1 SRX Series Switches - Comparison
1 SRX Series Switches - Comparison
1 SRX Series Switches - Comparison
Product Description
Juniper Networks® SRX300 line of services gateways delivers a next-generation networking
and security solution that supports the changing needs of cloud-enabled enterprise
networks. Whether rolling out new services and applications across locations, connecting
to the cloud, or trying to achieve operational efficiency, the SRX300 line helps
Product Overview organizations realize their business objectives while providing scalable, easy to manage,
secure connectivity and advanced threat mitigation capabilities. Next-generation firewall
The SRX300 line of services and unified threat management (UTM) capabilities also make it easier to detect and
gateways combines security, proactively mitigate threats to improve the user and application experience.
SD-WAN, routing, switching,
The SRX300 line consists of five models:
and WAN interfaces with next-
generation firewall and • SRX300: Securing small branch or retail offices, the SRX300 Services Gateway
advanced threat mitigation consolidates security, routing, switching, and WAN connectivity in a small desktop
capabilities for cost-effective, device. The SRX300 supports up to 1 Gbps firewall and 300 Mbps IPsec VPN in a
secure connectivity across single, cost-effective networking and security platform.
distributed enterprise locations. • SRX320: Securely connecting small distributed enterprise branch offices, the SRX320
By consolidating fast, highly Services Gateway consolidates security, routing, switching, and WAN connectivity in a
available switching, routing, small desktop device. The SRX320 supports up to 1 Gbps firewall and 300 Mbps IPsec
security, and next-generation VPN in a single, consolidated, cost-effective networking and security platform.
firewall capabilities in a single
• SRX340: Securely connecting midsize distributed enterprise branch offices, the
device, enterprises can remove
SRX340 Services Gateway consolidates security, routing, switching, and WAN
network complexity, protect and
connectivity in a 1 U form factor. The SRX340 supports up to 3 Gbps firewall and 600
prioritize their resources, and
Mbps IPsec VPN in a single, cost-effective networking and security platform.
improve user and application
experience while lowering total • SRX345: Best suited for midsize to large distributed enterprise branch offices, the
cost of ownership (TCO). SRX345 Services Gateway consolidates security, routing, switching, and WAN
connectivity in a 1 U form factor. The SRX345 supports up to 5 Gbps firewall and 800
Mbps IPsec VPN in a single, consolidated, cost-effective networking and security
platform.
• SRX380: A high-performance and secure SD-WAN gateway, the SRX380 offers
superior and reliable WAN connectivity while consolidating security, routing, and
switching for distributed enterprise offices. The SRX380 features greater port density
than other SRX300 models, with 16x1GbE PoE+ and 4x10GbE ports, and includes
redundant dual power supplies, all in a 1 U form factor.
SRX300 Highlights
The SRX300 line of services gateways consists of secure routers that bring high
performance and proven deployment capabilities to enterprises that need to build a
worldwide network of thousands of remote sites. WAN or Internet connectivity and Wi-Fi
module options include:
• Ethernet, serial, T1/E1, ADSL2/2+, and VDSL
• 3G/4G LTE wireless
• 802.11ac Wave 2 Wi-Fi
1
SRX300 Line of Services Gateways for the Branch
Industry best, high-performance IPsec VPN solutions provide created by the enterprise to steer application traffic towards a
comprehensive encryption and authentication capabilities to secure preferred path.
intersite communications. Multiple form factors with Ethernet For the perimeter, the SRX300 line offers a comprehensive suite of
switching support on native Gigabit Ethernet ports allow cost- application security services, threat defenses, and intelligence
effective choices for mission-critical deployments. Juniper services. The services consist of intrusion prevention system (IPS),
Networks Junos® automation and scripting capabilities and Junos application security user role-based firewall controls and cloud-
Space Security Director reduce operational complexity and simplify based antivirus, anti-spam, and enhanced Web filtering, protecting
the provisioning of new sites. networks from the latest content-borne threats. Integrated threat
The SRX300 line of devices recognizes more than 3,500 Layer 3-7 intelligence via Juniper Networks SecIntel offers adaptive threat
applications, including Web 2.0 and evasive peer-to-peer (P2P) protection against Command and Control (C&C)-related botnets
applications like Skype, torrents, and others. Correlating application and policy enforcement based on GeoIP. Customers can also
information with user contextual information, the SRX300 line can leverage their own custom and third-party feeds for protection
generate bandwidth usage reports, enforce access control policies, from advanced malware and other threats. Integrating the Juniper
prioritize and rate-limit traffic going out of WAN interfaces, and Networks Advanced Threat Protection solution, the SRX300 line
proactively secure remote sites. This optimizes resources in the detects and enforces automated protection against known malware
branch office and improves the application and user experience. and zero-day threats with a very high degree of accuracy.
