SSR 7.1 Release Notes
The SSR has moved away from the historical package-based delivery to an image-based delivery. As such, it is strongly suggested that you revisit your "standard" procedures for installation and upgrade of SSR Software.
Beginning with SSR v6.3.0, the use of the interactive installer is not supported, or necessary. Software installation and upgrade activities are supported from the Web Interface or the Command Line Interface.
With the image-based ISO delivered beginning with version 6.3.0, the manual installation process no longer supports the initialize128t command.
Initializing devices as a conductor or conductor-managed router is easily accomplished from the GUI using the Initialize Your Device - Web Workflow, or from the CLI using the the initialize conductor and initialize conductor-managed commands described in the Initialize Your Device - Advanced Workflow documentation.
Installation from ISO
When installing SSR V6.3.0 or newer on a new system, use the image-based ISO - identified by the filename prefix "SSR": SSR-6.3.0-107.r1.el7.x86_64.ibu-v1.iso. Installation documentation for the image-based process can be found in the Image-based ISO Installation Overview.
Offline mode conductor and router upgrades to image-based installations are detailed in the Single-Version 6.3.0 Upgrade instructions.
Upgrade Considerations
7.x Conductor Upgrades
If you are upgrading a conductor that is currently running version 6.3.4 or lower, and you wish to upgrade to any version of 7.x, you must first perform a transitional upgrade of the conductor to version 6.3.5 - 6.3.7.
Once the conductor has completed the 6.3.5-6.3.7 transitional upgrade, you may then upgrade the conductor to any 7.x version of the SSR software.
If your conductor is currently running SSR version 6.3.5+, you may upgrade to 7.x normally.
Routers that are being upgraded to 7.x DO NOT have to make a transitional upgrade step. The transitional upgrade through 6.3.5-6.3.7 applies ONLY to Conductor. Routers can be upgraded directly from pre-7.x to 7.x.
VM Upgrades 6.2.x to 7.x
Users upgrading a virtual machine, including those on AWS or Azure, previously installed with package-based SSR releases (6.2 and prior on Conductor-managed deployments only) should be aware of the following:
Due to changes in the base SSR/Linux OS in 7.X, interface naming behavior has changed for virtual machines. Older SSR versions using earlier versions of the SSR OS may have named Linux interfaces with the ethX naming convention. Interfaces in 7.X and above use the Linux predictable interface naming convention as seen in SSR hardware installs. This change in interface naming could prevent existing Linux interface configurations not to apply to the ethX-named interface. This applies to interfaces configured directly in Linux, such as dedicated management interfaces, and not interfaces configured via SSR configuration.
This issue is currently being addressed by engineering. However, if your deployment requires an upgrade to 7.X on a VM configured with interfaces using the ethX naming convention, please ensure that console access is available, as manual updates to the Linux interface configuration may be required.
System Disk Considerations
As mentioned above, during the upgrade to an image-based installation, existing systems will go through a conversion process to support image-based delivery. This process involves resizing the existing disk partition to support writing a new disk image to the remaining disk space. As such, the usable disk space seen after this conversion will be approximately halved. The system will automatically detect if there is not enough usable disk space on the existing drive to support this partition resizing and, if so, will trigger an upgrade failure. Even if the conversion is successful and the upgrade succeeds, users may note that the system is experiencing disk space alarms after the upgrade due to the reduction in overall capacity. It is suggested to remove unnecessary large files from systems before upgrading. Old saved tech-support-info archives (check for tar.gz or zip files in /var/log/128technology) and uploaded ISO images are frequent contributors to used disk space and should be manually deleted.
In certain scenarios, existing cloud routers may have been installed from images that did not use LVM for partitions. For these systems, the automatic resizing of disk partitions will fail and they cannot be upgraded. It is suggested to rebuild these instances from the official SSR BYOL image for either AWS or Azure.
When the conductor is initially upgraded to an image-based installation, it will be upgraded as a package-based system. This is because the system does not understand how to handle image-based delivery until it is running 6.3 software. Once the conductor is running 6.3 all router upgrades will be treated as image-based upgrades and any subsequent conductor upgrade will be treated as image-based. Therefore, it is possible that issues related to disk usage on conductor may not arise until a subsequent upgrade of the conductor beyond the initial step to 6.3.
Offline-Mode: Upgrading 6.3.x Conductor Deployments to 6.3.x+
An issue has been identified that may be observed in conductor deployments running version 6.3.x software, when attempting to upgrade from one 6.3.x patch release to another. This results in the message, “SSR firmware upgrade failed for the local node: SSR upgrade failed after reboot”. To work around this, run request system software upgrade installation-service from the command line of the Conductor, after importing the image-based ISO. Once complete, perform the full system upgrade from the Web interface. This issue will be resolved in a future release.
Offline-Mode: Onboarding Routers Running older SSR Software to a 6.3.x Conductor
An issue has been identified when onboarding SSR routers installed with older versions of software (such as 5.4.4) to Conductors running 6.3.x, when running in offline-mode. In some cases, certain software packages are not available to be installed during onboarding. To work around this issue, import the package-based (the "128T" prefixed) ISO for the current conductor version onto the conductor. This provides the necessary software packages to complete the onboarding process. This issue will be resolved in a future release.
After installing / upgrading to SSR 7.1.3 or later, downgrading to an earlier version of SSR software where Configuration Integrity (CI) is not available is NOT supported.
Rollback to the previously installed version of software is supported.
An issue has been identified involving the use of the HA Sync Redundancy Plugin with SSR 7.0.1, which prevents proper functioning of the plugin. If you use the HA Plugin in your SSR deployment and are upgrading to SSR 7.X, it is recommended to upgrade to SSR 7.2.x and replace the plugin with a bond control interface.
Before upgrading please review the Upgrade Considerations and the Rolling Back Software pages. Several modifications have been made to the process for verifying configurations, which will impact existing configurations.
After the installation of SSR 7.x, it is not possible to downgrade to a 6.x version of the SSR software. Because of the format of the image based installation (dividing the disk into two partitions), downgrading from SSR 7.x to any package based installation (6.x) is not possible. A downgrade is defined as uninstalling the 7.x software, and attempting to install a 6.x version.
Rollback (to the previously installed version) is supported.
Release 7.1.7-15-sts
Release Date: September 17, 2026
New Features
- I95-63985 VRRP Non-revertive Active/Active Recovery: Added support for VRRP to automatically revert from an active/active state back to active/standby when the underlying Layer 2 connectivity is restored, without requiring manual intervention such as priority changes or interface flaps.
- I95-65332 BGP Authentication with MD5 in FIPS Mode: BGP and MSDP now support TCP MD5 authentication when the system is operating in FIPS mode. Previously, enabling FIPS mode prevented BGP authentication from functioning.
Resolved Issues
- The following CVEs have been identified and resolved in this release: CVE-2024-12086, CVE-2024-34459, CVE-2025-5278, CVE-2025-6170, CVE-2025-9714, CVE-2025-10911, CVE-2025-12748, CVE-2025-13151, CVE-2025-14087, CVE-2025-14512, CVE-2025-21502, CVE-2025-21587, CVE-2025-30691, CVE-2025-30698, CVE-2025-30749, CVE-2025-30754, CVE-2025-50059, CVE-2025-50106, CVE-2025-53057, CVE-2025-53066, CVE-2025-64720, CVE-2025-65018, CVE-2026-0865, CVE-2026-1933, CVE-2026-2291, CVE-2026-2340, CVE-2026-3012, CVE-2026-3039, CVE-2026-3832, CVE-2026-3833, CVE-2026-4046, CVE-2026-4408, CVE-2026-4437, CVE-2026-4438, CVE-2026-4480, CVE-2026-4786, CVE-2026-4800, CVE-2026-4878, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, CVE-2026-5119, CVE-2026-5260, CVE-2026-5419, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-5946, CVE-2026-6238, CVE-2026-6893, CVE-2026-7383, CVE-2026-9076, CVE-2026-9698, CVE-2026-14380, CVE-2026-14474, CVE-2026-14476, CVE-2026-14739, CVE-2026-15308, CVE-2026-21925, CVE-2026-21933, CVE-2026-21945, CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23479, CVE-2026-23631, CVE-2026-23865, CVE-2026-25243, CVE-2026-28390, CVE-2026-28780, CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-29111, CVE-2026-29518, CVE-2026-33007, CVE-2026-33278, CVE-2026-33845, CVE-2026-33846, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059, CVE-2026-34180, CVE-2026-34181, CVE-2026-34182, CVE-2026-34183, CVE-2026-34268, CVE-2026-34282, CVE-2026-34980, CVE-2026-35177, CVE-2026-35385, CVE-2026-37555, CVE-2026-39979, CVE-2026-40164, CVE-2026-40170, CVE-2026-40355, CVE-2026-40356, CVE-2026-40622, CVE-2026-41035, CVE-2026-41254, CVE-2026-41292, CVE-2026-41411, CVE-2026-42009, CVE-2026-42010, CVE-2026-42011, CVE-2026-42012, CVE-2026-42013, CVE-2026-42014, CVE-2026-42015, CVE-2026-42055, CVE-2026-42534, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-42944, CVE-2026-42959, CVE-2026-43618, CVE-2026-43658, CVE-2026-43660, CVE-2026-44390, CVE-2026-44431, CVE-2026-44432, CVE-2026-44673, CVE-2026-45186, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447, CVE-2026-46483, CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47059, CVE-2026-47063, CVE-2026-47162, CVE-2026-47167, CVE-2026-48142, CVE-2026-48864, CVE-2026-48914, CVE-2026-48962, CVE-2026-52858, CVE-2026-54369, CVE-2026-54370, CVE-2026-54371, CVE-2026-55693, CVE-2026-57455, CVE-2026-57456, CVE-2026-58016, CVE-2026-59856, CVE-2026-59858, CVE-2026-60147, CVE-2026-60589, CVE-2026-61308, CVE-2026-70907
- The following issues have been addressed and delivered to increase the overall security posture of the SSR: I95-65025, I95-65026, I95-65027, I95-65033, I95-65038, I95-65044, I95-65205, I95-65208, I95-65217, I95-65226, I95-65235, I95-65236, I95-65239, I95-65252, I95-65297.
- I95-62331 OSPF Default Route Not Re-Advertised After Restart: Resolved an issue where a timing condition could prevent OSPF from generating the external (Type 5) LSA for a configured default route after a restart, so peers did not receive the default route until the OSPF process was manually cleared. OSPF now reliably advertises the default route after a restart.
- I95-63195 Highway Crash During ESKM Session Scaling: Resolved an issue where the highway process could crash during high session scaling due to incorrect metadata propagation in ESKM encrypt/decrypt contexts.
- I95-63811 IPv6 Service with ICMP Transport Not Routed: Resolved an issue where PINGv6 sessions were not routed when an IPv6 service was configured with ICMP as the transport protocol. The system now correctly remaps ICMP to ICMPv6 for IPv6 service prefixes.
- I95-64464 Slow Initial Router Onboarding to Conductor: Resolved an issue where router onboarding to the conductor was slow, causing assets to remain stuck in a synchronizing state for extended periods before reaching the synchronized state.
- I95-64063 Salt Minion restarting every minute when one Conductor is Unreachable: Resolved an issue where the Salt Minion restarted once per minute whenever one conductor in a two-conductor deployment was unreachable, causing repeated instability in the management plane connection.
- I95-64908 Runtime Error Collapsing Logs Panel in Web Interface: Resolved an issue where interacting with the collapse control on the Conductor Logs page before the page had fully rendered could trigger a runtime script error. The Logs page now safely handles this interaction.
- I95-64978 Highway crash on head-end router causing interface flaps: Resolved an issue where a race condition on session classification fields (such as domain name, URI, and application classification) could cause the highway process to crash with a core dump, resulting in interface flaps. Access to these fields is now properly synchronized.
- I95-65190 Stale HA State Remained After Converting a Router to Standalone: Resolved an issue where converting a router from an HA pair to a standalone node by deleting the placeholder peer node did not fully clear local HA state, including the peer's initialization data and key files, on the remaining node. This caused the node to loop continuously attempting to synchronize. The node now fully clears HA-related local state when a peer node is removed.
- I95-65314 Sessions Not Switching to Available Source NAT IPs: Resolved an issue where a source NAT database corruption and race condition prevented sessions from switching to additional available IP addresses on a WAN interface, causing packet drops.
- I95-65337 Missing FIB Entries After Router Migration: Resolved an issue where FIB entries were missing after migrating WAN interfaces from one router to another using the same IP addresses. The system now correctly detects new peers and triggers path addition for peers that are already up.
- I95-65348 Added Support for Bouncing PoE Ports: Added the ability to force a link down/up cycle ("bounce") on SSR4xx PoE ports, allowing a connected access point to be power-cycled without physically disconnecting the cable.
- I95-65365 PCLI Command to Trigger GARP: Added the PCLI command to manually trigger Gratuitous ARP (GARP) on VRRP interfaces, accepting device and network-interface as arguments.
- I95-65392 Hierarchical services ping traffic failure between sites: Resolved an issue where ICMP ping traffic between specific sites failed when using hierarchical service configurations with application identification groups.
- I95-65394 Improved Detail in Peer Certificate Validation Alarms: Resolved an issue where the peer certificate invalid alarm provided no specific reason for the validation failure. The alarm now includes the underlying certificate validation error, such as expiration, revocation, or a name mismatch, to help identify the root cause.
- I95-65527 Added Missing sysServices SNMP OID on Conductor: Resolved an issue where the conductor did not return the standard
sysServicesSNMP OID (.1.3.6.1.2.1.1.7.0), which some third-party management systems require for device discovery. The conductor's generated SNMP configuration now includes this OID.
- II95-65532 Application Identification Not Available Immediately After IDP Engine Restart: Resolved an issue where restarting the IDP Engine removed the installed application-identification package, causing traffic to be classified as an unknown application until the next scheduled download. The application-identification package is now installed automatically during IDP startup.
- I95-65535 Assets Stuck in Synchronizing State: Resolved an issue where assets could become stuck in a synchronizing state for extended periods (up to 24 hours) due to overly aggressive watchdog timer defaults. The default timer settings have been relaxed.
- I95-65545 Incorrect Fragmentation Stats Table Name: Resolved an issue where the PCLI displayed an incorrect table name ("Non-Fabric IPv6 Fragmented Packets" instead of "Non-Fabric IPv4 Fragmented Packets") for IPv4 fragmentation statistics.
- I95-65548 DSCP steering support with deferred classification in hierarchical services: Added support for DSCP steering services when classification is deferred in hierarchical service configurations, enabling correct traffic handling in Mist-managed deployments.
- I95-65557 Highway Crash During Show Commands on HA Router: Resolved an issue where issuing show commands on an HA router could cause a highway crash on both nodes due to FIB table contention. FIB table operations are now batched to prevent mutex lock errors.
- I95-65583 Corrected Log Rotation Frequency for InfluxDB Logs: Resolved an issue where InfluxDB log rotation ran only once per day instead of hourly on some platforms, allowing log files to grow much larger than expected and, in some cases, consume all available disk space. Log rotation now runs hourly as intended.
- I95-65609 After upgrading using Secure Conductor Onboarding and reaching the Syncronized state, routers return to Waiting: An issue has been identified for any upgrade where 128T processes start slowly relative to the SCO server could produce this symptom for all previously-onboarded routers.
- I95-65635 Source NAT Port Exhaustion on Loopback Interface: Resolved an issue where a large number of
SourceNatPortExceptionerrors for the local KNI interface caused SSH connection failures to the SSR loopback IP. Host-type service routes no longer use the KNI IPv6 control interface for source NAT.
- I95-65656 Conductor upgrade fails on health check: Resolved an issue where conductor upgrades could fail due to a health check timeout, preventing the upgrade from completing successfully.
- I95-65680 RoutingManager Not Running on HA Headend Router: Resolved an issue where the routingManager could remain in STANDBY after a session interruption, leaving the router without an active routing process (loss of BGP/routing connectivity) until restarted.
- I95-65754 Highway Crash on Shutdown Due to Static Sessions: Resolved an issue where the highway process crashed during shutdown on HA nodes performing a downgrade. Static sessions were not being cleared during the shutdown sequence. Static sessions are now properly cleared alongside the session table during shutdown, preventing the crash.
- I95-65771 Resolved a Highway Crash Related to Unclassified Application Statistics: Resolved an issue where the highway process could crash while collecting application identification statistics for sessions that had no classified application type. Application statistics handling now safely accounts for this case.
- I95-65772 Resolved a Highway Crash When a Peer Path Was Removed During an SLA Update: Resolved an issue where the highway process could crash if a peer path was removed while its SLA or forwarding-path-metric data was being updated. Path data handling now safely handles this timing condition.
- I95-65797 ESKM Peering Stays Down After Late Metadata Key: Resolved an issue where ESKM peering remained down when BFD received the local metadata key late because retransmit timers were not being restarted after their initial firing.
- I95-65803 Connected Routes on a Bonded Interface Missing from the RIB After Upgrade: Resolved an issue where, after an upgrade, directly connected routes on a bonded (LAG) interface could be missing from the routing table even though the interface and its members were up, requiring the interface to be manually flapped to restore the routes. The system now correctly handles the race condition that caused this during interface initialization.
- I95-65819 Fixed Syslog TLS Certificate Validation Failure: Resolved an issue where syslog messages configured to use TLS could fail to be forwarded because the certificate authority bundle was not concatenated correctly. CA certificate bundles are now assembled correctly.
- I95-65826 Assets enter a
Disconnectedstate after upgrading the Conductor: After a Conductor upgrade, assets entered aDisconnectedstate while the SSH connections were restored. In some cases this took an hour or more. The Minion connector has been upgraded to version 1.7.6 to resolve this issue.
- I95-65832 Installation Failure When a Network Block Device Was Present: Resolved an issue where ISO installation with the erase-all option enabled could fail if a network block device (NBD) was present on the system, because the installer attempted to erase it. The installer now skips network block devices during disk erasure.
- I95-65855 Nginx Resolver Loop When No DNS Servers Were Configured: Resolved an issue where, with no DNS servers configured, the system could select a link-local IPv6 address as a resolver, causing nginx to repeatedly fail to parse it and loop. The syslog resolver now honors static host-to-IP mappings instead of falling back to an unusable address.
- I95-65886 Static DNS Host Entries Not Honored for Syslog Destinations: Resolved an issue where syslog destinations configured by hostname did not resolve using locally configured static host-to-IP mappings when public DNS was unavailable. Syslog now resolves configured hostnames using static entries directly, rather than through the nginx resolver.
- I95-65893 Added ESKM Payload Key Indices to Session Detail Output: Added the current encryption and decryption payload key indices to the
show session by-idPCLI output and corresponding API responses, providing additional visibility into ESKM key rotation for active sessions.
- I95-65912 Resolved Source NAT Port Exhaustion Caused by Duplicate Internal Interfaces: Resolved an issue where enabling both source NAT and IDP could result in duplicate internal interface identifiers being created, contributing to premature exhaustion of available source NAT ports and dropped packets. Internal IDP interface identifiers are now allocated uniquely.
- I95-65959 Improved Subtenant Support in IDP Access Policy Configuration: Improved handling of subtenant relationships in IDP access policy configuration to ensure access policies are applied correctly across tenant hierarchies.
- I95-65962 False-Positive NAT Duplicate Validation Error on HA Routers with IDP Enabled: Resolved an issue where committing a dynamic or bidirectional source NAT configuration on an HA router with IDP enabled could fail with a false "duplicate" validation error, because the configuration validator did not account for the shared interface existing identically on both HA nodes. The validator now correctly recognizes this as a single logical interface.
- I95-65963 Secure Conductor Onboarding Panels Displayed in Inconsistent Order: Resolved an issue where Secure Conductor Onboarding (SCO) panels were displayed in a random order in the web interface. Panels are now displayed in a consistent, deterministic order.
- I95-65971 Improved Subtenant Support in Access Policy Validation: Improved access policy validation to correctly accept bidirectional tenant relationships when subtenants are configured.
- I95-65972 Improved Subtenant Prefix Inheritance in Access Policy: Resolved an issue where child tenants did not correctly inherit prefix bindings from an ancestor tenant in access policy configurations. Subtenant configurations now correctly inherit ancestor prefix bindings.
- I95-66067 Offline upgrade failure: Resolved an issue during upgrade that was being reported as an
Unpacker Failure. The service startup order has been adjusted to prevent the issue in future upgrades/installations.
- I95-66070 Highway Crash in High-Scale Peer Scenarios: Resolved an issue where the Highway process would crash with a large number of SSR peers, due to a race condition. The fix adds thread-safe locking mechanisms to protect all read and write operations, ensuring stable operation at scale.
- I95-66071 Resolved a Highway Crash During GRE Tunnel Configuration Updates: Resolved an issue where a failed lookup during a GRE tunnel interface modification could leave stale internal state, causing the highway process to crash on a subsequent configuration change to the same tunnel. GRE tunnel state is now cleaned up correctly when a lookup fails.
- I95-66082 Resolved a Highway Crash on Reverse-Flow Session Collision: Resolved an issue where the highway process could crash when a returning packet collided with an internal session during reverse-flow processing, causing peer instability. The colliding packet is now safely dropped instead of causing a crash.
- I95-66127 401 Authorization Required error when refreshing Logs page: Resolved a
401 Authorization Requirederror that prevented non-default administrator users from viewing router displays, the Logs page, and FIB tables in the Conductor GUI.
- I95-66131 Resolved a Highway Crash When Setting PoE Port Provisional Status: Resolved an issue where setting the provisional status of a PoE port could cause the highway process to abort due to a cross-thread access violation. The operation now safely executes on the correct thread.
- I95-66196 Commit Failures After Upgrade Due to Auto-Generated IPv6 DNS Service Routes: Resolved an issue where upgrading could automatically generate an IPv6 DNS management service and associated service-route even when IPv6 DNS was not in use, causing configuration commits to fail on routers where the management interface did not have source NAT enabled. The DNS service route is now generated only for address families that have a corresponding management interface.
- I95-66222 Encrypted Directories Occasionally Not Unlocked at Boot: Resolved an issue where a timing condition between TPM initialization and the integrity handler could cause the system to incorrectly determine that TPM support was unavailable, resulting in encrypted directories not being unlocked at boot. The integrity handler now retries TPM detection before proceeding.
- I05-66238 NTP fails to sync after upgrade: Resolved an issue where NTP failed to sync after a linux upgrade due to an outdated NetworkManager script not removed by the upgrade process.
- I95-66278 Resolved Peer-Path Instability with SVR2 ML-KEM Sessions: Resolved an issue where an incorrect retransmit timer for SVR2 sessions using ML-KEM could cause peer-paths to intermittently flap and drop traffic. The retransmit timer has been corrected.
Release 7.1.6-7-sts
Release Date: July 15, 2026
New Features
- I95-62868 Multicast Failover Optimizations / PIM GR: Additional improvements to multicast failover and convergence times for PIM Graceful Restart. These optimizations reduce traffic loss during HA and non-HA failover events for multicast traffic.
- I95-63012 AppID Scale Optimization: Improved application identification performance and scale for WAN deployments. Optimizations reduce resource consumption on spoke routers where application identification is enabled by default, improving capacity under high traffic loads.
Resolved Issues
- The following CVEs have been identified and resolved in this release: CVE-2023-40403, CVE-2025-9230, CVE-2025-12084, CVE-2025-13601, CVE-2025-14087, CVE-2025-14512, CVE-2025-61662, CVE-2025-67873, CVE-2025-68114, CVE-2025-68973, CVE-2026-1519, CVE-2026-3497, CVE-2026-4111, CVE-2026-4424, CVE-2026-4519, CVE-2026-4786, CVE-2026-4878, CVE-2026-5119, CVE-2026-5121, CVE-2026-6100, CVE-2026-9256, CVE-2026-21710, CVE-2026-25646, CVE-2026-25749, CVE-2026-26996, CVE-2026-27135, CVE-2026-27651, CVE-2026-27654, CVE-2026-27784, CVE-2026-27904, CVE-2026-28417, CVE-2026-28421, CVE-2026-29111, CVE-2026-31431, CVE-2026-32647, CVE-2026-32748, CVE-2026-33412, CVE-2026-33416, CVE-2026-33526, CVE-2026-33636, CVE-2026-34982, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414, CVE-2026-35535, CVE-2026-39979, CVE-2026-40164, CVE-2026-40460, CVE-2026-40701, CVE-2026-41242, CVE-2026-42926, CVE-2026-42934, CVE-2026-42945, CVE-2026-42946, CVE-2026-43284, CVE-2026-43500, CVE-2026-46300, CVE-2026-46333.
- The following issues have been addressed and delivered to increase the overall security posture of the SSR: I95-62091, I95-65017, I95-65018, I95-65019, I95-65028, I95-65030, I95-65039, I95-65054, I95-65055, I95-65080, I95-65206, I95-65210, I95-65211, I95-65219, I95-65221, I95-65222, I95-65224, I95-65225, I95-65237, I95-65238, I95-65247, I95-65249.
- I95-60912 PIM and PIMv6 cannot be enabled on the same interface: Resolved an issue where enabling both PIM (IPv4) and PIMv6 on the same interface was not possible, preventing dual-stack multicast configurations.
- I95-63033
show lte detailcrash when LTE apn-name is invalid: Resolved an issue where executingshow lte detailwhen an invalid APN name is configured caused a CLI crash due to an unhandled dictionary update error.
- I95-63035 Antivirus warning when missing tenant for AV traffic: Resolved an issue where an antivirus alert was incorrectly raised on the passive node in an HA system, indicating AV was not active.
- I95-63876 Route Flapping and Inaccessibility: Resolved an issue where routes would flap or become inaccessible in hub-and-spoke topologies with inter-hub steering preferences configured, causing intermittent connectivity failures.
- I95-63895 SSR sending packets larger than configured MTU: Resolved an issue where the SSR was sending packets larger than the configured MTU (e.g., 1518 bytes instead of 1500), causing packet drops on downstream network elements.
- I95-63913 Session-source incorrect in BFD pinhole: Resolved an issue where session-source was incorrectly set to public when a BFD pinhole also happened to be a flow-move scenario.
- I95-63951 BGP Graceful Restart Sending EOR Prematurely: Resolved an issue where the SSR sent End-of-RIB (EOR) markers prematurely during BGP graceful restart, without waiting to receive EOR from its peers as required by RFC 4724, potentially causing route convergence issues.
- I95-63965 SNMP MIB subinterfaces not reporting correct stats: Resolved an issue where SNMP MIB walks on subinterfaces were not reporting correct statistics, causing inaccurate monitoring data in network management systems.
- I95-64061 Azure kernel hung task after upgrade: Resolved an issue where Azure VMs could experience a kernel hung task condition related to the
uio_hv_genericdriver after upgrading to 7.1.3.
- I95-64150 User-defined SNMP metrics not working: Resolved an issue where custom SNMP metric MIBs were not functioning correctly after upgrading to 7.1.3, preventing SNMP-based polling systems from collecting metrics.
- I95-64250 BGP routes received but not installed in RIB: Resolved an issue where BGP routes were received from peers but not installed in the BGP table or the routing information base (RIB), preventing traffic from using those routes.
- I95-64306 Optimize ICMP probe profile update on config change: Resolved an issue where configuration changes that contained no actual ICMP probe modifications still triggered a full restart of all ICMP probes, causing unnecessary overhead and brief monitoring gaps.
- I95-64344 Extended multicast traffic loss with PIM GR not being used: Resolved an issue where PIM Graceful Restart was not properly engaged during HA failover, resulting in extended multicast traffic loss instead of seamless failover.
- I95-64397 Cosmetic error message on SSR1500: Resolved an issue where a harmless but misleading
systemd-rc-local-generatorerror message was displayed on the SSR1500 console, which could cause unnecessary alarm during routine operations.
- I95-64407 Alternate SHA ciphers (256/384/512) not working properly with ESKM: Metadata-key handling has been updated to correctly support the SHA384/SHA512 HMAC ciphers by making metadata keys and policy indices cipher-aware end-to-end.
- I95-64408 TCP timers used for syslogs not set or too relaxed: Resolved an issue where TCP keepalive timers for syslog connections were either not set or configured with excessively long intervals, resulting in stale connections not being detected and syslog failover not triggering in a timely manner.
- I95-64411 IPv6 BGP route-map
set ipv6 next-hop peer-addresssupport: Added support for theset ipv6 next-hop peer-addressdirective in route-maps, which is required for IPv6 WAN assurance deployments.
- I95-64434 IDP bypass
alertpolicy not working: Resolved an issue where setting the IDP bypass policy toalertmode was not functioning correctly, preventing traffic from being properly inspected and alerts issued.
- I95-64479 Invalid application WEBEX not recognized: Resolved an issue where the WEBEX application was not being recognized by the application identification module after an upgrade, resulting in
invalid applicationevents and missing FIB entries for the associated service.
- I95-64541 Node disconnection during upgrade: Resolved an issue where upgrading HA router nodes could result in one node entering a disconnected state with stale SSH control sockets, while the other node became stuck in the upgrading state, requiring a manual reboot to recover.
- I95-64549 Onboarding routers cannot install salt packages: Resolved an issue where routers being onboarded to a conductor could not install the required salt packages, preventing successful onboarding completion.
- I95-64566 CSR generation ignores camelCase parameters: Resolved an issue where the certificate signing request (CSR) API silently ignored camelCase parameter names (e.g.,
commonNameinstead ofcommon_name).
- I95-64575 Unable to login to SSR routers from conductor in cloud deployment: Resolved an issue where the SSH configuration on cloud-deployed routers disabled password authentication, preventing login from the conductor.
- I95-64603 Chronyd requires manual restart after reboot: Resolved an issue where all NTP servers appeared as rejected after a reboot, requiring a manual restart of chronyd to restore time synchronization.
- I95-64619 Config validation rejects DHCP network-interface when VRRP is present: Resolved an issue where configuration validation incorrectly rejected DHCP-enabled network-interfaces when VRRP was configured on the same interface, even if VRRP was not enabled.
- I95-64627 Certificate Unavailable for Peering After Upgrade: Resolved an issue where the local certificate became unavailable for peering after an upgrade, resulting in peer paths remaining down with a
No local certificate availableerror.
- I95-64684 HMAC cipher mode information in logs and session output: Added HMAC mode and cipher information to session logs and
show sessionsoutput, improving visibility into the encryption parameters used for active sessions.
- I95-64696 Salt connectivity issues after Conductor upgrade: Resolved an issue where salt-minion lost connectivity to the salt-master after a Conductor upgrade, affecting approximately 20% of routers. The minion-connector service now correctly manages the salt master address.
- I95-64709 BGP stale-routes-time and Selection Deferral Timer alignment: Resolved an issue where the
stale-routes-timeparameter behavior did not properly align with RFC 4724's Selection_Deferral_Timer semantics, potentially causing premature route selection during graceful restart.
- I95-64732 Update
show peers certificatedate format: Updated theshow peers certificatecommand to use a newer API for certificate date rendering, providing a more user-friendly output format.
- I95-64811 Highway crash causing session drops: Resolved a highway process crash that occurred under specific traffic conditions, resulting in session drops and temporary traffic disruption.
- I95-64829 Device disconnected from Mist and stopped processing sessions: Resolved an issue where a device could disconnect from Mist and stop processing sessions after a configuration push, requiring a power cycle to recover.
- I95-64835 Remove UI checkbox for Rollback on Failure during Conductor migration: Removed the erroneous
Rollback on Failurecheckbox from the Conductor migration UI, as the underlying feature was never implemented. This prevents user confusion during migration operations.
- I95-64876 Intermittent application issues due to child service design: Resolved an issue where hierarchical service configurations with child services could intermittently fail to match traffic correctly, causing application connectivity issues.
- I95-64877 Changes to guard against L7 security stack crash: Resolved an issue where the IDP attack database was lost on reboot. The database is now stored persistently, and additional safeguards have been added for AV engine health checks, SSL certificate staging retries, and error code accuracy.
- I95-64903 High CPU and disk usage on standalone SSR440: Resolved an issue where a standalone SSR440 could experience high CPU utilization and disk usage under certain operational conditions, impacting device performance.
- I95-64905 401 Authorization Required error when refreshing Logs page: Resolved an issue where refreshing the Logs page on the conductor GUI returned a 401 Authorization Required error, requiring a full page reload or re-login.
- I95-64929 Peer certificate expiration time unit conversion error: Resolved an issue where a seconds-to-milliseconds conversion error caused premature peer certificate expiration.
- I95-64977 Certificate ingestion ignores expiry and revocation validation: Resolved an issue where ingesting a certificate did not properly validate its expiry date or revocation status, allowing expired or revoked certificates to be accepted.
- I95-64997 SYSLOG SEIM Integration Not Sending Failed Session Attempts: Resolved an issue where the SYSLOG SEIM integration did not send log events for ERROR/FAILED session attempts (dropped packets), limiting visibility into denied traffic.
- I95-65056
show app-id cache-sizescommand not found: Resolved an issue where theshow app-id cache-sizescommand was missing from the CLI, preventing users from inspecting application identification cache utilization.
- I95-65099 Traffic engineering stats displaying incorrect output: Resolved an issue where
show stats traffic-eng internal-application per-traffic-classdisplayed incorrect or unexpected output.
- I95-65128 nodeMonitor crash loop on hub node: Resolved an issue where the nodeMonitor process entered a continuous crash loop on hub nodes during conductor-based Hub-and-Spoke setup, preventing the hub from becoming operational.
- I95-65131 CPS performance degradation: Resolved a performance regression that caused approximately 10% reduction in connections-per-second (CPS) throughput.
- I95-65171 TSI Download Missing File Extension: Resolved an issue where Tech Support Info (TSI) bundles downloaded from the SSR Web UI had no file extension, preventing extraction with standard archive tools. Tech support files downloaded from the web UI now have the correct
.zipextension.
- I95-65296 ESKM peering failures with fragmentation: Resolved an issue where ESKM peering connections failed when packet fragmentation occurred on the path between peers, preventing secure peer relationships from establishing.
- I95-65299 SSR440 upgrade from 7.1.0 to 7.1.5 failure: Resolved an issue where upgrading an SSR440 from 7.1.0 to 7.1.5 could fail, with the highway process not running after reboot, causing the system to roll back automatically.
- I95-65336 Factory reset resilience to interruption: Improved the factory reset procedure to be more resilient to interruption (e.g., unexpected reboot). The system now tracks reset progress and can resume or indicate completion status after recovery.
- I95-65351 IMA and security incompatibility preventing engine start: Resolved an issue where IMA (Integrity Measurement Architecture) validation conflicted with IDP security features, preventing the SSR engine from starting after upgrade.
- I95-65354 Missing dependencies in offline ISO: Resolved an issue where certain package dependencies were missing from the offline ISO, preventing successful package installation in air-gapped environments.
- I95-65366 Maximum GARP interval for VRRP: Added a configurable
maximum-garp-intervalparameter for VRRP, allowing control over how frequently gratuitous ARP messages are sent during VRRP state transitions. This prevents excessive ARP traffic in environments with many VRRP instances.
- I95-65374 Child tenants not applied to security policies: Resolved an issue where child tenants were not correctly applied to security policies, preventing IDP rules from being enforced on traffic matching child tenant definitions.
- I95-65392 Hierarchical services ping traffic failure between sites: Resolved an issue where ICMP ping traffic between specific sites failed when using hierarchical service configurations with application identification groups (AIG).
- I95-65393 ESKM Certificate Invalid Alarm After Upgrade: Resolved an issue where a certificate invalid alarm was incorrectly raised after upgrading to a newer SSR version, causing peering to go down even though the certificate was not expired.
- I95-65403 Disallow CA certificates from being used for peering: Added validation to prevent CA certificates (those with
CA:Truein basic constraints) from being used as peering certificates, which would cause unexpected trust chain behavior.
- I95-65410 Incorrect RBAC requirements for certificate API: Resolved an issue where the POST
/api/v1/certificateendpoint required READ permission for the entire configuration instead of WRITE permission, allowing unintended access.
- I95-65411 CLI Command Appending Unrelated Output: Resolved an issue where executing certain PCLI commands (such as
show peer router all force) would append unrelated command output at the end of the expected results.
- I95-65414 Overlapping child tenant IP validation: Added configuration validation to disallow overlapping IP addresses across child tenants, preventing ambiguous traffic classification.
- I95-65431 SSR failing to sync with NTP server: Resolved an issue where the SSR failed to synchronize with configured NTP servers after boot, requiring manual intervention to restore time synchronization.
- I95-65432 Conflux process crash during upgrade: Resolved an issue where the Conflux process exited unexpectedly during or after an upgrade, causing temporary loss of analytics data collection.
- I95-65439 CRL in certificate not taken into account: Resolved an issue where the CRL distribution point embedded in a certificate was not being used for revocation checking, requiring manual CRL configuration on the conductor.
- I95-65455 Network Manager interface preventing HA sync: Resolved an issue where a spurious "Wired Connection" entry in Network Manager could prevent HA sync interfaces from obtaining IP addresses after an upgrade.
- I95-65459 IDP bypass not engaged during restart/rebuild: Resolved an issue where IDP bypass rules were not properly engaged during engine restart or rebuild operations, causing traffic that should be bypassed to be dropped temporarily.
- I95-65469 GUI not showing Network Interfaces: Resolved an issue where the GUI no longer displayed Network Interfaces on the device page, while Device Interfaces remained visible.
- I95-65470 Multicast session display count discrepancy: Resolved an issue where
show sessionsdisplayed fewer multicast sessions than expected (e.g., 334 of 400), even though all multicast routes were correctly installed.
- I95-65486 Highway crash during upgrade from older versions: Resolved a highway crash that could occur during router upgrades from significantly older software versions (e.g., 5.5.x to 7.x).
- I95-65529 Auto-generated syslog service incorrectly uses UDP for TLS: Resolved an issue where the auto-generated service for TLS-based syslog was incorrectly configured with UDP as the transport protocol instead of TCP.
- I95-65548 DSCP steering support with deferred classification in hierarchical services: Added support for DSCP steering services when classification is deferred in hierarchical service configurations, enabling correct traffic handling in Mist-managed deployments.
- I95-65617 Loss of syslog forwarding over TLS after upgrade to 7.1.6: Resolved an issue where syslog forwarding over TLS stopped working after upgrading to 7.1.6, preventing log delivery to remote collectors.
- I95-65624 KNI application scripts test failure: Resolved an internal test failure in KNI application scripts that could affect KNI interface initialization in certain configurations.
- I95-65656 Conductor upgrade fails on health check: Resolved an issue where conductor upgrades could fail due to a health check timeout, preventing the upgrade from completing successfully.
- I95-65691 Node disconnected after headend partial rollback: Resolved an issue where a node could remain disconnected from the conductor after a partial rollback scenario on a headend router.
- I95-65719 Secure Conductor Onboarding (SCO) failing: Resolved an issue where Secure Conductor Onboarding (SCO) failed when using RSA certificates in full chain format, incorrectly reporting that only RSA certificates are supported.
- I95-65769 Minion connector update: Resolved an issue where runtime RPM upgrades of the minion-connector on SSR400-series platforms failed to start due to missing IMA file signatures, resulting in loss of conductor connectivity.
- WAN-4774 Configuration model list key derivation: Improved internal configuration model handling by deriving list keys from the consolidated configuration model instead of using a hardcoded path map, improving accuracy for Mist-managed deployments.
Release 7.1.5-7r2
Release Date: April 30, 2026
New Features
- I95-63393 SSR400/SSR440 power supply status visibility: Added CLI support to display the status of power supplies on dual-AC SSR400/SSR440 platforms. The
show chassis powercommand displays power supply status for both single and dual power supply devices. This improves operational visibility into power redundancy and health on SSR400/SSR440 systems.
- I95-64568 TPM details in platform information: The
show platform securitycommand has been added to display TPM information such as TPM family (version number), revision, firmware version, and manufacturer. This allows users to verify TPM availability and configuration for security and compliance workflows.
- I95-64623 Plugin packaging improvements: Updated plugin packaging to include
128T-plugin-support-files. This ensures that plugin dependencies are available on systems that rely on the extra packages bundle.
Resolved Issues
- The following CVEs have been identified and resolved in this release: CVE-2021-47670, CVE-2022-25883, CVE-2022-49985, CVE-2022-50087, CVE-2022-50228, CVE-2022-50367, CVE-2022-50386, CVE-2022-50543, CVE-2023-53125, CVE-2023-53178, CVE-2023-53226, CVE-2023-53257, CVE-2023-53297, CVE-2023-53305, CVE-2023-53386, CVE-2023-53401, CVE-2023-53513, CVE-2023-53539, CVE-2024-56644, CVE-2025-4945, CVE-2025-6176, CVE-2025-9086, CVE-2025-9230, CVE-2025-11021, CVE-2025-12084, CVE-2025-13601, CVE-2025-14104, CVE-2025-21727, CVE-2025-21759, CVE-2025-22026, CVE-2025-22058, CVE-2025-22097, CVE-2025-37797, CVE-2025-37914, CVE-2025-38085, CVE-2025-38159, CVE-2025-38200, CVE-2025-38211, CVE-2025-38250, CVE-2025-38332, CVE-2025-38350, CVE-2025-38352, CVE-2025-38380, CVE-2025-38392, CVE-2025-38449, CVE-2025-38461, CVE-2025-38464, CVE-2025-38477, CVE-2025-38498, CVE-2025-38527, CVE-2025-38556, CVE-2025-38718, CVE-2025-38724, CVE-2025-39697, CVE-2025-39718, CVE-2025-39730, CVE-2025-39817, CVE-2025-39825, CVE-2025-39841, CVE-2025-39849, CVE-2025-39864, CVE-2025-39883, CVE-2025-39898, CVE-2025-39955, CVE-2025-39971, CVE-2025-40300, CVE-2025-66418, CVE-2025-66471, CVE-2026-0719, CVE-2026-1761, CVE-2026-21441.
- I95-62421 DHCP relay failures causing clients to miss IP assignment: Resolved an issue where DHCP session information is lost on the hub, causing the session reverse flow to collide with the forward flow of the session initiated originally from the spoke. This includes a new (configurable) default behavior for collision resolution. For detailed information, see
configure authority service-policy prefer-established-session {true | false}.
- I95-62710 Unnecessary web server processing for
router allin the PCLI: Addressed a problem where the web server performed unnecessary work when PCLI commands referencedrouter all. This optimization reduces overhead and improves responsiveness.
- I95-63174 IDP
Criticalprofile not applied: Resolved an issue where setting the IDP policy/profile toCriticalwas not properly applied on IDP. With this fix, profile changes toCriticalnow take effect as expected.
- I95-63355 Node-level security controls for serial console and USB: Restored support for configuring node-level security features that disable serial console output and USB boot/mass storage (for example, settings such as
serial-console-enabledandusb-mass-storage-enabled). This allows users to reapply hardened platform settings where supported.
- I95-63393 SSR400/SSR440 power supply status visibility: Added CLI support to display the status of power supplies on dual-AC SSR400/SSR440 platforms. The
show chassis powercommand displays power supply status for both single and dual power supply devices. This improves operational visibility into power redundancy and health on SSR400/SSR440 systems.
- I95-63839 SNMP walk failures on Conductors onboarding to NMS: Resolved an issue where SNMP walks on Conductors could fail with a
genError, preventing successful onboarding into some network management systems. System MIB walks on Conductors now complete successfully; IF-MIB is no longer exposed on Conductors where it is not supported.
- I95-63873 DHCP leases not showing in Conductor UI: Resolved an issue where attempting to retrieve DHCP v4 leases via the Conductor UI for a specific router results in
no leases found. Also resolved an issue where viewing a router Logs page via the Conductor UI displayed ALL logs rather than using the selected time range.
- I95-64152 Conductor connectivity blocked by stale SSH control sockets: Resolved a condition where, after a router reboot (particularly following an unclean shutdown), the router could remain Disconnected in the Conductor due to stale SSH control sockets. The SSH coordination logic now cleans up stale control sockets automatically, restoring Conductor–router connectivity.
- I95-64187 Improved handling of TPM Dictionary Attack (DA) lockout: Improved detection and handling when the TPM is in Dictionary Attack (DA) lockout mode. The integrity handler now detects this condition earlier and fails in a more predictable manner, simplifying troubleshooting of TPM-related integrity issues.
- I95-64568 TPM details in platform information: The
show platform securitycommand has been added to display TPM information such as TPM family (version number), revision, firmware version, and manufacturer. This allows users to verify TPM availability and configuration for security and compliance workflows.
- I95-64575 Unable to login to SSR routers from conductor in Cloud deployment: Resolved an issue where the SSH configuration on cloud-deployed routers disabled password authentication, preventing login from the conductor.
- I95-64595 Excessive audit log severity: Adjusted the log severity for the audit log event collector to better match expected operational conditions and reduce unnecessary log noise.
- I95-64687 Recursive cleanup of Salt cache directory Resolved an issue where cleanup of
/var/cache/salt/was not performed recursively, which could leave behind cached data. The cleanup process now removes this directory recursively to ensure a more complete reset.
- I95-64688 Highway coredumps causing peer path flaps: Resolved an issue where highway process coredumps were occurring, resulting in peer path flaps.
- I95-64719 Secure Conductor Onboarding (SCO) config validation incorrect: Resolved an issue where validating SCO config checked each node for an assetID but did not verify that at least one assetID was configured, which is a requirement.
Release 7.1.4-3r2
Release Date: March 17, 2026
Resolved Issues
- I95-64521 Upgrade from 7.1.0-r1 to 7.1.3-r2 failed on SSR440: Resolved an issue where an upgrade to 7.1.3-r2 on an SSR440 HA router would fail because the system health check failed. The
ha-0-0interface did not come up during boot (eth1comes up instead), causing the system health check to fail. Theha-0-0interface is now correctly initialized during upgrades on all SSR4x0 HA configurations.
- I95-64543 Onboarding an SSR440 router running 7.1.0 to a conductor running 7.1.3 fails: Resolved an issue where an older default cipher-string operator had been disallowed and caused the onboarding to fail. All of the following characters are now treated as valid:
. - _ : + @ = , !.
Release 7.1.3-29r2
Release Date: March 10, 2026
If you have an SSR400 or SSR440, it is strongly recommended that you upgrade to 7.1.4-2r2, and not use 7.1.3-29r2, due to the HA interface upgrade issue I95-64521 mentioned above.
New Features
- I95-26081 Display negotiated BFD Interval: The command
show peers bfd-intervalhas been added to display the negotiated bfd-interval in three columns,Rx Timer,Tx Timer, andMultiplier. See Negotiated BFD Intervals for more information.
- I95-48934 Configuration Integrity: SSR Configuration Integrity protects authentication credentials, keys and certificates, network topology information, and other pieces of sensitive SSR configuration from unauthorized access when the system is powered off. It prevents network and SSR operations from executing when the system is determined to be in a compromised state. To learn more, see Configuration Integrity.
- I95-54247 IMA - SSR Signed packages only execution: IMA is Linux’s Integrity Measurement Architecture. The SSR400 and SSR440 support IMA validation using GPG Signatures. IMA validation is enabled by default for the root user, allowing the kernel to check the signature of each file before loading it for execution. If these checks fail, execution is denied with a Permission denied (EACCES) error code. For more information, see Secure Boot - IMA.
- I95-54248 Smart OS Download: The SSR download process is now configurable, to provide better recovery and control over software downloads when a network connection fails. To improve resiliency against these network connectivity issues, the SSR queries available versions from all sources before beginning the download. If a request to a source fails, the SSR moves on to the next source. See Smart OS Download for more information.
- I95-56719 Conductor Scaling: Several improvements have been made to increase the scale of conductor managed router/node deployments, as well as the reporting of router information to the GUI and PCLI, and the efficiency of the device communications. The conductor can now manage up to a combination of 5000 nodes and routers (on appropriately resourced hardware platforms). Improvements to web interface responsiveness and updates to the following pages: Peer Path table, Event history, and Peering Connections panel of the Topology view.
- I95-58446 EoSVR Loop Prevention: EoSVR A/S Loop Prevention has been added, allowing EoSVR traffic to pass Broadcast, unknown-unicast, and multicast traffic through a switch without causing the port to be shut down.
- I95-58959 Secure Conductor Onboarding: Secure Conductor Onboarding (SCO) provides the ability to onboard a router to a conductor ensuring that each device proves possession of a private key, and that the connection is trusted and authenticated. For more information, see Secure Conductor Onboarding.
- I95-59948 SHA-384 and SHA-512 Support: Added support for CNSA 2.0 algorithms SHA-384 and SHA-512 to support US Federal government deployments. For additional information, see
configure-authority-security-hmac-cipher.
- I95-60209 ML-KEM support [FIPS-203]: ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) is a cryptographic protocol used in post-quantum cryptography to securely exchange keys over public channels. This level of protection offers security against both quantum and classical adversaries. On the SSR, ML-KEM can be used alone, or in conjunction with Diffie-Hellman as a hybrid approach to peer-key exchange and encryption. For more information, see Post Quantum Cryptography Support.
- I95-61176 Multicast Failover Optimization: Several internal improvements have been made to improve failover and convergence in both HA and non-HA scenarios for Multicast/PIM, as well as failover times in general.
- I95-63476 Router/Peer path override for
key-exchange-algorithm: A router/peer-path override has been added to enable the transition to a new algorithm within authority. For more information, see Key Exchange Algorithm Router Override.
Resolved Issues
- The following CVEs have been identified and resolved in this release: CVE-2024-56326, CVE-2025-47273, CVE-2025-32415, CVE-2025-58060, CVE-2025-54389, CVE-2021-28651, CVE-2025-54574, CVE-2025-8194, CVE-2025-32462, CVE-2018-10906, CVE-2018-14468, CVE-2021-42574, CVE-2022-24407, CVE-2019-12749, CVE-2021-20277, CVE-2021-4034, CVE-2021-3621, CVE-2024-28956, CVE-2025-53057, CVE-2025-53066, CVE-2025-62168, CVE-2025-11561, CVE-2024-43876, CVE-2024-43877, CVE-2025-22058, CVE-2025-23143, CVE-2025-38678, CVE-2025-39880, CVE-2025-39883, CVE-2025-39885, CVE-2025-39911, CVE-2025-39913, CVE-2025-39923, CVE-2025-39945, CVE-2025-39949, CVE-2025-39953, CVE-2025-39955, CVE-2025-39964, CVE-2025-39967, CVE-2025-39968, CVE-2025-39969, CVE-2025-39970, CVE-2025-39971, CVE-2025-39972, CVE-2025-39973, CVE-2025-39980, CVE-2025-39993, CVE-2025-39994, CVE-2025-39996, CVE-2025-39998, CVE-2025-40001, CVE-2025-40006, CVE-2025-40011, CVE-2025-40018, CVE-2025-40019, CVE-2025-40020, CVE-2025-40021, CVE-2025-40022, CVE-2025-40026, CVE-2025-40027, CVE-2025-40030, CVE-2025-40035, CVE-2025-40042, CVE-2025-40044, CVE-2025-40048, CVE-2025-40049, CVE-2025-40053, CVE-2025-40055, CVE-2025-40070, CVE-2025-40078, CVE-2025-40081, CVE-2025-40085, CVE-2025-40087, CVE-2025-40092, CVE-2025-40094, CVE-2025-40105, CVE-2025-40109, CVE-2025-40111, CVE-2025-40115, CVE-2025-40118, CVE-2025-40120, CVE-2025-40121, CVE-2025-40125, CVE-2025-40134, CVE-2025-40140, CVE-2025-40153, CVE-2025-40154, CVE-2025-40167, CVE-2025-40171, CVE-2025-40173, CVE-2025-40178, CVE-2025-40179, CVE-2025-40183, CVE-2025-40186, CVE-2025-40187, CVE-2025-40190, CVE-2025-40194, CVE-2025-40197, CVE-2025-40200, CVE-2025-40204, CVE-2025-40205, CVE-2025-5987, CVE-2025-11083, CVE-2025-61984, CVE-2025-61985, CVE-2024-5642, CVE-2025-6069, CVE-2025-6075, CVE-2025-8291, CVE-2025-58098, CVE-2025-65082, CVE-2025-66200, CVE-2025-45582, CVE-2024-12087, CVE-2025-64720, CVE-2025-65018, CVE-2025-66293, CVE-2025-40778, CVE-2025-58436, CVE-2025-61915, CVE-2025-14523, CVE-2025-68615, CVE-2025-68973, CVE-2025-61729, CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796.
- I95-57605 BFD link-test-interval not accurate: Resolved as part of I95-59720. Several modifications have been made to the BFD timers to improve accuracy.
- I95-60545 Attempting network interface lookup with invalid ID: Resolved an issue where errors due to an invalid ID were flooding the logs. Error logs in highway regarding a failed interface lookup for an invalid interface are now suppressed.
- I95-61588 Console access failures post-migration: Resolved an issue where a lower baud rate was being used by the serial console, resulting in unreadable output. The check and enforcement for the 115200 baud rate has been improved.
- I95-61823 Change
ESKM_DISABLEDtoESKM_STANDBYfor HA router in standby state: For routers configured as part of an HA Enhanced Security Key Management (ESKM) deployment, the standby state is now correctly identified asESKM_STANDBY.
- I95-61856 Add
reload local certificatescommand for ESKM: Thereload local certificatescommand has been added to allow the updating of local certificates. Seereload local certificatesfor more information.
- I95-62074 Highway requests metadata key when
enhanced-security-key-managementfeature is disabled: Resolved an issue where even whenenhanced-security-key-managementwas disabled, it continued to attempt to get the key information.
- I95-62343 Routers disconnecting from the Conductor while still successfully routing traffic: Resolved an issue where Salt gets stuck with a bad network connection. Added new functionality to the
minion-watchdogservice which will restart thesalt-minionif there is a salt job stuck for over an hour.
- I95-62580 Conflicting network interface names slowing application traffic: Resolved an issue in the app summary tracking logic related to conflicting network interface names for non-redundant ports of an HA router.
- I95-62631 Race condition for multiple dhcp servers startup: Resolved and issue where the multiple DHCP server config change from single DHCP server to multiple DHCP server under the same device interface would stop working. Updates have been made to the monitoring script to identify the changes and prevent the issue.
- I95-62662 SSR4x0 Time not synchronized after reboot: Resolved an issue with the SSR400 and SSR440 where the hardware real time clock (RTC) was not updated after synchronizing with the NTP server. This has been resolved and the time is now fully synchronized. Note that this is an SSR4x0-only issue.
- I95-62772 Add details to
show peers certificateoutput: Theshow peers certificateoutput no longer just shows PEM file output; the data has been rendered in a more friendly format.
- I95-62859 Duplicate alarms created for duplicate asset IDs: Resolved an issue where the Conductor created a duplicate asset ID alarm each time an asset with a duplicate ID tried to authenticate.
- I95-62956 Configuration failure due to service definition expecting subnet mask: Resolved an issue where the Anti-Virus and IDP configuration expected a subnet mask as part of the Service Address. The subnet mask has been added.
- I95-62957 Configuration failure due to invalid name: Anti-Virus and IDP do not allow policy names using a dot (.). This has been resolved — configurations will use an underscore for policy name creation.
- I95-62982 SSR limits the number of supported network-interfaces: Resolved an issue where the limit on the number of network-interfaces was low. Improved implementation of data structure storing network-interface objects, resulting in an increase of 7x the current capacity.
- I95-63018 Memory corruption after reading VSA: Resolved a rare issue where in remote authentication through a RADIUS server, pam_radius was causing memory corruption after a Vendor Specific Attribute (VSA) is read.
- I95-63124 Harden HTTPS security: HTTPS security has been improved and hardened by following best practices. Security headers and SSL algorithms have been updated so that browsers and external clients are only using strong algorithms. Users on older Windows/IE versions can choose to extend the SSR security using
configure authority router <name> system services webserver ssl ciphersto allow older ciphers.
- I95-63190 Router intermittently disconnects from conductor: Resolved an issue where process errors were filling the buffer queue, dropping messages, and causing node disconnections from the Conductor.
- I95-63202 Unable to bind interfaces in Azure F8 flavor in West Europe region: Resolved an issue where driver optimization on lower core count systems required more more memory usage, causing initialization failures.
- I95-63228 Premature route installation complete notification: In some cases a premature internal notification that the route installation was complete was being transmitted, causing the Graceful Restart process to terminate early. This issue has been resolved.
- I95-63292 Add upgrade timeout and rpm operation timeout: Added the ability to configure the timeout for upgrades and for rpm download/install operations under
config authority router <RouterName> system software-update. The defaults are 1 hour for SSR upgrade and 10 minutes for rpm operations.
- I95-63295 Highway crash when show fib is executed on very large FIB: Resolved an issue where a time intensive operation on a large entry was preventing other threads from accessing data and causing a crash.
- I95-63299 Keys signed with ECDSA do not work with Enhanced Security Key Management: Resolved an issue where ECC-based keys fail during the validation process, because the SSR was using hardcoded SHA256 for its signature validation checking. This issue has been resolved.
- I95-63306 Allow RSA keys with ECC signatures on certificates: Resolved an unnecessary restriction between the allowed PKI private key algorithm and the CA signature algorithm. The key is now validated independently from the signature on the certificate.
- I95-63324 Duplicate static DHCP addresses cause crashes: Added validation steps to identify and prevent duplicate MAC addresses for the static address assignment.
- I95-63330 Repeated interface flaps on vSSR led to crash in highway process: Truncated packets are validated prior to processing, preventing crash.
- I95-63353 Invalid assert that leads to a crash: Resolved an issue where an incorrect assertion led to a crash. Protections have been added to prevent the race condition leading to the crash.
- I95-63356 Do not allow new sessions after peer's certificate expired/revoked: Resolved an issue where sessions were one peer continued to send new sessions after the other peers' certificate was revoked. When the peer's certificate expires, the peer is now forced to re-initiate the key exchange.
- I95-63368 SSR400/SSR440 PMTU cannot exceed 8978: Resolved an issue where SSR400/SSR440 PMTU discovery was lower than other platforms. The issue has been resolved, and SSR400/SSR440 PMTU now discovers at 9198.
- I95-63377 HA LEDs not working correctly: On early versions of the SS400 and SSR440 hardware with pre-release builds of the SSR 7.1.3 software, the HA network interface LEDs (on the rear panel) did not function correctly. This issue has been resolved with the general release of the SSR 7.1.3-29-r2 and subsequent release of SSR 7.1.4-3r2 (recommended version). These HA port LEDs now function as documented.
- I95-63412 Glare condition leading to highway crash when session terminates prematurely: Resolved an issue where session exception processing was not handled properly.
- I95-63422 Factory reset routers not re-onboarding when ESKM enabled: Resolved an issue where if ESKM was initially started using invalid certificate on one node, it would be unable to onboard until the remote peering relationship is restarted.
- I95-63675 Node page in the GUI appears to load indefinitely: Resolved an issue where the GUI Node page would load infinitely.
- I95-63676 Waypoints fail to allocate when the
service-path peer next-hop gatewayis off the subnet: Resolved an issue where the first network-interface IP was selected as the local IP for waypoint allocation, even if that IP is not a valid waypoint.
- I95-63729 Asset state not accurately reported in conductor: Resolved an issue where issue where the SSH authorized keys from one HA conductor node were deleted after restarting both HA conductor nodes.
- I95-63817 Default peering certificates are unable to use the configured peering-common-name: Resolved an issue where the default peering certificates were generated before receiving the configuration. The default generated peering certificate now properly uses the
peering-common-nameSSR configuration element.
- I95-63873 DHCP leases not showing in Conductor UI: Resolved an issue where attempting to retrieve DHCP v4 leases via the Conductor UI for a specific router results in
no leases found. Also resolved an issue where viewing a router Logs page via the Conductor UI displayed ALL logs rather than using the selected time range.
- I95-63923 Redundant conductor fails to upgrade: Resolved an issue where a minion disconnects from the conductor node and never attempts to reconnect. The minion watchdog process now restarts the salt minion if it is not connected to all conductor nodes.
- I95-63943 Edge-case crash when changing from regular services to app-id: Resolved an issue where a system that never had app-id services or had app-id services, reverted them and restarted the highway process; and then modified an existing service to use app-id caused a crash. Protections have been added to safeguard against this edge case.
- I95-64066 Race condition when syncing SSH keys to the peer node: Resolved an issue where SSH keys were not synced between peer nodes automatically by the Conductor.
Caveats
- I95-64317 Dropped Packets Capture continues to run: If you have initiated a packet Capture from any page in the GUI, it will continue to run on the web server even after the request is terminated, resulting in expensive per packet export overhead. The web server must be restarted to terminate the packet capture. This issue is under investigation and will be resolved in an upcoming release.
-
I95-64407 Alternate SHA ciphers (256/384/512) not working properly with ESKM: SSR 7.1.3 introduces
sha384andsha512as configurable options for thehmac-cipherfield on security policies, alongside a new internal data structure that tracks metadata keys per HMAC mode and cipher combination.In deployments with peers running different versions of software and sharing security policies, configuring
hmac-cipher sha384orhmac-cipher sha512in a fabric where any peer has not yet been upgraded to 7.1.3, those older versions of software will not recognizehmac-cipher sha384orhmac-cipher sha512. These devices will continue to runsha-256-128. Currently, no alarm or warning will be generated, and there is no performance impact.
Release 7.1.0-50r1
Release Date: December 4, 2025
New Features
- I95-34739 SSR400 and SSR440 Factory reset: The SSR4x0 devices provide the ability to reset the device to either a pre-defined rescue (or Golden) configuration, or a secure zeroization of the system and a return to the factory default configuration. For more information, see Factory Reset.
- I95-44742 SFP Optical interface transceiver stats: Support has been added to display optical interface transceiver stats in the CLI. Issuing the
show device-interface node all name <interface> optics-statisticswill display information for debugging and diagnostic information from network transceiver modules (SFP, SFP+, QSFP, etc.). It displays optical power levels, vendor information, and hardware thresholds for monitoring physical layer connectivity.
- I95-53402 SSR400/SSR440 Chassis Manager: The SSR400 and SSR440 support an integrated Chassis Manager to help monitor connectivity, power, temperature, as well as providing insight into other vital operational data. For more information, see the SSR Chassis Manager.
- I95-53405 5G modem support: Support for 5G modems as provided in the SSR400 and SSR440 devices has been added.
- I95-54238 Uninterruptible Boot Process: When the uninterruptible boot process is configured, a failed upgrade will not allow the user to select the image on the other volume (since the Console port is disabled, no user input is possible). For more information, see the Uniterruptable Boot Process.
- I95-54244 Secure Boot: The SSR400 and SSR440 are factory configured with a cryptographic public key that only allows an authenticated firmware image to run on the device. This ensures that only trusted (Juniper-signed) code will run from power-on through to linux OS boot. For additional information, see Secure Boot.
- I95-55746 Connection to Mist via proxy server/Support Mist Secure ZTP Onboarding: Support has been added to allow a connection to a public URL or to MIST using an explicit proxy and a private web proxy. See Proxy Server Configuration for information to configure the SSR to identify and use the non-transparent proxy. For information about the secure ztp process using Mist, see Secure ZTP Onboarding Using a Mist Proxy.
- I95-55936 Alarm and Events when service area hits threshold: Support has been added to allow users to configure alarms thresholds to monitor session processing capacity, and provide visibility into the system’s capacity to establish new sessions. For more information, see Session Processing Alarms.
- I95-57174 DCSP Steering - UDP/TCP destination port: With SSR version 7.1.0, the restriction for matching ports has been lifted, and support has been added for DCSP steering over non-IPSEC tunnels. For more information, see DSCP Steering Using GTP.
- I95-58502 Disable on box management ports: Configuration fields have been added to the SSR400 and SSR440 devices, allowing you to control physical security features. For more information, see Disable SSR400 and SSR440 Management Interfaces.
- I95-59235 HTTP/S proxy server for all public URLs: Support has been added to allow a connection to a public URL or to MIST using an explicit proxy and a private web proxy. See Proxy Server Configuration for information to configure the SSR to identify and use the non-transparent proxy. This process can also be used to support the Mist secure ZTP onboarding process.
Resolved Issues
- The following CVEs have been identified and resolved in this release: CVE-2024-3651, CVE-2024-56171, CVE-2025-24928, CVE-2024-11187, CVE-2024-1737, CVE-2024-1975, CVE-2024-3596, CVE-2024-37370, CVE-2024-37371, CVE-2025-24528, CVE-2023-46846, CVE-2024-45802, CVE-2024-12085, CVE-2023-26604, CVE-2024-7347, CVE-2025-23419, CVE-2024-43842, CVE-2024-40906, CVE-2024-44970, CVE-2025-21756, CVE-2022-49011, CVE-2024-53141, CVE-2025-21587, CVE-2025-30691, CVE-2025-30698, CVE-2024-0727, CVE-2023-5678, CVE-2024-5535, CVE-2024-9143, CVE-2024-13176, CVE-2016-9840, CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4435, CVE-2025-4517, CVE-2025-32462, CVE-2025-5702, CVE-2025-5702, CVE-2025-4802, CVE-2025-6020, CVE-2025-47268, CVE-2025-25724, CVE-2025-3576, CVE-2025-47273, CVE-2024-23337, CVE-2025-48060, CVE-2023-52572, CVE-2023-52621, CVE-2023-52757, CVE-2024-26686, CVE-2024-26739, CVE-2024-26952, CVE-2024-27402, CVE-2024-35790, CVE-2024-35866, CVE-2024-35867, CVE-2024-35943, CVE-2024-36350, CVE-2024-36357, CVE-2024-36908, CVE-2024-38540, CVE-2024-38541, CVE-2024-42160, CVE-2024-42322, CVE-2024-44938, CVE-2024-46742, CVE-2024-46751, CVE-2024-46774, CVE-2024-46784, CVE-2024-46816, CVE-2024-49960, CVE-2024-49989, CVE-2024-50047, CVE-2024-50125, CVE-2024-50258, CVE-2024-50272, CVE-2024-50280, CVE-2024-53128, CVE-2024-53185, CVE-2024-53203, CVE-2024-54458, CVE-2024-56551, CVE-2024-56599, CVE-2024-56655, CVE-2024-56658, CVE-2024-56751, CVE-2025-21681, CVE-2025-21839, CVE-2025-21853, CVE-2025-22027, CVE-2025-22062, CVE-2025-23140, CVE-2025-23142, CVE-2025-23144, CVE-2025-23145, CVE-2025-23146, CVE-2025-23147, CVE-2025-23148, CVE-2025-23150, CVE-2025-23151, CVE-2025-23156, CVE-2025-23157, CVE-2025-23158, CVE-2025-23159, CVE-2025-23161, CVE-2025-23163, CVE-2025-37738, CVE-2025-37739, CVE-2025-37740, CVE-2025-37741, CVE-2025-37742, CVE-2025-37749, CVE-2025-37752, CVE-2025-37756, CVE-2025-37757, CVE-2025-37758, CVE-2025-37765, CVE-2025-37766, CVE-2025-37767, CVE-2025-37768, CVE-2025-37770, CVE-2025-37771, CVE-2025-37773, CVE-2025-37780, CVE-2025-37781, CVE-2025-37787, CVE-2025-37788, CVE-2025-37789, CVE-2025-37790, CVE-2025-37792, CVE-2025-37794, CVE-2025-37796, CVE-2025-37797, CVE-2025-37803, CVE-2025-37805, CVE-2025-37808, CVE-2025-37810, CVE-2025-37812, CVE-2025-37817, CVE-2025-37819, CVE-2025-37823, CVE-2025-37824, CVE-2025-37829, CVE-2025-37830, CVE-2025-37836, CVE-2025-37838, CVE-2025-37839, CVE-2025-37840, CVE-2025-37841, CVE-2025-37844, CVE-2025-37850, CVE-2025-37857, CVE-2025-37858, CVE-2025-37859, CVE-2025-37862, CVE-2025-37867, CVE-2025-37875, CVE-2025-37881, CVE-2025-37883, CVE-2025-37885, CVE-2025-37890, CVE-2025-37892, CVE-2025-37905, CVE-2025-37909, CVE-2025-37911, CVE-2025-37913, CVE-2025-37914, CVE-2025-37915, CVE-2025-37923, CVE-2025-37927, CVE-2025-37929, CVE-2025-37930, CVE-2025-37940, CVE-2025-37949, CVE-2025-37967, CVE-2025-37969, CVE-2025-37970, CVE-2025-37982, CVE-2025-37983, CVE-2025-37985, CVE-2025-37989, CVE-2025-37990, CVE-2025-37991, CVE-2025-37992, CVE-2025-37994, CVE-2025-37995, CVE-2025-37997, CVE-2025-37998, CVE-2025-38005, CVE-2025-38009, CVE-2025-38023, CVE-2025-38024, CVE-2025-38031, CVE-2025-38089, CVE-2025-7425, CVE-2025-32414, CVE-2025-32415, CVE-2025-27151, CVE-2025-32023, CVE-2025-48367, CVE-2025-49133, CVE-2025-6965, CVE-2025-5222, CVE-2025-4373, CVE-2024-52533, CVE-2024-6174, CVE-2025-5994, CVE-2024-52615, CVE-2025-40909, CVE-2022-29458, CVE-2024-47081, CVE-2025-6965, CVE-2025-8058, CVE-2025-30749, CVE-2025-30754, CVE-2025-30761, CVE-2025-50106, CVE-2025-5914, CVE-2025-54389, CVE-2025-7425, CVE-2025-8194, CVE-2025-48964, CVE-2025-53905, CVE-2025-53906, CVE-2025-58060, CVE-2025-58364, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990, CVE-2025-6395, CVE-2023-49083, CVE-2024-47252, CVE-2025-23048, CVE-2025-49812, CVE-2020-11023, CVE-2025-5318, CVE-2025-6021, CVE-2025-32414 ,CVE-2025-49794, CVE-2025-49796, CVE-2025-49844, CVE-2023-4752, CVE-2023-6693, CVE-2024-12797, CVE-2024-25742, CVE-2024-25743, CVE-2024-25744, CVE-2024-28956, CVE-2024-3567, CVE-2024-52616, CVE-2024-55549, CVE-2024-56583, CVE-2024-8176, CVE-2024-8508, CVE-2025-21605, CVE-2025-2784, CVE-2025-31498, CVE-2025-32049, CVE-2025-32050, CVE-2025-32052, CVE-2025-32053, CVE-2025-32906, CVE-2025-32907, CVE-2025-32911, CVE-2025-32913, CVE-2025-32914, CVE-2025-4598, CVE-2025-46420, CVE-2025-46421, CVE-2025-4948.
- I95-39653 Negative duration in session table after applying filter: Resolved an issue where applying a filter to the session table resulted in sessions displaying a negative duration.
- I95-57019 KNI host interfaces erroneously generate LLDP: Resolved an issue where host KNI interfaces are incrementally generating out-errors in
show device-interface.
- I95-58007 Add ability to set PIM graceful restart-time: The
routing default-instance pim restart-timecommand has been added to allow users to define the number of seconds that the PIM protocol will performgraceful-restartafter a node failure. This resolution addresses all the listed issues. For more information, see PIM Graceful Restart Timer. This also addresses I95-57702, I95-57906, I95-60637, and I95-60731.
- I95-60767
service-route > next-hopvalidation rejects configuration: Resolved an issue where the rule validator did not consider the service application-type as DNS proxy during the configuration rule validation. This issue has been resolved.
- I95-60799 Tenant prefix use within a VRF: The SSR allows the configuration of tenant-prefixes without giving an error, and correctly handles interfaces with tenant-prefixes within the protocol code.
- I95-61058 Peer paths fail when additional IPs are added to a WAN interface: Resolved a case where adding a second address for use in nat-pools to a peering interface caused continuous bfd peer flaps. The SSR now handles address changes when the local IP address changes.
- I95-61075 BGP does not re-establish after firewall failover: Resolved an issue where when initiating a BFD for BGP session, the cached MAC to IP mapping was being used. If the MAC address had changed, stale information was used and the BFD session would not be established. We now issue an ARP request to get the latest MAC Address.
- I95-61093 Router first time synchronization: Resolved an issue where a minion is restarted multiple times during the first connection to the conductor, resulting an extended wait time before synchronization.
- I95-61453 'mist' user missing from '128t-user' group at login: Resolved an issue that prevented the modification of lock files causing the process responsible for managing user permissions to fail.
- I95-61580 CLI does not prompt for required router restart: Resolved an issue where making a configuration change requiring a restart only generates a warning only for the router that the PCLI is running on. Committing a configuration change that requires a restart now results in a warning even when the change is on a different router.
- I95-61866 Unnecessary events sync: Resolved an issue where data is unintentionally sync'ed between HA nodes.
- I95-61869 Peer paths not coming back up after manual reboot: Resolved an issue with the control message capacity. In configurations with more than 1000 VLANs, the aggregate size of all the control messages grew larger than the space allocated for the messages, and messages failed to send and some packet processing threads were left with incomplete interface tables. The capacity to handle these messages has been increased and can now handle up to 12,000 VLANs.
- I95-61910 FIPS installation failure: Resolved an issue where package renaming resulted in missing installation files.
- I95-61999 ATT SIM card MNC code update: Resolved an issue with the ATT SIM card using an unexpected MNC code.
- I95-62011 Stats from adjacency traffic engineering throw an exception when a hostname is used: Resolved an issue where dynamic reconfiguration when adding neighbors/adjacencies that use an FQDN and have adjacency Traffic Engineering enabled, caused the device interface to reach a failure state.
- I95-62071 Multicast Traffic contributing to service area resource contention: Resolved an issue when an mroute has no outgoing interfaces. A Detour Path is now used instead of NoServicePaths to prevent resource contention.
- I95-62179 Software Lifecycle History not up to date: Resolved an issue where the software lifecycle page was not showing any history, or in some cases, the history was outdated. Internal functionality has been updated, and both the GUI and CLI outputs now show the correct information.
- I95-62258 Packet steered to egress non-existent interface causes highway crash: Added logic to capture the errant packet and prevent the crash. An exception is logged so that the issue can be more easily rectified.
- I95-62369 Session error record shows 0s for session-id: Resolved an issue where the session record information was incomplete. The SSR now also uses the redundancy session data to gather records.
- I95-62449 HA conductor fails to initialize secondary node: Resolved an issue with password validation that was preventing the secondary node from accessing the primary node to download files needed for initialization. The user is now prompted to enter the new password for the primary node when setting up the secondary node.
- I95-62695 Management interface placed in incorrect zone during conductor onboarding: Resolved an issue where an earlier change did not put the management infterface in the t128 zone.
- I95-62703 Highway process crashed when BGP over SVR is activated: Resolved an issue where the unicast code path was incorrectly calling the multicast variant of getBestMultiHomedPathIndex() and causing a highway crash.
- I95-62742 Cannot see sync errors for nodes that are stuck synchronizing: Resolved an issue where errors in
show assetsdisappeared when the synchronizing state retries.
- I95-63334 HA node failover causing mismatched node IDs: Resolved an issue where where Enhanced Security Key Management security exchange state may get stuck on HA node failover.
Caveats
- I95-63422 Factory reset routers not re-onboarding when ESKM enabled: Resolved an issue where if ESKM was initially started using invalid certificate on one node, it would be unable to onboard until the remote peering relationship is restarted.