Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Resolved Issues: 21.3R2

Application Layer Gateways (ALGs)

  • On MX Series routers, the flowd daemon will crash if the SIP ALG is enabled and specific SIP messages are processed (CVE-2022-22175). PR1604123

  • Junos OS: Flowd core file is generated if the SIP ALG is enabled and a specific session initiation protocol (SIP) packet is received (CVE-2022-22178). PR1615438

Class of Service (CoS)

  • Transit packets from local to remote VTEP might get punted to CPU and cause DDoS events. PR1489233

  • In a Junos Fusion deployment, dynamically removing and adding a logical interface under interface-set might lead to traffic control profile on the interface-set not working. PR1593058

  • The fabric queues priority might not get changed after activating or deactivating CoS configuration. PR1613541

EVPN

  • Baseline EVPN-VXLAN transition from IPv4 to IPv6 or vice verse does not work in certain sequence. PR1552498

  • The BUM traffic might be dropped after changing any configuration on the device without router-id configured. PR1576943

  • Bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance. PR1600310

  • Missing MAC address entries in EVPN mac-table despite the presence of the corresponding Type 2 route. PR1611618

  • Few ARP/ND/MAC entries for VLANs are missing with MAC-VRF configuration. PR1609322

  • The l2ald crash might be seen after performing restart routing on EVPN PE. PR1629426

  • Removing the configuration statement es-label-oldstyle might not be committed if it is the only statement configured under the EVPN protocol. PR1629953

  • The traffic loss might be seen when the link goes down for the local ESI. PR1632723

Flow-based and Packet-based Processing

  • Bad file descriptor is observed when descriptive clear services inline-monitoring statistics statement is performed. PR1624094

Forwarding and Sampling

  • More than 5 minutes delay in getting the response for the clear interfaces statistics all command with RIB scale configuration. PR1605544

  • Commit is allowed even if firewall filter is not applied to the FPC. PR1618231

  • The FPC might crash when an interface participating in "next-interface" filter action flap. PR1622585

  • BFD session on a few aggregated Ethernet stuck in init/down with slice 2 connections in GNF. PR1625309

General Routing

  • DHCP subscribers might not be synchronized to backup BNG when DHCP ALQ is configured without topology-discover. PR1620544

  • On MX10003, despite of having all AC low or high PEM, Mix of AC PEMs alarm is raised. PR1315577

  • Error message sensord: Error updating RRD file: /var/run/sensord.rrd might be seen on WRL9-based line card. PR1420927

  • The following error messages are observed unable to set line-side lane config (err 30). PR1492162

  • During flooding, MAC is learnt only on normal access port but not on the aggregated Ethernet interface trunk port. PR1506403

  • Next-hops are not programmed correctly after Virtual Chassis global switchover. PR1518467

  • Junos OS 'et-' interface get stuck and remains down between two particular ports. PR1535078

  • Some transmitting packets might get dropped because the "disable-pfe" action is not invoked when the fabric self-ping failure is detected. PR1558899

  • Na-grpcd process might generate a core file during longevity tests. PR1565255

  • When using log templates (introduced in Junos OS Release 21.1R1) with unified policies, logs were not generated in a predictable manner. A new construct has been added that allows you to define a default log profile set security log profile name default-profile, that can be used to improve this behaviour when multiple log profiles are defined. PR1570105

  • Interfaces might fail to come up on MX240, MX480 and MX960 platforms PR1571274

  • pkid core file is generated at #0 0x08456bb3 in je_bitmap_set (bitmap=0x8c7c00c, binfo= optimized out, bit= optimized out) at ../../../../../../../../src/external/bsd/jemalloc/dist/include/jemalloc/internal/bitmap.h:101. PR1573892

  • CHASSISD_FRU_IPC_WRITE_ERROR: fru_send_msg: FRU GNF 2, errno 40, Message too long might appear periodically in the chassisd logs. PR1576173

  • MIC specific alarms are not cleared after MIC reboot. PR1576370

  • MPC7E, MPC10E, MX-SPC3 and LC2103 line cards might become offline when the device is running on FIPS mode. PR1576577

