SSR 7.1 Release Notes
The SSR has moved away from the historical package-based delivery to an image-based delivery. As such, it is strongly suggested that you revisit your "standard" procedures for installation and upgrade of SSR Software.
Beginning with SSR v6.3.0, the use of the interactive installer is not supported, or necessary. Software installation and upgrade activities are supported from the Web Interface or the Command Line Interface.
With the image-based ISO delivered beginning with version 6.3.0, the manual installation process no longer supports the initialize128t command.
Initializing devices as a conductor or conductor-managed router is easily accomplished from the GUI using the Initialize Your Device - Web Workflow, or from the CLI using the the initialize conductor and initialize conductor-managed commands described in the Initialize Your Device - Advanced Workflow documentation.
Installation from ISO
When installing SSR V6.3.0 or newer on a new system, use the image-based ISO - identified by the filename prefix "SSR": SSR-6.3.0-107.r1.el7.x86_64.ibu-v1.iso. Installation documentation for the image-based process can be found in the Image-based ISO Installation Overview.
Offline mode conductor and router upgrades to image-based installations are detailed in the Single-Version 6.3.0 Upgrade instructions.
Upgrade Considerations
Before upgrading please review the Upgrade Considerations and the Rolling Back Software pages. Several modifications have been made to the process for verifying configurations, which will impact existing configurations.
After installing / upgrading to SSR 7.1.3, downgrading to an earlier version of SSR software where Configuration Integrity (CI) is not available is NOT supported.
Rollback to the previously installed version of software is supported.
An issue has been identified involving the use of the HA Sync Redundancy Plugin with SSR 7.0.0, which prevents proper functioning of the plugin. If you use the HA Plugin in your SSR deployment, it is not advised to upgrade at this time. The issue is being investigated and will be resolved in a future release.
7.0.1 Conductor Upgrades
If you are upgrading a conductor that is currently installed with version 6.3.4 or lower, and you wish to upgrade to version 7.0.1 or higher, you must first upgrade the conductor to any version of the 6.3.x software, including and higher than 6.3.5.
Routers running SSR software versions earlier than 6.3.5 cannot connect to conductors running SSR software version 7.0.1 and higher. A transitional step is required to enable routers running versions earlier than 6.3.5 (6.0.x, 6.1.x, 6.2.x, 6.3.4 and lower) to communicate with a conductor running 7.0.1+.
- Upgrade the conductor to any version of the 6.3.x software, including and higher than 6.3.5.
- Upon completion of the install, allow all managed routers to connect and reach the Synchronized state. The new keying requirements that are part of 6.3.5+ are loaded onto the routers during synchronization. These are required for routers to communicate with a 7.0.1+ conductor. If the routers do not reach the synchronized state, those routers will not be able to communicate with the 7.0.1+ conductor.
- Once the routers are synchronized, you may upgrade the conductor to 7.0.1. All synchronized routers, regardless of version, will be able to communicate with the upgraded conductor. The routers are not required to upgrade to 7.0.1 or to 6.3.5.
If your conductor is currently running SSR version 6.3.5+, you may upgrade to 7.0.1 normally.
VM Upgrades 6.2.x to 7.x
Users upgrading a virtual machine, including those on AWS or Azure, previously installed with package-based SSR releases (6.2 and prior on Conductor-managed deployments only) should be aware of the following:
Due to changes in the base SSR/Linux OS in 7.X, interface naming behavior has changed for virtual machines. Older SSR versions using earlier versions of the SSR OS may have named Linux interfaces with the ethX naming convention. Interfaces in 7.X and above use the Linux predictable interface naming convention as seen in SSR hardware installs. This change in interface naming could prevent existing Linux interface configurations not to apply to the ethX-named interface. This applies to interfaces configured directly in Linux, such as dedicated management interfaces, and not interfaces configured via SSR configuration.
This issue is currently being addressed by engineering. However, if your deployment requires an upgrade to 7.X on a VM configured with interfaces using the ethX naming convention, please ensure that console access is available, as manual updates to the Linux interface configuration may be required.
System Disk Considerations
As mentioned above, during the upgrade to an image-based installation, existing systems will go through a conversion process to support image-based delivery. This process involves resizing the existing disk partition to support writing a new disk image to the remaining disk space. As such, the usable disk space seen after this conversion will be approximately halved. The system will automatically detect if there is not enough usable disk space on the existing drive to support this partition resizing and, if so, will trigger an upgrade failure. Even if the conversion is successful and the upgrade succeeds, users may note that the system is experiencing disk space alarms after the upgrade due to the reduction in overall capacity. It is suggested to remove unnecessary large files from systems before upgrading. Old saved tech-support-info archives (check for tar.gz or zip files in /var/log/128technology) and uploaded ISO images are frequent contributors to used disk space and should be manually deleted.
In certain scenarios, existing cloud routers may have been installed from images that did not use LVM for partitions. For these systems, the automatic resizing of disk partitions will fail and they cannot be upgraded. It is suggested to rebuild these instances from the official SSR BYOL image for either AWS or Azure.
When the conductor is initially upgraded to an image-based installation, it will be upgraded as a package-based system. This is because the system does not understand how to handle image-based delivery until it is running 6.3 software. Once the conductor is running 6.3 all router upgrades will be treated as image-based upgrades and any subsequent conductor upgrade will be treated as image-based. Therefore, it is possible that issues related to disk usage on conductor may not arise until a subsequent upgrade of the conductor beyond the initial step to 6.3.
Offline-Mode: Upgrading 6.3.x Conductor Deployments to 6.3.x+
An issue has been identified that may be observed in conductor deployments running version 6.3.x software, when attempting to upgrade from one 6.3.x patch release to another. This results in the message, “SSR firmware upgrade failed for the local node: SSR upgrade failed after reboot”. To work around this, run request system software upgrade installation-service from the command line of the Conductor, after importing the image-based ISO. Once complete, perform the full system upgrade from the Web interface. This issue will be resolved in a future release.
Offline-Mode: Onboarding Routers Running older SSR Software to a 6.3.x Conductor
An issue has been identified when onboarding SSR routers installed with older versions of software (such as 5.4.4) to Conductors running 6.3.x, when running in offline-mode. In some cases, certain software packages are not available to be installed during onboarding. To work around this issue, import the package-based (the "128T" prefixed) ISO for the current conductor version onto the conductor. This provides the necessary software packages to complete the onboarding process. This issue will be resolved in a future release.
Release 7.1.6-7-sts
Release Date: July 15, 2026
New Features
- I95-62868 Multicast Failover Optimizations / PIM GR: Additional improvements to multicast failover and convergence times for PIM Graceful Restart. These optimizations reduce traffic loss during HA and non-HA failover events for multicast traffic.
- I95-63012 AppID Scale Optimization: Improved application identification performance and scale for WAN deployments. Optimizations reduce resource consumption on spoke routers where application identification is enabled by default, improving capacity under high traffic loads.
