Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 22.2R3-S6 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

No

Call to Action

Review

Solution

Junos Software service Release version 22.2R3-S6 is now available.

22.2R3-S6 - List of Fixed issues 

PR NumberSynopsisCategory: SRX-1RU System Hardware defects
1843413
Major
Split brain condition will be seen in SRX4600 configured in Chassis Cluster under certain conditions
Product-Group=junos
Severity=Major
On SRX4600 platforms configured in Chassis Cluster, split brain condition will be seen under two conditions: 1. A node is isolated from the cluster and is reinstalled with Junos image using a USB and then re-joined into the cluster 2. A standalone SRX4600 is moved into a cluster The split brain condition will lead to potential loss of packets or routing inconsistencies.
PR NumberSynopsisCategory: QFX VC Datapath
1773425
Major
QFX5120, EX4650, EX4400, EX4100 Virtual Chassis (VC) drops Address Resolution Protocol(ARP) packets from remote leaf
Product-Group=junos
Severity=Major
QFX5120, EX4650, EX4400, EX4100 Virtual Chassis (VC) platforms running Junos, drops Address Resolution Protocol(ARP) packets from remote leaf when Virtual Extensible LAN(VxLAN) encapsulated ARP packets are received from ingress port on one of the Flexible PIC concentrator (FPC) and egress port is an Aggregate Ethernet(AE) not having ingress port members on the FPC.
PR NumberSynopsisCategory: JUNOS kernel/ukernel changes for ACX
1833705
Major
Configuration archival does not work using SFTP when using the mgmt_junos routing instance
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms, when the SFTP protocol uses the mgmt_junos routing instance to communicate with the SFTP server, it will fail.
PR NumberSynopsisCategory: This gnats category is required to track NG-SPC PRS for SBU
1841859
Major
High traffic on MX-SPC3 will cause PIC to go down
Product-Group=junos
Severity=Major
On Junos platforms, specifically MX240, MX480 and MX960 supporting MX-SPC3 (Services Processing Card) service cards, if PIC (Physical Interface Cards) receives high traffic enough to make CPU (Central processing unit) almost 100% busy, it will go down, triggers flowd core-dump and cause network impact.
PR NumberSynopsisCategory: Border Gateway Protocol
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.
1838490
Minor
BGP_PREFIX_THRESH_EXCEEDED warning message keeps flooding after accepted max prefix limit is reached
Product-Group=junos
Severity=Minor
With this PR fix, BGP_PREFIX_THRESH_EXCEEDED warning message will be stopped after the max prefix limit is reached. The behavior is consitent with prefix-limit feature.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1759991
Major
RPD process crash is seen post RE switchover
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms with BGP (Border Gateway Protocol) and BMP (BGP Monitoring Protocol) rib-out configuration, rpd (Routing Protocol Daemon) process crash happen during an BMP initial rib-walk. This issue is observed in a rare race condition.
PR NumberSynopsisCategory: MX304 LCMD specific issues
1851100
Major
MX304 rebooted after misreading a temperature sensor
Product-Group=junos
Severity=Major
On Junos MX304, due to erroneous data read from a temperature sensor, the device will shutdown.
PR NumberSynopsisCategory: Class of Service
1836528
Minor
FC id goes out of sync between the RE and PFE impacting all CoS features using FC id
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved Platform, forwarding-class (FC) identifier (id) goes out of sync between the Routing Engine (RE) and Packet Forwarding Engine (PFE) when software upgrade is performed. When In Service Software Upgrade (ISSU) is performed, FC id goes out of sync between the RE and PFE impacting all class-of-service (CoS) features using FC id. When manual software upgrade is performed (without using ISSU) , this issue will be seen as a cosmetic display issue where the order in which the FC configurations are displayed will differ.
PR NumberSynopsisCategory: Platform PR for 1G/10G LC
1818475
Minor
[LC480] STS LED may display incorrectly
Product-Group=junosvae
Severity=Minor
STS LED may display incorrectly due to lcmd and driver code inconsistencies
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1811734
Major
The LFM session flaps will be observed at random
Product-Group=junos
Severity=Major
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1844623
Major
Stale MAC-IP entries are not cleared in an EVPN-VXLAN scenario when encapsulate-inner-vlan or decapsulate-accept-inner-vlan or both knobs are present
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when decapsulate-accept-inner-vlan or encapsulate-inner-vlan or both knobs are configured for a VXLAN (Virtual Extensible Local Area Network) and when any action corresponding to MAC-IP entries cleanup takes place, the MAC-IP entries will not be cleaned up from kernel. This will result in anomalies in device and could also lead to a core crash.
PR NumberSynopsisCategory: EVPN control plane issues
1691132
Major
In the EVPN-MPLS multihoming scenario, MAC-IP route deletion and addition result in traffic drop
Product-Group=junos
Severity=Major
On all platforms, MAC-IP route deletion and addition are triggered when re-ARP (Address Resolution Protocol) on MH (Multihoming) device fails in the EVPN-MPLS multihoming scenario resulting in traffic drop.
1839959
Critical
The MAC+IP table and mac-table are not in sync in the EVPN-MPLS active-active multihomed scenario leading to traffic loss
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms that supports ESI lag interface and in an EVPN-MPLS (Ethernet Virtual Private Network - Multi Protocol Label Switching) active-active multihomed scenario, when the multihomed access interfaces are flapped in quick succession, it results in an unresolved destination route for the specific IP host. This is occurred due to race condition within l2ald (Layer 2 Address learning daemon) followed by an interface flap which causes the locally learned MAC to go missing from the mac-table on the other PE router.
PR NumberSynopsisCategory: EX4100 PFE
1802455
Major
The default port behaviour is not working as expected after deleting VOIP (Voice over IP) configuration on an access interface
Product-Group=junos
Severity=Major
On EX4400/EX4100 Platforms for VXLAN (Virtual extensible Local Area Network) configuration the interface is expected to accept untagged and member vlan tagged packet on deleting VOIP (Voice over IP) configuration on an access interface. But the access interface is not allowing member vlan tagged packets and only untagged packets are allowed.
1846286
Major
The error message will be seen on EX4100 platforms when deactivating/activating IRB interfaces
Product-Group=junos
Severity=Major
On EX4100 platforms, When deactivating/activating IRB interfaces on vlans with vni enabled, error message will be observed.
PR NumberSynopsisCategory: EX interfaces issues
1788328
Major
Master FPC taking 20 sec time to shut backup FPC's network port after backup FPC reboot in a VC set-up
Product-Group=junos
Severity=Major
On all EX platforms with Virtual Chassis (VC) and Graceful Routing Engine Switchover(GRES) enabled, if during failover the secondary Flexible Physical Interface Card Concentrator (FPC) gets rebooted then there will be traffic loss of 20 seconds more than the expected traffic loss (1to2 seconds).
1805100
Major
Establishing virtual-chassis connection between EX4300-MP platforms, the traffic sent via the VCP port is lost minimally
Product-Group=junos
Severity=Major
On EX4300-MP platforms in non-mixed VC mode, when the VC connection is established between the platforms, the ports don't pass traffic, which leads to minimum traffic loss.
PR NumberSynopsisCategory: EX4400 PFE software
1854253
Major
Devices fail to obtain an IP address when DHCP Security Option 82 is enabled
Product-Group=junos
Severity=Major
On Junos EX and QFX platforms when DHCP (Dynamic Host Configuration Protocol) option 82 settings are enabled under dhcp-security, hosts fail to get an IP address from the DHCP server.
PR NumberSynopsisCategory: Express PFE Services including JTI, TOE, HostPath, Jflow
1830575
Major
The dcpfe crashes when ukern_trace handle buffer size is set to 10000
Product-Group=junos
Severity=Major
On all Junos platforms, the dcpfe crash is seen with a core-dcpfe dump when the ukern_trace handle buffer size is set to 10000. It is a rare issue.
PR NumberSynopsisCategory: SRX1500 platform software
1845143
Major
SRX1500 constantly reboots due to linux watchdogd process getting struck
Product-Group=junosvae
Severity=Major
On the Junos SRX1500 platform, the device reboots spontaneously because the watchdog is triggered unnecessarily.
1845407
Major
SRX1500 will not show jnxOperatingTemp and jnxFruTemp temperature reading for PSU temperature
Product-Group=junos
Severity=Major
On SRX1500, "show snmp mib walk jnxOperatingTemp" and "show snmp mib walk jnxFruTemp" will not show up temperature reading for PSU temperature.
1863943
Critical
SRX1500 clustered FWs go in Split brain when more than 7 RGs are configured
Product-Group=junos
Severity=Critical
On SRX1500 clustered Firewalls, when more than 7 RGs (Redundancy Groups are configured and a switchover takes place, the FW cluster goes into a split-brain mode which leads to both node becoming primary and consequently traffic loss is seen.
PR NumberSynopsisCategory: MX Inline Jflow
1813925
Major
FPC reboots after sensor configuration is removed and readded over a long period on MX and EX9200-15C platforms
Product-Group=junos
Severity=Major
On all MX platforms with MPC10/MPC11/LC9600, MX304 and EX9200-15C platforms, when any sensor configuration on protocols, for example, MPLS LSP, is configured and removed over a long period, the aftd-trio process starts a memory leak and eventually causes FPC to reboot.
PR NumberSynopsisCategory: jdhcpd daemon
1808289
Major
Switch provisioned via ZTP going unreachable due to DHCP misbehaviour on upgrading to 21.4R3-S6
Product-Group=junos
Severity=Major
All IRB (Integrated Bridging and Routing) interfaces of EX3400-48P switches which pull initial configuration from Dynamic Host Configuration Protocol (DHCP) server via zero touch provisioning (ZTP) process, upon upgrade to 21.4R3-S6 do not send DHCPdiscover packet to obtain a new IP address after sending DHCPrelease packet resulting in interface not able to obtain IP address until rebooted.
1819269
Major
On QFX10008 platforms, DHCPv6 will filter relay-reply packets towards the DHCP client.
Product-Group=junosvae
Severity=Major
On QFX10008 platforms with Junos OS software and DHCPv6 configured, relay-reply packets will be filtered due to no-snoop being disabled and causing IPv6 address assignment rejected towards the customer, therefore client won't receive any valid IP address.
PR NumberSynopsisCategory: Flow Module
1807505
Major
On SRX5000 series and SRX4600, the setting "apply-to-half-close-state" for TCP sessions is not taking effect.
Product-Group=junos
Severity=Major
On SRX5000 series and SRX4600, the setting "set security flow tcp-session time-wait-state apply-to-half-close-state" is not taking effect for sessions that are using express path (services-offload). This may lead to an increased number of sessions compared to earlier Junos releases which did not have an express path enabled by default.
PR NumberSynopsisCategory: SRX Firewall Authentication
1804149
Major
A fwauthd process crash is seen when a user access group name of more than 64 characters is configured
Product-Group=junos
Severity=Major
On all SRX platforms, the fwauthd process crash is seen when it processes a user access group name of size more than 64 characters received from authd process. There is no impact to forwarding traffic due to fwauthd crash.
PR NumberSynopsisCategory: RPM, TWAMP feature related to SRX specific design
1830290
Major
Log messages related to 'gencfg no msg handlers' will be seen on SRX4600 platforms
Product-Group=junos
Severity=Major
On SRX4600 platforms when Real-time Performance Monitoring (RPM) related configuration is committed, 'gencfg no msg handlers for gencfg msg' log messages will be generated. This will not have any functional impact.
PR NumberSynopsisCategory: Security platform jweb support
1766378
Major
J-Web UI cannot be launched
Product-Group=junos
Severity=Major
On all SRX platforms, while displaying the configured login message from Command Line Interface (CLI), the newline characters will be added which results in parsing error. Hence J-Web UI cannot be launched.
1837925
Major
Junos image upload via J-Web fails on select SRX platforms
Product-Group=junos
Severity=Major
On Junos SRX (SRX1500, SRX4600, SRX4100 and SRX5K's) platforms, image upload via J-Web fails with an error "Access Error: 502 -- Bad Gateway".
1851362
Major
Unable to load J-Web after upgrading SRX when time zone is set to GMT+x or GMT-x.
Product-Group=junos
Severity=Major
Due to GMT+x or GMT-x time zone is not supported, J-Web will fail to load after upgrading SRX.
1858466
Major
VPN failures on SRX due to file descriptor issue
Product-Group=junos
Severity=Major
On all SRX platforms, Juniper Secure Connect (JSC) clients may fail to establish a VPN session after successful authentication if more than 20 concurrent connections per client IP are active. In a NATTed environment, the 21st connection will fail, and the customer must retry.
PR NumberSynopsisCategory: Key Management Daemon
1797377
Major
MX Failed IKE SAs not cleared, Struck in non-matured
Product-Group=junos
Severity=Major
A wrong remote id received from peer results in AUTH failure and this fails the IKE SA setup. This immature IKE SA doesn't go for proper cleanup hence "Not matured" IKE SA piles UP. Restarting the kmd will clear the Not matured SAs.
PR NumberSynopsisCategory: Track Mt Rainier RE platform software issues
1776854
Major
VM Core with the reason "panic: deadlres_td_sleep_q: possible deadlock detected" might be seen on all JUNOS vmhost platforms
Product-Group=junos
Severity=Major
PR1735843 has fixed a VM core on ACX5448 platform with the reason "panic: deadlres_td_sleep_q: possible deadlock detected". The same issue might also be seen on all other JUNOS vmhost platforms but with a different root cause.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1818740
Major
On Junos QFX5K series platforms multicast traffic impact is observed after device reboot
Product-Group=junosvae
Severity=Major
On Junos QFX5K series products enabled with multicast service, multicast forwarding traffic abruptly ceases after rebooting the device due to routes get in discard state. It affects multicast forwarding traffic because of the loss of multicast packets.
1823601
Critical
Protocol traffic drops were seen in the network for any configuration change in the protocol
Product-Group=junos
Severity=Critical
On all Junos QFX5K platforms, with ECMP (Equal Cost Multi Path) configured, when there is any routing protocol change (like ISIS cost metric change), the protocol traffic on the network is dropped.
1841913
Major
QFX5210/AS7816 lpm ip route install failed due to table full unit 0
Product-Group=junos
Severity=Major
On QFX5210/AS7816 Platforms, when using forwarding-options custom profile , the PFE "show pfe route summary hw" outputs will differ as compared to the actual capacity of the HW for IPV4/IPV6 LPM route installation. As a result, when trying to scale to the max supported limits that are shown in the PFE "show pfe route summary hw" output, will result in route installation errors/table full errors in the PFE.
1855990
Major
Traffic drop observed due to ECMP next-hop programming issue
Product-Group=junos
Severity=Major
On QFX5k, EX4k, EX2300 and EX3400 platforms, ECMP next-hop programming issue causes some prefixes to drop traffic. The issue is observed when the software-configured ECMP size (maximum-ecmp) exceeds the limit of 64 during a network churn event in the network. This triggers ECMP to skip updates, leading to stale forwarding paths and a temporary traffic freeze.
PR NumberSynopsisCategory: QFX analyzer, sflow
1811308
Major
Multicast traffic is not forwarded over the VXLAN tunnel interface on QFX5120 variants
Product-Group=junosvae
Severity=Major
