Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX

Alert Description

Junos Software Service Release version 23.4R2-S4 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Solution

Junos Software service Release version 23.4R2-S4 is now available.

For the list of "Known Issues" see TSB96278 [juniper.net].

23.4R2-S4 - List of Fixed issues 

PR NumberCategory: SRX-1RU System Hardware defects
1843413
Major
On SRX4600 platforms configured in Chassis Cluster, split brain condition will be seen under two conditions: 1. A node is isolated from the cluster and is reinstalled with Junos image using a USB and then re-joined into the cluster 2. A standalone SRX4600 is moved into a cluster The split brain condition will lead to potential loss of packets or routing inconsistencies.
PR NumberCategory: QFX VC Datapath
1773425
Major
QFX5120, EX4650, EX4400, EX4100 Virtual Chassis (VC) platforms running Junos, drops Address Resolution Protocol(ARP) packets from remote leaf when Virtual Extensible LAN(VxLAN) encapsulated ARP packets are received from ingress port on one of the Flexible PIC concentrator (FPC) and egress port is an Aggregate Ethernet(AE) not having ingress port members on the FPC.
PR NumberCategory: SRX1600 MACsec
1847366
Critical
On SRX3xx series configured with native-vlan-id, after upgrading the device to Junos version 23.4R1 or higher the native-vlan-id option is missing under the interface hierarchy. This leads to a syntax error, stopping users from setting the native-vlan-id.
PR NumberCategory: "agentd" software daemon
1815195
Minor
On all Junos and Junos Evolved platforms, 23.2/23.4 release onwards, when gNMI is subscribed for the sensors, duplicate entries are seen. There is no traffic/service impact of the issue.
PR NumberCategory: MX YT-ZF Linecards Interface Software Category
1846164
Major
In a scenario where a fiber link has transport devices to amplify the signal, excessive logging of alarms for an interface can occur. The transport devices will amplify the incoming signal, which isn't valid when the fiber has been cut. This causes the router to receive a good signal and Rx power but it contains no valid data. In response, the interface on the router will attempt to link up repeatedly and after failing multiple retries, which is set per platform, the router will attempt to reinitialize the data path. This causes multiple alarms from the optic to get set and then cleared resulting in alarm logs in the system logs. This can become excessive if the link remains down for an extended period of time. To avoid continuous logging to the system log, after a number of retries the logs will be suppressed. The interface will continue to attempt to link up including reinitializing the the data path, but without the logging. This will allow the interface to link up when the physical link is repaired, and at that point the logs will stop being suppressed
PR NumberCategory: access node control protocol daemon
1841954
Major
The "show ancp subscriber detail" command is enhanced to display the port-up / port-down timestamps and port-down cause. It's neither an issue nor a regression an additional display output to enhance debuggability.
PR NumberCategory: This gnats category is required to track NG-SPC PRS for SBU
1841859
Major
On Junos platforms, specifically MX240, MX480 and MX960 supporting MX-SPC3 (Services Processing Card) service cards, if PIC (Physical Interface Cards) receives high traffic enough to make CPU (Central processing unit) almost 100% busy, it will go down, triggers flowd core-dump and cause network impact.
PR NumberCategory: the replication daemon (repd) for Shared Memory-base
1797189
Major
On all Junos and Junos Evolved platforms, repd core observed (in the "from" release) during ISSU.
PR NumberCategory: BBE routing
1826324
Critical
On all Junos and Junos Evolved platforms configured with subscriber management with GRES (Graceful Routing Engine Switchover) enabled, the subscribers will not come up after an ungraceful switchover as RE0( Routing Engine) went down and FPC's rebooted.
PR NumberCategory: Bi Directional Forwarding Detection (BFD)
1807182
Minor
On all Junos and Junos OS Evolved platforms with BFD (Bidirectional Forwarding Detection) authentication enabled, interface flap is observed and subsequent protocols will go down. This could result in traffic disruption for that protocol leading to outages.
PR NumberCategory: Border Gateway Protocol
1793714
Major
On all Junos and Junos Evolved platforms, when 'delay-route-advertisements always-wait-for-krt-drain' is configured, the EoR (End of Record) from the source peer of the routes is not received in the BGP (Border Gateway Protocol) peer which is sent by a BGP speaker to indicate the end of a record or a sequence of updates. This is due to the BGP router advertiser being stuck in the wait-for-inbound-convergence state, which may cause the KRT (Kernel Routing Table) queue to get stuck, thereby halting the advertisement of BGP routes.
1826685
Major
On Junos and Junos Evolved platforms, when a catastrophic Border Gateway Protocol (BGP) configuration change occurs, creating a new peer structure due to this configuration change, the BGP state transitions from open-sent to established multiple times (until the local device finishes cleaning the old BGP session). This results in traffic impact as the peer is reset multiple times (until a new peer connection is established).
1839318
Major
On all Junos and Junos OS Evolved platforms, setting next-hop (NH) doesn't work with BGP (Border Gateway Protocol) import policy, if the policy is also modifying community. Due to this, the traffic will not be forwarded to the intended NH.
1841090
Major
On all Junos and Junos Evolved platform, the rpd process will crash when an IPv6 (Internet Protocol Version 6) BGP (Border Gateway Protocol) - Labeled route is leaked using rib-groups to VRF (Virtual Routing and Forwarding) table and auto exported to IPv6 VPN(Virtual Private Network) table.
1845169
Major
On all Junos and Junos OS Evolved platforms, for MPLS L3 VPN's (Multi Protocol Label Switching L3 Virtual Private Network) if static route-target-filter as local is configured, BGP (Border Gateway Protocol) stops advertising VPN routes to EBGP (External BGP) peer.
PR NumberCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1807892
Major
A route can get stuck in 
1839288
Major
On all Junos and Junos Evolved platforms, when "clear bgp statistics" command is issued while one or more BMP peers are coming up the soft_assert will be hit. This issue has no impact on the traffic or services.
PR NumberCategory: BBE Remote Access Server
1826901
Major
On all Junos MX platforms, the authd process would crash if it attempts to access the subscriber management database (SDB) while the SDB is undergoing re-initialization due to a problem. Due to this, new subscriber login will be affected possibly for few seconds.
PR NumberCategory: EVO L3 routing for BCM XGS Platforms
1828017
Minor
On all Junos and Evolved platforms, in a scaled setup when the "clear bgp neighbor all" command is executed or "restart l2-learning immediately" is executed, the pfemand crash will be seen which leads to the restarting of the Flexible Packet Forwarding Card (FPC).
PR NumberCategory: MX304 Chassis specific platform 
1802195
Major
On Junos Evolved platforms and MX platforms with LC9600, MPC11 or MX304, the mapping optics temperature sensor name with ifd name is not correct. This PR is for correcting the behaviour and does not have any service impact.
PR NumberCategory: MX304 interface specific 
1861672
Major
On MX304 platforms, random interfaces operating at 100G speed will remain down after an FPC (Flexible Port Concentrator) reboot, resulting in traffic loss.
PR NumberCategory: MX304 line card platform software
1849915
Major
On Junos MX204, MX304, MX2010, MX2020, MX10004, MX10008, MX10016 with MPC11, LC2301/LC9600, LMIC16 and LC480 line cards, when installing and uninstalling specific telemetry sensors that export data from LC (Line Card), a few bytes of memory are allocated but not freed, leading to a memory leak. This issue is seen when "sensor-based-stats" is configured and LSP (Link State Path) flaps occur. Each flap triggers repeated installation and uninstallation of the telemetry sensor, accelerating memory consumption. Over time, this exhausts the memory allocated to aft-ulcd process causing FPC (Flexible PIC Concentrator) to reboot.