Resolved Issues
- The following CVEs have been identified and resolved in this release: CVE-2023-40403, CVE-2025-9230, CVE-2025-12084, CVE-2025-13601, CVE-2025-14087, CVE-2025-14512, CVE-2025-61662, CVE-2025-67873, CVE-2025-68114, CVE-2025-68973, CVE-2026-1519, CVE-2026-3497, CVE-2026-4111, CVE-2026-4424, CVE-2026-4519, CVE-2026-4786, CVE-2026-4878, CVE-2026-5119, CVE-2026-5121, CVE-2026-6100, CVE-2026-9256, CVE-2026-21710, CVE-2026-25646, CVE-2026-25749, CVE-2026-26996, CVE-2026-27135, CVE-2026-27651, CVE-2026-27654, CVE-2026-27784, CVE-2026-27904, CVE-2026-28417, CVE-2026-28421, CVE-2026-29111, CVE-2026-31431, CVE-2026-32647, CVE-2026-32748, CVE-2026-33412, CVE-2026-33416, CVE-2026-33526, CVE-2026-33636, CVE-2026-34982, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414, CVE-2026-35535, CVE-2026-39979, CVE-2026-40164, CVE-2026-40460, CVE-2026-40701, CVE-2026-41242, CVE-2026-42926, CVE-2026-42934, CVE-2026-42945, CVE-2026-42946, CVE-2026-43284, CVE-2026-43500, CVE-2026-46300, CVE-2026-46333.
- The following issues have been addressed and delivered to increase the overall security posture of the SSR: I95-62091, I95-65017, I95-65018, I95-65019, I95-65028, I95-65030, I95-65039, I95-65054, I95-65055, I95-65080, I95-65206, I95-65210, I95-65211, I95-65219, I95-65221, I95-65222, I95-65224, I95-65225, I95-65237, I95-65238, I95-65247, I95-65249.
- I95-60912 PIM and PIMv6 cannot be enabled on the same interface: Resolved an issue where enabling both PIM (IPv4) and PIMv6 on the same interface was not possible, preventing dual-stack multicast configurations.
- I95-63033
show lte detailcrash when LTE apn-name is invalid: Resolved an issue where executingshow lte detailwhen an invalid APN name is configured caused a CLI crash due to an unhandled dictionary update error.
- I95-63035 Antivirus warning when missing tenant for AV traffic: Resolved an issue where an antivirus alert was incorrectly raised on the passive node in an HA system, indicating AV was not active.
- I95-63876 Route Flapping and Inaccessibility: Resolved an issue where routes would flap or become inaccessible in hub-and-spoke topologies with inter-hub steering preferences configured, causing intermittent connectivity failures.
- I95-63895 SSR sending packets larger than configured MTU: Resolved an issue where the SSR was sending packets larger than the configured MTU (e.g., 1518 bytes instead of 1500), causing packet drops on downstream network elements.
- I95-63913 Session-source incorrect in BFD pinhole: Resolved an issue where session-source was incorrectly set to public when a BFD pinhole also happened to be a flow-move scenario.
- I95-63951 BGP Graceful Restart Sending EOR Prematurely: Resolved an issue where the SSR sent End-of-RIB (EOR) markers prematurely during BGP graceful restart, without waiting to receive EOR from its peers as required by RFC 4724, potentially causing route convergence issues.
- I95-63965 SNMP MIB subinterfaces not reporting correct stats: Resolved an issue where SNMP MIB walks on subinterfaces were not reporting correct statistics, causing inaccurate monitoring data in network management systems.
- I95-64061 Azure kernel hung task after upgrade: Resolved an issue where Azure VMs could experience a kernel hung task condition related to the
uio_hv_genericdriver after upgrading to 7.1.3.
- I95-64150 User-defined SNMP metrics not working: Resolved an issue where custom SNMP metric MIBs were not functioning correctly after upgrading to 7.1.3, preventing SNMP-based polling systems from collecting metrics.
- I95-64250 BGP routes received but not installed in RIB: Resolved an issue where BGP routes were received from peers but not installed in the BGP table or the routing information base (RIB), preventing traffic from using those routes.
- I95-64306 Optimize ICMP probe profile update on config change: Resolved an issue where configuration changes that contained no actual ICMP probe modifications still triggered a full restart of all ICMP probes, causing unnecessary overhead and brief monitoring gaps.
- I95-64344 Extended multicast traffic loss with PIM GR not being used: Resolved an issue where PIM Graceful Restart was not properly engaged during HA failover, resulting in extended multicast traffic loss instead of seamless failover.
- I95-64397 Cosmetic error message on SSR1500: Resolved an issue where a harmless but misleading
systemd-rc-local-generatorerror message was displayed on the SSR1500 console, which could cause unnecessary alarm during routine operations.
- I95-64407 Alternate SHA ciphers (256/384/512) not working properly with ESKM: Resolved an issue introduced in 7.1.3 where configuring
hmac-cipher sha384orhmac-cipher sha512on security policies did not properly apply in deployments with peers running different software versions. These ciphers now function correctly when all peers are upgraded to a version that supports them.
- I95-64408 TCP timers used for syslogs not set or too relaxed: Resolved an issue where TCP keepalive timers for syslog connections were either not set or configured with excessively long intervals, resulting in stale connections not being detected and syslog failover not triggering in a timely manner.
- I95-64411 IPv6 BGP route-map
set ipv6 next-hop peer-addresssupport: Added support for theset ipv6 next-hop peer-addressdirective in route-maps, which is required for IPv6 WAN assurance deployments.
- I95-64434 IDP bypass
alertpolicy not working: Resolved an issue where setting the IDP bypass policy toalertmode was not functioning correctly, preventing traffic from being properly inspected and alerts issued.
- I95-64479 Invalid application WEBEX not recognized: Resolved an issue where the WEBEX application was not being recognized by the application identification module after an upgrade, resulting in
invalid applicationevents and missing FIB entries for the associated service.
- I95-64541 Node disconnection during upgrade: Resolved an issue where upgrading HA router nodes could result in one node entering a disconnected state with stale SSH control sockets, while the other node became stuck in the upgrading state, requiring a manual reboot to recover.
- I95-64549 Onboarding routers cannot install salt packages: Resolved an issue where routers being onboarded to a conductor could not install the required salt packages, preventing successful onboarding completion.
- I95-64566 CSR generation ignores camelCase parameters: Resolved an issue where the certificate signing request (CSR) API silently ignored camelCase parameter names (e.g.,
commonNameinstead ofcommon_name).
- I95-64575 Unable to login to SSR routers from conductor in cloud deployment: Resolved an issue where the SSH configuration on cloud-deployed routers disabled password authentication, preventing login from the conductor.
- I95-64603 Chronyd requires manual restart after reboot: Resolved an issue where all NTP servers appeared as rejected after a reboot, requiring a manual restart of chronyd to restore time synchronization.
- I95-64619 Config validation rejects DHCP network-interface when VRRP is present: Resolved an issue where configuration validation incorrectly rejected DHCP-enabled network-interfaces when VRRP was configured on the same interface, even if VRRP was not enabled.
- I95-64627 Certificate Unavailable for Peering After Upgrade: Resolved an issue where the local certificate became unavailable for peering after an upgrade, resulting in peer paths remaining down with a
No local certificate availableerror.
- I95-64684 HMAC cipher mode information in logs and session output: Added HMAC mode and cipher information to session logs and
show sessionsoutput, improving visibility into the encryption parameters used for active sessions.
- I95-64696 Salt connectivity issues after Conductor upgrade: Resolved an issue where salt-minion lost connectivity to the salt-master after a Conductor upgrade, affecting approximately 20% of routers. The minion-connector service now correctly manages the salt master address.
- I95-64709 BGP stale-routes-time and Selection Deferral Timer alignment: Resolved an issue where the
stale-routes-timeparameter behavior did not properly align with RFC 4724's Selection_Deferral_Timer semantics, potentially causing premature route selection during graceful restart.
- I95-64732 Update
show peers certificatedate format: Updated theshow peers certificatecommand to use a newer API for certificate date rendering, providing a more user-friendly output format.
- I95-64811 Highway crash causing session drops: Resolved a highway process crash that occurred under specific traffic conditions, resulting in session drops and temporary traffic disruption.
