Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 23.4R2-S4 is now available for download from the Junos software download site

This is a list of "Known Issues" for Junos 23.4R2-S4

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Solution

23.4R2-S4 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 PFE
1833502
Major
EX2300 ECMP : Traffic failure due to ECMP programming failure on PFE
Product-Group=junos
On EX2300 series switch which is working with ECMP function, you may observe traffic failure due to ECMP programming error.

Resolved In:
PR NumberSynopsisCategory: NFX Dual CPE software category
1794559
Critical
Fab probe loss observed due to fab down on NFX cluster
Product-Group=junosvae
When HA is enabled on NFX150/250/350 and fabric links are configured, the fabric link monitored status is 'Down' leading to 'FL' HA status.

Resolved In: junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: "agentd" software daemon
1855112
Major
Telemetry streaming during ISSU (upgrading pre 22.1 image to 22.1+)
Product-Group=junos
In 22.1, JUNOS telemetry infrastructure under gone an enhancement in its message infrastructure. Due to this enhancement, telemetry streaming is not advisable during ISSU (upgrading pre 22.1 image to 22.1+).

Resolved In:
PR NumberSynopsisCategory: Border Gateway Protocol
1817834
Major
The rpd crashes when stale label entry keeps increasing when knob stale-labels-holddown-period is configured
Product-Group=junos
On all Junos and Junos Evolved platforms configured with the "stale-labels-holddown-period" setting and extensive label configurations (such as Multiprotocol Label Switching labels), the Routing Protocol Daemon (RPD) may crash if stale labels are not cleared periodically and keep accumulating. Due this, temporary traffic impact will be seen until the rpd process restarts.

Resolved In: evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S10 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
1826686
Major
Traffic impact due to BGP route stuck in hidden state
Product-Group=junos
On all Junos and Junos Evolved platforms, with BMP (BGP Monitoring Protocol) configured, the BGP route gets stuck in a hidden state with the next hop state as 'Next hop type unusable' leading to traffic drop.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S9 junos:22.4R3-S5 junos:23.2R2-S3 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: BBE Remote Access Server
1857161
Major
RADIUS COA request with INET6 RADIUS server is reporting CoA Error Processing.
Product-Group=junos
RADIUS COA request with INET6 RADIUS server is reporting CoA Error Processing.

Resolved In: junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: MX304 LCMD specific issues
1851100
Major
MX304 rebooted after misreading a temperature sensor
Product-Group=junos
On Junos MX304, due to erroneous data read from a temperature sensor, the device will shutdown.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.2R3-S6 junos:22.4R3-S7 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1784438
Major
MX304 not reachable with the power-off failure on the PIC
Product-Group=junos
When an MX304 LMIC is offline due to a power issue, it may take up to 20 minutes for the LMIC to come back online. You can configure event-options to reduce the time to restart the LMIC. See also: TSB83899 [juniper.net]

Resolved In: evo:23.2R2-S2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:22.2R3-S5 junos:22.4R3-S4 junos:23.2R2-J15 junos:23.2R2-S2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: QFX Access Control related
1851299
Minor
EX3400 Dot1x Radius accounting send incorrect value to the server for Acct-Input-Gigawords/ Acct-Output-Gigawords
Product-Group=junos
With Dot1x Radius Authentication and Accounting, when the Stop Accounting (due to disconnect) is sent to the Radius server the Acct-Input-Gigawords and the Acct-Output-Gigawords contains unexpectedly large value.

Resolved In: evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2-S1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: VPWS, L2 CKT, EVPN-VPWS
1844218
Major
ACX/Junos- Forwarding stops in l2ckt with hot-standby config at mpls core link switchover
Product-Group=junos
Traffic drop is seen with l2circuit redundancy (hot-standby) when primary and backup PEs are connected via same interface , We do have race conditions where updates of primary, backup and unlist next-hops might go out of order, and pfe might not program well. This is not a typical use-case and not a recommended to have hot-standby feature to used both primary and backup via same interface when two or more uplinks are available.