On QFX5120-32C, QFX5120-48T, QFX5120-48Y and QFX5120-48YM platforms are configured with EVPN-VXLAN( Ethernet VPN-Virtual Extensible LAN) , when server sends multicast traffic through border leaf switches (providing the north-south data traffic and connects to the WAN or outside of the fabric), multicast traffic is not forwarded through VXLAN tunnel interfaces even when multiple interfaces exists for the same multicast destination. Multicast traffic will be impacted.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1820318
Major
Egress-link-protection in combination with IGMP/MLD snooping breaks snooping functionality
Product-Group=junos
Severity=Major
On Junos EX and QFX platforms, when IGMP (Internet Gateway Monitoring Protocol)/MLD (Multicast Listener Discovery) snooping is configured on AE (Aggregated Ethernet) for which FRR (Fast Rerouting) is enabled, the snooping functionality breaks.
1842475
Major
Traffic drops are observed in the EVPN-VxLAN scenario due to VPLAG flaps
Product-Group=junos
Severity=Major
On Junos OS QFX5k and EX4k platforms having EVPN-VxLAN (Ethernet VPN - Virtual Extensible Local Area Network) configured, traffic drops are observed due to missing hardware programming caused by stale hardware entries leading to VTEP (Virtual Tunnel Endpoint) Destination IP-address is not updated properly. The issue is observed due to VPLAG (Virtual Chassis Port Link Aggregation) flaps (any incident, such as a reboot of the gateway device / remote device) causes VPLAG to uninstall and install.
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1757704
Major
JUNOS_REG: QFX5110-48S : "mge" interface is going down after performing soft OIR
Product-Group=junos
Severity=Major
this is an issue with SOFT OIR, which is used for internal debugging purposes.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1823771
Major
The SFP 10GBASE-T part No. 740-083295 on platforms running Junos/Junos EVO is unable to detect a linkdown
Product-Group=junos
Severity=Major
On Junos/Junos EVO platforms with the SFP 10GBASE-T part No. 740-083295 Link up/Link down is randomly not detected.
PR NumberSynopsisCategory: RPD Interfaces related issues
1795659
Minor
"JTASK_NO_SOCKACCEPT: Process events: no read/accept method for MGMT socket -1" logs may be seen in the messages file or an external syslog server
Product-Group=junos
Severity=Minor
"JTASK_NO_SOCKACCEPT: Process events: no read/accept method for MGMT socket -1" logs may be seen in the messages file or an external syslog server
PR NumberSynopsisCategory: KRT Queue issues within RPD
1817807
Major
Routes for secure tunnel interface interface not installed on forwarding-table on SRX platforms
Product-Group=junos
Severity=Major
On all SRX platforms, after the In-Band Cluster (ICU) upgrade if the system has routes pointing to the secure tunnel interface (st0) interface, or on clearing security IPsec sa on peer router a few routes might have trouble getting installed in forwarding, impacting traffic on the routes that are not installed after the upgrade.
1834859
Major
The RPD crashes after executing "show krt error-statistics errorno X"
Product-Group=junos
Severity=Major
Please do not issue the "show krt error-statistics errorno ..." stanza. This command causes RPD to restart unexpectedly.
PR NumberSynopsisCategory: Resource Reservation Protocol
1820893
Major
The detour path is not coming up when the detour hop limit is set to 255
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms configured with MPLS/RSVP (Multiprotocol Label Switching/Resource Reservation Protocol), the detour path might not form when the "fast-reroute hop-limit" is set to 255. Thus, traffic loss will be observed when a node or link in an LSP fails, as the detour will not happen.
1837770
Major
mgd timeout communicating with routing daemon rpd for 30 minutes during RSVP MBB event
Product-Group=junos
Severity=Major
On all Junos OS platforms, Management Daemon (MGD) on a Junos device was unable to communicate with the Routing Protocol Daemon (RPD) for an extended period during a Make Before Break (MBB) event for RSVP signaling. This issue is seen mostly under high scale mpls label switch paths.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1734549
Major
Syslog messages modification for SNMPv3 authentication failure
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, the syslog message for a wrong auth/privacy and password has been changed to include more information.
PR NumberSynopsisCategory: SRX branch platforms
1747849
Major
The CLI command "set system processes watchdog '" results in kernel panic
Product-Group=junos
Severity=Major
On SRX-branch series platforms, configuring the "set system processes watchdog " command causes a commit kernel panic i.e. device will get stuck, and traffic loss will be observed. Watchdog related commands are unsupported.
1811858
Major
Monitored-Status keeps Up after CTL link down in branch model SRX HA
Product-Group=junos
Severity=Major
After CTL link down, Monitored-Status in "show chassis cluster interfaces" keeps showing "Up" state.
1827123
Major
Root user does not get logged out from shell
Product-Group=junos
Severity=Major
On the SRX 3xx series the root user does not get logged out from the shell mode even though the session logout time is configured. There is no traffic impact because of this issue, however, this is unexpected behaviour and not seen on other platforms.
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1808923
