ON THIS PAGE
Open Issues
Learn about open issues in this release for MX Series routers.
For the most complete and latest information about known Junos OS defects, use the Juniper Networks online Junos Problem Report Search application.
Class of Service (CoS)
-
While Traffic control profile is having only scheduler map associated with it and if its attached to IFL , commit error to be thrown. PR1688790
EVPN
-
On all platforms, MAC-IP route deletion and addition are triggered when re-ARP (Address Resolution Protocol) on MH (Multihoming) device fails in the EVPN-MPLS multihoming scenario resulting in traffic drop. PR1691132
-
On all Junos and Junos OS Evolved platforms with IGMP-snooping (Internet Group Management Protocol) enabled under instance type EVPN (Ethernet Virtual Private Network) with vlan-id=none or unspecified vlan-id there will be a spike in the mcsnoopd process CPU utilization. This will lead to the mcsnoopd process crash and there will be disruptions in the traffic. PR1713508
General Routing
-
AFEB crashing with PTP thread hog on the device. PR1068306
-
When there is an input failure on one of the AC PEMs (low or high) it's incorrectly categorized as a "Mix of AC PEMs". Thus, instead of "PEM input failure" an alarm "Mix of AC PEMs" might be raised.PR1315577
-
"TALUS(number) PCIe(number) DMA RX interrupt received. Queue stuck status 0xeeeeee0" are spurious messages which are triggered in system logs due to queue-back pressure or FPGA drops. PR1465888
-
On WRL8 based VMHost platforms (i.e., ACX6360/PTX10001/MX150/NFX150/NFX250/NFX350), there is no log rotation for resild log and temperature sensor info is incorrectly written into resild log which could result in continuous logs in resild log file. The disk usage might keep increasing due to this issue. The disk usage could be eventually full which could cause system to hang and reboot. PR1480217
-
When there are HW link errors occurred on all 32 links on an FPC 11. Because of these link errors, all FPCs reported destination errors towards FPC 11 and FPC 11 was taken offline with reason "offlined due to unreachable destinations". PR1483529
-
Runt, fragment and jabber counters are not incrementing. PR1492605
-
After backup Routing Engine halt, CB1 goes offline and comes back online; this leads to the backup Routing Engine booting up, and it shows the reboot reason as "0x1:power cycle/failure." This issue is only for the Routing Engine reboot reason, and there is no other functional impact of this. PR1497592
-
In the platform using INH (indirect next hop, such as Unilist) as route next hop type for multiple paths scenario (such as BGP PIC or ECMP), the session fast-reroute might be enabled in Packet Forwarding Engines (PFEs). When the version-id of session-id of INH is above 256, the PFE might not respond to session update, which might cause the session-id permanently to be stuck with the weight of 65535 in PFE. It might lead PFE to have a different view of Unilist against load-balance selectors. Then either the BGP PIC or the ECMP-FRR might not work properly and traffic might be dropped or silently discarded. PR1501817
-
PR1463859 introduces a software defect that causes a 10GE interface to flap continuously when configuring with the WAN-PHY framing with the default "hold-down" timer (0). Once upgrading a router to an affected software release, the interface may flap continuously. This is not applicable to an interface with the default framing - LAN-PHY. PR1508794
-
When launching a guest Virtual Machine (VM) to run a third party application on Junos OS Release 15.1R1 and above, the guest VM might be shown as "UNAVAILABLE" even after successfully installing the third party application. This is due to duplicated device ID assigned to different disks. PR1529596
-
Due to BRCM KBP issue route lookup might fail. Need to upgrade KBP to address this issue, Due to high risk KBP SDK upgrade planned for Junos OS Release 21.1. PR1533513
-
USF-SPC3 : With ipsec PMI/fat-core enabled, "show services sessions utilization" CLI not displaying right CPU utilization. PR1557751
-
The Sync-E to PTP transient simulated by Calnex Paragon Test equipment is not real network scenario. In real network deployment model typically there will be two Sync-E sources (Primary and Secondary) and switchover happens from one source to another source. MPCE7 would pass real network SyncE switchover and associated transient mask. PR1557999
-
VE and CE mesh groups are default mesh groups created for a given Routing instance. On vlan/bridge-domain add, flood tokens and routes are created for both VE and CE mesh-group/flood-group. Ideally, VE mesh-group doesn't require on a CE router where IGMP is enabled on CE interfaces. Trinity based CE boxes have unlimited capacity of tokens, so this would not be a major issue. PR1560588
-
When the active slave interface is deactivated, the PTP lock status is set to 'INITIALIZING' state in 'show ptp lock-status' output for few seconds before BMCA chooses the next best slave interface. This is the day-1 behavior and there is no functional impact. PR1585529
-
Pim Vxlan not working on TD3 chipsets enabling VxLAN flexflow after Junos OS Release 21.3R1. Customers Pim Vxlan or data plane VxLAN can use the version prior to 21.3R1. PR1597276
-
During RE switchover, if there is a burst of ICMP/BFD/SSH/FTP/TELNET/RSVP packets (~18K pps) you might see new backup RE restarting. PR1604299
-
On MX-VC (Virtual Chassis) platforms with MS-MPC or SPC3 service cards and Aggregated Multi-Service (AMS), traffic on the line card in the backup chassis might not be load-balanced properly due to timing conditions. This works well on the line card in the master chassis. There might be traffic loss when interfaces are not properly balanced. PR1605284
-
The output of show network agent command should be null, which shows statistic per component after GRES. PR1610325
-
When user tries to disable AMS IFD using configuration knob, the ipsec tunnels are not deleted. Deactivating the services will provide the desired result. PR1613432
-
On all Junos platforms the MAC address of the 17th ae interface might be changed after the upgrade from 18.4+ to 20.4+ releases. It will lead to mac based service interruption.PR1629050
-
For a topology with VSTP and VRRP configured and IPV6 traffic, if VSTP bridge priority is changed a couple of times (to trigger toggling of root bridge), it is possible that V6 traffic drop is seen on some of the streams. PR1629345
-
The fabric statistics counters are not displayed in the output of "show snmp mib walk ascii jnxFabricMib". PR1634372
-
On all devices running Junos OS or Junos OS Evolved, where this is a high BGP scale with flapping route and the BGP Monitoring Protocol (BMP) collector/station is very slow, the rpd process might crash due to memory pressure. PR1635143
-
The mspmand daemon running on MS-MPC/MS-MIC cards can occasionally crash when the service card (fpc/pic) is turned offline and then online at regular intervals when the number of service-set configured is moderately high and when extensive hardware crypto operations are being performed. Exact issue is yet to be isolated. PR1641107
-
Source MAC should nt be configured on the underlying static interface on the UP for PPPoE login to work correctly. PR1641495
-
vMX: "input fifo errors" drops reported under pfe shell "show ifd" but not seen in "show interface extensive" output. PR1642426
-
bb device has to be manually enabled in configuration for DHCP and PPP access models for BNG CUPS. Configuration to enable bb device is as follows::
user@router #set system subscriber-management mode force-broadband-device
. PR1645075 -
On Junos platform, PTP does not lock when port speed is not configured under PIC hierarchy or port speed for some additional random ports are configured under the PIC hierarchy or perform PIC deactivate/activate. PR1645562
-
Currently User can install images older that the minimum supported image on RE-S-X6-128G-K. System comes up in Linux prompt in such cases.PR1655935
-
Core files reported intermittently where random grpc stack crash is observed. The license service will auto restart and recover. PR1656975
-
On Junos platforms, in the VPLS environment with
routing-options resolution preserve-nexthop-hierarchy
configured results in the packet dropped at egress PE for multiple MPLS stack labels. PR1658406 -
The OpenSSL project has published security advisories for multiple vulnerabilities resolved in OpenSSL. Please Refer to https://kb.juniper.net/JSA70186 for more information.PR1661450
-
Not all MAC addresses are learnt for some VPLS instances after "clear vpls mac-table" command is executed. PR1664694
-
With following configuration changes subscribers are coming up. Configuration changes:
set forwarding-options dhcp-relay overrides allow-snooped-clients set forwarding-options dhcp-relay group DHCP-FO overrides allow-snooped-clients set forwarding-options dhcp-relay group DHCP-FO overrides user-defined-option-82 100.112.77.66 deactivate forwarding-options dhcp-relay group DHCP-FO interface ae31.0 overrides
PR1665499 -
UDP Telemetry might not work when subscribes to /junos/system/linecard/intf-exp/ sensor. PR1666714
-
User should not modify the locator attributes, instead locator, SIDs should be deleted and configured back. Otherwise it will lead to generating core files.PR1667320
-
On MX platforms with MIC-MACSEC-20GE, Forwarding Engine Board (FEB) might go down while activating/deactivating GRES(G?raceful Routing Engine Switchover) configuration.PR1668983
-