Along with Juniper Contrail Service Orchestration, the SRX300 line The SRX300 line enables agile SecOps through automation
delivers fully automated SD-WAN to both enterprises and service capabilities that support Zero Touch Deployment, Python scripts for
providers. A Zero-Touch Provisioning (ZTP) capability greatly orchestration, and event scripting for operational management.
simplifies branch network connectivity for initial deployment and SRX300 services gateways run Juniper Networks Junos operating
ongoing management. The SRX300 firewalls efficiently utilize system, a proven, carrier-hardened network OS that powers the top
multiple links and load-balance traffic across the enterprise WAN, 100 service provider networks around the world. The rigorously
blending traditional MPLS with other connectivity options such as tested, carrier-class, rich routing features such as IPv4/IPv6, OSPF,
broadband internet, leased lines, 4G/LTE, and more. Policy- and BGP, and multicast have been proven in over 15 years of worldwide
application-based forwarding capabilities enforce business rules deployments.
Business continuity Stateful high availability (HA), IP • Uses stateful HA to synchronize configuration and firewall sessions
monitoring • Supports multiple WAN interface with dial-on-demand backup
• Route/link failover based on real-time link performance
SD-WAN Better end-user application and • ZTP simplifies remote device provisioning
cloud experience and lower • Advanced Policy-Based Routing (APBR) orchestrates business intent policies across the enterprise WAN
operational costs
• Application quality of experience (AppQoE) measures application SLAs and improves end-user experience
End-user experience App visibility and control • Detects 3,500+ Layer 3-7 applications, including Web 2.0
• Controls and prioritizes traffic based on application and use role
• Inspects and detects applications inside the SSL encrypted traffic
Highly secure IPsec VPN, Media Access Control • Creates secure, reliable, and fast overlay link over public internet
Security (MACsec) • Employs anti-counterfeit features to protect from unauthorized hardware spares
• High-performance CPU with built-in hardware assist IPsec acceleration
• TPM-based protection of device secrets such as passwords and certificates
Threat protection IPS, antivirus, anti-spam, Juniper • Enables zone-based stateful firewall by default
Advanced Threat Prevention • Protects from zero-day malware and other attacks with IPS, antivirus, and ATP
• Integrates open threat intelligence platform with third-party feeds
Easy to manage and On-box GUI, Security Director • Includes centralized management for auto-provisioning, firewall policy management, Network Address Translation (NAT),
scale and IPsec VPN deployments
• Includes simple easy-to-use on-box GUI for local management
Minimize TCO Junos OS • Integrates routing, switching, and security in a single device
• Reduces operation expense with Junos automation capabilities
2
SRX300 Line of Services Gateways for the Branch
SRX300 Specifications
Software Specifications
Routing Protocols Switching Features
• IPv4, IPv6, ISO, Connectionless Network Service (CLNS) • ASIC-based Layer 2 Forwarding
• Static routes • MAC address learning
• RIP v1/v2 • VLAN addressing and integrated routing and bridging (IRB)
• OSPF/OSPF v3 support
• BGP with Route Reflector • Link aggregation and LACP
• IS-IS • LLDP and LLDP-MED
• Multicast: Internet Group Management Protocol (IGMP) v1/v2, • STP, RSTP, MSTP
Protocol Independent Multicast (PIM) sparse mode (SM)/dense • MVRP
mode (DM)/source-specific multicast (SSM), Session • 802.1X authentication
Description Protocol (SDP), Distance Vector Multicast Routing
Firewall Services
Protocol (DVMRP), Multicast Source Discovery Protocol
• Stateful and stateless firewall
(MSDP), Reverse Path Forwarding (RPF)
• Zone-based firewall
• Encapsulation: VLAN, Point-to-Point Protocol (PPP), Frame
• Screens and distributed denial of service (DDoS) protection
Relay, High-Level Data Link Control (HDLC), serial, Multilink
• Protection from protocol and traffic anomaly
Point-to-Point Protocol (MLPPP), Multilink Frame Relay
• Integration with Pulse Unified Access Control (UAC)
(MLFR), and Point-to-Point Protocol over Ethernet (PPPoE)
• Integration with Aruba Clear Pass Policy Manager