Major
Traffic loss occurs if persistent link error is seen on a fabric plane to PFE, after restarting or rebooting another FPC in a different slot
Product-Group=junos
Severity=Major
On all MX platforms, if there is persistent link error or training failure at fabric link between Switch Fabric Boards/ Switch Control Board (SFB/SCB) and a Packet Forwarding Engine (PFE) at one Flexible PIC concentrator (FPC) in some fabric plane then once another FPC in a different slot comes online, it will be sending traffic to the PFE over that link with error for a short period of time and then the FPC which is just brought online will declare destination errors towards that PFE and the Fabric plane with error will be removed from fabric spraying masks. This can result in temporary traffic loss.
PR NumberSynopsisCategory: SRX-1RU infrastructure SW defects
1839346
Major
After performing ISSU on SRX4600, the SPM is no longer operational
Product-Group=junos
Severity=Major
On SRX4600 platform with chassis cluster, after performing an ISSU (In-service Software Upgrade) upgrade, the SPM (Secure Port Module) (fpc 0) against the node that is upgraded first will experience issue states where it can either cycle through 'Present' or 'Offline', or it will not report any errors but will be unable to perform any PFE (Packet Forwarding Engine) functions such as session management i.e. wont be able to process traffic resulting in traffic impact.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1641517
Major
Multiple J-UKERN core files might be generated during the sanity test
Product-Group=junos
Severity=Major
On SRX4600 platform, the CPU may overrun while performing sanity check due to incompatibility issues between ukern scheduler and Linux driver which might lead to traffic loss.
1823577
Major
On SRX4600, in rare cases with heavy traffic, the FPGA may drop packets.
Product-Group=junosvae
Severity=Major
On SRX4600, in rare cases with heavy traffic, the FPGA may drop packets.
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1793375
Critical
CMErrors are observed on MX platforms running MPC10/MPC11 causing the PFE to be disabled
Product-Group=junos
Severity=Critical
On all MX platforms having MPC10 or MPC11 having class-of-service configured, it is observed that in a scaled scenario (1500 IFLs (Interface Logical)), when queues are oversubscribed and the output interface starts to get congested, "CMERROR 0x230063 " or "XQSS_CMERROR_SCHED_QL4_INT_REG_DQU_QSUM_UDR" error message is seen. These cm errors would result in PFE (Packet Forwarding Engine) disable or the action configured in the device.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1813253
Major
Memory issue seen with syslog/log in firewall terms
Product-Group=junos
Severity=Major
On all Junos MX150 platforms, firewall terms with syslog or logging may cause an mbuf (memory buffer) memory leak, resulting in an FPC crash.
1841876
Major
Q-in-Q transit traffic will be lost when Tag Protocol ID (TPID) is different than 0x8100
Product-Group=junos
Severity=Major
In different MX series routers references, when Q-in-Q is configured with outer Vlan Tag protocol ID (TPID) different than 0x8100, the traffic is lost and will not find its destination.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Major
RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
Severity=Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1784818
Major
The non-root user will not be able to copy files
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when logged in as a non-root user and trying to copy a file from a remote location, it shows as cannot become non-root username although logged in as a non-root user and an error message is thrown.
1799215
Major
The commit fails error can be seen when configuration is modified after commit prepare
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when the user attempts to issue the commit command after modifying the configuration post 'commit prepare', the commit discards the prepared commit cache as it is no longer valid and throws " commit fails" error and proceeds with the regular commit process from scratch.
1799277
Major
The mgd crash is seen on aggregation device and upgrade is halted during upgrade to aggregated satellite switches
Product-Group=junos
Severity=Major
The satellite package is not conforming to the expected junos version format leading to the problem reported. The code which parses this version string has been modified to handle such format incompatibility gracefully.
1842518
Major
The device become unresponsive in a race condition due to maximum process (maxproc) limit
Product-Group=junos
Severity=Major
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.
PR NumberSynopsisCategory: Issues related to NETCONF
1796297
Major
Error message not prompted on commit confirmed RPC sent in private mode on all Junos and Junos Evolved platforms
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, commit confirmed command executed with remote procedure call (RPC) in private configuration mode is being allowed where ideally it should not be.
PR NumberSynopsisCategory: Issues related to YANG Data Models
1725934
Major
ODL controller is throwing unavailable capabilities error for few of the Openconfig Yang modules
Product-Group=junos
Severity=Major
ODL controller is throwing unavailable capabilities error for few of the Openconfig Yang modules

