Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

Junos software version 23.2R2-S3

Alert Description

Alert Description

Junos Software Service Release version 23.2R2-S3 is now available for download from the Junos software download site

This SRN contains the list of Known issues for Junos software version 23.2R2-S3.

For the list of fixed issue see TSB94156 [juniper.net]

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For review

Solution

23.2R2-S3 - List of Known issues 

PR NumberSynopsisCategory: EX4300 PFE
1794342
Minor
High CPU after software upgrade of EX4300 from 21.2R3-S4.8 to 21.4R3-S5.4
Product-Group=junos
It is noticed that EX4300 switches after an upgrade of Junos from 21.2R3-SX to 21.4R3-SX may exhibit a higher Cpu. Issue is resulting from fast path thread profiling code. It takes on an average 1 ms more for one fast path thread cycle, cumulatively overall fast path thread usage had increased. Thread profiling code has been optimised and the issue is fixed in the future JUNOS.

Resolved In: junos:21.4R3-S9
PR NumberSynopsisCategory: EX2300/3400 PFE
1833502
Major
EX2300 ECMP : Traffic failure due to ECMP programming failure on PFE
Product-Group=junos
On EX2300 series switch which is working with ECMP function, you may observe traffic failure due to ECMP programming error.

Resolved In:
PR NumberSynopsisCategory: "agentd" software daemon
1808259
Major
Openconfig data type value is streaming in gnmi update as float_val instead of bytes_val
Product-Group=junos
On all Junos Evolved platforms configured with Openconfig telemetry, when streaming the GNMI leaves updates for data type value "ieeefloat32"will be seen streaming as type "float_val" instead of "bytes_val". There is no traffic impact due to this, and just a display issue.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D45-EVO evo:22.3X80-D47-EVO evo:22.4R0-J0-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: MX YT-ZF Linecards Interface Software Category
1846164
Major
Continuous logging of alarms during a fiber cut with transport devices
Product-Group=junos
In a scenario where a fiber link has transport devices to amplify the signal, excessive logging of alarms for an interface can occur. The transport devices will amplify the incoming signal, which isn't valid when the fiber has been cut. This causes the router to receive a good signal and Rx power but it contains no valid data. In response, the interface on the router will attempt to link up repeatedly and after failing multiple retries, which is set per platform, the router will attempt to reinitialize the data path. This causes multiple alarms from the optic to get set and then cleared resulting in alarm logs in the system logs. This can become excessive if the link remains down for an extended period of time. To avoid continuous logging to the system log, after a number of retries the logs will be suppressed. The interface will continue to attempt to link up including reinitializing the the data path, but without the logging. This will allow the interface to link up when the physical link is repaired, and at that point the logs will stop being suppressed

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: MX YT-ZF Linecards YT, MQSS, Pre-Classifier, HBM Driver Category
1839265
Major
Resource Errors observed on PFE slices when egress is logical tunnel
Product-Group=junos
On all MX platforms, the Logical Tunnel (LT) back pressures the ingress interface with store resource errors if throughput exceeds 400Gbps per Packet Forwarding Engine (PFE) slice (200Gbps per LT interface).

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: SRX2000/50000 issue
1811765
Major
The vmcore process crashes on when XLP PIC is initiated
Product-Group=junos
On SRX5400/SRX5600/SRX5800 platforms, if vmcore is initiated for XLP PIC ( Extreme Low Power Peripheral Interface Controller ), vmcore process crashes.

