Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX platforms running Junos Evolved software

Alert Description

Junos Software Service Release version 23.2R2-S3-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 23.2R2-S3-EVO is now available.

23.2R2-S3-EVO - List of Fixed issues 

PR NumberSynopsisCategory: PTX10003 Hardware Generic
1797283
Major
On Junos evolved PTX1003-160C and PTX10003-80C platforms FPC instability lead to CPU reset and service interruption
Product-Group=evo
Severity=Major
Issue is seen when system is rebooted, while coming up during initialization of Peripheral Component Interconnect Express (PCIe) link of Quad Band Advanced Modem Field-Programmable Gate Array (QBAM FPGA). In a rare condition when the FPGA PCIe link could not lock properly, it intermittently did not respond to PCIe requests from the CPU.
PR NumberSynopsisCategory: MX/PTX 20A AC power Software Issues
1758201
Critical
On PTX10K platforms, certain conditions may cause Fans to be reported as failed after system reboot or when the Fan Tray is removed and reinserted
Product-Group=evo
Severity=Critical
The Fans may be reported as failed due to the rapid switching of Fan Tray hot-swaps settings. This is not a hardware failure, but rather a transient condition caused by the immediate toggling of hot-swaps.
PR NumberSynopsisCategory: "agentd" software daemon
1820510
Major
The JTI/UDP export format prompts "gpb-sdm" as a possible completion on executing "set services analytics export-profile format gpb-?" command
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms having JTI (Junos Telemetry Interface)/UDP (User Datagram Protocol) based telemetry, unsupported configuration i.e. "gpb-sdm" is showing a possible completion when the command "set services analytics export-profile format gpb-?" is executed.
1826196
Major
The error messages will be observed while configuring native sensor paths
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms with telemetry enabled, configuring any native sensor path like "set services analytics sensor interface_stats resource /junos/system/linecard/optics " will not be enabled unless "/" is added at the end. This will not have any traffic impact.
1831841
Major
Telemetry streaming will not happen because the resource path is not valid
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms with analytics sensor resource configured, when the CLI telemetry configure command is accepting the resource path even if there is no leading / which is not a valid path results in telemetry streaming is not happening.
PR NumberSynopsisCategory: PTX10001 diagnostics software related issues.
1822938
Major
PTX10001-36MR-K Major Alarm Host 0 Ethernet Interface Link Down
Product-Group=evo
Severity=Major
On the PTX10001-36MR-K routers, sometimes on a reboot the "Link Mon" app starts before the eth1 links come UP. This results in the major alarm "Host 0 Ethernet Interface Link Down" being raised. The alarm does not clear on its own although the Eth1 link does come up and there is no issue with management port connectivity.
PR NumberSynopsisCategory: EVO platform software
1799275
Major
PTX10001-36MR enters booting loop when a system reboot or software upgrade initiated reboot is performed
Product-Group=evo
Severity=Major
PTX10001-36MR enters booting loop when the system reboots as part of system reboot or software upgrade procedure. A rare timing issue prevents the initialisation of internal component causing the issue.
PR NumberSynopsisCategory: EVO RCB software
1799443
Major
USB Media installation shows up minor alarm "Host 0 Voltage Threshold Crossed"
Product-Group=evo
Severity=Major
On Junos Evolved PTX10001-36MR platform, upon software installation with USB Media, the system might report a minor Alarm "Host 0 Voltage Threshold Crossed ". The root cause is a missing symbolic link for the voltage sensor configuration. During the installation reboot process, the assembly_id readout did not return a value. This is only applicable during media USB installation and not during regular system reboots. There is no operational impact.
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1820001
Critical
Multiple processes on both the REs are crashing
Product-Group=evo
Severity=Critical
On Junos MX platforms, when a Stats DB corrupt entry in encountered, several processes related to subscriber management were high like CPU/Memory and statsd and authd both continuously crashing in both REs. As a result subscribers stuck in terminating.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1846448
Major
The S-BFD responder session cannot be distributed to PFE and failing S-BFD session to establish
Product-Group=evo
Severity=Major
On al MX and PTX platforms, If S-BFD(Seamless-Bidirectional Forwarding Detection) responder is configured without the "lo0.0" on device and with any other "lo0.x " then this S-BFD responder session cannot be distributed to PFE(Packet Forwarding Engine) and fails to come up in distributed mode. Hence BFD service will be impacted.
PR NumberSynopsisCategory: Border Gateway Protocol
1793714
Major
BGP routes may not get advertised when always-wait-for-krt-drain is configured with BGP sharding
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when 'delay-route-advertisements always-wait-for-krt-drain' is configured, the EoR (End of Record) from the source peer of the routes is not received in the BGP (Border Gateway Protocol) peer which is sent by a BGP speaker to indicate the end of a record or a sequence of updates. This is due to the BGP router advertiser being stuck in the wait-for-inbound-convergence state, which may cause the KRT (Kernel Routing Table) queue to get stuck, thereby halting the advertisement of BGP routes.
1807504
Major
BGP multipath selects wrong interface with "Multiple Single-Hop EBGP sessions on different links using the same IPv6 Link-Local Address"
Product-Group=evo
Severity=Major
On Junos and Junos Evolved Platforms having BGP (Border Gateway Protocol) Multipath when "Multiple Single-Hop EBGP Sessions on different links using the same IPv6 (Internet Protocol Version 6) Link-Local Address" as over multiple links and one of those links is down, the next-hop information which has the smallest IFL (Logical Interface) index interface will get deleted. Since RIB (Routing Information Base) and FIB (Forwarding Information Base) are not correct network traffic will be lost when one of the peer device is down.
1811862
Major
Improper maximum value for limit-bandwidth of policy-statement
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms limit-bandwidth of policy-statement can only be configured to maximum value 4.2G (4294967295) which is not large enough based on actual maximum capacity. user@router# set policy-options policy-statement test then limit-bandwidth ? Possible completions:  Limit advertised aggregate outbound link bandwidth (0...4294967295)
1817834
Major
The rpd crashes when stale label entry keeps increasing when knob stale-labels-holddown-period is configured
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms configured with the "stale-labels-holddown-period" setting and extensive label configurations (such as Multiprotocol Label Switching labels), the Routing Protocol Daemon (RPD) may crash if stale labels are not cleared periodically and keep accumulating. Due this, temporary traffic impact will be seen until the rpd process restarts.
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.
1823612
Major
Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash (CVE-2025-21600)
Product-Group=evo
Severity=Major
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.. Please refer to https://supportportal.juniper.net/JSA92870 [juniper.net] for more information.
1826686
Major
Traffic impact due to BGP route stuck in hidden state
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, with BMP (BGP Monitoring Protocol) configured, the BGP route gets stuck in a hidden state with the next hop state as 'Next hop type unusable' leading to traffic drop.
1828380
Major
Junos OS and Junos OS Evolved: Receipt of specially crafted BGP update packet causes RPD crash (CVE-2025-21602)
Product-Group=evo
Severity=Major
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA92872 [juniper.net] for more information.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1776453
Major
BMP does not come up after switchover when configured with sharding and NSR
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved Dual RE platforms, After switchover, BMP does not come up when configured with sharding and NSR enabled.
1807892
Major
A route stuck in A route can get stuck in 
PR NumberSynopsisCategory: BBE Remote Access Server
1826901
Major
The authd process crash is seen when subscriber management is enabled
Product-Group=evo
Severity=Major
On all Junos MX platforms, the authd process would crash if it attempts to access the subscriber management database (SDB) while the SDB is undergoing re-initialization due to a problem. Due to this, new subscriber login will be affected possibly for few seconds.
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1799760
Major
MPLS payload traffic coming over EVPN-MPLS tunnel is dropped on PTX Junos OS Evolved platforms
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX platforms, if MPLS payload packet is received on Ethernet Virtual Private Network-Multi-Protocol Label Switching (EVPN-MPLS) tunnel, then that traffic will be dropped.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1786788
Minor
The evo-aftmand process will crash when PFE or FPC is restarted
Product-Group=evo
Severity=Minor
On all Junos Evolved PTX platforms when PFE/FPC is restarted, evo-aftmand will crash leading to line card restart. The line card restart will impact the traffic.
1809955
Major
On PTX10001 EVO platform, traffic could get dropped unexpectedly due to uRPF failure
Product-Group=evo
Severity=Major
If uRPF is enabled and default route and source route both have same forwarding traits i.e. nexthop, iflistindex etc. then due to FIB compression, the source route might get compressed with default route which could lead to traffic drop due to urpf.
1811245
Major
BGP session on PTX platforms may flap when inline BFD is configured with low BFD timer
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX platform, the Border Gateway Protocol (BGP) session flap can be seen when inline Bidirectional Forwarding Detection (BFD) is configured under routing instance without loopback interface (lo0) leading to partial traffic drop. The issue is only seen when the interface is within the routing-instance.
1859387
Major
PFH Interface Down After PFE Offline and Re-anchor
Product-Group=evo
Severity=Major
On all PTX Series with Junos OS Evolved, after performing several 'request chassis fpc slot <#> pfe-instance <#> restart' commands, BFD (Bidirectional Forwarding Detection) session flapping is observed, leading to BFD session flapping and partial service impact on the control plane.
PR NumberSynopsisCategory: CFM
1846960
Major
The cfmman memory leaks when CFM remote-mep is configured and adjacency goes down
Product-Group=evo
Severity=Major
On Junos Evolved PTX10K platforms, the cfmman memory leaks when CFM remote-mep is configured and adjacency goes down. The cfmman memory leak will crash the FPC.
PR NumberSynopsisCategory: CoS support on DNX
1779030
Major
The cosd crashes when configuring CoS host-outbound-traffic without forwarding-class
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, cosd crash is observed i.e. traffic impact when fetching forwarding-class detail having CoS (Class-of-Service) host-outbound-traffic configured without forwarding-class.
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1841071
Major
Incorrect routing seen for VRF traffic after changing packet-forwarding options from hw-db-profile to balanced-exem
Product-Group=evo
Severity=Major
On all ACX Evolved platforms the packet-forwarding options hw-db-profiles "balanced-exem" and "l3-xl" causes routing issues for traffic coming in a VRF (Virtual routing and forwarding) and forwarded using the default route leading to traffic impact.
PR NumberSynopsisCategory: sflow issues on ACX platforms
1836394
Major
On ACX EVO devices inline-sampling for sflow does not work with default route advertised via BGP.
Product-Group=evo
Severity=Major
If Inline-sampling for sflow is used with default route advertised via BGP in ACX device running Junos Evo, then the ingress sampling does not work. There will be issues in monitoring as there will be no datagrams captured.
PR NumberSynopsisCategory: Dynamic rendering infrastructure
1745615
Major
Telemetry data is not exported in an IS-IS scaled Segment Routing scenario
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms configured with SR-ISIS(Segment Routing-Intermediate System to Intermediate System) and with gRPC/gNMI telemetry, subscription to the path: "/junos/services/segment-routing/sid/usage/" will not work and the output could not be proper. The issue could happen only in scaled configuration (Approximately, 4000 or more per-sid ingress sensors and 4000 or more IPv4/IPv6 per-sid egress sensors are configured).
PR NumberSynopsisCategory: EVO Class of Services
1829632
Major
[EVO] cosd application may crash when the "interface-set" statement is configured under class-of-services hierarchy.
Product-Group=evo
Severity=Major
On all Junos EVO platforms, cosd crash may be seen upon commit when the "interface-set" statement is configured within the class-of-services hierarchy with ".", "*, " or "?" characters specified in the interface-set name and a traffic-control-profile being associated to it.
PR NumberSynopsisCategory: Firewall related development
1815533
Major
Firewalld process crashes when port range optimization parameter is configured with a value greater than 255
Product-Group=evo
Severity=Major
On EVO QFX platforms, when the destination/source-port-range-optimize feature is configured and it matches a value greater than 255, the firewalld process will crash and a core dump is raised.
PR NumberSynopsisCategory: management ethernet related issues - mgmt-ethd daemon
1799681
Critical
DHCP client on mgmt0 interface failed to start and dhcp-managerd dumped core
Product-Group=evo
Severity=Critical
On all Junos Evolved platforms with DHCP (Dynamic Host Configuration Protocol) configuration, if a user enable DHCP on the management interface, dhcp-managerd process crashes and creates a core dump while trying to set up the default route. This can affect accessing the router through the management interface. However, it does not disrupt traffic on the WAN ports.
PR NumberSynopsisCategory: Issues related to debug utilties - objmon, objshell/Dashboard
1792415
Major
Junos Ping inet command does not force IPv4 in EVO platforms
Product-Group=evo
Severity=Major
On Junos Evo platforms, when "ping " is executed on cli it does not force IPv4 as documentation suggests, rather displays no route found.
PR NumberSynopsisCategory: EVO Services Jflow PRs for defect & enhancement requests
1816542
Major
A router running sampling may see the msvcs-db daemon run at 99.9% for an extended period
Product-Group=evo
Severity=Major
A router running sampling may see the msvcs-db daemon run at 99.9% for an extended period
1828032
Major
The flow record outputs are not displayed correctly on Junos Evolved platforms
Product-Group=evo
Severity=Major
The Jflow record output are not displayed correctly, if the unknown prefix/route hits this sampling interface on Junos Evolved platforms configured with a Default route and Sampling. It has no traffic impact.
1858721
Major
PTX10k EVO: JFLOW exported flow data InputInt is set to zero when redirecting to routing-instance and redirecting back to default instance
Product-Group=evo
Severity=Major
JFLOW ingress sample on an aggregate interface with vlan and the sampled data gets redirected into a routing-instance, the route is then pointing back to inet.0 via the next-table inet.0 configuration, the exported JFLOW InputInt data is not filled out and reported with value zero. If sampled data is redirected into routing-instance and not sent back to inet.0 the InputInt field is filled out properly.
PR NumberSynopsisCategory: EVO category to hold IPv6 Neighbor Discovery Protocol and re
1807906
Major
Traffic loss is seen due to stale route after running a test script on Junos Evolved platforms
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, running EVPN MPLS, after events involving hosts moving across the tunnel and a flap of the underlying interface of the tunnel, the output for command show platform app-controller incomplete" is seen which indicates stale route.
PR NumberSynopsisCategory: Express PFE MPLS for EVO platforms
1829924
Major
PTX devices acting as transit nodes display incorrect MPLS traceroute or TTL
Product-Group=evo
Severity=Major
On Junos Evolved PTX10K platforms, when there is an ECMP to destination, PTX devices in a transit MPLS path do not decrement the TTL value properly, leading to ICMP tunneling failure and incorrect traceroute behavior.
PR NumberSynopsisCategory: EVO RPD agent PRs
1739567
Major
evo-pfemand and rpdagent object anomalies are being observed on ACX7509
Product-Group=evo
Severity=Major
MBB ASSISTD attribute was enabled on single node platforms and the app is not launched for master RE on chassis platform causing object anomaly resulting in forwarding issues.
1802000
Major
The rpd process crashes when Routing Instance type is changed from L2 to L3 or vice versa
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms, when a layer 2 RI (Routing Instance) is changed to layer 3 RI or vice versa without changing the name of the RI in a single commit, due to a rare timing issue, the rpd process can crash. During the rpd crash and restart, the routing protocols will be impacted and traffic disruption will be seen due to the loss of routing information.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1825793
Minor
[EVO] The timestamp of the "show system configuration rescue" output shows wrong time.
Product-Group=evo
Severity=Minor
"show system configuration rescue" may show strange "Last changed" timestamp. It may happen under any time zone potentially and looks like there are some patterns. In case of "Asia/Tokyo", Last changed timestamp may show "1970-01-01 08:59:59 JST".
PR NumberSynopsisCategory: EVPN control plane issues
1816672
Major
[Junos OS Evolved] LACP on non-DF ACX router comes out of "out-of-sync" state by deactivating one of the EVPN instances, causing CE device to move to Collecting distributing
Product-Group=evo
Severity=Major
There are multiple EVPN instances each having separate IFL of AE IFD. AE is configured with per-esi lacp-oos-on-ndf on the AE IFD. On deactivating one of the instances, LACP on non-DF router comes out of "out-of-sync" state, causing CE device to move to Collecting distributing.
PR NumberSynopsisCategory: Issues related to EX MACsec
1830395
Major
Commit error on using more than 31 characters authentication-key-chain-name
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when authentication-key-chain-name is configured with more than 31 characters, commit error is seen due to which MACSEC will not work with the configuration.
PR NumberSynopsisCategory: Express PFE COS AFT software issues
1814641
Minor
One CoS drop-profile might not work on PTX EVO platforms
Product-Group=evo
Severity=Minor
Due to mishandling reserved 'drop-profile" curve index zero, one of "class-of-service drop-profiles" might not get programmed correctly in the ASICs on some FPCs. Curve index zero is reserved for 'default-drop-profile', which disables WRED (for dropping or ECN). If a non-default drop-profile configuration object reaches FPC AFT software first, AFT wrongly assigns curve index zero to that drop-profile. But lower-layer software will not program WRED for curve index zero. It is unpredictable whether this bug occurs for a given FPC reboot, with drop-profiles already configured. Schedulers whose drop-profile-map uses the affected drop-profile might have WRED disabled in hardware, so only Tail-drops will be seen if that queue drops packets for congestion.
PR NumberSynopsisCategory: Express PFE CFM
1822526
Critical
BFD protocol sessions flap continuously when operating in hardware-assisted inline mode
Product-Group=evo
Severity=Critical
On Junos Evolved PTX10K platforms, Bidirectional Forwarding Detection (BFD) protocol sessions will flap continuously and never become stable after this. This exposure is not deterministic and is only exposed if BFD is operating in hardware-assisted inline mode.
PR NumberSynopsisCategory: Express pfe ddos protection feature
1801290
Major
PTX EVO DDoS stats values of "Arrival rate" and "Max arrival rate" on System-wide and FPC showing larger values than expected
Product-Group=evo
Severity=Major
On PTX EVO platforms, ddos(distributed denial of service) statistics values of "Arrival rate" and "Max arrival rate" on System-wide and FPC show larger values than expected.
PR NumberSynopsisCategory: All Guardian (ACX7509) Linecard (FPC) related issues
1821275
Major
100G LR4 optics did not come up after upgrade on Junos Evolved ACX7509 platform
Product-Group=evo
Severity=Major
On all Junos Evolved ACX7509 platform, interfaces configured with QSFP-100GBASE-LR4/ 2X100GBASE-LR4 optics could fail to come up following a software upgrade or system reboot. As a result, the 100G-LR4 interface/link will remain down after the upgrade or reboot, leading to a complete loss of traffic.
PR NumberSynopsisCategory: All Guardian ACX7509 platform, FEB, RCB & linecaard resiliency
1835268
Major
Major FEB alarm due to broadsync unlock
Product-Group=evo
Severity=Major
On ACX7509, major FEB alarm due to broadsync unlock.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1787707
Major
The KRT queue will be stuck on Junos ACX710 platform
Product-Group=evo
Severity=Major
On Junos ACX710 platform with BGP (Border Gateway Protocol) configuration, the response message will be lost and it will lead to element being stuck in the KRT (Kernel Routing Table) queue.
1826194
Major
The rpd crash is observed during upgrade or restart
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, rpd crash is observed during upgrade or restart since kernel takes more time to update ifstate information.
PR NumberSynopsisCategory: MX Inline Jflow
1813925
Major
FPC reboots after sensor configuration is removed and readded over a long period on MX and EX9200-15C platforms
Product-Group=evo
Severity=Major
On all MX platforms with MPC10/MPC11/LC9600, MX304 and EX9200-15C platforms, when any sensor configuration on protocols, for example, MPLS LSP, is configured and removed over a long period, the aftd-trio process starts a memory leak and eventually causes FPC to reboot.
PR NumberSynopsisCategory: ISIS routing protocol
1808185
Critical
The rpd crash is observed for the leaked ISIS SRv6 locator route holding a stale pointer
Product-Group=evo
Severity=Critical
On Junos and Junos Evolved platforms with SRv6 (Segment Routing IPv6) and ISIS (Intermediate System-to-Intermediate System) configured, the rpd (Routing Protocol Process Daemon) crash is observed for the leaked ISIS SRv6 locator route holding a stale pointer when SRv6 locators are leaked across ISIS multi-instances (standard and non-standard) and also if changes to these locators are too frequent.
1837289
Major
The 'overload advertise-high-metrics' does not work after the graceful restart for ISIS
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms configured with "protocols isis overload advertise-high-metrics" (without timeout) and graceful-restart, IS-IS (Intermediate System to Intermediate System) will start advertising high link metrics immediately as expected. However, when IS-IS is in graceful restart mode either via GRES (Graceful Routing Engine Switchover) switchover or restart routing, the high link metrics are not advertised and IS-IS continues to advertise the usual link metrics even when IS-IS graceful restart is completed. When the issue is hit, the node configured as an overload might be used for transit traffic based on the IGP metric.
1841108
Major
Traffic drop is seen after GRES on ISIS peer
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, in an ISIS(Intermediate System-Intermediate System) graceful restart scenario, helper node sends and programs its locally configured hold-time (180 secs) instead of the "Restart-duration" received as hold-time from DUT (210 secs), due to this incorrect update, the hold timer expires at the helper node before the GR (Graceful Restart) is complete on DUT and it causes a flap of ISIS adjacency on peer/helper Node.
PR NumberSynopsisCategory: jdhcpd daemon
1825998
Major
DHCP ALQ process crashes to recover from memory leak.
Product-Group=evo
Severity=Major
On all Junos OS and Junos OS Evolved platforms , In a rare scenario when memory leak happens the Dynamic Host Configuration Protocol (DHCP) active-leasequery (ALQ) process crashes automatically.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1824739
Major
The traffic is getting duplicated when VPLS to EVPN transition is performed
Product-Group=evo
Severity=Major
On platforms with MPC10, MPC11, LC9600 and MX304-LMIC line cards, during a transition from VPLS (Virtual Private LAN Services) to EVPN (Ethernet Virtual Private Network) or when the MAC (Media Access Control Address) addresses move from a local to a remote state, control MAC addresses are incorrectly programmed in the hardware, leading to traffic duplication and unresolved destination errors.
PR NumberSynopsisCategory: Label Distribution Protocol
1812545
Major
The rpd process crashes with LDP entropy-label policy configuration with "from instance "
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, complete service impact will seen because of the rpd crash on using match condition "from instance " for LDP ( Label Distribution Protocol) entropy-label policy-statement under "set protocols ldp entropy-label ingress-policy .
1835938
Major
In a scenario involving NG-MVPN and point-to-multipoint LDP LSP the LDP point-to-multipoint FEC may remain in an inactive state on the PE after uplink interfaces flap
Product-Group=evo
Severity=Major
In a NG-MVPN (Next Generation - Multicast Virtual Private Network) scenario where mLDP (Multipoint Label Distribution Protocol) is used for multicast MPLS (Multi Protocol Label Switching) label signalling and BGP (Border Gateway Protocol) is utilised to reach the LDP (Label Distribution Protocol) point-to-multipoint root address, a high BGP scale along with short uplink interface flaps cause the LDP point-to-multipoint FEC (Forwarding Equivalence Class) to remain in an inactive state. This can lead to point-to-multipoint traffic drop and impact multicast services.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1759618
Major
License-service crash is seen on Junos OS Evolved platforms
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, when license with unknown feature ID/platform reserved feature ID is added via configuration set system license keys key and then if License-service is restarted or system is rebooted or software upgrade is done then license service crashes and crash files are seen. This is a non service impacting issue.
1792672
Major
License is lost on NG-RE platforms after device/routing-engine reboot
Product-Group=evo
Severity=Major
On NG-RE (Next Generation Routing Engine) platforms, license is lost after restarting device/routing-engine. If any service depends on that license, that service will be impacted.
PR NumberSynopsisCategory: lldp sw on MX platform
1811545
Major
The LLDP neighborship does not recover on AE interfaces
Product-Group=evo
Severity=Major
When LLDP is configured on interface all and there are AE interfaces configured, to disable LLDP on one of the AE "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, AE is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1757100
Major
Memory leak observed in AFTd-Trio daemon in PFE with IFL based MACSEC enabled on MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16
Product-Group=evo
Severity=Major
On all Junos MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16, the statistics for MACSEC (MAC Security) are not displayed properly and lead to memory not getting freed. In a scaled environment of IFLs with MACSEC configured, eventually leads to AFTd-Trio daemon crash due to memory exhaustion.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1744584
Major
Traffic loss will be observed whenever a soft preemption reroute request arrives
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, whenever a soft preemption reroute request arrives in the middle of the ongoing make-before-break, traffic loss would be observed which is still referring to the old instance.
1814358
Major
LSP keep retrying over the transit router marked as "overload" resulting in traffic drops or using the suboptimal path for the LSP
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms with RSVP-TE (Reservation Protocol-Traffic Engineering) configured, when IGP (Interior Gateway Protocol) "overload" is configured on the transit router, the traffic should move away from the transit router. But in the issue scenario, the LSP (Label Switched Path) continues to stay across the transit router which has been marked as overload and traffic continues across the transit router resulting in traffic drops or using the suboptimal path for the LSP. The issue happens when Patherr is received for the re-optimized path and CSPF (Constrained Shortest Path First) computation is triggered before the backoff timer.
PR NumberSynopsisCategory: Multicast for L3VPNs
1747703
Major
The MVPN traffic starts dropping after RE switchover
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms with Dual RE and MVPN ((Multicast Virtual Private Network) enabled, when the user initiates a GRES ( Graceful Routing Engine Switchover) switchover, it triggers a route change from the MVPN . During this process, there's a gap where traffic loss is observed because the flood next hop pointed to by the route gets deleted.
PR NumberSynopsisCategory: Path computation client daemon
1823220
Major
Authentication failure will be seen for routing protocols when MD5 is configured for routing protocols and PCEP on Junos OS Evolved platforms post reboot
Product-Group=evo
Severity=Major
When MD5 is configured for PCEP (Path Computation Element Protocol) on Junos OS Evolved platforms, MD5 will not work for other protocols after reboot. Authentication failure will be seen and it causes a connectivity issue or a service impact.
PR NumberSynopsisCategory: Issues related to PKI daemon
1801377
Minor
Crash files are generated every 24 hours due to a pkid process crash
Product-Group=evo
Severity=Minor
On all Junos OS Evolved platforms, a pkid (Public key infrastructure daemon) process crash is observed every time a periodic auto CDN (Content delivery network) query to download the latest trusted CA bundle takes place (every 24 hours by default)
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1818022
Major
On Junos OS Evolved platforms, any new L2 functionality doesn't work when ELP configuration is not present on the connected device(s)
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, when ELP (Egress link protection) is present on one device and not present on it's connected device(s), it causes any new L2 (Layer 2) functionality (e.g. new VLAN creation, updating L2 message, etc.) to not work. As there is no ELP configuration on the other device, it blocks l2ald ( layer 2 addressing learning daemon) event queue. This impacts the L2 functionality of the other node where ELP is not configured.
PR NumberSynopsisCategory: Category for QFX5K EVO Platform Software PRs related to Chas
1757471
Major
[ACX7100 QFX5130 QFX5220] PSM Input Under Voltage Failure is displayed in 'show chassis hardware' but PSM status is OK
Product-Group=evo
Severity=Major
A "Major" alarm is generated when the input voltage is low. However, the alarm is not cleared when input voltage comes back within the acceptable range and the ower supplies continue to function without any issue.
PR NumberSynopsisCategory: rosen-6 and rosen-7 mvpn bugs
1736328
Major
RPD core@bgp_rt_terminate_job -> bgp_process_rt_terminate -> bgp_rt_terminate_subr -> bgp_rto_adv_q_free -> bgpg_rt_open ()
Product-Group=evo
Severity=Major
This is a day one code and is seen only in the scale setup with specific configuration with both l2vpn and rosen mvpn configuration present, when the scale configurations are done and then deleted (load baseline config). As per existing implementation, the MDT table though not required for l2vpn instances was being created and this code has been there since day one and in normal cases this should not create any issues. However in this scaled configs setup, when all configs were deleted, bgp global and group specific tables were getting to inconsistent state specifically for the MDT table and hence the issue.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1805427
Minor
The rpd process crashes during rpd restart on Junos and Junos Evolved platforms
Product-Group=evo
Severity=Minor
On all Junos platforms, due to timing issue during the restart of the rpd process may cause it to crash. This can temporarily impacts traffic until the process recovers.
1817807
Major
Routes for secure tunnel interface interface not installed on forwarding-table on SRX platforms
Product-Group=evo
Severity=Major
On all SRX platforms, after the In-Band Cluster (ICU) upgrade if the system has routes pointing to the secure tunnel interface (st0) interface, or on clearing security IPsec sa on peer router a few routes might have trouble getting installed in forwarding, impacting traffic on the routes that are not installed after the upgrade.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1808463
Major
CPU utilization of the rpd process stays high on all Junos and Junos OS Evolved platforms
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms in a corner case, the Routing Protocol Daemon (rpd) CPU utilization will be seen high in scenarios where recursive route resolution is involved. The rpd process will be continuously spinning in the re-resolution job which could impact scheduling of other jobs and re-resolution of other routes impacting traffic.
1810866
Major
The rpd crash is observed due to the segmentation fault on Junos OS Evolved platforms
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, the rpd (Routing Process Daemon) crash i.e. traffic impact is observed due to a segmentation fault. The issue happens when the rpd sends an add request for the same next-hop ID for multiple routes/unicast next-hops with the same prefix and points to a discard interface. The rpd doesn't expect the same next-hop ID for multiple routes/unicast next-hops.
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1818978
Major
The "preserve-nexthop-hierarchy" knob configured with VPLS , brings down the L3 protocol sessions running over the IRB interface
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, "preserve-nexthop-hierarchy" knob configured with Virtual Private LAN Service (VPLS), causes the Layer-3 (L3) control packets like that of Border Gateway Protocol (BGP) / Open Shortest Path First (OSPF) running over Integrated Routing and Bridging (IRB) interface to be dropped and brings down the protocol sessions.
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1812009
Major
The rpd process crash is observed when there are catastrophic changes under the particular routing instance configuration
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, when there is any catastrophic changes made in the configuration without deactivating a particular routing instance will lead to the rpd process crash.
PR NumberSynopsisCategory: Resource Reservation Protocol
1840543
Major
The rpd crash is observed when "expand-loose-hop" knob is configured and rpd is undergoing graceful restart
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when RSVP (Resource Reservation Protocol) LSP (Label Switched Path) is configured to perform loose hop expansion by enabling "expand-loose-hop" under MPLS (Multi-Protocol Label Switching) LSP knob and "graceful-restart" is configured in routing-options, rpd crash can be seen if it is undergoing graceful restart, causing service impact.
PR NumberSynopsisCategory: PTX10K specific platform PRs
1767111
Major
Fan tray OIR will result in fan-tray failures
Product-Group=evo
Severity=Major
On all Junos OS Evolved PTX10008/PTX10004/PTX10016 platforms, when a Fan-tray is removed followed by an insertion, it will lead to fan-tray failures.
PR NumberSynopsisCategory: N/A:sw-scbe3-timing
1742266
Major
Implement an alarm to notify the system in the "PLL Core Frozen" event
Product-Group=evo
Severity=Major
In a rare occation, an MPC, or an SCB3's hardware clock synchronization PLL module may locked up and not be able to lock on to the clocking signal during holdover, resulting in PTP or SyncE failure. The change in this PR raises a "PLL Core Frozen" major alarm so the system can react to this by raising an alarm, and rebooting the affected MPC, or the SCBE3.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1820791
Major
Per-Segment-list telemetry for colored tunnel doesn't work
Product-Group=evo
Severity=Major
Per-Segment-list telemetry for colored tunnel doesn't work on PTX-Series platform with Junos OS Evolved such as PTX10004, PTX10003, PTX10001, but it works on PTX10008 and PTX10016.
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1812276
Critical
Persistent link error in one fabric plane towards some PFE could causes traffic blackholing from non-native LC PFE towards that remote PFE over all fabric planes
Product-Group=evo
Severity=Critical
On MX2010/MX2020 platforms with non-native LCs installed with an ADC, if a non-native LC PFE erroneously starts sending the traffic to a remote PFE using some fabric plane with link error towards that remote PFE, then this traffic will build up at the sending LC ADC, which cause the traffic blackholing to the remote PFE over all fabric planes.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329
Major
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=evo
Severity=Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1702344
Minor
Apply-path special handling for wildcard after a leaf attribute
Product-Group=evo
Severity=Minor
On EVO platform, if the apply-path config has a wild-card <*> character after an attribute node then, the wild-card character is not processed. Due to which, the apply-path config is not expanded into matching prefixes by ui-infra. Please refer workaround section on how to avoid the issue.
1818692
Major
Configuration commit fails due to mustd process crash
Product-Group=evo
Severity=Major
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP
1829886
Major
Commit error check-out failed does not get triggered when a complete bridge-domain is configured in instance-type vrf.
Product-Group=evo
Severity=Major
Commit error check-out failed does not get triggered when a complete bridge-domain is configured in instance-type vrf.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1799215
Major
The commit fails error can be seen when configuration is modified after commit prepare
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when the user attempts to issue the commit command after modifying the configuration post 'commit prepare', the commit discards the prepared commit cache as it is no longer valid and throws " commit fails" error and proceeds with the regular commit process from scratch.
1799277
Major
The mgd crash is seen on aggregation device and upgrade is halted during upgrade to aggregated satellite switches
Product-Group=evo
Severity=Major
The satellite package is not conforming to the expected junos version format leading to the problem reported. The code which parses this version string has been modified to handle such format incompatibility gracefully.
1842518
Major
The device become unresponsive in a race condition due to maximum process (maxproc) limit
Product-Group=evo
Severity=Major
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1774292
Major
The error messages "eventd: could not bind to address x.x.x.x: Can't assign requested address" is generated on the backup RE and cpu usage of eventd gets 100%.
Product-Group=evo
Severity=Major
The following Error messages are generated on the backup RE and cpu usage of eventd gets 100% when "syslog host" and "syslog source-address" are configured.eventd: could not bind to address x.x.x.x: Can't assign requested addresseventd: Trying bind to default address: Inappropriate ioctl for deviceeventd: bind: Invalid argument.
PR NumberSynopsisCategory: Issues related to NETCONF
1796297
Major
Error message not prompted on commit confirmed RPC sent in private mode on all Junos and Junos Evolved platforms
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, commit confirmed command executed with remote procedure call (RPC) in private configuration mode is being allowed where ideally it should not be.
1800859
Major
Configuration push to device using RPC resulted in incorrect policy order
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms,  RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.
PR NumberSynopsisCategory: Issues related to YANG Data Models
1826630
Major
Annotations are improperly structured in NETCONF after enabling YANG compliance
Product-Group=evo
Severity=Major
When the YANG(Yet Another Next Generation)-compliant knob is configured, annotations containing non-alphanumeric characters are written as-is, instead of being escaped into their corresponding formats.
PR NumberSynopsisCategory: Virtual Private LAN Services
1774580
Major
Multicast traffic loop will be observed when Multicast traffic is sent over the Access Interface marked as CCC-DOWN
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms in the VPLS (Virtual Private LAN Service) Multi-homing with Multicast Snooping enabled, Multicast traffic looping will be observed due to L2 (Layer 2) Multicast traffic being sent on the access interface status marked as CCC-DOWN.
1793342
Major
VPLS traffic will be impacted when routing-engine switchover happens due to master routing-engine reboot in NSR scenario
Product-Group=evo
Severity=Major
With VPLS service having NSR+GRES configured it may be seen that post RE switchover few of the VPLS sessions that were undergoing changes during transition to new RE may not come up, due to LSI IFL not getting created. This will impact the traffic flowing over that VPLS session
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1760534
Major
VRRP Status displayed incorrectly in CLI command
Product-Group=evo
Severity=Major
On Junos and Junios OS Evolved platforms with dual RE, when GRES and NSR are enabled. VRRP status is wrongly displayed in standby RE when VRRP is configured although it is in the correct state. There is no impact with services. its a display issue.
1822867
Major
After RE switchover the VRRP master and backup router will start functioning as master routers
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms configured with VRRP (Virtual Router Redundancy Protocol) and NSR (Non-Stop Routing), after RE switchover or GRES (Graceful Routing Engine Switchover) the master router would starts sending VRRP advertisements with a different priority value. As a result, both the master and backup VRRP routers will begin operating as the master which results in inconsistent traffic routing or packet loss as the system fails to establish a single master node.
PR NumberSynopsisCategory: usf nat related issues
1829633
Critical
The flowd process crashes in scaled scenario when subscribers exceed maximum session limit for NAPT44 on MX platforms with MX-SPC3
Product-Group=evo
Severity=Critical
On MX240, MX480 and MX960 with MX-SPC3 and in highly scaled subscriber scenario with high memory utilisation, MX-SPC3 reboots and flowd process crashes when subscriber received through Endpoint Independent Filtering (EIF) reaches the configured "max-sessions-per-subscriber" limit for Network Address and Port Translation(NAPT44).

 


 

23.2R2-S3-EVO - List of Known issues 

PR NumberSynopsisCategory: EVO interface software
1736206
Major
The interface comes up with a mismatch FEC after setting FEC91 on one end and will be stuck in down state after deleting FEC91
Product-Group=evo
The interface comes up with a mismatch FEC after setting FEC91 on one end and will be stuck in down state after deleting FEC91.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D41-EVO evo:22.3X80-D42-EVO evo:23.4R1-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: Border Gateway Protocol
1788543
Major
BGP OutQ counter of one of the BGP peers gets stuck after system reboot/restart routing/clear bgp neighbor
Product-Group=evo
On all Junos and Junos Evolved platforms, when there is a high route churn and the system reboot/restart routing/clear bgp neighbor is done, there are some values stuck in the OutQ counter of one of the peers in a group. Due to this, the route updates are not sent which might result in traffic/service impact.

Resolved In: evo:22.3X50-EVO evo:23.4R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1839288
Major
BMP soft assert due to counter reset by clear command
Product-Group=evo
On all Junos and Junos Evolved platforms, when "clear bgp statistics" command is issued while one or more BMP peers are coming up the soft_assert will be hit. This issue has no impact on the traffic or services.

Resolved In: evo:22.3X50-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO junos:22.4R3-S5 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: EVO VXLAN PFE for BCM XGS Platforms
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1777003
Major
PTX10001-36MR: epp_epc_intr_shmem_err seen in logs
Product-Group=evo
On a BT-base PTX platform, you may see the "epp_epc_intr_shmem_err" in its Syslog when a vlan id is missing from an interface.

Resolved In: evo:21.4R3-S6-EVO evo:22.2R3-S6-EVO evo:22.4R3-S7-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO
PR NumberSynopsisCategory: Express BT PFE L3 Features
1840295
Major
Multihop BFD remains down when it's associated with a static route in the routing instance
Product-Group=evo
On Junos Evolved, specifically in PTX platforms (PTX10001/2/3/8/16), the next-hop interface related to the static route is down, and the ARP (Address Resolution Protocol) is deleted. Even if the interface recovers, BFD (Bidirectional Forwarding Detection) will not recover.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO
PR NumberSynopsisCategory: MX304 line card platform software
1849915
Major
FPC reboot due to memory leak from telemetry sensor installation/uninstallation
Product-Group=evo
On Junos MX204, MX304, MX2010, MX2020, MX10004, MX10008, MX10016 with MPC11, LC2301/LC9600, LMIC16 and LC480 line cards, when installing and uninstalling specific telemetry sensors that export data from LC (Line Card), a few bytes of memory are allocated but not freed, leading to a memory leak. This issue is seen when "sensor-based-stats" is configured and LSP (Link State Path) flaps occur. Each flap triggers repeated installation and uninstallation of the telemetry sensor, accelerating memory consumption. Over time, this exhausts the memory allocated to aft-ulcd process causing FPC (Flexible PIC Concentrator) to reboot.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S5-J2 junos:22.4R3-S6 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: N/A:sw-bx-pfe-vpls
1836692
Major
CFM session fails to install after changing the child links of the AE bundle
Product-Group=evo
On all Junos Evolved PTX10004, PTX10008, PTX10016, PTX10001-36MR and PTX10002-36DD platforms, with CFM (Connectivity Fault Management) configured on AE (Aggregate Ethernet) interfaces, moving or changing the child AE links from one interface to another will lead to failed CFM sessions.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: CFM
1836228
Major
All PTX-EVO platforms doesn't support CFM Performance Monitoring Loss Measurement SLA iterator feature
Product-Group=evo
On all Junos Evolved PTX platforms CFM (Connectivity Fault Management) Performance Monitoring LM(Loss Measurement) SLA(Service Level Agreement) iterator feature is not supported starting version 23.2. This issue is not traffic impacting.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: CoS support on DNX
1776127
Major
Multihop BFD packets always uses the network-control egress queue
Product-Group=evo
Multihop BFD packets by default uses the network-control queue in EVO ACX. This setting will remain same despite configuring the host-outbound-traffic to a different forwarding-class.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO
1839055
Major
Junos Evolved ACX7k platforms may experience packet drops due to a delay in route update
Product-Group=evo
Junos Evolved ACX7k platforms may experience delays in route programming on handling AE (Aggregated Ethernet) interface down events causing convergence issues.

Resolved In: evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO
PR NumberSynopsisCategory: Host path software for ACX platform
1851810
Major
The Devdb messages will be seen continuously on ACX EVO platforms
Product-Group=evo
On ACX EVO platforms, due to the Discard filter programmed and the traffic hitting continuously on the same discard filter, the Devdb messages continuously keeps flooded.

Resolved In: evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO
PR NumberSynopsisCategory: DNX L2 related features
1845015
Major
Traffic will be flooded for a prolonged time when mac-table-size is reduced
Product-Group=evo
On Junos Evolved ACX platforms, when "mac-table-size" is reduced(to make the size less than the usable MAC), traffic will be flooded for a prolonged time(around 5 mins). Based on remote MAC installation behavior traffic will be impacted.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1854763
Major
[ACX7000] Post-convergence-lfa configuration causing a suboptimal-routing
Product-Group=evo
A suboptimal routing of traffic can be seen post configuring the post-convergence-lfa due to failover ID miss programming in the PFE.

Resolved In: evo:24.2R2-EVO
PR NumberSynopsisCategory: DNX platform MPLS FRR features
1844739
Major
ACX7024 - [Error] BrcmPlusNhMpls: status_t BrcmPlusNhMplsTunnel:: mplsFecHwCreate(BrcmPlusNhMplsTunVal&)Fec id alloc failed
Product-Group=evo
Customers may see the following message errors in the logs which can causing performance degradation ACX7024 routers. Oct 21 15:45:06 ACXR1 evo-pfemand[10937]: [t:10937] [Error] BrcmPlusNh: status_t BrcmNhRedUnilist:: configProtectionInHw(const BrcmParamsRedUnilistNhPtr&) Failed to allocate protection shadow FECs for unilist NH 79662 Oct 21 15:45:06 ACXR1 evo-pfemand[10937]: [t:10937] [Error] BrcmPlusNh: Failed configuring protection in HW unilist NH 79662 Impact to forwarding is seen when error messages are seen.

Resolved In: evo:23.4B1-EVO
PR NumberSynopsisCategory: ACX VxLAN Issue
1854255
Major
The evo-pfemand process crashes on ACX platforms without specific trigger
Product-Group=evo
On all Junos Evolved ACX platforms, evo-pfemand process crash is seen in a rare scenario when target next-hop is received with type Reject.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO
PR NumberSynopsisCategory: Issues related to debug utilties - objmon, objshell/Dashboard
1827914
Major
NETCONF output for unsuccessful ping is empty
Product-Group=evo
On all Junos Evolved platforms, when a ping is initiated using NETCONF RPC to a destination which is unreachable, the expected output corresponding to an unsuccessful ping is seen to be empty in the NETCONF RPC response. This is a cosmetic issue.

Resolved In: evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2 junos:24.4R1 junos:25.1R1
1843642
Major
Core dumps are incomplete after unzip.
Product-Group=evo
When unzipping core dump tar balls, there is an error or warning related to gzip hitting unexpected end of file.

Resolved In: evo:22.3X50-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.4R2
PR NumberSynopsisCategory: jdhcpd daemon refactored for evo
1816246
Major
[ACX7000 Series] DHCPv4/v6 packets may be dropped because DHCP packets are not routed to kernel after initial jdhcpd starts
Product-Group=evo
Under certain conditions, the DHCP session database becomes unstable or JDHCPD not getting IFL/IFD events which cause DHCP packets to fail to route to the kernel and then leads to DHCP packet drop.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Issues related to NTP issues on evo
1761546
Major
NTP association with source address and routing instance configuration is failing.
Product-Group=evo
NTP association with source address and routing instance configuration is failing.

Resolved In: evo:24.1R1-EVO evo:24.4R2-EVO junos:24.1R1
PR NumberSynopsisCategory: PRs related to software Agentd daemon on EVO
1783542
Major
ACX7024 is not booting after request system zeroize
Product-Group=evo
On Junos OS Evolved ACX7024, when performing "request system zeroize", disk operation related command will consume more time than 500s thus results kernel panic. The solution is provided through this PR to periodically reset the watchdog with upper limit. This provides additional buffer time for the command to complete.

Resolved In: evo:22.2R3-S6-EVO evo:22.3R3-S3-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R2-EVO
PR NumberSynopsisCategory: Express ptx-evo PFE L3 Features
1836337
Major
Packet loss is observed when the "indirect-next-hop-change-acknowledgements" command is missing from the junos-default configuration
Product-Group=evo
On Junos Evolved PTX10003 platform the command "indirect-next-hop-change-acknowledgements" is required in the junos-default configuration. If the said command is missing, it will result in packet loss.

Resolved In: evo:25.1R1-EVO junos:25.1R1
PR NumberSynopsisCategory: eventd, syslog infra issues
1815238
Major
PTX10004 - Host-name is not updated in picd logs
Product-Group=evo
On Junos OS Evolved platforms, host-name was not appended to PICD logs.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1827751
Major
ACX7100 sees an RPD core when adding a sampling flow-server
Product-Group=evo
ACX7100 sees an RPD core when adding a sampling flow-server

Resolved In: evo:23.4R2-S2-EVO evo:24.2R2-EVO
1840652
Major
RPD crash after RIB Sharding activation.
Product-Group=evo
RPD crash after RIB Sharding activation.

Resolved In:
PR NumberSynopsisCategory: SNMP, mib2d issues
1836012
Minor
The mib2d memory increase observed during 24 hours testing
Product-Group=evo
On all Junos OS Evolved platforms, mib2d memory leak may be observed when querying ip, tcp, udp, jnxIpv6GlobalStats and jnxIcmpv6GlobalStats scalar mib objects.

Resolved In: evo:23.2R2-S2-J6-EVO evo:23.2R2-S4-EVO evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO
PR NumberSynopsisCategory: All Guardian (ACX7509) Linecard (FPC) related issues
1788848
Major
Interfaces with QSFP-100GBASE-LR4 optics may not come up after SW upgrade or system reboot
Product-Group=evo
Interfaces with QSFP-100GBASE-LR4 optics may not come up after SW upgrade or system reboot

Resolved In: evo:23.2R2-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO
PR NumberSynopsisCategory: ISIS routing protocol
1760334
Major
Routing loop will be observed during ISIS-FRC implementation
Product-Group=evo
On Junos and Junos Evolved platforms, routing loop will be observed, when configuring FRC (Flood-Reflector Client) and processing anycast Layer 2 prefix advertisements, it leads to the installation of ISIS routes with incorrect nexthops .

Resolved In: evo:22.2R3-S4-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:20.3X75-D44 junos:22.2R3-S4 junos:23.4R1-S1 junos:23.4R2 junos:24.1R1 junos:24.2R1
1777702
Minor
The rpd process crashes after multiple iterations of disable/enable ISIS protocol
Product-Group=evo
On all Junos and Junos Evolved platforms, the rpd process crashes after disabling/enabling the ISIS (Intermediate System-to-Intermediate System) protocol using the set command. The issue is seen after 2-3 hours of continuous disabling, and enabling the ISIS process with a 90-sec interval.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:21.2R3-S9 junos:22.4R3-S5 junos:23.4R1-S1 junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: Platform infra to support jvision
1735274
Minor
ACX7024 and ACX7100 should not display the Temp, CPU and Memory utilization values in the show chassis fpc output.
Product-Group=evo
ACX7024 and ACX7100 should not display the Temp, CPU and Memory utilization values in the show chassis fpc output.

Resolved In: evo:23.1R2-EVO evo:23.2R1-EVO evo:23.2R2-EVO evo:23.3R1-EVO
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1728646
Major
The lsp-scale license counts both TE and non-TE LSPs
Product-Group=evo
On all Junos Evolved PTX platforms, when we have both TE and non-TE LSPs, the lsp-scale license would count both TE and non-TE LSPs. so feature enhancement done to lsp-scale license to count only TE LSPs (RSVP-TE & SRTE).

Resolved In: evo:22.4R3-EVO evo:23.4R1-EVO junos:23.4R1
1808956
Major
The syslog "LICENSE_EXPIRED" are not seen when license gets expired"
Product-Group=evo


Resolved In: evo:22.2R3-S5-EVO evo:23.4R2-S4-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1829765
Major
uKern DDOS Aggregate stats not updated for BFD packets at system wide and FPC level
Product-Group=evo
BFD Aggregate policer in 22.4R3S5 polices BFD Single-Hop packets. Hence the BFD Aggregate statistics may not reflect accurate statistics for other BFD packets like Multihop and Bundle. This will be fixed in upcoming release.

Resolved In:
PR NumberSynopsisCategory: Express Chip L3 software
1826626
Major
Unpoliced sampling traffic causes host congestion and forwarding failure
Product-Group=evo
On Junos PTX and QFX platforms, unpoliced sampling traffic can cause host path congestion, leading to a failure in forwarding operations. This issue occurs when specific conditions, such as higher rates of sampling classes or smaller packet sizes, are met.

Resolved In: junos:21.4R3-S10 junos:22.4R3-S5
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover, 
1848313
Major
OSPF neighbours go down due to link flapping after NSR switchover on Junos OS Evolved platforms with IPSEC configuration
Product-Group=evo
OSPF neighborship goes down after NSR (Nonstop routing) switchover due to link flapping on Junos OS Evolved platforms with Dual RE and IPSEC configuration.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1761667
Major
The rpd process and chassisd process crash is seen
Product-Group=evo
On Junos and Junos Evolved platforms configuring BGP causes the rpd to crash abnormally and later chassisd crashes too.

Resolved In: evo:22.2R3-S3-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.3X80-D45-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.4R3-S10 junos:22.2R3-S3 junos:22.2R3-S4 junos:22.3R3-S2-J2 junos:22.3R3-S3 junos:22.4R3-J6 junos:22.4R3-S1 junos:23.2R1-S1-J7 junos:23.2R2 junos:23.2R2-J14 junos:23.4R1 junos:23.4R2 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: RPD policy options
1807830
Major
OSPF neighbourship with IPsec authentication goes down after RE switchover
Product-Group=evo
On all Junos OS Evolved platforms, the Open Shortest Path First (OSPF) neighbourship configured with Internet Protocol Security (IPsec) authentication will go down during the Routing Engine (RE) switchover.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1808481
Minor
The error message "sysctl kern.corefile not supported" is seen for multiple daemons during daemon initialisation
Product-Group=evo
On all Junos Evolved platforms, while executing "show log messages", error message "sysctl kern.corefile not supported" is seen which is introduced during daemon initialisation.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1819948
Major
LSP re-optimization issue has been observed
Product-Group=evo
On all Junos and Junos Evolved platforms, the LSP (Label Switched Path) re-optimization issue has been observed. LSP bandwidth change is unsuccessful due to bandwidth unavailable RSVP (Resource Reservation Protocol) PathErr.

Resolved In: evo:22.4R3-S5-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D441 junos:20.3X75-D46 junos:21.4R3-S10 junos:22.4R3-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
1823215
Major
Bypass re-optimisation not taking SRLG or fate-sharing into account when protected link is down
Product-Group=evo
On all MX and PTX platforms, In RSVP-TE (Resource Reservation Protocol-Traffic Engineering) scenario, when interface protected by bypass LSP (Label Switched Path) goes down, re-optimization of bypass can leads to unexpected path selection due to non consideration of SRLG (Shared Risk Link Group) or fate-sharing information with respect to protected interface during CSPF (Constrained Shortest Path First) path computation, could result in traffic impact due to this unexpected path selection.

Resolved In: evo:22.3X50-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:20.3X75-D52 junos:22.4R3-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1
1833448
Major
Detours not coming up when link-protection is turned-off while interoperating with ZTE device
Product-Group=evo
On all Junos and Junos Evolved Platforms, an MPLS-TE (Traffic Engineering) interoperability problem exists where Juniper routers misinterpret ZTE's RSVP (Resource Reservation Protocol) Detour backup protection signals, causing unnecessary facility backup attempts and inefficient resource usage. This only impacts networks with both Juniper and ZTE equipment.

Resolved In: evo:24.2R2-EVO evo:25.1R1-EVO junos:24.2R2 junos:25.1R1
PR NumberSynopsisCategory: Issues related to control plane security
1822901
Minor
Junos OS Evolved: Multiple vulnerabilities resolved in OpenSSH
Product-Group=evo
Multiple vulnerabilities in OpenSSH used in Junos OS Evolved have been resolved by applying specific upstream fixes. Please refer to https://supportportal.juniper.net/JSA92873 [juniper.net] for more information.

Resolved In: evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R1-S1-EVO evo:24.4R1-S2-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1825728
Minor
The mgd process crashes while using an FQDN in conjunction with the ephemeral configuration database
Product-Group=evo
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.

Resolved In: evo:21.4X9-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:22.4R3-S4-EVO evo:23.2R2-S2-EVO evo:23.4R2-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S2 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.3R2 junos:24.4R1
PR NumberSynopsisCategory: Issues related to NETCONF
1792554
Minor
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241
Product-Group=evo
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241

Resolved In:
PR NumberSynopsisCategory: ACX7000 platform software related issues.
1856617
Major
PSM Information will not be available for jnxFru OIDs when the module is not installed on the ACX7100-32C device.
Product-Group=evo
PSM Information will not be available for jnxFru OIDs when the module is not installed on the ACX7100-32C device. This is expected behaviour on all EVO platforms.

Resolved In: