Download presentation
1
SRX Product Presentation
Mike Flaum Product Marketing Manager April 23, 2009
2
Legal statement This statement of product direction sets forth Juniper Networks’ current intention and is subject to change at any time without notice. No purchases are contingent upon Juniper Networks delivering any feature or functionality depicted on this statement. This presentation is under NDA until May 4, 2009 for all customers, Partners, Resellers, Distributors or any person or entity outside of Juniper Networks.
3
Table of contents Distributed Enterprise
SRX Series Services Gateways - Product 9am - 10:00am Service Provider Key Trends and Vertical Market and (Scott and Michael) 10am – 11:30am Examples of Managed Services with a Juniper Networks Foundation (Scott and Michael) 12am - 1:30am Juniper Enterprise Product Overview, Road Maps for J series and Firewalls (Scott and Michael) 1:30- 2:00 Lunch 2:00- 3:30PM Technical Presentation (Patricio or Eric)
4
Today’s news New Distributed Enterprise Solutions
Best reach for a carrier-grade network OS New SRX Services Gateway Series starting at $699 New entry-level EX Series Gigabit access switches First Secure Router with integrated content security Unified Threat Management and Intrusion Prevention Services now integrated into JUNOS software Only “Support Engineer in a Box” service Advanced Insight Solutions now available for branch products 4
5
Multi-year trends in the enterprise
Clients (billions) Global High-Performance Network Mega Data Centers (thousands) The Distributed Enterprise Workforce Globalization Mobile Home Branch Data/App Consolidation Campus 5
6
Distributed enterprise realities
Global workforce centers Thousands of employees Headquarters in Sunnyvale Why Does the Distributed Enterprise Need a High-Performance Network? Secure and reliable transactions Responsive and private applications High-quality collaboration and communications Hundreds of employees Design center in Bangalore Acquisition in Boston Cost Complexity Risk Regional Sales Office Tens of employees Service office Sales office A handful of employees
7
Using high-performance networking to reduce complexity
Scalable Fast Reliable Secure Simple Legacy Network Juniper High-Performance Network OS #1 OS #2 OS #3 OS #4 Learn and configure one OS Firewall/VPN Switch Router Voice gateway UTM IPS Access Control Dynamic Services Architecture Firewall/VPN Switch Router Voice gateway UTM IPS Access Control Use fewer boxes Simplify software management 9.2 9.3 9.4 7 7
8
Unified Management (NSM)
Solution portfolio SRX5000 Series EX8216 SRX3000 Series MX Series SERVICES GATEWAYS SRX650 EX8208 ROUTERS SWITCHES SRX240 EX4200 M Series SRX210 EX3200 J Series SRX100 EX2200 Unified Management (NSM) 8 8
9
SRX SERIES SERVICE GATEWAYS
10
Branch SRX Launch What When Value Proposition Non-Disclosure Agreement
Juniper SRX for the Branch, a broad line of dynamic services platforms with leading connectivity, security, and application delivery capabilities on a single box When New products will be publicly announced during Juniper’s “Distributed Enterprise Solutions” launch on May 4th Value Proposition Single-box integration of fast, highly available routing, switching, adaptive threat management, and application services using a common, proven operating system for exceptional Enterprise-wide consistency Non-Disclosure Agreement NDA is required for SRX Series briefings for all customers, partners, resellers, and distributors prior to the May 4, 2009 launch date
11
Three key market drivers
Antispam Antivirus IPS Web filtering UTM LICENSED UAC Content Filtering FREE CONSOLIDATION Voice and Data Network migration to multi-service platform—“Secure Router” instead of multiple appliances Secure Router = Router + Firewall + VPN + Switching Unified Threat Management IPSec VPN Routing Firewall Ethernet Switching NETWORK SECURITY VoIP Analog Fax WLAN AP Security Camera Power Over Ethernet CONVERGENCE VoIP Gateway and VoIP handsets Power over Ethernet Wireless Access Points 3G PSTN MPLS Internet Metro CONNECTIVITY Internet Metro Ethernet MPLS Wireless WAN 3G PSTN
12
Content Security Acceleration
New SRX Services Gateways Leveraging Juniper’s Dynamic Services Architecture Up to 80% lower price Highly configurable Fixed, semi-modular, and modular form factors Choice of WAN, wireless, and LAN interfaces Available voice media gateway Extensive integration Full suite of JUNOS routing and switching capabilities Unmatched security, including FW, VPN, UTM, UAC, and full IPS Exceptional performance and availability Hardware-assisted Content Security Acceleration for ExpressAV and IPS Control & data plane separation, redundant processing and power Priced at $699, $1099, $2999, and $16000 (list) 20X IPS performance Full UTM 16 X Gigabit Ethernet Model Configuration SIP Gateway Content Security Acceleration FW/IPS Performance SRX100 Fixed No 600/50 Mbps SRX210 1 mini PIM slot Optional Optional 750/80 Mbps SRX240 4 mini PIM slots 1500/250 Mbps SRX650 8 GPIM slots Standard 7000/900 Mbps Advanced FW / VPN /ROUTING license included Roadmap 12
13
The SRX Branch portfolio 2009
+ More LAN slots, dual processors, dual P/S SRX 240 NSM + 4 WAN slots, 16 x Gig E Centrally managed by NSM SRX 210 + WAN slot, 2 x Gig E, PoE SRX 100 Telecommuter/Small Office Small to Medium Office Large Branch/Regional Office 13
14
Typical Deployment
15
SRX Series Specification Summary
FEATURES SRX100 (target) SRX210 SRX240 SRX650 On-board Ethernet 8 x FE 2 x GE + 6 x FE 16 x GE 4 x GE Power over Ethernet (802.3af, 802.3at) None 4 ports—50 W total 16 ports GE, 150 W 48 ports GE, 250 W or 500 W WAN slots 1 x mini PIM 4 x SRX mini PIM 8 x GPIM USB ports (flash) 1 2 2 per processor Content Security Acceleration— ExpressAV and Intrusion Detection and Prevention No YES JUNOS Software version support JUNOS 9.6 JUNOS 9.5 Routing Performance 60 Kpps 80Kpps 200Kpps 900Kpps Firewall performance (Large Packets) 600 Mbps 750 Mbps 1.5 Gbps 7.0 Gbps Firewall performance (IMIX) 175 Mbps 250 Mbps 500 Mbps 2.5 Gbps Firewall performance (Firewall + Routing PPS 64byte) 65 Kpps 75 Kpps 150 Kpps VPN Performance—AES256+SHA-1 3DES+SHA 1 65 Mbps 75 Mbps Intrusion Prevention System 50 Mbps 80 Mbps 900 Mbps Connections Per Second (CPS) 2K 9K 35K Maximum Concurrent Sessions (512MB/1GB RAM) 16 K / 32K 32K / 64K 64K / 128K 512 K Antivirus TBD 30 Mbps 85 Mbps 350 Mbps High Availability A/A or A/P A/A* or A/P A/A* or A/P, Hot swap GPIMs, Dual processors*, Dual power SRX650 * Supported in JUNOS 9.6 15
