Juniper
106 incident problems in Juniper environments.
먼저 읽을 가이드
추천 문제
All problems (106)
NETWORK-119A route-policy regex matches the AS path set too broadly and blackholes partner prefixes that should stay externalTraffic loss starts after a policy cleanup because the new pattern captures more paths than the operator intended.NetworkAdvanced17 minProNETWORK-270A VRRP pair shares the gateway IP while one downstream ACL still permits only the previous virtual MAC during a failover rehearsalRedundancy is healthy and the dependent security policy remains bound to yesterday's identity. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.NetworkAdvanced17 minProNETWORK-144A VXLAN flood-and-learn segment still receives BUM traffic, but ARP suppression on one VTEP keeps a stale host mapping and east-west packets disappearThe overlay fabric is generally healthy, yet one stale optimization prevents correct endpoint learning.NetworkAdvanced17 minProNETWORK-146An MPLS TE tunnel comes up, but autoroute announce is disabled on one node and normal traffic never uses the engineered pathThe tunnel exists, yet forwarding behavior does not change because one control flag was left off.NetworkAdvanced17 minProNETWORK-129BFD minimum receive timers do not align between vendors, and only one side believes the session is stableBoth devices show partial liveliness, but the negotiated timing reality differs enough to keep the path flapping.NetworkAdvanced17 minProNETWORK-115BGP confederation sub-AS policy strips the community needed to choose the correct exit pathThe routes arrive everywhere, but exit selection is wrong because a transit policy removed the signal the edge uses for preference.NetworkAdvanced17 minProNETWORK-111Consistent hashing is disabled during a line-card replacement and long-lived sessions reset across ECMP membersRedundancy remains, but user sessions drop because path stickiness disappeared during the hardware swap window.NetworkAdvanced17 minProNETWORK-122eBGP TTL security is configured on one side only after the provider path gains an extra hop, and the session drops permanentlyBoth peers still have the right neighbors configured, yet the control-plane hardening assumption no longer matches reality.NetworkAdvanced17 minProNETWORK-1207Native VLAN assumptions hide the real issueA multi-vendor trunk stays healthy on paper, but one service VLAN never crosses it.NetworkIntermediate17 minProNETWORK-137VRRP advertisements pass, but the mixed-vendor pair uses different packet version expectations and both routers think they are masterLayer-3 reachability exists, yet first-hop symmetry collapses because redundancy control messages are interpreted differently.NetworkAdvanced17 minProNETWORK-143A BGP blackhole community is set correctly, but the route reflector policy strips it before it reaches the transit edge and mitigation never activatesMitigation signaling exists at the source, yet it vanishes in the core policy path.NetworkAdvanced18 minProNETWORK-234A BGP session remains established while graceful restart keeps stale forwarding alive longer than the outage can tolerate during a failover rehearsalControl-plane continuity looks stable while data-plane truth is already different. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.NetworkAdvanced18 minProNETWORK-258A GRE keepalive stays up while recursive routing toward the tunnel destination loops through the tunnel itself during a failover rehearsalThe health signal survives on a path definition that undermines the tunnel's own reachability. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.NetworkAdvanced18 minProNETWORK-294A GRE over IPsec path stays established (Rollout Stuck)A GRE over IPsec path stays established (Rollout Stuck) focuses on wan-and-overlay-connectivity and asks the reader to isolate Rollout Stuck in Cisco. 실무에서는 rollout-stuck 이슈를 볼 때 DNS, 라우팅, ACL/방화벽, 목적지 응답을 계층별로 잘라서 확인하면 장애 구간을 훨씬 빠르게 좁힐 수 있습니다.NetworkAdvanced18 minProNETWORK-176A mitigation community is set at the source and stripped before it reaches the edge that should act on it after a control-plane upgradeThe intent exists in one domain and disappears in the middle of the network. The workload or policy had been stable, but the upgraded control layer now interprets one dependency differently.NetworkAdvanced18 minProNETWORK-173A mitigation community is set at the source and stripped before it reaches the edge that should act on it after a maintenance template changeThe intent exists in one domain and disappears in the middle of the network. The path looked stable before the template changed, but one inherited assumption no longer matches the live environment.NetworkAdvanced18 minProNETWORK-224A route-map matches the right prefix set while one additive community action is replaced instead of appended after a control-plane upgradeThe route is still policy-matched, yet a downstream signal disappears because one action semantics was misunderstood. The workload or policy had been stable, but the upgraded control layer now interprets one dependency differently.NetworkAdvanced18 minProNETWORK-222A route-map matches the right prefix set while one additive community action is replaced instead of appended during a failover rehearsalThe route is still policy-matched, yet a downstream signal disappears because one action semantics was misunderstood. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.NetworkAdvanced18 minProNETWORK-226A route-map matches the right prefix set while one additive community action is replaced instead of appended during a rollback rehearsalThe route is still policy-matched, yet a downstream signal disappears because one action semantics was misunderstood. The steady path hides the problem until the system is asked to move backward through the dependency chain.NetworkAdvanced18 minProNETWORK-151A route-reflector cluster reflects the primary path, but the add-path policy excludes backup labels and remote PIC never builds the alternate forwarding stateCore routing is healthy, yet fast failover never materializes because backup state was never distributed.NetworkAdvanced18 minPro