Resolved In:
PR NumberSynopsisCategory: All issues related to PFE Resiliency for ACX7K products
1823195
Major
Network Protocol Outage on ACX Junos platforms due to SER of Memory ECC Parity Errors
Product-Group=junos
On Junos ACX710/ACX5448 platforms, the protocols like BGP/ISIS/OSPF/LACP/BFD etc. will go down due to Soft Error Recovery (SER) of memory ECC parity error. The impact will be malfunction on critical memory.

Resolved In: junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: AF interface in Node Virtualization
1857225
Major
Input traffic on physical interface increases in the fabric statistics count despite locality bias feature configured
Product-Group=junos
On all MX platforms having MPC10 or MPC11 the traffic coming from any physical interface belonging to these MPCs will always take a fabric hop before forwarding to any physical link in egress. As a result despite locality bias feature being configured, instead of avoiding fabric hops while sending out of local PFE links, it will still be chosen but the fabric hop is forced and the input traffic on that physical interface will still end up showing increase in the fabric statistics count. But there is no traffic impact due to this issue.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: EVPN control plane issues
1846096
Critical
RPD restart immediately on EVPN Designated Forwarder PE with Graceful-restart results in 100% traffic loss for 12-15 secs
Product-Group=junos
With a EVPN PE running 24.2, 24.4 releases with Graceful restart enabled, if RPD is restarted or flaps, traffic loss for 15s could be seen to Multihomed CEs

Resolved In: evo:23.4R2-S5-EVO evo:24.2R2-EVO evo:25.1R1-EVO junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: EX4000 PFE issues
1847159
Major
Reachability issues are seen on interfaces that are aggregated without address-family
Product-Group=junos
On Junos platforms, specifically on EX and QFX series aggregated interfaces configured without address-family results in reachability issues.

Resolved In: junos:24.4R1 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: EX4100 PFE
1846286
Major
The error message will be seen on EX4100 platforms when deactivating/activating IRB interfaces
Product-Group=junos
On EX4100 platforms, When deactivating/activating IRB interfaces on vlans with vni enabled, error message will be observed.

Resolved In: junos:22.2R3-S6 junos:22.4R3-S6 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: EX interfaces issues
1580560
Major
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.
Product-Group=junos
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.

Resolved In:
1771119
Major
Mixed speed support in PIC2 phyless 4x10G uplink module
Product-Group=junos
1G and 10G are now default speeds in 10G ULM.

Resolved In: junos:24.2R1-S1-J4 junos:24.2R1-S2-J1 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
1831409
Major
On an EX4400 device with 4x25G Uplink module configured in 1GE or 25G speed, peer side of an interface with 10GBASE-T transceiver may remain up even when the IFD(xe-x/2/y) is not created
Product-Group=junos
On an EX4400 device with 4x25G Uplink module configured in 1GE or 25G speed, peer side of an interface with 10GBASE-T transceiver may remain up even when the IFD(xe-x/2/y) is not created. For this to happen, a speed mismatched configuration is needed, where a 1G speed or a 25G speed is configured on the PIC 2.

Resolved In: junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: EX4400 PFE software
1817034
Major
For Junos OS platforms, the OSPF neighborship gets stuck in EXSTART state after performing NSSU
Product-Group=junos
For Junos OS platforms, in a specific configuration change after NSSU (Nonstop Software Upgrade), i.e. delete and add sequence of LAG (Link Aggregation Group) bundles performed via load baseline configuration and re-apply original configuration, OSPF (Open Shortest Path First) session might get stuck in EXSTART state. This issue will impact the traffic.

Resolved In: junos:23.2R2-S4 junos:24.2R2-S1 junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: ISIS routing protocol
1841108
Major
Traffic drop is seen after GRES on ISIS peer
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in an ISIS(Intermediate System-Intermediate System) graceful restart scenario, helper node sends and programs its locally configured hold-time (180 secs) instead of the "Restart-duration" received as hold-time from DUT (210 secs), due to this incorrect update, the hold timer expires at the helper node before the GR (Graceful Restart) is complete on DUT and it causes a flap of ISIS adjacency on peer/helper Node.