16
SRX100 Ideal for micro-branch, managed telecommuters, SOHO
Q3 2009 SRX100 Features SRX100 (target) On-board Ethernet 8 x FE Power over Ethernet (802.3af, 802.3at) None WAN slots USB ports 1 3G Future Intrusion Prevention System No JUNOS Software version support JUNOS 9.6 Routing performance 60 Kpps Firewall performance (Large Packets) 600 Mbps Firewall performance (IMIX) 175 Mbps Firewall performance (Firewall + Routing PPS 64byte) 65 Kpps VPN Performance—AES256+SHA-1 65 Mbps VPN Performance —3DES+SHA 1 50 Mbps Connections Per Second (CPS) 2K Maximum Concurrent Sessions (512MB/1GB RAM) 16 K / 32K IPS performance TBD High Availability A/A or A/P Ideal for micro-branch, managed telecommuters, SOHO Fixed I/O—8 x 10/100 Ethernet ports Full UTM features IDP Antivirus Anti-spam Web filtering UAC Enforcement UTM requires High Memory model (UTM, license), no CSA 16
17
SRX210 Ideal for Small branches Full UTM features
Q2 2009 SRX210 Features SRX210 On-board Ethernet 2 x GE + 6 x FE Power over Ethernet (802.3af, 802.3at) 4 ports—50 W total WAN slots 1 x mini PIM 3G wireless (ExpressCard slot) Yes USB ports (flash) 2 Content Security Accelerator—ExpressAV and Intrusion Detection and Prevention JUNOS Software version support JUNOS 9.5 Routing performance 80 Kpps Firewall performance (Large Packets) 750 Mbps Firewall performance (IMIX) 250 Mbps Firewall performance (Firewall + Routing PPS 64byte) 75 Kpps VPN Performance—AES256+SHA-1 75 Mbps VPN Performance —3DES+SHA 1 Connections Per Second (CPS) 2K CPS Maximum Concurrent Sessions (512MB/1GB RAM) 32K / 64K IPS performance 80 Mbps High Availability A/A or A/P Ideal for Small branches Full UTM features IDP, Antivirus, Anti-spam, Web filtering, Content filtering UAC Enforcement UTM requires High Memory model Available Voice version with mini-PIM options—Q3 2009 Factory-configured voice model (Q3 2009) 17
18
SRX240 Ideal for small–medium branches Full UTM features
Q2 2009 SRX240 Features SRX240 On-board Ethernet 16 x GE Power over Ethernet (802.3af, 802.3at) 16 ports GE, 150 W WAN slots 4 x SRX mini PIM USB ports (flash) 2 3G Future Content Security Accelerator—ExpressAV and Intrusion Detection and Prevention Yes JUNOS Software version support JUNOS 9.5 Routing performance 200 Kpps Firewall performance (Large Packets) 1.5 Gbps Firewall performance (IMIX) 500 Mbps Firewall performance (Firewall + Routing PPS 64byte) 150 Kpps VPN Performance—AES256+SHA-1 250 Mbps VPN Performance —3DES+SHA 1 Connections Per Second (CPS) 9K CPS Maximum Concurrent Sessions (512MB/1GB RAM) 64K / 128K IPS performance High Availability A/A* or A/P Ideal for small–medium branches Full UTM features IDP, Antivirus, Anti-spam, Web filtering, Content filtering UAC Enforcement UTM requires High Memory model Available Voice version with mini-PIM options—Q4 2009 Factory-configured voice model (Q4 2009) Single PS for both POE and non POE options. * Supported in JUNOS 9.6 18
19
A/A* or A/P Hot swap GPIMs, Dual processors*, Dual power