Resolved In: junos:21.4R3-S9
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1797189
Major
We may observe repd core (in the "from" release) during ISSU. There are no functional impact due to this repd core
Product-Group=junos
On all Junos and Junos Evolved platforms, repd core observed (in the "from" release) during ISSU.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:22.4R3-S6 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: MIBs related to BBE
1824274
Major
The jnxSubscriberPortTerminatedCounter shows incorrect values for interfaces
Product-Group=junos
On Junos MX platforms, the jnxSubscriberPortTerminatedCounter no longer shows the correct values for the individual ports. It shows the same value for all ports. These subscribers are enabled over PS interface.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO junos:23.2R2-S4 junos:23.4R2-S2-J5 junos:23.4R2-S3-J4 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1814017
Major
Extensible Subscriber Services Manager (ESSM) sessions gets disconnected when PFE encounters an issue for any service or subscriber session
Product-Group=junos
On all Junos and Junos OS Evolved platforms, where subscriber-management is configured and if PFE encounters an issue for any service or subscriber session then it sends an error for anyone of the session in bulk response which results in the subscriber services to be disconnected.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Border Gateway Protocol
1838490
Minor
BGP_PREFIX_THRESH_EXCEEDED warning message keeps flooding after accepted max prefix limit is reached
Product-Group=junos
With this PR fix, BGP_PREFIX_THRESH_EXCEEDED warning message will be stopped after the max prefix limit is reached. The behavior is consitent with prefix-limit feature.

Resolved In: evo:22.2R3-S6-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.2R3-J10 junos:22.2R3-S6 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1784438
Major
MX304 not reachable with the power-off failure on the PIC
Product-Group=junos
When an MX304 LMIC is offline due to a power issue, it may take up to 20 minutes for the LMIC to come back online. You can configure event-options to reduce the time to restart the LMIC. See also: TSB83899 [juniper.net]

Resolved In: evo:23.2R2-S2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:22.2R3-S5 junos:22.4R3-S4 junos:23.2R2-J15 junos:23.2R2-S2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: CoS support on DNX
1850907
Major
Inner VLAN tag DEI bit in VLAN header set incorrectly
Product-Group=junos
On Junos OS ACX5448 and ACX710 platforms, the DEI(Drop Eligibility Indicator) bit in the VLAN(Virtual Local Area Network) header for the inner VLAN tag is being set incorrectly. As a result, packets with the DEI bit set will be dropped downstream.

Resolved In: junos:23.4R2-S4 junos:23.4R2-S5 junos:24.2R2 junos:24.4R2
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1849241
Major
Packets are forwarded with native VLAN tagged on ACX5448 and ACX710 platforms
Product-Group=junos
On Junos OS ACX5448 and ACX710 platforms with native-vlan-id configured over L3 (Layer 3) interface with AE (Aggregated Ethernet), the device forwards packets with native VLAN (Virtual Local Area Network) tagged in the packet i.e. packets will be egressed out of the interface configured with VLAN matching the native VLAN resulting in the peer the device will drop the packet.

Resolved In: junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: N/A:sw-ex-edradour-pfe
1847159
Major
Reachability issues are seen on interfaces that are aggregated without address-family
Product-Group=junos
On Junos platforms, specifically on EX and QFX series aggregated interfaces configured without address-family results in reachability issues.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: EX4100 PFE
1846286
Major
The error message will be seen on EX4100 platforms when deactivating/activating IRB interfaces
Product-Group=junos
On EX4100 platforms, When deactivating/activating IRB interfaces on vlans with vni enabled, error message will be observed.

Resolved In: junos:22.2R3-S6 junos:22.4R3-S6 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: EX interfaces issues
1580560
Major
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.
Product-Group=junos
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.

Resolved In:
PR NumberSynopsisCategory: EX4400 PFE software
1817034
Major
For Junos OS platforms, the OSPF neighborship gets stuck in EXSTART state after performing NSSU
Product-Group=junos
For Junos OS platforms, in a specific configuration change after NSSU (Nonstop Software Upgrade), i.e. delete and add sequence of LAG (Link Aggregation Group) bundles performed via load baseline configuration and re-apply original configuration, OSPF (Open Shortest Path First) session might get stuck in EXSTART state. This issue will impact the traffic.