Resolved In: evo:21.4R3-S10-EVO evo:22.3X80-D47-EVO evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S6 junos:23.2R2-S4 junos:24.2R2 junos:24.4R1 junos:25.1R1
1849975
Major
IPv6 link local addresses advertised through cRPD ISIS
Product-Group=junos
IPv6 link local addresses are announced through cRPD (Containerized Routing Protocol Daemon) ISIS (Intermediate System to Intermediate System) routing tables

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: jdhcpd daemon
1839348
Minor
DHCPv6 BLQ not working as expected
Product-Group=junos
DHCPv6 BLQ query is not working if queried with server address/server group since relay id information is not passed as part of query.

Resolved In: junos:22.4R3-S6 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1843596
Major
DHCPv6 Renew from a dual-stack CPE may be ignored if DHCP server is using DUID type 3 (DUID-LL) and DHCPv6 binding doesn't exist
Product-Group=junos
DHCPv6 Renew packets from dual-stack CPE could be silently ignored by MX configured as DHCPv6 local server if such DHCPv6 binding doesn't exist.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Juniper Device Manager VM Mgmt and infrastructure function
1774177
Critical
Performance degradation on NFX platform running WRL LTS19
Product-Group=junos
Degradation on all NFX platform running Wind River Linux (WRL) Long Term Support (LTS) 19, due to several components in LTS19 taking up more CPU/memory and reducing performance.

Resolved In:
PR NumberSynopsisCategory: Issues related to Junos Kernel Debug Streaming Daemon (jkdsd
1850033
Major
Telemetry query on /system xpaths does not work on QFX10002-36Q platform
Product-Group=junos
There would not be any streaming of values for paths under /system on QFX10002-36Q platform.

Resolved In: junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Flow Module
1807505
Major
On SRX5000 series and SRX4600, the setting "apply-to-half-close-state" for TCP sessions is not taking effect.
Product-Group=junos
On SRX5000 series and SRX4600, the setting "set security flow tcp-session time-wait-state apply-to-half-close-state" is not taking effect for sessions that are using express path (services-offload). This may lead to an increased number of sessions compared to earlier Junos releases which did not have an express path enabled by default.

Resolved In: junos:21.4R3-S9 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1850967
Major
L3MNHA with SRG1 IPSEC : MNHA ICL ipsec encryption link went down permanently after rebooting connected router through which ICL was established before. During this state IKE process got stuck at ~70% on MNHA Active node.
Product-Group=junos
Generic MNHA issue not specific to CSDS

Resolved In: junos:23.2R2-S4 junos:24.2R2-S1 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Firewall Policy
1809563
Major
The "show security match-policies" command results in a timeout error
Product-Group=junos
On all SRX platforms, when a scaled DNS (Domain Name System) configuration with approximately 500 entries is applied along with a policy configuration, issuing the "show security match-policies" command results in a timeout error. This issue has no functional impact.

Resolved In: junos:23.2R2-S4 junos:24.2R2-S1 junos:24.4R1-S2 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: JNP10K-RE3 CB Centralized MX timing
1817097
Critical
On MX10K4, MX10K8, MX10K16 systems, in some cases, a SPMB PFE (spmbpfe)core might be seen when system is going down.
Product-Group=junos
On MX10K4, MX10K8, MX10K16 systems , a SPMB PFE (spmbpfe) may occationally create a core file when the system is being shutdown. This event adds 10 seconds to the time to shut the system down. The delay dues to the PTP FPGA reset sequence during the shutdown process.

Resolved In: junos:24.4R1-S2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1798780
Critical
The system goes into a bad state when an SFB ungraceful offline happens due to a fatal Interrupt
Product-Group=junos
On MX platforms with SFB, in case of a fatal error encountered during SFB reboot ( due to hardware issue or ungrateful power restart ), SPMB will try to offline this SFB during bootup. At the same time, the system is busy training the fabric links to begin it online. This may cause a system-wide traffic impact due to the fabric not being consistent.

