Juniper
106 incident problems in Juniper environments.
Read first
When DNS changed but some clients still hit the old backendAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the DNS record is updated but resolver cache, HTTP/2 keepalive, or client pools hold on to the old target.Network3 min readWhen firewalld looks open but connections keep getting blockedAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when a port rule appears to exist but the connection fails because of zone, runtime/permanent drift, source binding, or an upstream firewall.Network3 min readHow to separate timeout and connection refused by network pathAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when DNS, route, firewall, proxy, and listener states all look like the same connection failure.Network3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
All problems (106)
NETWORK-107DHCP relay uses the correct helper address but the source interface belongs to the wrong VRF so replies never returnDiscover messages leave the switch, yet offers vanish because the server replies into a routing context that has no path back to the client segment.NetworkIntermediate17 minFreeNETWORK-079OSPF virtual link stays downArea IDs still look familiar, but the virtual link cannot form because the transit area assumptions were broken during a partial topology cleanup.NetworkIntermediate17 minFreeNETWORK-080MAC flapping alarms appearThe network is stable, but one mobile workload triggers MAC move alarms and intermittent forwarding loss because the switching design assumes slower host movement.NetworkIntermediate18 minFreeNETWORK-054VRRP stays on the backup routerFailover worked during the incident, but the original priority path never resumes because preemption policy no longer matches the intended steady state.NetworkIntermediate18 minFreeNETWORK-019After a BGP route change, only certain ASNs take a detour pathA network operations problem where the global route is alive but only certain carrier networks get an inefficient detour.NetworkAdvanced30 minProNETWORK-1287A BFD-assisted routing failover flaps repeatedlyFast failover becomes unstable after a QoS change even though throughput tests show the path is otherwise healthy.NetworkAdvanced17 minProNETWORK-1271A BGP session stays Established but traffic preference changesA provider-facing BGP session remains healthy while traffic suddenly shifts to another path after an upstream policy change.NetworkAdvanced17 minProNETWORK-1258An IS-IS adjacency never formsA backbone link carries traffic normally but IS-IS adjacencies never come up across it.NetworkAdvanced17 minProNETWORK-1278A BGP keepalive path is stable but larger updates failA peering looks healthy until one change introduces larger update sets and route learning becomes inconsistent.NetworkAdvanced18 minProNETWORK-100Anycast DNS stays reachable but one site serves stale zone data after an AXFR policy changeThe service appears up globally, yet answers diverge because one anycast site stopped receiving zone transfers under the new policy.NetworkAdvanced18 minProNETWORK-089OSPF adjacency forms but area type mismatch suppresses the LSAs needed by the branch routeNeighbor status looks correct, yet the expected route never appears because one side treats the area differently and filters critical LSA propagation.NetworkAdvanced18 minProNETWORK-1248A BGP session remains Established while one route class disappearsA peering stays up after a provider-side change and one business-critical route class vanishes from the local table.NetworkAdvanced19 minProNETWORK-1243A BGP session remains Established while one route class vanishesA peering stays up after a provider change but one business-critical prefix set no longer enters the local table.NetworkAdvanced19 minProNETWORK-1253A BGP session stays Established while one route class disappearsA provider-side change leaves the peering up while one set of business routes vanishes from the local table.NetworkAdvanced19 minProNETWORK-1211BGP is Established but no prefixes arriveA new external BGP peer reaches Established immediately but no expected routes appear locally.NetworkAdvanced19 minProNETWORK-1231BGP peering looks stable but only one prefix set disappearsA peer remains healthy and only one class of routes disappears after a provider-side policy change.NetworkAdvanced19 minProNETWORK-093OSPF adjacency remains full but the summary route hides the more specific path needed for policy routingThe protocol is healthy, yet the application path fails because route summarization obscures the specific destination the policy logic depends on.NetworkAdvanced19 minProNETWORK-1228Policy routing works for small flows but larger sessions dieA firewall and router pair pass small health checks, but file transfers or TLS handshakes break only on some sessions.NetworkAdvanced19 minProNETWORK-1218BGP routes appear after reset but disappear againA peer begins showing routes after intervention, but the table empties again once normal policy evaluation resumes.NetworkAdvanced20 minProNETWORK-1223BGP routes appear and disappearA route-map based on BGP community works right after reset and then loses routes during later convergence.NetworkAdvanced20 minPro