Resolved In: junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1621998
Major
AR:Firewall: percentage physical-interface policer is not working on AE, after switching between baseline config to policer config.
Product-Group=junos
Percentage physical-interface policer is not working on AE, after switching between baseline config to policer config

Resolved In:
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1808353
Major
Traffic drop is seen when "monitor traffic interface" command is issued for an interface on Junos SRX platforms
Product-Group=junosvae
On Junos SRX4100/SRX4200 platform, starting and stopping the "monitor traffic interface", causes the VPN tunnel or tagged traffic to be dropped. However, keeping the "monitor traffic interface" running, ensures that traffic will function properly. Issue occurs when monitor interface command on an interface is performed on devices that has vlan-tagging configured.

Resolved In: junos:21.4R3-S9 junos:22.2R3-S5 junos:22.4R3-S4 junos:23.2R2-S2 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1826194
Major
The rpd crash is observed during upgrade or restart
Product-Group=junos
On all Junos and Junos Evolved platforms, rpd crash is observed during upgrade or restart since kernel takes more time to update ifstate information.

Resolved In: evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO junos:21.4R3-S10 junos:22.4R3-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1827648
Major
ARP not learned on Switch Leading to Traffic Drop in EVPN-VXLAN Setup
Product-Group=junos
On all Junos QFX series platforms in an EVPN (Ethernet Virtual Private Network) VXLAN (Virtual Extensible Local Area Network) setup with CRB (Centralized Routing Bridge) architecture, ARP packets are not being learned, leading to traffic forwarding issues. This problem arises when ARP packets are sent from the firewall to the spine switches. The issue is linked to IRB (Integrated Routing and Bridging) handling and bridge domain re-incarnation, which triggers ARP request failures and impacts L3 forwarding.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: jdhcpd daemon
1817227
Major
DHCP asymmetric-lease-time is slow processing large scale requests to terminate 64K subscribers.
Product-Group=junos
DHCP asymmetric-lease-time code has been optimized to increase the processing speed from 20 client requests per second to 100 client requests per second.

Resolved In: junos:21.2R3-S9 junos:23.2R2-S2 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Firewall Authentication
1732210
Major
23.1R2:ISSU:USERFW-CP: Clearpass Auth entry's are getting deleted post successful ISSU
Product-Group=junos
On SRX devices on aruba-clearpass webapi configuration set system services webapi <*> authentication entries could be lost during ISSU or during Junos version upgrades to 23.1 from prior versions. Due to this issue any dataplane traffic using the ClearPass Authentication entries will require reauthentication.

Resolved In: junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: Flow Module
1791633
Minor
Packets over GRE or IPIP or GRE(PMI) will not reach destination
Product-Group=junos
On Junos platforms with GRE or GRE(PMI) or IPIP tunnels, when tunnel TTL(Time To Live) is set to 1 in the CLI, the traffic sent over GRE or IPIP or GREoIPSec tunnel does not reach its destination.

Resolved In: junos:21.2R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Security platform jweb support
1851362
Major
Unable to load J-Web after upgrading SRX when time zone is set to GMT+x or GMT-x.
Product-Group=junos
Due to GMT+x or GMT-x time zone is not supported, J-Web will fail to load after upgrading SRX.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
1858466
Major
Intermittent Empty Configuration Reply in Juniper Secure Connect VPN Due to Improper MGD File Descriptor Handling
Product-Group=junos
On all SRX platforms, Juniper Secure Connect clients may experience intermittent connectivity issues and fail to establish a VPN session after successful authentication, due to the SRX device sending an empty configuration reply when more than 20 concurrent connections per client are active, leading to service impact.

Resolved In: junos:22.4R3-S7
PR NumberSynopsisCategory: Key Management Daemon
1781993
Major
Memory leak is observed on MX series platforms that run kmd process
Product-Group=junos
On all MX series platforms that support MS-MPC/MS-MIC cards, memory leak is observed on kmd (Key Management Deamon) process when IPSec VPN is configured with DiffieHellman group24. The issue is not seen on platforms that support iked process. Memory leak causes incorrect outputs for CLI ipsec/ike show commands and over time kmd might crash when reach its maximum memory, creating a core-dump and resulting in ipsec/vpn going down.