Resolved In: junos:21.2R3-S9 junos:22.4R3-S7 junos:23.2R2-S2 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: MX104 Software - Timing
1782868
Major
MX104 AFEB might crash following a change of PTP clock source.
Product-Group=junos
On MX104, the AFEB could crash and reboot following a change of PTP GM clock source, which affects traffic forwarding.

Resolved In: junos:21.2R3-S9
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1801129
Major
IP routes can get added to a deleted routing table
Product-Group=junos
On all Junos platforms routes can get added to deleted routing tables.

Resolved In: junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1850071
Major
PCT : Commit error seen while configuring system syslog host with routing instance
Product-Group=junos
PCT : Commit error seen while configuring system syslog host with routing instance

Resolved In:
PR NumberSynopsisCategory: PTX10K Routing Engine
1770585
Major
Junos vmhost upgrade will continue to reboot the box even if the upgrade has failed due to tar errors when the reboot option is used
Product-Group=junos
Issue identified when upgrading vmhost, but applies to all Junos platforms that support vmhost. When there are tar errors during the upgrade, and the reboot option is used in the upgrade command, the machine will still reboot the RE despite that the upgrade was not completed correctly. This will break the routing engine. It is necessary to stop the reboot, if error or tar problems occurred during the upgrade.

Resolved In: junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: QFX L2 PFE
1820830
Major
Complete packet loss will be observed for the inter-VLAN traffic in EVPN-VXLAN CRB scenario
Product-Group=junos
On Junos QFX and EX platforms in an EVPN-VXLAN (Extended Virtual Private Network- Virtual Extensible LAN) CRB (Centrally-Routed Bridging) scenario where the ingress leaf switch is configured with ESI (Ethernet Segment Identifier) lags (i.e. the server is multihomed), if there is an overlap between ESI lag(s) trunk ID with physical port number(s) and overlap of DMAC (destination MAC) between VGA (Virtual Gateway Address) MAC address 00:00:5e:00:01:01 (CRB setup with VGA / GW is on spine) with VRRP (Virtual Router Redundancy Protocol) MAC (specifically for the VRRP group 1 MAC address 00:00:5e:00:01:01) on the physical ports of the Leaf switches, then traffic loss will be observed for the inter-VLAN traffic.

Resolved In: junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2-S1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1790234
Major
JUNOS_REG: QFX5210: dcpfe core seen at __kernel_vsyscall, tvp_watchdog, dcbcm_driver_read32, soc_dcbcm_ipoll_check, cpu_sched_update_timers
Product-Group=junos
QFX5210: dcpfe core seen at __kernel_vsyscall, tvp_watchdog, dcbcm_driver_read32, soc_dcbcm_ipoll_check, cpu_sched_update_timers

Resolved In:
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1823771
Major
The SFP 10GBASE-T part No. 740-083295 on platforms running Junos/Junos EVO is unable to detect a linkdown
Product-Group=junos
On Junos/Junos EVO platforms with the SFP 10GBASE-T part No. 740-083295 Link up/Link down is randomly not detected.

Resolved In:
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1758400
Major
JUNOS_REG: QFX51200-48YM: Fan status output was not same after/before device vc-switch over.
Product-Group=junos
In a QFX51200-48YM-8C VC setup, after a a mastership switch over fan tray of linecard may not be displayed in show chassis hardware and show chassis environment. There is no functional impact

Resolved In:
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover, 
1848313
Major
OSPF neighbours go down due to link flapping after NSR switchover on Junos OS Evolved platforms with IPSEC configuration
Product-Group=junos
OSPF neighborship goes down after NSR (Nonstop routing) switchover due to link flapping on Junos OS Evolved platforms with Dual RE and IPSEC configuration.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1851629
Major
Next-hop APIs to support LDP stitching cases over BGP routes pointing to list of indirects
Product-Group=junos
On all Junos and Junos Evolved platforms this is an enhancement for Nexthop APIs to support LDP stitching cases over BGP routes pointing to list of indirects next-hops.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1692818
Major
The rpd process crash is observed
Product-Group=junos
On all Junos and Junos Evolved platforms configured with BGP rib-sharding, an rpd process crash is observed with route flap and route table deletion scenarios. It is a timing issue. During the rpd crash and restart, the routing protocols might be impacted and traffic disruption might be seen due to the loss of routing information.