• Virtual routers
• User role-based firewall
• Policy-based routing, source-based routing
• SSL Inspection (Forward-proxy)
• Equal-cost multipath (ECMP)
Network Address Translation (NAT)
QoS Features
• Source NAT with Port Address Translation (PAT)
• Support for 802.1p, DiffServ code point (DSCP), EXP
• Bidirectional 1:1 static NAT
• Classification based on VLAN, data-link connection identifier
• Destination NAT with PAT
(DLCI), interface, bundles, or multifield filters
• Persistent NAT
• Marking, policing, and shaping
• IPv6 address translation
• Classification and scheduling
• Weighted random early detection (WRED)
• Guaranteed and maximum bandwidth
• Ingress traffic policing
• Virtual channels
• Hierarchical shaping and policing
3
SRX300 Line of Services Gateways for the Branch
• Tunnels: Generic routing encapsulation (GRE)3, IP-IP3, IPsec • SSH, Telnet, SNMP
• Site-site IPsec VPN, auto VPN, group VPN • Smart image download
• IPsec crypto algorithms: Data Encryption Standard (DES), triple • Juniper CLI and Web UI
DES (3DES), Advanced Encryption Standard (AES-256), AES- • Junos Space and Security Director
GCM • Python
• IPsec authentication algorithms: MD5, SHA-1, SHA-128, • Junos OS event, commit, and OP script
SHA-256 • Application and bandwidth usage reporting
• Pre-shared key and public key infrastructure (PKI) (X.509) • Auto installation
• Perfect forward secrecy, anti-reply • Debug and troubleshooting tools
• IPv4 and IPv6 IPsec VPN • Zero-Touch Provisioning with Contrail Service Orchestration
• Multi-proxy ID for site-site VPN Advanced Routing Services
• Internet Key Exchange (IKEv1, IKEv2), NAT-T • Packet mode
• Virtual router and quality-of-service (QoS) aware • MPLS (RSVP, LDP)
• Standard-based dead peer detection (DPD) support • Circuit cross-connect (CCC), translational cross-connect (TCC)
• VPN monitoring • L2/L3 MPLS VPN, pseudowires
Network Services • Virtual private LAN service (VPLS), next-generation multicast
• Dynamic Host Configuration Protocol (DHCP) client/server/ VPN (NG-MVPN)
relay • MPLS traffic engineering and MPLS fast reroute
• Domain Name System (DNS) proxy, dynamic DNS (DDNS) Application Security Services2
• Juniper real-time performance monitoring (RPM) and IP- • Application visibility and control
monitoring • Application-based firewall
• Juniper flow monitoring (J-Flow)1 • Application QoS
• Bidirectional Forwarding Detection (BFD) • Application-based advanced policy-based routing
• Two-Way Active Measurement Protocol (TWAMP) • Application quality of experience (AppQoE)
• IEEE 802.3ah Link Fault Management (LFM)
Enhanced SD-WAN Services
• IEEE 802.1ag Connectivity Fault Management (CFM)
• Application-based advanced policy-based routing (APBR)
High Availability Features
• Application-based link monitoring and switchover with
• Virtual Router Redundancy Protocol (VRRP)1 Application quality of experience (AppQoE)
• Stateful high availability
Threat Defense and Intelligence Services3
• Dual box clustering
• Active/passive • Intrusion prevention
• Active/active • Antivirus
• Configuration synchronization • Antispam
• Firewall session synchronization • Category/reputation-based URL filtering
• Device/link detection • SecIntel to provide threat intelligence
• In-Band Cluster Upgrade (ICU) • Protection from botnets (command and control)
• Dial on-demand backup interfaces • Adaptive enforcement based on GeoIP
• IP monitoring with route and interface failover • Juniper Advanced Threat Prevention to detect and block zero-
day attacks
1
GRE, IP-IP, J-Flow monitoring, and VRRP are not supported in stateful high-availability mode.
2
Available as part of Junos Software Enhanced (JSE) software package or advanced security subscription licenses.
3
Offered as advanced security services subscription licenses.
4
SRX300 Line of Services Gateways for the Branch
Hardware Specifications
4
SRX320 with PoE+ ports available as a separate SKU: SRX320-POE.
5
SRX345 with dual AC PSU model.
6
SRX320 non PoE model.
7
SRX320-POE with 6 ports PoE+ model.
8
As per GR63 Issue 4 (2012) test criteria.
9
SRX345 with DC power supply (operating temperature as per GR-63 Issue 4 2012 test criteria).
5
SRX300 Line of Services Gateways for the Branch
10
Throughput numbers based on UDP packets and RFC2544 test methodology.