 


 

22.2R3-S6 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 PFE
1833502
Major
EX2300 ECMP : Traffic failure due to ECMP programming failure on PFE
Product-Group=junos
On EX2300 series switch which is working with ECMP function, you may observe traffic failure due to ECMP programming error.

Resolved In:
PR NumberSynopsisCategory: BBE interface related issues
1850562
Major
Host unreachable from the router with PPPoE when "routing-service" and "RPF-check" are enabled, and the route is learned via EBGP
Product-Group=junos
On Junos platforms configured with BGP (Border Gateway Protocol) and rpf-check over PPPoE (PPP over Ethernet) subscribers, the platform is unable to reach the hosts present in the routing table when these are learnt by EBGP. This issue affects MX Platforms and QFX platforms.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:22.4R3-S7 junos:23.2R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Border Gateway Protocol
1756603
Minor
RPD process crash is seen on high scale peering scenario where the sessions are un-configured/shutdown abruptly
Product-Group=junos
The RPD process crashes on all Junos and Junos OS Evolved platforms in a highly scaled scenario of more than 2000 BGP peers if the BGP sessions are un-configured/brought down abruptly. This leads to loss of routing information and will lead to loss of protocol traffic.

Resolved In: evo:22.3X50-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:20.3X75-D52 junos:22.4R3-S5 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1 junos:24.1R1
1793435
Major
Route learning process degrades when multipath is enabled
Product-Group=junos
BGP (Border Gateway Protocol) route learning rate shows degradation even if the BGP next hop trace option is disabled.

Resolved In: evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:23.2R2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:22.3R3-S3 junos:22.4R3-S3 junos:23.2R2 junos:23.2R2-J14 junos:23.4R2 junos:24.2R1 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1796530
Major
High CPU utilization due to BMP to be running with the longest and highest run count
Product-Group=junos
In a rare situation, BMP might falls into a loop processing rib-in RM update messages but none of message being sent out. It can hog CPU for long time until the BMP station state is bounced. Since BMP task has low priority, it will yield CPU if there are other tasks jump in. So BMP will only hog CPU when system is idle and won't block other important tasks.

Resolved In: evo:22.3X50-EVO evo:22.4R3-S2-EVO evo:23.2R2-S1-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:20.3X75-D440 junos:20.3X75-D52 junos:21.2R3-S9 junos:21.4R3-S9 junos:22.4R3-S2 junos:22.4R3-S5 junos:23.2R2-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: EVO L3 routing for BCM XGS Platforms
1828017
Minor
The pfemand crash will be observed when "clear bgp neighbor all" command is executed
Product-Group=junos
On all Junos and Evolved platforms, in a scaled setup when the "clear bgp neighbor all" command is executed or "restart l2-learning immediately" is executed, the pfemand crash will be seen which leads to the restarting of the Flexible Packet Forwarding Card (FPC).

