Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX MX NFX QFX SRX vSRX

Alert Description

Junos Software Service Release version 24.4R1-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Solution

Junos Software service Release version 24.4R1-S2 is now available.

24.4R1-S2 - List of Fixed issues 

PR NumberSynopsisCategory: BBE Cloud Infrastructure
1853279
Major
Loss of subscriber state is observed when cluster node restarts
Product-Group=junos
Severity=Major
On BNG (Broadband Network Gateway) CUPS Controller, when a cluster node that is hosting NFS share for the PVCs (Persistent Volume Claims) mounted by CPi and Scache micro-service fails, both the CPi and the sache will restart and all subscriber state will be lost.
PR NumberSynopsisCategory: NFX Layer 3 Features Software
1832087
Major
IKE SAs tunnel is down for IPv6 with IKEv1 on NFX350
Product-Group=junos
Severity=Major
On NFX350 with flex mode, traceoptions consume memory which causes IKE (Internet Key Exchange) SAs (Security Associations) tunnel to be down for IPv6 with IKEv1. Users should enable selective traceoptions to allow other components to work with limited memory.
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1855947
Critical
During ISSU the repd experiences a process crash in the master RE during the image validation phase
Product-Group=junos
Severity=Critical
On MX240/480/960 with dual REs (Routing Engine), when performing ISSU (In-Service Software Upgrade) from 23.4R1 to 24.4R1, the replication service daemon (repd) will core in master Routing Engine (RE) during image validation phase. The master RE becomes unresponsive, and the system drops to emergency shell mode (# prompt).
PR NumberSynopsisCategory: Border Gateway Protocol
1841090
Major
The rpd process will crash when secondary route in VRF is auto-exported
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platform, the rpd process will crash when an IPv6 (Internet Protocol Version 6) BGP (Border Gateway Protocol) - Labeled route is leaked using rib-groups to VRF (Virtual Routing and Forwarding) table and auto exported to IPv6 VPN(Virtual Private Network) table.
PR NumberSynopsisCategory: JNU issues in CSDS solution
1854326
Major
After the JNU config is deleted and added back jnuadmin's uid changes
Product-Group=junos
Severity=Major
Not impacting production.
1854356
Major
jnud continues to further sync with the MX controller when the schema tar file failed to secure copy from satellite to the controller
Product-Group=junos
Severity=Major
On Junos Node Unifier (JNU) topology when the schema tar file failed to secure copy (scp) from satellite to the controller, the jnud process continues synchronizing with the MX Series controller.
PR NumberSynopsisCategory: DNS software support.
1816951
Minor
Crash dump on DNSF plugin observed on SRX platforms
Product-Group=junos
Severity=Minor
On SRX and vSRX platforms, when unified policy ( dynamic applications) is configured along with DNS profile configuration, a crash is observed.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1839955
Major
On Junos OS Evolved platforms, HTTPS download fails when HTTPS URL is present in the configuration
Product-Group=junos
Severity=Major
On Junos OS Evolved platforms, when HTTPS URL is present as a part of file or mentioned explicitly in the configuration, and when there is a download attempted through this file the download fails. However, this is will not impact the forwarding traffic only the download through HTTPS will fail.
PR NumberSynopsisCategory: EVPN control plane issues
1857154
Major
Using SRv6 or MPLS IPv6 encapsulation over EVPN instances causes IPv4 packets to be dropped
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms configured with EVPN-VPWS (Ethernet Virtual Private Network - Virtual private wire service ) instance with SRv6 (Segment Routing IPv6) encapsulation or with IPv6 MPLS (Multiprotocol Label Switching) encapsulation causes all IPv4 packets to be dropped and experience complete traffic loss for IPv4 packets.
PR NumberSynopsisCategory: EX4400 PFE software
1854253
Major
Devices fail to obtain an IP address when DHCP Security Option 82 is enabled
Product-Group=junos
Severity=Major
On Junos EX and QFX platforms when DHCP (Dynamic Host Configuration Protocol) option 82 settings are enabled under dhcp-security, hosts fail to get an IP address from the DHCP server.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1852215
Major
VoIP Phones are unable to receive an IP address with or without dot1x configuration
Product-Group=junos
Severity=Major
On EX4400/EX4100/EX4650/QFX5120 platforms VoIP (Voice over IP) phones do not receive an IP address when the VXLAN (Virtual Extensible LAN) access port on the switch is configured as VoIP port causing voip tagged traffic on VXLAN access port to be dropped.
PR NumberSynopsisCategory: IoT data filtering/streaming
1845645
Major
Security-metadata streaming is impacted due to dynamic-filter issue
Product-Group=junos
Severity=Major
On Junos SRX1600/SRX2300/SRX4300, the dynamic filter feature, which is part of the security-metadata-streaming service, fails to establish a connection with the cloud service on port 8444. This prevents the device from establishing secure authentication with the cloud service, impacting the IOT (Internet of Things) policy's functionality for HTTP and DNS (Domain Name System) threat detection and logging.
PR NumberSynopsisCategory: jdhcpd daemon
1854827
Major
Unable to assign an IP address on management interface with DHCP configuration even if DHCP is bound after a power cycle
Product-Group=junos
Severity=Major
On all Junos devices, management interface does not get an IPv4 from Dynamic Host Configuration Protocol (DHCP) even if the interface is bound. When power cycle or reboot is triggered, management is lost without traffic impact.
PR NumberSynopsisCategory: jpppd daemon
1854387
Major
The jpppd process will crash with frequent subscribers login/logout
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, the jpppd (Juniper PPP daemon) process crash will be seen after a certain time of subscribers login/logout. The issue could be seen with the applications that write their private data in /mfs/var/sdb/shmem/sdb_intf.ad.db.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1852968
Major
The SRX platform may experience a flowd process crash and generate core dump files when the ALG feature is enabled
Product-Group=junos
Severity=Major
On SRX platforms running the Junos Operating System (OS) with Application Layer Gateway (ALG) enabled, in rare scenarios, flowd process can crash and crash files are generated. While the platform eventually recovers, traffic loss will occur during this process.
PR NumberSynopsisCategory: Flow Module
1833132
Major
[False Drop messages for defrag traffic] Packet-drop records with fragmented traffic ", Dropped by FLOW:Defrag return error" seen on " show security packet-drop records "
Product-Group=junos
Severity=Major
monitor security packet drop records show the packets are dropped with defrag error. Actually the packets are processed correctly by the flow. the records are reported as dropped by mistake only.
1859062
Major
The flowd process crash when service offload and system stats are enabled
Product-Group=junos
Severity=Major
On SRX5K platforms, when service offload feature is enabled and system stats are enabled, the flowd process crashes which impacts the network.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1850967
Major
L3MNHA with SRG1 IPSEC : MNHA ICL ipsec encryption link went down permanently after rebooting connected router through which ICL was established before. During this state IKE process got stuck at ~70% on MNHA Active node.
Product-Group=junos
Severity=Major
Generic MNHA issue not specific to CSDS
PR NumberSynopsisCategory: Firewall Policy
1809563
Major
The "show security match-policies" command results in a timeout error
Product-Group=junos
Severity=Major
On all SRX platforms, when a scaled DNS (Domain Name System) configuration with approximately 500 entries is applied along with a policy configuration, issuing the "show security match-policies" command results in a timeout error. This issue has no functional impact.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1824880
Major
IPsec VPN tunnel on specific platforms will be brought down when AES_GCM algorithm is used along with ESN
Product-Group=junosvae
Severity=Major
On SRX1500, SRX1600, SRX2300, SRX4100, SRX4200, SRX4300, SRX4600, SRX4700, MX304, MX10004 and MX10008 (with LC9600 and LC4800 MPCs) platforms with IPSec tunnels configured using AES_GCM algorithm combination with Extended sequence number (ESN), the IPSec tunnel will go down.
1846168
Major
FIPS-CC:SRX-SME(Berkeley-FreeBSD12): IPSEC sa_config entries on node0 PFE are empty when configured from secondary node.
Product-Group=junos
Severity=Major
This issue is only with FIPS using the VPN traffic-selector in a SRX HA cluster. When a VPN traffic-selector configuration is committed in the backup HA cluster node (i.e. the RG0 is backup at this HA cluster node), the VPN may not be present in the PFE after the configuration. This issue will prevent VPN to initiate an IKE negotiation if the VPN is triggered on-traffic locally, and the RG1+ is active at the other HA node than that of the RG0 (i.e. where the VPN is missing in the PFE).
1850526
Major
IPSEC tunnel distribution table on the RE is not cleaned up hitting SRXPFE coredump eventhough DPD is configured.
Product-Group=junos
Severity=Major
Generic MNHA issue not specific to CSDS
1851652
Major
SRX fails to renegotiate VPN with the correct gateway when the active tunnel goes down
Product-Group=junos
Severity=Major
On all SRX platforms, if the active VPN (Virtual Private Network) tunnel is disabled or failed, the device does not correctly transition to negotiate with an active gateway. Instead, it continues attempting negotiation with the inactive gateway, leading to failed tunnel establishment.
PR NumberSynopsisCategory: Layer 2 Control Module
1855088
Major
In Junos EX and QFX platforms, when ERPS protocol is enabled on a ISL trunk, the commit command fails
Product-Group=junos
Severity=Major
In Junos EX and QFX platforms, when a port is configured with Inter-switch-link (ISL) trunk and the Ethernet ring protection switching (ERPS) protocol is enabled on the port, the commit command fails, causing the commit-check daemon process to crash and preventing the new configuration from being applied. This doesn't impact the devices traffic, performance, or management.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1864295
Major
L2ald core observed upon executing hidden command "show ethernet-switching debug-statistics fast-mac-update" in case the command doesn't have any output.
Product-Group=junos
Severity=Major
"request support information l2-debug fpc <>" can cause l2ald core as the HIDDEN command "show ethernet-switching debug-statistics fast-mac-update" which is part of l2-debug list of show commands, causes fork of child process and doesn't terminate it if output is empty.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1845079
Major
Unnecessary trace log files related to licenses are generated
Product-Group=junos
Severity=Major
On Junos platforms agile-licensing infra, when upgrading to 23.4R1 and above, unnecessary trace log files related to licenses are generated. This issue has no impact on traffic.
PR NumberSynopsisCategory: JNP10K-RE3 CB Centralized MX timing
1817097
Critical
On MX10K4, MX10K8, MX10K16 systems, in some cases, a SPMB PFE (spmbpfe)core might be seen when system is going down.
Product-Group=junos
Severity=Critical
On MX10K4, MX10K8, MX10K16 systems , a SPMB PFE (spmbpfe) may occationally create a core file when the system is being shutdown. This event adds 10 seconds to the time to shut the system down. The delay dues to the PTP FPGA reset sequence during the shutdown process.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when RSVP-TE (Resource Reservation Protocol - Traffic Engineering) is configured with MBB (make-before-break) setup, if the protected link of the primary LSP (Label Switched Path) goes down and if "clear mpls lsp" or "clear rsvp session" commands are executed, then LSP switches to new instance from the old which will be on higher IGP (Interior Gateway Protocol) metric. However, after re-optimization, LSP will not get switched to better IGP metric path and remain in old instance. Traffic drop can be seen due to this double fault events.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1847307
Major
The standby router goes into the error state when the switchover is performed.
Product-Group=junos
Severity=Major
On Junos platforms , the standby router goes into the error state when the switchover is performed. This will not impact the traffic.
PR NumberSynopsisCategory: Issues related to PKI daemon
1845573
Major
Auto-re-enrollment for local certificate once fail, not trigger again on SRX platforms
Product-Group=junos
Severity=Major
Added missing syslog messages for SCEP and CMPv2 certificate enrolment failure.
PR NumberSynopsisCategory: QFX access control list
1856361
Major
Port mirroring fails due to mismatched analyzer and outgoing interface configuration
Product-Group=junos
Severity=Major
On Junos EX and QFX5120 platforms, the system fails to retrieve the necessary analyzer details, preventing the port mirroring action from being applied in the filter entry. As a result, the system defaults to the reject action, causing the expected mirrored traffic to be missed, and packet captures are not generated.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1858750
Critical
JDI-RCT:EVO:PTX10002-36QDD - app-controller incomplete for EVO APPs seen
Product-Group=junos
Severity=Critical
Route change is not being sent from routing daemon RIB to forwarding plane FIB in some scenarios after RPD restart. This leads to data out of sync between RIB and FIB causing this problem.
PR NumberSynopsisCategory: Secure Web Proxy functionality on Junos
1851686
Major
Traffic reduction observed for SWP sessions when traffic hits SWP as passthrough.
Product-Group=junos
Severity=Major
In srx1500 platforms, passthrough TCP sessions associated with service web proxy (SWP) as a transparent-proxy can be seen as being reduced by a buffer leak under session handling. This lack of memory generates traffic reduction around 98% of the defined traffic.This is detected with the command "show service web-proxy statistics |no-more" and a considerable decrease is observed in the number of sessions in "Active Transparent proxy sessions" compared to normal transactions.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1840503
Major
Tactical Traffic Engineered load sharing utilization displays incorrect percentage on MX platforms
Product-Group=junos
Severity=Major
On MX platforms is configured with SRv6 (Segment Routing) along that Tactical Traffic Engineered(TTE) load sharing is enabled for SRv6, in some circumstances, TTE value displays percentage in 10 digit ( example 8889140224.00% ) when executing "show congestion-protection interface detail". It does not cause any traffic impact.
PR NumberSynopsisCategory: SRX branch platforms
1838923
Major
In FIPS mode, kernel panics at MipsSwitchFPState and reboots generating a vmcore
Product-Group=junos
Severity=Major
On all Junos SRX platforms with MIPS (Microprocessor without Interlocked Pipelined Stages) architecture, in Federal Information Processing Standards (FIPS) mode, kernel panics while switching Floating Point state, reboots and generates a vmcore. This is because, when threads run on multi-CPU, it is possible to have a stale thread saved in floating point current thread in per-CPU (PCPU) data structure.
1845997
Major
Packet drops are observed in the VPLS environment on SRX380 platforms in packet mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms in packet mode, when VLAN (Virtual Local Area Network)-VPLS (Virtual Private LAN Service) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 (Layer 2) unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.
1851261
Major
The commit command failed due to a speed mismatch between the Ten-Gigabit Ethernet (XE) port and the Aggregated Ethernet (AE) interface to which it belongs.
Product-Group=junos
Severity=Major
On all platforms running the Junos Operating System (OS), the commit command fails when the speed of XE interfaces is downgraded using a Small Form-factor Pluggable (SFP) module, causing a speed mismatch with the AE interface to which they belong. However, this does not affect the overall operation of the AE interface.
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1861483
Critical
On srx4700, LACP is not coming up in distributed mode
Product-Group=junos
Severity=Critical
In Release 24.4R1-S2, for SRX4700: LACP will not work in a distributed mode. To check the mode: root@casinoroyale-sol-01# run show ppm interfaces detail IFL-index: 2082, Protocol: LACP Interface Key: N/A Distributed: FALSE <=== This should be False for centralized (true for distributed) LACP will continue to work fine in centralized mode. The way to enter centralized mode is through the following CLI command: >set protocols lacp ppm centralized If the LACP is in distributed mode the LACP PDU will not be exchanged with the peer device resulting in the LACP state remaining in Attached. This will cause the interface (or the ae bundle) to remain in a DOWN state. The only impact of a centralized mode is when the RE is heavily utilized and busy, we might end up loosing packets in a FAST periodic mode of LACP causing interface to flap. This behavior will be fixed in S3 release and distributed mode will be enabled again.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1641517
Major
Multiple J-UKERN core files might be generated during the sanity test
Product-Group=junos
Severity=Major
On SRX4600 platform, the CPU may overrun while performing sanity check due to incompatibility issues between ukern scheduler and Linux driver which might lead to traffic loss.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1843935
Major
On SRX300 series DHCP relay stops working and the device generates coredump after upgrading to JunOS 23.4R2-S2.1
Product-Group=junos
Severity=Major
On SRX300 series devices, when TACACS accounting is configured, after an upgrade to Junos 23.4R2-S2.1, the DHCP-relay may not work anymore and the shm-rtsdbd process may produce coredumps.
1855393
Major
User root is shown as incorrect after power cycle of the device
Product-Group=junos
Severity=Major
After a power cycle, telnet login through the console fails. The issue occurs randomly and does not happen after every power cycle. To recover the device, another power cycle should be performed.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1829886
Major
Commit error check-out failed does not get triggered when a complete bridge-domain is configured in instance-type vrf.
Product-Group=junos
Severity=Major
Commit error check-out failed does not get triggered when a complete bridge-domain is configured in instance-type vrf.
1845657
Major
Baseline configuration commit takes more time with 256000 MAC configurations
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms with dual RE (Routing Engine), the baseline configuration commit takes more time when the device has 256000 MAC (Media Access Control) configurations configured under groups. It is a scaling issue, and occurs when a large number (256000 or more) of MAC configurations are configured. This has no impact to network traffic.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1847834
Major
Multiple daemons crash upon ephemeral or static db commits
Product-Group=junos
Severity=Major
On all Junos platforms with ephemeral configuration, multiple daemons like chassisd, dcd, l2ald, l2cpd, mib2d and transportd crash upon ephemeral or static db commits causing service traffic impact. The services will self recover after the issue is hit in the network.
PR NumberSynopsisCategory: Issues related to NETCONF
1852868
Major
commit confirmed rpc request displays closing tag without opening tag in private mode
Product-Group=junos
Severity=Major
Fixed xml format in rpc output
PR NumberSynopsisCategory: QFX10002 Platform
1851588
Critical
QFX10002-60C : FPC CPU utilization
Product-Group=junosvae
Severity=Critical
For QFX10002-60c platform, In output of 'show chassis fpc' CLI, CPU utilization comes high(~94%) in both with and without traffic condition.

 


 

24.4R1-S2 - List of Known issues 

PR NumberSynopsisCategory: SRX Casino Royale cluster HA/MNHA infra related issues
1861684
Major
Reboot failover of SRX4700 (A/A Node0) doesn't come up in the expected MNHA State because of ICL BFD flap
Product-Group=junos
With "restart-chassis control" cli command or reboot of one of the MNHA node on SRX4700, BFD ICL will flap. which will have unexpected behaviour.

Resolved In:
PR NumberSynopsisCategory: JDM issues in CSDS solution
1838151
Minor
JDM spawned vsrx satellite device should get booted with config having same timezone as MX controller. Currently its using default UTC timezone
Product-Group=junos
vSRX will get controller's timezone settings via baseline config.

Resolved In: junos:25.2R1
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1832094
Major
The IDP security-package install is throwing 'Attack DB Update Failed' error and AppID stops working
Product-Group=junos
On all Junos SRX platform if the IDP (Intrusion Detection and Prevention) security-package is installed multiple times, it will cause sigpack installation failure as the AppID (Application Identification) memory allocation got failed. This issue is reproduced via script execution (not specific to any script) but it is not seen manually.

Resolved In: junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1833667
Major
Custom application detection fails for L4 traffic after upgrade due to uncompiled signatures
Product-Group=junos
On SRX branch series devices configured with custom applications and sigpack ( signature package ) already installed, installing a new sigpack would result in failure to recompile the custom applications. This leads to memory corruption during L4 (Layer 4) traffic processing, causing applications to be marked as "INCONCLUSIVE" and results in incorrect attack counts if IDP ( Intrusion Detection and Prevention ) custom attacks are configured, impacting application detection and security monitoring.

Resolved In: junos:24.4R2 junos:25.2R1
1841520
Major
24.4R1[SRX380]: Flowd core got dumped at "0x06ede790 in jdpi_cust_pctxt_pid_to_rule_id_hash_construct (cust_pctxt_dbs=0x6b0d23d8) at ../../../../../../../../../src/junos/jsf/plugin/jdpi/jdpi_cust_pctxt.c:601"
Product-Group=junos
This core dump is due to memory corruption when sigpack install is pushed from RE to PFE. The core is a corner case and is getting reproduced very rarely.

Resolved In: junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1853868
Major
Router flag is not getting set in Neighbor Advertisement message
Product-Group=junos
When EVPN (Ethernet Virtual Private Network) routing instance has IRB (Integrated Routing and Bridging) interface with IPv6 (Internet Protocol version 6) address, ICMPv6 NA (Neighbour advertisement) reply from IRB IPv6 address doesn't have router flag. The ICMPv6 NA from IRB IPv6 should have router flag.

Resolved In: evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1762490
Minor
JDI-RCT-MPC10E: Ksyncd crash on backup RE after fpc reboot
Product-Group=junos
On MX series, when PS over RLT is configured where all member LTs are hosted on the same FPC and user restarts this FPC then on rare occasion, ksyncd crash can occur on backup RE. However, there is no impact on the master and only backup RE is affected. This issue is not consistent and seen only once out of ~10 or 15 fpc restart operations.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1789245
Major
ICL failure/recovery causes BFD to flap on other node
Product-Group=junos
With restart-chassis control command on SRX4200/SRX4700/SRX5k, BFD ICL will flap.

Resolved In:
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1860597
Major
Security log report messages w.r.t logical system is not generated
Product-Group=junos
show security log report cli command for logical systems is not working for 24.2R2, 24.4R1-S2, if log report is disabled under root system. Work around is available for this issue.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1861843
Critical
Traffic through IPSec-VPN tunnel does not work when we have chacha20-poly1305 configured
Product-Group=junos
On 24.4R1 and above releases, due to some internal changes/issues, the chacha20-poly1305 feature for IPsec VPN will not work. 24.4R2 has no issue and can be used for the same.

Resolved In:
PR NumberSynopsisCategory: Security platform jweb support
1858466
Major
VPN failures on SRX due to file descriptor issue
Product-Group=junos
On all SRX platforms, Juniper Secure Connect (JSC) clients may fail to establish a VPN session after successful authentication if more than 20 concurrent connections per client IP are active. In a NATTed environment, the 21st connection will fail, and the customer must retry.

Resolved In: junos:21.2R3-S9 junos:22.2R3-S6 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: MX104 Software - Timing
1782868
Major
MX104 AFEB might crash following a change of PTP clock source.
Product-Group=junos
On MX104, the AFEB could crash and reboot following a change of PTP GM clock source, which affects traffic forwarding.

Resolved In: junos:21.2R3-S9
PR NumberSynopsisCategory: QFX L2 PFE
1820830
Major
Complete packet loss will be observed for the inter-VLAN traffic in EVPN-VXLAN CRB scenario
Product-Group=junosvae
On Junos QFX and EX platforms in an EVPN-VXLAN (Extended Virtual Private Network- Virtual Extensible LAN) CRB (Centrally-Routed Bridging) scenario where the ingress leaf switch is configured with ESI (Ethernet Segment Identifier) lags (i.e. the server is multihomed), if there is an overlap between ESI lag(s) trunk ID with physical port number(s) and overlap of DMAC (destination MAC) between VGA (Virtual Gateway Address) MAC address 00:00:5e:00:01:01 (CRB setup with VGA / GW is on spine) with VRRP (Virtual Router Redundancy Protocol) MAC (specifically for the VRRP group 1 MAC address 00:00:5e:00:01:01) on the physical ports of the Leaf switches, then traffic loss will be observed for the inter-VLAN traffic.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2-S1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1758400
Major
JUNOS_REG: QFX51200-48YM: Fan status output was not same after/before device vc-switch over.
Product-Group=junos
In a QFX51200-48YM-8C VC setup, after a a mastership switch over fan tray of linecard may not be displayed in show chassis hardware and show chassis environment. There is no functional impact

Resolved In:
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1825835
Major
IPsec traffic loss is observed when SA is stuck in the routing table even when the IPsec tunnel does not exist on the device
Product-Group=junos
On MX platforms with MS-MPC/MS-MIC with IPsec (Internet Protocol Security) configured, IPsec traffic loss will be observed if an SA (Security Association) deletion request is sent by the peer just before the SA installation is completed. The issue happens in the scale scenario (4000 tunnels are configured, and when the SA count reaches up to 3900).

Resolved In: junos:19.1R3-S14 junos:19.2R3-S11 junos:19.3R3-S12 junos:20.2R3-S10 junos:21.2R3-J14 junos:21.2R3-S8-J10 junos:21.4R3-S9 junos:22.4R3-S5
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1848897
Major
24.4R1: SecPDT: MX960:With Local bias knob enabled, Fabric I/O stats pfe traffic stats tolerance is higher +50% with on-going traffic.
Product-Group=junos
After PR 1848897 fix, on all MX platforms having MPC10 or MPC11 the traffic coming from any physical interface belonging to these MPCs will always take a fabric hop before forwarding to any physical link in egress. As a result despite locality bias feature being configured, the input traffic on that physical interface will still end up showing increase in the fabric statistics count.

Resolved In: junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1846365
Major
Traffic drops after link flap on active-active ESI setup with MAC pinning enabled
Product-Group=junos
On MX platforms with ukern (legacy) FPC (Flexible PIC Concentrator) based in trio chipset and configured in an active-active ESI (Ethernet Segment Identifier) setup, traffic will be dropped after a flap of the DF (Designated Forwarder) or BDF (Backup Designated Forwarder) LAG (Link Aggregation Group) interface member.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Major
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: MX10K platform
1852648
Critical
JUNOS_REG: MX10008 : Observing core-spmbpfe at cmty_doob_rcb_fpga_init, cmty_spmb_hw_init, cmty_spmb_module_init, __pthread_kill_implementation, __kernel_vsyscall
Product-Group=junos
spmbpfe core can be seen sometimes in these two case: 1. During ISSU when old master RE comes up with the new image, a spmbpfe core is generated when the old master RE goes down after reboot is given post new image installation. The core will be seen post the reboot. 2. When "request system reboot" cli command is executed, a spmbpfe core will occur when the junos goes down and the core will be seen post the system comes up. These cores generated at these stages will have no impact on a running system. The core are seen only when some kind of reboot is triggered.

Resolved In:

 

Modification History

First publication 2025-03-25