Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX cRPD EX MX NFX PTX QFX SRX vSRX platforms running Junos Software

Alert Description

Junos Software Service Release version 23.2R2-S4 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Review the content and plan for upgrade as necessary - see KB21476 [juniper.net] for recommend releases.

Solution

Junos Software service Release version 23.2R2-S4 is now available.

23.2R2-S4 - List of Fixed issues 

PR NumberSynopsisCategory: SRX-1RU System Hardware defects
1843413
Major
Split brain condition will be seen in SRX4600 configured in Chassis Cluster under certain conditions
Product-Group=junos
Severity=Major
On SRX4600 platforms configured in Chassis Cluster, split brain condition will be seen under two conditions: 1. A node is isolated from the cluster and is reinstalled with Junos image using a USB and then re-joined into the cluster 2. A standalone SRX4600 is moved into a cluster The split brain condition will lead to potential loss of packets or routing inconsistencies.
PR NumberSynopsisCategory: NSD process
1857379
Critical
The nsd process crashes on SRX platforms during cluster reboot, failover, or policy addition causes traffic outage
Product-Group=junos
Severity=Critical
On all Junos OS SRX series platforms configured with the logical systems (LSYS), the network security daemon (nsd) process crashes due to cluster failover or reboot of node in a standalone firewall setup or while adding security policies. This crash generates a core dump and prevents the system from configuring security policies. As a result, all policy configurations are removed, leading to a traffic outage.
PR NumberSynopsisCategory: MX/PTX 20A AC power Hardware Issues
1740767
Minor
"Voltage Threshold Crossed" alarm seen as power supply gives off more power to the FPC
Product-Group=junos
Severity=Minor
On Junos MX10004, and MX10008 the power supply gives off more power to the FPC and as a result "Voltage Threshold Crossed" alarm is observed.
PR NumberSynopsisCategory: QFX VC Datapath
1773425
Major
QFX5120, EX4650, EX4400, EX4100 Virtual Chassis (VC) drops Address Resolution Protocol(ARP) packets from remote leaf
Product-Group=junos
Severity=Major
QFX5120, EX4650, EX4400, EX4100 Virtual Chassis (VC) platforms running Junos, drops Address Resolution Protocol(ARP) packets from remote leaf when Virtual Extensible LAN(VxLAN) encapsulated ARP packets are received from ingress port on one of the Flexible PIC concentrator (FPC) and egress port is an Aggregate Ethernet(AE) not having ingress port members on the FPC.
PR NumberSynopsisCategory: MX YT-ZF Linecards Interface Software Category
1846164
Minor
Continuous logging of alarms during a fiber cut with transport devices
Product-Group=junos
Severity=Minor
In a scenario where a fiber link has transport devices to amplify the signal, excessive logging of alarms for an interface can occur. The transport devices will amplify the incoming signal, which isn't valid when the fiber has been cut. This causes the router to receive a good signal and Rx power but it contains no valid data. In response, the interface on the router will attempt to link up repeatedly and after failing multiple retries, which is set per platform, the router will attempt to reinitialize the data path. This causes multiple alarms from the optic to get set and then cleared resulting in alarm logs in the system logs. This can become excessive if the link remains down for an extended period of time. To avoid continuous logging to the system log, after a number of retries the logs will be suppressed. The interface will continue to attempt to link up including reinitializing the the data path, but without the logging. This will allow the interface to link up when the physical link is repaired, and at that point the logs will stop being suppressed
PR NumberSynopsisCategory: BBE interface related issues
1850562
Major
Host unreachable from the router with PPPoE when "routing-service" and "RPF-check" are enabled, and the route is learned via EBGP
Product-Group=junos
Severity=Major
On Junos platforms configured with BGP (Border Gateway Protocol) and rpf-check over PPPoE (PPP over Ethernet) subscribers, the platform is unable to reach the hosts present in the routing table when these are learnt by EBGP. This issue affects MX Platforms and QFX platforms.
PR NumberSynopsisCategory: MIBs related to BBE
1824274
Minor
The jnxSubscriberPortTerminatedCounter shows incorrect values for interfaces
Product-Group=junos
Severity=Minor
On Junos MX platforms, the jnxSubscriberPortTerminatedCounter no longer shows the correct values for the individual ports. It shows the same value for all ports. These subscribers are enabled over PS interface.
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1814017
Minor
Extensible Subscriber Services Manager (ESSM) sessions gets disconnected when PFE encounters an issue for any service or subscriber session
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, where subscriber-management is configured and if PFE encounters an issue for any service or subscriber session then it sends an error for anyone of the session in bulk response which results in the subscriber services to be disconnected.
1852532
Major
Memory leaks are seen in bbe-statsd process during the subscriber logout phase
Product-Group=junos
Severity=Major
On all MX platforms, a memory leak in bbe-statsd (Broadband Edge statistics collection and management process) can be seen during the subscriber logout phase when repd (replication service daemon ) takes time to replicate the entries to standby RE (Routing Engine).
PR NumberSynopsisCategory: Border Gateway Protocol
1788543
Minor
BGP OutQ counter of one of the BGP peers gets stuck after system reboot/restart routing/clear bgp neighbor
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, when there is a high route churn and the system reboot/restart routing/clear bgp neighbor is done, there are some values stuck in the OutQ counter of one of the peers in a group. Due to this, the route updates are not sent which might result in traffic/service impact.
1826685
Minor
Unexpected behaviour after BGP sessions reset for catastrophic BGP configuration changes
Product-Group=junos
Severity=Minor
On Junos and Junos Evolved platforms, when a catastrophic Border Gateway Protocol (BGP) configuration change occurs, creating a new peer structure due to this configuration change, the BGP state transitions from open-sent to established multiple times (until the local device finishes cleaning the old BGP session). This results in traffic impact as the peer is reset multiple times (until a new peer connection is established).
1848939
Major
The CPU for the rpd stuck at 100% on Junos platforms
Product-Group=junos
Severity=Major
On Junos platforms, where BGP import policy is running on a BGP multipath setup and BMP post-policy exclude-non-eligible knob is configured. In such cases when the route change from usable to non-usable state and vice-versa, the route is moved to the end of the peer gateway route list for BMP to process it latter. At the same time, BGP stop_rt cursor (used by BGP import policy) is moved to the end of the peer gateway route list. With some network churn and on-going multipath evaluations, the stop_rt cursor keeps moving to the end of the list for ever. This causes BGP import policy to never converge and CPU remains high for a long time.
1849568
Minor
L3VPN routes are not advertised to peer when BGP sessions with route-target filter flaps
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, after Border Gateway Protocol (BGP) sessions configured with 'family route-target' flaps, delayed route deletion causes the loss of the Route Target Filter (RTF), preventing the node from advertising L3VPN (Layer 3 Virtual Private Network) and direct routes (e.g., loopbacks and interface routes) to the BGP peer, leading to VPN route loss and service disruption.
1859020
Minor
Incorrect subcode NOTIFICATION is sent when local interface is disabled for which multihop is configured for directly connected peer
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, when 'multihop' is configured on a directly connected interface towards a peer and the session goes in IDLE state due to no local interface (interface is disabled or down), the log messages shows 'subcode 6 'Other Configuration Change'' instead of 'subcode 9 'Hard Reset''.
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=junos
Severity=Major
On all Junos, Junos OS Evolved, and cRPD platforms, due to deadlock in internal processes, BGP (Border Gateway Protocol) route advertisement fails leading to traffic disruption.
1863551
Major
BGP route advertisement failure with as-override and peer-as configured at group level
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, BGP ( Border Gateway Protocol ) fails to advertise routes to external peers in an L3VPN ( Layer 3 Virtual Private Network ) environment when as-override is configured for a neighbor on the local device, and peer-as is applied at the group level. Since the routes are not advertised to peers, traffic matching those routes are dropped, causing service disruption.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1839288
Major
BMP soft assert due to counter reset by clear command
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when "clear bgp statistics" command is issued while one or more BMP peers are coming up the soft_assert will be hit. This issue has no impact on the traffic or services.
PR NumberSynopsisCategory: PTX10003 Interface related issues
1851078
Major
Configuration of ZR optics(400G) is not available on PTX platforms
Product-Group=junos
Severity=Major
On PTX10003 systems, it is not allowed to configure ZR optics (400G) through CLI.
PR NumberSynopsisCategory: BBE Remote Access Server
1812697
Minor
authd core after running ZTP
Product-Group=junos
Severity=Minor
On Junos Evolved platforms, after device has finished booting up with Zero Touch Provisioning (ZTP), authd process will crash and generate a core file.
1813456
Minor
Error message is observed after device is restarted
Product-Group=junos
Severity=Minor
On all Junos Evolved platforms, the error message "UI_SCHEMA_SEQUENCE_ERROR" is observed when device is restarted. There is no traffic impact due to this issue.
PR NumberSynopsisCategory: MX304 line card platform software
1849915
Major
FPC reboot due to memory leak from telemetry sensor installation/uninstallation
Product-Group=junos
Severity=Major
On Junos MX204, MX304, MX2010, MX2020, MX10004, MX10008, MX10016 with MPC11, LC2301/LC9600, LMIC16 and LC480 line cards, when installing and uninstalling specific telemetry sensors that export data from LC (Line Card), a few bytes of memory are allocated but not freed, leading to a memory leak. This issue is seen when "sensor-based-stats" is configured and LSP (Link State Path) flaps occur. Each flap triggers repeated installation and uninstallation of the telemetry sensor, accelerating memory consumption. Over time, this exhausts the memory allocated to aft-ulcd process causing FPC (Flexible PIC Concentrator) to reboot.
PR NumberSynopsisCategory: MX304 Routing Engine issues
1857833
Major
The chassisd process crash is seen after the device reboot when chassisd stalls after configuration commit
Product-Group=junos
Severity=Major
On all VMHost platforms, the chassisd crash can be seen, which can also lead to mastership switchover. This is mainly caused by a configuration commit (no specific configuration required) followed by a reboot.
PR NumberSynopsisCategory: QFX Access Control related
1872280
Major
The l2ald process crash is observed on non L2NG Junos platforms configured with "native-vlan-id" and "bridge-domains" on an IFL
Product-Group=junos
Severity=Major
On non L2NG (Layer2 Next Generation) Junos EX, MX and SRX platforms, the l2ald (Layer 2 Address Learning Daemon) process crash is observed when an IFL (Logical Interface) configured with "native-vlan-id" and "bridge-domains" and when certain config change takes place in an IFL which maps VLAN (Virtual Local Area Network) index to NULL. The dereferencing of this NULL pointer causes the crash.
PR NumberSynopsisCategory: Device Configuration Daemon
1848768
Major
MTU configuration is not applied from the configuration group after commit and "warning" is seen
Product-Group=junos
Severity=Major
When configuring MTU on interfaces through a configuration-group and commit the changes, those are not saved on the configuration file.
PR NumberSynopsisCategory: Firewall Filter
1872347
Critical
System becomes unresponsive or crash due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=junos
Severity=Critical
On Junos OS platforms, The system experiences memory exhaustion due to an mbuf (Memory Buffer) leak, system logs error message. This condition can cause the system to become unresponsive (hang state) or potentially crash, resulting in a VMcore file and service disruption. The issue arises when a firewall filter is applied to approximately 1k (1000) logical interfaces (IFLs), each filter containing over 250 terms and these filters are updated every 2-3 minutes, triggering updates for all filter attachments.
PR NumberSynopsisCategory: jdhcpd daemon refactored for evo
1817061
Major
EVO(EVPN Fabric): DHCP packets are getting relayed even after deleting the dhcp relay configuration from the leaf
Product-Group=junos
Severity=Major
DHCP packets will get relayed even after deleting the DHCP realy configuration for the irb.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1844623
Major
Stale MAC-IP entries are not cleared in an EVPN-VXLAN scenario when encapsulate-inner-vlan or decapsulate-accept-inner-vlan or both knobs are present
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when decapsulate-accept-inner-vlan or encapsulate-inner-vlan or both knobs are configured for a VXLAN (Virtual Extensible Local Area Network) and when any action corresponding to MAC-IP entries cleanup takes place, the MAC-IP entries will not be cleaned up from kernel. This will result in anomalies in device and could also lead to a core crash.
PR NumberSynopsisCategory: event/op/commit scripts, SLAX, netconf issues
1840232
Major
REST API doesn t work with passwords that includes the "%" character
Product-Group=junos
Severity=Major
On all Junos and Junos EVO (Evolved) platforms, the REST API (Representational State Transfer Application Programming Interface) doesn t function correctly when password contains "%" character.
1847814
Major
Unable to run event scripts for events: system_abnormal_shutdown/ system_shutdown/ system_reboot_event
Product-Group=junos
Severity=Major
* system_abnormal_shutdown * system_shutdown Above events are not supported in EVO. These events cannot be used in scripts. Hence the event tags have been removed for EVO.
PR NumberSynopsisCategory: EVPN control plane issues
1830295
Major
An enhancement to improve BGP performance
Product-Group=junos
Severity=Major
On all platforms, Border Gateway Protocol (BGP) will have a performance degradation causing high CPU utilization.
1839959
Critical
The MAC+IP table and mac-table are not in sync in the EVPN-MPLS active-active multihomed scenario leading to traffic loss
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms that supports ESI lag interface and in an EVPN-MPLS (Ethernet Virtual Private Network - Multi Protocol Label Switching) active-active multihomed scenario, when the multihomed access interfaces are flapped in quick succession, it results in an unresolved destination route for the specific IP host. This is occurred due to race condition within l2ald (Layer 2 Address learning daemon) followed by an interface flap which causes the locally learned MAC to go missing from the mac-table on the other PE router.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1833660
Major
Stale MAC entries may remain in the MAC table of EVPN routing instances after rapid MAC-IP move scenarios
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms with EVPN-MPLS (Ethernet Virtual Private Network - Multiprotocol Label Switching) setup , stale MAC entries may remain in the MAC table of the EVPN (Ethernet Virtual Private Network) routing instances during rapid MAC-IP move scenarios. This can cause MAC tables to reach their limits preventing new MAC addresses learning and user registration.
PR NumberSynopsisCategory: EX4100 RE, Platform Infra, Drivers
1848292
Minor
Junos EX platform will display multiple intermittent Fan overspeed alarms
Product-Group=junos
Severity=Minor
On the Junos EX platform, fan overspeed alarms may intermittently trigger as fan speeds exceed and fall below the set threshold, with no impact on service
PR NumberSynopsisCategory: EX interfaces issues
1788328
Major
Master FPC taking 20 sec time to shut backup FPC's network port after backup FPC reboot in a VC set-up
Product-Group=junos
Severity=Major
On all EX platforms with Virtual Chassis (VC) and Graceful Routing Engine Switchover(GRES) enabled, if during failover the secondary Flexible Physical Interface Card Concentrator (FPC) gets rebooted then there will be traffic loss of 20 seconds more than the expected traffic loss (1to2 seconds).
1805100
Major
Establishing virtual-chassis connection between EX4300-MP platforms, the traffic sent via the VCP port is lost minimally
Product-Group=junos
Severity=Major
On EX4300-MP platforms in non-mixed VC mode, when the VC connection is established between the platforms, the ports don't pass traffic, which leads to minimum traffic loss.
1814093
Major
Multi-rate Gigabit Ethernet port on the EX4100 and EX4400 platforms does not receive or forward traffic
Product-Group=junos
Severity=Major
On all EX4100 and EX4400 platforms with mge ports, the mge (multi rate gigabit ethernet) port shows up but does not allow traffic to pass through after port initialization or port flap.
1843585
Major
Traffic blockage observed with SFP-100BASE-BX10 optics in EX4400-48F
Product-Group=junos
Severity=Major
On Junos EX4400-48F platform, specific to the EX4400-48F (ports 0-35) SKU, not applicable to any other SKU (Stock Keeping Unit) , where SFP-100BASE-BX10 optics are used between two EX4400-48F ports, traffic blockage occurs. The link comes up, but no traffic (e.g., ping) passes through.
PR NumberSynopsisCategory: EX4400 PFE software
1817034
Major
For Junos OS platforms, the OSPF neighborship gets stuck in EXSTART state after performing NSSU
Product-Group=junos
Severity=Major
For Junos OS platforms, in a specific configuration change after NSSU (Nonstop Software Upgrade), i.e. delete and add sequence of LAG (Link Aggregation Group) bundles performed via load baseline configuration and re-apply original configuration, OSPF (Open Shortest Path First) session might get stuck in EXSTART state. This issue will impact the traffic.
1849952
Major
Handling AE Child Members, VT port properties reset when Access Port is destroyed
Product-Group=junos
Severity=Major
NA
1854253
Major
Devices fail to obtain an IP address when DHCP Security Option 82 is enabled
Product-Group=junos
Severity=Major
On Junos EX and QFX platforms when DHCP (Dynamic Host Configuration Protocol) option 82 settings are enabled under dhcp-security, hosts fail to get an IP address from the DHCP server.
1867562
Major
Default Route configured with Discard Next Hop on PFE instead of ECMP Next Hop after reboot
Product-Group=junos
Severity=Major
On all Junos EX4K (except EX4300) in a VC (Virtual Chassis) environment using LPM (Longest Prefix Match) routing, after a reboot the default route on the PFE (Packet Forwarding Engine) is incorrectly set to a "discard next-hop (NH)" instead of an ECMP (Equal-Cost Multi-Path) next-hop resulting in connectivity issues.
1870016
Minor
Traffic will be dropped due to IPv4 header checksum mismatch on EX4400 platform
Product-Group=junos
Severity=Minor
On EX4400 platform, if the switch is acting as a routing transit device, and if the value of the IPv4 header checksum is 0xFFFF in the ingress traffic, the checksum of the IPv4 header will not be recalculated even though the TTL (time to live) value has been reduced. This will lead to traffic being dropped by the next transit-device due to the bad checksum.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1801237
Major
ARP won't be forwarded in VLAN associated VNI in VxLAN Fabric
Product-Group=junos
Severity=Major
On EX4100/EX4400/QFX5120 platforms where dot1x is configured with multiple supplicant mode, if the MAC (Media Access Control )+IP (Internet Protocol ) is not in the EVPN (Ethernet Virtual Private Network) database, there will be an ARP (Address Resolution Protocol ) and it will not work as the ARP is suppressed. It will be generated to specific VLAN in VxLAN and it is suppressed due to arp suppression.This issue is seen due to dot1x configured on the interfaces. This can be restored by restarting the FPC.
PR NumberSynopsisCategory: SRX1500 platform software
1831955
Major
The SRX1500 drops the packet if MTU matches the MRU of the receiving device
Product-Group=junosvae
Severity=Major
On SRX1500 platforms, if the Maximum Transmission Unit (MTU) is configured to match the Maximum Receive Unit (MRU) of the receiving device, packet drops occur. This occurs because additional processing overhead increases the packet size beyond the MRU limit, causing the receiving device to drop the packets.
1863943
Critical
SRX1500 clustered Firewalls can go to split-brain when more than 7 RGs are configured
Product-Group=junos
Severity=Critical
On SRX1500 clustered Firewalls, when more than 7 RGs (Redundancy Groups) are configured, the Firewall cluster goes into a split-brain mode which leads to both node becoming primary and consequently traffic loss is seen.
PR NumberSynopsisCategory: Signature Database
1822319
Minor
Not able to update IDP signature DB when using Proxy server
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, the IDP signature download issue is seen with squid proxy server of a specific version like 6.6 is installed.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1826194
Minor
The rpd crash is observed during upgrade or restart
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, rpd crash is observed during upgrade or restart since kernel takes more time to update ifstate information.
1846294
Major
Memory Leak: Memory leak is detected with rpd task blocks "rpd-trace"
Product-Group=junos
Severity=Major
Memory Leak: Memory leak is detected with rpd task blocks "rpd-trace"
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1845370
Major
Interface not added back to AE bundle with multiple changes in single commit
Product-Group=junos
Severity=Major
On all Junos platforms when speed is changed on an interface which is part of AE bundle, interface will be removed and added with the updated speed. When some other operation such as interface disable is configured along with speed change on the interface in the same commit, then the interface is not removed and added to the bundle, it can cause other AE interfaces flap and traffic drop.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1827648
Minor
ARP not learned on Switch Leading to Traffic Drop in EVPN-VXLAN Setup
Product-Group=junos
Severity=Minor
On all Junos QFX series platforms in an EVPN (Ethernet Virtual Private Network) VXLAN (Virtual Extensible Local Area Network) setup with CRB (Centralized Routing Bridge) architecture, ARP packets are not being learned, leading to traffic forwarding issues. This problem arises when ARP packets are sent from the firewall to the spine switches. The issue is linked to IRB (Integrated Routing and Bridging) handling and bridge domain re-incarnation, which triggers ARP request failures and impacts L3 forwarding.
PR NumberSynopsisCategory: ISIS routing protocol
1777702
Minor
The rpd process crashes after multiple iterations of disable/enable ISIS protocol
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, the rpd process crashes after disabling/enabling the ISIS (Intermediate System-to-Intermediate System) protocol using the set command. The issue is seen after 2-3 hours of continuous disabling, and enabling the ISIS process with a 90-sec interval.
1841108
Major
Traffic drop is seen after GRES on ISIS peer
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, in an ISIS(Intermediate System-Intermediate System) graceful restart scenario, helper node sends and programs its locally configured hold-time (180 secs) instead of the "Restart-duration" received as hold-time from DUT (210 secs), due to this incorrect update, the hold timer expires at the helper node before the GR (Graceful Restart) is complete on DUT and it causes a flap of ISIS adjacency on peer/helper Node.
PR NumberSynopsisCategory: jdhcpd daemon
1808289
Minor
Switch provisioned via ZTP going unreachable due to DHCP misbehaviour on upgrading to 21.4R3-S6
Product-Group=junos
Severity=Minor
All IRB (Integrated Bridging and Routing) interfaces of EX3400-48P switches which pull initial configuration from Dynamic Host Configuration Protocol (DHCP) server via zero touch provisioning (ZTP) process, upon upgrade to 21.4R3-S6 do not send DHCPdiscover packet to obtain a new IP address after sending DHCPrelease packet resulting in interface not able to obtain IP address until rebooted.
1835753
Minor
DHCP-Relay short cycle protection can get stuck in Grace period
Product-Group=junos
Severity=Minor
DHCP-Relay short cycle protection can get stuck in Grace period
PR NumberSynopsisCategory: JFlow bug tracker for SRX platforms
1843679
Minor
Application crash is observed due to insufficient memory when a large number of JFlow entries are created
Product-Group=junos
Severity=Minor
On Junos OS SRX platforms with JFlow configured with sampling interval set to 1, traffic impact is observed due to insufficient memory for the Layer 7 applications leading to application failure. The issue happens when a large number of JFlow entries are created exhausting memory potentially leading to crash.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1804025
Major
The flowd process crash is seen on HA and MNHA mode with H323 ALG configured
Product-Group=junos
Severity=Major
On all SRX platforms configured with H323 Application Layer Gateway (ALG) when a H.323 audio call is placed which is not disconnected and RAS request and confirm messages are received and the traffic is changed between the Primary and backup nodes in a High availability (HA) mode multiple times, it will lead to flowd process crash.
1852968
Major
The SRX platform may experience a flowd process crash and generate core dump files when the ALG feature is enabled
Product-Group=junos
Severity=Major
On SRX platforms running the Junos Operating System (OS) with Application Layer Gateway (ALG) enabled, in rare scenarios, flowd process can crash and crash files are generated. While the platform eventually recovers, traffic loss will occur during this process.
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1817417
Minor
Commit error is observed on Junos platforms with MS-MPC or SPC3 when last octet of source-ip of jflow-log collector is above 223
Product-Group=junos
Severity=Minor
Configuration is not committed and shows commit error on Junos platforms with MS-MPC or SPC3 when last octet of source-ip of jflow-log collector is higher than 223.
PR NumberSynopsisCategory: Flow Module
1847419
Minor
Type 5 VXLAN traffic drops are observed when SRX run as L3-VNI gateway and the ingress and egress traffic goes to the same Type-5 VXLAN peer
Product-Group=junos
Severity=Minor
On Junos OS SRX platforms running as L3-VNI (Layer 3 - Virtual Network Identifier) gateway in EVPN-VxLAN (Ethernet Virtual Private Network - Virtual Extensible LAN) scenario, traffic drops will be observed if traffic passes through two VxLAN tunnels and traffic fails to cross the two VxLAN tunnels when the PFE (Packet Forwarding Engine) is processing the packet having same remote IPs for two VXLAN tunnels.
1856521
Major
Data Plane CPU on one device spikes up to 95% during primary node system reboot in SRX cluster
Product-Group=junos
Severity=Major
On all SRX platforms in a cluster, during an HA switchover, especially with a large number of sessions (e.g., greater than 1M), CPU utilization spikes temporarily, reaching up to 95% for a brief period. This occurs during the primary node's reboot or HA switchover. The CPU spikes cause partial service impact, which can affect traffic for a short time during the event. Once the session scan is completed, CPU utilization should return to normal as the session synchronization and cleanup processes are finalized, reducing the load on the system and restoring traffic flow to its usual performance levels.
1859163
Minor
Security forwarding process crash may occur when multicast traffic triggers a route resolution request that needs to be processed for a pending session
Product-Group=junos
Severity=Minor
When multicast traffic triggers a route resolution request for a pending session, and the route is subsequently resolved, a race condition may occur if that pending session is terminated by a different thread before processing can continue. This can result in a crash of the flowd (security forwarding process). However, the control plane remains online and unaffected.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1789245
Major
ICL failure/recovery causes BFD to flap on other node
Product-Group=junos
Severity=Major
With restart-chassis control command on SRX4200/SRX4700/SRX5k, BFD ICL will flap.
1850967
Major
L3MNHA with SRG1 IPSEC : MNHA ICL ipsec encryption link went down permanently after rebooting connected router through which ICL was established before. During this state IKE process got stuck at ~70% on MNHA Active node.
Product-Group=junos
Severity=Major
Generic MNHA issue not specific to CSDS
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1860597
Major
Security log report messages w.r.t logical system is not generated
Product-Group=junos
Severity=Major
show security log report cli command for logical systems is not working for 24.2R2, 24.4R1-S2, if log report is disabled under root system. Work around is available for this issue.
PR NumberSynopsisCategory: Firewall Policy
1809563
Major
The "show security match-policies" command results in a timeout error
Product-Group=junos
Severity=Major
On all SRX platforms, when a scaled DNS (Domain Name System) configuration with approximately 500 entries is applied along with a policy configuration, issuing the "show security match-policies" command results in a timeout error. This issue has no functional impact.
1823591
Minor
Failed inter-process communication results in higher heap and buffer usage which impacts the functionality of processes
Product-Group=junos
Severity=Minor
On all Junos SRX platforms, when there is a broken Inter-Process Communication (IPC) link between the Routing Engine (RE) and Packet Forwarding Engine (PFE), heap and buffer utilization gradually increase to 99%, causing some software modules to start failing.
1838698
Minor
Security flow sessions are impacted during ISSU on SRX platforms
Product-Group=junos
Severity=Minor
On Junos SRX platforms configured as chassis clusters, while performing ISSU (In-Service Software Upgrade), when the secondary node is being upgraded, synchronization between primary and secondary nodes is concluded without completion. Due to this, the security session flows are impacted when the secondary node takes over primary role and polices are realised and pushed to PFE (Packet Forwarding Engine).
1859554
Minor
Wrong service-name display in SRX RT_FLOW traffic log.
Product-Group=junos
Severity=Minor
On SRX platforms, wrong service-name might display in SRX RT_FLOW traffic log.
PR NumberSynopsisCategory: RPM, TWAMP feature related to SRX specific design
1830290
Minor
Log messages related to 'gencfg no msg handlers' will be seen on SRX4600 platforms
Product-Group=junos
Severity=Minor
On SRX4600 platforms when Real-time Performance Monitoring (RPM) related configuration is committed, 'gencfg no msg handlers for gencfg msg' log messages will be generated. This will not have any functional impact.
PR NumberSynopsisCategory: User Firewall related issues
1810310
Minor
NSD file handles incrementing consistently in database file causing a rare condition of ssh access failure
Product-Group=junos
Severity=Minor
On all Junos SRX branch platforms, Network Security Daemon(NSD) file handles increments consistently. Triggering a rare condition of ssh access failure of the device.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1864758
Major
Post reboot , IPSec VPN is not coming up over MNHA active/active deployment
Product-Group=junos
Severity=Major
On all SRX platforms with the new IKE daemon (iked) enabled in an MNHA (Multinode High Availability) active active setup, with the IKE gateway is configured to use the loopback (lo0) interface with the node-local knob enabled, Internet Protocol Security (IPsec) VPN will not come up after a reboot.
PR NumberSynopsisCategory: Security platform jweb support
1851362
Minor
Unable to load J-Web after upgrading SRX when time zone is set to GMT+x or GMT-x.
Product-Group=junos
Severity=Minor
Due to GMT+x or GMT-x time zone is not supported, J-Web will fail to load after upgrading SRX.
1858466
Major
VPN failures on SRX due to file descriptor issue
Product-Group=junos
Severity=Major
On all SRX platforms, Juniper Secure Connect (JSC) clients may fail to establish a VPN session after successful authentication if more than 20 concurrent connections per client IP are active. In a NATTed environment, the 21st connection will fail, and the customer must retry.
PR NumberSynopsisCategory: Layer 2 VPN related issues
1867040
Minor
Type 5 EVPN traffic is dropped on SRX when PMI is disabled or not supported
Product-Group=junos
Severity=Minor
On all SRX platforms, in an EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) environment, when PMI (Power Mode IPSec) is disabled or not supported, type 5 EVPN traffic gets dropped. The issue occurs due to flow context being cleared incorrectly, causing the overlay JEXEC nexthop to be pushed after the underlay one. This leads to the packet being treated as multicast and subsequently dropped.
PR NumberSynopsisCategory: Layer 2 Control Module
1855088
Major
In Junos EX and QFX platforms, when ERPS protocol is enabled on a ISL trunk, the commit command fails
Product-Group=junos
Severity=Major
In Junos EX and QFX platforms, when a port is configured with Inter-switch-link (ISL) trunk and the Ethernet ring protection switching (ERPS) protocol is enabled on the port, the commit command fails, causing the commit-check daemon process to crash and preventing the new configuration from being applied. This doesn't impact the devices traffic, performance, or management.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1847418
Major
MACSec fails after applying MACSec configuration on IFL and removing it
Product-Group=junos
Severity=Major
On MX devices with MPC10 linecard when applying Media Access Control Security (MACSec) configuration on IFL and removing it, MACSec negotiation fails and complete traffic blackholing.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1773796
Minor
The LSP name and bandwidth values are displayed continuously in "show mpls lsp autobandwidth name X" command
Product-Group=junos
Severity=Minor
In "show mpls lsp autobandwidth name X" command when the name of the Link State Packet (LSP) is greater than 21 characters, the first column with LSP name and the second column with the Last bandwidth are merged.
1802244
Minor
Traffic loss is seen during the LSP re-optimisation MBB process
Product-Group=junos
Severity=Minor
On Junos and Junos Evolved platforms with link/Node protection configured, when the tunnel local repair patherr or link down event arrives at the ingress for the new instance i.e. PSB2 (Path State Block) while a path in MBB (Make Before Break) is waiting for the old instance (PSB1) teardown results in traffic loss if P2B2 is carrying traffic at that time.
PR NumberSynopsisCategory: Multicast Routing
1863470
Major
The rpd crash due to memory corruption in PIM/MSDP network
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, enabling PIM (Protocol Independent Multicast) or MSDP (Multicast Source Discovery Protocol) may cause a rare memory corruption during the update of the MSDP Source Active route. This issue primarily affects highly scaled environments, leading to rpd (routing protocol daemon) coredumps and potential traffic loss.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1872010
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
Severity=Major
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberSynopsisCategory: QFX access control list
1876904
Major
Commit failure when configuring CCC firewall filter with user-vlan-id above 255 on Junos QFX5K platforms
Product-Group=junos
Severity=Major
On all Junos QFX5K platforms running versions 22.2, 22.4, or 23.2, configuring a Circuit Cross-Connect (CCC) family firewall filter with a user-vlan-id value higher than 255 results in a commit error. This prevents the user from creating a firewall filter with VLANs (Virtual Local Area Network) above 255, which disrupts traffic or allows unwanted traffic if certain traffic is being sent on those VLANs.
PR NumberSynopsisCategory: QFX L2 PFE
1820830
Major
Complete packet loss will be observed for the inter-VLAN traffic in EVPN-VXLAN CRB scenario
Product-Group=junosvae
Severity=Major
On Junos QFX and EX platforms in an EVPN-VXLAN (Extended Virtual Private Network- Virtual Extensible LAN) CRB (Centrally-Routed Bridging) scenario where the ingress leaf switch is configured with ESI (Ethernet Segment Identifier) lags (i.e. the server is multihomed), if there is an overlap between ESI lag(s) trunk ID with physical port number(s) and overlap of DMAC (destination MAC) between VGA (Virtual Gateway Address) MAC address 00:00:5e:00:01:01 (CRB setup with VGA / GW is on spine) with VRRP (Virtual Router Redundancy Protocol) MAC (specifically for the VRRP group 1 MAC address 00:00:5e:00:01:01) on the physical ports of the Leaf switches, then traffic loss will be observed for the inter-VLAN traffic.
1850203
Minor
Duplication of DHCP request packets when unicast to VRRP gateway
Product-Group=junos
Severity=Minor
On Junos QFX5100, QFX5110, QFX5120, QFX5200, QFX5210, EX4100, EX4000, EX4400 and EX4300-48MP platforms, when a client sends a single DHCP (Dynamic Host Configuration Protocol) request, the switch generates and forwards two DHCP request messages to the VRRP (Virtual Router Redundancy Protocol) gateway. This behaviour causes the client to fail to renew its IP address, resulting in a loss of network connectivity.
1855085
Major
Warning message 'Too many VLAN-IDs on untagged interface' is seen when 2049 vlans are configured on trunk LAG interface
Product-Group=junosvae
Severity=Major
On QFX5120 series switch, a warning message 'Too many VLAN-IDs on untagged interface' is seen when configuring more than 2049 vlans on trunk LAG interface.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1841913
Minor
QFX5210/AS7816 lpm ip route install failed due to table full unit 0
Product-Group=junos
Severity=Minor
On QFX5210/AS7816 Platforms, when using forwarding-options custom profile , the PFE "show pfe route summary hw" outputs will differ as compared to the actual capacity of the HW for IPV4/IPV6 LPM route installation. As a result, when trying to scale to the max supported limits that are shown in the PFE "show pfe route summary hw" output, will result in route installation errors/table full errors in the PFE.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1866130
Minor
Command "show pfe vxlan" is not supported on QFX5200 devices
Product-Group=junosvae
Severity=Minor
Support added for "show pfe vxlan" CLI command on QFX 5200 devices
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1773567
Major
100G optics settings to CAUI4 on Junos QFX5120-48T platforms
Product-Group=junos
Severity=Major
The port interface on the 100G optics of the QFX5120-48T platform is incorrectly configured
1820286
Major
The remote end of port JNP-SFPP-10GE-T doesn't shut down when the hardware is rebooted using request system reboot
Product-Group=junos
Severity=Major
On all Junos QFX devices or any platform which is using qfx-5e image, the interface JNP-SFPP-10GE-T does not get disabled using the CLI command "request system reboot" causing the remote end interface to show active.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1855279
Minor
Auto-negotiation issue will be observed on 10ge-type SFP in QFX5120-48YM platform
Product-Group=junosvae
Severity=Minor
On Junos QFX5120-48YM platforms, auto-negotiation is not enabled for 10ge-type transceivers. Resulting in the port remaining down when connected to a peer device with 1G/10G.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1852227
Major
Unintended reboots on QFX5120-48Y and EX4650-48Y platforms with Acbel PSU
Product-Group=junosvae
Severity=Major
On QFX5120-48Y and EX4650-48Y platforms with Acbel PSU (Power Supply Unit) sudden reboots are seen during UPS (Uninterruptible Power Supply) switchover. This results in impact on the traffic switchover.
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover, 
1848313
Major
OSPF neighbours go down due to link flapping after NSR switchover on Junos OS Evolved platforms with IPSEC configuration
Product-Group=junos
Severity=Major
OSPF neighborship goes down after NSR (Nonstop routing) switchover due to link flapping on Junos OS Evolved platforms with Dual RE and IPSEC configuration.
PR NumberSynopsisCategory: RPD Interfaces related issues
1850620
Minor
When BGP RIB Sharding is enabled, new BGP group/peer added gets stuck at Flags: 
Product-Group=junos
Severity=Minor
On Junos OS and Junos Evolved platforms, when BGP RIB Sharding is enabled, new BGP group/peer added gets stuck at Flags: . Route is established but freezes by sending 0 size window and the peer stops sending routes then, after some time the remote side tears the session down.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1801382
Minor
Memory Leak in the rpd Process During Protocol Deactivation/Activation
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, A memory leak occurs during protocol, routing instance, or interface deactivation/activation, linked to improper IPv6 Interface Address (IFA) reference handling in the " ifx_dist_msg " process. This can lead to rpd crashes and service disruptions.
1834859
Major
The RPD crashes after executing "show krt error-statistics errorno X"
Product-Group=junos
Severity=Major
Please do not issue the "show krt error-statistics errorno ..." stanza. This command causes RPD to restart unexpectedly.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1793196
Major
Multicast traffic black-holing upon MoFRR primary link went down
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when MoFRR (Multicast-only fast reroute) is configured with NSR (Non-stop routing) while interface flapping or RE switchover, there is a next-hop leak and the next-hop in RIB (Routing Information Base) is different from the next-hop in FIB (Forwarding information base) due to that multicast traffic will be impacted.
1848971
Major
Configuring BGP rib-sharding and generate route will cause rpd process to crash
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring BGP (Border Gateway Protocol) rib-sharding and generate routes will cause the rpd process to crash.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1845425
Major
Traffic blackhole is observed for IPv4 /32 LDP prefixes advertised over BGP-LU when BGP sharding is configured
Product-Group=junos
Severity=Major
On Junos OS MX and Junos OS Evolved PTX platforms with MPLS (Multiprotocol Label Switching) and BGP (Border Gateway Protocol) sharding configured, the route is not resolved as the resolver does not request PNH (Protocol Next Hop) information from RaaS (Routing as a Service) server although BGP added the route resolution in the inet.3 table. This issue leads to IPv4 /32 LDP (Label Distribution Protocol) prefixes advertised over BGP-LU (BGP Label Unicast) not being installed in the mpls.0 table i.e. corresponding labels being marked as hidden in the MPLS routing table (mpls.0), preventing proper traffic forwarding, leading to a traffic blackhole.
1854481
Minor
The rpd gets struck with 100% CPU usage after enabling BGP RIB-Sharding
Product-Group=junos
Severity=Minor
On all Junos OS and Junos OS Evolved platforms , enabling the BGP RIB-Sharding causes the routing protocol daemon (rpd) leading to spike and remain at 100% CPU usage due to a background task ( such as the Route Target/User Interface (RT/UI) delete job ) entering into the continuous processing cycle and looping behaviour.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1813582
Minor
Static route refreshes age when commit full is performed
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, with import policy defined in the rib-group and commit full is performed, static route refreshes age. There is no service impact due to this issue. This issue is not seen with normal commit.
1849202
Major
BGP route still seen in routing table when route not available
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms , the router learns routes through the BGP (Border Gateway Protocol) and has the feature: "BGP RIB Sharding" enabled for IPv4. These routes are stored in the Inet.0 routing table. Later, if the neighbor that announced this route or the protocols associated with the routing table of the used VRF (Virtual Routing and Forwarding) are removed, the route remains in the routing table, and hence traffic is forwarded to the stale routes.
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1808481
Minor
The error message "sysctl kern.corefile not supported" is seen for multiple daemons during daemon initialisation
Product-Group=junos
Severity=Minor
On all Junos Evolved platforms, while executing "show log messages", error message "sysctl kern.corefile not supported" is seen which is introduced during daemon initialisation.
PR NumberSynopsisCategory: Resource Reservation Protocol
1792192
Major
Missing HELLO object in RSVP Hello messages after RE failovers in the NSR mode
Product-Group=junos
Severity=Major
In rare unknown condition after RE switchover, rsvp hello can have local instance to be zero due to wrong information synced from master RE by mirroring process. When rsvp neighbor is created and never received hello exchange with neighbor, the replication entry which is synced to standby RE will have most of the information as zero, including the local instance, which is used to generate hello object. After RE switchover, rsvp hello will have local instance to be zero due to the wrong information synced from master RE by mirroring process. This is addressed by update the replication entry once all the parameters of the rsvp neighbor is filled, so standby RE will receive the right info, also for future protection, backup RE will avoid creating neighbor until after switchover and setting a new local instance if it is zero.
1819948
Minor
LSP re-optimization issue has been observed
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, the LSP (Label Switched Path) re-optimization issue has been observed. LSP bandwidth change is unsuccessful due to bandwidth unavailable RSVP (Resource Reservation Protocol) PathErr.
1823215
Minor
Bypass re-optimisation not taking SRLG or fate-sharing into account when protected link is down
Product-Group=junos
Severity=Minor
On all MX and PTX platforms, In RSVP-TE (Resource Reservation Protocol-Traffic Engineering) scenario, when interface protected by bypass LSP (Label Switched Path) goes down, re-optimization of bypass can leads to unexpected path selection due to non consideration of SRLG (Shared Risk Link Group) or fate-sharing information with respect to protected interface during CSPF (Constrained Shortest Path First) path computation, could result in traffic impact due to this unexpected path selection.
1837770
Major
mgd timeout communicating with routing daemon rpd for 30 minutes during RSVP MBB event
Product-Group=junos
Severity=Major
On all Junos OS platforms, Management Daemon (MGD) on a Junos device was unable to communicate with the Routing Protocol Daemon (RPD) for an extended period during a Make Before Break (MBB) event for RSVP signaling. This issue is seen mostly under high scale mpls label switch paths.
1864949
Major
User traffic dropped after ISIS went down on one side with trapcode observed
Product-Group=junos
Severity=Major
On all JUNOS and JUNOS evolved Operating Systems, if a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in unexpected traffic blackholing on the router at the downstream end of the flapping link.
PR NumberSynopsisCategory: HA functionality on ASP
1853304
Major
Traffic was lost on MX platforms following a Routing Engine failover
Product-Group=junos
Severity=Major
On Junos MX240/MX480/MX960/MX2010/MX2020 platforms which support TLB (Traffic-Load Balancer) the PFE (Packet Forwarding Engine) is not properly synchronized with the new master RE (Routing Engine) after a RE failover causing traffic loss
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1866948
Major
SNMPV3 Engine-ID does not update to MAC address as configured
Product-Group=junos
Severity=Major
On SRX platforms, when changing the SNMPV3 Engine-ID configuration from 'use-default-ip-address' to 'use-mac-address'. SNMP local engine does not reflect the MAC address.
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1706171
Major
PFE crash observed during deletion of service-set
Product-Group=junos
Severity=Major
When deleting a service-sets configuration, the PFE (Packet Forwarding Engine) may restart on MX platforms with MS-MPC (Multiservice-Modular Port Concentrator). This leads to traffic loss.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
Severity=Major
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.
PR NumberSynopsisCategory: SRX Advanced Anti-Malware module
1827283
Minor
PFE core can be seen on SRX platforms during ISSU
Product-Group=junos
Severity=Minor
On Junos SRX4k/5k series platforms in a chassis cluster environment, the srxpfe (Packet Forwarding Engine) process crashes during ISSU ( In service Software Upgrade). It happens after failover to the upgraded node and before the secondary node is all the way up to join the cluster. This process crash will cause traffic impact, however the system self-recovers.
PR NumberSynopsisCategory: SRX branch platforms
1776656
Minor
Interfaces stay down when 1G SFP fiber transceiver connected to SRX380 platform
Product-Group=junos
Severity=Minor
Ports are staying down on SRX380 platform with 1G SFP fiber transceiver while trying to connect to a device that doesn't support auto-negotiation and/or having hard-coded speed and duplex setting
1836235
Minor
SRX default named.conf file is created with non dns-proxy related configuration changes
Product-Group=junos
Severity=Minor
On SRX platforms with dns-proxy configured, default named.conf file is created with non dns-proxy related configuration changes. This leads to halting of dns-proxy operation.
1845997
Major
Packet drops are observed in the VPLS environment on SRX380 platforms in packet mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms in packet mode, when VLAN (Virtual Local Area Network)-VPLS (Virtual Private LAN Service) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 (Layer 2) unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1641517
Minor
Multiple J-UKERN core files might be generated during the sanity test
Product-Group=junos
Severity=Minor
On SRX4600 platform, the CPU may overrun while performing sanity check due to incompatibility issues between ukern scheduler and Linux driver which might lead to traffic loss.
1852821
Major
FPC restart observed after continuous commits on SRX4600 and SRX5k series platforms
Product-Group=junos
Severity=Major
On SRX4600 and SRX5k Series platforms, when continuous commits operations are performed and that commit operations consist of IDS configuration changes causes a memory leak and these memory leak continues leading FPC(Flexible PIC Concentrator) restart followed by J-UKERN(Junos kernel core files are related to the Junos OS kernel) core generation due to memory exhaustion. Traffic loss will be seen during FPC restart.
PR NumberSynopsisCategory: MX10003/MX204 Timing/Sync-E issues tracking
1863091
Major
FPC will crash in MX10003 during the Master switchover to RE1 or Master set to RE1
Product-Group=junos
Severity=Major
MX10003 FPC (Flexible PIC Concentrators) will crash if Primary RE (Routing Engine) switchover to RE1 (Routing Engine 1) or RE1 is set to Master from release 21.2 and above.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1865649
Major
Traffic drop from subscriber will be observed when rpf-check knob is enabled under subscriber dynamic-profile with static underlying VLAN interface
Product-Group=junos
Severity=Major
On all Junos MX platforms with BBE subscribers (Broadband Edge) over static IFLs (Logical Interface) with static underlying VLAN (Virtual Local Area Network) interface and ISSU (In-Service Software Upgrade) is performed, traffic drop will be observed when rpf-check (Reverse-path forwarding) knob is enabled under subscriber dynamic-profile.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1856393
Minor
Aftd-trio core dump seen while removing subscribers (vbf) on an AFT based line card may result in a crash
Product-Group=junos
Severity=Minor
Aft-trio crash will be seen in some scenario when subscriber interface on aft based line card is removed and at the same time those subscribers interfaces stats are collected
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1850604
Major
Packet duplication and flooding issues are seen when vpls bridge domain is configured on an aggregated Ethernet and label-switched interface across multiple line cards
Product-Group=junos
Severity=Major
On MX240/MX480/MX960/MX2008/MX2010/MX2020/MX10003/MX10008/MX10016/MX10004 platforms with vpls (Virtual private LAN service) bridge domain configured, when the core facing ecmp (Equal cost multipath) are across multiple line cards and when MAC is learned up to MAC limit, packet flooding might be seen continuously for 5 mins after uplink or downlink going down causing network congestion.
1853607
Minor
On MX304 and MX platforms with MPC10, MPC11, LC9600 configured with Virtual Private LAN Service (VPLS) observe validation/installation errors logged by Advanced Forwarding Toolkit(AFT) in the PFE software.
Product-Group=junos
Severity=Minor
On MX304 and MX platforms with MPC10, MPC11, LC9600 configured with Virtual Private LAN Service (VPLS) observe validation/installation errors logged by Advanced Forwarding Toolkit(AFT) in the PFE software.
1861020
Major
In an EVPN with IRB solution underlying NH change can cause packet drops on certain MX/EX platforms
Product-Group=junos
Severity=Major
On Junos MX with MPC10/MPC11/LC9600 line cards and EX92K platforms, , when IRB (Integrated Routing and Bridging) is configured under EVPN (Ethernet Virtual Private Network) routing instance, and any event that cause changes in the existing target of indirect NH (Next Hop) to a new target, the new target's token is not updated in IRB NH, will result in OOO (Out of Order) errors and packet drops.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1858076
Major
The aftd process crash is seen on Junos OS platforms running MPC10, MPC11, LC4800, LC9600 line cards and in Junos OS platforms MX304, EX9200-15C
Product-Group=junos
Severity=Major
On Junos OS platforms running MPC10, MPC11, LC4800, LC9600 line cards and in Junos OS platforms MX304, EX9200-15C, aftd process crash is seen resulting in crash of FPC (Flexible PIC Concentrator) line card while the route module of PFE (Packet Forwarding Engine) processing route churns as simultaneous actions (add/delete/read) by multiple threads on the process.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1846365
Major
Traffic drops after link flap on active-active ESI setup with MAC pinning enabled
Product-Group=junos
Severity=Major
On MX platforms with ukern (legacy) FPC (Flexible PIC Concentrator) based in trio chipset and configured in an active-active ESI (Ethernet Segment Identifier) setup, traffic will be dropped after a flap of the DF (Designated Forwarder) or BDF (Backup Designated Forwarder) LAG (Link Aggregation Group) interface member.
1849854
Major
VPLS flooding is affected in mesh-group when one of the interfaces goes down
Product-Group=junos
Severity=Major
On MX304 and MX platforms with MPC10, MPC11, LC9600 and static Label-Switched Path (LSP) configured for Virtual Private LAN Service (VPLS), flooding does not happen in mesh-group when one of the interfaces goes down.
1853874
Minor
The forward next-hop for multicast is not updated during indirect next-hop change in VPLS
Product-Group=junos
Severity=Minor
On MX series platforms with MPC10/MPC11/LC9600 line cards and MX304 series platforms, when an indirect next hop changes, the forwarding next hop entries associated with the multicast in a VPLS instance are not immediately updated.As a result, BUM(broadcast, unicast and multicast) traffic is impacted in the VPLS.
1856573
Minor
Octet and frame count is displayed incorrectly in jnxMacStatsEntry.
Product-Group=junos
Severity=Minor
On all MX platforms with MPC10, MPC11 and LC9600, when the SNMP query is run using the command "show snmp mib walk jnxMac" . The output of jnxMacStatsEntry provides statistics from one of logical unit only even if there are multiple logical units configured and the vlan id information shows up as "0", whatever the actual vlan id is. This is a display issue with no impact.
1865605
Critical
ARP packet drops seen if proxy-arp restricted is configured on an IRB interface.
Product-Group=junos
Severity=Critical
On the Junos MX and EX9K platforms, when a Bridge Domain(BD) is configured with an integrated Routing and Bridging(IRB) interface that has proxy ARP set to restricted mode, the switch forwards ARP requests only to the Routing Engine(RE) without broadcasting them across the VLAN. Thus, impacting the hosts within the same VLAN.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1813253
Minor
Memory issue seen with syslog/log in firewall terms
Product-Group=junos
Severity=Minor
On all Junos MX150 platforms, firewall terms with syslog or logging may cause an mbuf (memory buffer) memory leak, resulting in an FPC crash.
1864237
Critical
Observing out-of-order packets when the TCP traffic gets passed over AE bundle and tunnelled via MPLSoUDP tunnel
Product-Group=junos
Severity=Critical
On Junos OS platforms, When "dynamic tunnels" configured and "set chassis loopback-dynamic-tunnel" knob is used and when TCP (Transmission Control Protocol) traffic passed via MPLSoUDP (Multi-Protocol Label Switching Over User Datagram Protocol) tunnel through an outgoing AE (Aggregated Ethernet) bundle interface having member interfaces, use of either inner or outer header hash calculations lead to out-of-order packets at the egress. It causes service impact on related flow of traffic due to out-of-order packets.
PR NumberSynopsisCategory: DDos Support on MX
1848317
Major
SCFD flow variation leads to error messages or process crash
Product-Group=junos
Severity=Major
On all Junos MX platforms with line cards MPC10/11/LC9600/LC4800 and SCFD (Suspicious Control Flow Detection) enabled, when there are numerous flows being added, deleted, or modified simultaneously, the system experiences error messages or process crashes due to thread synchronization issues. The process crash will cause the FPC to restart.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1829031
Minor
An authentication failure occurs when the TACACS+ server detects an error in sending authentication response
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved products configured with TACACS+(Terminal Access Controller Access Control System Plus) authentication method, authentication seems to fail when TACACS+ server detects an error in sending authentication response to the host device. This impacts authentication and user cannot login into the device.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1751025
Major
User key mismatch will be observed when ssh key has more than 1024 characters
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, ssh host key configured under system services is limited to taking only up to 1024 characters. So any key with more than 1024 characters won't be getting the full content of the certificate file. Only partial content will be stored in the attribute and user key mismatch will be observed.
1847834
Major
Multiple daemons crash upon ephemeral or static db commits
Product-Group=junos
Severity=Major
On all Junos platforms with ephemeral configuration, multiple daemons like chassisd, dcd, l2ald, l2cpd, mib2d and transportd crash upon ephemeral or static db commits causing service traffic impact. The services will self recover after the issue is hit in the network.
1854070
Minor
cli coredump genarated when the size of buffer area (user input) increased to 1GB
Product-Group=junos
Severity=Minor
Cli coredump genarated when the size of buffer area (user input) increased to 1GB.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1814980
Major
The eventd crash is observed on Junos and Junos Evolved platforms
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platform, when syslog over TLS is configured, empty hostnames are generated in logs. The logging will be briefly affected since eventd is cored.
PR NumberSynopsisCategory: Issues related to NETCONF
1852868
Major
commit confirmed rpc request displays closing tag without opening tag in private mode
Product-Group=junos
Severity=Major
Fixed xml format in rpc output
PR NumberSynopsisCategory: Antivirus UTM issue
PR NumberSynopsisCategory: web filterig issues
1816280
Minor
Memory corruption resulting in srxpfe crash on SRX platforms
Product-Group=junos
Severity=Minor
On SRX platforms with UTM (Unified Threat Management) Sophos Anti-virus configured, srxpfe process (SRX Packet Forwarding Engine) crashes resulting in traffic impact due to memory corruption for insufficient buffer size allocation.
1854519
Major
FPC crashing when web filtering type set to "juniper-enhanced" or "NG-juniper"
Product-Group=junos
Severity=Major
On all SRX platforms, when the web-filtering type set to "juniper-enhanced" or "NG-juniper" (NextGen-juniper), it might cause FPC (Flexible Port Concentrator) card crash and with "srxpfe" or "lcore" crash files generated.
PR NumberSynopsisCategory: MX10K linecard
1809644
Major
FPC crash due to race condition on MX platforms with LC480
Product-Group=junos
Severity=Major
On MX platforms with LC480, a crash file is generated because of this issue which results in entire ukern reboot. The issue happens due to race conditions. The ukern automatically reboots and the FPC (Flexible PIC Concentrator) comes up online. Traffic loss is observed till the FPC restarts after the ukern crash.
PR NumberSynopsisCategory: Virtual Private LAN Services
1797423
Major
Memory leak is observed for the VPLS CE facing interface on all Junos and Junos Evolved platforms
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms memory leak in task_timer block is observed for Virtual Private LAN Service (VPLS) CE facing interface. These leaks are configuration driven and can happen when VPLS instance configuration is deleted or probably when CE interface moves across VPLS instances or deleted from the VPLS instance.
PR NumberSynopsisCategory: usf url filtering related issue
1814701
Major
, URL filtering sessions are bypassed on MX platform with SPC3
Product-Group=junos
Severity=Major
On MX platform with SPC3, the packets matched under the URL-filtering configuration are bypassed rather than the action mentioned in the rule.
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1844731
Major
High heap memory caused MX-SPC3 PIC to go offline
Product-Group=junos
Severity=Major
On Junos platforms, specifically MX240, MX480 and MX960 supporting MX-SPC3 service cards, if inline-jflow is configured with huge scaled routes (~4M routes) resulting in kernel memory exhaustion that is high Heap Memory and SPC3 Pic goes offline.
PR NumberSynopsisCategory: usf nat related issues
1841231
Minor
PCP mapping fails for specific internal IPv4 addresses in DS-lite scenario
Product-Group=junos
Severity=Minor
On MX240, MX480 and MX960 with Unified-Services Framework (USF) and Dual-stack lite (DS-lite) enabled, Port Control Protocol (PCP) mapping fails for any internal IPv4 with fourth octet greater than ".223".

 

 

Extended Solution

 

23.2R2-S4 - List of Known issues 

PR NumberSynopsisCategory: "agentd" software daemon
1811739
Minor
XMLProxyd core dump might be triggred due to UI Libs thread has not enabled TLS for 32-bit applications
Product-Group=junos
On all Junos platforms, XMLProxyd core dump might be seen due to TLS is not enabled for 32-bit UI libs threads

Resolved In:
PR NumberSynopsisCategory: access node control protocol daemon
1814300
Major
L2BSA sessions remain down when port messages from ANCP neighbor are dropped in a scaled scenario after ISSU followed by GRES
Product-Group=junos
On all Junos MX platforms with dual RE (Routing Engine), having ANCP (Access Node Control Protocol ) and L2BSA (Layer 2 Bitstream Access) sessions under a scaled scenario (about 10k subscribers), when ISSU (Unified In-Service Software Upgrade) is performed followed by a GRES (Graceful Routing Engine Switchover), it is observed that the port-up messages from ANCP neighbor are dropped either at PFE (Packet Forwarding Engine) or by the ANCP daemon or BBE (Broadband Edge)/autoconf plugin which causes L2BSA sessions to remain down and as a result traffic over the affected subscriber sessions are dropped.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.1R1
1877794
Major
The L2BSA subscriber fails to logout when "auto-configure-trigger" knob is edited on ANCP neighbour of MX platforms
Product-Group=junos
On all MX platforms with Access Node Control Protocol(ANCP) configured, the knob auto-configure-trigger on ANCP neighbor if edited (deactivate and activate) between system boot-ups, is not getting applied to the ANCP neighbour correctly. As a result, if an ANCP session goes down and the adjacency-loss-hold-time expires, the Layer 2 Bit Stream Access(L2BSA) interface still remains up indefinitely and the subscribers will fail to logout. Chassis needs to be rebooted after editing the configuration.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1849377
Major
The bbe-statsd process crash due to malformed PFE packets
Product-Group=junos
On all MX and Junos Evolved platforms, bbe-statsd process crashes are observed in rare scenario. The issue happens when malformed packets are received from PFE (Packet Forwarding Engine). The continuous crashing of bbe-statsd every 5 minutes disrupts logout processes and accounting functions.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Border Gateway Protocol
1853025
Major
Updating a source-file to load ROAs should be done by changing the name of the source file
Product-Group=junos
Loading ROAs from a source-file was a feature introduced as a convenience feature and as such this only affects that feature. This feature is not in widespread use and was created to have a fallback ROA when all sessions go down. This problem scenario requires multiple reloads with the being modified back and forth to add and then delete and re-add the database configured in the import policy.

Resolved In: evo:22.4R3-S7-EVO evo:23.4R2-S5-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:23.4R2-S2-J13 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP-LU (Border Gateway Protocol-Labeled Unicast) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.2R2-J6 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1
PR NumberSynopsisCategory: Issues related to Common BIOS on x86 based designs
1608045
Minor
The TSC_DEADLINE disabled error logs are observed on Junos vmhost platforms after upgrade
Product-Group=junos


Resolved In: junos:22.2R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: PTX10003 Platform related issues
1805380
Minor
The correct number of FPCs are not being listed
Product-Group=junos
On PTX10003 platforms, the correct number of Flexible PIC Concentrators (FPCs) are not being listed when requesting the output from Packet Forwarding Engine (PFE).

Resolved In: evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.3R1-EVO junos:23.4R2-S4 junos:24.3R1
PR NumberSynopsisCategory: BBE Remote Access Server
1813456
Minor
Error message is observed after device is restarted
Product-Group=junos
On all Junos Evolved platforms, the error message "UI_SCHEMA_SEQUENCE_ERROR" is observed when device is restarted. There is no traffic impact due to this issue.

Resolved In: evo:23.2R2-S4-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: MX304 timing software
1869538
Minor
PTP FPGA ethernet interface down and cause PTP stuck in initializing state
Product-Group=junos
On Junos OS Evolved platforms and MX304 device with PTP (Precision Time Protocol) enabled, on bootup or FPC reboot, device will encounter issues with time synchronization, including devices going out of phase, disconnecting, or remaining in freerun state, potentially impacting applications that rely on precise timing. PTP will be stuck in initializing state.

Resolved In: evo:23.4R2-S5-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.4R2-S5 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1872743
Major
Packet loss or retransmissions observed on MX platforms using SFP-T transceivers
Product-Group=junos
On MX10004, MX10008 and MX10016 platforms with LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) transceiver will lead to packet loss or retransmissions on neighboring devices due to incorrect Inter-Packet Gap (IPG) handling.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S6-J8 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1865403
Major
Memory leak is observed when Telemetry is configured
Product-Group=junos
On all Junos and Junos Evolved platforms having Telemetry configured, the memory allocations in 512 bytes slab that are seen to be growing in problem state, are related to write on a unix domain socket (internal to application). Since the data is not read, the send buffer keeps growing and the associated memory does not gets released. Every telemetry response from the producer does a 1 byte write on this socket and over a period of time the send buffer gets full. The default size of the unix socket send buffer is set to 512MB. But there is no functional impact.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.4R2-S5-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.4R2-S5 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: EX interfaces issues
1723924
Major
[optics] [opticstag] EX4400-48F :: RLI-53126: Carrier tranistions is not setting properly for channelized ports on non-DUT Lagavulin for QSFP28-100G-AOC-30M 740-064980 of FINISAR
Product-Group=junos
EX4400-48F :: RLI-53126: Carrier tranistions is not setting properly for channelized ports on non-DUT Lagavulin for QSFP28-100G-AOC-30M 740-064980 of FINISAR

Resolved In:
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1815250
Major
ARP resolution issues might happen when VxLAN and non-VxLAN are both configured on the same ifd but different ifl
Product-Group=junos
Due to a conflict in the config between the VXLAN (Virtual Extensible LAN) hardware token and the VLAN (Virtual Local Area Network) traffic loss could happen as consequence of wrong path for ARP (Address Resolution Protocol)

Resolved In: junos:23.4R2-S4 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Flow Module
1779792
Critical
Junos OS: SRX Series: Transmission of specific control traffic sent out of a DS-Lite tunnel results in flowd crash (CVE-2025-30645)
Product-Group=junos
A NULL Pointer Dereference vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker causing specific, valid control traffic to be sent out of a Dual-Stack (DS) Lite tunnel to crash the flowd process, resulting in a Denial of Service (DoS). Continuous triggering of specific control traffic will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA96455 [juniper.net] for more information.

Resolved In: junos:20.2R3-S10 junos:21.2R3-S9 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2 junos:24.2R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1868453
Major
IPSec tunnel inactive after multiple srg failovers on SRX platforms
Product-Group=junos
On all SRX platforms, IPSec tunnels remain inactive if multiple Service Redundancy Group (SRG) failovers occur within a short period. This issue is specifically observed when the IPSec VPN is configured with the default establish on traffic setting. During rapid failovers, if high volumes of traffic are present, the tunnel re-establishment process fails, leading to inactive tunnels and potential traffic disruption.

Resolved In: junos:24.4R1-S3 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1873674
Major
In EVPN IPv6 route learning for MAC address fails if mac pinning is enabled
Product-Group=junos
In EVPN IPv6 route learning for MAC address fails if mac pinning is enabled on the interface.

Resolved In: junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1847378
Major
Some ports take longer than others to come back online when multiple ports experience simultaneous flap
Product-Group=junos
If interfaces on MPC10E card are configured with hold down timer and the link hit a short flap then it may take additional time for that link to be up. It cause interruption for traffic as well as control plane protocols which are enabled on that link, for example BFD, OSPF, LACP and etc .

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.4R3-S1-J3 junos:22.4R3-S2-J11 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: MX104 Software - Timing
1782868
Major
MX104 AFEB might crash following a change of PTP clock source.
Product-Group=junos
On MX104, the AFEB could crash and reboot following a change of PTP GM clock source, which affects traffic forwarding.

Resolved In: junos:21.2R3-S9
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1849296
Minor
The self-generated traffic on Junos platforms use the incorrect source IP with ECMP configuration
Product-Group=junos
On all Junos platforms configured with Equal-Cost Multi-Path (ECMP) routing, self-generated traffic selects an incorrect source (Internet Protocol) IP address. As a result, the peer device lacks the relevant route information, causing self-generated traffic to be dropped. This issue is specific to ECMP configurations and does not impact data traffic.

Resolved In: evo:23.4R2-S5-EVO junos:22.4R3-S7 junos:22.4R3-S8 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1568757
Major
The image validation is not supported during upgrading from Pre 21.2 to 21.2 and onward
Product-Group=junos
When upgrading from releases before Junos OS Release 21.2 to Release 21.2 and onward, validation and upgrade might fail. The upgrade requires using the 'no-validate' option to complete successfully. https://kb.juniper.net/TSB18251 [juniper.net]

Resolved In:
PR NumberSynopsisCategory: Kernel socket data replication issues for protocols that use
1675057
Minor
An expected error message is seen due to an interruption with the master and backup RE
Product-Group=junos
These are expected error logs, and doesn't cause any functional impact. "jsr_iha_pri_unrepl_msg_func: Error: Invalid primary handle in msg 0x10006c600000621, error=2" These logs might be seen if the following conditions are met: * On all Junos OS platforms * Non stop routing is enabled. * with scaled setup The possible triggers would be restart chassisd, ksyncd, switchover, re reboot... which causes nsr unreplication/replication.

Resolved In:
PR NumberSynopsisCategory: Issues related to PKI daemon
1801377
Minor
Crash files are generated every 24 hours due to a pkid process crash
Product-Group=junos
On all Junos OS Evolved platforms, a pkid (Public key infrastructure daemon) process crash is observed every time a periodic auto CDN (Content delivery network) query to download the latest trusted CA bundle takes place (every 24 hours by default)

Resolved In: evo:23.2R2-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.1R1-EVO evo:25.3R1-EVO junos:23.2R2-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1800862
Major
On all dual disk QFX5K platforms having QFX-5e image with secondary (sdb) disk failure, WRITE DMA errors are observed and the device goes unresponsive
Product-Group=junos
Due to a the disk failure reboot support was not added for dual disk scenario, hence system was not booting in case of disk failure on sdb (the other disk) on QFX platform.

Resolved In: junos:22.2R3-S5
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover, 
1848313
Major
OSPF neighbours go down due to link flapping after NSR switchover on Junos OS Evolved platforms with IPSEC configuration
Product-Group=junos
OSPF neighborship goes down after NSR (Nonstop routing) switchover due to link flapping on Junos OS Evolved platforms with Dual RE and IPSEC configuration.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: RPD Interfaces related issues
1761238
Minor
with BGP sharding , observed memory leak in cookie ifx_dist_msg
Product-Group=junos
On Junos Evolved platforms, when a labeled route resolves to a unicast nexthop that doesn't have label encapsulation, then every time the corresponding egress interface is bounced, there is a small memory leak (block size 84 bytes).

Resolved In: evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:23.4R2-S4 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1817450
Minor
Route on backup shard is not resolved under certain conditions
Product-Group=junos
after protocol BGP is deactivated, the resolution tables __raass_ at backup RPD are marked as deleted, and not resurrected post commit sync.

Resolved In: evo:23.4R2-S5-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.4R2-S5 junos:25.2R1
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1808481
Minor
The error message "sysctl kern.corefile not supported" is seen for multiple daemons during daemon initialisation
Product-Group=junos
On all Junos Evolved platforms, while executing "show log messages", error message "sysctl kern.corefile not supported" is seen which is introduced during daemon initialisation.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1819948
Minor
LSP re-optimization issue has been observed
Product-Group=junos
On all Junos and Junos Evolved platforms, the LSP (Label Switched Path) re-optimization issue has been observed. LSP bandwidth change is unsuccessful due to bandwidth unavailable RSVP (Resource Reservation Protocol) PathErr.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D441 junos:20.3X75-D46 junos:21.4R3-S10 junos:22.4R3-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1825835
Major
IPsec traffic loss is observed when SA is stuck in the routing table even when the IPsec tunnel does not exist on the device
Product-Group=junos
On MX platforms with MS-MPC/MS-MIC with IPsec (Internet Protocol Security) configured, IPsec traffic loss will be observed if an SA (Security Association) deletion request is sent by the peer just before the SA installation is completed. The issue happens in the scale scenario (4000 tunnels are configured, and when the SA count reaches up to 3900).

Resolved In: junos:19.1R3-S14 junos:19.2R3-S11 junos:19.3R3-S12 junos:20.2R3-S10 junos:21.2R3-J14 junos:21.2R3-S8-J10 junos:21.2R3-S9-J2 junos:21.4R3-S9 junos:22.4R3-S5
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: MX10K linecard
1865576
Major
Due to race condition the FPC on MX platform crashes
Product-Group=junos
On MX platforms with LC480, LC2101, and LC2103 a crash file is generated, resulting in the ukern rebooting and a complete reboot of the LC.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S6-J8 junos:22.4R3-S7 junos:23.4R2-S4 junos:23.4R2-S4-J3 junos:23.4R2-S5 junos:24.4R2 junos:25.1R1 junos:25.2R1



Modification History

2025-06-05 Update to remove PR1850107 from the known issue section