Resolved In: evo:21.4R3-S10-EVO evo:22.4R3-S7-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:21.4R3-S10 junos:22.4R3-S7 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: QFX Access Control related
1851299
Minor
EX3400 Dot1x Radius accounting send incorrect value to the server for Acct-Input-Gigawords/ Acct-Output-Gigawords
Product-Group=junos
With Dot1x Radius Authentication and Accounting, when the Stop Accounting (due to disconnect) is sent to the Radius server the Acct-Input-Gigawords and the Acct-Output-Gigawords contains unexpectedly large value.

Resolved In: evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2-S1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1844623
Major
Stale MAC-IP entries are not cleared in an EVPN-VXLAN scenario when encapsulate-inner-vlan or decapsulate-accept-inner-vlan or both knobs are present
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when decapsulate-accept-inner-vlan or encapsulate-inner-vlan or both knobs are configured for a VXLAN (Virtual Extensible Local Area Network) and when any action corresponding to MAC-IP entries cleanup takes place, the MAC-IP entries will not be cleaned up from kernel. This will result in anomalies in device and could also lead to a core crash.

Resolved In: evo:21.4R3-S10-EVO evo:22.2R3-S6-EVO evo:22.4R3-S6-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:23.4X100-D20-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.4R3-S10 junos:22.4R3-S6 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: EX4000 PFE issues
1847159
Major
Reachability issues are seen on interfaces that are aggregated without address-family
Product-Group=junos
On Junos platforms, specifically on EX and QFX series aggregated interfaces configured without address-family results in reachability issues.

Resolved In: junos:24.4R1
PR NumberSynopsisCategory: EX interfaces issues
1580560
Major
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.
Product-Group=junos
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.

Resolved In:
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1815250
Major
ARP resolution issues might happen when VxLAN and non-VxLAN are both configured on the same ifd but different ifl
Product-Group=junos
Due to a conflict in the config between the VXLAN (Virtual Extensible LAN) hardware token and the VLAN (Virtual Local Area Network) traffic loss could happen as consequence of wrong path for ARP (Address Resolution Protocol)

Resolved In: junos:23.4R2-S4 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: jdhcpd daemon
1835753
Minor
DHCP-Relay short cycle protection can get stuck in Grace period
Product-Group=junos
DHCP-Relay short cycle protection can get stuck in Grace period

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1
PR NumberSynopsisCategory: Flow Module
1834338
Major
GRE traffic is getting blocked due to a software programming issue and MTU going below minimum value
Product-Group=junos
On Junos OS SRX platforms with GRE (Generic Routing Encapsulation) configured, due to a software programming issue, some threads have incomplete information while processing the data and even if "no-path-mtu-discovery" or "no-gre-path-mtu-discovery" is configured, the MTU going below minimum value (IPv4- 578, IPv6 1280) resulting in the GRE traffic being blocked i.e. complete traffic impact.

Resolved In: junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1860597
Major
Security log report messages w.r.t logical system is not generated
Product-Group=junos
show security log report cli command for logical systems is not working for 24.2R2, 24.4R1-S2, if log report is disabled under root system. Work around is available for this issue.

Resolved In: junos:22.4R3-S7 junos:23.2R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1782239
Major
After Routing Engine switchover PPPoE subscribers may fail to login
Product-Group=junos
On all Junos OS on MX Platforms, after Routing Engine (RE) switchover using BNG for PPPoE (Point-to-Point Protocol over Ethernet) subscribers, may impacting customers authentication or failing to connect.

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:19.4R3-J20 junos:19.4R3-S10-J1 junos:19.4R3-S13 junos:21.2R3-S7-J4 junos:21.2R3-S8 junos:22.1R3-S6 junos:22.3R3-S3 junos:22.4R2-S1-J6 junos:22.4R3-S1 junos:23.2R2 junos:23.4R2 junos:24.1R1 junos:24.2R1 junos:24.2R2
PR NumberSynopsisCategory: QFX L2 PFE
1820830
Major
Complete packet loss will be observed for the inter-VLAN traffic in EVPN-VXLAN CRB scenario
Product-Group=junosvae
On Junos QFX and EX platforms in an EVPN-VXLAN (Extended Virtual Private Network- Virtual Extensible LAN) CRB (Centrally-Routed Bridging) scenario where the ingress leaf switch is configured with ESI (Ethernet Segment Identifier) lags (i.e. the server is multihomed), if there is an overlap between ESI lag(s) trunk ID with physical port number(s) and overlap of DMAC (destination MAC) between VGA (Virtual Gateway Address) MAC address 00:00:5e:00:01:01 (CRB setup with VGA / GW is on spine) with VRRP (Virtual Router Redundancy Protocol) MAC (specifically for the VRRP group 1 MAC address 00:00:5e:00:01:01) on the physical ports of the Leaf switches, then traffic loss will be observed for the inter-VLAN traffic.

Resolved In: junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: RPD Interfaces related issues
1795659
Minor
"JTASK_NO_SOCKACCEPT: Process events: no read/accept method for MGMT socket -1" logs may be seen in the messages file or an external syslog server
Product-Group=junos
"JTASK_NO_SOCKACCEPT: Process events: no read/accept method for MGMT socket -1" logs may be seen in the messages file or an external syslog server

Resolved In: evo:22.2R3-S6-EVO evo:24.4R1-EVO junos:24.4R1
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1825835
Major
IPsec traffic loss is observed when SA is stuck in the routing table even when the IPsec tunnel does not exist on the device
Product-Group=junos
On MX platforms with MS-MPC/MS-MIC with IPsec (Internet Protocol Security) configured, IPsec traffic loss will be observed if an SA (Security Association) deletion request is sent by the peer just before the SA installation is completed. The issue happens in the scale scenario (4000 tunnels are configured, and when the SA count reaches up to 3900).

Resolved In: junos:21.2R3-J14 junos:21.2R3-S8-J10 junos:21.4R3-S9 junos:22.4R3-S5
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1825573
Major
Juniper Secure Connect will not get connected if loopback is configured as external interface
Product-Group=junos
On all SRX platforms, if a loopback interface is configured as an external interface in Internet Key Exchange (IKE) gateway and there are one or more loopback addresses configured without an IPv6 address configured against it, remote access solution will not work, and Juniper Secure Connect (JSC) will report an "HTTPS request failed" error.

Resolved In: junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: SRX branch platforms
1836235
Major
SRX default named.conf file is created with non dns-proxy related configuration changes
Product-Group=junos
On SRX platforms with dns-proxy configured, default named.conf file is created with non dns-proxy related configuration changes. This leads to halting of dns-proxy operation.

Resolved In: junos:21.4R3-S10 junos:24.2R2 junos:24.4R1 junos:25.1R1
1845997
Major
Packet drops are observed in the VPLS environment on SRX380 platforms in packet mode
Product-Group=junos
On Junos OS SRX380 platforms in packet mode, when VLAN (Virtual Local Area Network)-VPLS (Virtual Private LAN Service) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 (Layer 2) unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.

Resolved In: junos:22.4R3-S7 junos:23.2R2-S4 junos:24.2R2 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: ZT/YT pfe qos software issues
1851317
Minor
Packet drops are observed on rate-limited queues
Product-Group=junos
On MX platforms with MPC10E, MPC11E, MX304 and JNP10K-LC9600 with Class-of-Service (COS), packet drops are seen in rate-limited queues with high, medium-high or strict-high priority due to shallow buffer-size.

Resolved In: evo:25.2R1-EVO junos:25.2R1
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1858076
Major
The aftd process crash is seen on Junos OS platforms running MPC10, MPC11, LC4800, LC9600 line cards and in Junos OS platforms MX304, EX9200-15C
Product-Group=junos
On Junos OS platforms running MPC10, MPC11, LC4800, LC9600 line cards and in Junos OS platforms MX304, EX9200-15C, aftd process crash is seen resulting in crash of FPC (Flexible PIC Concentrator) line card while the route module of PFE (Packet Forwarding Engine) processing route churns as simultaneous actions (add/delete/read) by multiple threads on the process.

Resolved In: evo:24.4R2-EVO evo:25.3R1-EVO junos:23.2R2-S4 junos:24.4R2
PR NumberSynopsisCategory: Issues related to NETCONF
1792362
Major
RPC request for file copy with routing instances is failing
Product-Group=junos
On Junos OS and Junos OS Evolved platforms configured with routing instances, RPC (Remote Procedure Call) request for file copy using routing instance fails. There is no service/traffic impact due to this issue.

Resolved In: evo:22.2R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D47-EVO evo:22.4R0-J0-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:20.3X75-D52 junos:21.2R3-S9 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.2R2-S2 junos:24.2R1 junos:24.3R1
1800859
Major
Configuration push to device using RPC resulted in incorrect policy order
Product-Group=junos
On all Junos and Junos OS Evolved platforms,  RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.

Resolved In: evo:22.3X50-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.2X32-D30 junos:21.4R3-S9 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:25.1R1

 

Modification History

First publication 2025-03-06