Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 23.2R2-S3 is now available for download from the Junos software download site

See TSB94157 [juniper.net] for the list of Known Issues

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 23.2R2-S3 is now available.

23.2R2-S3 - List of Fixed issues 

PR NumberCategory: EX4100 Hardware
1822363
Major
On Junos EX4100 platform, intermittent alarms can occur regarding fan overspeed on the FPCs if they exceed the predefined fan speed threshold. These alarms are regularly activated and deactivated whenever the fan speed crosses the threshold and subsequently falls back below it. There is no service impact due to this
PR NumberCategory: ChassisD changes specific for ACX series
1794939
Major
On all Junos platforms, port goes down after unplugging the 1g copper and plugging 10g fiber and adding interface configuration because after unplugging the 1g copper (where autoneg is supported) , the auto-negotiationg structure does not get cleared and is still gets applied after plugging in the 10g fiber (where auto-negotiation is not supported).
PR NumberCategory: JUNOS kernel/ukernel changes for ACX
1833705
Major
Configuration Archival does not work using SFTP when using the mgmt_junos routing-instance on ACX5448
PR NumberCategory: "agentd" software daemon
1820510
Major
On all Junos and Junos Evolved platforms having JTI (Junos Telemetry Interface)/UDP (User Datagram Protocol) based telemetry, unsupported configuration i.e. "gpb-sdm" is showing a possible completion when the command "set services analytics export-profile format gpb-?" is executed.
1826196
Major
On Junos and Junos Evolved platforms with telemetry enabled, configuring any native sensor path like "set services analytics sensor interface_stats resource /junos/system/linecard/optics " will not be enabled unless "/" is added at the end. This will not have any traffic impact.
1831841
Major
On Junos and Junos Evolved platforms with analytics sensor resource configured, when the CLI telemetry configure command is accepting the resource path even if there is no leading / which is not a valid path results in telemetry streaming is not happening.
PR NumberCategory: access node control protocol daemon
1814300
Major
On all Junos MX platforms with dual RE (Routing Engine), having ANCP (Access Node Control Protocol ) and L2BSA (Layer 2 Bitstream Access) sessions under a scaled scenario (about 10k subscribers), when ISSU (Unified In-Service Software Upgrade) is performed followed by a GRES (Graceful Routing Engine Switchover), it is observed that the port-up messages from ANCP neighbor are dropped either at PFE (Packet Forwarding Engine) or by the ANCP daemon or BBE (Broadband Edge)/autoconf plugin which causes L2BSA sessions to remain down and as a result traffic over the affected subscriber sessions are dropped.
1841954
Major
The "show ancp subscriber detail" command is enhanced to display the port-up / port-down timestamps and port-down cause. It's neither an issue nor a regression an additional display output to enhance debuggability.
PR NumberCategory: Interface related area
1809220
Major
On Junos SRX5400/5600/5800 platforms in cluster, with 40G interface in layer 2 (L2) transparent mode, when the chassis failovers, the interfaces on node0 will remain in a down state and will not come up. The same issue can also occur when node1 failovers to node0.
PR NumberCategory: BBE Advanced Services related issues
1815502
Major
In the subscriber configured scenario along with advanced service (such as cpcd, pcef, hcm....etc) is there, the bbe-smgd crashes on executing show command during RSI output collection.
PR NumberCategory: BBE interface related issues
1741401
Minor
PPPOE and DHCP subscribers over ae went down after performing FPC restart.The issue is subscriber loss happening due to gencfg out of order event where family PPPoE on rtsock ifl is received later and before it corresponding portal flow is received.
1848887
Major
On MX platforms, with routing-services enabled on PPPoE (Point-to-Point over Ethernet) Dynamic Profile, subscriber login fails for new subscribers with specific stacking model.
PR NumberCategory: BBE routing
1826324
Critical
On all Junos and Junos Evolved platforms configured with subscriber management with GRES (Graceful Routing Engine Switchover) enabled, the subscribers will not come up after an ungraceful switchover as RE0( Routing Engine) went down and FPC's rebooted.
PR NumberCategory: BBE Statistics daemon & libraries
1820001
Critical
On Junos MX platforms, when a Stats DB corrupt entry in encountered, several processes related to subscriber management were high like CPU/Memory and statsd and authd both continuously crashing in both REs. As a result subscribers stuck in terminating.
PR NumberCategory: Bi Directional Forwarding Detection (BFD)
1846448
Major
On al MX and PTX platforms, If S-BFD(Seamless-Bidirectional Forwarding Detection) responder is configured without the "lo0.0" on device and with any other "lo0.x " then this S-BFD responder session cannot be distributed to PFE(Packet Forwarding Engine) and fails to come up in distributed mode. Hence BFD service will be impacted.
PR NumberCategory: Border Gateway Protocol
1793714
Major
On all Junos and Junos Evolved platforms, when 'delay-route-advertisements always-wait-for-krt-drain' is configured, the EoR (End of Record) from the source peer of the routes is not received in the BGP (Border Gateway Protocol) peer which is sent by a BGP speaker to indicate the end of a record or a sequence of updates. This is due to the BGP router advertiser being stuck in the wait-for-inbound-convergence state, which may cause the KRT (Kernel Routing Table) queue to get stuck, thereby halting the advertisement of BGP routes.
1807504
Major
On Junos and Junos Evolved Platforms having BGP (Border Gateway Protocol) Multipath when "Multiple Single-Hop EBGP Sessions on different links using the same IPv6 (Internet Protocol Version 6) Link-Local Address" as over multiple links and one of those links is down, the next-hop information which has the smallest IFL (Logical Interface) index interface will get deleted. Since RIB (Routing Information Base) and FIB (Forwarding Information Base) are not correct network traffic will be lost when one of the peer device is down.
1811862
Major
On all Junos and Junos Evolved platforms limit-bandwidth of policy-statement can only be configured to maximum value 4.2G (4294967295) which is not large enough based on actual maximum capacity. user@router# set policy-options policy-statement test then limit-bandwidth ? Possible completions:  Limit advertised aggregate outbound link bandwidth (0...4294967295)
1817834
Major
On all Junos and Junos Evolved platforms configured with the "stale-labels-holddown-period" setting and extensive label configurations (such as Multiprotocol Label Switching labels), the Routing Protocol Daemon (RPD) may crash if stale labels are not cleared periodically and keep accumulating. Due this, temporary traffic impact will be seen until the rpd process restarts.
1818545
Major
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.
1823612
Major
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.. Please refer to https://supportportal.juniper.net/JSA92870 [juniper.net] for more information.
1826686
Major
On all Junos and Junos Evolved platforms, with BMP (BGP Monitoring Protocol) configured, the BGP route gets stuck in a hidden state with the next hop state as 'Next hop type unusable' leading to traffic drop.
1828380
Major
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA92872 [juniper.net] for more information.
PR NumberCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1776453
Major
On all Junos and Junos Evolved Dual RE platforms, After switchover, BMP does not come up when configured with sharding and NSR enabled.
1785723
Major
On all Junos and Junos evolved platforms, the output of command show bgp bmp hangs when rib-sharding is enabled and rpd restarts
1807892
Major
A route can get stuck in 
PR NumberCategory: BBE Remote Access Server
1826901
Major
On all Junos MX platforms, the authd process would crash if it attempts to access the subscriber management database (SDB) while the SDB is undergoing re-initialization due to a problem. Due to this, new subscriber login will be affected possibly for few seconds.
PR NumberCategory: MX304 interface specific 
1830620
Major
On Junos MX304 platform, the FPC (Flexible PIC Concentrators) reboot results in some ports and optics staying in 'Down' state.
PR NumberCategory: MX Platform SW - FRU Management
1801284
Major
On MX platforms with SCBE3-MX (MX240, MX480 and MX960) due to a hardware failure of the Control Board, the Routing Engine(RE) switchover might not happen. This will result in the 19.4Mhz clock failure and has potential risk for chassis wide traffic impact. In worst case all revenue ports will be impacted. If the RE switchover is done in a timely manner then the device will recover because FPCs will try using the 19.4Mhz clock from the new master.
1816912
Major
On Junos platforms, RE detects IIC read or write failures and triggers a minor alarm " RE1 IIC access alarm" during commit operations
PR NumberCategory: Class of Service
1828018
Major
An unrelated commit will trigger flap of protocol adjacencies (BFD, LFM, LACP, etc.) over aggregated Ethernet interfaces if scheduler-map is attached to aggregated Ethernet interfaces (this commit shouldn't necessarily be the first, but it may be). The issue is typically seen only once, the subsequent commits do not trigger further flaps, unless child links of the affected aggregated Ethernet interfaces flap.
1836528
Minor
On all Junos and Junos Evolved Platform, forwarding-class (FC) identifier (id) goes out of sync between the Routing Engine (RE) and Packet Forwarding Engine (PFE) when software upgrade is performed. When In Service Software Upgrade (ISSU) is performed, FC id goes out of sync between the RE and PFE impacting all class-of-service (CoS) features using FC id. When manual software upgrade is performed (without using ISSU) , this issue will be seen as a cosmetic display issue where the order in which the FC configurations are displayed will differ.
PR NumberCategory: CFM
1846960
Major
On Junos Evolved PTX10K platforms, the cfmman memory leaks when CFM remote-mep is configured and adjacency goes down. The cfmman memory leak will crash the FPC.
PR NumberCategory: QFX Access Control related
1826621
Major
On all Junos and Junos OS Evolved platforms configured with a dot1x authentication in single/single-secure supplicant mode, client authentication fails when the dot1x protocol is deactivated and activated back while having active authenticated sessions with Dynamic VLAN and VOIP (Voice Over IP).
PR NumberCategory: OpenSSL and related subsystems
1815253
Major
The OpenSSL project has published security advisories for multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA88107 [juniper.net] for more information.
PR NumberCategory: Platform PR for 1G/10G LC
PR NumberCategory: DNS software support.
1826129
Major
On all Junos SRX and vSRX series platforms Juniper networks Deep Packet Inspection (JDPI) gives events per packet. Domain Name System Firewall (DNSF) plugin is leaking memory while processing those events.
PR NumberCategory: CoS support on DNX
1841079
Major
On all Junos ACX platforms , When VPLS (Virtual Private LAN Services) routing instance is used and HQoS (Hierarchical Quality of Service) scheduler is configured and all the IFLs (Logical Interfaces) over the same IFD (Physical Interface) and each IFL is configured with different VLAN (Virtual Local Area Network). The BUM (Broadcast, unknown-unicast and multicast) traffic sent of one IFL is getting flooded to all the IFL's.
PR NumberCategory: DNX Multicast
1799619
Major
On Junos ACX5448 and ACX710 platforms, if IGMP (Internet Group Management Protocol) snooping is enabled, arrival of IGMP Query packet on a port where IGMP Join packet was previously received may lead to an inconsistency in NHDB (Next-Hop Database) and eventually trigger a core dump of acx-arm-feb process.
PR NumberCategory: Segment Routing PFE part for v4 + SR-TE
1816807
Major
On Junos ACX2K, ACX5448, and ACX710 platforms in an l2circuit (Layer 2 Circuit) scenario with MPLS (Multiprotocol Label Switching) or any other labeling protocols configured as transport, when a non-active path is shut/disabled the l2circuit traffic blackholing will be observed.
PR NumberCategory: Dynamic rendering infrastructure
1745615
Major
On all Junos and Junos OS Evolved platforms configured with SR-ISIS(Segment Routing-Intermediate System to Intermediate System) and with gRPC/gNMI telemetry, subscription to the path: "/junos/services/segment-routing/sid/usage/" will not work and the output could not be proper. The issue could happen only in scaled configuration (Approximately, 4000 or more per-sid ingress sensors and 4000 or more IPv4/IPv6 per-sid egress sensors are configured).
PR NumberCategory: Ethernet OAM (LFM)
1811734
Major
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.
PR NumberCategory: Firewall related development
1815533
Major
On EVO QFX platforms, when the destination/source-port-range-optimize feature is configured and it matches a value greater than 255, the firewalld process will crash and a core dump is raised.
PR NumberCategory: mgd, ddl, odl infra issues
1825793
Minor
"show system configuration rescue" may show strange "Last changed" timestamp. It may happen under any time zone potentially and looks like there are some patterns. In case of "Asia/Tokyo", Last changed timestamp may show "1970-01-01 08:59:59 JST".
PR NumberCategory: EVPN control plane issues
1816672
Major
There are multiple EVPN instances each having separate IFL of AE IFD. AE is configured with per-esi lacp-oos-on-ndf on the AE IFD. On deactivating one of the instances, LACP on non-DF router comes out of "out-of-sync" state, causing CE device to move to Collecting distributing.
PR NumberCategory: EX interfaces issues
1805370
Major
On Junos EX4400-48F platform only after replacing a 100 MB SFP endpoint device for a 1 GB SFP the switch port doesn't come up.
1814093
Major
On all EX4100 and EX4400 platforms with mge ports, the mge (multi rate gigabit ethernet) port shows up but does not allow traffic to pass through after port initialization or port flap.
PR NumberCategory: Issues related to EX MACsec
1830395
Major
On all Junos and Junos Evolved platforms, when authentication-key-chain-name is configured with more than 31 characters, commit error is seen due to which MACSEC will not work with the configuration.
PR NumberCategory: EX Entry Level Access VC platform
1806262
Major
On all EX4100 and EX4400 platforms configured in virtual-chassis mode and set to HGOE (HiGig over Ethernet), changing the port type from vc-port to network port causes the network port to stay down and traffic loss is observed.
PR NumberCategory: Express PFE FW Features
1830706
Major
On all Junos platforms, when a filter instance is modified or deleted, there should not be any old Packet Forwarding Engine (PFE) instances. However, during these operations, old PFE instances are being incorrectly assigned, resulting in incorrect memory address allocation. This leads to an Flexible PIC Concentrator (FPC) crash after committing the configuration, causing traffic loss.
PR NumberCategory: Express PFE including evpn, vxlan
1814387
Major
In the EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) scenario on Junos QFX10K platforms, if the Layer 3 unicast and VTEP (VXLAN Tunnel Endpoint) next hops are both enabled for the same destination, traffic drop will be observed.