PR NumberCategory: MX Platform SW - FRU Management
1816912
Major
On Junos platforms, RE detects IIC read or write failures and triggers a minor alarm " RE1 IIC access alarm" during commit operations
PR NumberCategory: MX Platform SW - UI management
1805508
Major
The "show snmp mib walk jnxOperatingFRUPower" is NOT correctly updated for CB components.
PR NumberCategory: Class of Service
1828018
Major
An unrelated commit will trigger flap of protocol adjacencies (BFD, LFM, LACP, etc.) over aggregated Ethernet interfaces if scheduler-map is attached to aggregated Ethernet interfaces (this commit shouldn't necessarily be the first, but it may be). The issue is typically seen only once, the subsequent commits do not trigger further flaps, unless child links of the affected aggregated Ethernet interfaces flap.
1836528
Minor
On all Junos and Junos Evolved Platform, forwarding-class (FC) identifier (id) goes out of sync between the Routing Engine (RE) and Packet Forwarding Engine (PFE) when software upgrade is performed. When In Service Software Upgrade (ISSU) is performed, FC id goes out of sync between the RE and PFE impacting all class-of-service (CoS) features using FC id. When manual software upgrade is performed (without using ISSU) , this issue will be seen as a cosmetic display issue where the order in which the FC configurations are displayed will differ.
PR NumberCategory: QFX Access Control related
1840988
Major
On Junos EX2300, EX3400, EX4100, EX4300, EX4400 platforms, the issue in CWA (Centralised Web Authentication) occurs when authentication web-management is not configured, leaving stale entries until the authentication session clears, the interface where the client device is connected flaps or the end user MAC ages out. If memory is exhausted due to these stale entries, a PFE (Packet Forwarding Engine) process crash will occur, impacting traffic on all ports.
PR NumberCategory: OpenSSL and related subsystems
1815253
Major
The OpenSSL project has published security advisories for multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA88107 [juniper.net] for more information.
PR NumberCategory: DNS software support.
1816951
Minor
On SRX and vSRX platforms, when unified policy ( dynamic applications) is configured along with DNS profile configuration, a crash is observed.
1826129
Major
On all Junos SRX and vSRX series platforms Juniper networks Deep Packet Inspection (JDPI) gives events per packet. Domain Name System Firewall (DNSF) plugin is leaking memory while processing those events.
PR NumberCategory: CoS support on DNX
1850907
Major
On Junos OS ACX5448 and ACX710 platforms, the DEI(Drop Eligibility Indicator) bit in the VLAN(Virtual Local Area Network) header for the inner VLAN tag is being set incorrectly. As a result, packets with the DEI bit set will be dropped downstream.
PR NumberCategory: Layer 3 forwarding, both v4+v6
1849241
Major
On Junos OS ACX5448 and ACX710 platforms with native-vlan-id configured over L3 (Layer 3) interface with AE (Aggregated Ethernet), the device forwards packets with native VLAN (Virtual Local Area Network) tagged in the packet i.e. packets will be egressed out of the interface configured with VLAN matching the native VLAN resulting in the peer the device will drop the packet.
PR NumberCategory: jdhcpd daemon refactored for evo
1816246
Major
Under certain conditions, the DHCP session database becomes unstable or JDHCPD not getting IFL/IFD events which cause DHCP packets to fail to route to the kernel and then leads to DHCP packet drop.
PR NumberCategory: EVO L2 Control Plane PRs
1828741
Major
On all Apstra polled Junos Evolved devices experiencing heavy load. Specifically, when L2ald and l2ald-agent were engaged in high-volume data exchange over the management socket, L2ald becomes unresponsive.
1844623
Major
On all Junos and Junos OS Evolved platforms, when decapsulate-accept-inner-vlan or encapsulate-inner-vlan or both knobs are configured for a VXLAN (Virtual Extensible Local Area Network) and when any action corresponding to MAC-IP entries cleanup takes place, the MAC-IP entries will not be cleaned up from kernel. This will result in anomalies in device and could also lead to a core crash.
1853868
Major
When EVPN (Ethernet Virtual Private Network) routing instance has IRB (Integrated Routing and Bridging) interface with IPv6 (Internet Protocol version 6) address, ICMPv6 NA (Neighbour advertisement) reply from IRB IPv6 address doesn't have router flag. The ICMPv6 NA from IRB IPv6 should have router flag.
PR NumberCategory: mgd, ddl, odl infra issues
1825793
Minor
"show system configuration rescue" may show strange "Last changed" timestamp. It may happen under any time zone potentially and looks like there are some patterns. In case of "Asia/Tokyo", Last changed timestamp may show "1970-01-01 08:59:59 JST".
1839955
Major
On Junos OS Evolved platforms, when HTTPS URL is present as a part of file or mentioned explicitly in the configuration, and when there is a download attempted through this file the download fails. However, this is will not impact the forwarding traffic only the download through HTTPS will fail.
PR NumberCategory: EVPN control plane issues
1796532
Major
On all Junos and Junos Evolved platforms, duplicate mac-ip detection for IRB IP is not working since the IP move is not triggered after adding an IP address to the IRB interface.
1816672
Major
There are multiple EVPN instances each having separate IFL of AE IFD. AE is configured with per-esi lacp-oos-on-ndf on the AE IFD. On deactivating one of the instances, LACP on non-DF router comes out of "out-of-sync" state, causing CE device to move to Collecting distributing.
PR NumberCategory: EX4100 PFE
1831813
Major
On Junos EX platforms, the PFE's (Packet Forwarding Engine) handling of NEWSYSLOGD signals during UKERN file archiving is inefficient, leading to repeated memory allocations and subsequent memory leaks.
PR NumberCategory: EX4100 RE, Platform Infra, Drivers
1848292
Major
On the Junos EX platform, fan overspeed alarms may intermittently trigger as fan speeds exceed and fall below the set threshold, with no impact on service
PR NumberCategory: EX interfaces issues
1788328
Major
On all EX platforms with Virtual Chassis (VC) and Graceful Routing Engine Switchover(GRES) enabled, if during failover the secondary Flexible Physical Interface Card Concentrator (FPC) gets rebooted then there will be traffic loss of 20 seconds more than the expected traffic loss (1to2 seconds).
1793137
Major
On EX4100-24T, EX4100-48T, EX4100-48P, EX4100-48MP, and EX4100-24MP platforms, after a power cycle, the uplink interfaces may go down with a LOCAL-FAULT alarm. This issue is caused by an anomaly in the Broadcom PHY (bcm82756) third-party SDK code used on these devices.
1805100
Major
On EX4300-MP platforms in non-mixed VC mode, when the VC connection is established between the platforms, the ports don't pass traffic, which leads to minimum traffic loss.
1849992
Major
On EX4400 devices, inserting SFP+-10G-BX10-D/U or SFP+-10G-BX40-D/U into the 4x25G uplink module causes all ports on the Physical Interface Card (PIC) 2 to go down.
PR NumberCategory: EX4400 PFE software
1849952
Major
NA
1854253
Major
On Junos EX and QFX platforms when DHCP (Dynamic Host Configuration Protocol) option 82 settings are enabled under dhcp-security, hosts fail to get an IP address from the DHCP server.
PR NumberCategory: EX4400 platform
1826615
Major
On all EX4400 platform, all time sensitive protocols are getting flapped due to process call getting stuck in System Management Bus (SMBus).