Sometimes core files are reported on backup Routing Engine during init after a reboot etc. When the backup Routing Engine initialization is being done and system is busy, some commands executed in context of spmbpfe are taking more time to complete due to the initial heavy lifting by the kernel, In this stage, in case the commands from spmbpfe process do not complete for >2.5 seconds, then there are chances of spmbpfe core files. This is a temporary issue seen on backup Routing Engine during init time only. This might not be impacting because if in case spmbpfe process crashes due to this, it would restart by itself and continue to init and run once the initial high CPU condition has passed. It should not cause any functionality or performance impact; especially since it is reported only on backup RE.PR1675268
-
On LC480 MX line-card with 1G interface 1PPS time error does not meet class B requirement (maximum absolute time error is 70 ns). PR1677471
-
There will be drop of syslog packets seen for RT_FLOW: RT_FLOW_SESSION_CREATE_USF logs until this is fixed. This will not impact the functionality.PR1678453
-
The issue here is that we see ?MQSS(0): DRD: Error: WAN reorder ID timeout error? once per PFE during bootup of FPC. This happens because during the FPC bootup some control packet from vmhost comes before the PFE init is fully complete. Because of this the EA Asic is not able to process the packet and throwing the error. The fix involves complex changes in the bootup sequence of ASICS and will result in other major issues. The original issue has no functionality impact. It is just one error per PFE seen during the FPC reload case only. At that time the traffic is not started yet and once the system is up no other impact is seen due to the Error. Hence the issue will not be fixed. Any "WAN reorder ID timeout error" during the bootup of FPC can be safely ignored. PR1681763
-
When the hostname configuration is changed, the change is not reflected in the RIFT output. Also when changes are made to the REDIS configuration, they are not applied until rift is restarted via "restart rift-proxyd". PR1686233
-
If MVRP is enabled on an MSTP enabled interface, the interface will be made part of all the existing instances on the switch. PR1686596
-
With Sharding enabled, BGP flags like the following are not displayed on Active route in "show route extensive" output:"Accepted Multipath MultipathContrib MultiNexthop" Per shard view, using "show route extensive prefix rib-sharding shard-name" will show these flags.PR1693207
-
It is recommended to use IGP shortcut with strict SPF SIDs in SR-TE path. if Strict SPF SIDs are used then this issue would not occur. This issue will occur only if regular IS-IS SIDs are used in SR-TE path and IGP shortcut is enabled. with this, if customer perform multiple times deactivate/activate for SR-TE telemetry.PR1697880
-
On Junos platforms, Kernel crashes can happen in Virtual Private LAN Service (VPLS) scenario. This issue is seen when the VPLS has IRB (Integrated Routing and Bridging) interface and the next-hop of IRB is RLT (Redundant Logical Tunnel) interface. This issue is triggered when there is an ARP request sent from the IRB interface. There can be a service impact because of this issue as the device can reboot.PR1698781
-
During BGP MP route 9.0.0.2 re-resolution window, a corner case was hit, such that rpd will assert and restart. This error case is observed during Multi-Feature-Test with BGP-MP, L3VPN/L2VPN, over RSVP/LDP transport, as well as colored SRTE, and SRv6 tunnel transport along with BGP CT. This issue will get resolved in next Junos OS 22.4R1 services releases.PR1699773
-
When packets of size bigger than 1518 Bytes are received/transmitted, pps counter value does not show correct value. PR1700309
-
On MX platforms, traffic egressing on the IRB (Integrated Routing and Bridging) interface with the underlying L2 (layer2) access port has VLAN tags imposed incorrectly.PR1700321
-
The optic configuration mismatch alarm was always enabled, but was not reported by the RE during 'show chassis alarms'. This alarm will now be correctly reported by the FPC and displayed in the RE. There is no behavior change other than the alarm being reported correctly now.PR1700606
-
When subscribing to sensor paths "/junos/system/linecard/packet/usage/", "/junos/services/label-switched-path/usage/" or other line card (PFE) sensor paths in gNMI subscription mode, packet drops may be seen in the CLI command "show network-agent statistics gnmi detail" output. The collector output might also contain missing sequence numbers. For example, the sequence number output might be 0, 3, 6, 9, 12, etc. instead of 0, 1, 2, 3, 4, etc. PR1703418
-
The line card abruptly rebooted with a process crash when ISSU (In-Service Software Upgrade) is performed without properly disabling Jflow.PR1703910
-
