Alert Type

SRN - Software Release Notification
Low/NotificationNotification
Low/NotificationNotification

Product Affected

JUNOS

Alert Description

Junos Software Service Release version 22.4R3-S5 is now available for download from the Junos software download site.

This SRN contains the list of Known PRs which are not fixed in 22.4R3-S5. See TSB90223 [juniper.net] for the list of PRs included in 22.4R3-S5.

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

22.4R3-S5 - List of Known issues

PR NumberSynopsisCategory: "agentd" software daemon
1785219Added support for ADD/DEL based sensor config propagation in multithreaded xmlproxyd
Product-Group=junos
On all Junos and Junos OS Evolved platforms, support has been added for ADD/DEL based sensor config propagation in multithreaded xmlproxyd.

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: MX YT-ZF Linecards Timing software
1715831MX reports continuous PLL Access Failures for LC9600
Product-Group=junos
For platforms which are designed with Junos and EVO there could be the repetition of PLL Access Failure logs which are cleared after 5 seconds

Resolved In: evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.4R2-S2 junos:22.4R3 junos:22.4R3-J4 junos:22.4R3-S2 junos:23.2R1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: access node control protocol daemon
1814300L2BSA sessions remain down when port messages from ANCP neighbor are dropped in a scaled scenario after ISSU followed by GRES
Product-Group=junos
On all Junos MX platforms with dual RE (Routing Engine), having ANCP (Access Node Control Protocol ) and L2BSA (Layer 2 Bitstream Access) sessions under a scaled scenario (about 10k subscribers), when ISSU (Unified In-Service Software Upgrade) is performed followed by a GRES (Graceful Routing Engine Switchover), it is observed that the port-up messages from ANCP neighbor are dropped either at PFE (Packet Forwarding Engine) or by the ANCP daemon or BBE (Broadband Edge)/autoconf plugin which causes L2BSA sessions to remain down and as a result traffic over the affected subscriber sessions are dropped.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:23.2R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Border Gateway Protocol
1776851Internal Border Gateway Protocol (IBGP) sessions to Route Reflector (RR) are flapping due to " UPDATE prefix length 0 invalid ".
Product-Group=junos
On all Junos and Junos Evolved platforms when a too-short NLRI for RTC packets was detected, Internal Border Gateway Protocol (IBGP) sessions to Route Reflector (RR) are flapping due to " UPDATE prefix length 0 invalid ".

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO junos:19.1R3-S12 junos:19.2R3-S9 junos:20.2R3-S9 junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S8 junos:21.4R3-S7 junos:22.1R3-S6 junos:22.3R3-S3 junos:22.4R3-S1 junos:23.2R2 junos:23.4R2 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: BBE Remote Access Server
1766308Procedure for releasing remaining pools in an idle pool-domain
Product-Group=junos
Deactivate/delete, atcivate/add the domain-profile in configuration. This resets the domain-profile so that logins may proceed using the matching FramedPool value.

Resolved In:
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1784438MX304 not reachable with the power-off failure on the PIC
Product-Group=junos
When an MX304 LMIC is offline due to a power issue, it may take up to 20 minutes for the LMIC to come back online. You can configure event-options to reduce the time to restart the LMIC. See also: TSB83899 [juniper.net]

Resolved In: evo:23.2R2-S2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:22.2R3-S5 junos:22.4R3-S4 junos:23.2R2-J15 junos:23.2R2-S2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1811734The LFM session flaps will be observed at random
Product-Group=junos
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.

Resolved In: junos:19.3R3-S11 junos:21.2R3-S9 junos:21.4R3-S9 junos:23.2R2-S3 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: EVPN control plane issues
1821582Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.4R1
PR NumberSynopsisCategory: EX Chassis Interface Handling
1833698On Junos EX4100 and EX4400 platforms, switch core dump when user commits a command to ignore a "power entry module" alarm
Product-Group=junos
On Junos EX4100 and EX4400 platforms, at commit time to configure device to ignore a PEM (Power Entry Module) alarm, switch core dump due to an error on Chassis control process (chassisd).

Resolved In: junos:23.4R2-S3 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Sflow on qfx10k/ptx series PRs for defect & enhancement req
1841446SFLOWD process cores after FPC restart event.
Product-Group=junos
Once SFLOW is configured on most interfaces and traffic is getting sampled; in SFLOWD RE daemon, the adaptive sampling feature will start adapting the sampling rate on the interfaces. This is a continuous exercise and there will be interfaces getting adapted based on the traffic getting sampled. When the FPC gets restarted, all the interfaces will get down and come back again. During this the SFLOWD daemon receives the DOWN events followed by UP events for all the interfaces. The pointers related to maintenance of the adaptive list are getting modified in SFLOWD. During the further adaption on interfaces, this results in a SFLOWD core. Due to SFLOWD core, neither the forwarding nor SFLOW feature is getting affected. Based on the analysis, this core is seen only when all the interfaces on which SFLOW is enabled are going down at once.

Resolved In:
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1827648ARP not learned on Switch Leading to Traffic Drop in EVPN-VXLAN Setup
Product-Group=junos
On all Junos QFX series platforms in an EVPN (Ethernet Virtual Private Network) VXLAN (Virtual Extensible Local Area Network) setup with CRB (Centralized Routing Bridge) architecture, ARP packets are not being learned, leading to traffic forwarding issues. This problem arises when ARP packets are sent from the firewall to the spine switches. The issue is linked to IRB (Integrated Routing and Bridging) handling and bridge domain re-incarnation, which triggers ARP request failures and impacts L3 forwarding.

Resolved In: junos:22.2R3-S5 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: ISIS routing protocol
1841108Meta: Traffic drop seen after GR GRES
Product-Group=junos
During further debugging, we found a corner case scenario where the helper node (in this case moneybus), sends and programs its locally configured hold-time (180 secs) instead of the "Restart-duration" received as hold-time from DUT (210 secs). Due to this incorrect update, the hold timer expires at the helper node before the GR is complete on DUT and it causes a flap of ISIS adjacency on PEER/Helper Node.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.4R1
PR NumberSynopsisCategory: SRX Firewall Authentication
1829894Captive portal authentication fails when firewall-authentication is used in conjunction with identity management services (JIMS)
Product-Group=junos
On all SRX platforms, when a user tries to authenticate to a captive portal to get access to resources, the authentication is successful, but the user is rerouted back to the captive portal with no resources access.

Resolved In: junos:21.2R3-S9 junos:21.2X32-D30 junos:22.2R3-S5 junos:22.3R3-S4 junos:23.2R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1722689IKED cores are generated in node1, while doing ISSU upgrade from any release before Junos 22.4R1 to Junos 22.4R1 or later.
Product-Group=junos
On all SRX platforms in chassis cluster which support ISSU, when the JUNOS IKE package is present and IPSec VPN is configured, ISSU is not supported from any release before 22.4R1 to 22.4R1 or later. You can use CLI command 'show version' to confirm if JUNOS IKE package is present on your device.

Resolved In:
1805690MNHA: Stale IPSEC tunnel in Backup node
Product-Group=junos
Stale IPSEC tunnel entry can be reported on the backup node's PFE

Resolved In: junos:24.4R1
PR NumberSynopsisCategory: Security platform jweb support
1837925Junos image upload via J-Web fails on select SRX platforms
Product-Group=junos
On Junos SRX (SRX1500, SRX4600, SRX4100 and SRX5K's) platforms, image upload via J-Web fails with an error "Access Error: 502 -- Bad Gateway".

Resolved In: junos:23.2R2-S3 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1827058The PFE gets disabled due to large number of fabric self ping errors
Product-Group=junos
On MX platforms with MPC11E and LC9600 and MX304, when multiple fabric self ping errors and timeouts are seen, device attempts to recover by performing port bounces at fabric end. But when there are large number of self ping errors and timeouts are seen which require more than 256 port bounces, the affected PFE(Packet Forwarding Engine) will get disabled resulting in traffic loss.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1759082Junos OS and Junos OS Evolved: Inconsistent information in the TE database can lead to an rpd crash (CVE-2024-39541)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA83001 [juniper.net] for more information.

Resolved In: evo:22.3X50-EVO evo:22.4R3-S2-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:22.4R3-S1 junos:22.4R3-S2 junos:23.2R2 junos:23.2R2-J14 junos:23.4R1-S1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1829765uKern DDOS Aggregate stats not updated for BFD packets at system wide and FPC level
Product-Group=junos
BFD Aggregate policer in 22.4R3S5 polices BFD Single-Hop packets. Hence the BFD Aggregate statistics may not reflect accurate statistics for other BFD packets like Multihop and Bundle. This will be fixed in upcoming release.

Resolved In:
1830188clear ddos-protection protocols statistics will not clearing statistics at the PFE level
Product-Group=junos
DDoS clear statistics command will not work in 22.4R3-S5 release. DDoS violation reporting happens on the basis of incoming rate and not based on statistics, hence DDoS functionality will not be impacted. only clear stats will not work, we will fix it next release.

Resolved In:
PR NumberSynopsisCategory: Protocol Independant Multicast
1767314RPD may restart unexpectedly when MSDP peers were reset or closed
Product-Group=junos
When an MSDP peer is terminated, the peer's information may not be cleaned up properly. Causing the RPD process to restart unexpectedly.

Resolved In: evo:23.2R2-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:22.4R3-S1 junos:23.2R2-S1 junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: SRX branch platforms
1803966The cl interface goes down when the dl interface is disabled for link failover
Product-Group=junos
On the SRX300 series platforms and SRX550 supporting the LTE Mini-Physical Interface Module (Mini-PIM), the cellular interface (cl) goes down when the dialer interface (dl) interface is disabled for link failover.

Resolved In: junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
1821368DAC interface does not send fault signal to a peer device when the DAC interface is admin disabled
Product-Group=junos
On SRX380 platform, when a DAC interface is admin disabled, the DAC interface does not send a fault signal to a peer device and on peer device it will reflect as up.

Resolved In: junos:23.4R2-S3 junos:24.2R1-S2 junos:24.2R2 junos:24.3R2 junos:24.4R1
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1766578The FPC Crash will be observed on Junos MX platforms
Product-Group=junos
On Junos MX platforms with dual RE, repeated reboots of a SCBE2/ SCBE3 (Switch Control Board) during FPC transition state can trigger multiple PCIe (Peripheral Component Interconnect) interface error alarms. This results in input/output failures for the fabric planes on that SCB ( SCBE2/ SCBE3), leading them to enter a faulty state. Consequently, the affected FPC crashes, impacting traffic on the line card.

Resolved In: junos:21.2R3-S9 junos:21.4R3-S8 junos:23.2R2-S1 junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1818853Enabling "preserve-nexthop-hierarchy" knob under "l2-circuit resolution" stanza causes multicast traffic to be replicated several times
Product-Group=junos
On Junos MX platforms with certain licecards when the knob 'preserve-nexthop-hierarchy' is configured under protocol L2 (Layer2)circuit, the native multicast traffic is getting replicated multiple (depending on the number of Packet Forwarding Engine which is part of multicast replication) times on the egress interface. This is not expected behaviour and can cause possible bottleneck/forwarding issues.

Resolved In: evo:24.4R1-EVO junos:24.4R1
PR NumberSynopsisCategory: Configuration management, ffp, load action
1780549cRPD- configuration history/commits are not shown when docker is restarted/booted with new container id.
Product-Group=junos
cRPD- configuration history/commits are not shown when docker is restarted/booted with new container id.

Resolved In: evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:23.4R1-S1 junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: VMHOST platforms software
1787608The chassisd crashes at first boot up after reboot
Product-Group=junos
Additional logging has been added to the primry Routing Engine. This is to help narrow down the issue which chassisd process restarted unexpectedly at snmp_init_oids( ) function on the primary Routing Engine while booting up.

Resolved In:
PR NumberSynopsisCategory: QFX10002 Platform
1818082QFX10002-60C - random 10G link failures on a QFX10002 system with densely populated transceivers
Product-Group=junos
In a system with densely populated transceivers, some 10G links would fail to come up after reboot or image install. These errors show up as "REMOTE-FAULT" errors on the interfaces.

Resolved In: junos:24.2R1-S2 junos:24.2R2

 

Modification History

Published 2025-03-25