  • The subscribers over PS interface are not cleared after FPC offline. PR1580812

  • The deleted loopback route prefix might exist under subscriber management when the loopback IP is deleted and added in a single commit. PR1582263

  • The line cards might fail after hitting the I2C error on MX Series router FPC. PR1583060

  • A high rate of small packets might cause CPU hogging and firmware crash in MPC5E and MPC6E cards. PR1587551

  • PEM capacity shows incorrectly on MX10003 platform. PR1587694

  • Fabric link training might be seen if fabric self ping silently drop or get descarded. PR1590054

  • Some logical interfaces might go down under logical tunnel because of the limited number of MAC addresses in a pool. PR1591853

  • The DCI interVNI and intraVNI traffic might silently drop or get descarded in gateway node due to the tagged underlay interfaces. PR1596462

  • Mcscnoopd might crash during deleting and then adding layer-2 forwarding configuration after performing a unified ISSU. PR1596483

  • The l2ald process might crash due to memory leak when all active interfaces in a VLAN are unstable. PR1599094

  • Traffic might be silently dropped and discarded upon link flap after a topology change. PR1599215

  • NSR switchover performed with BGP SR-TE tunnels might generate an rpd core file. PR1599446

  • High FPC CPU utilization might be intermittently observed after receiving a great number of NS/NA message. PR1600318

  • gNMI telemetry might stop working after the Routing Engine switchover. PR1600412

  • Traffic might be dropped at NAT gateway if EIM is enabled. PR1601890

  • Kernel crash might be seen when static routes are configured with GRE interfaces being used as next hop. PR1601996

  • Some EVPN mac-ip entries might get stuck and do not age-out. PR1602010

  • In a rare case, the l2ald core file is seen when EVPN (mac-vrf) uses IPv4 underlay. PR1602244

  • Junos OS: Specific packets over VXLAN cause FPC memory leak and ultimately reset (CVE-2022-22170). PR1602407

  • IPv6 link local BFD session might not come up if you do not have a child link of an aggregated Ethernet mapped to Packet Forwarding Engine inst 0. PR1602493

  • Jflow-syslog for CGNAT might use 0x0000 in IPv4 identification field for all fragments. PR1602528

  • The statement show system errors fru detail does not display reset-pfe as the cmerror configured action. PR1602726

  • When using J-Web with HTTP an attacker might retrieve encryption keys via person-in-the-middle attacks (CVE-2021-31386). PR1603199

  • Packet loss might be seen on filter-based GRE deployments. PR1603453

  • Traffic loss might be seen on the device because of the continuous errors observed in the Fabric Healing process (FHP) phase-1. PR1603499

  • 21.3TOT:TCP_TLS_SYSLOG:core-usf-qnc-a-fpc3.pic1-flowd_spc3.elf.0.tgz is seeing while verifying TCP-based logging functionality with GRES with AMS-nexthop style. PR1603466

  • NSSU performed with MACsec configuration might result in fxpc core file. PR1603602

  • VRRP and BFD might flap on the IRB interface on MPC10 and MPC11 line cards. PR1604150

  • NPC logs are seen when VRF localisation is enabled. PR1604304

  • GRE tunnel might flap when hierarchical-scheduling is configured. PR1605189

  • The interface on MCP3-NG HQoS or MPC7E flaps continuously after enabling LACP on aggregated Ethernet interface. PR1605446

  • VM host platforms might boot exactly 30 minutes after executing request vmhost halt command. PR1605971

  • 5G-CUPS:bbe-cups-5G-setup:wf-eabu-dev.tadcaster:re1 {version} vmcore.0.gz. PR1606146

  • Fabric error might be seen when MPC10E to MPC2, MPC3, MPC4, MPC5, and MPC6 based FPC fabric traffic is congested. PR1606296

  • Observing continuous SNMP trap for "Over Temperature!" for all the Renault_Daniel line cards (FPC: JNP10K-LC480). PR1606555

  • Random IP assignment might be done on MX Series routers configured with PCP and DS-Lite. PR1606687

  • New subscribers might not connect due to the CR-features service object missing on FPC. PR1607056

  • IPv6 link-local BFD session might not come up on MX Series routers. PR1607077

  • TCP traffic might be dropped on source port range 512 to 767 when the FlowSpec IPv6 filter is configured. PR1607185

  • Commit related to dynamic profile configuration changes might fail upon executing request vmhost reboot routing-engine both on MX Seris routers. PR1607494

  • The speed auto-negotiated SFP-T transceiver might not be joined to the aggregated Ethernet after performing dcd restart or Routing Engine switchover on MX104. PR1607734

  • MPC10 and MPC11 filters matching unknown-unicast does not take effect. PR1608723

  • The FPC might crash when the option sensor-based-stats is configured. PR1608871

  • BFD over GRE tunnel interface stuck in "init" state with GRES enabled. PR1609630

  • DHCP subscribers over PWHT might be dropped upon GRES after the system reboot. PR1609818

  • The single-vlan tagged subscribers might fail to reconnect through dynamic-vlan over PS interface. PR1609844

  • Interface flaps might be observed on certain ports. PR1609988

  • The authd process and RADIUS might have stale L2BSA subscriber entries PR1610476

  • Traffic loss might be observed if dot1X is configured with supplicant multiple and authenticated user from RADIUS is in single supplicant mode. PR1610746

  • MACsec session might be dropped because of one way congestion. PR1611091

  • Erratic behaviour might be seen on the platforms using MPC line cards after unified ISSU is performed. PR1611165

  • Inter-vlan connectivity might be lost in an EVPN-VXLAN with CRB topology. PR1611488

  • The service PICs are unable to come up when dnsf package is configured. PR1612316

  • The routing protocol engine CPU is getting stuck at 100 percent. PR1612387

  • The B4 client traffic will be dropped on MX-SPC3 based AFTR in DS-Lite with EIM activated CGNAT scenario. PR1612555

  • Some of the fabric links might go into faulty state after swapping FPC LC1201 with LC1202. PR1612624

  • l2ald core file is generated during routing-instance configuration change. PR1612738

  • The PFE/SIB/SCBE/FPCs might reboot due to the unexpected fabric errors shown on MX240, MX480, and MX960 platforms. PR1612957

  • Memory might be exhausted when both BGP rib-sharding and the BGP Optimal Route Reflection (ORR) is enabled. PR1613104

  • Traffic loss might be observed because of the shaping rate being incorrectly adjusted in a subscriber environment on MX Series routers. PR1613126

  • Enhanced-hash-key might not take effect when configured with forwarding-options. PR1613142

  • IGP routing updates might be delayed to program in Packet Forwarding Engine after interface flaps in a scaled BGP routes environment. PR1613160

  • Enabling security-metadata-streaming DNS policy might cause a dataplane memory leak. PR1613489

  • The rpd process might crash in BGP rib-sharding scenario. PR1613723

  • Any irrelevant configuration changes might trigger NAT routes flap on MX Series routers in USF mode. PR1614688

  • Modifying the input service-filter via COA might fail in subscriber management environment. PR1614903

  • Line-cards might be unstable because of the continuous growing memory usage of evo-cda-bt app. PR1614952

  • Export memory and temperature metrics for all existing components when it subscribes to telemetry sensor. PR1615045

  • The l2ald process might crash in an EVPN scenario. PR1615269

  • Traffic drop may occur when huge number of EIM mappings are created or deleted continuously. PR1615332

  • Request to provide an API which lists the potential policy given in a session id. PR1615355

  • The rasdaemon processes memory leak triggered by hardware memory errors on the VMHost platforms. PR1615488

  • Slow memory leak (32 bytes each time) of rpd might be seen. PR1616065

  • show subscribers accounting-statistics, show services l2tp session interface asi0.xx statistics might not work on LNS with ASI interfaces. PR1616454

  • The dual Routing Engine system might not be GRES ready after backup Routing Engine reboot in a subscriber management environment. PR1616611

  • L2 cpd memory leak might lead l2cpd process to crash. PR1617151

  • In MX Series VC spcd running on SPC3 crashes. PR1617280

  • MPC8E in 1.6T bandwidth mode might not work correctly. PR1617469

  • The l2cpd core file is seen with FIP snooping configuration on any interface. PR1617632

  • Traceroute packets might get dropped in SFW service-set when other service-sets with asymmetric traffic processing are also enabled on the same MS-MIC/MS-MPC. PR1617830

  • GMC clock class is seen transmitted for an additional 16 seconds after the PTP source switches from one line card to another. PR1618344

  • The traffic loss might be seen after cleaning the large-scaled NAT sessions in MS-SPC3 based Next-Gen services inter-chassis stateful high availability scenario. PR1618360

  • A device which is configured IP interface(ip-x/x/x) cannot send encapsulated IPv4-over-IPv6 packets to a remote device in case of transit packets. PR1618391

  • The clksyncd might crash and PTP/SyncE might not work. PR1618929

  • Support whole (atomic) updates at CNHG level. PR1619011

  • The nsd might crash while validating NAT translation on MX Series routers with SPC3. PR1619216

  • Traffic might be dropped when RSVP is configured with mtu-signaling. PR1619510

  • Additional commit warnings and errors were introduced to improve security log profile usability. PR1619694

  • The bbe subscriber access services might get stuck during rebooting the one redundancy line-card of the RLT. PR1620227

  • Observed output drop packet while verifying services PCEF subscribers. PR1620421

  • OAM CFM session does not come up if ERPS configured and CFM control traffic uses the same VLAN as ERPS control traffic. PR1620536

  • High wired memory utilization might be observed if GRES is enabled. PR1620599

  • EVPN type 5 routes might not be installed. PR1620808

  • Static-subscribers session might get stuck in initializing state after ungraceful Routing Engine switchover. PR1620827

  • CoS hierarchy for logical interface missed in backup leg after rebooting FPC when we have subscriber logical interface targeting over IFLSET non-targeting. PR1621164

  • Flapping of all ports in the same Packet Forwarding Engine might cause Packet Forwarding Engine to be disabled. PR1621286

  • Commit failure while applying tunnel interface configurations using openconfig CLI. PR1621369

  • Traffic loss is seen on the new primary Routing Engine post GRES. PR1621696

  • When PHY-Sync state moved to 'False' it internally disables the PHY-timestamping of PTP packets. PR1622108

  • Invocation of netconf get command will fail if there are no L2 interfaces in the system. PR1622496

  • Port speed might show as 100G even though chassis configuration is set for 40G manually. PR1623237

  • The chassisd memory leak might be seen after adding or removing an interface configuration. PR1623273

  • The aggregated Ethernet member link might not be correctly populated on the Packet Forwarding Engine after FPC restart on MX Series platforms. PR1624772

  • On single IPSec tunnel with PMI sending an internet traffic packet processing might get delayed due to session management issue. PR1624974

  • Junos OS: Specific packets over VXLAN might reset FPC(CVE-2022-22171). PR1625292

  • The bbe-statsd crash might be seen in the LTS subscriber scenario. PR1625648

  • gNMI set RPC might fail when multiple values within a single gNMI SetRequest are used for the Junos telemetry interface. PR1625806

  • Packet loops in the PIC even after stopping the traffic on MX Series routers with SPC3 line card. PR1625888

  • The bbe-smgd might crash on the backup Routing Engine after unified ISSU or GRES. PR1626091

  • Some interfaces might not come online after linecard reboots. PR1626130

  • Implement show task scheduler-slip-history to display no of scheduler slips and last 64 slip details. PR1626148

  • The chassisd might crash on MX104. PR1626486

  • The autoconf might not work if the DHCPv4 discover message has an option-80 (rapid commit) ahead of option-82. PR1626558

  • Memory leak might occur in the pfed process when the statement flat-file-profile is configured with the use-fc-ingress-stats statement. PR1628139

  • EAPol packets over l2circuit may get dropped at the tunnel start. PR1628196

  • Broadcast traffic might not be forwarded to LT interface in VPLS routing instance after LT interface is deleted then added back. PR1626714

  • The line card might crash and reload if the EVPN MAC entry is not deleted correctly. PR1627617

  • show system subscriber-management route summary does not report route summary as expected. PR1629450

  • The l2ald might be stuck in "issu state" when ISSU is aborted PR1629678

  • Multiple link flaps and traffic might be lost on the links. PR1630006

  • The kmd daemon might crash with core file every few minutes on the MX Series routers. PR1630070

  • LLDP packets might be sent with incorrect source MAC for RETH/LAG child members. PR1630886

  • The kmd might crash since the pkid requested memory leak happens on MX Series platforms. PR1631443

  • RPD core file is generated on RE1 krt_inh.c,krt_nexthop.c,krt_remnant.c. PR1631871

  • When deleting the VNI and there is another vlan-id-list with a different VNI might cause traffic loss. PR1632444

  • The bbe-smgd process might crash after removing and adding a child link from aggregated Ethernet interface. PR1633392

  • Slow chassis memory leak may occur when chassisd related configuration change is committed. PR1634164

  • PTP clock class is incorrectly downgraded to 248 when PTP is enabled on MIC linecard which does not support phy-timestamping. PR1634569

  • Data might not be exchanged via EVPN-VxLAN domain. PR1635347

  • SFP-1FE-FX might not function properly on MIC-MACSEC-20G. PR1636322

  • Delay might be observed for the interfaces to come up after reboot/transceiver replacement. PR1638045

  • When all configured anchor Packet Forwarding Engines are offline on the SAEGW-u, there might be a peer association mis-match between the SAEGW-u and SAEGW-c. PR1634966

  • CFM CCM PDU is not forwarded transparently on generating a core file if the physical interface is configured under OAM protocol. PR1635293

  • Locally switched traffic might be dropped on MX10003 with ESI configured. PR1638386

High Availability (HA) and Resiliency

  • Memory leaking might occur on the backup Routing Engine when ksyncd is in inconsistent state and has encountered an initialization error. PR1601960

  • When MTU is configured on an interface a rare ifstate timing issue occurs at a later point resulting in ksyncd process crash on backup Routing Engine. PR1606779

Infrastructure

  • The fxpc process might crash and generate a core file. PR1611480

Interfaces and Chassis

  • The dcd process crash might be observed after removing the aggregated Ethernet logical interface from the targeted distribution database. PR1591032

  • lo0 family maximum labels is non-adjustable in syslog messages. PR1611098

  • Commit check failure might occur if similar interfaces are configured under VRRP group. PR1617020

  • Delay in application of CLI configuration by DCD when an aggregated Ethernet interface members are configured via JET API. PR1621482

  • CFM enhanced SLA iterators monitoring might stop after restarting chassis-control daemon in vMX. PR1622081

  • The subscribers might be deleted when "host-prefix-only" statement is configured on the underlying-interface in GRES scenario. PR1630229

  • The syslog messages and the dcd crash might be seen in Junos OS. PR1633339

  • VRRP route tracking for routes in VRF might not work if "chained-composite-next-hop ingress l3vpn" is used. PR1635351

  • Some daemons might get stuck when snmpd is at 100 percent CPU utilization. PR1636093

  • FPC might crash if the continuity-check interval under CFM is modified. PR1636226

  • On Junos OS Release 20.3 and later, the tracking routes of VRRP might become unknown after upgradation. PR1639242

Layer 2 Ethernet Services

  • Making configuration changes with apply-group add/delete associated with DHCP may result in client connection failure. PR1550628

  • The jdhcpd process might crash under certain conditions. PR1603992

  • DHCP leasequery is failing to restore binding when the reply is received over IRB interface. PR1611111

  • Enabling DHCP on Junos OS platforms might cause the router's file system storage to get filled up with log files. PR1617695

  • The jdhcpd crashes upon receiving a specific DHCP packet (CVE-2022-22179). PR1618977

  • Circuit-id handled incorrectly with backup node for ALQ with topology discover configured. PR1620461

  • The jdhcpd process crashes in DHCP/DHCPv6 environment. PR1625011

  • The jdhcpd process may stuck at 100 percent post clients login/logout. PR1625112

  • Option-82 might not be attached on DHCP request packets. PR1625604

  • The rpd scheduler might continuously slip after GRES when there are 7000 DHCP clients in a subscriber management environment. PR1625617

  • Non-DHCPv4 BOOTP protocol packets might not be processed if enhanced subscriber management is enabled. PR1629172

MPLS

  • D-CSPF node segment label: unresolved when node index 0 is configured. PR1564169

  • Post GRES, LDP P2MP traffic might be interrupted. PR1609559

  • RPD might crash on standby_re LDP module when VPLS mac-flush enabled on peer by default or configuration. PR1610638

  • LDP does not support policy import with rib-groups. PR1611081

  • The rpd process might crash if express segments using SR-TE underlay are configured. PR1613372

  • The rpd core file might be generated for few value configurations of signaling bandwidth on container LSP. PR1614248

  • Protected LSP goes down with strict hops and link protection configured. PR1616841

  • LDP protections paths might not be established when auto-targeted-session statement is deactivated and activated. PR1620262

  • VCCV BFD session keeps flapping between MX Series and peer device if ultimate-hop popping is enabled. PR1634632

  • The rpd memory leak may be observed in a subscriber management environment with RSVP. PR1637645

  • Dynamic bypass LSP might flap at every re-optimization interval. PR1639292

Multicast

  • Intermittent p2mp traffic drop might be seen in MVPN scenario PR1608311

Network Management and Monitoring

  • Ephemeral instance configuration not removed even after deleting the ephemeral instance from set system configuration-database. PR1553469

  • Master-eventd process might go down when syslog configuration is misconfigured. PR1611885

  • Syslog messages may be lost partially in case of lots of messages generated to eventd. PR1612535

  • After receiving a specific number of crafted packets snmpd will segmentation fault (SIGSEGV) requiring a manual restart (CVE-2022-22177). PR1613874

Platform and Infrastructure

  • The subscribers might not come online after interface flaps on MX Series platforms. PR1591905

  • "XMCHIP_CMERROR_PT_INT_REG_PCT_PAR_ERR (0x70296)" might be observed on MPC5 card which triggers Packet Forwarding Engine disable. PR1597953

  • Traffic through one SPU may stop with potential packet drop issue with alarm as FPC Major Errors raised due to the PIC_CMERROR_TALUS_PKT_LOSS error. PR1600216

  • On MX Series routers, mbuf corrupts resulting in generating a vmcore file on both the Routing Engines. PR1602442

  • The FPC might crash if flow-table-size is configured on MX Series routers. PR1606731

  • Multicast traffic is dropped when forwarded over VPLS via IRB. PR1607311

  • FPC crash might be seen due to mac-move between two interfaces under same bridge domain. PR1607767

  • Degraded traffic processing performance might be observed in case of processing high PPS rate traffic. PR1619111

  • CoS custom classifier might not work on the logical interface. PR1619630

  • MX Series-based line cards might crash when PFE memory is hot-banking. PR1626041

  • Unrealistic service accounting statistics might be reported due to firewall counter corruption. PR1627908

  • Error message "gencfg_cfg_msg_gen_handler drop" is seen after running commit command. PR1629647

  • The packet drop might be seen on FPC on MX Series-based platforms. PR1631313

  • Committing authentication-key-chains statement under groups might fail. PR1626400

  • Continuous fabric link sanity check interrupts in intervals of weeks might cause at some point fabric input block traffic getting dropped or discarded. PR1636060

Routing Policy and Firewall Filters

  • The interface-routes rib-group policy does not work as expected in the VxLAN scenario. PR1537306

  • Evaluation of inet-vpn route-filters might not work with /32 exact statements for BGP flowspec routes. PR1618726

Routing Protocols

  • New version of OpenSSL (1.1.1) is not supported for NTF-agent of Junos telemetry interface. PR1597714

  • Observing commit error while configuring "routing-options rib inet6.0 static" on all Junos OS platforms. PR1599273

  • The rpd core file might be observed due to memory corruption. PR1599751

  • Kernel crash might be observed on platforms having BGP configured with family L2VPN. PR1600599

  • rpd crash might be seen after deactivating and then activating the interfaces PR1605620

  • The BGP replication might be stuck in "InProgress" state. PR1606420

  • Multicast traffic might be duplicated on subscriber interface on MX Series routers. PR1607493

  • The rpd crash might be seen with telemetry used setup. PR1607667

  • microloop-avoidance post-convergence-path might not work without source-packet-routing. PR1608992

  • The rpd might crash after a commit if there are more than one address in the same address ranges configured under 'bgp allow'. PR1611070

  • The interface might receive multicast traffic from a multicast group which it is not interested in. PR1612279

  • The rpd crash might be seen on all Junos OS platforms PR1613384

  • Undesired protection path may get selected for some destination prefixes PR1614683

  • The memory leak on rpd might be observed after running "show route" CLI command. PR1615162

  • BFD sessions flapping may occur after performing GRES. PR1615503

  • The wrong BGP path may get selected even when a better/preferred route is available. PR1616595

  • Traffic drop will be seen when VPN labels are incorrectly allocated due to change in nexthop. PR1617691

  • Verification of BGP peer count fails after deleting BGP neighbors. PR1618103

  • Junos OS: OpenSSL Security Advisory [24 Aug 2021.] PR1618985

  • The rpd might crash and restart when NSR is enabled. PR1620463

  • Time delay to export prefixes to BGP neighbors might occur post applying peer-specific BGP export policies. PR1626367

  • Multipath route with List-NH which has Indirect-NH as members fails into BGP-LU. PR1626756

  • The contributing routes might not be advertised properly if "from aggregate-contributor" is used. PR1629437

  • The multicast forwarding cache might not get updated after deactivating the scope-policy configuration. PR1630144

  • The BGP ECMP might not work and multipath route wont be created. PR1630220

  • The rpd might crash after clearing isis database. PR1631738

  • The BGP session might flap after rpd crash with switchover-on-routing-crash and NSR enabled in a highly scaled environment. PR1632132

  • IS-IS database may not be synchronized in some multiple areas scenario. PR1633858

  • Multipath route getting formed for a VPN prefix due to incorrect BGP route selection logic. PR1635009

Services Applications

  • L2TP tunnels might go down and not able to re-establish after restarting the bbe-smgd process. PR1629104

  • Tunneled subscribers may be stuck in terminating state in L2TP subscriber scenario. PR1630150

Subscriber Access Management

  • Install discard routes is not supported on APM managed BNGs running Junos OS Release 21.3R1. PR1604967

  • Prefix duplication errors might occur for DHCPv6 over PPPoE subscribers. PR1609403

  • DHCP session fails with the configuration statement session-limit-per-username. PR1612196

  • Class attribute is corrupted for RADIUS accounting messages since ISSU to Junos OS Release 19.1 or later on MX Series platforms. PR1624066

  • RADIUS Change of Authorization ( CoA) NAK might not be sent with the configured source address in a virtual-router environment. PR1625858

  • BNG does not correctly issue the statement alarm to APM when condition is met. PR1626632

  • ESSM sessions may get terminated in Radius as class attribute has got corrupted after performing ISSU. PR1626718

  • When connectivity between BNG and APM is lost, the BNG does not regenerate pool drained alarms to APM. PR1627974

User Interface and Configuration

  • A low privileged user can elevate their privileges to the ones of the highest privileged j-web user logged in. PR1593200

  • Junos OS upgrade might fail with error configuration database size limit exceeded. PR1626721

VPNs

  • The multicast route is not getting installed after exporting the secondary routes from one instance to another. PR1562056

  • Wrong st0 IFL deletion at spoke when multiple VPNs negotiate same destination address as TS. PR1601047

  • Authentication might fail on bringing up IPsec tunnel when ECDSA is configured in the security ike. PR1605275

  • The rpd process might crash during ISSU if the auto-sensing knob is enabled for l2circuit. PR1626219