In Chassisd, Jvision thread takes more time in streaming of jvision packets because of volume of data and number of sensors involved with this daemon. Jvision thread engaged for more time to process streaming events caused Chassisd master thread to lose receive/send keepalive messages to/from other Routing Engine, which eventually was causing automatic Routing Engine switchover in most of the cases. To avoid this, fix done for exporting small payload jvision packets (formation of which takes less time) and deferring jvision thread more in an interval, to allow chassisd master thread to process high-priority hello/keep-alive messages. This means now, more number of packets is sent in one reporting interval and with larger spread (earlier same amount of data was sent with 2 or 3 packets of higher payload size, and 100ms of deferring time for jvision thread. This behaviour is increasing KPI-2 but lowering KPI-1 (payload size). It is not possible to back out changes done to solve keep-alive message loss issue. Hence we will have to keep Chassisd as an exception, when we measure/report KPI-2 values. Jvision in Chassisd has to give more priority/time to process keep-alive messages than sending of jvision packets. Hence delay between jvision packets are more. PR1706300
-
For DHCP access-model and IFL-SETs, when the load-balancing group is not configured with the same port name for each user-plane, during IFL-SET weigh-based load-balancing, the last IFL-SET over the max-weight could be incorrectly placed on both user-planes at the same time. This is because the load-balancing logic takes into account IFL-SET affinity by comparing the IFL-SET names on each UP in the load-balancing group to see if the same IFL-SET is already installed, and if it is installed already, to place the subscriber on an existent IFL-SET. However, the IFL-SET affinity check fails if the IFL-SET name is formed using different port names. This is documented in the Functional Spec of the RLI.So when this issue is seen, the IFL-SET names are different for each UP: UP xda, port up:xda:xe-2/0/0:0 UP xda1, port up:xda1:xe-0/1/0:2 which results in the creation of: IFL-SET: on UP "xda" IFL-SET = xe-2/0/0:0-101 AND on UP "xda1" IFL-SET:= xe-0/1/0:2-101 Then the names are different and the load-balancing logic cannot distinguish between the 2. PR1710447
-
Second IFL macsec interface stats not working. PR1710867
-
On all Junos platforms, Master and Backup Routing-Engine synchronization issues will be seen when chassisd (Chassis process) is restarted. The ksyncd (Kernel Synchronization) process crash will be observed on the backup RE and traffic would be impacted. PR1712352
-
On MX platforms with MPC10/MPC11 line cards, when the Logical Tunnel (LT) interface is configured with family Virtual Private LAN Service (VPLS) and VLAN, unknown unicast traffic on this line card forwards the traffic instead of discarding it. Hence the services configured on the LT interface which will use unicast traffic are affected. PR1713523
-
On Junos MX2010 and MX2020 platforms, when Junos Node Slicing is configured containing a sliced MPC11E line card (sub line card or SLC), a software upgrade or downgrade activity on the Guest Network Functions (GNF) containing the SLC can lead to a crash on the SLC. Traffic through the affected SLC will be impacted as it crashes and fails to come online.PR1715603
-
The fast-lookup-filter is not working on the router's loopback interface with AlfaRomeo line cards in the routers. PR1718893
-
With no-reduced-srh configured, MX304 removes the last SID value from the SRH. Expectation is Last SID should be retained in SRH when "no-reduced-srh" is configured. There is no impact to the traffic. Traffic flow fine, since the "SEGMENT-LIST" and "LAST ENTRY" are encoded properly in the packet. PR1721404
-
In some srv6 scenarios, with no-reduced-srh configured, next header in SRH is not set and packets may be dropped as invalid hop option. PR1721429
-
On the MX10008 platform, the low-priority stream might be marked as a destination error and as a result, the low-priority stream is stuck and all traffic might get dropped. Complete traffic blackhole is observed from one PFE to another. PR1724007
-
Issue: Convert the VNI model in GW from "Global-to-Translated" excluded vlan range from trigger having traffic loss Trigger: Convert the VNI model in GW from "Global-to-Translated" Impact: Experiencing traffic loss in other vlan ranges. PR1725496
-
On MX platforms supporting packet-triggered subscribers and policy control (PTSP) feature, a high percentage of packet triggered subscribers are getting stuck in 'Configured' state due to an authentication failure. PR1726136
-
On Junos MX304 device , Enabling disk smart-check utility on the routing-engine with Innodisk SSD raises a false positive smart error, which is visible in 'show chassis alarms'. PR1726252
-
On Junos EX92xx, MX304 and MX series platforms with MPC10, MPC11 and LC9600, traffic drop will happen with the attachment of family filter configured with percent policer (bandwidth-percent) via input-list/output-list. PR1726733
-
On MPC1/2/3/4/5/6/7/8/9 line cards, route churn (add or deletes) when the ASIC usage crosses a threshold (ASIC usage is high) which leads to a FPC crash. PR1727427
-
On all MX platforms with SPC3 cards and PCP (Port Control Protocol) with DS-Lite (Dual Stack -lite) configured , PCP client should renew the mapping before its expiry time to keep the PCP mapping always active. issue seen if the traffic from outside network (public network) toward B4 (softwire initiator) was suspended for sometime . when traffic started again toward B4 from outside network , it will be dropped and service will be impacted. PR1729801
High Availability (HA) and Resiliency
-
When GRES is performed with the interface em0 (or fxp0) disabled on the primary Routing Engine, then enable the interface on the new backup Routing Engine, it isn't able to access network.PR1372087
Infrastructure
-
A use after free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA70198 for more information. PR1636063
-
Earlier implementation of kvmclock with vDSO (virtual Dynamic Shared Object) which helps avoid the system call overhead for user space applications had problem of time drift, the latest set of changes takes care of initializing the clock after all auxiliary processors are launched so that the clock initialization is accurate. PR1691036
Interfaces and Chassis
-
MediaType value in SNMP/Jvision is not correct at the beginning after the switch comes up only for the DOWN interfaces where copper mediaType is connected till the link is not UP. This value is correct always in CLI output. Below are the recovery ways 1. Bring the link up (Connect the other side) 2. Restart dcd daemon. PR1671706
-
IFL packet counters are not implemented for AMS interface. It is a new change. PR1673337
-
This issue is specific to MX Series Virtual Chassis only and the issue is not seen during manual execution of the test case. The issue is seen only with the test script that too rarely and hence the exact trigger of the issue is not clear. PR1686425
-
On Junos MX platforms, when Virtual Router Redundancy Protocol (VRRP) packets come from the LAG interface with delegate-processing enabled, it should be processed on anchor PFE. If it comes from non-anchor PFE - it goes to anchor PFE through the fabric. In that case, TTL is decremented. If a FW filter on the loopback interface is applied for VRRP with a ttl=255 condition, the VRRP won't work - there will be a service impact. PR1701874
-
In case of evpn routing-instance, there will be an implicit bridge-domain created for VPLS route table. This BD index will be used by daemon DCD in successive commits. When igmp-snooping is enabled, mcsnoopd daemon publishes update on INET route table with BD index value 0, which is mismatching with the DCD. As a result, this might cause to flap ifls which are part of this routing-instance on successive commits. PR1712800
Layer 2 Features
-
In case of the access-side interfaces used as SP-style interfaces, when a new logical interface is added and if there is already a logical interface on the physical interface, there is 20--50 ms traffic drop on the existing logical interface. PR1367488
Layer 2 Ethernet Services
-
If a client sends a DHCP request packet, and option 55 includes PAD option (0), a DHCP ACK will not be sent back to the client. PR1201413
-
In the CBNG (XDA CUPS) environment, DHCPv6 subscribers fail to login over PPP over L2tp Tunneled. This setup has XDA CP and UP for both LAC and LNS. DHCPv6 subscriber is stacked over PPP from the Client side. While the PPP(v4 and v6) session gets established successfully, DHCPv6 subscriber traffic is being dropped at the LNS UP. Though this is the Release notes for 22.4R1 Release, issue is not seen in 23.1 based Dev Common Branch. Adding the release notes for 22.4R1 scope only.PR1683955
MPLS
Network Management and Monitoring
-
When maximum-password-length is configured and user tries to configure password whose length exceeds configured maximum-password-length, error is thrown, along with error 'ok/' tag is also emitted. (Ideally 'ok/' tag should not be emitted in an error scenario.) The configuration does not get committed.PR1585855
-
In some NAPT44 and NAT64 scenarios, Duplicate SESSION_CLOSE Syslog will be seen. PR1614358
Platform and Infrastructure
-
With given multi dimensional scale, if configuration is removed and restored continuously for more than 24 times, MX Trio based FPC might crash and restart. During the reboot, there can be traffic impact if backup paths are not configured. PR1636758
-
On Junos MX platforms with specific line cards, when PFE (Packet Forwarding Engine) is disabled, scenarios like multicast receiver join/leave that result in allocation and de-allocation of memory on disabled PFE can cause a memory leak. This is because memory is allocated on the disabled PFE, but not freed. PR1686068
-
PVSTP protocol packets is getting duplicated when it tunnelled through Layer2 tunnelling protocol. Other protocol data units PDUs ( STP,VTP,CDP ) are not impacted. PR1686331
-
On all Junos platforms, in a rare scenario, GRES (Graceful Routing Engine switchover) may result in LACP (Link Aggregation Control Protocol) on the new master being down which may cause an FPC crash. PR1720591
-
On Junos MX and EX92XX with specific line cards, VLAN rewrites will not happen for traffic egressing from IRB(Integrated Routing and Bridging) interface over an L2 AE (Aggregated Ethernet) IFL (Interface Logical), if the L2 AE IFL is configured to perform VLAN rewrites on the frames. This happens when the IRB is configured as a routing-interface on EVPN (Ethernet Virtual Private LAN) or VXLAN (Virtual Extensible LAN) routing instances and the traffic has to egress on IRB over an L2 AE IFL. As a result, the frames are forwarded with incorrect VLAN tag information. PR1720772
Routing Policy and Firewall Filters
-
Delete single prefix from prefix-list will cause all the prefixes to be deleted.PR1691218
Routing Protocols
-
Errors might be seen on ephemeral commit during unified ISSU.PR1679645
-
BGP LU statistics does not report correct statistics when sharding is enabled. PR1684238
-
Junos OS Release 22.3 onwards, isis yang is uplifted to 1.0.0 version which has major change in existing OC path that was supported earlier. Since OC path has change, same need to reflected in translation script which is not done. As part of D27 release for cloud, translation script will be modified with newer OC path. Till then supported older OC config is broken. eventually D27 code will come back to DCB and things will work fine after that.PR1686751
-
This issue is seen with only evo and not seen Junos. Its seen in a combination of Rsvp and IS-IS. Stats is getting incremented. PR1700063
-
On all Junos and Junos OS Evolved platforms with dual-RE, after back to back graceful routing engine switchover (GRES) is performed, the periodic packet management process (ppmd) crash will be seen.PR1702687
-
Show route advertising-protocol bgp reporting NextHop self rather than IP in the configured policy-statement for next-hop. Behavior change observed after JUNOS upgrade from 18.4 to 20.4. #set policy-options policy-statement set-NH-MX term to-PP-All then next-hop 20.20.20.1 show route advertising-protocol bgp 10.10.10.10 test.inet.0: 5 destinations, 5 routes (5 active, 0 holddown, 0 hidden) Prefix Nexthop MED Lclpref AS path * 10.0.0.0/31 Self 65000 I The CLI output for Nexthop reported Self rather than IP address 20.20.20.1. PR1712527
-
On all Junos and Junos OS Evolved platforms unexpected behavior of bandwidth based metric in IS-IS is seen since actual bandwidth is falling back to 0 bps when one of the member interface of AE (Aggregated Ethernet) bundle (interface-group) goes down. PR1718734
-
On all Junos and Junos Evolved platforms with PIM (Protocol Independent Multicast), MVPN (Multicast Virtual Private Network) configured and when the number of downstream interfaces is more than three thousand, slow convergence of PIM joins is seen to take up more of the time and CPU, causing traffic loss for some time. PR1720708
Services Applications
-
When a configured tunnel interface is changed to another one, flow-tap-lite functionality stops working that is, packets don't get mirrored to content destination. But, this problem isn't consistently seen.PR1660588
Subscriber Access Management
-
On MX platforms in a scaled subscriber scenario the session database and IP pool database can get out of sync on the backup RE if there is subscriber churn. After RE switchover this condition will lead to immediate termination of new subscriber sessions if the assigned IP address is still in use by existing subscriber. PR1723183
VPNs
-
When using Group VPN, in certain cases, the PUSH ACK message from the group member to the group key server might be lost. The group member can still send rekey requests for the TEK SAs before the hard lifetime expiry. Only if the key server sends any new PUSH messages to the group members, those updates would not be received by the group member since the key server would have removed the member from registered members list. PR1608290
-
This happens only when MVPN protocol has separate route targets configured and then both the address families are disabled. rpd (Routing process daemon) infra parsing does not check if MVPN protocol is disabled and hence will create the auto policies for route-targets if configured. So if those policies are not marked as active in MVPN configuration flow, it does not get resolved and thereby the policy object might not be valid thus leading to the core files.PR1700345