AppID DB is not installed
Product-Group=junos
On Junos SRX Series devices, when Application Identification Database (AppID DB) is not installed but dynamic-application any is matched in security policy, all traffic will be dropped due to default deny policy. When AppID is not installed on the system, the CLI still allows to configure dynamic-application match condition with "any" and "none". Ideally, when AppID is not installed on the system, "none" and "any" should work same.

Resolved In: junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Security platform jweb support
1810991Display issue is observed when range option is used to configure destination/source port range in custom application
Product-Group=junos
On Junos SRX platform, J-web shows error message "The maximum length for this field is 9", when range option is used to configure destination/source port range in custom application and if the value is more than 10 characters.

Resolved In: junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Layer 2 VPN related issues
1807853ISIS packets over 1500 bytes sent to L2VPN over MPLS are not being processed
Product-Group=junos
On SRX-branch series platforms, due to incorrect mbuf (Memory Buffer) allocation, the ISIS (Intermediate System-to-Intermediate System) packets transiting over L2VPN (Layer 2 Virtual Private Network) over MPLS (Multiprotocol Label Switching) are dropped if is more than 1500 bytes. The issue happens when jumbo frames is enabled or the MTU is configured above 1514.

Resolved In: junos:22.4R3-S5 junos:23.2R2-S2 junos:23.4R2-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1776782Host device cannot resolve target IP's ARP when client uses virtual mac address
Product-Group=junos
On Junos or Junos OS Evolved platforms which supports EVPN-MPLS/EVPN-VXLAN, device will not reply for ARP (Address Resolution Protocol) requests when source MAC (Media Access Control) of ethernet header and ARP source MAC are different and ARP target address are exists in mac-ip-table. Traffic drop will be seen.

Resolved In: evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:22.4R3-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Label Distribution Protocol
1772904The rpd process crashes when LDP telemetry streaming xpath is enabled
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, the rpd process crash when LDP telemetry for xpath "/network-instances/network-instance/mpls/signaling-protocols/ldp/neighbors/neighbor/hello-adjacencies/hello-adjacency/hello-holdtime/state/hello-expiration" is enabled.

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO junos:23.2R2-S2 junos:23.4R2 junos:24.1R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1812046On MX2K, offline manually SFB2 or SFB3 or Plane to recover from a fabric link training failure, fabric mananger is not able to turn off the fabric links on a neighbor slot FPC
Product-Group=junos
Once SFB2 or SFB3 or plane is manually offline in an attempt to recover from a Fabric Training Failure of one FPC, the neighbor slot FPC is not be able to stop the high speed link and is ending up with training failure as well.

Resolved In: junos:21.2R3-S9 junos:22.2R3-S3-J3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: MX Timing software
1799397The "show chassis synchronization clock-module | display xml validate" get "INVALID" output
Product-Group=junos
On Junos platforms, the "show chassis synchronization clock-module | display xml validate" get "INVALID" output.

Resolved In: evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1740873ARP resolution will not work properly if the L3 interfaces are configured with native vlan-id
Product-Group=junos
On MX platforms with MPC10/MPC11/LC9600 linecards and MX304, in problematic scenario if a device interface is configured with native vlan the packet goes out tagged and peer device receives tagged packet. If the peer device is not configured to expect tagged packets (either due to different native VLAN configuration or no VLAN configuration), the peer will drop the packet. Due to this, ARP (Address Resolution Protocol) resolution would fail which leads to traffic drop. Ideally if the L3 interfaces are configured with native-vlan id, the packets should go out untagged.

Resolved In: evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:22.1R3-S6 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R2-S2 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: Kernel Composite Next Hop (composite / l3vpn) Infrastructure
1780215The l2ald/rpd processes will be stuck in an infinite loop and stop responding to CLI and calls
Product-Group=junos
On all Junos platforms configured with MPLS(Multiprotocol label switching) / VPLS(Virtual Private LAN Services), the l2ald (Layer 2 Address Learning Daemon) / rpd (Routing Protocol Daemon) will get stuck in an infinite loop and stop responding to CLI (command-line interface) and system function calls when kernel returns negative values to daemons causing the CPU usage spikes excessively which leads to loss of CLI access and partial traffic drop.

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO junos:21.2R3-S8 junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3 junos:22.4R3-S1 junos:23.2R2 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1676154The rpd crash can be seen in MoFRR scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd ( routing protocol daemon) can crash when PIM (Protocol Independent Multicast), MoFRR (Multicast only Fast Reroute) configuration is present and some network churn event such as continuous interface cost changes, resulting in a change of active and backup paths for ECMP (Equal Cost Multi-Path) happens. There will be service impact because of the rpd crash but the system self-recovers until the next crash.

Resolved In: junos:20.2R3-S4-J10 junos:20.3R3-S6 junos:21.2R3-S3 junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:23.4R1-S2 junos:23.4R2 junos:24.1R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.3R2
1795964The rpd process crash is seen when routing-instances name length is greater than 60 characters
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Protocol Independent Multicast (PIM) enabled under Routing-instance, the Routing Protocol Daemon (rpd) process crash is seen when the routing instance (RI) name length is greater than 60 characters. Due to the rpd process crash, protocols will be impacted and traffic loss will be seen.

Resolved In: evo:22.3R3-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: QFX L2 PFE
1838439Discontinuous VLAN-ID-LIST in a Q-in-Q not working as expected
Product-Group=junos
Support of multiple discontinuous vlan-id-list in QFX5120/EX4K TD3 chipset in vxlan

Resolved In:
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1771445Untagged traffic gets dropped when 'native-vlan-id' and 'vlan-id-list' are configured together under same interface
Product-Group=junos
On Junos QFX5110 platforms, and while having configured 'native-vlan-id' and 'vlan-id-list' combined under an interface , untagged traffic gets dropped

Resolved In: junos:23.2R2-S3 junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1742565Ports with SFP-T 1G plugged in may go to hung state on QFX5100 (non-tvp-image) platforms
Product-Group=junos
When the remote end server/system reboots, QFX5100 platform ports with SFP-T 1G inserted may go into a hung state and remain in that state even after the reboot is complete. This may affect traffic after the remote end system comes online and resumes traffic transmission.

Resolved In: junos:20.4R3-S10 junos:21.4R3-S5 junos:21.4R3-S6 junos:21.4R3-S9
PR NumberSynopsisCategory: KRT Queue issues within RPD
1834859The RPD crashes after executing "show krt error-statistics errorno X"
Product-Group=junos
Please do not issue the "show krt error-statistics errorno ..." stanza. This command causes RPD to restart unexpectedly.

Resolved In:
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1810866The rpd crash is observed due to the segmentation fault on Junos OS Evolved platforms
Product-Group=junos
On Junos OS Evolved platforms, the rpd (Routing Process Daemon) crash i.e. traffic impact is observed due to a segmentation fault. The issue happens when the rpd sends an add request for the same next-hop ID for multiple routes/unicast next-hops with the same prefix and points to a discard interface. The rpd doesn't expect the same next-hop ID for multiple routes/unicast next-hops.

Resolved In: evo:23.2R2-S2-J1-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:23.2R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: SRX Argon module
1828721Flowd crash seen on SRX platforms with security metadata streaming knob configured
Product-Group=junos
On all SRX platforms, when security metadata streaming knob is configured, the flowd process crashes, impacting traffic and service.

Resolved In: junos:21.2R3-S9 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: SRX RTCOM module bugs
1814271The srpfe crash during SAV longevity testing
Product-Group=junos
On SRX platforms, when Sophos antivirus (SAV) was enabled srpfe crash was observed. If a new packet tries to access the memory before it gets free, it may lead to the race condition, where it tries to fetch a null memory. The issue is hardly reproducible.

Resolved In: junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: SRX branch platforms
1768050ARP resolution does not work if generated from the L3 Interface such as the IRB interface
Product-Group=junos
On SRX300 series platforms, ARP (Address Resolution Protocol) resolution does not work if it is generated internally from the L3 (Layer 3) interface such as the IRB (Integrated Routing and Bridging) interface. The routing protocol connections will not get established resulting in traffic impact.

Resolved In: junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
1777464Junos OS: Multiple vulnerabilities in OSS component nginx resolved (CVE-2023-44487)
Product-Group=junos
Multiple vulnerabilities have been resolved in nginx software included with Juniper Networks Junos OS by upgrading nginx to version 1.22.1 or by applying specific fixes. Please refer to https://supportportal.juniper.net/JSA88135 [juniper.net] for more information.

Resolved In: junos:23.2R2-S2 junos:23.4R2-S1 junos:24.1R1 junos:24.2R1
1811858Monitored-Status keeps Up after CTL link down in branch model SRX HA
Product-Group=junos
After CTL link down, Monitored-Status in "show chassis cluster interfaces" keeps showing "Up" state.

Resolved In: junos:22.4R3-S5 junos:23.2R2-S2 junos:23.4R2-S3 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
1821368DAC interface does not send fault signal to a peer device when the DAC interface is admin disabled
Product-Group=junos
On SRX380 platform, when a DAC interface is admin disabled, the DAC interface does not send a fault signal to a peer device and on peer device it will reflect as up.

Resolved In: junos:23.4R2-S3 junos:24.2R1-S2 junos:24.2R2 junos:24.3R2 junos:24.4R1
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1827439A BFD flap and subsequent impact in the traffic is seen when BGP FlowSpec session goes down or withdrawal of all BGP FlowSpec routes making entries on netflow.0 table to zero at once
Product-Group=junos
On MX platforms with ukern based line cards (till MPC9), when the BGP FlowSpec session goes down or withdrawal of all BGP FlowSpec routes making entries on netflow.0 table to zero at once, a BFD (Bidirectional Forwarding Detection) flap occurs with the subsequent impact in the traffic.

Resolved In: evo:25.1R1-EVO junos:21.2R3-S9 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: usf nat related issues
1802242Interim logs for deterministic NAT are not generated as per the modified time interval
Product-Group=junos
On all MX platforms, the configuration change done to interim logging interval for deterministic Network Address Translation (NAT) does not come into effect. Even after modifying the interval value from T1 to T2, logs still get generated at the interval T1.

Resolved In: junos:21.2R3-S9 junos:23.2R2-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1

Modification History

First publication 2025-01-21 (published retrospectively)