- I95-64829 Device disconnected from Mist and stopped processing sessions: Resolved an issue where a device could disconnect from Mist and stop processing sessions after a configuration push, requiring a power cycle to recover.
- I95-64835 Remove UI checkbox for Rollback on Failure during Conductor migration: Removed the erroneous
Rollback on Failurecheckbox from the Conductor migration UI, as the underlying feature was never implemented. This prevents user confusion during migration operations.
- I95-64876 Intermittent application issues due to child service design: Resolved an issue where hierarchical service configurations with child services could intermittently fail to match traffic correctly, causing application connectivity issues.
- I95-64877 Changes to guard against L7 security stack crash: Resolved an issue where the IDP attack database was lost on reboot. The database is now stored persistently, and additional safeguards have been added for AV engine health checks, SSL certificate staging retries, and error code accuracy.
- I95-64903 High CPU and disk usage on standalone SSR440: Resolved an issue where a standalone SSR440 could experience high CPU utilization and disk usage under certain operational conditions, impacting device performance.
- I95-64905 401 Authorization Required error when refreshing Logs page: Resolved an issue where refreshing the Logs page on the conductor GUI returned a 401 Authorization Required error, requiring a full page reload or re-login.
- I95-64929 Peer certificate expiration time unit conversion error: Resolved an issue where a seconds-to-milliseconds conversion error caused premature peer certificate expiration.
- I95-64977 Certificate ingestion ignores expiry and revocation validation: Resolved an issue where ingesting a certificate did not properly validate its expiry date or revocation status, allowing expired or revoked certificates to be accepted.
- I95-64997 SYSLOG SEIM Integration Not Sending Failed Session Attempts: Resolved an issue where the SYSLOG SEIM integration did not send log events for ERROR/FAILED session attempts (dropped packets), limiting visibility into denied traffic.
- I95-65056
show app-id cache-sizescommand not found: Resolved an issue where theshow app-id cache-sizescommand was missing from the CLI, preventing users from inspecting application identification cache utilization.
- I95-65099 Traffic engineering stats displaying incorrect output: Resolved an issue where
show stats traffic-eng internal-application per-traffic-classdisplayed incorrect or unexpected output.
- I95-65128 nodeMonitor crash loop on hub node: Resolved an issue where the nodeMonitor process entered a continuous crash loop on hub nodes during conductor-based Hub-and-Spoke setup, preventing the hub from becoming operational.
- I95-65131 CPS performance degradation: Resolved a performance regression that caused approximately 10% reduction in connections-per-second (CPS) throughput.
- I95-65171 TSI Download Missing File Extension: Resolved an issue where Tech Support Info (TSI) bundles downloaded from the SSR Web UI had no file extension, preventing extraction with standard archive tools. Tech support files downloaded from the web UI now have the correct
.zipextension.
- I95-65296 ESKM peering failures with fragmentation: Resolved an issue where ESKM peering connections failed when packet fragmentation occurred on the path between peers, preventing secure peer relationships from establishing.
- I95-65299 SSR440 upgrade from 7.1.0 to 7.1.5 failure: Resolved an issue where upgrading an SSR440 from 7.1.0 to 7.1.5 could fail, with the highway process not running after reboot, causing the system to roll back automatically.
- I95-65336 Factory reset resilience to interruption: Improved the factory reset procedure to be more resilient to interruption (e.g., unexpected reboot). The system now tracks reset progress and can resume or indicate completion status after recovery.
- I95-65351 IMA and security incompatibility preventing engine start: Resolved an issue where IMA (Integrity Measurement Architecture) validation conflicted with IDP security features, preventing the SSR engine from starting after upgrade.
- I95-65354 Missing dependencies in offline ISO: Resolved an issue where certain package dependencies were missing from the offline ISO, preventing successful package installation in air-gapped environments.
- I95-65366 Maximum GARP interval for VRRP: Added a configurable
maximum-garp-intervalparameter for VRRP, allowing control over how frequently gratuitous ARP messages are sent during VRRP state transitions. This prevents excessive ARP traffic in environments with many VRRP instances.
- I95-65374 Child tenants not applied to security policies: Resolved an issue where child tenants were not correctly applied to security policies, preventing IDP rules from being enforced on traffic matching child tenant definitions.
- I95-65392 Hierarchical services ping traffic failure between sites: Resolved an issue where ICMP ping traffic between specific sites failed when using hierarchical service configurations with application identification groups (AIG).
- I95-65393 ESKM Certificate Invalid Alarm After Upgrade: Resolved an issue where a certificate invalid alarm was incorrectly raised after upgrading to a newer SSR version, causing peering to go down even though the certificate was not expired.
- I95-65403 Disallow CA certificates from being used for peering: Added validation to prevent CA certificates (those with
CA:Truein basic constraints) from being used as peering certificates, which would cause unexpected trust chain behavior.
- I95-65410 Incorrect RBAC requirements for certificate API: Resolved an issue where the POST
/api/v1/certificateendpoint required READ permission for the entire configuration instead of WRITE permission, allowing unintended access.
- I95-65411 CLI Command Appending Unrelated Output: Resolved an issue where executing certain PCLI commands (such as
show peer router all force) would append unrelated command output at the end of the expected results.
- I95-65414 Overlapping child tenant IP validation: Added configuration validation to disallow overlapping IP addresses across child tenants, preventing ambiguous traffic classification.
- I95-65431 SSR failing to sync with NTP server: Resolved an issue where the SSR failed to synchronize with configured NTP servers after boot, requiring manual intervention to restore time synchronization.
- I95-65432 Conflux process crash during upgrade: Resolved an issue where the Conflux process exited unexpectedly during or after an upgrade, causing temporary loss of analytics data collection.
- I95-65439 CRL in certificate not taken into account: Resolved an issue where the CRL distribution point embedded in a certificate was not being used for revocation checking, requiring manual CRL configuration on the conductor.
- I95-65455 Network Manager interface preventing HA sync: Resolved an issue where a spurious "Wired Connection" entry in Network Manager could prevent HA sync interfaces from obtaining IP addresses after an upgrade.
- I95-65459 IDP bypass not engaged during restart/rebuild: Resolved an issue where IDP bypass rules were not properly engaged during engine restart or rebuild operations, causing traffic that should be bypassed to be dropped temporarily.
- I95-65469 GUI not showing Network Interfaces: Resolved an issue where the GUI no longer displayed Network Interfaces on the device page, while Device Interfaces remained visible.
- I95-65470 Multicast session display count discrepancy: Resolved an issue where
show sessionsdisplayed fewer multicast sessions than expected (e.g., 334 of 400), even though all multicast routes were correctly installed.
- I95-65486 Highway crash during upgrade from older versions: Resolved a highway crash that could occur during router upgrades from significantly older software versions (e.g., 5.5.x to 7.x).
- I95-65529 Auto-generated syslog service incorrectly uses UDP for TLS: Resolved an issue where the auto-generated service for TLS-based syslog was incorrectly configured with UDP as the transport protocol instead of TCP.
- I95-65548 DSCP steering support with deferred classification in hierarchical services: Added support for DSCP steering services when classification is deferred in hierarchical service configurations, enabling correct traffic handling in Mist-managed deployments.
- I95-65617 Loss of syslog forwarding over TLS after upgrade to 7.1.6: Resolved an issue where syslog forwarding over TLS stopped working after upgrading to 7.1.6, preventing log delivery to remote collectors.
- I95-65624 KNI application scripts test failure: Resolved an internal test failure in KNI application scripts that could affect KNI interface initialization in certain configurations.
- I95-65656 Conductor upgrade fails on health check: Resolved an issue where conductor upgrades could fail due to a health check timeout, preventing the upgrade from completing successfully.
- I95-65691 Node disconnected after headend partial rollback: Resolved an issue where a node could remain disconnected from the conductor after a partial rollback scenario on a headend router.
- I95-65719 Secure Conductor Onboarding (SCO) failing: Resolved an issue where Secure Conductor Onboarding (SCO) failed when using RSA certificates in full chain format, incorrectly reporting that only RSA certificates are supported.
- I95-65769 Minion connector update: Updated the minion connector to version 1.7.6, incorporating connectivity reliability improvements.
- WAN-4774 Configuration model list key derivation: Improved internal configuration model handling by deriving list keys from the consolidated configuration model instead of using a hardcoded path map, improving accuracy for Mist-managed deployments.
Release 7.1.5-7r2
Release Date: April 30, 2026
New Features
- I95-63393 SSR400/SSR440 power supply status visibility: Added CLI support to display the status of power supplies on dual-AC SSR400/SSR440 platforms. The
show chassis powercommand displays power supply status for both single and dual power supply devices. This improves operational visibility into power redundancy and health on SSR400/SSR440 systems.
- I95-64568 TPM details in platform information: The
show platform securitycommand has been added to display TPM information such as TPM family (version number), revision, firmware version, and manufacturer. This allows users to verify TPM availability and configuration for security and compliance workflows.
- I95-64623 Plugin packaging improvements: Updated plugin packaging to include
128T-plugin-support-files. This ensures that plugin dependencies are available on systems that rely on the extra packages bundle.
Resolved Issues
- The following CVEs have been identified and resolved in this release: CVE-2021-47670, CVE-2022-25883, CVE-2022-49985, CVE-2022-50087, CVE-2022-50228, CVE-2022-50367, CVE-2022-50386, CVE-2022-50543, CVE-2023-53125, CVE-2023-53178, CVE-2023-53226, CVE-2023-53257, CVE-2023-53297, CVE-2023-53305, CVE-2023-53386, CVE-2023-53401, CVE-2023-53513, CVE-2023-53539, CVE-2024-56644, CVE-2025-4945, CVE-2025-6176, CVE-2025-9086, CVE-2025-9230, CVE-2025-11021, CVE-2025-12084, CVE-2025-13601, CVE-2025-14104, CVE-2025-21727, CVE-2025-21759, CVE-2025-22026, CVE-2025-22058, CVE-2025-22097, CVE-2025-37797, CVE-2025-37914, CVE-2025-38085, CVE-2025-38159, CVE-2025-38200, CVE-2025-38211, CVE-2025-38250, CVE-2025-38332, CVE-2025-38350, CVE-2025-38352, CVE-2025-38380, CVE-2025-38392, CVE-2025-38449, CVE-2025-38461, CVE-2025-38464, CVE-2025-38477, CVE-2025-38498, CVE-2025-38527, CVE-2025-38556, CVE-2025-38718, CVE-2025-38724, CVE-2025-39697, CVE-2025-39718, CVE-2025-39730, CVE-2025-39817, CVE-2025-39825, CVE-2025-39841, CVE-2025-39849, CVE-2025-39864, CVE-2025-39883, CVE-2025-39898, CVE-2025-39955, CVE-2025-39971, CVE-2025-40300, CVE-2025-66418, CVE-2025-66471, CVE-2026-0719, CVE-2026-1761, CVE-2026-21441.
- I95-62421 DHCP relay failures causing clients to miss IP assignment: Resolved an issue where DHCP session information is lost on the hub, causing the session reverse flow to collide with the forward flow of the session initiated originally from the spoke. This includes a new (configurable) default behavior for collision resolution. For detailed information, see
configure authority service-policy prefer-established-session {true | false}.
- I95-62710 Unnecessary web server processing for
router allin the PCLI: Addressed a problem where the web server performed unnecessary work when PCLI commands referencedrouter all. This optimization reduces overhead and improves responsiveness.
- I95-63174 IDP
Criticalprofile not applied: Resolved an issue where setting the IDP policy/profile toCriticalwas not properly applied on IDP. With this fix, profile changes toCriticalnow take effect as expected.
- I95-63355 Node-level security controls for serial console and USB: Restored support for configuring node-level security features that disable serial console output and USB boot/mass storage (for example, settings such as
serial-console-enabledandusb-mass-storage-enabled). This allows users to reapply hardened platform settings where supported.
- I95-63393 SSR400/SSR440 power supply status visibility: Added CLI support to display the status of power supplies on dual-AC SSR400/SSR440 platforms. The
show chassis powercommand displays power supply status for both single and dual power supply devices. This improves operational visibility into power redundancy and health on SSR400/SSR440 systems.
- I95-63839 SNMP walk failures on Conductors onboarding to NMS: Resolved an issue where SNMP walks on Conductors could fail with a
genError, preventing successful onboarding into some network management systems. System MIB walks on Conductors now complete successfully; IF-MIB is no longer exposed on Conductors where it is not supported.
- I95-63873 DHCP leases not showing in Conductor UI: Resolved an issue where attempting to retrieve DHCP v4 leases via the Conductor UI for a specific router results in
no leases found. Also resolved an issue where viewing a router Logs page via the Conductor UI displayed ALL logs rather than using the selected time range.
- I95-64152 Conductor connectivity blocked by stale SSH control sockets: Resolved a condition where, after a router reboot (particularly following an unclean shutdown), the router could remain Disconnected in the Conductor due to stale SSH control sockets. The SSH coordination logic now cleans up stale control sockets automatically, restoring Conductor–router connectivity.
- I95-64187 Improved handling of TPM Dictionary Attack (DA) lockout: Improved detection and handling when the TPM is in Dictionary Attack (DA) lockout mode. The integrity handler now detects this condition earlier and fails in a more predictable manner, simplifying troubleshooting of TPM-related integrity issues.
- I95-64568 TPM details in platform information: The
show platform securitycommand has been added to display TPM information such as TPM family (version number), revision, firmware version, and manufacturer. This allows users to verify TPM availability and configuration for security and compliance workflows.
- I95-64575 Unable to login to SSR routers from conductor in Cloud deployment: Resolved an issue where the SSH configuration on cloud-deployed routers disabled password authentication, preventing login from the conductor.
- I95-64595 Excessive audit log severity: Adjusted the log severity for the audit log event collector to better match expected operational conditions and reduce unnecessary log noise.
- I95-64687 Recursive cleanup of Salt cache directory Resolved an issue where cleanup of
/var/cache/salt/was not performed recursively, which could leave behind cached data. The cleanup process now removes this directory recursively to ensure a more complete reset.
- I95-64688 Highway coredumps causing peer path flaps: Resolved an issue where highway process coredumps were occurring, resulting in peer path flaps.
- I95-64719 Secure Conductor Onboarding (SCO) config validation incorrect: Resolved an issue where validating SCO config checked each node for an assetID but did not verify that at least one assetID was configured, which is a requirement.
Release 7.1.4-3r2
Release Date: March 17, 2026
Resolved Issues
- I95-64521 Upgrade from 7.1.0-r1 to 7.1.3-r2 failed on SSR440: Resolved an issue where an upgrade to 7.1.3-r2 on an SSR440 HA router would fail because the system health check failed. The
ha-0-0interface did not come up during boot (eth1comes up instead), causing the system health check to fail. Theha-0-0interface is now correctly initialized during upgrades on all SSR4x0 HA configurations.
- I95-64543 Onboarding an SSR440 router running 7.1.0 to a conductor running 7.1.3 fails: Resolved an issue where an older default cipher-string operator had been disallowed and caused the onboarding to fail. All of the following characters are now treated as valid:
. - _ : + @ = , !.
Release 7.1.3-29r2
Release Date: March 10, 2026
If you have an SSR400 or SSR440, it is strongly recommended that you upgrade to 7.1.4-2r2, and not use 7.1.3-29r2, due to the HA interface upgrade issue I95-64521 mentioned above.
New Features
- I95-26081 Display negotiated BFD Interval: The command
show peers bfd-intervalhas been added to display the negotiated bfd-interval in three columns,Rx Timer,Tx Timer, andMultiplier. See Negotiated BFD Intervals for more information.
- I95-48934 Configuration Integrity: SSR Configuration Integrity protects authentication credentials, keys and certificates, network topology information, and other pieces of sensitive SSR configuration from unauthorized access when the system is powered off. It prevents network and SSR operations from executing when the system is determined to be in a compromised state. To learn more, see Configuration Integrity.
- I95-54247 IMA - SSR Signed packages only execution: IMA is Linux’s Integrity Measurement Architecture. The SSR400 and SSR440 support IMA validation using GPG Signatures. IMA validation is enabled by default for the root user, allowing the kernel to check the signature of each file before loading it for execution. If these checks fail, execution is denied with a Permission denied (EACCES) error code. For more information, see Secure Boot - IMA.
- I95-54248 Smart OS Download: The SSR download process is now configurable, to provide better recovery and control over software downloads when a network connection fails. To improve resiliency against these network connectivity issues, the SSR queries available versions from all sources before beginning the download. If a request to a source fails, the SSR moves on to the next source. See Smart OS Download for more information.
- I95-56719 Conductor Scaling: Several improvements have been made to increase the scale of conductor managed router/node deployments, as well as the reporting of router information to the GUI and PCLI, and the efficiency of the device communications. The conductor can now manage up to a combination of 5000 nodes and routers (on appropriately resourced hardware platforms). Improvements to web interface responsiveness and updates to the following pages: Peer Path table, Event history, and Peering Connections panel of the Topology view.
- I95-58446 EoSVR Loop Prevention: EoSVR A/S Loop Prevention has been added, allowing EoSVR traffic to pass Broadcast, unknown-unicast, and multicast traffic through a switch without causing the port to be shut down.
- I95-58959 Secure Conductor Onboarding: Secure Conductor Onboarding (SCO) provides the ability to onboard a router to a conductor ensuring that each device proves possession of a private key, and that the connection is trusted and authenticated. For more information, see Secure Conductor Onboarding.
- I95-59948 SHA-384 and SHA-512 Support: Added support for CNSA 2.0 algorithms SHA-384 and SHA-512 to support US Federal government deployments. For additional information, see
configure-authority-security-hmac-cipher.
- I95-60209 ML-KEM support [FIPS-203]: ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) is a cryptographic protocol used in post-quantum cryptography to securely exchange keys over public channels. This level of protection offers security against both quantum and classical adversaries. On the SSR, ML-KEM can be used alone, or in conjunction with Diffie-Hellman as a hybrid approach to peer-key exchange and encryption. For more information, see Post Quantum Cryptography Support.
- I95-61176 Multicast Failover Optimization: Several internal improvements have been made to improve failover and convergence in both HA and non-HA scenarios for Multicast/PIM, as well as failover times in general.
- I95-63476 Router/Peer path override for
key-exchange-algorithm: A router/peer-path override has been added to enable the transition to a new algorithm within authority. For more information, see Key Exchange Algorithm Router Override.
Resolved Issues
- The following CVEs have been identified and resolved in this release: CVE-2024-56326, CVE-2025-47273, CVE-2025-32415, CVE-2025-58060, CVE-2025-54389, CVE-2021-28651, CVE-2025-54574, CVE-2025-8194, CVE-2025-32462, CVE-2018-10906, CVE-2018-14468, CVE-2021-42574, CVE-2022-24407, CVE-2019-12749, CVE-2021-20277, CVE-2021-4034, CVE-2021-3621, CVE-2024-28956, CVE-2025-53057, CVE-2025-53066, CVE-2025-62168, CVE-2025-11561, CVE-2024-43876, CVE-2024-43877, CVE-2025-22058, CVE-2025-23143, CVE-2025-38678, CVE-2025-39880, CVE-2025-39883, CVE-2025-39885, CVE-2025-39911, CVE-2025-39913, CVE-2025-39923, CVE-2025-39945, CVE-2025-39949, CVE-2025-39953, CVE-2025-39955, CVE-2025-39964, CVE-2025-39967, CVE-2025-39968, CVE-2025-39969, CVE-2025-39970, CVE-2025-39971, CVE-2025-39972, CVE-2025-39973, CVE-2025-39980, CVE-2025-39993, CVE-2025-39994, CVE-2025-39996, CVE-2025-39998, CVE-2025-40001, CVE-2025-40006, CVE-2025-40011, CVE-2025-40018, CVE-2025-40019, CVE-2025-40020, CVE-2025-40021, CVE-2025-40022, CVE-2025-40026, CVE-2025-40027, CVE-2025-40030, CVE-2025-40035, CVE-2025-40042, CVE-2025-40044, CVE-2025-40048, CVE-2025-40049, CVE-2025-40053, CVE-2025-40055, CVE-2025-40070, CVE-2025-40078, CVE-2025-40081, CVE-2025-40085, CVE-2025-40087, CVE-2025-40092, CVE-2025-40094, CVE-2025-40105, CVE-2025-40109, CVE-2025-40111, CVE-2025-40115, CVE-2025-40118, CVE-2025-40120, CVE-2025-40121, CVE-2025-40125, CVE-2025-40134, CVE-2025-40140, CVE-2025-40153, CVE-2025-40154, CVE-2025-40167, CVE-2025-40171, CVE-2025-40173, CVE-2025-40178, CVE-2025-40179, CVE-2025-40183, CVE-2025-40186, CVE-2025-40187, CVE-2025-40190, CVE-2025-40194, CVE-2025-40197, CVE-2025-40200, CVE-2025-40204, CVE-2025-40205, CVE-2025-5987, CVE-2025-11083, CVE-2025-61984, CVE-2025-61985, CVE-2024-5642, CVE-2025-6069, CVE-2025-6075, CVE-2025-8291, CVE-2025-58098, CVE-2025-65082, CVE-2025-66200, CVE-2025-45582, CVE-2024-12087, CVE-2025-64720, CVE-2025-65018, CVE-2025-66293, CVE-2025-40778, CVE-2025-58436, CVE-2025-61915, CVE-2025-14523, CVE-2025-68615, CVE-2025-68973, CVE-2025-61729, CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796.
- I95-57605 BFD link-test-interval not accurate: Resolved as part of I95-59720. Several modifications have been made to the BFD timers to improve accuracy.
- I95-60545 Attempting network interface lookup with invalid ID: Resolved an issue where errors due to an invalid ID were flooding the logs. Error logs in highway regarding a failed interface lookup for an invalid interface are now suppressed.
- I95-61588 Console access failures post-migration: Resolved an issue where a lower baud rate was being used by the serial console, resulting in unreadable output. The check and enforcement for the 115200 baud rate has been improved.
- I95-61823 Change
ESKM_DISABLEDtoESKM_STANDBYfor HA router in standby state: For routers configured as part of an HA Enhanced Security Key Management (ESKM) deployment, the standby state is now correctly identified asESKM_STANDBY.
- I95-61856 Add
reload local certificatescommand for ESKM: Thereload local certificatescommand has been added to allow the updating of local certificates. Seereload local certificatesfor more information.
- I95-62074 Highway requests metadata key when
enhanced-security-key-managementfeature is disabled: Resolved an issue where even whenenhanced-security-key-managementwas disabled, it continued to attempt to get the key information.
- I95-62343 Routers disconnecting from the Conductor while still successfully routing traffic: Resolved an issue where Salt gets stuck with a bad network connection. Added new functionality to the
minion-watchdogservice which will restart thesalt-minionif there is a salt job stuck for over an hour.
- I95-62580 Conflicting network interface names slowing application traffic: Resolved an issue in the app summary tracking logic related to conflicting network interface names for non-redundant ports of an HA router.
- I95-62631 Race condition for multiple dhcp servers startup: Resolved and issue where the multiple DHCP server config change from single DHCP server to multiple DHCP server under the same device interface would stop working. Updates have been made to the monitoring script to identify the changes and prevent the issue.
- I95-62662 SSR4x0 Time not synchronized after reboot: Resolved an issue with the SSR400 and SSR440 where the hardware real time clock (RTC) was not updated after synchronizing with the NTP server. This has been resolved and the time is now fully synchronized. Note that this is an SSR4x0-only issue.
- I95-62772 Add details to
show peers certificateoutput: Theshow peers certificateoutput no longer just shows PEM file output; the data has been rendered in a more friendly format.
- I95-62859 Duplicate alarms created for duplicate asset IDs: Resolved an issue where the Conductor created a duplicate asset ID alarm each time an asset with a duplicate ID tried to authenticate.
- I95-62956 Configuration failure due to service definition expecting subnet mask: Resolved an issue where the Anti-Virus and IDP configuration expected a subnet mask as part of the Service Address. The subnet mask has been added.
- I95-62957 Configuration failure due to invalid name: Anti-Virus and IDP do not allow policy names using a dot (.). This has been resolved — configurations will use an underscore for policy name creation.
- I95-62982 SSR limits the number of supported network-interfaces: Resolved an issue where the limit on the number of network-interfaces was low. Improved implementation of data structure storing network-interface objects, resulting in an increase of 7x the current capacity.
- I95-63018 Memory corruption after reading VSA: Resolved a rare issue where in remote authentication through a RADIUS server, pam_radius was causing memory corruption after a Vendor Specific Attribute (VSA) is read.
- I95-63124 Harden HTTPS security: HTTPS security has been improved and hardened by following best practices. Security headers and SSL algorithms have been updated so that browsers and external clients are only using strong algorithms. Users on older Windows/IE versions can choose to extend the SSR security using
configure authority router <name> system services webserver ssl ciphersto allow older ciphers.
- I95-63190 Router intermittently disconnects from conductor: Resolved an issue where process errors were filling the buffer queue, dropping messages, and causing node disconnections from the Conductor.
- I95-63202 Unable to bind interfaces in Azure F8 flavor in West Europe region: Resolved an issue where driver optimization on lower core count systems required more more memory usage, causing initialization failures.
- I95-63228 Premature route installation complete notification: In some cases a premature internal notification that the route installation was complete was being transmitted, causing the Graceful Restart process to terminate early. This issue has been resolved.
- I95-63292 Add upgrade timeout and rpm operation timeout: Added the ability to configure the timeout for upgrades and for rpm download/install operations under
config authority router <RouterName> system software-update. The defaults are 1 hour for SSR upgrade and 10 minutes for rpm operations.
- I95-63295 Highway crash when show fib is executed on very large FIB: Resolved an issue where a time intensive operation on a large entry was preventing other threads from accessing data and causing a crash.
- I95-63299 Keys signed with ECDSA do not work with Enhanced Security Key Management: Resolved an issue where ECC-based keys fail during the validation process, because the SSR was using hardcoded SHA256 for its signature validation checking. This issue has been resolved.
- I95-63306 Allow RSA keys with ECC signatures on certificates: Resolved an unnecessary restriction between the allowed PKI private key algorithm and the CA signature algorithm. The key is now validated independently from the signature on the certificate.
- I95-63324 Duplicate static DHCP addresses cause crashes: Added validation steps to identify and prevent duplicate MAC addresses for the static address assignment.
- I95-63330 Repeated interface flaps on vSSR led to crash in highway process: Truncated packets are validated prior to processing, preventing crash.
- I95-63353 Invalid assert that leads to a crash: Resolved an issue where an incorrect assertion led to a crash. Protections have been added to prevent the race condition leading to the crash.
- I95-63356 Do not allow new sessions after peer's certificate expired/revoked: Resolved an issue where sessions were one peer continued to send new sessions after the other peers' certificate was revoked. When the peer's certificate expires, the peer is now forced to re-initiate the key exchange.
- I95-63368 SSR400/SSR440 PMTU cannot exceed 8978: Resolved an issue where SSR400/SSR440 PMTU discovery was lower than other platforms. The issue has been resolved, and SSR400/SSR440 PMTU now discovers at 9198.
- I95-63377 HA LEDs not working correctly: On early versions of the SS400 and SSR440 hardware with pre-release builds of the SSR 7.1.3 software, the HA network interface LEDs (on the rear panel) did not function correctly. This issue has been resolved with the general release of the SSR 7.1.3-29-r2 and subsequent release of SSR 7.1.4-3r2 (recommended version). These HA port LEDs now function as documented.
- I95-63412 Glare condition leading to highway crash when session terminates prematurely: Resolved an issue where session exception processing was not handled properly.
- I95-63422 Factory reset routers not re-onboarding when ESKM enabled: Resolved an issue where if ESKM was initially started using invalid certificate on one node, it would be unable to onboard until the remote peering relationship is restarted.
- I95-63675 Node page in the GUI appears to load indefinitely: Resolved an issue where the GUI Node page would load infinitely.
- I95-63676 Waypoints fail to allocate when the
service-path peer next-hop gatewayis off the subnet: Resolved an issue where the first network-interface IP was selected as the local IP for waypoint allocation, even if that IP is not a valid waypoint.
- I95-63729 Asset state not accurately reported in conductor: Resolved an issue where issue where the SSH authorized keys from one HA conductor node were deleted after restarting both HA conductor nodes.
- I95-63817 Default peering certificates are unable to use the configured peering-common-name: Resolved an issue where the default peering certificates were generated before receiving the configuration. The default generated peering certificate now properly uses the
peering-common-nameSSR configuration element.
- I95-63873 DHCP leases not showing in Conductor UI: Resolved an issue where attempting to retrieve DHCP v4 leases via the Conductor UI for a specific router results in
no leases found. Also resolved an issue where viewing a router Logs page via the Conductor UI displayed ALL logs rather than using the selected time range.
- I95-63923 Redundant conductor fails to upgrade: Resolved an issue where a minion disconnects from the conductor node and never attempts to reconnect. The minion watchdog process now restarts the salt minion if it is not connected to all conductor nodes.
- I95-63943 Edge-case crash when changing from regular services to app-id: Resolved an issue where a system that never had app-id services or had app-id services, reverted them and restarted the highway process; and then modified an existing service to use app-id caused a crash. Protections have been added to safeguard against this edge case.
- I95-64066 Race condition when syncing SSH keys to the peer node: Resolved an issue where SSH keys were not synced between peer nodes automatically by the Conductor.
Caveats
- I95-64317 Dropped Packets Capture continues to run: If you have initiated a packet Capture from any page in the GUI, it will continue to run on the web server even after the request is terminated, resulting in expensive per packet export overhead. The web server must be restarted to terminate the packet capture. This issue is under investigation and will be resolved in an upcoming release.