1844354
Major
On EX4400 platforms with Media Access Control Security (MACsec) environment configured, if a transceiver is removed and then inserted again, MACsec will not work and a core file will be generated.
PR NumberCategory: Issues related to EX MACsec
1830395
Major
On all Junos and Junos Evolved platforms, when authentication-key-chain-name is configured with more than 31 characters, commit error is seen due to which MACSEC will not work with the configuration.
PR NumberCategory: PFE EVPN / VxLAN related issues on EX platforms
1852215
Major
On EX4400/EX4100/EX4650/QFX5120 platforms VoIP (Voice over IP) phones do not receive an IP address when the VXLAN (Virtual Extensible LAN) access port on the switch is configured as VoIP port causing voip tagged traffic on VXLAN access port to be dropped.
PR NumberCategory: Express PFE FW Features
1830706
Major
On all Junos platforms, when a filter instance is modified or deleted, there should not be any old Packet Forwarding Engine (PFE) instances. However, during these operations, old PFE instances are being incorrectly assigned, resulting in incorrect memory address allocation. This leads to an Flexible PIC Concentrator (FPC) crash after committing the configuration, causing traffic loss.
PR NumberCategory: Express PFE Services including JTI, TOE, HostPath, Jflow
1830575
Major
On all Junos platforms, the dcpfe crash is seen with a core-dcpfe dump when the ukern_trace handle buffer size is set to 10000. It is a rare issue.
PR NumberCategory: Express PFE L2 fwding Features
1802615
Major
Unreachability to VRRP gateway IP causes end host connectivity issues. This issue impacts unicast packets addressed to the VRRP gateway IP on QFX10002-36Q, QFX10002-72Q, QFX10008, and QFX10016 platforms. It is triggered by VRRP configuration and unicast traffic to the gateway IP. It impacts both IPv4 and IPv6 traffic.
PR NumberCategory: SRX1500 platform software
1845143
Major
On the Junos SRX1500 platform, the device reboots spontaneously because the watchdog is triggered unnecessarily.
1845407
Major
On SRX1500, "show snmp mib walk jnxOperatingTemp" and "show snmp mib walk jnxFruTemp" will not show up temperature reading for PSU temperature.
PR NumberCategory: SRX4100/SRX4200 platform software
1823978
Major
On Junos SRX platforms, due to common cache feature, more accurate IP address resolutions are being updated to the PFE (Packet Forwarding Engine). However, this led to increased CPU utilisation by the nsd (Network Services Daemon) process. Due to high CPU load, the newly resolved IP addresses may not be updated promptly to PFE leading to traffic loss.
PR NumberCategory: Interface Information Display
1631200
Major
IFL counter has a counter named "IPv6 transit statistics". It can be confirmed on "show interfaces extensive" command output. However, this counter is originally for IPv6 total statistics(transit + local) and the counter name was wrong from the first. On older releases like 19.1R1, as the support for IPv6 local stats was not available the local stats was always zero. So, the meaning of the counter name was the same to the counting content coincidentally. In latest releases support for IPv6 local stats has been added but the counter name was not changed. As the local stats will not be zero the difference between the meaning of the counter name and the counting content started being visible.
PR NumberCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1826194
Major
On all Junos and Junos Evolved platforms, rpd crash is observed during upgrade or restart since kernel takes more time to update ifstate information.
1843627
Critical
On all Junos Evolved platforms, a memory leak occurs when a routing instance configured with "vrf-table-label" is deactivated and then reactivated, followed by a Routing Engine (RE) switchover on dual RE systems. This issue causes a slow memory leak in the system.
PR NumberCategory: MX Inline Jflow
1813925
Major
On all MX platforms with MPC10/MPC11/LC9600, MX304 and EX9200-15C platforms, when any sensor configuration on protocols, for example, MPLS LSP, is configured and removed over a long period, the aftd-trio process starts a memory leak and eventually causes FPC to reboot.
PR NumberCategory: Kernel software for AE/AS/Container
1840734
Major
On all Junos platforms which support PS over RLT, after modifying or deleting and re-adding a logical interface on RLT interface, the logical interface remains down and the following log messages is seen in the messages log:DCD_CONFIG_WRITE_FAILED: IFL rlt0.0 configuration write failed for an IFL ADD: File exists after configuration change.
PR NumberCategory: Integrated Routing & Bridging (IRB) module
1815250
Major
Due to a conflict in the config between the VXLAN (Virtual Extensible LAN) hardware token and the VLAN (Virtual Local Area Network) traffic loss could happen as consequence of wrong path for ARP (Address Resolution Protocol)
1827648
Major
On all Junos QFX series platforms in an EVPN (Ethernet Virtual Private Network) VXLAN (Virtual Extensible Local Area Network) setup with CRB (Centralized Routing Bridge) architecture, ARP packets are not being learned, leading to traffic forwarding issues. This problem arises when ARP packets are sent from the firewall to the spine switches. The issue is linked to IRB (Integrated Routing and Bridging) handling and bridge domain re-incarnation, which triggers ARP request failures and impacts L3 forwarding.
PR NumberCategory: ISIS routing protocol
1837289
Major
On all Junos and Junos OS Evolved platforms configured with "protocols isis overload advertise-high-metrics" (without timeout) and graceful-restart, IS-IS (Intermediate System to Intermediate System) will start advertising high link metrics immediately as expected. However, when IS-IS is in graceful restart mode either via GRES (Graceful Routing Engine Switchover) switchover or restart routing, the high link metrics are not advertised and IS-IS continues to advertise the usual link metrics even when IS-IS graceful restart is completed. When the issue is hit, the node configured as an overload might be used for transit traffic based on the IGP metric.
1841108
Major
On all Junos and Junos OS Evolved platforms, in an ISIS(Intermediate System-Intermediate System) graceful restart scenario, helper node sends and programs its locally configured hold-time (180 secs) instead of the "Restart-duration" received as hold-time from DUT (210 secs), due to this incorrect update, the hold timer expires at the helper node before the GR (Graceful Restart) is complete on DUT and it causes a flap of ISIS adjacency on peer/helper Node.
PR NumberCategory: jdhcpd daemon
1714260
Major
On all Junos and Junos OS Evolved platforms, when Dynamic Host Configuration Protocol (DHCPv4) Relay is configured with forward-only mode along with "trust-option-82", DHCP-relay should not add another option 82 to the packet sent to the DHCP server. The DHCP server upon receiving the packet with two option-82 will respond only with 1st header of option-82 which might get dropped by the relay, thus the packet is not forwarded to the DHCP client and the DHCP session won't get established.
1833148
Major
On all Junos and Junos Evolved platforms when roaming between Wireless Access Points (WAP) and binding server is down, server failover does not happen in an active-server group even when "allow-server-change" is configured on Dynamic Host Configuration Protocol (DHCP) relay agent.
1854827
Major
On all Junos devices, management interface does not get an IPv4 from Dynamic Host Configuration Protocol (DHCP) even if the interface is bound. When power cycle or reboot is triggered, management is lost without traffic impact.
PR NumberCategory: jpppd daemon
1854387
Major
On Junos and Junos OS Evolved platforms, the jpppd (Juniper PPP daemon) process crash will be seen after a certain time of subscribers login/logout. The issue could be seen with the applications that write their private data in /mfs/var/sdb/shmem/sdb_intf.ad.db.
PR NumberCategory: Adresses ALG issues found in JSF
1804025
Major
On all SRX platforms configured with H323 Application Layer Gateway (ALG) when a H.323 audio call is placed which is not disconnected and RAS request and confirm messages are received and the traffic is changed between the Primary and backup nodes in a High availability (HA) mode multiple times, it will lead to flowd process crash.