Resolved In: junos:21.2R3-S2-J6 junos:21.2R3-S3-J23 junos:21.2R3-S4
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1849202
Major
BGP route still seen in routing table when route not available
Product-Group=junos
On all Junos and Junos Evolved platforms , the router learns routes through the BGP (Border Gateway Protocol) and has the feature: "BGP RIB Sharding" enabled for IPv4. These routes are stored in the Inet.0 routing table. Later, if the neighbor that announced this route or the protocols associated with the routing table of the used VRF (Virtual Routing and Forwarding) are removed, the route remains in the routing table, and hence traffic is forwarded to the stale routes.

Resolved In: evo:23.4R2-S4-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Issues related to control plane security
1859514
Major
For Passwordless authentication private/public keys are getting overwritten
Product-Group=junos
On Junos OS platforms supporting VMHost, keys are overwritten when ~/.ssh/id_rsa and ~/.ssh/id_rsa.pub keys are updated by the root user. This will not impact the forwarding traffic.

Resolved In:
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1825835
Major
IPsec traffic loss is observed when SA is stuck in the routing table even when the IPsec tunnel does not exist on the device
Product-Group=junos
On MX platforms with MS-MPC/MS-MIC with IPsec (Internet Protocol Security) configured, IPsec traffic loss will be observed if an SA (Security Association) deletion request is sent by the peer just before the SA installation is completed. The issue happens in the scale scenario (4000 tunnels are configured, and when the SA count reaches up to 3900).

Resolved In: junos:19.1R3-S14 junos:19.2R3-S11 junos:19.3R3-S12 junos:20.2R3-S10 junos:21.2R3-J14 junos:21.2R3-S8-J10 junos:21.4R3-S9 junos:22.4R3-S5
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1743031
Major
The picd process crashes when executing the CLI command "show service sessions/flows" or "clear service sessions/flows"
Product-Group=junos
On MX platforms with MS-MPC/MS-DPC, when the system is busy in the creation/deletion of sessions results in the picd process crashes for executing the CLI command "show service sessions/flows" or "clear service sessions/flows" aggressively (executing CLI command in 5-10 secs iteration).

Resolved In: evo:24.1R1-EVO junos:21.2R3-S4-J31 junos:21.2R3-S5-J41 junos:21.2R3-S6-J16 junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:24.1R1
PR NumberSynopsisCategory: SRX Argon module
1828721
Major
Flowd crash seen on SRX platforms with security metadata streaming enabled and then enabling AAMW traceoptions
Product-Group=junos
On all SRX platforms, when security metadata streaming is configured, the flowd process crashes if you enabled AAMW traceoptions, impacting traffic and service.

Resolved In: junos:21.2R3-S9 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: all ipv6 flow bugs on srx platforms
1809400
Major
SRX4600 with SOF is observed to continue sending ipv6 sessions even after removing the security policy
Product-Group=junos
While using SoF from an SRX4600, ipv6 sessions may be seen continuing to forward traffic despite its assigned security policy being removed as well as its session being flushed out of the session table.

Resolved In:
PR NumberSynopsisCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1803105
Major
PTP attribute changes on upstream device causes best clock master slot switchover
Product-Group=junos
On all MX platforms(except MX80) with multi line card chassis, when PTP slave or stateful streams are configured across multiple linecards with clock from same PTP time provider and the announce msg parameters changes from the upstream device, the best master clock (BMC) slot switchover is observed and is restored back within few seconds. Although the slot time interval is very less, it can still lead to major impact as the active PTP slot and clock path is switched over and results in re-routing of the clocks.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.4R1 junos:24.4R2 junos:25.1R1
1830281
Major
Sourceport-ID comparison resulting in higher value for MPC7E compared to MPC5E for distributed PTP architecture
Product-Group=junos
SourcePort-ID comparison across line cards between MPC7E and MPC5E/6E/3E-NG/2E-NG shall result in selecting MPC5E/6E/3E-NG/2E-NG compared to MPC7E/8E/9E/10E.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:21.2R3-S9 junos:21.4R3-S10 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: MX10003/MX204 Platform SW - Chassisd s/w defects
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1824162
Major
Error messages are seen when DHCP subscribers with BFD liveness detection are logging out
Product-Group=junos
On MX series devices, error messages can appear when DHCP subscribers with BFD liveness detection are logging out, leading to an improper heap memory cleanup.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1850604
Major
Packet duplication and flooding issues are seen when vpls bridge domain is configured on an aggregated Ethernet and label-switched interface across multiple line cards
Product-Group=junos
On MX240/MX480/MX960/MX2008/MX2010/MX2020/MX10003/MX10008/MX10016/MX10004 platforms with vpls (Virtual private LAN service) bridge domain configured, when the core facing ecmp (Equal cost multipath) are across multiple line cards and when MAC is learned up to MAC limit, packet flooding might be seen continuously for 5 mins after uplink or downlink going down causing network congestion.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:22.4R3-S7 junos:23.2R1-S1-J8 junos:23.2R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1731587
Minor
Telemetry data not sent for /junos/services/label-switched-path/usage/ on MPC11E cards
Product-Group=junos
Telemetry Stats are not visible for MPLS LSP( RSVP Based) when the core interface is MPC11/MPC10.

Resolved In: junos:21.2R3-S6 junos:21.4R3-S5 junos:22.2R3-S3
1848897
Major
24.4R1: SecPDT: MX960:With Local bias knob enabled, Fabric I/O stats pfe traffic stats tolerance is higher +50% with on-going traffic.
Product-Group=junos
After PR 1848897 fix, on all MX platforms having MPC10 or MPC11 the traffic coming from any physical interface belonging to these MPCs will always take a fabric hop before forwarding to any physical link in egress. As a result despite locality bias feature being configured, the input traffic on that physical interface will still end up showing increase in the fabric statistics count.

Resolved In: junos:24.2R2 junos:24.4R2 junos:25.1R1
1858076
Major
The aftd process crash is seen on Junos OS platforms running MPC10, MPC11, LC4800, LC9600 line cards and in Junos OS platforms MX304, EX9200-15C
Product-Group=junos
On Junos OS platforms running MPC10, MPC11, LC4800, LC9600 line cards and in Junos OS platforms MX304, EX9200-15C, aftd process crash is seen resulting in crash of FPC (Flexible PIC Concentrator) line card while the route module of PFE (Packet Forwarding Engine) processing route churns as simultaneous actions (add/delete/read) by multiple threads on the process.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S4 junos:24.4R2
PR NumberSynopsisCategory: Trio ASIC MQSS Software
1855966
Major
WAN Interfaces fail to receive hostbound traffic when OGE interface FIFO overflow error is detected
Product-Group=junos
On LC9600 MX10008/MX10004 and MX304 platforms , PFE fails to receive hostbound traffic when OGE interface FIFO overflow error is detected.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S7 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1837840
Major
Incorrect color-aware srTCM marking with yellow packet loss priority
Product-Group=junos
There was a software side limitation on the highest CBS that can be configured for MPCs that have LU type lookup chips due to a hardware PR. The Hardware PR was resolved in MX240/ MX480/ MX960/ MX2008/ MX2010/ MX2020/ MX10003/ MX10008/MX10016/EX9200/EX9204/EX9208/EX9214/EX9251/EX9253/SRX5400/SRX5600/SRX5800 platforms, but the software-side limitation was not removed for the same. Due to this limitation, whenever the CBS was configured above its limit (earlier 33m), the low-level parameters used to get configured such that the packets would not have any credits available, resulting in them getting marked as RED.

Resolved In: junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1865605
Critical
ARP packet drops may be seen if proxy-arp restricted is configured on an IRB interface
Product-Group=junos
On the Junos MX and EX9K platform, when a Bridge Domain(BD) is configured with an integrated Routing and Bridging(IRB) interface that has proxy ARP set to restricted mode, the switch forwards ARP requests only to the Routing Engine(RE) without broadcasting them across the VLAN. Thus, impacting the hosts within the same VLAN.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.2R2-S1 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1822793
Major
Few flows for BUM traffic gets dropped when a mix of MPC1-9 and MPC10 and above is used
Product-Group=junos
On Junos MX series platforms with preserve nexthop hierarchy knob enabled in setup having a mix of MPC10, MPC11 or LC9600 cards and MPC1-9 line card, BUM (Broadcast, unknown-unicast and multicast) traffic can be dropped for few flows. This occurs because the forwarding path detects a mismatch in the distribution pattern for these flows, resulting in packet loss.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Major
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1702344
Minor
Apply-path special handling for wildcard after a leaf attribute
Product-Group=junos
On EVO platform, if the apply-path config has a wild-card <*> character after an attribute node then, the wild-card character is not processed. Due to which, the apply-path config is not expanded into matching prefixes by ui-infra. Please refer workaround section on how to avoid the issue.

Resolved In: evo:22.4R0-J0-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.2R2-S3-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:23.4R2-S4-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:24.2R1
1818692
Major
Configuration commit fails due to mustd process crash
Product-Group=junos
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP

Resolved In: evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.2X32-D30 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Issues related to NETCONF
1792554
Minor
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241
Product-Group=junos
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241

Resolved In:
1819656
Major
In all Junos and Junos OS Evolved platforms, with Multinode High Availability configured, node configuration on primary might differ from backup due to configuration synchronization failure at the time of commit
Product-Group=junos
In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.

Resolved In: evo:21.4R3-S9-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:23.2R2-S2-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: MX10004 Chassis Category
1811485
Minor
Intermittent SFB I2C failure Alarm and Alarm cleared after 3 polls of 5 seconds due to ZF0 VDD 0.75V intermittent access failure
Product-Group=junos
Those sporadic raising and clearing SFB I2C Alarms are pure cosmetic and have no operational impact. The alarm threshold heuristic had been adapted to avoid such spurious Alarms. If there is no i2c access failure, reading out the voltage sensor, the error counter will be cleared after 24 hours. The Alarm will be only raised if the error is reported 3 times within 24 hours.

Resolved In: junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: VMHOST platforms software
1787608
Major
The chassisd crashes at first boot up after reboot
Product-Group=junos
Additional logging has been added to the primry Routing Engine. This is to help narrow down the issue which chassisd process restarted unexpectedly at snmp_init_oids( ) function on the primary Routing Engine while booting up.

Resolved In:
1795506
Major
A non service impacting warning message 'Failed to set 'memory.limit' will be observed
Product-Group=junos
On all Junos OS Evolved platforms a warning message "Failed to set 'memory.limit_in_bytes' attribute on '/user.slice' to '-1': Invalid argument" would be observed.

Resolved In: evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:24.2R1-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.4R1
PR NumberSynopsisCategory: VSRX platform software
1845886
Minor
vSRX3.0 kernel panic when deployed in Qemu version 8.1 and above
Product-Group=junos
With vSRX3.0 deployed on QEMU8.1 and above, the VM (Virtual Machine) does not start and keeps rebooting.

Resolved In: junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1844731
Major
High heap memory caused MX-SPC3 PIC to go offline
Product-Group=junos
On Junos platforms, specifically MX240, MX480 and MX960 supporting MX-SPC3 service cards, if inline-jflow is configured with huge scaled routes (~4M routes) resulting in kernel memory exhaustion that is high Heap Memory and SPC3 Pic goes offline.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:22.4R3-S6 junos:23.2R2-S4 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1