-
I95-64407 Alternate SHA ciphers (256/384/512) not working properly with ESKM: SSR 7.1.3 introduces
sha384andsha512as configurable options for thehmac-cipherfield on security policies, alongside a new internal data structure that tracks metadata keys per HMAC mode and cipher combination.In deployments with peers running different versions of software and sharing security policies, configuring
hmac-cipher sha384orhmac-cipher sha512in a fabric where any peer has not yet been upgraded to 7.1.3, those older versions of software will not recognizehmac-cipher sha384orhmac-cipher sha512. These devices will continue to runsha-256-128. Currently, no alarm or warning will be generated, and there is no performance impact.
Release 7.1.0-50r1
Release Date: December 4, 2025
New Features
- I95-34739 SSR400 and SSR440 Factory reset: The SSR4x0 devices provide the ability to reset the device to either a pre-defined rescue (or Golden) configuration, or a secure zeroization of the system and a return to the factory default configuration. For more information, see Factory Reset.
- I95-44742 SFP Optical interface transceiver stats: Support has been added to display optical interface transceiver stats in the CLI. Issuing the
show device-interface node all name <interface> optics-statisticswill display information for debugging and diagnostic information from network transceiver modules (SFP, SFP+, QSFP, etc.). It displays optical power levels, vendor information, and hardware thresholds for monitoring physical layer connectivity.
- I95-53402 SSR400/SSR440 Chassis Manager: The SSR400 and SSR440 support an integrated Chassis Manager to help monitor connectivity, power, temperature, as well as providing insight into other vital operational data. For more information, see the SSR Chassis Manager.
- I95-53405 5G modem support: Support for 5G modems as provided in the SSR400 and SSR440 devices has been added.
- I95-54238 Uninterruptible Boot Process: When the uninterruptible boot process is configured, a failed upgrade will not allow the user to select the image on the other volume (since the Console port is disabled, no user input is possible). For more information, see the Uniterruptable Boot Process.
- I95-54244 Secure Boot: The SSR400 and SSR440 are factory configured with a cryptographic public key that only allows an authenticated firmware image to run on the device. This ensures that only trusted (Juniper-signed) code will run from power-on through to linux OS boot. For additional information, see Secure Boot.
- I95-55746 Connection to Mist via proxy server/Support Mist Secure ZTP Onboarding: Support has been added to allow a connection to a public URL or to MIST using an explicit proxy and a private web proxy. See Proxy Server Configuration for information to configure the SSR to identify and use the non-transparent proxy. For information about the secure ztp process using Mist, see Secure ZTP Onboarding Using a Mist Proxy.
- I95-55936 Alarm and Events when service area hits threshold: Support has been added to allow users to configure alarms thresholds to monitor session processing capacity, and provide visibility into the system’s capacity to establish new sessions. For more information, see Session Processing Alarms.
- I95-57174 DCSP Steering - UDP/TCP destination port: With SSR version 7.1.0, the restriction for matching ports has been lifted, and support has been added for DCSP steering over non-IPSEC tunnels. For more information, see DSCP Steering Using GTP.
- I95-58502 Disable on box management ports: Configuration fields have been added to the SSR400 and SSR440 devices, allowing you to control physical security features. For more information, see Disable SSR400 and SSR440 Management Interfaces.
- I95-59235 HTTP/S proxy server for all public URLs: Support has been added to allow a connection to a public URL or to MIST using an explicit proxy and a private web proxy. See Proxy Server Configuration for information to configure the SSR to identify and use the non-transparent proxy. This process can also be used to support the Mist secure ZTP onboarding process.
Resolved Issues
- The following CVEs have been identified and resolved in this release: CVE-2024-3651, CVE-2024-56171, CVE-2025-24928, CVE-2024-11187, CVE-2024-1737, CVE-2024-1975, CVE-2024-3596, CVE-2024-37370, CVE-2024-37371, CVE-2025-24528, CVE-2023-46846, CVE-2024-45802, CVE-2024-12085, CVE-2023-26604, CVE-2024-7347, CVE-2025-23419, CVE-2024-43842, CVE-2024-40906, CVE-2024-44970, CVE-2025-21756, CVE-2022-49011, CVE-2024-53141, CVE-2025-21587, CVE-2025-30691, CVE-2025-30698, CVE-2024-0727, CVE-2023-5678, CVE-2024-5535, CVE-2024-9143, CVE-2024-13176, CVE-2016-9840, CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4435, CVE-2025-4517, CVE-2025-32462, CVE-2025-5702, CVE-2025-5702, CVE-2025-4802, CVE-2025-6020, CVE-2025-47268, CVE-2025-25724, CVE-2025-3576, CVE-2025-47273, CVE-2024-23337, CVE-2025-48060, CVE-2023-52572, CVE-2023-52621, CVE-2023-52757, CVE-2024-26686, CVE-2024-26739, CVE-2024-26952, CVE-2024-27402, CVE-2024-35790, CVE-2024-35866, CVE-2024-35867, CVE-2024-35943, CVE-2024-36350, CVE-2024-36357, CVE-2024-36908, CVE-2024-38540, CVE-2024-38541, CVE-2024-42160, CVE-2024-42322, CVE-2024-44938, CVE-2024-46742, CVE-2024-46751, CVE-2024-46774, CVE-2024-46784, CVE-2024-46816, CVE-2024-49960, CVE-2024-49989, CVE-2024-50047, CVE-2024-50125, CVE-2024-50258, CVE-2024-50272, CVE-2024-50280, CVE-2024-53128, CVE-2024-53185, CVE-2024-53203, CVE-2024-54458, CVE-2024-56551, CVE-2024-56599, CVE-2024-56655, CVE-2024-56658, CVE-2024-56751, CVE-2025-21681, CVE-2025-21839, CVE-2025-21853, CVE-2025-22027, CVE-2025-22062, CVE-2025-23140, CVE-2025-23142, CVE-2025-23144, CVE-2025-23145, CVE-2025-23146, CVE-2025-23147, CVE-2025-23148, CVE-2025-23150, CVE-2025-23151, CVE-2025-23156, CVE-2025-23157, CVE-2025-23158, CVE-2025-23159, CVE-2025-23161, CVE-2025-23163, CVE-2025-37738, CVE-2025-37739, CVE-2025-37740, CVE-2025-37741, CVE-2025-37742, CVE-2025-37749, CVE-2025-37752, CVE-2025-37756, CVE-2025-37757, CVE-2025-37758, CVE-2025-37765, CVE-2025-37766, CVE-2025-37767, CVE-2025-37768, CVE-2025-37770, CVE-2025-37771, CVE-2025-37773, CVE-2025-37780, CVE-2025-37781, CVE-2025-37787, CVE-2025-37788, CVE-2025-37789, CVE-2025-37790, CVE-2025-37792, CVE-2025-37794, CVE-2025-37796, CVE-2025-37797, CVE-2025-37803, CVE-2025-37805, CVE-2025-37808, CVE-2025-37810, CVE-2025-37812, CVE-2025-37817, CVE-2025-37819, CVE-2025-37823, CVE-2025-37824, CVE-2025-37829, CVE-2025-37830, CVE-2025-37836, CVE-2025-37838, CVE-2025-37839, CVE-2025-37840, CVE-2025-37841, CVE-2025-37844, CVE-2025-37850, CVE-2025-37857, CVE-2025-37858, CVE-2025-37859, CVE-2025-37862, CVE-2025-37867, CVE-2025-37875, CVE-2025-37881, CVE-2025-37883, CVE-2025-37885, CVE-2025-37890, CVE-2025-37892, CVE-2025-37905, CVE-2025-37909, CVE-2025-37911, CVE-2025-37913, CVE-2025-37914, CVE-2025-37915, CVE-2025-37923, CVE-2025-37927, CVE-2025-37929, CVE-2025-37930, CVE-2025-37940, CVE-2025-37949, CVE-2025-37967, CVE-2025-37969, CVE-2025-37970, CVE-2025-37982, CVE-2025-37983, CVE-2025-37985, CVE-2025-37989, CVE-2025-37990, CVE-2025-37991, CVE-2025-37992, CVE-2025-37994, CVE-2025-37995, CVE-2025-37997, CVE-2025-37998, CVE-2025-38005, CVE-2025-38009, CVE-2025-38023, CVE-2025-38024, CVE-2025-38031, CVE-2025-38089, CVE-2025-7425, CVE-2025-32414, CVE-2025-32415, CVE-2025-27151, CVE-2025-32023, CVE-2025-48367, CVE-2025-49133, CVE-2025-6965, CVE-2025-5222, CVE-2025-4373, CVE-2024-52533, CVE-2024-6174, CVE-2025-5994, CVE-2024-52615, CVE-2025-40909, CVE-2022-29458, CVE-2024-47081, CVE-2025-6965, CVE-2025-8058, CVE-2025-30749, CVE-2025-30754, CVE-2025-30761, CVE-2025-50106, CVE-2025-5914, CVE-2025-54389, CVE-2025-7425, CVE-2025-8194, CVE-2025-48964, CVE-2025-53905, CVE-2025-53906, CVE-2025-58060, CVE-2025-58364, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990, CVE-2025-6395, CVE-2023-49083, CVE-2024-47252, CVE-2025-23048, CVE-2025-49812, CVE-2020-11023, CVE-2025-5318, CVE-2025-6021, CVE-2025-32414 ,CVE-2025-49794, CVE-2025-49796, CVE-2025-49844, CVE-2023-4752, CVE-2023-6693, CVE-2024-12797, CVE-2024-25742, CVE-2024-25743, CVE-2024-25744, CVE-2024-28956, CVE-2024-3567, CVE-2024-52616, CVE-2024-55549, CVE-2024-56583, CVE-2024-8176, CVE-2024-8508, CVE-2025-21605, CVE-2025-2784, CVE-2025-31498, CVE-2025-32049, CVE-2025-32050, CVE-2025-32052, CVE-2025-32053, CVE-2025-32906, CVE-2025-32907, CVE-2025-32911, CVE-2025-32913, CVE-2025-32914, CVE-2025-4598, CVE-2025-46420, CVE-2025-46421, CVE-2025-4948.
- I95-39653 Negative duration in session table after applying filter: Resolved an issue where applying a filter to the session table resulted in sessions displaying a negative duration.
- I95-57019 KNI host interfaces erroneously generate LLDP: Resolved an issue where host KNI interfaces are incrementally generating out-errors in
show device-interface.
- I95-58007 Add ability to set PIM graceful restart-time: The
routing default-instance pim restart-timecommand has been added to allow users to define the number of seconds that the PIM protocol will performgraceful-restartafter a node failure. This resolution addresses all the listed issues. For more information, see PIM Graceful Restart Timer. This also addresses I95-57702, I95-57906, I95-60637, and I95-60731.
- I95-60767
service-route > next-hopvalidation rejects configuration: Resolved an issue where the rule validator did not consider the service application-type as DNS proxy during the configuration rule validation. This issue has been resolved.
- I95-60799 Tenant prefix use within a VRF: The SSR allows the configuration of tenant-prefixes without giving an error, and correctly handles interfaces with tenant-prefixes within the protocol code.
- I95-61058 Peer paths fail when additional IPs are added to a WAN interface: Resolved a case where adding a second address for use in nat-pools to a peering interface caused continuous bfd peer flaps. The SSR now handles address changes when the local IP address changes.
- I95-61075 BGP does not re-establish after firewall failover: Resolved an issue where when initiating a BFD for BGP session, the cached MAC to IP mapping was being used. If the MAC address had changed, stale information was used and the BFD session would not be established. We now issue an ARP request to get the latest MAC Address.
- I95-61093 Router first time synchronization: Resolved an issue where a minion is restarted multiple times during the first connection to the conductor, resulting an extended wait time before synchronization.
- I95-61453 'mist' user missing from '128t-user' group at login: Resolved an issue that prevented the modification of lock files causing the process responsible for managing user permissions to fail.
- I95-61580 CLI does not prompt for required router restart: Resolved an issue where making a configuration change requiring a restart only generates a warning only for the router that the PCLI is running on. Committing a configuration change that requires a restart now results in a warning even when the change is on a different router.
- I95-61866 Unnecessary events sync: Resolved an issue where data is unintentionally sync'ed between HA nodes.
- I95-61869 Peer paths not coming back up after manual reboot: Resolved an issue with the control message capacity. In configurations with more than 1000 VLANs, the aggregate size of all the control messages grew larger than the space allocated for the messages, and messages failed to send and some packet processing threads were left with incomplete interface tables. The capacity to handle these messages has been increased and can now handle up to 12,000 VLANs.
- I95-61910 FIPS installation failure: Resolved an issue where package renaming resulted in missing installation files.
- I95-61999 ATT SIM card MNC code update: Resolved an issue with the ATT SIM card using an unexpected MNC code.
- I95-62011 Stats from adjacency traffic engineering throw an exception when a hostname is used: Resolved an issue where dynamic reconfiguration when adding neighbors/adjacencies that use an FQDN and have adjacency Traffic Engineering enabled, caused the device interface to reach a failure state.
- I95-62071 Multicast Traffic contributing to service area resource contention: Resolved an issue when we have an mroute with no outgoing interfaces. We now use a Detour Path instead of NoServicePaths to prevent resource contention.
- I95-62179 Software Lifecycle History not up to date: Resolved an issue where the software lifecycle page was not showing any history, or in some cases, the history was outdated. Internal functionality has been updated, and both the GUI and CLI outputs now show the correct information.
- I95-62258 Packet steered to egress non-existent interface causes highway crash: Added logic to capture the errant packet and prevent the crash. An exception is logged so that the issue can be more easily rectified.
- I95-62369 Session error record shows 0s for session-id: Resolved an issue where the session record information was incomplete. The SSR now also uses the redundancy session data to gather records.
- I95-62449 HA conductor fails to initialize secondary node: Resolved an issue with password validation that was preventing the secondary node from accessing the primary node to download files needed for initialization. The user is now prompted to enter the new password for the primary node when setting up the secondary node.
- I95-62695 Management interface placed in incorrect zone during conductor onboarding: Resolved an issue where an earlier change did not put the management infterface in the t128 zone.
- I95-62703 Highway process crashed when BGP over SVR is activated: Resolved an issue where the unicast code path was incorrectly calling the multicast variant of getBestMultiHomedPathIndex() and causing a highway crash.
- I95-62742 Cannot see sync errors for nodes that are stuck synchronizing: Resolved an issue where errors in
show assetsdisappeared when the synchronizing state retries.
- I95-63334 HA node failover causing mismatched node IDs: Resolved an issue where where Enhanced Security Key Management security exchange state may get stuck on HA node failover.
Caveats
- I95-63422 Factory reset routers not re-onboarding when ESKM enabled: Resolved an issue where if ESKM was initially started using invalid certificate on one node, it would be unable to onboard until the remote peering relationship is restarted.