11
Throughput numbers based on HTTP traffic with 44 KB transaction size.
12
Route scaling numbers are with enhanced route-scale features turned on.
6
SRX300 Line of Services Gateways for the Branch
subscription-based services with any of the Junos software SRX320-SYS-JB-P SRX320 Services Gateway includes hardware (8GbE, 6-port POE+, 2x
MPIM slots, 4G RAM, 8G Flash, power adapter and cable) and Junos
packages. Software Base (firewall, NAT, IPSec, routing, MPLS and switching). RMK
not included.
SRXnnn-SYS-JB SRXnnn-SYS-JE
SRX320-SYS-JE-P SRX320 Services Gateway includes hardware (8GbE, 6-port POE+, 2x
Hardware Included Included MPIM slots, 4G RAM, 8G Flash, power adapter and cable) and Junos
Software Enhanced (firewall, NAT, IPSec, routing, MPLS, switching and
Management (CLI, JWEB, SNMP, Telnet, SSH) • • application security). RMK not included.
Ethernet switching (L2 Forwarding, IRB, LACP etc) • • SRX340-SYS-JB SRX340 Services Gateway includes hardware (16GbE, 4x MPIM slots,
L2 Transparent, Secure Wire • • 4G RAM, 8G Flash, power supply, cable and RMK) and Junos Software
Base (firewall, NAT, IPSec, routing, MPLS and switching)
Routing (RIP, OSPF, BGP, Virtual router) • •
SRX340-SYS-JE SRX340 Services Gateway includes hardware (16GbE, 4x MPIM slots,
Multicast (IGMP, PIM, SSDP, DMVRP) • • 4G RAM, 8G Flash, power supply, cable and RMK) and Junos Software
Enhanced (firewall, NAT, IPSec, routing, MPLS, switching and application
Packet Mode • •
security)
Overlay (GRE, IP-IP) • •
SRX345-SYS-JB SRX345 Services Gateway includes hardware (16GbE, 4x MPIM slots,
Network Services (J-Flow, DHCP, QOS, BFD) • • 4G RAM, 8G Flash, power supply, cable and RMK) and Junos Software
Base (firewall, NAT, IPSec, routing, MPLS and switching)
Stateful Firewall, Screens, ALGs • •
SRX345-SYS-JE SRX345 Services Gateway includes hardware (16GbE, 4x MPIM slots,
NAT (static, SNAT, DNAT) • • 4G RAM, 8G Flash, power supply, cable and RMK) and Junos Software
IPSec VPN (Site-Site VPN, Auto VPN, Group VPN) • • Enhanced (firewall, NAT, IPSec, routing, MPLS, switching and application
security)
Firewall policy enforcement (UAC, Aruba CPPM) • •
SRX345-SYS- SRX345 Services Gateway includes hardware (16GbE, 4x MPIM slots,
Remote Access VPN (2 free licenses) L L JB-2AC 4G RAM, 8G Flash, dual AC power supply, cable and RMK) and Junos
Chassis Cluster, VRRP, ISSU / ICU • • Software Base (firewall, NAT, IPSec, routing, MPLS and switching)
Automation (Junos scripting, auto-installation) • • SRX345-SYS- SRX345 Services Gateway includes hardware (16GbE, 4x MPIM slots,
JE-2AC 4G RAM, 8G Flash, dual AC power supply, cable and RMK) and Junos
MPLS, LDP, RSVP, L3 VPN, pseudo-wires, VPLS • • Software Enhanced (firewall, NAT, IPSec, routing, MPLS, switching and
application security)
Application Security (AppID, AppFW, AppQOS,
•
AppRoute) SRX345-SYS-JB- SRX345 Services Gateway includes hardware (16GbE, 4x MPIM slots,
DC 4G RAM, 8G Flash, single DC power supply, cable and RMK) and Junos
Software Base (firewall, NAT, IPSec, routing, MPLS and switching)
L = Per-user license-based; two free user licenses included.
SRX345-SYS-JE- SRX345 Services Gateway includes hardware (16GbE, 4x MPIM slots,
DC 4G RAM, 8G Flash, single DC power supply, cable and RMK) and Junos
Software Enhanced (firewall, NAT, IPSec, routing, MPLS, switching and
application security)
7
SRX300 Line of Services Gateways for the Branch
www.juniper.net
Copyright 2019 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper Networks logo, Juniper, and Junos are registered trademarks of Juniper Networks, Inc. in the United
States and other countries. All other trademarks, service marks, registered marks, or registered service marks are the property of their respective owners. Juniper Networks assumes no
responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice.