Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

Platforms running Junos software

Alert Description

Junos Software Service Release version 22.4R3-S6 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 22.4R3-S6 is now available.

22.4R3-S6 - List of Fixed issues 

PR NumberSynopsisCategory: SRX-1RU System Hardware defects
1843413
Major
Split brain condition will be seen in SRX4600 configured in Chassis Cluster under certain conditions
Product-Group=junos
Severity=Major
On SRX4600 platforms configured in Chassis Cluster, split brain condition will be seen under two conditions: 1. A node is isolated from the cluster and is reinstalled with Junos image using a USB and then re-joined into the cluster 2. A standalone SRX4600 is moved into a cluster The split brain condition will lead to potential loss of packets or routing inconsistencies.
PR NumberSynopsisCategory: QFX VC Datapath
1773425
Major
QFX5120, EX4650, EX4400, EX4100 Virtual Chassis (VC) drops Address Resolution Protocol(ARP) packets from remote leaf
Product-Group=junos
Severity=Major
QFX5120, EX4650, EX4400, EX4100 Virtual Chassis (VC) platforms running Junos, drops Address Resolution Protocol(ARP) packets from remote leaf when Virtual Extensible LAN(VxLAN) encapsulated ARP packets are received from ingress port on one of the Flexible PIC concentrator (FPC) and egress port is an Aggregate Ethernet(AE) not having ingress port members on the FPC.
PR NumberSynopsisCategory: ChassisD changes specific for ACX series
1794939
Major
Port goes down after adding interface configuration and changing the port from 1g copper to 10g fiber
Product-Group=junos
Severity=Major
On all Junos platforms, port goes down after unplugging the 1g copper and plugging 10g fiber and adding interface configuration because after unplugging the 1g copper (where autoneg is supported) , the auto-negotiationg structure does not get cleared and is still gets applied after plugging in the 10g fiber (where auto-negotiation is not supported).
PR NumberSynopsisCategory: Interface related area
1809220
Major
40G interfaces on Junos SRX5K cluster will go down after cluster failover
Product-Group=junos
Severity=Major
On Junos SRX5400/5600/5800 platforms in cluster, with 40G interface in layer 2 (L2) transparent mode, when the chassis failovers, the interfaces on node0 will remain in a down state and will not come up. The same issue can also occur when node1 failovers to node0.
PR NumberSynopsisCategory: ACX platforms Timing
1696511
Major
PLL Access Failure logs are seen
Product-Group=junos
Severity=Major
Fixing Multiple threads accesses Zarlink DPLL (digital phase-locked loops) issue.
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1797189
Major
We may observe repd core (in the "from" release) during ISSU. There are no functional impact due to this repd core
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, repd core observed (in the "from" release) during ISSU.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1846448
Major
The S-BFD responder session cannot be distributed to PFE and failing S-BFD session to establish
Product-Group=junos
Severity=Major
On al MX and PTX platforms, If S-BFD(Seamless-Bidirectional Forwarding Detection) responder is configured without the "lo0.0" on device and with any other "lo0.x " then this S-BFD responder session cannot be distributed to PFE(Packet Forwarding Engine) and fails to come up in distributed mode. Hence BFD service will be impacted.
PR NumberSynopsisCategory: Border Gateway Protocol
1817834
Major
The rpd crashes when stale label entry keeps increasing when knob stale-labels-holddown-period is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms configured with the "stale-labels-holddown-period" setting and extensive label configurations (such as Multiprotocol Label Switching labels), the Routing Protocol Daemon (RPD) may crash if stale labels are not cleared periodically and keep accumulating. Due this, temporary traffic impact will be seen until the rpd process restarts.
PR NumberSynopsisCategory: MX304 line card platform software
1849915
Major
FPC reboot due to memory leak from telemetry sensor installation/uninstallation
Product-Group=junos
Severity=Major
On Junos MX204, MX304, MX2010, MX2020, MX10004, MX10008, MX10016 with MPC11, LC2301/LC9600, LMIC16 and LC480 line cards, when installing and uninstalling specific telemetry sensors that export data from LC (Line Card), a few bytes of memory are allocated but not freed, leading to a memory leak. This issue is seen when "sensor-based-stats" is configured and LSP (Link State Path) flaps occur. Each flap triggers repeated installation and uninstallation of the telemetry sensor, accelerating memory consumption. Over time, this exhausts the memory allocated to aft-ulcd process causing FPC (Flexible PIC Concentrator) to reboot.
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1816912
Major
IIC access error during commit operation cause false positive alarms in devices
Product-Group=junos
Severity=Major
On Junos platforms, RE detects IIC read or write failures and triggers a minor alarm " RE1 IIC access alarm" during commit operations
PR NumberSynopsisCategory: Class of Service
1828018
Major
Multiple adjacencies may get dropped over AE interfaces
Product-Group=junos
Severity=Major
An unrelated commit will trigger flap of protocol adjacencies (BFD, LFM, LACP, etc.) over aggregated Ethernet interfaces if scheduler-map is attached to aggregated Ethernet interfaces (this commit shouldn't necessarily be the first, but it may be). The issue is typically seen only once, the subsequent commits do not trigger further flaps, unless child links of the affected aggregated Ethernet interfaces flap.
1836528
Minor
FC id goes out of sync between the RE and PFE impacting all CoS features using FC id
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved Platform, forwarding-class (FC) identifier (id) goes out of sync between the Routing Engine (RE) and Packet Forwarding Engine (PFE) when software upgrade is performed. When In Service Software Upgrade (ISSU) is performed, FC id goes out of sync between the RE and PFE impacting all class-of-service (CoS) features using FC id. When manual software upgrade is performed (without using ISSU) , this issue will be seen as a cosmetic display issue where the order in which the FC configurations are displayed will differ.
PR NumberSynopsisCategory: Platform PR for 1G/10G LC
PR NumberSynopsisCategory: Device Configuration Daemon
1848768
Major
MTU configuration is not applied from the configuration group after commit and "warning" is seen
Product-Group=junos
Severity=Major
When configuring MTU on interfaces through a configuration-group and commit the changes, those are not saved on the configuration file.
PR NumberSynopsisCategory: DNS software support.
1826129
Major
Traffic outages due to memory shortage and core files
Product-Group=junos
Severity=Major
On all Junos SRX and vSRX series platforms Juniper networks Deep Packet Inspection (JDPI) gives events per packet. Domain Name System Firewall (DNSF) plugin is leaking memory while processing those events.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1811734
Major
The LFM session flaps will be observed at random
Product-Group=junos
Severity=Major
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1844623
Major
Stale MAC-IP entries are not cleared in an EVPN-VXLAN scenario when encapsulate-inner-vlan or decapsulate-accept-inner-vlan or both knobs are present
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when decapsulate-accept-inner-vlan or encapsulate-inner-vlan or both knobs are configured for a VXLAN (Virtual Extensible Local Area Network) and when any action corresponding to MAC-IP entries cleanup takes place, the MAC-IP entries will not be cleaned up from kernel. This will result in anomalies in device and could also lead to a core crash.
PR NumberSynopsisCategory: EVPN control plane issues
1806416
Major
The MAC pinning functionality is not working on QFX platforms
Product-Group=junos
Severity=Major
On Junos and Junos Evolved QFX platforms with EVPN-VXLAN (Ethernet Virtual Private Network- Virtual Extensible LAN) configuration, the MAC pinning functionality is not working as expected, causing traffic forwarding issues.
PR NumberSynopsisCategory: EX Chassis Interface Handling
1833698
Major
On Junos EX4100 and EX4400 platforms, switch core dump when user commits a command to ignore a "power entry module" alarm
Product-Group=junos
Severity=Major
On Junos EX4100 and EX4400 platforms, at commit time to configure device to ignore a PEM (Power Entry Module) alarm, switch core dump due to an error on Chassis control process (chassisd).
PR NumberSynopsisCategory: EX4100 PFE
1802455
Major
The default port behaviour is not working as expected after deleting VOIP (Voice over IP) configuration on an access interface
Product-Group=junos
Severity=Major
On EX4400/EX4100 Platforms for VXLAN (Virtual extensible Local Area Network) configuration the interface is expected to accept untagged and member vlan tagged packet on deleting VOIP (Voice over IP) configuration on an access interface. But the access interface is not allowing member vlan tagged packets and only untagged packets are allowed.
1846286
Major
The error message will be seen on EX4100 platforms when deactivating/activating IRB interfaces
Product-Group=junos
Severity=Major
On EX4100 platforms, When deactivating/activating IRB interfaces on vlans with vni enabled, error message will be observed.
PR NumberSynopsisCategory: EX interfaces issues
1788328
Major
Master FPC taking 20 sec time to shut backup FPC's network port after backup FPC reboot in a VC set-up
Product-Group=junos
Severity=Major
On all EX platforms with Virtual Chassis (VC) and Graceful Routing Engine Switchover(GRES) enabled, if during failover the secondary Flexible Physical Interface Card Concentrator (FPC) gets rebooted then there will be traffic loss of 20 seconds more than the expected traffic loss (1to2 seconds).
1793137
Major
Interfaces down with LOCAL-FAULT alarm after power cycle
Product-Group=junosvae
Severity=Major
On EX4100-48T, EX4100-48P, EX4100-48MP, and EX4100-24MP platforms, after a power cycle, the uplink interfaces may go down with a LOCAL-FAULT alarm. This issue is caused by an anomaly in the Broadcom PHY (bcm82756) third-party SDK code used on these devices.
1805370
Major
Interfaces remain down on EX4400-48F platform after replacing a 100MB SFP with 1GB SFP
Product-Group=junos
Severity=Major
On Junos EX4400-48F platform only after replacing a 100 MB SFP endpoint device for a 1 GB SFP the switch port doesn't come up.
PR NumberSynopsisCategory: EX4400 PFE software
1854253
Major
Devices fail to obtain an IP address when DHCP Security Option 82 is enabled
Product-Group=junos
Severity=Major
On Junos EX and QFX platforms when DHCP (Dynamic Host Configuration Protocol) option 82 settings are enabled under dhcp-security, hosts fail to get an IP address from the DHCP server.
PR NumberSynopsisCategory: EX4400 platform
1826615
Major
System call process stuck in SMbus causing LACP timeouts and affecting all control traffic
Product-Group=junos
Severity=Major
On all EX4400 platform, all time sensitive protocols are getting flapped due to process call getting stuck in System Management Bus (SMBus).
1844354
Major
Media Access Control Security (MACsec) does not work properly after a transceiver is removed and re-inserted
Product-Group=junos
Severity=Major
On EX4400 platforms with Media Access Control Security (MACsec) environment configured, if a transceiver is removed and then inserted again, MACsec will not work and a core file will be generated.
PR NumberSynopsisCategory: EX Entry Level Access VC platform
1806262
Major
When VC-mode is set to HGOE and converting port type from vc-port to network port, traffic loss is observed
Product-Group=junos
Severity=Major
On all EX4100 and EX4400 platforms configured in virtual-chassis mode and set to HGOE (HiGig over Ethernet), changing the port type from vc-port to network port causes the network port to stay down and traffic loss is observed.
PR NumberSynopsisCategory: Sflow on qfx10k/ptx series PRs for defect & enhancement req
1841446
Major
SFLOWD process cores after FPC restart event
Product-Group=junos
Severity=Major
Once SFLOW is configured on most interfaces and traffic is getting sampled; in SFLOWD RE daemon, the adaptive sampling feature will start adapting the sampling rate on the interfaces. This is a continuous exercise and there will be interfaces getting adapted based on the traffic getting sampled. When the FPC gets restarted, all the interfaces will get down and come back again. During this the SFLOWD daemon receives the DOWN events followed by UP events for all the interfaces. The pointers related to maintenance of the adaptive list are getting modified in SFLOWD. During the further adaption on interfaces, this results in a SFLOWD core. Due to SFLOWD core, neither the forwarding nor SFLOW feature is getting affected. Based on the analysis, this core is seen only when all the interfaces on which SFLOW is enabled are going down at once.
PR NumberSynopsisCategory: Express PFE FW Features
1855459
Major
On some PTX and QFX platform parity error causes packet drop
Product-Group=junos
Severity=Major
On Junos PTX1000, PTX5000, QFX10000, PTX10002-60C, QFX10002-60C, QFX10008, QFX10016 and PTX10000 platforms packet drops are seen when transient hardware parity error is triggered. This is a rare issue.
PR NumberSynopsisCategory: SRX1500 platform software
1845143
Major
SRX1500 constantly reboots due to linux watchdogd process getting struck
Product-Group=junosvae
Severity=Major
On the Junos SRX1500 platform, the device reboots spontaneously because the watchdog is triggered unnecessarily.
1845407
Major
SRX1500 will not show jnxOperatingTemp and jnxFruTemp temperature reading for PSU temperature
Product-Group=junos
Severity=Major
On SRX1500, "show snmp mib walk jnxOperatingTemp" and "show snmp mib walk jnxFruTemp" will not show up temperature reading for PSU temperature.
PR NumberSynopsisCategory: Interface Information Display
1631200
Major
The packets for IPv6 'Local statistics'(host-inbound/outbound) are counted against the 'IPv6 transit statistics' in IFL.
Product-Group=junos
Severity=Major
IFL counter has a counter named "IPv6 transit statistics". It can be confirmed on "show interfaces extensive" command output. However, this counter is originally for IPv6 total statistics(transit + local) and the counter name was wrong from the first. On older releases like 19.1R1, as the support for IPv6 local stats was not available the local stats was always zero. So, the meaning of the counter name was the same to the counting content coincidentally. In latest releases support for IPv6 local stats has been added but the counter name was not changed. As the local stats will not be zero the difference between the meaning of the counter name and the counting content started being visible.
PR NumberSynopsisCategory: MX Inline Jflow
1813925
Major
FPC reboots after sensor configuration is removed and readded over a long period on MX and EX9200-15C platforms
Product-Group=junos
Severity=Major
On all MX platforms with MPC10/MPC11/LC9600, MX304 and EX9200-15C platforms, when any sensor configuration on protocols, for example, MPLS LSP, is configured and removed over a long period, the aftd-trio process starts a memory leak and eventually causes FPC to reboot.
PR NumberSynopsisCategory: ISIS routing protocol
1841108
Major
Traffic drop is seen after GRES on ISIS peer
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, in an ISIS(Intermediate System-Intermediate System) graceful restart scenario, helper node sends and programs its locally configured hold-time (180 secs) instead of the "Restart-duration" received as hold-time from DUT (210 secs), due to this incorrect update, the hold timer expires at the helper node before the GR (Graceful Restart) is complete on DUT and it causes a flap of ISIS adjacency on peer/helper Node.
PR NumberSynopsisCategory: track re issu control procedure bugs
1740744
Major
ISSU doesn't break if INDB crashes
Product-Group=junos
Severity=Major
On Junos platforms, when ISSU (in-service software upgrade) is initiated, a process called INDB (Incompatible Database) will be triggered to perform a pre-check on database compatibility. There could be some corner case that causes the INDB crash. If that happens, the ISSU should be aborted.
PR NumberSynopsisCategory: jdhcpd daemon
1779273
Major
DHCPv6 Information-request packets will be dropped when it has server identifier option
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms acting as Dynamic Host Control protocol (DHCP) relay agent or DHCP server, DHCPv6 information-request packets are dropped when it has server identifier option. There will be no traffic impact however, the requested configuration parameters by client will not be shared by servers.
1825998
Major
DHCP ALQ process crashes to recover from memory leak.
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms , In a rare scenario when memory leak happens the Dynamic Host Configuration Protocol (DHCP) active-leasequery (ALQ) process crashes automatically.
1833148
Major
DHCP relay option "allow-server-change" does not work as expected in trusted server group when roaming between access points
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms when roaming between Wireless Access Points (WAP) and binding server is down, server failover does not happen in an active-server group even when "allow-server-change" is configured on Dynamic Host Configuration Protocol (DHCP) relay agent.
1839348
Minor
DHCPv6 BLQ not working as expected
Product-Group=junos
Severity=Minor
DHCPv6 BLQ query is not working if queried with server address/server group since relay id information is not passed as part of query.
PR NumberSynopsisCategory: Flow Module
1761542
Major
In a chassis cluster setup the flowd crashes and SPC cards will fail
Product-Group=junos
Severity=Major
On SRX platforms, in a chassis cluster setup configured in Active/Active mode, the fabric forward packet enters the flow module causing the flow processing daemon (flowd) to crash, impacting the traffic forwarding and failing the Services Processing Card (SPC).
1762801
Major
Packet routed to wrong destination on Junos SRX platforms when TCP proxy and reverse-route-packet-mode-vr is configured
Product-Group=junos
Severity=Major
On Junos SRX platforms, when (Transmission Control Protocol TCP) proxy and reverse-route-packet-mode-vr option is enabled, flow daemon (flowd) uses incorrect routing table information for reverse packet route lookup causing the packet to route to wrong destination.
1807505
Major
On SRX5000 series and SRX4600, the setting "apply-to-half-close-state" for TCP sessions is not taking effect.
Product-Group=junos
Severity=Major
On SRX5000 series and SRX4600, the setting "set security flow tcp-session time-wait-state apply-to-half-close-state" is not taking effect for sessions that are using express path (services-offload). This may lead to an increased number of sessions compared to earlier Junos releases which did not have an express path enabled by default.
1828819
Major
AppQoS rate limit in PMI mode on SRX5K and SRX4600 may drop packets unexpectedly
Product-Group=junos
Severity=Major
Application quality of service (AppQoS) rate limit in PowerMode IPsec (PMI) mode on Junos SRX5K and SRX4600 drop packets unexpectedly due to internal issue.
1839910
Major
On SRX5800, SRX4700 and SRX4600 flowd crash is detected during PIM register packet processing
Product-Group=junos
Severity=Major
The SRX5800, SRX4700 and SRX4600 platforms encounters a flowd crash issue when processing PIM (Protocol Independent Multicast) register packets under specific multicast topologies. The issue disrupts data plane traffic temporarily but recovers after a flowd reboot.
PR NumberSynopsisCategory: SRX Firewall Authentication
1829894
Major
Captive portal authentication fails when firewall-authentication is used in conjunction with identity management services (JIMS)
Product-Group=junos
Severity=Major
On all SRX platforms, when a user tries to authenticate to a captive portal to get access to resources, the authentication is successful, but the user is rerouted back to the captive portal with no resources access.
PR NumberSynopsisCategory: Firewall Policy
1844191
Major
FQDN based security policies will not work as expected when DNS server responds with a non-positive error code or refuse responses
Product-Group=junos
Severity=Major
On all SRX platforms, if has one DNS server which was unresponsive and another which refuse responses or responds with a non-positive error code, the FQDN-based security policies will not work as expected and packets might hit a different allow/deny rule.
PR NumberSynopsisCategory: RPM, TWAMP feature related to SRX specific design
1830290
Major
Log messages related to 'gencfg no msg handlers' will be seen on SRX4600 platforms
Product-Group=junos
Severity=Major
On SRX4600 platforms when Real-time Performance Monitoring (RPM) related configuration is committed, 'gencfg no msg handlers for gencfg msg' log messages will be generated. This will not have any functional impact.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1805690
Major
MNHA: Stale IPSEC tunnel in Backup node
Product-Group=junos
Severity=Major
Stale IPSEC tunnel entry can be reported on the backup node's PFE
1817228
Major
IPsec VPN traffic disruption after a change of Authentication protocol is seen on platforms running kmd process
Product-Group=junos
Severity=Major
On all Junos platforms that run kmd process, IPsec VPN tunnels experience traffic disruption after a change of authentication protocol (ESP is change to AH or vice versa).
PR NumberSynopsisCategory: Security platform jweb support
1837925
Major
Junos image upload via J-Web fails on select SRX platforms
Product-Group=junos
Severity=Major
On Junos SRX (SRX1500, SRX4600, SRX4100 and SRX5K's) platforms, image upload via J-Web fails with an error "Access Error: 502 -- Bad Gateway".
1851362
Major
Unable to load J-Web after upgrading SRX when time zone is set to GMT+x or GMT-x.
Product-Group=junos
Severity=Major
Due to GMT+x or GMT-x time zone is not supported, J-Web will fail to load after upgrading SRX.
PR NumberSynopsisCategory: Key Management Daemon
1797377
Major
MX Failed IKE SAs not cleared, Struck in non-matured
Product-Group=junos
Severity=Major
A wrong remote id received from peer results in AUTH failure and this fails the IKE SA setup. This immature IKE SA doesn't go for proper cleanup hence "Not matured" IKE SA piles UP. Restarting the kmd will clear the Not matured SAs.
PR NumberSynopsisCategory: lacp protocol
1773702
Major
MC-LAG will not work as expected on all platforms
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, due to mis-wiring or unexpected design in MC-LAG topology, when all the Multi-Chassis Link Aggregation (MC-LAG) nodes including Customer Edge (CE) devices are rebooted at once, MC-LAG will not work as expected.
PR NumberSynopsisCategory: lldp sw on MX platform
1811545
Major
The LLDP neighborship does not recover on AE interfaces
Product-Group=junos
Severity=Major
When LLDP is configured on interface all and there are AE interfaces configured, to disable LLDP on one of the AE "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, AE is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1758838
Minor
Allow encryption offset with XPN cipher, but may not interoperate
Product-Group=junos
Severity=Minor
Allowing offset configuration even for XPN cipher, for some specific deployment. This may not be interoperable.
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1847378
Major
Some ports take longer than others to come back online when multiple ports experience simultaneous flap
Product-Group=junos
Severity=Major
If interfaces on MPC10E card are configured with hold down timer and the link hit a short flap then it may take additional time for that link to be up. It cause interruption for traffic as well as control plane protocols which are enabled on that link, for example BFD, OSPF, LACP and etc .
PR NumberSynopsisCategory: Track Mt Rainier RE platform software issues
1776854
Major
VM Core with the reason "panic: deadlres_td_sleep_q: possible deadlock detected" might be seen on all JUNOS vmhost platforms
Product-Group=junos
Severity=Major
PR NumberSynopsisCategory: Protocol Independant Multicast
1767314
Major
RPD may restart unexpectedly when MSDP peers were reset or closed
Product-Group=junos
Severity=Major
When an MSDP peer is terminated, the peer's information may not be cleaned up properly. Causing the RPD process to restart unexpectedly.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1789507
Major
Nexthop is not getting uninstalled from FPC and is throwing errors causing traffic drop
Product-Group=junos
Severity=Major
On all Junos QFX5120 and EX4650 platforms the NH(Next-Hops) are not getting uninstalled from the FPC(Flexible PIC Concengrator) L3(Layer 3) Next Hop table. This issue applies to both standalone and VC (Virtual Chassis) setups and can been in MPLS(Multiple Protocol Labeled Switching) setup with Node/Link protection enabled and is triggered by network churn which causes a change in LSP (Labeled Switch Path).
1838623
Major
On all Junos QFX5K & EX4K platforms the next hop for WECMP (Weighted Equal Cost MultiPath) is not programmed in PFE (Packet Forwarding Engine) properly
Product-Group=junos
Severity=Major
On all Junos QFX5K & EX4K platforms, using BGP extended community 'bandwidth' for WECMP (Weighted Equal Cost MultiPath) might results in traffic congestion as the bandwidth % are not adhered to, leading to delays or drops, depending on the network state and handling by the next-hop nodes.
1841913
Major
QFX5210/AS7816 lpm ip route install failed due to table full unit 0
Product-Group=junosvae
Severity=Major
On QFX5210/AS7816 Platforms, when using forwarding-options custom profile , the PFE "show pfe route summary hw" outputs will differ as compared to the actual capacity of the HW for IPV4/IPV6 LPM route installation. As a result, when trying to scale to the max supported limits that are shown in the PFE "show pfe route summary hw" output, will result in route installation errors/table full errors in the PFE.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1840251
Major
The Vxlan ARP packets goes to the ARP queue 34 after disabling ARP suppression
Product-Group=junos
Severity=Major
On Junos QFX5110, QFX5120, QFX5200, QFX5210, EX4100, EX4400 platforms on using the 'no-arp-suppression' hidden CLI knob, the ARP packets from the vtep (Virtual tunnel endpoints) remote side as well as access port side go to Queue 34 (ARP Queue) leading to instability of underlay protocols and causes traffic drop.
1842475
Major
Traffic drops are observed in the EVPN-VxLAN scenario due to VPLAG flaps
Product-Group=junos
Severity=Major
On Junos OS QFX5k and EX4k platforms having EVPN-VxLAN (Ethernet VPN - Virtual Extensible Local Area Network) configured, traffic drops are observed due to missing hardware programming caused by stale hardware entries leading to VTEP (Virtual Tunnel Endpoint) Destination IP-address is not updated properly. The issue is observed due to VPLAG (Virtual Chassis Port Link Aggregation) flaps (any incident, such as a reboot of the gateway device / remote device) causes VPLAG to uninstall and install.
1843817
Major
vlan tagging in Q-in-Q is not handled correctly over EVPN-VxLAN
Product-Group=junos
Severity=Major
On all Junos EX and QFX platforms configured with EVPN-VxLAN (Ethernet VPN - Virtual Extensible Local Area Network), access port to access port traffic on interfaces configured with Q-in-Q is transmitted with incorrect outer vlan tag. This impacts the traffic traversing via the interface.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 linecard, serdes and uboot
1782441
Major
Harmless log messages seen continuously on QFX10k platforms
Product-Group=junos
Severity=Major
"pechip_mac_stream_update_fault|SNMP_TRAP_LINK_DOWN.*et|SNMP_TRAP_LINK_UP.*et" are observed in the output of "show log messages". These log entries indicate that the ports are flapping.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1795339
Major
FPC crash (dcpfe process core-dump) and traffic drop occurred due to "Err Detect Register" and "Data Cache Parity Error"
Product-Group=junosvae
Severity=Major
With some HW memory failure in QFX10008/16 Linecards, the PFE process gets stuck in bad state which takes 2-3min for detection causing traffic drops for that time.
1833154
Major
FPC crashed with "Last Reboot Reason: CPU Watchdog Reset"
Product-Group=junosvae
Severity=Major
On all Junos QFX10008, QFX10016 platforms, the FPC (Flexible PIC Concentrator) crashed with the reboot reason CPU Watchdog Reset due to the system placing the PCI (Peripheral Component Interconnect) bridge port into a low-power state.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 ISSU Infrastructure
1703229
Major
JDI_REG:: QFX5200:: After ISSU upgrade, device is hanged and not able to perform any operations until USB recovery done on device
Product-Group=junos
Severity=Major
When TISSU upgrade is done from 22.4 release onwards, the box come up as backup RE.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1848971
Major
Configuring BGP rib-sharding and generate route will cause rpd process to crash
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring BGP (Border Gateway Protocol) rib-sharding and generate routes will cause the rpd process to crash.
PR NumberSynopsisCategory: RPD policy options
1849500
Major
Static route validation fails when using an interface-route leaked with rib-groups using "to rib " as matching condition under rib-groups import-policy
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, static route validation fails if it is using a leaked interface-route as next hop via a rib-group using "to rib " as matching condition under rib-groups import-policy. That would impact the traffic dependent on such a route.
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1826847
Major
Large number of CGNAT NAT pool out-of-address errors and stale NAT mappings for SIP traffic are observed
Product-Group=junos
Severity=Major
On MX platforms with MS-MPC and CGNAT (Carrier-Grade Network Address Translation) configured, a large number of "out-of-address" errors and stale NAT mappings for SIP (Session Initiation Protocol) traffic can occur. This can lead to a lack of available resources and cause new connections to be dropped.
PR NumberSynopsisCategory: SRX branch platforms
1747849
Major
The CLI command "set system processes watchdog '" results in kernel panic
Product-Group=junos
Severity=Major
On SRX-branch series platforms, configuring the "set system processes watchdog " command causes a commit kernel panic i.e. device will get stuck, and traffic loss will be observed. Watchdog related commands are unsupported.
1827123
Major
Root user does not get logged out from shell
Product-Group=junos
Severity=Major
On the SRX 3xx series the root user does not get logged out from the shell mode even though the session logout time is configured. There is no traffic impact because of this issue, however, this is unexpected behaviour and not seen on other platforms.
1841080
Major
Xe interfaces link down when IP address is assigned
Product-Group=junos
Severity=Major
On SRX380 platforms configured for packet-mode operation and an IP address is assigned to xe (10 Gigabit ethernet) interfaces, the interface link status will go to down state.
1848557
Major
Local or peer device's interface reflects down after SRX380's reboot
Product-Group=junos
Severity=Major
On SRX380 platforms, the local interface status or the peer device's interface reflects down after SRX380's reboot when both devices are configured with auto-negotiation on the SRX380's 4x10GbE ports.
PR NumberSynopsisCategory: MX10002 Platform SW - Platform s/w defects
1809306
Major
On Junos MX204 platform and platforms with MPC7E/8E/9E, JNP10K-LC2101, JNP10003-LC2103, JNP10K-LC480 line cards, the interface goes down when re-initialisation issue occurs, causing 'Avago SERDES' EA (Eagle ASIC) chip crash
Product-Group=junos
Severity=Major
On Junos MX204 platform and platforms with MPC7E/8E/9E, JNP10K-LC2101, JNP10003-LC2103, JNP10K-LC480 line cards, the interface goes down when re-initialisation issue occurs as part of system reboot, FPC(Flexible PIC Concentrators) restart, removal/insertion of optics etc, causing 'Avago SERDES' EA (Eagle ASIC) chip crash.
PR NumberSynopsisCategory: SRX-1RU infrastructure SW defects
1839346
Major
After performing ISSU on SRX4600, the SPM is no longer operational
Product-Group=junos
Severity=Major
On SRX4600 platform with chassis cluster, after performing an ISSU (In-service Software Upgrade) upgrade, the SPM (Secure Port Module) (fpc 0) against the node that is upgraded first will experience issue states where it can either cycle through 'Present' or 'Offline', or it will not report any errors but will be unable to perform any PFE (Packet Forwarding Engine) functions such as session management i.e. wont be able to process traffic resulting in traffic impact.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1823577
Major
On SRX4600, in rare cases with heavy traffic, the FPGA may drop packets.
Product-Group=junosvae
Severity=Major
On SRX4600, in rare cases with heavy traffic, the FPGA may drop packets.
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1793375
Critical
CMErrors are observed on MX platforms running MPC10/MPC11 causing the PFE to be disabled
Product-Group=junos
Severity=Critical
On all MX platforms having MPC10 or MPC11 having class-of-service configured, it is observed that in a scaled scenario (1500 IFLs (Interface Logical)), when queues are oversubscribed and the output interface starts to get congested, "CMERROR 0x230063 " or "XQSS_CMERROR_SCHED_QL4_INT_REG_DQU_QSUM_UDR" error message is seen. These cm errors would result in PFE (Packet Forwarding Engine) disable or the action configured in the device.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1800623
Major
Wedge condition is seen on MX platforms with MPC10/MPC11/JNP10K-LC9600 and MX304 platform switch port utilization is above 80%
Product-Group=junos
Severity=Major
On MX platforms with MPC10/MPC11/JNP10K-LC9600 and MX304 platforms, if the switch port utilization is above 80%, then traffic matches with any firewall filter that is configured with log/syslog firewall action on it, leading to the wedge condition. In that wedge condition, if any commit operation is performed on the firewall filter, it causes the PFE process to crash.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1849854
Major
VPLS flooding is affected in mesh-group when one of the interfaces goes down
Product-Group=junos
Severity=Major
On MX304 and MX platforms with MPC10, MPC11, LC9600 and static Label-Switched Path (LSP) configured for Virtual Private LAN Service (VPLS), flooding does not happen in mesh-group when one of the interfaces goes down.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1841876
Major
Q-in-Q transit traffic will be lost when Tag Protocol ID (TPID) is different than 0x8100
Product-Group=junos
Severity=Major
In different MX series routers references, when Q-in-Q is configured with outer Vlan Tag protocol ID (TPID) different than 0x8100, the traffic is lost and will not find its destination.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1736976
Major
qfx goes into amnesiac after a power outage and commit errors for scripts prevent recovery
Product-Group=junos
Severity=Major
On all Junos platforms, the group file /etc/backup/group and the directory /var/etc/ are becoming corrupt, causing the mgd initialization to fail during system boot. This rare issue occur due to an abrupt power outage occurring while the files were being written.
1842518
Major
The device become unresponsive in a race condition due to maximum process (maxproc) limit
Product-Group=junos
Severity=Major
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1774292
Major
The error messages "eventd: could not bind to address x.x.x.x: Can't assign requested address" is generated on the backup RE and cpu usage of eventd gets 100%.
Product-Group=junos
Severity=Major
The following Error messages are generated on the backup RE and cpu usage of eventd gets 100% when "syslog host" and "syslog source-address" are configured.eventd: could not bind to address x.x.x.x: Can't assign requested addresseventd: Trying bind to default address: Inappropriate ioctl for deviceeventd: bind: Invalid argument.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1760534
Major
VRRP Status displayed incorrectly in CLI command
Product-Group=junos
Severity=Major
On Junos and Junios OS Evolved platforms with dual RE, when GRES and NSR are enabled. VRRP status is wrongly displayed in standby RE when VRRP is configured although it is in the correct state. There is no impact with services. its a display issue.
PR NumberSynopsisCategory: QFX10002 Platform
1792732
Major
Packet corruption on QFX10k and PTX10k in the egress pipeline
Product-Group=junos
Severity=Major
On QFX10002-36Q/QFX10002-72Q/Q/QFX10002-60C/PTX10002-60C platforms the packet corruption is seen on the egress pipeline and can be seen with any type of traffic.
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1841859
Major
Due to high bursty traffic, PIC on MX-SPC3 might go down.
Product-Group=junos
Severity=Major
On all MX Junos devices with SPC3, on receiving bursty traffic PIC may go down and cause network disruption.
1844731
Major
High heap memory caused MX-SPC3 PIC to go offline
Product-Group=junos
Severity=Major
On Junos platforms, specifically MX240, MX480 and MX960 supporting MX-SPC3 service cards, if inline-jflow is configured with huge scaled routes (~4M routes) resulting in kernel memory exhaustion that is high Heap Memory and SPC3 Pic goes offline.
PR NumberSynopsisCategory: usf nat related issues
1841231
Major
PCP mapping fails for specific internal IPv4 addresses in DS-lite scenario
Product-Group=junos
Severity=Major
On MX240, MX480 and MX960 with Unified-Services Framework (USF) and Dual-stack lite (DS-lite) enabled, Port Control Protocol (PCP) mapping fails for any internal IPv4 with fourth octet greater than ".223".

 


 

22.4R3-S6 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 PFE
1833502
Major
EX2300 ECMP : Traffic failure due to ECMP programming failure on PFE
Product-Group=junos
On EX2300 series switch which is working with ECMP function, you may observe traffic failure due to ECMP programming error.

Resolved In:
PR NumberSynopsisCategory: MX YT-ZF Linecards Timing software
1715831
Major
MX reports continuous PLL Access Failures for LC9600
Product-Group=junos
For platforms which are designed with Junos and EVO there could be the repetition of PLL Access Failure logs which are cleared after 5 seconds

Resolved In: evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.4R2-S2 junos:22.4R3 junos:22.4R3-J4 junos:22.4R3-S2 junos:23.2R1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1635143
Major
The rpd may crash due to memory pressure for high BGP scale with flapping route and BGP Monitoring Protocol (BMP) collector/station is very slow on all Junos and EVO platforms
Product-Group=junos
On all devices running Junos OS or Junos OS Evolved, where this is a high BGP scale with flapping route and the BGP Monitoring Protocol (BMP) collector/station is very slow, the rpd process might crash due to memory pressure.

Resolved In: junos:20.3X75-D45
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1784438
Major
MX304 not reachable with the power-off failure on the PIC
Product-Group=junos
When an MX304 LMIC is offline due to a power issue, it may take up to 20 minutes for the LMIC to come back online. You can configure event-options to reduce the time to restart the LMIC. See also: TSB83899 [juniper.net]

Resolved In: evo:23.2R2-S2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:22.2R3-S5 junos:22.4R3-S4 junos:23.2R2-J15 junos:23.2R2-S2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Enhanced Broadband Edge support for cos
1782016
Major
Subscribers login and logout leads to FPC crash on Junos MX platforms with MPC10E/ MPC11E linecards
Product-Group=junos
On Junos MX with MPC10/11 and MX304 chip based platforms, when configured with 16k subscribers ( PPPoE { Point-to-Point Protocol} or DHCP { Dynamic Host Configuration Protocol } ) and COS ( Class of Service) settings, a crash in the Flexible PIC Concentrators (FPC) occurs during subscriber login and logout. Due to the crash the affected subscriber connection will be disconnected and re-establishing is not possible.

Resolved In: evo:23.2R2-EVO evo:23.2R2-S3-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:23.2R2 junos:23.2R2-S3 junos:23.4R2
PR NumberSynopsisCategory: EX interfaces issues
1580560
Major
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.
Product-Group=junos
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.

Resolved In:
1831409
Major
On an EX4400 device with 4x25G Uplink module configured in 1GE or 25G speed, peer side of an interface with 10GBASE-T transceiver may remain up even when the IFD(xe-x/2/y) is not created
Product-Group=junos
On an EX4400 device with 4x25G Uplink module configured in 1GE or 25G speed, peer side of an interface with 10GBASE-T transceiver may remain up even when the IFD(xe-x/2/y) is not created. For this to happen, a speed mismatched configuration is needed, where a 1G speed or a 25G speed is configured on the PIC 2.

Resolved In: junos:24.2R2
PR NumberSynopsisCategory: MX Inline Jflow
1742752
Major
Flow data is no longer learned and sampling data is no longer sent when inline jflow sampling is configured.
Product-Group=junos
On MX304 and MX platform with MPC11 line cards and inline jflow sampling configured, the Inline Jflow stops learning new flows as flows created on odd slices are not cleared when they time out, hence the values become large enough and no new flows will be learned.

Resolved In: evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1762490
Minor
JDI-RCT-MPC10E: Ksyncd crash on backup RE after fpc reboot
Product-Group=junos
On MX series, when PS over RLT is configured where all member LTs are hosted on the same FPC and user restarts this FPC then on rare occasion, ksyncd crash can occur on backup RE. However, there is no impact on the master and only backup RE is affected. This issue is not consistent and seen only once out of ~10 or 15 fpc restart operations.

Resolved In: evo:25.2R1-EVO
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1827648
Major
ARP not learned on Switch Leading to Traffic Drop in EVPN-VXLAN Setup
Product-Group=junos
On all Junos QFX series platforms in an EVPN (Ethernet Virtual Private Network) VXLAN (Virtual Extensible Local Area Network) setup with CRB (Centralized Routing Bridge) architecture, ARP packets are not being learned, leading to traffic forwarding issues. This problem arises when ARP packets are sent from the firewall to the spine switches. The issue is linked to IRB (Integrated Routing and Bridging) handling and bridge domain re-incarnation, which triggers ARP request failures and impacts L3 forwarding.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: jdhcpd daemon
1808289
Major
Switch provisioned via ZTP going unreachable due to DHCP misbehaviour on upgrading to 21.4R3-S6
Product-Group=junos
All IRB (Integrated Bridging and Routing) interfaces of EX3400-48P switches which pull initial configuration from Dynamic Host Configuration Protocol (DHCP) server via zero touch provisioning (ZTP) process, upon upgrade to 21.4R3-S6 do not send DHCPdiscover packet to obtain a new IP address after sending DHCPrelease packet resulting in interface not able to obtain IP address until rebooted.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1722689
Major
IKED cores are generated in node1, while doing ISSU upgrade from any release before Junos 22.4R1 to Junos 22.4R1 or later.
Product-Group=junos
On all SRX platforms in chassis cluster which support ISSU, when the JUNOS IKE package is present and IPSec VPN is configured, ISSU is not supported from any release before 22.4R1 to 22.4R1 or later. You can use CLI command 'show version' to confirm if JUNOS IKE package is present on your device.

Resolved In:
1824880
Major
IPsec VPN tunnel on TVP platforms will be brought down when AES_GCM algorithm is used along with Extended sequence number (ESN)
Product-Group=junosvae
On IPSec tunnels when the AES_GCM algorithm is used in combination with Extended sequence number (ESN) on TVP (ToR velocity program) platforms, the VPN monitor will bring down the IPSec tunnel.

Resolved In: junos:24.4R1-S2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Layer 2 Control Module
1855088
Major
In EX4100 platform, when configuring an Inter-switch-link (ISL) trunk, the commit check command fails
Product-Group=junos
In EX4100 platform, when adding configuration for an ISL trunk, the commit check command fails, causing the L2CPD process to crash. This prevents the new configuration from being applied, but it doesnt impact the devices traffic, performance, or management.

Resolved In: evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1829765
Major
uKern DDOS Aggregate stats not updated for BFD packets at system wide and FPC level
Product-Group=junos
BFD Aggregate policer in 22.4R3S5 polices BFD Single-Hop packets. Hence the BFD Aggregate statistics may not reflect accurate statistics for other BFD packets like Multihop and Bundle. This will be fixed in upcoming release.

Resolved In:
1830188
Major
Counters not getting cleared at the PFE level when clear ddos-protection protocol statistics is executed
Product-Group=junos
On all Junos PTX platforms, Distributed Denial of Service(DDos) clear statistics will not work on 22.4R3-S5 however there will be no impact on its functionality.

Resolved In:
PR NumberSynopsisCategory: Express Chip L3 software
1826626
Major
Unpoliced sampling traffic causes host congestion and forwarding failure
Product-Group=junos
On Junos PTX and QFX platforms, unpoliced sampling traffic can cause host path congestion, leading to a failure in forwarding operations. This issue occurs when specific conditions, such as higher rates of sampling classes or smaller packet sizes, are met.

Resolved In: junos:21.4R3-S10 junos:22.4R3-S5
PR NumberSynopsisCategory: PTX10K Routing Engine
1770585
Major
Junos vmhost upgrade will continue to reboot the box even if the upgrade has failed due to tar errors when the reboot option is used
Product-Group=junos
Issue identified when upgrading vmhost, but applies to all Junos platforms that support vmhost. When there are tar errors during the upgrade, and the reboot option is used in the upgrade command, the machine will still reboot the RE despite that the upgrade was not completed correctly. This will break the routing engine. It is necessary to stop the reboot, if error or tar problems occurred during the upgrade.

Resolved In: junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: QFX L2 PFE
1820830
Major
Complete packet loss will be observed for the inter-VLAN traffic in EVPN-VXLAN CRB scenario
Product-Group=junosvae
On Junos QFX and EX platforms in an EVPN-VXLAN (Extended Virtual Private Network- Virtual Extensible LAN) CRB (Centrally-Routed Bridging) scenario where the ingress leaf switch is configured with ESI (Ethernet Segment Identifier) lags (i.e. the server is multihomed), if there is an overlap between ESI lag(s) trunk ID with physical port number(s) and overlap of DMAC (destination MAC) between VGA (Virtual Gateway Address) MAC address 00:00:5e:00:01:01 (CRB setup with VGA / GW is on spine) with VRRP (Virtual Router Redundancy Protocol) MAC (specifically for the VRRP group 1 MAC address 00:00:5e:00:01:01) on the physical ports of the Leaf switches, then traffic loss will be observed for the inter-VLAN traffic.

Resolved In: junos:23.4R2-S4 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: SRX Argon module
1827283
Major
PFE core can be seen on SRX platforms during ISSU
Product-Group=junos
On Junos SRX4k/5k series platforms in a chassis cluster environment, the srxpfe (Packet Forwarding Engine) process crashes during ISSU ( In service Software Upgrade). It happens after failover to the upgraded node and before the secondary node is all the way up to join the cluster. This process crash will cause traffic impact, however the system self-recovers.

Resolved In: junos:21.4R3-S7-J6 junos:21.4R3-S7-J7 junos:21.4R3-S9 junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: SRX branch platforms
1836235
Major
SRX default named.conf file is created with non dns-proxy related configuration changes
Product-Group=junos
On SRX platforms with dns-proxy configured, default named.conf file is created with non dns-proxy related configuration changes. This leads to halting of dns-proxy operation.

Resolved In: junos:21.4R3-S10 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1803105
Major
PTP attribute changes on upstream device causes best clock master slot switchover
Product-Group=junos
On all MX platforms(except MX80) with multi line card chassis, when PTP slave or stateful streams are configured across multiple linecards with clock from same PTP time provider and the announce msg parameters changes from the upstream device, the best master clock (BMC) slot switchover is observed and is restored back within few seconds. Although the slot time interval is very less, it can still lead to major impact as the active PTP slot and clock path is switched over and results in re-routing of the clocks.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1823577
Major
On SRX4600, in rare cases with heavy traffic, the FPGA may drop packets.
Product-Group=junos
On SRX4600, in rare cases with heavy traffic, the FPGA may drop packets.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1856393
Major
Aftd-trio core dump seen while removing subscribers (vbf) on an AFT based line card may result in a crash
Product-Group=junos
Aft-trio crash will be seen in some scenario when subscriber interface on aft based line card is removed and at the same time those subscribers interfaces stats are collected

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1837840
Major
Incorrect color-aware srTCM marking with yellow packet loss priority
Product-Group=junos
There was a software side limitation on the highest CBS that can be configured for MPCs that have LU type lookup chips due to a hardware PR. The Hardware PR was resolved in MX240/ MX480/ MX960/ MX2008/ MX2010/ MX2020/ MX10003/ MX10008/MX10016/EX9200/EX9204/EX9208/EX9214/EX9251/EX9253/SRX5400/SRX5600/SRX5800 platforms, but the software-side limitation was not removed for the same. Due to this limitation, whenever the CBS was configured above its limit (earlier 33m), the low-level parameters used to get configured such that the packets would not have any credits available, resulting in them getting marked as RED.

Resolved In: junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1740289
Major
The 'load replace' operation might result in mustd and mgd crash
Product-Group=junos
On Junos and Junos Evolved platforms with 'apply-group' configured, the mustd and mgd processes might crash when the 'load replace' operation is performed. When this happens, 'apply-groups' will get deleted internally and the respective hierarchies will not be notified.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-S4-J5-EVO evo:21.4R3-S5-EVO evo:21.4X1-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.3X80-D40-EVO evo:22.3X80-D43-EVO evo:22.4R3-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S7 junos:21.2X32-D20 junos:21.2X32-D30 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.2R1-S1 junos:23.2R1-S2 junos:23.2R2 junos:23.3R1 junos:23.4R1
1825728
Minor
The mgd process crashes while using an FQDN in conjunction with the ephemeral configuration database
Product-Group=junos
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.

Resolved In: evo:21.4X9-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:22.4R3-S4-EVO evo:23.2R2-S2-EVO evo:23.4R2-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S2 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.3R2 junos:24.4R1
PR NumberSynopsisCategory: QFX10002 Platform
1442249
Critical
JDI-PDT: Ping fails over interface in PTX-10002-60C , collateral damage in 18.2R2-S4.3 , Failed to get socket(-1) for index
Product-Group=junos
This is a timing issue during the sxe interface bring up (w.r.t i40e driver). This can be recovered by rebooting the complete board.

Resolved In: