Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 22.4R3-S7 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Junos Software service Release version 22.4R3-S7 is now available.

Solution

Junos Software service Release version 22.4R3-S7 is now available.

22.4R3-S7 - List of Fixed issues 

PR NumberSynopsisCategory: NFX Layer 3 Features Software
1776815
Major
The PFE process crash happens in NFX platforms
Product-Group=junos
Severity=Major
On all NFX series platforms, the pfe (packet forwarding engine) process crashes due to memory exhaustion when configured with custom mode templates like flex mode or any other custom mode.
PR NumberSynopsisCategory: Accounting Profile
1692411
Minor
Error messages are observed and incorrect values are returned for SNMP requests for pfe traffic statistics
Product-Group=junos
Severity=Minor
Below log messages will be seen while using SNMP and trying to poll "show pfe statistics notification" through MIB OID - 1.3.6.1.4.1.2636.3.44.1.1.2.1.2. "pfed: PFED_NOTIF_GLOBAL_STAT_UNKNOWN: xxxx"
PR NumberSynopsisCategory: BBE WiFi applications/services
1859542
Major
The smgd process crashes on MX Series Junos OS platforms when DHCP/PPPoE over soft-gre is configured
Product-Group=junos
Severity=Major
On all Junos OS MX Series platforms with Enhanced Subscriber Management enabled, the smgd (Subscriber Management Daemon) process crashes continuously when non default routing instances are used and the instance name is less than 7 characters . The issue can be seen when either DHCP (Dynamic Host Configuration Protocol) or PPPoE (Point-to-Point Protocol over Ethernet) subscribers over soft-gre is configured. Due to the continuous crashing of smgd process, the subscriber sessions are affected.
PR NumberSynopsisCategory: BBE interface related issues
1850562
Major
Host unreachable from the router with PPPoE when "routing-service" and "RPF-check" are enabled, and the route is learned via EBGP
Product-Group=junos
Severity=Major
On Junos platforms configured with BGP (Border Gateway Protocol) and rpf-check over PPPoE (PPP over Ethernet) subscribers, the platform is unable to reach the hosts present in the routing table when these are learnt by EBGP. This issue affects MX Platforms and QFX platforms.
PR NumberSynopsisCategory: Border Gateway Protocol
1853025
Major
Updating a source-file to load ROAs should be done by changing the name of the source file
Product-Group=junos
Severity=Major
Loading ROAs from a source-file was a feature introduced as a convenience feature and as such this only affects that feature. This feature is not in widespread use and was created to have a fallback ROA when all sessions go down. This problem scenario requires multiple reloads with the being modified back and forth to add and then delete and re-add the database configured in the import policy.
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=junos
Severity=Major
On all Junos, Junos OS Evolved, and cRPD platforms, due to deadlock in internal processes, BGP (Border Gateway Protocol) route advertisement fails leading to traffic disruption.
1875144
Minor
RPKI BGP RV Import Eval leading to longer convergence
Product-Group=junos
Severity=Minor
When any peer has validation policy configured for import, we have uncovered a bug where we reevaluate the routes in the loc-rib for validation even though we change policy for an unrelated peer.
PR NumberSynopsisCategory: EVO L3 routing for BCM XGS Platforms
1828017
Minor
The pfemand crash will be observed when "clear bgp neighbor all" command is executed
Product-Group=junos
Severity=Minor
On all Junos and Evolved platforms, in a scaled setup when the "clear bgp neighbor all" command is executed or "restart l2-learning immediately" is executed, the pfemand crash will be seen which leads to the restarting of the Flexible Packet Forwarding Card (FPC).
PR NumberSynopsisCategory: MX304 PSM issuues
1850857
Major
Chassis MX304 going offline due to Power-cycle
Product-Group=junosvae
Severity=Major
On all JUNOS Operating system MX304 platform, entire chassis is shutting down due to improper health checks triggered for the Power Entry Module (PEM). If a health check of the Power Entry Module (PEM) is triggered at the time when the power consumption in the chassis is less than the threshold (440W) required to run the health check, the issue might be triggered.
PR NumberSynopsisCategory: MX304 fabric issues (ULC side)
1863674
Major
Link error reported on one PFE(Packet Forwarding Engine) will also report error on other PFE
Product-Group=junos
Severity=Major
On all Junos MX304 platforms, when a link error or training failure occurs, the "show chassis fabric fpcs extended" and "show chassis fabric plane extended" commands display incorrect PFE-to-plane mappings for plane numbers greater than 9. As a result, an incorrect PFE is shown as affected. Due to this incorrect mapping, a training failure, it shows both PFEs getting impacted.
PR NumberSynopsisCategory: MX304 interface specific 
1861672
Major
Random interfaces on MX304 remain in down state after an FPC reboot
Product-Group=junos
Severity=Major
On MX304 platforms, random interfaces operating at 100G speed will remain down after an FPC (Flexible Port Concentrator) reboot, resulting in traffic loss.
PR NumberSynopsisCategory: MX304 LCMD specific issues
1851100
Major
Erroneous data read from a temperature sensor caused MX304 to reboot
Product-Group=junos
Severity=Major
On Junos MX304, due to erroneous data read from a temperature sensor, the device will shutdown.
PR NumberSynopsisCategory: QFX Access Control related
1872280
Major
The l2ald process crash is observed on non L2NG Junos platforms configured with "native-vlan-id" and "bridge-domains" on an IFL
Product-Group=junos
Severity=Major
On non L2NG (Layer2 Next Generation) Junos EX, MX and SRX platforms, the l2ald (Layer 2 Address Learning Daemon) process crash is observed when an IFL (Logical Interface) configured with "native-vlan-id" and "bridge-domains" and when certain config change takes place in an IFL which maps VLAN (Virtual Local Area Network) index to NULL. The dereferencing of this NULL pointer causes the crash.
PR NumberSynopsisCategory: Firewall Filter
1872347
Critical
System crash is observed due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=junos
Severity=Critical
On Junos OS platforms, the system runs out of memory due to mbuf (Memory Buffer) leak, leading to the system crash (VMcore is generated) resulting in service impact and error logs is observed. This issue happens when a firewall filter is applied to around 1k ifls (logical interface), each filter having > 250 terms and the filter is updated every 2-3 minutes which triggers an update for all filter attachments.
PR NumberSynopsisCategory: DNS software support.
1816951
Minor
Crash dump on DNSF plugin observed on SRX platforms
Product-Group=junos
Severity=Minor
On SRX and vSRX platforms, when unified policy ( dynamic applications) is configured along with DNS profile configuration, a crash is observed.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1874476
Major
Transient traffic loss for CE in an EVPN MPLS setup with Multi-Homing
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms with EVPN MPLS, Multi-homing scenarios, when there is a Multi-homing peer node reboot, the destination route entries that were learned locally on IRB(Integrated Routing and Bridging) interface of rebooted node get deleted on other multi-homing peers without RE-ARP (Routing Engine-Address Resolution Protocol) causing transient traffic loss for CE (Customer Edge) traffic.
PR NumberSynopsisCategory: EVPN control plane issues
1839959
Critical
The MAC+IP table and mac-table are not in sync in the EVPN-MPLS active-active multihomed scenario leading to traffic loss
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms that supports ESI lag interface and in an EVPN-MPLS (Ethernet Virtual Private Network - Multi Protocol Label Switching) active-active multihomed scenario, when the multihomed access interfaces are flapped in quick succession, it results in an unresolved destination route for the specific IP host. This is occurred due to race condition within l2ald (Layer 2 Address learning daemon) followed by an interface flap which causes the locally learned MAC to go missing from the mac-table on the other PE router.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1833660
Major
Stale MAC entries may remain in the MAC table of EVPN routing instances after rapid MAC-IP move scenarios
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms with EVPN-MPLS (Ethernet Virtual Private Network - Multiprotocol Label Switching) setup , stale MAC entries may remain in the MAC table of the EVPN (Ethernet Virtual Private Network) routing instances during rapid MAC-IP move scenarios. This can cause MAC tables to reach their limits preventing new MAC addresses learning and user registration.
PR NumberSynopsisCategory: EX interfaces issues
1757034
Major
EX3400: "Error:tvp_optics_eeprom_read: Failed to read eeprom for link" syslog error message
Product-Group=junos
Severity=Major
"Error:tvp_optics_eeprom_read: Failed to read eeprom for link" logs might be seen for some time during system reboot or pfe restart in EX3400. There is no functional impact due to these logs.
1844709
Major
EX4100 looses connectivity with the directly connected management port of QFX5120-48Y series platform
Product-Group=junos
Severity=Major
Unable to ping Management IP of QFX5120 directly connected to EX4100 (PIC2) after Power-Cycle or reboot the QFX5210 switch via CLI command : "request system reboot hypervisor"
1849992
Major
EX4400 uplink ports (PIC 2) with the 4x25G uplink module may go down when SFPs (SFP+-10G-BX10-D/U or SFP+-10G-BX40-D/U) are inserted.
Product-Group=junos
Severity=Major
On EX4400 devices, inserting SFP+-10G-BX10-D/U or SFP+-10G-BX40-D/U into the 4x25G uplink module causes all ports on the Physical Interface Card (PIC) 2 to go down.
PR NumberSynopsisCategory: EX4400 PFE software
1867562
Major
Default Route configured with Discard Next Hop on PFE instead of ECMP Next Hop after reboot
Product-Group=junos
Severity=Major
On all Junos EX4K (except EX4300) in a VC (Virtual Chassis) environment using LPM (Longest Prefix Match) routing, after a reboot the default route on the PFE (Packet Forwarding Engine) is incorrectly set to a "discard next-hop (NH)" instead of an ECMP (Equal-Cost Multi-Path) next-hop resulting in connectivity issues.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1801237
Major
ARP won't be forwarded in VLAN associated VNI in VxLAN Fabric
Product-Group=junos
Severity=Major
On EX4100/EX4400/QFX5120 platforms where dot1x is configured with multiple supplicant mode, if the MAC (Media Access Control )+IP (Internet Protocol ) is not in the EVPN (Ethernet Virtual Private Network) database, there will be an ARP (Address Resolution Protocol ) and it will not work as the ARP is suppressed. It will be generated to specific VLAN in VxLAN and it is suppressed due to arp suppression.This issue is seen due to dot1x configured on the interfaces. This can be restored by restarting the FPC.
PR NumberSynopsisCategory: Express PFE FW Features
1830706
Major
FPC crash will occur when modifying or deleting a filter instance on Junos platforms
Product-Group=junos
Severity=Major
On all Junos platforms, when a filter instance is modified or deleted, there should not be any old Packet Forwarding Engine (PFE) instances. However, during these operations, old PFE instances are being incorrectly assigned, resulting in incorrect memory address allocation. This leads to an Flexible PIC Concentrator (FPC) crash after committing the configuration, causing traffic loss.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1834429
Minor
VRRP fails on 802.1Q VLAN Layer 3 logical interface on QFX10002-60C
Product-Group=junos
Severity=Minor
On Junos QFX10002-60C platform, VRRP (Virtual Router Redundancy Protocol) fails to work on 802.1Q VLAN (Virtual Local Area Network) tagging due to the lack of support for VRRP on Layer 3 logical interface. As a result, the VRRP VIP (Virtual IP) is unreachable, causing VRRP functionality to fail.
PR NumberSynopsisCategory: SRX1500 platform software
1831955
Major
The SRX1500 drops the packet if MTU matches the MRU of the receiving device
Product-Group=junosvae
Severity=Major
On SRX1500 platforms, if the Maximum Transmission Unit (MTU) is configured to match the Maximum Receive Unit (MRU) of the receiving device, packet drops occur. This occurs because additional processing overhead increases the packet size beyond the MRU limit, causing the receiving device to drop the packets.
1863943
Critical
SRX1500 clustered Firewalls can go to split-brain when more than 7 RGs are configured
Product-Group=junos
Severity=Critical
On SRX1500 clustered Firewalls, when more than 7 RGs (Redundancy Groups) are configured, the Firewall cluster goes into a split-brain mode which leads to both node becoming primary and consequently traffic loss is seen.
PR NumberSynopsisCategory: ISIS routing protocol
PR NumberSynopsisCategory: jdhcpd daemon
1854827
Major
Unable to assign an IP address on management interface with DHCP configuration even if DHCP is bound after a power cycle
Product-Group=junos
Severity=Major
On all Junos devices, management interface does not get an IPv4 from Dynamic Host Configuration Protocol (DHCP) even if the interface is bound. When power cycle or reboot is triggered, management is lost without traffic impact.
PR NumberSynopsisCategory: JFlow bug tracker for SRX platforms
1843679
Minor
Application crash is observed due to insufficient memory when a large number of JFlow entries are created
Product-Group=junos
Severity=Minor
On Junos OS SRX platforms with JFlow configured with sampling interval set to 1, traffic impact is observed due to insufficient memory for the Layer 7 applications leading to application failure. The issue happens when a large number of JFlow entries are created exhausting memory potentially leading to crash.
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1864288
Major
On SRX platforms with NAT configuration, IPSEC tunnel flaps after a commit, causing multiple sites to go offline
Product-Group=junos
Severity=Major
On all SRX platforms, with Network Address Translation (NAT) matching 0.0.0.0/0 or :: /0 and Virtual Private Network (VPN) configurations, performing a commit triggers warning messages such as the following: warning: Configuring NAT rule with match address 0:: 0/0 and source-nat/destination-nat off adds default reject route, causing fxp0's IP not accessible from outside subnets. The warning messages during the commit cause the system to mark the configuration as changed on the device, but the management daemon does not reset the change-marked bits. While the warnings are present, iked/kmd is signaled as changed during the commit, causing VPN flaps afterward.
PR NumberSynopsisCategory: Flow Module
1854492
Major
Junos SRX platforms with chassis cluster configured experience flowd crash due to a race condition in multicast session handling
Product-Group=junos
Severity=Major
On Junos SRX platforms with chassis cluster configured, a crash is observed in multicast scenario due to a race condition where a link flap changes the ingress interface while a session is being aged out, leading to invalid session data access. This causes the flowd process to crash, resulting in a coredump and eventually the system crashes.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1789245
Major
ICL failure/recovery causes BFD to flap on other node
Product-Group=junos
Severity=Major
With restart-chassis control command on SRX4200/SRX4700/SRX5k, BFD ICL will flap.
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1860597
Major
Security log report messages w.r.t logical system is not generated
Product-Group=junos
Severity=Major
show security log report cli command for logical systems is not working for 24.2R2, 24.4R1-S2, if log report is disabled under root system. Work around is available for this issue.
PR NumberSynopsisCategory: Firewall Policy
1823591
Minor
Failed inter-process communication leads to increased buffer utilization, affecting process functionality
Product-Group=junos
Severity=Minor
On all Junos platforms, when there is a broken Inter-Process Communication (IPC) link between the Routing Engine (RE) and Packet Forwarding Engine (PFE), heap and buffer utilization gradually increases to 99%, causing some software modules to start failing.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1824880
Major
IPsec VPN tunnel on specific platforms will be brought down when AES_GCM algorithm is used along with ESN
Product-Group=junosvae
Severity=Major
On SRX1500, SRX1600, SRX2300, SRX4100, SRX4200, SRX4300, SRX4600, SRX4700, MX304, MX10004 and MX10008 (with LC9600 and LC4800 MPCs) platforms with IPSec tunnels configured using AES_GCM algorithm combination with Extended sequence number (ESN), the IPSec tunnel will go down.
1839665
Minor
The flowd process crashes on SRX5K platforms with multiple line cards in MNHA scenario
Product-Group=junos
Severity=Minor
On SRX5k platforms with more than two line cards and High Availability (HA) link encryption enabled, flowd process crash is seen after rebooting a node in Multinode High Availability (MNHA) deployment affecting traffic-forwarding.
PR NumberSynopsisCategory: Security platform jweb support
1858466
Major
VPN failures on SRX due to file descriptor issue
Product-Group=junos
Severity=Major
On all SRX platforms, Juniper Secure Connect (JSC) clients may fail to establish a VPN session after successful authentication if more than 20 concurrent connections per client IP are active. In a NATTed environment, the 21st connection will fail, and the customer must retry.
PR NumberSynopsisCategory: Key Management Daemon
1869769
Major
The kmd process crashes when device with MS-MPC has DPD enabled and a SA is deleted
Product-Group=junos
Severity=Major
On all MX platforms with MS-MPC (Multiservices Modular PIC Concentrator), when DPD (Dead Peer Detection) is enabled under IPsec/IKE (Internet Key Exchange) VPN settings and for any reason an IPsec SA (Security Association) is deleted, the kmd process crashes. Due to the kmd process restart some disruption in tunnel establishment is seen.
PR NumberSynopsisCategory: Layer 2 Control Module
1855088
Major
In Junos EX and QFX platforms, when ERPS protocol is enabled on a ISL trunk, the commit command fails
Product-Group=junos
Severity=Major
In Junos EX and QFX platforms, when a port is configured with Inter-switch-link (ISL) trunk and the Ethernet ring protection switching (ERPS) protocol is enabled on the port, the commit command fails, causing the commit-check daemon process to crash and preventing the new configuration from being applied. This doesn't impact the devices traffic, performance, or management.
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .
PR NumberSynopsisCategory: Label Distribution Protocol
1772904
Major
The rpd process crashes when LDP telemetry streaming xpath is enabled
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms, the rpd process crash when LDP telemetry for xpath "/network-instances/network-instance/mpls/signaling-protocols/ldp/neighbors/neighbor/hello-adjacencies/hello-adjacency/hello-holdtime/state/hello-expiration" is enabled.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1844934
Major
Subscribers unable to connect in GNF setup
Product-Group=junos
Severity=Major
On Junos MX platforms with Node Slicing, i.e., GNF (Guest Network Function), and Subscriber Management services enabled, Subscriber bring-up failure can occur when an upgrade is performed from a non-Agile License infra release to a release running Agile-based Licensing. This issue impacts subscriber services and is encountered due to the enforced Hard Licensing feature for node slicing.
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1798780
Critical
The system goes into a bad state when an SFB ungraceful offline happens due to a fatal Interrupt
Product-Group=junos
Severity=Critical
On MX platforms with SFB, in case of a fatal error encountered during SFB reboot ( due to hardware issue or ungrateful power restart ), SPMB will try to offline this SFB during bootup. At the same time, the system is busy training the fabric links to begin it online. This may cause a system-wide traffic impact due to the fabric not being consistent.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1849296
Minor
The self-generated traffic on Junos platforms use the incorrect source IP with ECMP configuration
Product-Group=junos
Severity=Minor
On all Junos platforms configured with Equal-Cost Multi-Path (ECMP) routing, self-generated traffic selects an incorrect source (Internet Protocol) IP address. As a result, the peer device lacks the relevant route information, causing self-generated traffic to be dropped. This issue is specific to ECMP configurations and does not impact data traffic.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1872010
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
Severity=Major
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberSynopsisCategory: TCP/UDP transport layer
1790049
Critical
The BGP TCP output queue remains full
Product-Group=junos
Severity=Critical
On all Junos platforms, after upgrading to 24.2 and above, a BGP TCP output queue (outQ) may remain full until the TCP session is clear.
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1830188
Major
Counters not getting cleared at the PFE level when clear ddos-protection protocol statistics is executed
Product-Group=junos
Severity=Major
On all Junos PTX platforms, Distributed Denial of Service(DDos) clear statistics will not work on 22.4R3-S5 however there will be no impact on its functionality.
PR NumberSynopsisCategory: Express Chip L3 software
1865171
Major
FPC crashes if the BGP protocol next-hop gets resolved over a discard logical interface (dsc.0)
Product-Group=junos
Severity=Major
On Junos OS PTX and QFX10k platforms, FPC crashes and reboot is seen due to the corruption of the data structures associated with dsc.0 (Discard Interface).
PR NumberSynopsisCategory: Protocol Independant Multicast
1740811
Critical
Drop in multicast traffic observed when multiple Reverse Path Forwarding (RPF) interfaces are available towards the upstream router
Product-Group=junos
Severity=Critical
This issue is linked to the PIM Join-load-balance feature. When downstream router has multiple ECMP paths towards the upstream router to reach the multicast source and is configured for PIM Join-load-balance, load balancing of joins creates an active upstream path and a standby upstream path. In scenarios with multiple links available towards the upstream router, the standby path for a given (S, G) pair needs to be reselected multiple times due to ongoing rebalancing. Consequently, the old standby path must be pruned, and periodic joins must be canceled. But, in this case, PIM prematurely removes the old standby path without sending a prune on that path and consequently does not remove the periodic joins. This mismanagement leads to the upstream router inadvertently adding an unintended interface to its OFIL (Outgoing Interface List). This causes replication issue at upstream router and traffic loss is observed.
PR NumberSynopsisCategory: QFX L2 PFE
1820830
Major
Complete packet loss will be observed for the inter-VLAN traffic in EVPN-VXLAN CRB scenario
Product-Group=junosvae
Severity=Major
On Junos QFX and EX platforms in an EVPN-VXLAN (Extended Virtual Private Network- Virtual Extensible LAN) CRB (Centrally-Routed Bridging) scenario where the ingress leaf switch is configured with ESI (Ethernet Segment Identifier) lags (i.e. the server is multihomed), if there is an overlap between ESI lag(s) trunk ID with physical port number(s) and overlap of DMAC (destination MAC) between VGA (Virtual Gateway Address) MAC address 00:00:5e:00:01:01 (CRB setup with VGA / GW is on spine) with VRRP (Virtual Router Redundancy Protocol) MAC (specifically for the VRRP group 1 MAC address 00:00:5e:00:01:01) on the physical ports of the Leaf switches, then traffic loss will be observed for the inter-VLAN traffic.
1850203
Minor
Duplication of DHCP request packets when unicast to VRRP gateway
Product-Group=junos
Severity=Minor
On Junos QFX5100, QFX5110, QFX5120, QFX5200, QFX5210, EX4100, EX4000, EX4400 and EX4300-48MP platforms, when a client sends a single DHCP (Dynamic Host Configuration Protocol) request, the switch generates and forwards two DHCP request messages to the VRRP (Virtual Router Redundancy Protocol) gateway. This behaviour causes the client to fail to renew its IP address, resulting in a loss of network connectivity.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1823601
Minor
Protocol traffic drops were seen in the network for any configuration change in the protocol
Product-Group=junos
Severity=Minor
On all Junos QFX5K platforms, with ECMP (Equal Cost Multi Path) configured, when there is any routing protocol change (like ISIS cost metric change), the protocol traffic on the network is dropped.
1855990
Major
Traffic drop observed due to ECMP next-hop programming issue
Product-Group=junos
Severity=Major
On QFX5k, EX4k, EX2300 and EX3400 platforms, ECMP next-hop programming issue causes some prefixes to drop traffic. The issue is observed when the software-configured ECMP size (maximum-ecmp) exceeds the limit of 64 during a network churn event in the network. This triggers ECMP to skip updates, leading to stale forwarding paths and a temporary traffic freeze.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1866130
Minor
Command "show pfe vxlan" is not supported on QFX5200 devices
Product-Group=junosvae
Severity=Minor
Support added for "show pfe vxlan" CLI command on QFX 5200 devices
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1773567
Major
100G optics settings to CAUI4 on Junos QFX5120-48T platforms
Product-Group=junos
Severity=Major
The port interface on the 100G optics of the QFX5120-48T platform is incorrectly configured
PR NumberSynopsisCategory: KRT Queue issues within RPD
1831421
Critical
Multiple flaps on BGP routes causing traffic blackholing
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms, BGP (Border Gateway Protocol) route with PNH1 (Preserve Nexthop Hierarchy) may not be resolved correctly during rapid route fluctuations (e.g., link flaps). Specifically, when the preferred route (Rt1) experiences rapid deletions and re-additions, the system might incorrectly associate the PNH with an outdated route (Rt2).
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1737594
Critical
Traffic drop can be seen in the MPLS traffic Engineering scenario
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms, traffic drop can be seen in MPLS (Multi-Protocol Label Switching) traffic engineering with IGP-FRR (Interior Gateway Protocol Fast Reroute) and preserve next-hop hierarchy. This issue happens when the BGP (Border Gateway Protocol) routes are resolving over BGP and there is a change in the active route. The session ID for the IGP-FRR is assigned to the new active route and the old active route is withdrawn, while the above processing is done the session ID is associated with both the old and new active route, and the old active route, the route gets deleted which triggers the IGP-FRR session ID to be down and the unilist (ECMP)path get stuck causing traffic impact.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1849202
Major
BGP route still seen in routing table when route not available
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms , the router learns routes through the BGP (Border Gateway Protocol) and has the feature: "BGP RIB Sharding" enabled for IPv4. These routes are stored in the Inet.0 routing table. Later, if the neighbor that announced this route or the protocols associated with the routing table of the used VRF (Virtual Routing and Forwarding) are removed, the route remains in the routing table, and hence traffic is forwarded to the stale routes.
PR NumberSynopsisCategory: Resource Reservation Protocol
1792192
Major
Missing HELLO object in RSVP Hello messages after RE failovers in the NSR mode
Product-Group=junos
Severity=Major
In rare unknown condition after RE switchover, rsvp hello can have local instance to be zero due to wrong information synced from master RE by mirroring process. When rsvp neighbor is created and never received hello exchange with neighbor, the replication entry which is synced to standby RE will have most of the information as zero, including the local instance, which is used to generate hello object. After RE switchover, rsvp hello will have local instance to be zero due to the wrong information synced from master RE by mirroring process. This is addressed by update the replication entry once all the parameters of the rsvp neighbor is filled, so standby RE will receive the right info, also for future protection, backup RE will avoid creating neighbor until after switchover and setting a new local instance if it is zero.
1864949
Major
User traffic dropped after ISIS went down on one side with trapcode observed
Product-Group=junos
Severity=Major
On all JUNOS and JUNOS evolved Operating Systems, if a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in unexpected traffic blackholing on the router at the downstream end of the flapping link.
PR NumberSynopsisCategory: Secure Web Proxy functionality on Junos
1851686
Minor
Traffic reduction observed for SWP sessions when traffic hits SWP as passthrough.
Product-Group=junos
Severity=Minor
In srx1500 platforms, passthrough TCP sessions associated with service web proxy (SWP) as a transparent-proxy can be seen as being reduced by a buffer leak under session handling. This lack of memory generates traffic reduction around 98% of the defined traffic.This is detected with the command "show service web-proxy statistics |no-more" and a considerable decrease is observed in the number of sessions in "Active Transparent proxy sessions" compared to normal transactions.
PR NumberSynopsisCategory: SRX Advanced Anti-Malware module
1827283
Minor
PFE core can be seen on SRX platforms during ISSU
Product-Group=junos
Severity=Minor
On Junos SRX4k/5k series platforms in a chassis cluster environment, the srxpfe (Packet Forwarding Engine) process crashes during ISSU ( In service Software Upgrade). It happens after failover to the upgraded node and before the secondary node is all the way up to join the cluster. This process crash will cause traffic impact, however the system self-recovers.
PR NumberSynopsisCategory: SRX branch platforms
1845997
Major
Packet drops are observed in the VPLS environment on SRX380 platforms in packet mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms in packet mode, when VLAN (Virtual Local Area Network)-VPLS (Virtual Private LAN Service) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 (Layer 2) unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1807277
Minor
Speed change between 1G and 10G with traffic in high-priority queue on ports causes the link to go down
Product-Group=junos
Severity=Minor
On MX204/MX10003/SRX4600/EX9251/EX9253 platforms on changing the interface speed manually from 1G to 10G or from 10G to 1G while running traffic in high-priority queue causes the link on port to go down causing traffic impact.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1748971
Minor
SRX4600 misleading Fan speed syslog output after removing or inserting one Fan tray unit
Product-Group=junosvae
Severity=Minor
On SRX4600, misleading Fan speed syslog is generated after removing or inserting one Fan tray unit.
1846340
Major
FPC0 will not transition to Online and may generate chassis alarm "FPC 0 Hard errors" in SRX4600 devices deployed in chassis cluster
Product-Group=junos
Severity=Major
On Junos SRX4600 platform devices deployed in a chassis cluster, after rebooting the Secondary node count of RIB(Routing Information Base) /FIB (Forwarding Information Base) is above 15000 FPC0 will not transition to Online, and a "FPC 0 Hard errors" chassis alarm may also be generated.
PR NumberSynopsisCategory: MX10003/MX204 Timing/Sync-E issues tracking
1863091
Major
FPC will crash in MX10003 during the Master switchover to RE1 or Master set to RE1
Product-Group=junos
Severity=Major
MX10003 FPC (Flexible PIC Concentrators) will crash if Primary RE (Routing Engine) switchover to RE1 (Routing Engine 1) or RE1 is set to Master from release 21.2 and above.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1850604
Major
Packet duplication and flooding issues are seen when vpls bridge domain is configured on an aggregated Ethernet and label-switched interface across multiple line cards
Product-Group=junos
Severity=Major
On MX240/MX480/MX960/MX2008/MX2010/MX2020/MX10003/MX10008/MX10016/MX10004 platforms with vpls (Virtual private LAN service) bridge domain configured, when the core facing ecmp (Equal cost multipath) are across multiple line cards and when MAC is learned up to MAC limit, packet flooding might be seen continuously for 5 mins after uplink or downlink going down causing network congestion.
1861020
Major
In an EVPN with IRB solution underlying NH change can cause packet drops on certain MX/EX platforms
Product-Group=junos
Severity=Major
On Junos MX with MPC10/MPC11/LC9600 line cards and EX92K platforms, , when IRB (Integrated Routing and Bridging) is configured under EVPN (Ethernet Virtual Private Network) routing instance, and any event that cause changes in the existing target of indirect NH (Next Hop) to a new target, the new target's token is not updated in IRB NH, will result in OOO (Out of Order) errors and packet drops.
PR NumberSynopsisCategory: ZT/YT LUSS SW driver
1765394
Major
Fatal(MQSS and XQSS errors) error on FPC leads to PIC card offline and traffic impact
Product-Group=junos
Severity=Major
On Junos MX304 and MX platforms with LC9600 linecards, With the current error handling mechanism upon receiving fatal error on Flexible pic concentrators(FPC), leads to disable both the Packet Forwarding Engine(PFE) on a Physical Interface Cards(PIC) card and seen traffic impact.
1802243
Major
AFTD crash may be observed when a MAJOR CMERROR that affects only one of the slice of a multi-slice PFE is triggered
Product-Group=junos
Severity=Major
LC9600, LC4800, MX304 may experience a Line-card AFTD core as a result of a MAJOR CMRROR trigger on one slice of the multi-slice PFE.
1861147
Major
FPC crash will be seen due to memory access violation
Product-Group=junos
Severity=Major
On MX platforms with MPC10/MPC11/LC9600 and MX304, the FPC (Flexible PIC Concentrator) will crash, generating a coredump due to memory access violation. This will result in traffic loss until the FPC recovers on its own.
PR NumberSynopsisCategory: Trio ASIC MQSS Software
1855966
Major
WAN Interfaces fail to receive hostbound traffic when OGE interface FIFO overflow error is detected
Product-Group=junos
Severity=Major
On LC9600 MX10008/MX10004 and MX304 platforms , PFE fails to receive hostbound traffic when OGE interface FIFO overflow error is detected.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1846365
Major
Traffic drops after link flap on active-active ESI setup with MAC pinning enabled
Product-Group=junos
Severity=Major
On MX platforms with ukern (legacy) FPC (Flexible PIC Concentrator) based in trio chipset and configured in an active-active ESI (Ethernet Segment Identifier) setup, traffic will be dropped after a flap of the DF (Designated Forwarder) or BDF (Backup Designated Forwarder) LAG (Link Aggregation Group) interface member.
1856573
Minor
Octet and frame count is displayed incorrectly in jnxMacStatsEntry.
Product-Group=junos
Severity=Minor
On all MX platforms with MPC10, MPC11 and LC9600, when the SNMP query is run using the command "show snmp mib walk jnxMac" . The output of jnxMacStatsEntry provides statistics from one of logical unit only even if there are multiple logical units configured and the vlan id information shows up as "0", whatever the actual vlan id is. This is a display issue with no impact.
PR NumberSynopsisCategory: DDos Support on MX
1848317
Major
SCFD flow variation leads to error messages or process crash
Product-Group=junos
Severity=Major
On all Junos MX platforms with line cards MPC10/11/LC9600/LC4800 and SCFD (Suspicious Control Flow Detection) enabled, when there are numerous flows being added, deleted, or modified simultaneously, the system experiences error messages or process crashes due to thread synchronization issues. The process crash will cause the FPC to restart.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1842518
Major
The device become unresponsive in a race condition due to maximum process (maxproc) limit
Product-Group=junos
Severity=Major
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.
1847834
Major
Multiple daemons crash upon ephemeral or static db commits
Product-Group=junos
Severity=Major
On all Junos platforms with ephemeral configuration, multiple daemons like chassisd, dcd, l2ald, l2cpd, mib2d and transportd crash upon ephemeral or static db commits causing service traffic impact. The services will self recover after the issue is hit in the network.
1861063
Critical
Unexpected issues such as login failures or disabled interfaces observed following abrupt reboot during commit operation
Product-Group=junos
Severity=Critical
On Junos platforms with boot-time optimization enabled, an abrupt reboot during a commit operation can cause configuration file corruption, potentially leading to issues like login failures or disabled interfaces.
PR NumberSynopsisCategory: Issues related to NETCONF
1796297
Major
Error message not prompted on commit confirmed RPC sent in private mode on all Junos and Junos Evolved platforms
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, commit confirmed command executed with remote procedure call (RPC) in private configuration mode is being allowed where ideally it should not be.
PR NumberSynopsisCategory: web filterig issues
1854519
Major
FPC crashing when web filtering type set to "juniper-enhanced" or "NG-juniper"
Product-Group=junos
Severity=Major
On all SRX platforms, when the web-filtering type set to "juniper-enhanced" or "NG-juniper" (NextGen-juniper), it might cause FPC (Flexible Port Concentrator) card crash and with "srxpfe" or "lcore" crash files generated.
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1865044
Minor
Process "spmd" crashes during upgrade activity
Product-Group=junos
Severity=Minor
In a Junos Fusion deployment with the MX2010 platform acting as an AD (Aggregation Device), performing a Junos upgrade on AD causes the SPMD process to crash.
PR NumberSynopsisCategory: MX10K linecard
1865576
Major
Due to race condition the FPC on MX platform crashes
Product-Group=junos
Severity=Major
On MX platforms with LC480, LC2101, and LC2103 a crash file is generated, resulting in the ukern rebooting and a complete reboot of the LC.
PR NumberSynopsisCategory: VMHOST platforms software
1856565
Minor
High memory consumption in VMhost causes FPC reboot
Product-Group=junosvae
Severity=Minor
On all VMhost based platforms, excessive file accumulation in the /var/tmp directory of the host side triggers FPC reboots, resulting in network traffic disruption. This condition occurs when available space falls below 65% (usage exceeds 35%).

 


 

22.4R3-S7 - List of Known issues 

PR NumberSynopsisCategory: "agentd" software daemon
1855112
Major
Telemetry streaming during ISSU (upgrading pre 22.1 image to 22.1+)
Product-Group=junos
In 22.1, JUNOS telemetry infrastructure under gone an enhancement in its message infrastructure. Due to this enhancement, telemetry streaming is not advisable during ISSU (upgrading pre 22.1 image to 22.1+).

Resolved In:
PR NumberSynopsisCategory: Border Gateway Protocol
1699633
Minor
The BGP graceful-shutdown community is not advertised on Junos/Junos Evolved platforms
Product-Group=junos
On Junos and Junos Evolved platforms configured with graceful-shutdown sender under the BGP(Border Gateway Protocol) dynamic neighborship, the peer device does not receive routes with communities "graceful-shutdown", as it is not advertised by the sender causing the traffic drop for the affected routes.

Resolved In: evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:22.3R3 junos:22.4R2 junos:23.1R1 junos:23.2R1
1788543
Minor
BGP OutQ counter of one of the BGP peers gets stuck after system reboot/restart routing/clear bgp neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms, when there is a high route churn and the system reboot/restart routing/clear bgp neighbor is done, there are some values stuck in the OutQ counter of one of the peers in a group. Due to this, the route updates are not sent which might result in traffic/service impact.

Resolved In: evo:22.3X50-EVO evo:23.2R2-S4-EVO evo:23.4R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:23.2R2-S4 junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
1849568
Minor
L3VPN routes are not advertised to peer when BGP sessions with route-target filter flaps
Product-Group=junos
On all Junos and Junos OS Evolved platforms, after Border Gateway Protocol (BGP) sessions configured with 'family route-target' flaps, delayed route deletion causes the loss of the Route Target Filter (RTF), preventing the node from advertising L3VPN (Layer 3 Virtual Private Network) and direct routes (e.g., loopbacks and interface routes) to the BGP peer, leading to VPN route loss and service disruption.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S5-EVO evo:24.2R2-S1-EVO evo:24.4R1-S1-EVO evo:24.4R2-EVO evo:25.2R1-EVO junos:23.2R2-S4 junos:23.4R2-S4-J9 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: MX304 PSM issuues
1850857
Major
Chassis MX304 going offline due to Power-cycle
Product-Group=junos
On all JUNOS Operating system MX304 platform, entire chassis is shutting down due to improper health checks triggered for the Power Entry Module (PEM). If a health check of the Power Entry Module (PEM) is triggered at the time when the power consumption in the chassis is less than the threshold (440W) required to run the health check, the issue might be triggered.

Resolved In: junos:22.4R3-S7 junos:23.4R2-S5 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: MX304 timing software
1841695
Major
The "show chassis synchronization extensive" command output shows syncE is locked to both primary and secondary sources after switching between primary and secondary sources
Product-Group=junos
On MX304/MX10k8 platforms, by setting the primary interface port down so that syncE switches to secondary source and then bring back the primary interface either through port down or LMIC offline and online, the "show chassis synchronization extensive" command output shows syncE is locked to both primary and secondary sources.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: QFX Access Control related
1851299
Minor
EX3400 Dot1x Radius accounting send incorrect value to the server for Acct-Input-Gigawords/ Acct-Output-Gigawords
Product-Group=junos
With Dot1x Radius Authentication and Accounting, when the Stop Accounting (due to disconnect) is sent to the Radius server the Acct-Input-Gigawords and the Acct-Output-Gigawords contains unexpectedly large value.

Resolved In: evo:23.4R2-S5-EVO evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2-S1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Device Configuration Daemon
1725168
Minor
Traffic impact will be seen with mismatched speeds on the LAG interface and member interface
Product-Group=junos
On all Junos platforms, if a speed mismatch happens in the LAG (Link Aggregation) & member interface then a traffic drop will be seen.

Resolved In: junos:22.2R3-S4 junos:22.4R3-S1 junos:23.2R2 junos:23.4R1
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1872743
Major
Packet loss or retransmissions observed across MX and ACX platforms using SFP-T transceivers
Product-Group=junos
On MX10008 platforms with LC480 line cards, as well as ACX7348 and ACX7332 platforms running Junos or Junos Evolved, the use of an Small Form-factor Pluggable Twisted-pair (SFP-T) transceiver will lead to packet loss or retransmissions on neighboring devices due to incorrect Inter-Packet Gap (IPG) handling.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S6-J8 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: EVPN control plane issues
1764126
Minor
Color related LSPs for next-hop will disappear from EVPN routes on mpls.0 routing-table by changing 'fallback none' option in 'transport-class' config.
Product-Group=junos
Service mapping EVPN service gets effected with change in fallback none option at routing-options transport-class name <>. Due to this configuration change EVPN(Ethernet virtual private network) service starts resolving over best effort in route inet.3 instead of classful transport colored rib junos-rti-tc-.inet[6].3. Service mapping with classful transport support added for EVPN service from 23.1.

Resolved In: evo:23.2R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:23.2R1-S2 junos:23.2R2 junos:23.2R2-J14 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: EX4000 PFE issues
1847159
Major
Reachability issues are seen on interfaces that are aggregated without address-family
Product-Group=junos
On Junos platforms, specifically on EX and QFX series aggregated interfaces configured without address-family results in reachability issues.

Resolved In: junos:21.4R3-S10 junos:24.4R1 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: EX interfaces issues
1789999
Major
[interfaces]:Ex-Hardening:Local/Remote fault insertion from TG is failing
Product-Group=junos
Ex-Hardening:Local/Remote fault insertion from TG is failing

Resolved In:
PR NumberSynopsisCategory: EX4400 platform
1814463
Minor
EX4400: MIST: Wrong PSU state is updating in the mist
Product-Group=junos
Unsupported PEM/PSU is shown as online (green)in the MIST Dashboard and the output of "show chassis environment" for that PSU shows the status as present/OK. No functional impact.

Resolved In: junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1679965
Major
MSFT EXR - AE Bundle with LACP went down, even though members links are up and running.On performing process restart of "firewall" & parallely changing the Firewall filter Mode from "physical -> interface.
Product-Group=junos
Changing a filter from interface-specific to physical-interface-filter (or visa versa) while also restarting the firewall process may result in issues with LACP. To avoid this, deactivate the filter before changing the mode.

Resolved In:
PR NumberSynopsisCategory: Signature Database
1822319
Minor
Not able to update IDP signature DB when using Proxy server
Product-Group=junos
On all Junos and Junos OS Evolved platforms, the IDP signature download issue is seen with squid proxy server of a specific version like 6.6 is installed.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1827648
Minor
ARP not learned on Switch Leading to Traffic Drop in EVPN-VXLAN Setup
Product-Group=junos
On all Junos QFX series platforms in an EVPN (Ethernet Virtual Private Network) VXLAN (Virtual Extensible Local Area Network) setup with CRB (Centralized Routing Bridge) architecture, ARP packets are not being learned, leading to traffic forwarding issues. This problem arises when ARP packets are sent from the firewall to the spine switches. The issue is linked to IRB (Integrated Routing and Bridging) handling and bridge domain re-incarnation, which triggers ARP request failures and impacts L3 forwarding.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S5 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1870200
Minor
mspmand coredump at handling SIP message
Product-Group=junos
The mspmand might crash when very high rate of SIP traffic flows through the device, specifically when SIP Register/Notify message comes with more than one VIA headers. Due to high rate of traffic, when system is unable to allocate memory to store the VIA information, the MSPMAND core dumped.

Resolved In:
PR NumberSynopsisCategory: IPSEC/IKE VPN
1868453
Major
IPSec tunnel inactive after multiple srg failovers on SRX platforms
Product-Group=junos
On all SRX platforms, IPSec tunnels remain inactive if multiple Service Redundancy Group (SRG) failovers occur within a short period. This issue is specifically observed when the IPSec VPN is configured with the default establish on traffic setting. During rapid failovers, if high volumes of traffic are present, the tunnel re-establishment process fails, leading to inactive tunnels and potential traffic disruption.

Resolved In: junos:24.4R1-S3 junos:24.4R2 junos:25.2R1
1877966
Minor
Some new VPN tunnels are not coming up
Product-Group=junos
On all SRX5k platforms with SPC3s installed, IPSec tunnels using IKED (Internet Key Exchange Daemon) that reuses the same IKE gateway peer IP may be observed not re-establishing.

Resolved In:
PR NumberSynopsisCategory: Multiprotocol Label Switching
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=junos
On all Junos and Junos Evolved platforms, an out-of-memory condition in the rpd process caused by uncontrolled memory allocation leads to the rpd process crashing.

Resolved In: evo:25.2R1-EVO junos:23.4R2-S4-J9 junos:23.4R2-S5 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: MX104 Software - Timing
1782868
Major
MX104 AFEB might crash following a change of PTP clock source.
Product-Group=junos
On MX104, the AFEB could crash and reboot following a change of PTP GM clock source, which affects traffic forwarding.

Resolved In: junos:21.2R3-S9
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1801129
Major
IP routes can get added to a deleted routing table
Product-Group=junos
On all Junos platforms routes can get added to deleted routing tables.

Resolved In: junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1568757
Major
The image validation is not supported during upgrading from Pre 21.2 to 21.2 and onward
Product-Group=junos
When upgrading from releases before Junos OS Release 21.2 to Release 21.2 and onward, validation and upgrade might fail. The upgrade requires using the 'no-validate' option to complete successfully. https://kb.juniper.net/TSB18251 [juniper.net]

Resolved In:
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1800862
Major
On all dual disk QFX5K platforms having QFX-5e image with secondary (sdb) disk failure, WRITE DMA errors are observed and the device goes unresponsive
Product-Group=junos
Due to a the disk failure reboot support was not added for dual disk scenario, hence system was not booting in case of disk failure on sdb (the other disk) on QFX platform.

Resolved In: junos:22.2R3-S5
PR NumberSynopsisCategory: N/A:sw-rio-timing
1830382
Major
The PTP global info parameters announce-interval, synchronization-interval, and delay-response-interval unicast packets are not captured as expected
Product-Group=junos
On the Junos ACX5448 platform, the PTP min and max announce, sync and delay-request/response do not match with the configured values in the CLI output "show ptp global-information".

Resolved In: junos:21.2R3-S9 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: RPD policy options
1873875
Minor
Junos error while configuring large community with regex
Product-Group=junos
On device running Junos commit error will be observed when configuring regex expression before large BGP community

Resolved In:
PR NumberSynopsisCategory: Resource Reservation Protocol
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
On all Junos and Junos Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.

Resolved In: evo:23.4R2-S5-EVO evo:25.3R1-EVO junos:20.3X75-D441 junos:23.4R2-S5 junos:24.4R2
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1842873
Minor
Load balance hash-key forwarding persists when switching to Layer 3-only
Product-Group=junos
On Junos SRX4600, SRX1600, SRX2300 and SRX4300 platforms, when switching load balance from L3+L4 to L3, hash-key forwarding fails; the device retains L3+L4.

Resolved In: junos:23.4R2-S5 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1745565
Major
The mgd process crash is observed when 'show' is executed from the configuration mode
Product-Group=junos
On all Junos platforms, when 'show' is executed from the configuration mode, a mgd process crash is observed which has no functionality impact.

Resolved In: evo:21.2R3-S6-EVO evo:21.3R3-S5-EVO evo:22.2R3-S2-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D36-EVO evo:22.3X80-D37-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R1-S1-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:20.3X75-D46 junos:20.4R3-S9 junos:21.2R3-S6 junos:21.2X32-D20 junos:21.2X32-D30 junos:21.3R3-S5 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:22.4R3-S5 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1 junos:25.1R1
1799215
Major
The commit fails error can be seen when configuration is modified after commit prepare
Product-Group=junos
On all Junos and Junos Evolved platforms, when the user attempts to issue the commit command after modifying the configuration post 'commit prepare', the commit discards the prepared commit cache as it is no longer valid and throws " commit fails" error and proceeds with the regular commit process from scratch.

Resolved In: evo:22.2R3-S6-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S10 junos:22.2R3-S6 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.1R1
1842518
Major
The device become unresponsive in a race condition due to maximum process (maxproc) limit
Product-Group=junos
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.

Resolved In: evo:22.2R3-S6-EVO evo:22.3X50-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:25.1R1
1869005
Minor
VMX file copy sftp reports error ssh: Could not resolve hostname sftp: Name does not resolve .
Product-Group=junos
VMX file copy sftp reports error ssh: Could not resolve hostname sftp: Name does not resolve . file copy sftp://10.85.211.4/home/labroot/junk.txt . ssh: Could not resolve hostname sftp: Name does not resolve error: file-fetch failed error: could not fetch local copy of file

Resolved In:
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1843602
Major
TCP session between syslog server and device remains in closed state
Product-Group=junos
On all Junos platforms, a TCP (Transmission Control Protocol) connection issue occurs between the device and syslog server after an idle period exceeding 2 hours. The session gets terminated and remains in a closed state without initiating any new session until the syslog server configuration is deleted and added again. This impacts disruption in log forwarding to the remote syslog server.

Resolved In: evo:23.4R2-S4-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:23.4R2-S5 junos:24.4R2 junos:25.1R1 junos:25.2R1
1853209
Major
Syslog forwarding intermittently stops post DUT reboot on virtual devices.
Product-Group=junos
On virtual devices, on reboot, vpn may take time to come up. Meanwhile since mgmt_junos is first in the routing table, syslog gets bound to mgmt_junos and hence forwarding stops.

Resolved In:
PR NumberSynopsisCategory: Issues related to YANG Data Models
1725934
Major
ODL controller is throwing unavailable capabilities error for few of the Openconfig Yang modules
Product-Group=junos
ODL controller is throwing unavailable capabilities error for few of the Openconfig Yang modules

Resolved In: evo:22.3X50-EVO evo:22.4R3-EVO evo:23.2R1-EVO evo:23.3R1-EVO evo:23.4R1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:21.4R3-S6 junos:22.2R3-S6 junos:23.2R2
1826630
Major
Annotations are improperly structured in NETCONF after enabling YANG compliance
Product-Group=junos
When the YANG(Yet Another Next Generation)-compliant knob is configured, annotations containing non-alphanumeric characters are written as-is, instead of being escaped into their corresponding formats.

Resolved In: evo:22.4R0-J0-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4X100-D30-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R1-S2 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: VMHOST platforms software
1787608
Major
The chassisd crashes at first boot up after reboot
Product-Group=junos
Additional logging has been added to the primry Routing Engine. This is to help narrow down the issue which chassisd process restarted unexpectedly at snmp_init_oids( ) function on the primary Routing Engine while booting up.

Resolved In:



Modification History

First publication 2025-05-09