Known Issues
This section lists the known issues in hardware and software in Junos OS Release 17.2R2 for the EX Series.
For the most complete and latest information about known Junos OS defects, use the Juniper Networks online Junos Problem Report Search application.
Authentication, Authorization, and Accounting (AAA) (RADIUS)
On EX4200 Virtual Chassis, if dhcp-relay under forwarding-options helpers is configured along with bpdu-block and an interface configured with bpdu-block receives a BPDU and the interface is disabled and reenabled, a memory allocation issue might be seen that can lead to a memory exhaustion issue for DHCP relay. PR1259918
General Routing
On EX4300 switches, when 802.1X single-supplicant authentication is initiated, multiple "EAP Request Id Frame Sent" packets might be sent. PR1163966
On an EX9200 switch with MC-LAG, when the enhanced-convergence statement is enabled, and when the kernel sends a next-hop message to the Packet Forwarding Engine, the full Layer 2 header is not sent and a packet might be generated with an invalid source MAC address for some VLANs. PR1223662
On EX4500 and EX4550 switches that have two routing instances configured with the same IP address, after you commit the configuration, you will get an IP conflict in configuration and the commit will fail. PR1256904
High Availability (HA) and Resiliency
During a nonstop software upgrade (NSSU) on an EX4300 Virtual Chassis, a traffic loop or loss might occur if the Junos OS software version that you are upgrading and the Junos OS software version that you are upgrading to use different internal message formats. PR1123764
On an EX4300 Virtual Chassis or a QFX5100 Virtual Chassis, when you perform an NSSU, there might be more than 5 seconds of traffic loss for multicast traffic. PR1125155
In a rare scenario, GRES might not reach the ready state and might fail to start, because the Routing Engine does not receive the state ACK message from the Packet Forwarding Engine after performing GRES. This is a timing issue. It might also stop Routing Engine resource release, resulting in resource exhaustion. As a workaround, reboot the system if this problem occurs. PR1236882
Interfaces and Chassis
On an EX9200-40XS line card, if you toggle the MACsec encryption option multiple times, encryption and protected MACsec statistics might be updated incorrectly. As a workaround, restart the line card. PR1185659
Junos Fusion Enterprise
On a Junos Fusion Enterprise, Link Layer Discovery Protocol-Media Endpoint Discovery (LLDP-MED) fast start does not work. PR1171899
Issue is specific to Junos Fusion Enterprise setup. Dot1x authenticated clients under dynamic VLAN might see traffic loss if l2ald gets restarted for some reason (crash/manually). PR1281824
In a Junos Fusion set up with dual access device on EX9200, the dot1x authentication might fail if frequent MAC moves occur. PR1299532
Layer 2 Features
The eswd process might crash after doing Routing Engine switchover in an EX Series Virtual Chassis scenario. The crash happens due to disordered processing of VLAN/vmember by eswd and L2PT modules. Because the order of processing does not remain the same every time, the crash is random across switchovers. PR1275468
Platform and Infrastructure
On EX4600 switches, the amount of time that it takes for Zero Touch Provisioning to complete might be lengthy because TFTP might take a long time to fetch required data. PR980530
On EX4300, EX4600, and QFX5100 switches, if a remote analyzer has an output IP address that is reachable through a route learned by BGP, the analyzer might be in a DOWN state. PR1007963
On EX4300 switches with power redundancy N+N mode, PoE interfaces flap when any side power supply unit is removed, leaving only one power supply unit. PR1258107
Some features of IPv6 router advertisement guard, in particular the MAC prefix, do not work as expected on the EX4300 switch. Also, traffic is seen egressing the chassis despite an RA block being enabled on an incoming interface. PR1294260
User Interface and Configuration
On EX4300 switches, J-Web allows configuration and commit of the source-address-filter command. This is not the expected behavior. PR1281290
Virtual Chassis
When a line-card role FPC is removed and rejoined to a Virtual Chassis immediately, the LAG interface on the master or backup Routing Engine is not reprogrammed in the rejoined FPC. PR1255302
On an EX4550 switch in a Virtual Chassis configuration, fast-failover function for VCP will work properly when you initially add this configuration. However, if the device is rebooted, the function will not take effect the next time. PR1267633