Resolved In: junos:21.2R3-S4-J36 junos:21.2R3-S9 junos:21.4R3-S9 junos:22.4R3-S5
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1827058
Major
The PFE gets disabled due to large number of fabric self ping errors
Product-Group=junos
On MX platforms with MPC11E and LC9600 and MX304, when multiple fabric self ping errors and timeouts are seen, device attempts to recover by performing port bounces at fabric end. But when there are large number of self ping errors and timeouts are seen which require more than 256 port bounces, the affected PFE(Packet Forwarding Engine) will get disabled resulting in traffic loss.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1801129
Major
IP routes can get added to a deleted routing table
Product-Group=junos
On all Junos platforms routes can get added to deleted routing tables.

Resolved In: junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1795218
Minor
JUNOS_REG: MX : With the GR interface configured, ASIC error at PFE can trigger vmcore on backup.
Product-Group=junos
With the GR interface configured, ASIC error at PFE can trigger vmcore on backup.

Resolved In: evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: OSPF routing protocol
1827435
Major
OSPF LSA flooding is impacted after database recovers from 'ignore' state when 'database-protection' is triggered
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when the LSA (Link State Advertisement) count exceeds the maximum number configured under 'database-protection' feature in OSPFV2 (Open Shortest Path First Version 2), the OSPF database (DB) enters into 'ignore' state. When the DB is recovered, OSPF LSA flooding is stopped on some interfaces.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:22.2R3-S5 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Express Chip L3 software
1826626
Major
Unpoliced sampling traffic causes host congestion and forwarding failure
Product-Group=junos
On Junos PTX and QFX platforms, unpoliced sampling traffic can cause host path congestion, leading to a failure in forwarding operations. This issue occurs when specific conditions, such as higher rates of sampling classes or smaller packet sizes, are met.

Resolved In: junos:21.4R3-S10 junos:22.4R3-S5
1827286
Major
The icmpv4/v6 ping fails with ddos-protection* icmp configuration
Product-Group=junos
The PTX10008, PTX10002-60C, or QFX10002-60C platforms may not send back ICMPv4/v6 reply packets properly due to defects leading to misprogramming of hardware. Ping with v4/v6 from another device to the PTX10008, PTX10002-60C, or QFX10002-60C platform will fail.

Resolved In: junos:22.4R3-S5
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1818740
Major
On Junos QFX5K series platforms multicast traffic impact is observed after device reboot
Product-Group=junos
On Junos QFX5K series products enabled with multicast service, multicast forwarding traffic abruptly ceases after rebooting the device due to routes get in discard state. It affects multicast forwarding traffic because of the loss of multicast packets.

Resolved In: junos:22.2R3-S6 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R2 junos:24.4R1 junos:25.1R1
1823601
Critical
Protocol traffic drops were seen in the network for any configuration change in the protocol
Product-Group=junos
On all Junos QFX5K platforms, with ECMP (Equal Cost Multi Path) configured, when there is any routing protocol change (like ISIS cost metric change), the protocol traffic on the network is dropped.

Resolved In: junos:21.4R3-S10 junos:25.1R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1757704
Major
JUNOS_REG: QFX5110-48S : "mge" interface is going down after performing soft OIR
Product-Group=junos
this is an issue with SOFT OIR, which is used for internal debugging purposes.

Resolved In: junos:22.2R3-S6 junos:22.4R3-S5 junos:24.2R2 junos:24.4R1 junos:25.1R1
1777336
Critical
Interface flap occurring unexpectedly on Junos QFX platforms
Product-Group=junos
On Junos QFX5120-48T devices, interface flap occurred unexpectedly. 1G/10GBT interfaces flaps due to Electro Magnetic Interference (EMI).