PR NumberCategory: Express PFE Services including JTI, TOE, HostPath, Jflow
1830575
Major
On all Junos platforms, the dcpfe crash is seen with a core-dcpfe dump when the ukern_trace handle buffer size is set to 10000. It is a rare issue.
PR NumberCategory: Express PFE L2 fwding Features
1792128
Major
On Junos QFX 10K platforms, traffic drop is seen when multiple interface logical (IFLs) of different families are configured on the same interface physical (IFD) with Service Provide (SP) style configuration and layer 2 (L2) ILF is the first IFL to be created.
PR NumberCategory: SRX1500 platform software
1845143
Major
On the Junos SRX1500 platform, the device reboots spontaneously because the watchdog is triggered unnecessarily.
1845407
Major
On SRX1500, "show snmp mib walk jnxOperatingTemp" and "show snmp mib walk jnxFruTemp" will not show up temperature reading for PSU temperature.
PR NumberCategory: SRX4100/SRX4200 platform software
1814404
Major
An Improper Handling of Exceptional Conditions vulnerability in the command-line processing of Juniper Networks Junos OS on SRX1500, SRX4100, and SRX4200 devices allows a local, low-privileged authenticated attacker executing the 'show chassis environment pem' command to cause the chassis daemon (chassisd) to crash and restart, resulting in a temporary Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA92864 [juniper.net] for more information.
1823978
Major
On Junos SRX platforms, due to common cache feature, more accurate IP address resolutions are being updated to the PFE (Packet Forwarding Engine). However, this led to increased CPU utilisation by the nsd (Network Services Daemon) process. Due to high CPU load, the newly resolved IP addresses may not be updated promptly to PFE leading to traffic loss.
PR NumberCategory: idp flow creation, deletion, notification, session mgr intfce
1825279
Major
On all SRX platforms, srxpfe (SRX Packet Forwarding Engine) process may produce coredumps and traffic drops may be observed under heavy traffic processing by IDP (Intrusion Detection and Prevention).
PR NumberCategory: MX10K LC2101 Timing
1754400
Major
On Junos MX platforms, timingd might become stucked on master RE; however, when master RE is switched to backup RE, this issue is not seen.
PR NumberCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1787707
Major
On Junos ACX710 platform with BGP (Border Gateway Protocol) configuration, the response message will be lost and it will lead to element being stuck in the KRT (Kernel Routing Table) queue.
1826194
Major
On all Junos and Junos Evolved platforms, rpd crash is observed during upgrade or restart since kernel takes more time to update ifstate information.
PR NumberCategory: MX Inline Jflow
1813925
Major
On all MX platforms with MPC10/MPC11/LC9600, MX304 and EX9200-15C platforms, when any sensor configuration on protocols, for example, MPLS LSP, is configured and removed over a long period, the aftd-trio process starts a memory leak and eventually causes FPC to reboot.
PR NumberCategory: IoT data filtering/streaming
1830246
Major
On SRX platforms when the dynamic filter is configured, the packet forwarding engine (PFE) crashes, impacting traffic.
PR NumberCategory: ISIS routing protocol
1760334
Major
On Junos and Junos Evolved platforms, routing loop will be observed, when configuring FRC (Flood-Reflector Client) and processing anycast Layer 2 prefix advertisements, it leads to the installation of ISIS routes with incorrect nexthops .
1808185
Critical
On Junos and Junos Evolved platforms with SRv6 (Segment Routing IPv6) and ISIS (Intermediate System-to-Intermediate System) configured, the rpd (Routing Protocol Process Daemon) crash is observed for the leaked ISIS SRv6 locator route holding a stale pointer when SRv6 locators are leaked across ISIS multi-instances (standard and non-standard) and also if changes to these locators are too frequent.
1837289
Major
On all Junos and Junos OS Evolved platforms configured with "protocols isis overload advertise-high-metrics" (without timeout) and graceful-restart, IS-IS (Intermediate System to Intermediate System) will start advertising high link metrics immediately as expected. However, when IS-IS is in graceful restart mode either via GRES (Graceful Routing Engine Switchover) switchover or restart routing, the high link metrics are not advertised and IS-IS continues to advertise the usual link metrics even when IS-IS graceful restart is completed. When the issue is hit, the node configured as an overload might be used for transit traffic based on the IGP metric.
1841108
Major
On all Junos and Junos OS Evolved platforms, in an ISIS(Intermediate System-Intermediate System) graceful restart scenario, helper node sends and programs its locally configured hold-time (180 secs) instead of the "Restart-duration" received as hold-time from DUT (210 secs), due to this incorrect update, the hold timer expires at the helper node before the GR (Graceful Restart) is complete on DUT and it causes a flap of ISIS adjacency on peer/helper Node.
PR NumberCategory: track re issu control procedure bugs
1740744
Major
On Junos platforms, when ISSU (in-service software upgrade) is initiated, a process called INDB (Incompatible Database) will be triggered to perform a pre-check on database compatibility. There could be some corner case that causes the INDB crash. If that happens, the ISSU should be aborted.
PR NumberCategory: jdhcpd daemon
1799888
Major
On all Junos MX platforms configured with primary pool, with BBE (Broadband Edge) subscriber management and ALQ (Active-Leasequery) enabled with different DHCP (Dynamic Host Configuration Protocol)-attributes within the linked address-assignment pools and with no radius server configured, in a corner case scenario, it is observed that when L2 (layer 2) failover happens, the client gets the subnet from primary pool and not from linked pool as it should and linked address-assignment pool name is not synced to the DHCP binding on the backup BNG (Border Network Gateway). This causes default gateway and other attributes to be wrong. So when existing CPEs (Customer Premises Equipment) send DHCP renew, they receive wrong DHCP default gateway and other attributes and that causes traffic drop.
1825998
Major
On all Junos OS and Junos OS Evolved platforms , In a rare scenario when memory leak happens the Dynamic Host Configuration Protocol (DHCP) active-leasequery (ALQ) process crashes automatically.
PR NumberCategory: To track issues related to jsf tcp proxy
1834248
Major
On all MX and SRX Junos platforms, during tcp session, where tcp-proxy gets engaged, the flowd process crash occurs when the server tries to terminate the connection before the 3-way handshake is complete. The flowd process crash is seen, resulting in a total traffic impact.
PR NumberCategory: Flow Module
1761542
Major
On SRX platforms, in a chassis cluster setup configured in Active/Active mode, the fabric forward packet enters the flow module causing the flow processing daemon (flowd) to crash, impacting the traffic forwarding and failing the Services Processing Card (SPC).
1807505
Major
On SRX5000 series and SRX4600, the setting "set security flow tcp-session time-wait-state apply-to-half-close-state" is not taking effect for sessions that are using express path (services-offload). This may lead to an increased number of sessions compared to earlier Junos releases which did not have an express path enabled by default.
1828819
Major
Application quality of service (AppQoS) rate limit in PowerMode IPsec (PMI) mode on Junos SRX5K and SRX4600 drop packets unexpectedly due to internal issue.
PR NumberCategory: SRX Firewall Authentication
1829894
Major
On all SRX platforms, when a user tries to authenticate to a captive portal to get access to resources, the authentication is successful, but the user is rerouted back to the captive portal with no resources access.
PR NumberCategory: JSR Infrastructure
1794303
Major
On SRX4600/SRX5400/SRX5600/SRX5800 series in cluster setup, when performing ISSU upgrade to release 23.1 or more the dfwd core will be seen which will not create any service impact. However ISSU happened successfully and cluster setup booted with latest image and firewall is working fine.
PR NumberCategory: Firewall Network Address Translation
1829549
Major
On all SRX platforms the use of address set (IP address) and address book (FQDN - Fully qualified domain name) in the same NAT (Network Address Translation) rule causes a nsd process crash.
PR NumberCategory: Firewall Policy
1844191
Major
On all SRX platforms, if has one DNS server which was unresponsive and another which refuse responses or responds with a non-positive error code, the FQDN-based security policies will not work as expected and packets might hit a different allow/deny rule.
1847877
Major
On all SRX platforms, the Management Daemon (mgd) core is seen after a large number of configurations executed when configuring the network address book and attach it to a security policy.
PR NumberCategory: IPSEC/IKE VPN
1788195
Major
On vSRX 3.0 platforms with vSRX/GCP (Google Cloud Platform) key-ring fail to sync-up which cause continuously state swaps which causes integrity failure.
1794895
Major
On Junos SRX platforms with a cluster, when a high volume of traffic is observed, high CPU (Central Processing Unit) usage might be seen from the SPUs (Security Processing Units). The FPC (Flexible PIC Concentrator) may reboot, and the IKE SAs (Internet Key Exchange Security Associations) may be cleared and timed out, preventing the VPNs (Virtual Private Networks) from failing over and causing a traffic impact.
1804965
Major
On certain SRX platforms using iked (Internet Key Exchange Protocol Daemon) with IPsec (Internet Protocol Security) and MNHA (Multi-Node High Availability) configured, traffic loss can occur when the VPN (Virtual Private Network) service-redundancy-group becomes active and there is an inconsistency between the VPN configuration in the iked and the service-redundancy-group database. This issue arises if the reconciliation process takes over 5 minutes and the VPN service-redundancy-group switches to backup before completing the reconciliation, especially with a high number of VPN tunnels (up to 16, 000) and VPN IKE traceoptions set to the highest level.
1817228
Major
On all Junos platforms that run kmd process, IPsec VPN tunnels experience traffic disruption after a change of authentication protocol (ESP is change to AH or vice versa).
1818197
Major
On SRX platforms, if the outgoing interface of the Internet Protocol Security (IPsec) Virtual Private Network (VPN) peer goes down when the peer device operates in the Network Address Translation-Traversal (NAT-T) environment and the default route points to the secure tunnel interface (st0), there are chances of an internal routing loop which will lead a srxpfe process crash caused by the Memory Buffer (mbuf) corruption.
PR NumberCategory: Security platform jweb support
1788364
Major
If session limit not configured in cli, default value of session limit will be 7 for Seige models and 1024 for other models
1837925
Major
On Junos SRX (SRX1500, SRX4600, SRX4100 and SRX5K's) platforms, image upload via J-Web fails with an error "Access Error: 502 -- Bad Gateway".
PR NumberCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1776782
Major
On Junos or Junos OS Evolved platforms which supports EVPN-MPLS/EVPN-VXLAN, device will not reply for ARP (Address Resolution Protocol) requests when source MAC (Media Access Control) of ethernet header and ARP source MAC are different and ARP target address are exists in mac-ip-table. Traffic drop will be seen.
1822911
Major
On all Junos platforms configured in EVPN (Ethernet Virtual Private Network) scenario with AE (Aggregated Ethernet) interface and esi "auto-derive type-3-system-mac" knob, if an IRB (Integrated Routing and Bridging) interface is activated or deactivated the link aggregation interfaces ( IFL) will get flapped due to which interface traffic gets impacted.
1824739
Major
On platforms with MPC10, MPC11, LC9600 and MX304-LMIC line cards, during a transition from VPLS (Virtual Private LAN Services) to EVPN (Ethernet Virtual Private Network) or when the MAC (Media Access Control Address) addresses move from a local to a remote state, control MAC addresses are incorrectly programmed in the hardware, leading to traffic duplication and unresolved destination errors.
PR NumberCategory: Label Distribution Protocol
1812545
Major
On all Junos and Junos OS Evolved platforms, complete service impact will seen because of the rpd crash on using match condition "from instance " for LDP ( Label Distribution Protocol) entropy-label policy-statement under "set protocols ldp entropy-label ingress-policy .
1835938
Major
In a NG-MVPN (Next Generation - Multicast Virtual Private Network) scenario where mLDP (Multipoint Label Distribution Protocol) is used for multicast MPLS (Multi Protocol Label Switching) label signalling and BGP (Border Gateway Protocol) is utilised to reach the LDP (Label Distribution Protocol) point-to-multipoint root address, a high BGP scale along with short uplink interface flaps cause the LDP point-to-multipoint FEC (Forwarding Equivalence Class) to remain in an inactive state. This can lead to point-to-multipoint traffic drop and impact multicast services.
PR NumberCategory: Issues related to Junos licensing infrastructure
1759618
Major
On Junos OS Evolved platforms, when license with unknown feature ID/platform reserved feature ID is added via configuration set system license keys key and then if License-service is restarted or system is rebooted or software upgrade is done then license service crashes and crash files are seen. This is a non service impacting issue.
1792672
Major
On NG-RE (Next Generation Routing Engine) platforms, license is lost after restarting device/routing-engine. If any service depends on that license, that service will be impacted.
PR NumberCategory: lldp sw on MX platform
1811545
Major
When LLDP is configured on interface all and there are AE interfaces configured, to disable LLDP on one of the AE "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, AE is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.
PR NumberCategory: Port-based link layer security services and protocols that a
1757100
Major
On all Junos MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16, the statistics for MACSEC (MAC Security) are not displayed properly and lead to memory not getting freed. In a scaled environment of IFLs with MACSEC configured, eventually leads to AFTd-Trio daemon crash due to memory exhaustion.
PR NumberCategory: SW PRs for MPC10E Interfaces
1847378
Major
If interfaces on MPC10E card are configured with hold down timer and the link hit a short flap then it may take additional time for that link to be up. It cause interruption for traffic as well as control plane protocols which are enabled on that link, for example BFD, OSPF, LACP and etc .
PR NumberCategory: MPC11 ULC fabric software related issues.
1802259
Critical
On MX2020/MX2010 platforms having SFB3, traffic drops will be observed due to multiple PFEs (Packet Forwarding Engine) getting disabled or blackholing traffic. This issue happens when an SFB3 comes up online after an ungraceful offline followed by a master SPMB reboot leading to fabric Link errors.
1807410
Critical
On MX2020 and MX2010 platforms, during fabric link training, if the SFB (Switch Fabric Board) suddenly shuts down due to a power off or being unplugged at a specific moment, a SPMB (Switch Processor Mezzanine Board) crash can be seen. It is a timing issue
PR NumberCategory: Multiprotocol Label Switching
1744584
Major
On all Junos and Junos OS Evolved platforms, whenever a soft preemption reroute request arrives in the middle of the ongoing make-before-break, traffic loss would be observed which is still referring to the old instance.
1814358
Major
On Junos and Junos Evolved platforms with RSVP-TE (Reservation Protocol-Traffic Engineering) configured, when IGP (Interior Gateway Protocol) "overload" is configured on the transit router, the traffic should move away from the transit router. But in the issue scenario, the LSP (Label Switched Path) continues to stay across the transit router which has been marked as overload and traffic continues across the transit router resulting in traffic drops or using the suboptimal path for the LSP. The issue happens when Patherr is received for the re-optimized path and CSPF (Constrained Shortest Path First) computation is triggered before the backoff timer.
PR NumberCategory: Multicast for L3VPNs
1747703
Major
On all Junos and Junos Evolved platforms with Dual RE and MVPN ((Multicast Virtual Private Network) enabled, when the user initiates a GRES ( Graceful Routing Engine Switchover) switchover, it triggers a route change from the MVPN . During this process, there's a gap where traffic loss is observed because the flood next hop pointed to by the route gets deleted.
PR NumberCategory: Track Mt Rainier RE platform software issues
1776854
Major
PR1735843 has fixed a VM core on ACX5448 platform with the reason "panic: deadlres_td_sleep_q: possible deadlock detected". The same issue might also be seen on all other JUNOS vmhost platforms but with a different root cause.
PR NumberCategory: Odin Timing software
1810429
Major
In a scenario where two T-GM devices (Telecom Grandmaster clocks) have identical BMCA (Best Master Clock Algorithm) parameters, except for steps removed or grandmaster ID, the ACX710 running the G.8275.1 profile can experience a failure in proper PTP (Precision Time Protocol) clock synchronization. This issue arises because the default BMCA is used instead of the expected Alternate BMCA profile in G.8275.1. This mismatch leads to incorrect PTP clock states, with master ports being marked as 'Passive' instead of 'Master'.
1829340
Major
ACX710 Junos Platforms reports error clksyncd-service subsystem is not responding to management requests after any new configuration commit causing clksyncd CLI to stuck affecting IPC (Interprocess communication).
PR NumberCategory: build tools
1789272
Major
On EX2300-MP platforms, when the SPI (Serial Peripheral Interface) bus is accessed by multiple processes simultaneously results in watchdog reset due to the lack of lock-unlock operations. Consequently, this can lead to interface flaps affecting the traffic flow.
PR NumberCategory: FreeBSD Kernel Infrastructure
1592495
Major
On EX2300/EX3400/EX2300-48MP platforms, the recovery snapshot creation fails due to a lack of storage on the Operations, Administration, and Management (OAM) partition.
1800020
Minor
On all Junos EX 64-bit/32-bit ARM platforms(EX2300/EX3400/EX4100), the image installation should fail when ARM 64-bit image tried to install in ARM 32-bit hardware and vice-versa. But the device proceeds with reboot and installation of the image and get stuck in u-boot after reboot. There will be complete service impact if install gets to reboot.
PR NumberCategory: PFE Peer Infra
1801535
Major
On all Junos platforms, CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log. This log is not an error log but still printed under LOG_ERROR and flooded with default log level. This causes restart which will impact normal user traffic.
PR NumberCategory: Express Paradise PFE Sflow
1803542
Major
Recurring logs -ppcfpc-multi-svcs.elf: FDB :: Ipv4 route operation 2 failed. Rt_index are seen in PTX10008 after upgrade
PR NumberCategory: Path computation client daemon
1823220
Major
When MD5 is configured for PCEP (Path Computation Element Protocol) on Junos OS Evolved platforms, MD5 will not work for other protocols after reboot. Authentication failure will be seen and it causes a connectivity issue or a service impact.
PR NumberCategory: Phone-Home-Client Infrastructure
1828735
Major
As PHC is expected to be run before onboarding, it is assumed, no user would run "ping" in CLI. So as a cleanup mechanism, the PHC script which is part of the factory default configuration kills all ping processes before it can check connectivity with its gateway.
PR NumberCategory: Issues related to PKI daemon
1801377
Minor
On all Junos OS Evolved platforms, a pkid (Public key infrastructure daemon) process crash is observed every time a periodic auto CDN (Content delivery network) query to download the latest trusted CA bundle takes place (every 24 hours by default)
PR NumberCategory: vMX Platform Infrastructure related issue tracking
1824497
Major
On MX150 platform, libvirtMib_subagent core dump will be created in /var/crash/ folder after every reboot.
PR NumberCategory: QFX access control list
1823280
Major
On EX and QFX5K series switch with egress filters configured in the system, you may observe dfw error whenever collecting RSI.
PR NumberCategory: QFX5K hostpath
1827299
Major
On Junos QFX5k and EX4k platforms with IPv6 (Internet Protocol Version 6) PTP (Precision Time Protocol) configured, PTP synchronization issue will be observed due to IPv6 PTP packets are getting dropped i.e. blocked by PFE (Packet Forwarding Engine) filter resulting in downstream devices losing PTP status. This issue happens when IPv6 address with specific range is configured.
PR NumberCategory: QFX L2 PFE
1820830
Major
On Junos QFX and EX platforms in an EVPN-VXLAN (Extended Virtual Private Network- Virtual Extensible LAN) CRB (Centrally-Routed Bridging) scenario where the ingress leaf switch is configured with ESI (Ethernet Segment Identifier) lags (i.e. the server is multihomed), if there is an overlap between ESI lag(s) trunk ID with physical port number(s) and overlap of DMAC (destination MAC) between VGA (Virtual Gateway Address) MAC address 00:00:5e:00:01:01 (CRB setup with VGA / GW is on spine) with VRRP (Virtual Router Redundancy Protocol) MAC (specifically for the VRRP group 1 MAC address 00:00:5e:00:01:01) on the physical ports of the Leaf switches, then traffic loss will be observed for the inter-VLAN traffic.
1822251
Major
On QFX5100, EX4600, QFX5110, QFX5200, QFX5210 platforms (VC and standalone), MAC address may get into stuck in hardware. As a result, traffic is black-holed.
1824750
Major
On EX4K/QFX5K VC (Virtual Chassis) with RTG (Redundant Trunk Group) enabled, if one of the VC members is rebooted without any RTG member link, the VC will start sending the traffic in the backup link. Forwarding of traffic on the backup link which is not supposed to forward the traffic will lead to storm in the network.
PR NumberCategory: QFX L3 data-plane/forwarding
1789507
Major
On all Junos QFX5120 and EX4650 platforms the NH(Next-Hops) are not getting uninstalled from the FPC(Flexible PIC Concengrator) L3(Layer 3) Next Hop table. This issue applies to both standalone and VC (Virtual Chassis) setups and can been in MPLS(Multiple Protocol Labeled Switching) setup with Node/Link protection enabled and is triggered by network churn which causes a change in LSP (Labeled Switch Path).
1818740
Major
On Junos QFX5K series products enabled with multicast service, multicast forwarding traffic abruptly ceases after rebooting the device due to routes get in discard state. It affects multicast forwarding traffic because of the loss of multicast packets.
PR NumberCategory: QFX EVPN / VxLAN
1771445
Major
On Junos QFX5110 platforms, and while having configured 'native-vlan-id' and 'vlan-id-list' combined under an interface , untagged traffic gets dropped
1796210
Major
On all Junos QFX5K and some specific EX4K in EVPN-VxLAN (Ethernet VPN-Virtual extensible LAN) environment with underlay connections using Virtual Chassis Port Link Aggregation with AE (Aggregated Ethernet) interface and during one of the spine reboot, traffic will not be immediately switched to another spine and traffic blackholes.
1810169
Critical
On Junos QFX5120 platforms, when MLD (Multicast Listener Discovery) snooping is enabled, IPv6 NS (Neighbor Solicitation) packets received on the network port are not forwarded to the access port. This issue is caused by a VXLAN (Virtual Extensible Local-Area Network) configuration that incorrectly redirects these packets back to the network port using an RedirectIPMC action. As a result, IPv6 ND (Neighbor Discovery) fails to complete, leading to IPv6 pings not working on the network port and disrupting IPv6 traffic.
1818022
Major
On Junos OS Evolved platforms, when ELP (Egress link protection) is present on one device and not present on it's connected device(s), it causes any new L2 (Layer 2) functionality (e.g. new VLAN creation, updating L2 message, etc.) to not work. As there is no ELP configuration on the other device, it blocks l2ald ( layer 2 addressing learning daemon) event queue. This impacts the L2 functionality of the other node where ELP is not configured.
1819073
Major
On Junos QFX5120/EX4650/EX4400/EX4100 platforms with pure EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) Type-5 tunnel (i.e. no type-2 tunnels), the VXLAN encapsulated packets received over Type-5 tunnel will be dropped, which will impact the traffic.
1820318
Major
On Junos EX and QFX platforms, when IGMP (Internet Gateway Monitoring Protocol)/MLD (Multicast Listener Discovery) snooping is configured on AE (Aggregated Ethernet) for which FRR (Fast Rerouting) is enabled, the snooping functionality breaks.
1842475
Major
On Junos OS QFX5k and EX4k platforms having EVPN-VxLAN (Ethernet VPN - Virtual Extensible Local Area Network) configured, traffic drops are observed due to missing hardware programming caused by stale hardware entries leading to VTEP (Virtual Tunnel Endpoint) Destination IP-address is not updated properly. The issue is observed due to VPLAG (Virtual Chassis Port Link Aggregation) flaps (any incident, such as a reboot of the gateway device / remote device) causes VPLAG to uninstall and install.
PR NumberCategory: QFX10008/16 QFX10002 linecard, serdes and uboot
1782441
Major
"pechip_mac_stream_update_fault|SNMP_TRAP_LINK_DOWN.*et|SNMP_TRAP_LINK_UP.*et" are observed in the output of "show log messages". These log entries indicate that the ports are flapping.
PR NumberCategory: QFX5200/5110/5120/5210 ISSU Infrastructure
1703229
Major
When TISSU upgrade is done from 22.4 release onwards, the box come up as backup RE.
PR NumberCategory: QFX5200/5110/5120/5210 Platfom issues
1795540
Major
After the upgrade, the interface on QFX5110 platforms flaps randomly with QSFP-100G-PSM4 optics present. This can lead to a traffic drop. This is a very corner case issue.
PR NumberCategory: rosen-6 and rosen-7 mvpn bugs
1736328
Major
This is a day one code and is seen only in the scale setup with specific configuration with both l2vpn and rosen mvpn configuration present, when the scale configurations are done and then deleted (load baseline config). As per existing implementation, the MDT table though not required for l2vpn instances was being created and this code has been there since day one and in normal cases this should not create any issues. However in this scaled configs setup, when all configs were deleted, bgp global and group specific tables were getting to inconsistent state specifically for the MDT table and hence the issue.
PR NumberCategory: KRT Queue issues within RPD
1805427
Minor
On all Junos platforms, due to timing issue during the restart of the rpd process may cause it to crash. This can temporarily impacts traffic until the process recovers.
1817807
Major
On all SRX platforms, after the In-Band Cluster (ICU) upgrade if the system has routes pointing to the secure tunnel interface (st0) interface, or on clearing security IPsec sa on peer router a few routes might have trouble getting installed in forwarding, impacting traffic on the routes that are not installed after the upgrade.
PR NumberCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1808463
Major
On all Junos and Junos OS Evolved platforms in a corner case, the Routing Protocol Daemon (rpd) CPU utilization will be seen high in scenarios where recursive route resolution is involved. The rpd process will be continuously spinning in the re-resolution job which could impact scheduling of other jobs and re-resolution of other routes impacting traffic.
1810866
Major
On Junos OS Evolved platforms, the rpd (Routing Process Daemon) crash i.e. traffic impact is observed due to a segmentation fault. The issue happens when the rpd sends an add request for the same next-hop ID for multiple routes/unicast next-hops with the same prefix and points to a discard interface. The rpd doesn't expect the same next-hop ID for multiple routes/unicast next-hops.
PR NumberCategory: Issues related route resolution routing infrastructure
1818978
Major
On all Junos and Junos Evolved platforms, "preserve-nexthop-hierarchy" knob configured with Virtual Private LAN Service (VPLS), causes the Layer-3 (L3) control packets like that of Border Gateway Protocol (BGP) / Open Shortest Path First (OSPF) running over Integrated Routing and Bridging (IRB) interface to be dropped and brings down the protocol sessions.
PR NumberCategory: show route table commands, tracing, and syslog facilities
1812009
Major
On all Junos and Junos OS Evolved platforms, when there is any catastrophic changes made in the configuration without deactivating a particular routing instance will lead to the rpd process crash.
PR NumberCategory: Resource Reservation Protocol
1840543
Major
On all Junos and Junos Evolved platforms, when RSVP (Resource Reservation Protocol) LSP (Label Switched Path) is configured to perform loose hop expansion by enabling "expand-loose-hop" under MPLS (Multi-Protocol Label Switching) LSP knob and "graceful-restart" is configured in routing-options, rpd crash can be seen if it is undergoing graceful restart, causing service impact.
PR NumberCategory: N/A:sw-scbe3-timing
1742266
Major
In a rare occation, an MPC, or an SCB3's hardware clock synchronization PLL module may locked up and not be able to lock on to the clocking signal during holdover, resulting in PTP or SyncE failure. The change in this PR raises a "PLL Core Frozen" major alarm so the system can react to this by raising an alarm, and rebooting the affected MPC, or the SCBE3.
PR NumberCategory: Scuba fabric software
1807812
Critical
During ungraceful Peer-SFB/Peer-FPC offline or due to a bad fabric link XM ASIC based FPCs can hit CPQ Underrun Major error on an unused queue resulting in PFE Disable action. This PR fixes the underlying reason for the CPQ Underrun error and prevents PFE from being disabled.
1811474
Major
On Junos MX platforms specifically MX2010 and MX2020 with SFB2 (Switch Fabric Board) Fabric installed, after inserting and powering on a new MPC6E in slot (swapping specifically with MPC9E linecard), fabric get into check state and all FPCs goes as unreachable destinations and gets offlined. Due to this, traffic loss can occur.
PR NumberCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1783745
Major
On Junos MX platforms with MS-MPC(Multiservices Modular Port Concentrator) line cards, with Network Address Translation (NAT) and PBA(Port Block Allocation) enabled, multiple times deletion of service-sets configuration, will lead to PFE (Packet Forwarding Engine) may restart due to which mspmand cores and MPC goes offline and during this interval, there is a drop in traffic.
PR NumberCategory: Bug and Review Tracking for Segment routing traffic eng
1820791
Major
Per-Segment-list telemetry for colored tunnel doesn't work on PTX-Series platform with Junos OS Evolved such as PTX10004, PTX10003, PTX10001, but it works on PTX10008 and PTX10016.
PR NumberCategory: all ipv6 vpn/tunnel bugs on srx platforms
1827426
Major
On All SRX platforms, If the assigned IPv6 address length is more than 12 bytes and the previous assigned address's first 12 byte matches with the new assigned address, then the old IKE (Internet Key Exchange) tunnel will be deleted and a new connection will come up even though the address is different and this causes session to flap. IPv6 address can be of variable lengths.
PR NumberCategory: Remote Access VPN issues on SRX
1825573
Major
On all SRX platforms, if a loopback interface is configured as an external interface in Internet Key Exchange (IKE) gateway and there are one or more loopback addresses configured without an IPv6 address configured against it, remote access solution will not work, and Juniper Secure Connect (JSC) will report an "HTTPS request failed" error.
PR NumberCategory: SRX branch platforms
1747849
Major
On SRX-branch series platforms, configuring the "set system processes watchdog " command causes a commit kernel panic i.e. device will get stuck, and traffic loss will be observed. Watchdog related commands are unsupported.
1819054
Major
On Branch SRX platforms the contents of ~root/.ssh directory is deleted on every reboot. This can cause issues with SSH issues as locally stored public and private keys are deleted (stored on ~root/.ssh by default)
1841080
Major
On SRX380 platforms configured for packet-mode operation and an IP address is assigned to xe (10 Gigabit ethernet) interfaces, the interface link status will go to down state.
1848557
Major
On SRX380 platforms, the local interface status or the peer device's interface reflects down after SRX380's reboot when both devices are configured with auto-negotiation on the SRX380's 4x10GbE ports.
PR NumberCategory: Stout card (MPC7) fabric issues
1808923
Major
On all MX platforms, if there is persistent link error or training failure at fabric link between Switch Fabric Boards/ Switch Control Board (SFB/SCB) and a Packet Forwarding Engine (PFE) at one Flexible PIC concentrator (FPC) in some fabric plane then once another FPC in a different slot comes online, it will be sending traffic to the PFE over that link with error for a short period of time and then the FPC which is just brought online will declare destination errors towards that PFE and the Fabric plane with error will be removed from fabric spraying masks. This can result in temporary traffic loss.
1812276
Critical
On MX2010/MX2020 platforms with non-native LCs installed with an ADC, if a non-native LC PFE erroneously starts sending the traffic to a remote PFE using some fabric plane with link error towards that remote PFE, then this traffic will build up at the sending LC ADC, which cause the traffic blackholing to the remote PFE over all fabric planes.
PR NumberCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1806526
Major
On Junos MX platforms, PLL gets frozen because of the Hardware failure but still advertises the GM provided clock-class leading to synchronization failure and potential service impact. This affects clock signals distributed to all devices on the line-card, resulting in service degradation. The issue affects line-cards from MPC3E to MPC10E, chassis with SCBE3, and platforms such as MX10003 and MX204.
PR NumberCategory: MX10003/MX204 Platform SW - Chassisd s/w defects
1818517
Major
For MX10003 fan min and max threshold were -40 and +20 set. If fan RPM goes below/beyond those RPM, s/w start raising alarms. Similarly for MX204 fan min and max threshold were -20 and +20 set. On log analyzing, its seen FAN RPM was running +34% , that was beyond ma threshold. After discussing with h/w team, min & max threshold values are now decided -40 and +40. Due to this FAN RPM will be in bandwidth and no alarm will be seen.
PR NumberCategory: SRX-1RU infrastructure SW defects
1839346
Major
On SRX4600 platform with chassis cluster, after performing an ISSU (In-service Software Upgrade) upgrade, the SPM (Secure Port Module) (fpc 0) against the node that is upgraded first will experience issue states where it can either cycle through 'Present' or 'Offline', or it will not report any errors but will be unable to perform any PFE (Packet Forwarding Engine) functions such as session management i.e. wont be able to process traffic resulting in traffic impact.
PR NumberCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1823577
Major
On SRX4600, in rare cases with heavy traffic, the FPGA may drop packets.
PR NumberCategory: ZT/YT pfe qos software issues
1793375
Critical
On all MX platforms having MPC10 or MPC11 having class-of-service configured, it is observed that in a scaled scenario (1500 IFLs (Interface Logical)), when queues are oversubscribed and the output interface starts to get congested, "CMERROR 0x230063 " or "XQSS_CMERROR_SCHED_QL4_INT_REG_DQU_QSUM_UDR" error message is seen. These cm errors would result in PFE (Packet Forwarding Engine) disable or the action configured in the device.
PR NumberCategory: ZT/YT pfe firewall software
1840815
Major
After rebooting chassis or fpc, L2 policer may not work sometimes due to not reflecting configuration properly.
PR NumberCategory: Trio pfe stateless firewall software
1800623
Major
On MX platforms with MPC10/MPC11/JNP10K-LC9600 and MX304 platforms, if the switch port utilization is above 80%, then traffic matches with any firewall filter that is configured with log/syslog firewall action on it, leading to the wedge condition. In that wedge condition, if any commit operation is performed on the firewall filter, it causes the PFE process to crash.
1827439
Major
On MX platforms with ukern based line cards (till MPC9), when the BGP FlowSpec session goes down or withdrawal of all BGP FlowSpec routes making entries on netflow.0 table to zero at once, a BFD (Bidirectional Forwarding Detection) flap occurs with the subsequent impact in the traffic.
PR NumberCategory: Trio pfe bridging, learning, stp, oam, irb software
1766080
Major
On Junos MX/EX92k platforms with MPC10 and above line cards (including MPC10, MPC11, LC9600 line cards and EX9204, EX9208, EX9214, EX9251, EX9253, MX240, MX480, MX960, MX2008, MX2010, MX2020, MX10003, MX10004, MX10008, MX10016, MX304 platforms) having EVPN (Ethernet Virtual Private Network) and IRB (Integrated Routing and Bridging), configuring "preserve-nexthop-hierarchy" at global level causing traffic from core to drop on PE (Provider Edge) in CRB (Centrally-Routed Bridging) mode.
PR NumberCategory: Trio pfe l3 forwarding issues
1816378
Major
On MX204, MX10003 and MX platforms with MPC7, MPC8, MPC9, LC480, LC2101, LC2103, MPC10 and MPC11 line cards or EX92xx platforms with EX9200-40XS, EX9200-12QS, EX9253-6Q12C, EX9253-6Q12C-M line cards, SRX5400, SRX5600, SRX5800 platforms with SRX5K-IOC4-10G, SRX5K-IOC4-MRAT line cards, in a scenario where there could be fabric drops because of over-subscription or CRC errors, there could be case when the same tail entry get re-used across packets leading to packet corruption and CM error. This is a corner case and might lead to PFE(Packet Forwarding Engine) disable resulting in traffic loss.
1841876
Major
In different MX series routers references, when Q-in-Q is configured with outer Vlan Tag protocol ID (TPID) different than 0x8100, the traffic is lost and will not find its destination.
PR NumberCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329
Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberCategory: Configuration mgmt, ffp, load-action, commit processing
1702344
Minor
On EVO platform, if the apply-path config has a wild-card <*> character after an attribute node then, the wild-card character is not processed. Due to which, the apply-path config is not expanded into matching prefixes by ui-infra. Please refer workaround section on how to avoid the issue.
1818692
Major
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP
1829886
Major
Commit error check-out failed does not get triggered when a complete bridge-domain is configured in instance-type vrf.
PR NumberCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1799215
Major
On all Junos and Junos Evolved platforms, when the user attempts to issue the commit command after modifying the configuration post 'commit prepare', the commit discards the prepared commit cache as it is no longer valid and throws " commit fails" error and proceeds with the regular commit process from scratch.
1799277
Major
The satellite package is not conforming to the expected junos version format leading to the problem reported. The code which parses this version string has been modified to handle such format incompatibility gracefully.
1825728
Minor
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.
1842518
Major
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.
PR NumberCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1774292
Major
The following Error messages are generated on the backup RE and cpu usage of eventd gets 100% when "syslog host" and "syslog source-address" are configured.eventd: could not bind to address x.x.x.x: Can't assign requested addresseventd: Trying bind to default address: Inappropriate ioctl for deviceeventd: bind: Invalid argument.
PR NumberCategory: Issues related to NETCONF
1796297
Major
On all Junos and Junos Evolved platforms, commit confirmed command executed with remote procedure call (RPC) in private configuration mode is being allowed where ideally it should not be.
1800859
Major
On all Junos and Junos OS Evolved platforms,  RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.
1819656
Major
In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.
PR NumberCategory: Issues related to YANG Data Models
1826630
Major
When the YANG(Yet Another Next Generation)-compliant knob is configured, annotations containing non-alphanumeric characters are written as-is, instead of being escaped into their corresponding formats.
PR NumberCategory: Antivirus UTM issue
1792169
Major
When using Avira Antivirus Solution for Unified Threat Management (UTM) on SRX Series Devices which support high availability (HA) cluster, automatic pattern updates won't occur if the pattern-update interval goes negative.
PR NumberCategory: PTX/QFX100002/8/16 interface software
1817562
Major
On Junos PTX10008, PTX10016 and PTX platforms with FPC3-PTX, after a router reboot or FPC (Flexible PIC Concentrator) restart, DFE (Decision Feedback Equalisation) tuning is initiated on all active interfaces. If a tuning failure occurs due to a FEC (Forward Error Correction) mismatch, the process gets stuck. Even after correcting the error, the interface remains down as the system cannot initiate a new DFE tuning until the previous attempt completes.
PR NumberCategory: MX10K linecard
1785182
Major
On Junos platforms with MPC7E, MPC8E, MPC9E. LC1201, LC480, MS-SPC3, SRX5K-SPC3 cards. When one of these line cards have uncorrectable memory issue, the line card reboots silently without generating any crash files.
PR NumberCategory: video monitoring feature
1822738
Major
On all Junos MX platforms with MPC2E, MPC3E, MPC4, MPC5 and MPC6 line cards and video monitoring configuration enabled, the Packet Forwarding Engine(PFE) goes in to disabled state when multicast traffic with more than 10 downstream interfaces. This leads to traffic loss.
PR NumberCategory: Virtual Private LAN Services
1774580
Major
On Junos and Junos Evolved platforms in the VPLS (Virtual Private LAN Service) Multi-homing with Multicast Snooping enabled, Multicast traffic looping will be observed due to L2 (Layer 2) Multicast traffic being sent on the access interface status marked as CCC-DOWN.
1793342
Major
With VPLS service having NSR+GRES configured it may be seen that post RE switchover few of the VPLS sessions that were undergoing changes during transition to new RE may not come up, due to LSI IFL not getting created. This will impact the traffic flowing over that VPLS session
PR NumberCategory: Virtual Router Redundancy Protocol
1760534
Major
On Junos and Junios OS Evolved platforms with dual RE, when GRES and NSR are enabled. VRRP status is wrongly displayed in standby RE when VRRP is configured although it is in the correct state. There is no impact with services. its a display issue.
1822867
Major
On all Junos and Junos Evolved platforms configured with VRRP (Virtual Router Redundancy Protocol) and NSR (Non-Stop Routing), after RE switchover or GRES (Graceful Routing Engine Switchover) the master router would starts sending VRRP advertisements with a different priority value. As a result, both the master and backup VRRP routers will begin operating as the master which results in inconsistent traffic routing or packet loss as the system fails to establish a single master node.
PR NumberCategory: Windsurf fabric software
1830457
Critical
On Junos MX2020 platform with non-native LCs (Line Cards) such as MPC-4/5/7 or MS-MPC, post FPCs (Flexible PIC Concentrator) restart the fabric planes goes into check state due to HSL2 (High Speed Link Version 2) 'failed word alignment' error. The link between fabric and FPC/PFE goes down hence there will be partial traffic impact through the impacted PFE and fabric-plane combination.
1835860
Major
On MX2010/MX2020 platforms having adapter cards MPC7E and MPC5E with SFB3 (Switch Fabric Boards), the alarm "Check plane * Fabric Chip" is seen when both the ADC cards are restarted, which then causes a fabric link error on the adjacent ADC slot. As a result, traffic drop is observed for FPC (Flexible Physical Interface Cards Concentrators)/PFE (Packet Forwarding Engine) plane combination for which the error is reported.
PR NumberCategory: Track Windriver Linux issues
1631579
Critical
A system equipped with specific line cards, the line cards will be stuck in the 'Present' state and later go 'Offline' after the line card or router is rebooted. Ideally, the Line Card should go 'Online' instead it goes 'Offline'.
PR NumberCategory: usf flow and datapath issue on SPC3
1841859
Major
On all MX Junos devices with SPC3, on receiving bursty traffic PIC may go down and cause network disruption.
PR NumberCategory: usf ipsec related issues
1808207
Major
On Junos MX platforms with SPC3 card and IPsec configuration, traffic loss is seen in existing service sessions following a tunnel flap when the "clear security ipsec security-associations" command is executed. After clearing the security associations (SA), the expected transition of data traffic to the new tunnel does not occur. Instead, the tunnel continues to drop traffic of the existing session. A new traffic session initiated after the new tunnel establishment works fine with no issue.
PR NumberCategory: usf nat related issues
1802242
Major
On all MX platforms, the configuration change done to interim logging interval for deterministic Network Address Translation (NAT) does not come into effect. Even after modifying the interval value from T1 to T2, logs still get generated at the interval T1.
1829633
Critical
On MX240, MX480 and MX960 with MX-SPC3 and in highly scaled subscriber scenario with high memory utilisation, MX-SPC3 reboots and flowd process crashes when subscriber received through Endpoint Independent Filtering (EIF) reaches the configured "max-sessions-per-subscriber" limit for Network Address and Port Translation(NAPT44).

 


 

23.2R2-S3 - List of Known issues 

 

Modification History

First publication 2025-01-30