PR NumberCategory: SRX power-mode-ipsec/power-mode-expresspath(PMI/PME)
1833746
Major
On SRX1500/SRX1600/SRX2300/SRX4K/SRX5K platforms with PMI (PowerMode IPsec) enabled, IRB (Integrated Routing and Bridging) traffic in Layer 2 switch mode is not supported, resulting in packet drops.
PR NumberCategory: Flow Module
1828819
Major
Application quality of service (AppQoS) rate limit in PowerMode IPsec (PMI) mode on Junos SRX5K and SRX4600 drop packets unexpectedly due to internal issue.
1846897
Major
In a vSRX High Availability (HA) setup, a high volume of orphaned backup sessions will be exhausting session resources. This happens because the timeout value for backup sessions is typically set to the minimum of 8 times the active session's timeout value and 1800 seconds. If the orphaned backup sessions accumulate and exhaust the session resources, the system will fail to allocate new sessions.
1856521
Major
On all SRX platforms in a cluster, during an HA switchover, especially with a large number of sessions (e.g., greater than 1M), CPU utilization spikes temporarily, reaching up to 95% for a brief period. This occurs during the primary node's reboot or HA switchover. The CPU spikes cause partial service impact, which can affect traffic for a short time during the event. Once the session scan is completed, CPU utilization should return to normal as the session synchronization and cleanup processes are finalized, reducing the load on the system and restoring traffic flow to its usual performance levels.
PR NumberCategory: Firewall Policy
1844191
Major
On all SRX platforms, if has one DNS server which was unresponsive and another which refuse responses or responds with a non-positive error code, the FQDN-based security policies will not work as expected and packets might hit a different allow/deny rule.
1847877
Major
On all SRX platforms, the Management Daemon (mgd) core is seen after a large number of configurations executed when configuring the network address book and attach it to a security policy.
PR NumberCategory: RPM, TWAMP feature related to SRX specific design
1830290
Major
On SRX4600 platforms when Real-time Performance Monitoring (RPM) related configuration is committed, 'gencfg no msg handlers for gencfg msg' log messages will be generated. This will not have any functional impact.
PR NumberCategory: User Firewall related issues
1845506
Major
On all SRX platforms with source-identify and logging enabled, the PFE (Packet Forwarding Engine) crashes if the source identity username and group-names exceeds certain count and length. The system self-recovers after the issue is hit.
PR NumberCategory: IPSEC/IKE VPN
1805690
Major
Stale IPSEC tunnel entry can be reported on the backup node's PFE
1818197
Major
On SRX platforms, if the outgoing interface of the Internet Protocol Security (IPsec) Virtual Private Network (VPN) peer goes down when the peer device operates in the Network Address Translation-Traversal (NAT-T) environment and the default route points to the secure tunnel interface (st0), there are chances of an internal routing loop which will lead a srxpfe process crash caused by the Memory Buffer (mbuf) corruption.
1833072
Major
On all Junos and Junos Evolved Platforms on rare circumstances, when the device is busy, the random number used for VPN negotiation cannot be generated by the third-party library API leading to IKEd process crash.
1834204
Major
On all SRX platforms (except SRX1600, SRX2300, SRX4700 and SRX5000 series with SPC3 card) using the IPsec-key-management service (KMD) for VPNs (Virtual private networks), the SRX becomes almost unresponsive impacting network when SNMP (Simple Network Management Protocol) requests for VPN information arrives from the PFE and are sent via the fxp0 interface immediately after a reboot before the IPC ( Interprocess communication) connection to the PFE is established.
1848834
Major
When IPSEC (Internet Protocol Security) is enabled, during a restart or failover, a failure in adding a node might occur while attempting to read from the Database. Consequently, when a deactivate operation is performed on the configuration, the system attempts to delete a node that was never successfully added. This mismatch between the system state and the database triggers a core dump.
1851652
Major
On all SRX platforms, if the active VPN (Virtual Private Network) tunnel is disabled or failed, the device does not correctly transition to negotiate with an active gateway. Instead, it continues attempting negotiation with the inactive gateway, leading to failed tunnel establishment.
PR NumberCategory: Security platform jweb support
1837925
Major
On Junos SRX (SRX1500, SRX4600, SRX4100 and SRX5K's) platforms, image upload via J-Web fails with an error "Access Error: 502 -- Bad Gateway".
1840753
Major
On all Junos SRX platforms, When J-Web is in use and user continously navigates between monitor -> interfaces and dashboard without waiting for the interface response. This leads to CPU (Central processing unit) spike.
1851362
Major
Due to GMT+x or GMT-x time zone is not supported, J-Web will fail to load after upgrading SRX.
1858466
Major
On all SRX platforms, Juniper Secure Connect (JSC) clients may fail to establish a VPN session after successful authentication if more than 20 concurrent connections per client IP are active. In a NATTed environment, the 21st connection will fail, and the customer must retry.
PR NumberCategory: Layer 2 Control Module
1855088
Major
In Junos EX and QFX platforms, when a port is configured with Inter-switch-link (ISL) trunk and the Ethernet ring protection switching (ERPS) protocol is enabled on the port, the commit command fails, causing the commit-check daemon process to crash and preventing the new configuration from being applied. This doesn't impact the devices traffic, performance, or management.
PR NumberCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1820882
Major
On all Junos and Junos Evolved platforms, in Ethernet VPN (EVPN) multihoming scenario with mac-pinning enabled, traffic drop will be seen when the Designated Forwarder role (DF) is changed.
PR NumberCategory: Label Distribution Protocol
1817712
Major
On all Junos and Junos Evolved platforms Label Distribution Protocol (LDP) sessions are not formed due to the configuration of "container-lsp" with an already existing configured lsp-template which has "ldp-tunneling" knob enabled.
PR NumberCategory: Issues related to Junos licensing infrastructure
1823449
Major
On all Junos OS Evolved platforms, when a reboot is performed, the license usage is not set for features like OSPF, BGP etc. Feature usage is not set again unless the commit is done.
1845079
Major
On Junos platforms agile-licensing infra, when upgrading to 23.4R1 and above, unnecessary trace log files related to licenses are generated. This issue has no impact on traffic.
1848160
Critical
On all JUNOS and JUNOS evolved platforms, while using license feature core is being generated for some processes.
PR NumberCategory: lldp sw on MX platform
1811545
Major
When LLDP is configured on interface all and there are AE interfaces configured, to disable LLDP on one of the AE "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, AE is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.
PR NumberCategory: Port-based link layer security services and protocols that a
1847418
Major
On MX devices with MPC10 linecard when applying Media Access Control Security (MACSec) configuration on IFL and removing it, MACSec negotiation fails and complete traffic blackholing.
PR NumberCategory: SW PRs for MPC10E Interfaces
1847378
Major
If interfaces on MPC10E card are configured with hold down timer and the link hit a short flap then it may take additional time for that link to be up. It cause interruption for traffic as well as control plane protocols which are enabled on that link, for example BFD, OSPF, LACP and etc .
PR NumberCategory: MPC11 ULC fabric software related issues.
1827058
Major
On MX platforms with MPC11E and LC9600 and MX304, when multiple fabric self ping errors and timeouts are seen, device attempts to recover by performing port bounces at fabric end. But when there are large number of self ping errors and timeouts are seen which require more than 256 port bounces, the affected PFE(Packet Forwarding Engine) will get disabled resulting in traffic loss.
PR NumberCategory: MPC11 ULC fabric software related issues.