Resolved In: junos:22.2R3-S5 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1761667
Major
The rpd process and chassisd process crash is seen
Product-Group=junos
On Junos and Junos Evolved platforms configuring BGP causes the rpd to crash abnormally and later chassisd crashes too.

Resolved In: evo:22.2R3-S3-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.3X80-D45-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.4R3-S10 junos:22.2R3-S3 junos:22.2R3-S4 junos:22.3R3-S2-J2 junos:22.3R3-S3 junos:22.4R3-J6 junos:22.4R3-S1 junos:23.2R1-S1-J7 junos:23.2R2 junos:23.2R2-J14 junos:23.4R1 junos:23.4R2 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1562387
Critical
The session status gets stuck in the Invalid state after the core-facing link fails in the primary PE devices.
Product-Group=junos
Due to a race condition, the 'show multicast route extensive instance " output can display the session status as Invalid. Such an output is a cosmetic defect and not indicative of a functional issue.

Resolved In: junos:22.4R3-S1
PR NumberSynopsisCategory: RPD policy options
1849500
Major
Static route validation fails when using an interface-route leaked with rib-groups using "to rib " as matching condition under rib-groups import-policy
Product-Group=junos
On all Junos and Junos Evolved platforms, static route validation fails if it is using a leaked interface-route as next hop via a rib-group using "to rib " as matching condition under rib-groups import-policy. That would impact the traffic dependent on such a route.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R1-S1-EVO evo:24.4R1-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:22.4R3-S6 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1839631
Major
Configuration check-out fails when applying "inet6.0 static route" with qualified-next-hop and interface settings
Product-Group=junos
On all Junos and Junos Evolved platforms, commit check for overlapping prefixes will fail to commit when inet6 static route is configured with qualified next-hop and Integrated Routing and Bridging (irb) interface.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1833448
Major
Detours not coming up when link-protection is turned-off while interoperating with ZTE device
Product-Group=junos
On all Junos and Junos Evolved Platforms, an MPLS-TE (Traffic Engineering) interoperability problem exists where Juniper routers misinterpret ZTE's RSVP (Resource Reservation Protocol) Detour backup protection signals, causing unnecessary facility backup attempts and inefficient resource usage. This only impacts networks with both Juniper and ZTE equipment.

Resolved In: evo:24.2R2-EVO evo:25.1R1-EVO junos:24.2R2 junos:25.1R1
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1801201
Major
IKE is not coming up with dhgroup19 and dhgroup20
Product-Group=junos
IKE is not coming up with dhgroup19 and dhgroup20. The below Junos releases are impacted. junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3-S1 junos:24.1R1. So previous to these releases dhgroup19 and dhgroup20 should be working.

Resolved In: evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S8 junos:21.2R3-S9 junos:21.4R3-S10 junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S3 junos:24.2R1 junos:24.3R1
1825835
Major
IPsec traffic loss is observed when SA is stuck in the routing table even when the IPsec tunnel does not exist on the device
Product-Group=junos
On MX platforms with MS-MPC/MS-MIC with IPsec (Internet Protocol Security) configured, IPsec traffic loss will be observed if an SA (Security Association) deletion request is sent by the peer just before the SA installation is completed. The issue happens in the scale scenario (4000 tunnels are configured, and when the SA count reaches up to 3900).

Resolved In: junos:21.2R3-J14 junos:21.2R3-S8-J10 junos:21.4R3-S9 junos:22.4R3-S5
PR NumberSynopsisCategory: SRX Argon module
1815751
Critical
Junos OS: SRX Series: Low privileged user able to access sensitive information on file system (CVE-2024-39527)
Product-Group=junos
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of protected files on the file system. Please refer to https://supportportal.juniper.net/JSA88104 [juniper.net] for more information.

Resolved In: junos:19.1R3-S13 junos:19.2R3-S10 junos:19.3R3-S11 junos:19.4R3-S14 junos:20.2R3-S10 junos:21.2R3-S9 junos:21.2X32-D20 junos:21.2X32-D30 junos:21.4R3-S8 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:23.2R2-S2 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1827283
Major
PFE core can be seen on SRX platforms during ISSU
Product-Group=junos
On Junos SRX4k/5k series platforms in a chassis cluster environment, the srxpfe (Packet Forwarding Engine) process crashes during ISSU ( In service Software Upgrade). It happens after failover to the upgraded node and before the secondary node is all the way up to join the cluster. This process crash will cause traffic impact, however the system self-recovers.

Resolved In: junos:21.4R3-S7-J6 junos:21.4R3-S7-J7 junos:21.4R3-S9 junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: SRX RTCOM module bugs
1814271
Major
The srpfe crash during SAV longevity testing
Product-Group=junos
On SRX platforms, when Sophos antivirus (SAV) was enabled srpfe crash was observed. If a new packet tries to access the memory before it gets free, it may lead to the race condition, where it tries to fetch a null memory. The issue is hardly reproducible.

Resolved In: junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: SRX branch platforms
1803966
Major
The cl interface goes down when the dl interface is disabled for link failover
Product-Group=junos
On the SRX300 series platforms and SRX550 supporting the LTE Mini-Physical Interface Module (Mini-PIM), the cellular interface (cl) goes down when the dialer interface (dl) interface is disabled for link failover.

Resolved In: junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
1821368
Major
DAC interface does not send fault signal to a peer device when the DAC interface is admin disabled
Product-Group=junos
On SRX380 platform, when a DAC interface is admin disabled, the DAC interface does not send a fault signal to a peer device and on peer device it will reflect as up.

Resolved In: junos:23.4R2-S3 junos:24.2R1-S2 junos:24.2R2 junos:24.3R2 junos:24.4R1
1827123
Major
Root user does not get logged out from shell
Product-Group=junos
On the SRX 3xx series the root user does not get logged out from the shell mode even though the session logout time is configured. There is no traffic impact because of this issue, however, this is unexpected behaviour and not seen on other platforms.

Resolved In: junos:21.4R3-S9 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.4R2-S4 junos:24.2R1-S2 junos:24.2R2 junos:25.1R1
1836235
Major
SRX default named.conf file is created with non dns-proxy related configuration changes
Product-Group=junos
On SRX platforms with dns-proxy configured, default named.conf file is created with non dns-proxy related configuration changes. This leads to halting of dns-proxy operation.

Resolved In: junos:21.4R3-S10 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1772138
Major
DUT is sending same source-port-id for two PTP master links connected to downstream node with multiline card scenarios
Product-Group=junos
On Junos MX240/480/960/2010/2020/2008 Distributed Precision Time Protocol (PTP) platforms, When PTP master/slave/stateful is configured across multiple linecards and allocated with same port-number in the line cards, then the packets generated from both the ports, shall contain the same source-port-id. It shall create Baseboard Management Controller (BMC) issues in G.8275.1 deployment and passive port monitoring deployments.

Resolved In: evo:23.4R2-EVO evo:24.1R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S8 junos:21.4R3-S10 junos:23.4R2 junos:24.1R2 junos:24.2R1 junos:24.3R1
1830281
Major
Sourceport-ID comparison resulting in higher value for MPC7E compared to MPC5E for distributed PTP architecture
Product-Group=junos
SourcePort-ID comparison across line cards between MPC7E and MPC5E/6E/3E-NG/2E-NG shall result in selecting MPC5E/6E/3E-NG/2E-NG compared to MPC7E/8E/9E/10E.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:21.2R3-S9 junos:21.4R3-S10 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1817609
Major
Interface Connectivity issue with MPC10E on Member 1, Slot 0 in MX Virtual Chassis
Product-Group=junos
On all Junos in MX-Virtual-Chassis (MXVC) setups involving MPC10E Flexible PIC Concentrators (FPCs) on member #1 in slot #0 causes incorrect interface number conversion, leading to all interfaces being down on this FPC. This problem affects any MXVC configuration with MPC10 FPCs positioned in this slot.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:23.4R2-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1855648
Major
On some MX platforms, "show firewall log" doesn't show output
Product-Group=junos
On MX platform with AFT based line cards ( MPC10E, MPC11E and LC9600), if firewall filter is applied to a loopback interface that has non-0 value for unit configured, the "show firewall log" doesn't show any output. This doesn't impact forwarding traffic.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1850604
Major
Packet duplication and flooding issues are seen when vpls bridge domain is configured on an aggregated Ethernet and label-switched interface across multiple line cards
Product-Group=junos
On MX240/MX480/MX960/MX2008/MX2010/MX2020/MX10003/MX10008/MX10016/MX10004 platforms with vpls (Virtual private LAN service) bridge domain configured, when the core facing ecmp (Equal cost multipath) are across multiple line cards and when MAC is learned up to MAC limit, packet flooding might be seen continuously for 5 mins after uplink or downlink going down causing network congestion.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1818853
Major
Enabling "preserve-nexthop-hierarchy" knob under "l2-circuit resolution" stanza causes multicast traffic to be replicated several times
Product-Group=junos
On Junos MX platforms with certain licecards when the knob 'preserve-nexthop-hierarchy' is configured under protocol L2 (Layer2)circuit, the native multicast traffic is getting replicated multiple (depending on the number of Packet Forwarding Engine which is part of multicast replication) times on the egress interface. This is not expected behaviour and can cause possible bottleneck/forwarding issues.

Resolved In: evo:24.4R1-EVO junos:24.4R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1822793
Major
Few flows for BUM traffic gets dropped when a mix of MPC1-9 and MPC10 and above is used
Product-Group=junos
On Junos MX series platforms with preserve nexthop hierarchy knob enabled in setup having a mix of MPC10, MPC11 or LC9600 cards and MPC1-9 line card, BUM (Broadcast, unknown-unicast and multicast) traffic can be dropped for few flows. This occurs because the forwarding path detects a mismatch in the distribution pattern for these flows, resulting in packet loss.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1702344
Minor
Apply-path special handling for wildcard after a leaf attribute
Product-Group=junos
On EVO platform, if the apply-path config has a wild-card <*> character after an attribute node then, the wild-card character is not processed. Due to which, the apply-path config is not expanded into matching prefixes by ui-infra. Please refer workaround section on how to avoid the issue.

Resolved In: evo:22.4R0-J0-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.2R2-S3-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:23.4R2-S4-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:24.2R1
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1831664
Major
load override failure due to error: configuration database size limit exceeded
Product-Group=junos
'load override' failure due to error: configuration database size limit exceeded. It is recommended to use 'load update' to overcome the reported problem.

Resolved In:
1854070
Major
cli coredump genarated when the size of buffer area (user input) increased to 1GB
Product-Group=junos
Cli coredump genarated when the size of buffer area (user input) increased to 1GB.

Resolved In: evo:25.2R1-EVO
PR NumberSynopsisCategory: Issues related to NETCONF
1792554
Minor
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241
Product-Group=junos
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241

Resolved In:
PR NumberSynopsisCategory: MX10K linecard
1809644
Major
FPC crash due to race condition on MX platforms with LC480
Product-Group=junos
On MX platforms with LC480, a crash file is generated because of this issue which results in entire ukern reboot. The issue happens due to race conditions. The ukern automatically reboots and the FPC (Flexible PIC Concentrator) comes up online. Traffic loss is observed till the FPC restarts after the ukern crash.

Resolved In: evo:22.4R3-S6-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S3-J6 junos:22.4R3-S6 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: usf service set related issues
1814935
Minor
jnxSpSvcSetIfMemoryZone SNMP mib always returns 0 for service-set memory usage zone
Product-Group=junos
All the statistics are 0 for the SNMP OID jnxSpSvcSetIfMemoryZone. Other statistics regarding memory utilization are normal.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1

 

Modification History

First publication 2025-01-30