TrustRadius: an HG Insights company

Juniper SRX

Score9 out of 10

34 Reviews and Ratings

What is Juniper SRX?

Juniper SRX is a firewall offering. It provides a variety of modular features, scaled for enterprise-level use, based on a 3-in-1 OS that enables routing, switching, and security in each product.

Categories & Use Cases

Top Performing Features

  • Policy-based Controls

    Firewall policy controls enable administrators to create firewall policies controlling what data is allowed to traverse the firewall

    Category average: 8.9

  • VPN

    VPN's implement encryption and anonymize IP addresses

    Category average: 9.1

  • High Availability

    Built-in capacity to prevent exposure if primary firewall stops working

    Category average: 9.2

Areas for Improvement

  • Reporting and Logging

    Custom and summary reports, and log files enabling analysis of security incidents, application usage and traffic patterns

    Category average: 8.2

  • Visualization Tools

    Visualization tools present administrators with data on applications traversing the network, who is using them, and the potential security impact.

    Category average: 8

  • Firewall Management Console

    Either command-line or web-based interface for centralized control and management

    Category average: 8.1

SRX: A very versitile Router/Firewall Box

Pros

  • Edge Device (Tunneling & Routing)
  • Routing Instances
  • Zone Based Firewall
  • L3 Gateway/Vlan termination
  • DHCP Server & DHCP Relay
  • Good support community & Good available documentation
  • Good support by the Vendor

Cons

  • The GUI is pretty basic and need some enhancements

Most Important Features

  • Edge Device/Tunnel Termination
  • Routing (eBGP)
  • Zone Based Firewall
  • L3 Gateway
  • DHCP Server/Relay

Return on Investment

  • Solid Return of investment as an edge gateway appliance
  • Very versatile appliance that supports multiple deployment scenarios and configuration. one ha/pair can serve multiple functions using Routing Instances.
  • Great support by the vendor, community and online resources
  • it is not hard to find people with Juniper experience and there is training courses and resources that can help anyone with networking experience pick it up and be able to administrate and configure the box.

Alternatives Considered

Palo Alto Networks Next-Generation Firewalls - PA Series, Fortinet FortiGate and Cisco Cloud Services Router 1000V Series (CSR 1000V)

Other Software Used

VMware NSX, IBM Cloud for VMware Solutions, Veeam Backup & Replication, VMware HCX (CloudVelox), Palo Alto Networks Next-Generation Firewalls - PA Series, Cisco Cloud Services Router 1000V Series (CSR 1000V)

Juniper SRX. A Swiss army knife for routing and security.

Pros

  • The ease of use for the CLI is a huge benefit. Unlike the Cisco platform, all changes are implemented in a commit statement vs. live on the box.
  • The devices hit a price point that is very competitive.
  • Dynamic routing support is a huge win.

Cons

  • The areas that can improve are met by higher-level platforms within the Juniper portfolio.

Return on Investment

  • It is a workhorse for our field operations. It provides the last touch for an ISP to the customer. The customer has no view of the device, but with the repeatability of the device, they do not need to.
  • The ability to roll out a dynamic routing protocol attached to a security zone allows elasticity to the environment that supports growth.
  • VLAN support on the inside interfaces allow this to be the only device in some smaller deployments we install these in.

Alternatives Considered

Cisco ASA and Cisco IOS

Juniper SRX stands tall for Service Provider Networks.

Use Cases and Deployment Scope

Juniper SRX is used as Network Firewall, which is responsible for securing the workload behind it. It addresses Network Security within the organization, limits the access of the organization's internal network, and secures the enterprise network from threats and from malicious users. Juniper SRX also helped send the traffic to the Internet with the help of Network Address Translation.

Pros

  • Network Address Translation.
  • Securing the Enterprise Workload.
  • Enterprise VPN Connectivity.

Cons

  • Antivirus Features can be more advanced.
  • Antispam Filtering features have room for improvement.
  • Cloud Capabilities.

Most Important Features

  • IPSec VPN.
  • Network Address Translation.
  • Security Policies.

Return on Investment

  • It really helped secure a big service provider environment.
  • It handles the traffic pretty well.
  • It helps in the seamless implementation of Firewall policies.

Alternatives Considered

Cisco ASA 5500-X with FirePOWER Services, Palo Alto Networks Next-Generation Firewalls - PA Series, Cisco Adaptive Security Appliance (ASA) Software and Fortinet FortiGate

Other Software Used

Fortinet FortiGate, Palo Alto Networks Next-Generation Firewalls - PA Series, Cisco Adaptive Security Appliance (ASA) Software

Juniper SRX: When you don't have time to play around!

Pros

  • The Juniper SRX platform is easy to set up (out of the box).
  • The support team responds to tickets quickly and with good solutions.

Cons

  • My only real criticism of the product is that it's hard to figure out how to upgrade the firmware from the CLI via TFTP via the docs, but it works great once you get it sorted.

Return on Investment

  • A loss of a single metro ethernet carrier link between buildings is no longer a problem - a warehouse filled with idle pickers is expensive!
  • Using single-purpose Juniper SRX devices on each end provides reliable connectivity independent of SDWAN or any other integrated devices, which helps avoid annoying finger-pointing

Other Software Used

Microsoft Office 365, Tableau Desktop, Octopus Deploy

Juniper SRXs are the shizzle!!!

Pros

  • One JUNOS is the Juniper mantra, including for the SRXs. While not entirely true, it comes close enough that if you learn some SRX configuration tricks, they will likely work across all of your SRXs.
  • Out of the box, with no additional license required, you have a NextGen firewall, by default. You can turn off the firewall and have just a plain ole router.

Cons

  • Technical support is often lacking. By that, I mean that Tier 1 support frequently has to escalate to the next group. I find that most of my support calls don't get resolved until I hit about Tier 3. Plus it takes minimum of 3 days with medium priority issues.
  • Automation is very flexible, but because there are so many options, it would great to have a road map to perform the most frequent automation tasks.

Return on Investment

  • Annual capital savings on infrastructure equipment about $500,000.
  • Data Center switches function (and are managed) as a single virtual chassis, reducing maintenance and troubleshooting time.

Alternatives Considered

Cisco Catalyst 3560-CX Series Switches

Other Software Used

Juniper QFX Series, Juniper EX Series Ethernet Switches, VMware ESXi, VMware Carbon Black Cloud Endpoint Standard (formerly Cb Defense)