1807410
Critical
On MX2020 and MX2010 platforms, during fabric link training, if the SFB (Switch Fabric Board) suddenly shuts down due to a power off or being unplugged at a specific moment, a SPMB (Switch Processor Mezzanine Board) crash can be seen. It is a timing issue
1812046
Minor
Once SFB2 or SFB3 or plane is manually offline in an attempt to recover from a Fabric Training Failure of one FPC, the neighbor slot FPC is not be able to stop the high speed link and is ending up with training failure as well.
PR NumberCategory: Multiprotocol Label Switching
1814358
Major
On Junos and Junos Evolved platforms with RSVP-TE (Reservation Protocol-Traffic Engineering) configured, when IGP (Interior Gateway Protocol) "overload" is configured on the transit router, the traffic should move away from the transit router. But in the issue scenario, the LSP (Label Switched Path) continues to stay across the transit router which has been marked as overload and traffic continues across the transit router resulting in traffic drops or using the suboptimal path for the LSP. The issue happens when Patherr is received for the re-optimized path and CSPF (Constrained Shortest Path First) computation is triggered before the backoff timer.
1854987
Minor
On all Junos and Junos Evolved platforms with normalization or auto-bandwidth configured for container Label Switched Paths (LSP) members, "in-place-lsp-bandwidth-update" configuration does not work as expected and Make-before-break (MBB) is triggered.
1857867
Major
On Junos OS and Junos OS Evolved platforms having container-LSP (Label Switched Path) with in-place-lsp-bandwidth-update configured, traffic loss is observed on the transit device when the old instance is deleted on the local device, which is being used even though the new instance was present after MBB (Make-Before-Break) occurred. The issue happens if the in-place-bandwidth-update fails and the old instance's route reference is not cleared due to its active weight, preventing the proper reallocation of traffic to the new instance.
PR NumberCategory: Multicast Routing
1845087
Major
On all Junos Evolved platforms with Multicast Virtual Private Network (MVPN) configured, MVPN traffic does not recover after clearing forwarding-cache using "clear multicast forwarding-cache instance all" command.
PR NumberCategory: Track Mt Rainier RE platform software issues
1776854
Major
PR1735843 has fixed a VM core on ACX5448 platform with the reason "panic: deadlres_td_sleep_q: possible deadlock detected". The same issue might also be seen on all other JUNOS vmhost platforms but with a different root cause.
PR NumberCategory: FreeBSD Kernel Infrastructure
1838460
Minor
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberCategory: Express Paradise PFE Sflow
1803542
Major
Recurring logs -ppcfpc-multi-svcs.elf: FDB :: Ipv4 route operation 2 failed. Rt_index are seen in PTX10008 after upgrade
PR NumberCategory: Issues related to PKI daemon
1839090
Major
On Junos platforms, during PKI (Public Key Infrastructure) certificate renewal in an HA (High Availability) setup, if the PKI daemon on the secondary node is busy, mismatched certificates will occur. If a failover happens, the mismatched certificates are used for IKE (Internet Key Exchange) tunnel establishment, causing tunnel failure and resulting in traffic loss.
1845573
Major
Added missing syslog messages for SCEP and CMPv2 certificate enrolment failure.
PR NumberCategory: QFX access control list
1823280
Major
On EX and QFX5K series switch with egress filters configured in the system, you may observe dfw error whenever collecting RSI.
PR NumberCategory: QFX PFE Class of Services
1786119
Major
On QFX5k virtual-chassis platforms working with 5e image, the pps rate display output for the egress interface would become zero after removing one of the VCP ports. The traffic is received as expected and it is only not displayed in the output.
PR NumberCategory: QFX5K hostpath
1827299
Major
On Junos QFX5k and EX4k platforms with IPv6 (Internet Protocol Version 6) PTP (Precision Time Protocol) configured, PTP synchronization issue will be observed due to IPv6 PTP packets are getting dropped i.e. blocked by PFE (Packet Forwarding Engine) filter resulting in downstream devices losing PTP status. This issue happens when IPv6 address with specific range is configured.
PR NumberCategory: QFX L2 PFE
1820830
Major
On Junos QFX and EX platforms in an EVPN-VXLAN (Extended Virtual Private Network- Virtual Extensible LAN) CRB (Centrally-Routed Bridging) scenario where the ingress leaf switch is configured with ESI (Ethernet Segment Identifier) lags (i.e. the server is multihomed), if there is an overlap between ESI lag(s) trunk ID with physical port number(s) and overlap of DMAC (destination MAC) between VGA (Virtual Gateway Address) MAC address 00:00:5e:00:01:01 (CRB setup with VGA / GW is on spine) with VRRP (Virtual Router Redundancy Protocol) MAC (specifically for the VRRP group 1 MAC address 00:00:5e:00:01:01) on the physical ports of the Leaf switches, then traffic loss will be observed for the inter-VLAN traffic.
1821012
Major
On all EX and QFX platforms, L2TP (Layer 2 Tunnel Protocol) cannot process and forward tagged frames for CDP (Cisco Discovery Protocol), VTP (VLAN Trunking Protocol), and UDLD (Unidirectional Link Detection). L2TP currently only supports untagged and native VLAN packets.
1824750
Major
On EX4K/QFX5K VC (Virtual Chassis) with RTG (Redundant Trunk Group) enabled, if one of the VC members is rebooted without any RTG member link, the VC will start sending the traffic in the backup link. Forwarding of traffic on the backup link which is not supposed to forward the traffic will lead to storm in the network.
1850203
Major
On Junos QFX5100, QFX5110, QFX5120, QFX5200, QFX5210, EX4100, EX4000, EX4400 and EX4300-48MP platforms, when a client sends a single DHCP (Dynamic Host Configuration Protocol) request, the switch generates and forwards two DHCP request messages to the VRRP (Virtual Router Redundancy Protocol) gateway. This behaviour causes the client to fail to renew its IP address, resulting in a loss of network connectivity.
PR NumberCategory: QFX L3 data-plane/forwarding
1823601
Critical
On all Junos QFX5K platforms, with ECMP (Equal Cost Multi Path) configured, when there is any routing protocol change (like ISIS cost metric change), the protocol traffic on the network is dropped.
1838623
Major
On all Junos QFX5K & EX4K platforms, using BGP extended community 'bandwidth' for WECMP (Weighted Equal Cost MultiPath) might results in traffic congestion as the bandwidth % are not adhered to, leading to delays or drops, depending on the network state and handling by the next-hop nodes.
1841913
Major
On QFX5210/AS7816 Platforms, when using forwarding-options custom profile , the PFE "show pfe route summary hw" outputs will differ as compared to the actual capacity of the HW for IPV4/IPV6 LPM route installation. As a result, when trying to scale to the max supported limits that are shown in the PFE "show pfe route summary hw" output, will result in route installation errors/table full errors in the PFE.
1854995
Major
On Junos QFX5200 platforms, a DCPFE (Packet Forwarding Engine Manager) crash may occur due to route churn involving large-scale next-hop changes when any PFE table is near capacity. This crash leads to an FPC restart, causing a complete outage. However, the system will recover automatically.
1855990
Major
On QFX5k, EX4k, EX2300 and EX3400 platforms, ECMP next-hop programming issue causes some prefixes to drop traffic. The issue is observed when the software-configured ECMP size (maximum-ecmp) exceeds the limit of 64 during a network churn event in the network. This triggers ECMP to skip updates, leading to stale forwarding paths and a temporary traffic freeze.
PR NumberCategory: QFX MPLS PFE
1830828
Major
On Junos QFX5K platforms with l2circuit configuration, forwarding traffic on all IFD (Physical Interface) with vlan-ccc encapsulation subunit is stopped when deleting or adding one of the IFLs (Logical Interfaces).
1844853
Major
On all QFX5120 and EX4650 platform, the push pop function is not performed when the frame originated is "untagged" then the device does not push the VLAN defined in the configuration.
PR NumberCategory: QFX EVPN / VxLAN
1839916
Major
On Junos EX4100, EX4400, EX4650 and QFX5120 platforms, in an Ethernet VPN Virtual Extensible LAN (EVPN-VXLAN) setup, when GBP (Group Based Policy) is configured with 'ingress-enforcement' a delay is observed in GBP installation after device reboot or link with ESI (Ethernet Segment Identifier) flaps. This leads to traffic disruption until the policy is installed.
1840251
Major
On Junos QFX5110, QFX5120, QFX5200, QFX5210, EX4100, EX4400 platforms on using the 'no-arp-suppression' hidden CLI knob, the ARP packets from the vtep (Virtual tunnel endpoints) remote side as well as access port side go to Queue 34 (ARP Queue) leading to instability of underlay protocols and causes traffic drop.
1842475
Major
On Junos OS QFX5k and EX4k platforms having EVPN-VxLAN (Ethernet VPN - Virtual Extensible Local Area Network) configured, traffic drops are observed due to missing hardware programming caused by stale hardware entries leading to VTEP (Virtual Tunnel Endpoint) Destination IP-address is not updated properly. The issue is observed due to VPLAG (Virtual Chassis Port Link Aggregation) flaps (any incident, such as a reboot of the gateway device / remote device) causes VPLAG to uninstall and install.
1843817
Major
On all Junos EX and QFX platforms configured with EVPN-VxLAN (Ethernet VPN - Virtual Extensible Local Area Network), access port to access port traffic on interfaces configured with Q-in-Q is transmitted with incorrect outer vlan tag. This impacts the traffic traversing via the interface.
PR NumberCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1825804
Major
On all QFX5120-48YM devices which are connected to JUNOS Evolved (Evo) platform, L3 protocols are not functioning on ports after Media Access Control Security (MACsec) is enabled due to packet size getting decreased due to decryption.
1845158
Major
When the 100G port with QSFP-100G-LR4-T2 is used the interface is negotiating to CAUI4 and when this happens the Speed needs to be explicitly set which was missing in the code.
PR NumberCategory: QFX5200/5110/5120/5210 ISSU Infrastructure
1703229
Major
When TISSU upgrade is done from 22.4 release onwards, the box come up as backup RE.
PR NumberCategory: QFX5200/5110/5120/5210 Platform optics related issues
1855279
Major
On Junos QFX5120-48YM platforms, auto-negotiation is not enabled for 10ge-type transceivers. Resulting in the port remaining down when connected to a peer device with 1G/10G.
PR NumberCategory: QFX5200/5110/5120/5210 Platfom issues
1711653
Major
On Junos QFX platforms, fan insertion trap will not be seen when fan is removed or inserted.
1850037
Major
On Junos QFX5K platforms running qfx-5e images, ungraceful shutdown may lead to file system corruption. Corruption of the RPM database in the Host OS can lead to several issues, including timeouts in certain Junos CLI show commands such as "show version", problems with FPCs (Flexible PIC Concentrators) or other FRUs (Field Replaceable Units) like power supplies and fan trays failing to initialize, or the device undergoing unexpected watchdog reboots.
PR NumberCategory: RPD infrastructure issues related to NSR, GRES, switchover, 
1848313
Major
OSPF neighborship goes down after NSR (Nonstop routing) switchover due to link flapping on Junos OS Evolved platforms with Dual RE and IPSEC configuration.
PR NumberCategory: RPD Interfaces related issues
1850620
Major
On Junos OS and Junos Evolved platforms, when BGP RIB Sharding is enabled, new BGP group/peer added gets stuck at Flags: . Route is established but freezes by sending 0 size window and the peer stops sending routes then, after some time the remote side tears the session down.
PR NumberCategory: KRT Queue issues within RPD
1801382
Minor
On all Junos and Junos Evolved platforms, A memory leak occurs during protocol, routing instance, or interface deactivation/activation, linked to improper IPv6 Interface Address (IFA) reference handling in the " ifx_dist_msg " process. This can lead to rpd crashes and service disruptions.
1817807
Major
On all SRX platforms, after the In-Band Cluster (ICU) upgrade if the system has routes pointing to the secure tunnel interface (st0) interface, or on clearing security IPsec sa on peer router a few routes might have trouble getting installed in forwarding, impacting traffic on the routes that are not installed after the upgrade.
1831421
Critical
On all Junos and Junos Evolved platforms, BGP (Border Gateway Protocol) route with PNH1 (Preserve Nexthop Hierarchy) may not be resolved correctly during rapid route fluctuations (e.g., link flaps). Specifically, when the preferred route (Rt1) experiences rapid deletions and re-additions, the system might incorrectly associate the PNH with an outdated route (Rt2).
PR NumberCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1838354
Major
On all Junos and Junos OS Evolved platforms, rpd (Routing Protocol Daemon) process crashes and crash file is generated. This is usually seen when the subscriber's session is created using the dynamic profile where the dynamic demux interface is configured under 'protocol igmp' (Internet Group Management Protocol) knob.
1858750
Critical
Route change is not being sent from routing daemon RIB to forwarding plane FIB in some scenarios after RPD restart. This leads to data out of sync between RIB and FIB causing this problem.
PR NumberCategory: RPD policy options
1849500
Major
On all Junos and Junos Evolved platforms, static route validation fails if it is using a leaked interface-route as next hop via a rib-group using "to rib " as matching condition under rib-groups import-policy. That would impact the traffic dependent on such a route.
PR NumberCategory: RPD route tables, resolver, routing instances, static routes
1771344
Major
On all Junos and Junos Evolved platforms having BGP (Border Gateway protocol) configured, when route is leaked via rib-group from one routing instance to another having the same AS (Autonomous System) number and one of the routing-instances has BGP configured with local-as, it is observed that even after configuring "loops" with any value greater than one as the number of loops option, the route still remains hidden instead of being active which results in traffic drop.
1812124
Major
On Junos and Junos Evolved platforms, the rpd process crash is observed on both REs (Routing Engines) and RE switchover was triggered when maximum-labels under MPLS(Multi Protocol Label System) address family is configured as 16 and an extra label is received.
1839631
Major
On all Junos and Junos Evolved platforms, commit check for overlapping prefixes will fail to commit when inet6 static route is configured with qualified next-hop and Integrated Routing and Bridging (irb) interface.
1842654
Major
On all Junos and Junos OS Evolved platforms the rpd (Routing Protocol Daemon) process will crash when dynamic tunnels are configured with overlap in destination networks under APP (Application-based tunnels) based and NHB (Next Hop Based) mode and rollback after some time.
1849202
Major
On all Junos and Junos Evolved platforms , the router learns routes through the BGP (Border Gateway Protocol) and has the feature: "BGP RIB Sharding" enabled for IPv4. These routes are stored in the Inet.0 routing table. Later, if the neighbor that announced this route or the protocols associated with the routing table of the used VRF (Virtual Routing and Forwarding) are removed, the route remains in the routing table, and hence traffic is forwarded to the stale routes.
PR NumberCategory: show route table commands, tracing, and syslog facilities
1808481
Minor
On all Junos Evolved platforms, while executing "show log messages", error message "sysctl kern.corefile not supported" is seen which is introduced during daemon initialisation.
PR NumberCategory: Resource Reservation Protocol
1819948
Major
On all Junos and Junos Evolved platforms, the LSP (Label Switched Path) re-optimization issue has been observed. LSP bandwidth change is unsuccessful due to bandwidth unavailable RSVP (Resource Reservation Protocol) PathErr.
1820893
Major
On all Junos and Junos Evolved platforms configured with MPLS/RSVP (Multiprotocol Label Switching/Resource Reservation Protocol), the detour path might not form when the "fast-reroute hop-limit" is set to 255. Thus, traffic loss will be observed when a node or link in an LSP fails, as the detour will not happen.
1823215
Major
On all MX and PTX platforms, In RSVP-TE (Resource Reservation Protocol-Traffic Engineering) scenario, when interface protected by bypass LSP (Label Switched Path) goes down, re-optimization of bypass can leads to unexpected path selection due to non consideration of SRLG (Shared Risk Link Group) or fate-sharing information with respect to protected interface during CSPF (Constrained Shortest Path First) path computation, could result in traffic impact due to this unexpected path selection.
1840543
Major
On all Junos and Junos Evolved platforms, when RSVP (Resource Reservation Protocol) LSP (Label Switched Path) is configured to perform loose hop expansion by enabling "expand-loose-hop" under MPLS (Multi-Protocol Label Switching) LSP knob and "graceful-restart" is configured in routing-options, rpd crash can be seen if it is undergoing graceful restart, causing service impact.
1850130
Major
On all Junos and Junos OS Evolved platforms, if the length of the authentication-key is 16 (the maximum allowed is 16 characters), RSVP authentication check fails. Authentication check succeeds if the length of the authentication-key is less than 16.
PR NumberCategory: PTX10K Line Card specific interface PRs
1794352
Major
On Junos EVO a channelized interface can get stuck in DOWN state.
PR NumberCategory: common srx platform ipv6 bugs
1834135
Major
IPV6 ping to multicast IP of all nodes fails on all SRX platforms using JEXEC (Juniper EXEC).
PR NumberCategory: SRX branch platforms
1747849
Major
On SRX-branch series platforms, configuring the "set system processes watchdog " command causes a commit kernel panic i.e. device will get stuck, and traffic loss will be observed. Watchdog related commands are unsupported.
1827123
Major
On the SRX 3xx series the root user does not get logged out from the shell mode even though the session logout time is configured. There is no traffic impact because of this issue, however, this is unexpected behaviour and not seen on other platforms.
1848557
Major
On SRX380 platforms, the local interface status or the peer device's interface reflects down after SRX380's reboot when both devices are configured with auto-negotiation on the SRX380's 4x10GbE ports.
PR NumberCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1806526
Major
On Junos MX platforms, PLL gets frozen because of the Hardware failure but still advertises the GM provided clock-class leading to synchronization failure and potential service impact. This affects clock signals distributed to all devices on the line-card, resulting in service degradation. The issue affects line-cards from MPC3E to MPC10E, chassis with SCBE3, and platforms such as MX10003 and MX204.
PR NumberCategory: MX10003/MX204 Platform SW - Chassisd s/w defects
1818517
Major
For MX10003 fan min and max threshold were -40 and +20 set. If fan RPM goes below/beyond those RPM, s/w start raising alarms. Similarly for MX204 fan min and max threshold were -20 and +20 set. On log analyzing, its seen FAN RPM was running +34% , that was beyond ma threshold. After discussing with h/w team, min & max threshold values are now decided -40 and +40. Due to this FAN RPM will be in bandwidth and no alarm will be seen.
PR NumberCategory: MX10003/MX204 MPC defects tracking
1807277
Major
On MX204/MX10003/SRX4600/EX9251/EX9253 platforms on changing the interface speed manually from 1G to 10G or from 10G to 1G while running traffic in high-priority queue causes the link on port to go down causing traffic impact.
PR NumberCategory: MX10002 Platform SW - Platform s/w defects
1809306
Major
On Junos MX204 platform and platforms with MPC7E/8E/9E, JNP10K-LC2101, JNP10003-LC2103, JNP10K-LC480 line cards, the interface goes down when re-initialisation issue occurs as part of system reboot, FPC(Flexible PIC Concentrators) restart, removal/insertion of optics etc, causing 'Avago SERDES' EA (Eagle ASIC) chip crash.
PR NumberCategory: SRX-1RU infrastructure SW defects
1839346
Major
On SRX4600 platform with chassis cluster, after performing an ISSU (In-service Software Upgrade) upgrade, the SPM (Secure Port Module) (fpc 0) against the node that is upgraded first will experience issue states where it can either cycle through 'Present' or 'Offline', or it will not report any errors but will be unable to perform any PFE (Packet Forwarding Engine) functions such as session management i.e. wont be able to process traffic resulting in traffic impact.
PR NumberCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1823577
Major
On SRX4600, in rare cases with heavy traffic, the FPGA may drop packets.
1846340
Major
On Junos SRX4600 platform devices deployed in a chassis cluster, after rebooting the Secondary node count of RIB(Routing Information Base) /FIB (Forwarding Information Base) is above 15000 FPC0 will not transition to Online, and a "FPC 0 Hard errors" chassis alarm may also be generated.
PR NumberCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1839023
Major
On MX240/MX480/MX960/MX2008/MX10008/MX10016/MX2010/MX2020 platforms with MPC10E/11E/LC9600 line cards and MX304 platforms, when Broadband Edge Internet Group Management Protocol (BBE IGMP ) is configured on Dynamic Host Configuration Protocol (DHCP) subscribers that are bound without any dynamic Virtual Local Area Network (VLAN) demux underneath, all the multicast traffic to the subscribers will be dropped.
PR NumberCategory: ZT/YT pfe infra issues
1856393
Major
Aft-trio crash will be seen in some scenario when subscriber interface on aft based line card is removed and at the same time those subscribers interfaces stats are collected
PR NumberCategory: ZT/YT pfe qos software issues
1793375
Critical
On all MX platforms having MPC10 or MPC11 having class-of-service configured, it is observed that in a scaled scenario (1500 IFLs (Interface Logical)), when queues are oversubscribed and the output interface starts to get congested, "CMERROR 0x230063 " or "XQSS_CMERROR_SCHED_QL4_INT_REG_DQU_QSUM_UDR" error message is seen. These cm errors would result in PFE (Packet Forwarding Engine) disable or the action configured in the device.
PR NumberCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1861020
Major
On Junos MX with MPC10/MPC11/LC9600 line cards and EX92K platforms, , when IRB (Integrated Routing and Bridging) is configured under EVPN (Ethernet Virtual Private Network) routing instance, and any event that cause changes in the existing target of indirect NH (Next Hop) to a new target, the new target's token is not updated in IRB NH, will result in OOO (Out of Order) errors and packet drops.
PR NumberCategory: ZT/YT pfe l3 forwarding issues
1803578
Major
On all MX platforms, the discrepancy is seen when attempting to establish LSP (Label Switched Paths) using MPLSoUDP (MPLS over UPD) routes due to the mishandling of IP options during tunnel processing.
1843505
Major
On all MX MPC10E/MPC11E/LC9600/MX304 and Junos Evolved platforms, configuring dynamic demux interface under IGMP (Internet Group Management Protocol) along with 'interface all disable', the appropriate 224 subnet route does not get added to PFE causing IGMP packets to be dropped.
PR NumberCategory: ZT/YT LUSS SW driver
1765394
Major
On Junos MX304 and MX platforms with LC9600 linecards, With the current error handling mechanism upon receiving fatal error on Flexible pic concentrators(FPC), leads to disable both the Packet Forwarding Engine(PFE) on a Physical Interface Cards(PIC) card and seen traffic impact.
1802243
Major
LC9600, LC4800, MX304 may experience a Line-card AFTD core as a result of a MAJOR CMRROR trigger on one slice of the multi-slice PFE.
PR NumberCategory: Trio pfe stateless firewall software
1827439
Major
On MX platforms with ukern based line cards (till MPC9), when the BGP FlowSpec session goes down or withdrawal of all BGP FlowSpec routes making entries on netflow.0 table to zero at once, a BFD (Bidirectional Forwarding Detection) flap occurs with the subsequent impact in the traffic.
PR NumberCategory: Trio pfe bridging, learning, stp, oam, irb software
1846365
Major
On MX platforms with ukern (legacy) FPC (Flexible PIC Concentrator) based in trio chipset and configured in an active-active ESI (Ethernet Segment Identifier) setup, traffic will be dropped after a flap of the DF (Designated Forwarder) or BDF (Backup Designated Forwarder) LAG (Link Aggregation Group) interface member.
1849854
Major
On MX304 and MX platforms with MPC10, MPC11, LC9600 and static Label-Switched Path (LSP) configured for Virtual Private LAN Service (VPLS), flooding does not happen in mesh-group when one of the interfaces goes down.
PR NumberCategory: Trio pfe l3 forwarding issues
1816378
Major
On MX204, MX10003 and MX platforms with MPC7, MPC8, MPC9, LC480, LC2101, LC2103, MPC10 and MPC11 line cards or EX92xx platforms with EX9200-40XS, EX9200-12QS, EX9253-6Q12C, EX9253-6Q12C-M line cards, SRX5400, SRX5600, SRX5800 platforms with SRX5K-IOC4-10G, SRX5K-IOC4-MRAT line cards, in a scenario where there could be fabric drops because of over-subscription or CRC errors, there could be case when the same tail entry get re-used across packets leading to packet corruption and CM error. This is a corner case and might lead to PFE(Packet Forwarding Engine) disable resulting in traffic loss.
PR NumberCategory: DDos Support on MX
1848317
Major
On all Junos MX platforms with line cards MPC10/11/LC9600/LC4800 and SCFD (Suspicious Control Flow Detection) enabled, when there are numerous flows being added, deleted, or modified simultaneously, the system experiences error messages or process crashes due to thread synchronization issues. The process crash will cause the FPC to restart.
PR NumberCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1829031
Minor
On all Junos and Junos Evolved products configured with TACACS+(Terminal Access Controller Access Control System Plus) authentication method, authentication seems to fail when TACACS+ server detects an error in sending authentication response to the host device. This impacts authentication and user cannot login into the device.
1843935
Major
On SRX300 series devices, when TACACS accounting is configured, after an upgrade to Junos 23.4R2-S2.1, the DHCP-relay may not work anymore and the shm-rtsdbd process may produce coredumps.
PR NumberCategory: Configuration mgmt, ffp, load-action, commit processing
1702344
Minor
On EVO platform, if the apply-path config has a wild-card <*> character after an attribute node then, the wild-card character is not processed. Due to which, the apply-path config is not expanded into matching prefixes by ui-infra. Please refer workaround section on how to avoid the issue.
PR NumberCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1799215
Major
On all Junos and Junos Evolved platforms, when the user attempts to issue the commit command after modifying the configuration post 'commit prepare', the commit discards the prepared commit cache as it is no longer valid and throws " commit fails" error and proceeds with the regular commit process from scratch.
1842518
Major
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
1847834
Major
On all Junos platforms with ephemeral db support, multiple daemons crash upon ephemeral commit Eg. chassisd, dcd, l2ald, l2cpd, mib2d and transportd causing service traffic impact. The services will self recover after the issue is hit in the network.
PR NumberCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1843602
Major
On all Junos platforms, a TCP (Transmission Control Protocol) connection issue occurs between the device and syslog server after an idle period exceeding 2 hours. The session gets terminated and remains in a closed state without initiating any new session until the syslog server configuration is deleted and added again. This impacts disruption in log forwarding to the remote syslog server.
1848106
Major
On all Junos and Junos OS Evolved platforms, eventd process crashes is observed. This happens when eventd process is processing the flooding of out of memory logs generated by any of the processes running on FPC (Flexible PIC Concentrator). This is traffic impacting depending on the process with memory issues.
PR NumberCategory: Issues related to NETCONF
1796297
Major
On all Junos and Junos Evolved platforms, commit confirmed command executed with remote procedure call (RPC) in private configuration mode is being allowed where ideally it should not be.
1852868
Major
Fixed xml format in rpc output
PR NumberCategory: Issues related to YANG Data Models
1826630
Major
When the YANG(Yet Another Next Generation)-compliant knob is configured, annotations containing non-alphanumeric characters are written as-is, instead of being escaped into their corresponding formats.
PR NumberCategory: Antivirus UTM issue
PR NumberCategory: web filterig issues
1816280
Major
On SRX platforms with UTM (Unified Threat Management) Sophos Anti-virus configured, srxpfe process (SRX Packet Forwarding Engine) crashes resulting in traffic impact due to memory corruption for insufficient buffer size allocation.
PR NumberCategory: MX10K linecard
1809511
Major
On MX platforms with LC2101 line cards and 10-gigabit ethernet interfaces configured in loopback mode, when Line card is booted multiple times, the ethernet interfaces on line card remains down and traffic on those interfaces will be impacted.
1809644
Major
On MX platforms with LC480, a crash file is generated because of this issue which results in entire ukern reboot. The issue happens due to race conditions. The ukern automatically reboots and the FPC (Flexible PIC Concentrator) comes up online. Traffic loss is observed till the FPC restarts after the ukern crash.
PR NumberCategory: VSRX platform software
1819911
Major
On vSRX3.0 platforms using SWRSS (Software Receive Side Scaling) having L2HA (Layer 2 High Availability) configured, traffic loss for RTO (Runtime Objects) traffic will observed and on secondary node sessions not getting cleared and sessions reaching maximum limit of 12M. The issue happens when RTO traffic not evenly distributed to all FLT (Flow Thread) threads over the fabric interface.
PR NumberCategory: Windsurf fabric software
1830457
Critical
On Junos MX2020 platform with non-native LCs (Line Cards) such as MPC-4/5/7 or MS-MPC, post FPCs (Flexible PIC Concentrator) restart the fabric planes goes into check state due to HSL2 (High Speed Link Version 2) 'failed word alignment' error. The link between fabric and FPC/PFE goes down hence there will be partial traffic impact through the impacted PFE and fabric-plane combination.
PR NumberCategory: Track Windriver Linux issues
1631579
Critical
A system equipped with specific line cards, the line cards will be stuck in the 'Present' state and later go 'Offline' after the line card or router is rebooted. Ideally, the Line Card should go 'Online' instead it goes 'Offline'.
1807939
Minor
RE uses enhanced mode RCMD protocol to communicate with the FPCs, by default. However, the FPC line cards do not understand the enhanced mode rcmd protocol. Hence the below logs generated. daemon.err rshd[618008]: Second port outside reserved range. After the failure, the communication falls back to the normal mode from enhanced mode.There is no production impact due to this issue. The fix has been implemented in the resolved versions, wherein the communication between RE and the FPC will now happen through the normal mode by default.

 

Modification History

First publication 2025-03-20