Q2 2009 SRX650 Features SRX650 On-board Ethernet 4 x GE Power over Ethernet (802.3af, 802.3at) 48 ports GE, 250 or 500 W WAN slots 8 x GPIM USB ports (flash) 2 per processor 3G Future Content Security Accelerator—ExpressAV and Intrusion Detection and Prevention Yes JUNOS Software version support JUNOS 9.5 Routing performance 900 Kpps Firewall performance (Large Packets) 7.0 Gbps Firewall performance (IMIX) 2.5 Gbps Firewall performance (Firewall + Routing PPS 64byte) VPN Performance—AES256+SHA-1 1.5 Gbps VPN Performance —3DES+SHA 1 Connections Per Second (CPS) 35K CPS Maximum Concurrent Sessions (512MB/1GB RAM) 512 K IPS performance 900 Mbps High Availability A/A* or A/P Hot swap GPIMs, Dual processors*, Dual power Ideal for regional sites, large branches Modular- LAN switching Services Routing Processors with optional redundancy (future) power supplies with optional redundancy (at FRS) voice configurations (field upgradable via PIMs in 2010) Full UTM features IDP, Antivirus, Anti-spam, Web filtering, Content filtering UAC Enforcement Max Gig E 52 ports (2 x 24 GE PIM + 4 integrated ports) * Supported in JUNOS 9.6 *Supported in JUNOS 9.6 19
20
SRX210 with Integrated Convergence Services
Q3 2009 SRX210 with Integrated Convergence Services FXS ports – connect your analog phone or FAX machine here E1/T1 or FXOs for carrier trunk or FXS for additional analog phones/ fax machines FXO ports – connect to your wall phone socket Target Branch Size (# users) No. Slots Base DSP Channels Base No. of Ports Expansion Slots SRX210 2–25 1 mPIM 8–16 (codec dependent) 2 FXO, 2FXS T1/E1 4 FXO 2 FXS + 2 FXO SRX240 10–50 4 mPIMs 30–48 2 FXO, 2 FXS SRX650 50–200 8 gPIMs Requires gPIM Dual T1/E1 6 FXO + 2 FXS 2 FXO + 6 FXS SRX Voice Elements Survivable SIP server SIP Media Gateway SIP Security Base and expandable voice ports PoE Ports PoE Ports scaling with EX switch 20
21
2H 2009 Juniper Integrated Convergence Services Stage 1: Survivable Media Gateway SERVICE PROVIDER VOIP SIP Trunking to Corporate to PSTN (typical) Failover to PSTN Local PSTN Local PSTN 5 3 SIP Soft Switch SIP Trunking “VoIP to PSTN” S.P. VoIP Channelized T-1 / E1/ FXO CORPORATE OFFICE 4 X INTERNET 4 SRX210 / SRX240 SIP VoIP handset SIP Server 4 3 3 WAN MPLS 3 2 2 2 SIP VoIP handset to digital or analog phone 1 SIP Trunking “Toll bypass”, “extension” 1 PBX, Key System SIP VoIP handset Analog FAX Soft Phones Digital Enterprise choice and flexibility SIP Server and SIP Soft switch SIP standards Choice of sip phones, call servers and applications 21
22
3G Wireless WAN Deployments-
2H 2009 3G Wireless WAN Deployments- Primary connection where wired broadband is not available Back up connectivity with wired primary. Out of band management, remote deployment. Available on SRX210 Datacenter HQ INTERNET 3G Wireless Dynamic VPN Services SRX210 Retail Branch Regional 22
23
Branch Wireless AP Solution
Q4 2009 Branch Wireless AP Solution Juniper n indoor Solution Backwards compatible to .11a/b/g Dual mode radio support 300Mbps (Aggregate) Single radio 200Mbps (160Mbps typical) Spatial Streams: 2x2:2, 2x3:2, 3x3:2 UL2043 Plenum rated for over ceiling mounting. 50 Meter range (indoor) Unit can be mounted on ceiling or wall Virtual AP technology – Support of up to 16 simultaneous SSIDs 802.11e WMM capable 1 Gigabit Ethernet POE support Optional External Power Supply Serial Consol Support L2 Managed by SRX Branch Products Additional licensing cost for Branch SRX to manage multiple access points – Clusters of 4,8,16 APs.
24
Ethernet Switching Hardware (Onboard Ethernet) Hardware Ethernet PIMs
SRX100 SRX210 SRX240 SRX650 Software Features 802.1Q VLAN support Up to 4,096 VLAN support (platform dependent) Routed VLAN Interface (RVI) GARP VLAN Registration Protocol (GVRP) QOS on VLAN interface L3 Strict priority queuing (LLQ) L3 Smoothed Deficit Weighted Round Robin (SDWRR) L3 Weighted Random Early Discard (WRED) L3 Per port and per queue shaping 802.1x Port based Authentication 802.3ad (AX) link aggregation* STP, Spanning Tree Protocol 802.1D Spanning Tree Protocol 802.1S Multiple STP 802.1w Rapid STP Jumbo Frame Support (9,216 Byte)* Hardware (Onboard Ethernet) SRX100 8 Fixed 10/100 (Switched or Routed) SRX210 Fixed 2 10/100/ /100 (Switched or Routed) 802.3af optional POE (2FE + 2GE) SRX240 Fixed 16 Ports 10/100/1000 (Switched or Routed) Power over Ethernet (optional all ports) 802.3af, 802.3at SRX650 Fixed 4 ports 10/100/1000 (Routed) Hardware Ethernet PIMs SRX Mini-PIM (SRX210/SRX240) 1 Port SFP 16 port GigE XPIM for SRX650 Double-high Full-duplex 20 Gbps backplane 16 port GE and optional PoE 24 port GigE including 4 SFP slots XPIM for SRX650 Double-high - double-wide Optional POE - 24 port GE with PoE incl 4 SFP slots Optics SRX GE SFP LH | SRX GE SFP LX | SRX GE SFP SX | SRX GE SFP 1000 Base-T | SRX FE FX SFP * Not supported on SRX100 24
25
SRX Series—Firewall, Zones, and Policies
ZONE “UNTRUST” Originating Zone INTERNET Default Policy—Allow All Default Policy—Deny All SRX Originating Zone ZONE “TRUST” ZONE “TRUST”
26
Unified Threat Management (UTM) Features
External Threats Internal Threats INTERNET IPS Juniper IDP detects/stops Worms, Trojans, DoS (L4 & L7), Scans Juniper IDP detects/stops Worms, Trojans, DoS (L4 & L7), Scans Web Filtering Websense to block to unapproved site access Antivirus Kaspersky Lab AV stops viruses, file-based trojans or spread of spyware, adware, keyloggers Kaspersky Lab AV stops Viruses, file-based Trojans, Spyware, Adware, Keyloggers Anti-spam Symantec stops Spam / Phishing Content Filtering SRX Series blocks transmission of files for Data Loss Prevention Core Security Firewall, VPN, Unified Access Control Firewall, VPN, Unified Access Control
27
Juniper Networks Unified Access Control (UAC)
POLICY SERVER Comprehensive, vendor-agnostic, standards-based access control across heterogeneous environments delivering investment protection 1 IC Series Identity Stores Authenticate User, Profile Endpoint, Determine Location 1 2 Dynamically Provision Policy Enforcement 2 APPLICATIONS 3 NS SSG ISG Control Access to Protected Resources Data App Internet SRX UAC Agent EX Series L2 Switch 802.1X Switches & Access Points Juniper Firewall Platforms UAC Enforcement Points
28
Remote Access Dynamic VPN Service – Access Manager Client
Q2 2009 Remote Access Dynamic VPN Service – Access Manager Client A dynamic IPSEC Client that is automatically downloaded 5-user, 10-user, 25-user, 50-user (SRX240) license option with simultaneous tunnel enforcement Supported on the SRX100, SRX210, and SRX240 Not supported on SRX650 Automatic client upgrade capabilities Self-provisioning from SRX210, SRX240 IPSec with TCP-based fallback for NAT traversal Initial release to support Windows platforms—XP, Vista, Win 2000 Wireless Wired 3G Wireless INTERNET Dynamic VPN Services SRX210 28
29
Juniper Unified Management
Unified management across Juniper’s network infrastructure Network lifecycle management—Provision, Monitor, and Troubleshoot Consistent and Open standards NBI for easy integration with 3rd party NMS SNMP, Syslog SNMP, Syslog, XML EMS NMS Visibility Diagnostics JUNOScope Network & Security Manager (NSM) Security Threat Response Manager Advanced Insight Manager NETWORK MANAGEMENT NetConf, DMI, Syslog, Sflow Telnet, SSH, XML ONE JUNOS CLI, JUNOScript ONE J-Web Web UI HTTP / HTTPS XML Juniper Network Management portfolio (NSM, STRM and AIM) enables operational and cost efficiencies through: - Full network life cycle management (Provisioning/Visibility/Diagnostics) -closed loop, less resource-intensive, one-stop-shop - Single configuration/provisioning platform across Juniper’s security/routing/switching devices - Single event monitoring/threat management solution across all Juniper systems - Case automation for efficient and cost effective incident management - Network-wide visibility with application-level granularity - Appliance form factor for one stop HW/OS/Application support - Rapid deployment – no server provisioning lead times - Schema-based device/NSM interface for day 0 deployment (application transparency) - One Stop Support for hw/OS/Application Juniper Network Management for the collapsed data center leverages industry leading juniper network management products widely deployed at customers such as NSM, STRM and AIM NSM is the configuration and policy manager JMP is juniper management platform. NSM could be dead after PCM on JMP shows up – roughly end of 09. ISG/IDP SSL VPN MX Series M Series Infranet Controller SRX5600 Routing Security Switching 29 29
30
Network Security Manager
*NSM currently manages J, M, MX, EX, SSL, UAC, FW/VPN, and IDP, but not WX Along with SRX, NSM Manages Juniper’s entire enterprise portfolio* NSM is a great way to port ScreenOS customers over to a JUNOS solution and to help manage a mixed environment Common Management also offers huge up-sell opportunity
31
Security Threat Response Manager
STRM supports SRX Series Intrusion Prevention System (IPS) 220+ out-of-the box report templates Fully customizable reporting engine: creating, branding and scheduling delivery of reports Compliance reporting packages for PCI, SOX, FISMA, GLBA, and HIPAA Reports based on control frameworks: NIST, ISO and CoBIT
32
Rapid Deployment Simplified deployment- Reduce - Provisioning time
Q4 2009 Rapid Deployment Simplified deployment- Eliminate need for- Pre-staging device IT at point of installation Reduce - Provisioning time Installation cost No “truck roll” USB Loads startup config Validation of start up config Secure communication to NSM SRX 210 6. SRX In Service 5. Download Running Config 1. Generate and export startup config to USB A Unique ID for tracking purposes Untrust Interface configuration Configuration parameters to enable “registration” of device to management server User/Password Management Server IP Address/Domain Name One time password Points: Rapid deployment – using ScreenOS, NSM can easily deploy new devices into the network in remote locations. Rapid Deployment: The device WebUI wizard has the ability to ask for a configlet file at initial install and then load minimal settings so that the device can talk to NetScreen-Security Manager to request a complete download of the full configuration file. Because the management system can automatically send a configuration to a new device upon successful registration, there is no need to pre-stage a device before shipping it to a remote office. This reduces provisioning time and lowers training costs, and it is all done using a secure provisioning process. This feature works with ScreenOS 5.0. Customers have been able to roll out 100 devices in a day with limited ScreenOS knowledge required for the installer. Network Security Manager
33
Juniper Branch Products SSG, SRX, and J Series Products
Unified Threat Management Full IDP—Juniper Antivirus—Kaspersky Web filtering—Websense Anti-spam—Symantec VoIP Juniper OpenCommunications Power over Ethernet FW, VPN, NAT, UAC SSG Family FW, VPN, NAT, UAC IPv6 Security Wireless (WLAN) Unified Threat Management Intrusion Prevention: DI Antivirus—Kaspersky Web filtering—Websense Anti-spam—Symantec J Series FW, VPN, NAT, UAC Routing, Switching, QOS, MPLS WX—ISM 200 Application Acceleration VoIP—Avaya Integ. Gway Unified Threat Management Full IDP—Juniper Antivirus—Kaspersky Web filtering—Websense Anti-spam—Symantec SRX 100 SRX 210 SRX 240 SRX 650 SSG20 Wireless J2320 SSG5 Wireless SSG140 SSG320M J2350 SSG520 SSG520M J4350 SSG350M ScreenOS SSG550 SSG550M J6350
34
THANK YOU 34
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.