Juniper SRX300 Line of Services Gateways For The Branch
Juniper SRX300 Line of Services Gateways For The Branch
Product Description
Juniper Networks® SRX300 line of services gateways delivers a next-generation secure SD-
WAN and security solution that supports the changing needs of cloud-enabled enterprise
networks. Whether rolling out new services and applications across locations, connecting
to the cloud, or trying to achieve operational efficiency, the SRX300 line helps
Product Overview organizations realize their business objectives while providing scalable, easy to manage,
secure connectivity and advanced threat mitigation capabilities. Next-generation firewall
The SRX300 line of services and unified threat management (UTM) capabilities also make it easier to detect and
gateways combines security, proactively mitigate threats to improve the user and application experience.
SD-WAN, routing, switching,
The SRX300 line consists of five models:
and WAN interfaces with next-
generation firewall and • SRX300: Securing small branch or retail offices, the SRX300 Services Gateway
advanced threat mitigation consolidates security, routing, switching, and WAN connectivity in a small desktop
capabilities for cost-effective, device. The SRX300 supports up to 1 Gbps firewall and 300 Mbps IPsec VPN in a
secure connectivity across single, cost-effective networking and security platform.
distributed enterprise locations. • SRX320: Securely connecting small distributed enterprise branch offices, the SRX320
By consolidating fast, highly Services Gateway consolidates security, routing, switching, and WAN connectivity in a
available switching, routing, small desktop device. The SRX320 supports up to 1 Gbps firewall and 300 Mbps IPsec
security, and next-generation VPN in a single, consolidated, cost-effective networking and security platform.
firewall capabilities in a single
• SRX340: Securely connecting midsize distributed enterprise branch offices, the
device, enterprises can remove
SRX340 Services Gateway consolidates security, routing, switching, and WAN
network complexity, protect and
connectivity in a 1 U form factor. The SRX340 supports up to 3 Gbps firewall and 600
prioritize their resources, and
Mbps IPsec VPN in a single, cost-effective networking and security platform.
improve user and application
experience while lowering total • SRX345: Best suited for midsize to large distributed enterprise branch offices, the
cost of ownership (TCO). SRX345 Services Gateway consolidates security, routing, switching, and WAN
connectivity in a 1 U form factor. The SRX345 supports up to 5 Gbps firewall and 800
Mbps IPsec VPN in a single, consolidated, cost-effective networking and security
platform.
• SRX380: A high-performance and secure SD-WAN gateway, the SRX380 offers
superior and reliable WAN connectivity while consolidating security, routing, and
switching for distributed enterprise offices. The SRX380 features greater port density
than other SRX300 models, with 16x1GbE PoE+ and 4x10GbE ports, and includes
redundant dual power supplies, all in a 1 U form factor.
1
SRX300 Line of Services Gateways for the Branch
2
SRX300 Line of Services Gateways for the Branch
Business continuity Stateful high availability (HA), IP • Uses stateful HA to synchronize configuration and firewall sessions
monitoring • Supports multiple WAN interface with dial-on-demand backup
• Route/link failover based on real-time link performance
SD-WAN Better end-user application and cloud • ZTP simplifies remote device provisioning
experience and lower operational • Advanced Policy-Based Routing (APBR) orchestrates business intent policies across the enterprise WAN
costs
• Application quality of experience (AppQoE) measures application SLAs and improves end-user experience
• Controls and prioritizes traffic based on application and user role
End-user experience WAN assurance • Complements the Juniper Secure SD-WAN solution with AI-powered automation and service levels
• Provides visibility and insights into users, applications, WAN links, control and data plane, and CPU for proactive
remediation
Highly secure IPsec VPN, Remote Access/SSL VPN, • Creates secure, reliable, and fast overlay link over public internet
Media Access Control Security • Employs anti-counterfeit features to protect from unauthorized hardware spares
(MACsec)
• Includes high-performance CPU with built-in hardware to assist IPsec acceleration
• Provides TPM-based protection of device secrets such as passwords and certificates
• Offers secure and flexible remote access SSL VPN with Juniper Secure Connect
Threat protection IPS, antivirus, anti-spam, enhanced • Provides real-time updates to IPS signatures and protects against exploits
web filtering, Juniper Advanced Threat • Protects from zero-day attacks
Prevention Cloud, Encrypted Traffic
Insights, and Threat Intelligence Feeds • Implements industry-leading antivirus and URL filtering
• Integrates open threat intelligence platform with third-party feeds
• Restores visibility that was lost due to encryption without the heavy burden of full TLS/SSL decryption
Application visibility On-box GUI, Security Director • Detects 3500+ Layer 3-7 applications, including Web 2.0
• Inspects and detects applications inside the SSL encrypted traffic
Easy to manage and On-box GUI, Security Director • Includes centralized management for auto-provisioning, firewall policy management, Network Address Translation (NAT),
scale and IPsec VPN deployments, or simple, easy-to-use on-box GUI for local management
Minimize TCO Junos OS • Integrates routing, switching, and security in a single device
• Reduces operation expense with Junos automation capabilities
3
SRX300 Line of Services Gateways for the Branch
SRX300 Specifications
Software Specifications
Routing Protocols Firewall Services
• IPv4, IPv6, ISO, Connectionless Network Service (CLNS) • Stateful and stateless firewall
• Static routes • Zone-based firewall
• RIP v1/v2 • Screens and distributed denial of service (DDoS) protection
• OSPF/OSPF v3 • Protection from protocol and traffic anomaly
• BGP with Route Reflector • Integration with Pulse Unified Access Control (UAC)
• IS-IS • Integration with Aruba Clear Pass Policy Manager
• Multicast: Internet Group Management Protocol (IGMP) v1/v2, • User role-based firewall
Protocol Independent Multicast (PIM) sparse mode (SM)/dense • SSL Inspection (Forward-proxy)
mode (DM)/source-specific multicast (SSM), Session
Network Address Translation (NAT)
Description Protocol (SDP), Distance Vector Multicast Routing
• Source NAT with Port Address Translation (PAT)
Protocol (DVMRP), Multicast Source Discovery Protocol
• Bidirectional 1:1 static NAT
(MSDP), Reverse Path Forwarding (RPF)
• Destination NAT with PAT
• Encapsulation: VLAN, Point-to-Point Protocol (PPP), Frame
• Persistent NAT
Relay, High-Level Data Link Control (HDLC), serial, Multilink
• IPv6 address translation
Point-to-Point Protocol (MLPPP), Multilink Frame Relay
(MLFR), and Point-to-Point Protocol over Ethernet (PPPoE) VPN Features
• Virtual routers • Tunnels: Site-to-Site, Hub and Spoke, Dynamic Endpoint,
• Policy-based routing, source-based routing AutoVPN, ADVPN, Group VPN (IPv4/ IPv6/ Dual Stack)
• Equal-cost multipath (ECMP) • Juniper Secure Connect: Remote access / SSL VPN
• Configuration payload: Yes
QoS Features
• IKE Encryption algorithms: Prime, DES-CBC, 3DES-CBC, AEC-
• Support for 802.1p, DiffServ code point (DSCP), EXP
CBC, AES-GCM, SuiteB
• Classification based on VLAN, data-link connection identifier
• IKE authentication algorithms: MD5, SHA-1, SHA-128,
(DLCI), interface, bundles, or multifield filters
SHA-256, SHA-384
• Marking, policing, and shaping
• Authentication: Pre-shared key and public key infrastructure
• Classification and scheduling
(PKI) (X.509)
• Weighted random early detection (WRED)
• IPsec (Internet Protocol Security): Authentication Header
• Guaranteed and maximum bandwidth
(AH) / Encapsulating Security Payload (ESP) protocol
• Ingress traffic policing
• IPsec Authentication Algorithms: hmac-md5, hmac-sha-196,
• Virtual channels
hmac-sha-256
• Hierarchical shaping and policing
• IPsec Encryption Algorithms: Prime, DES-CBC, 3DES-CBC,
Switching Features AEC-CBC, AES-GCM, SuiteB
• ASIC-based Layer 2 Forwarding • Perfect forward secrecy, anti-reply
• MAC address learning • Internet Key Exchange: IKEv1, IKEv2
• VLAN addressing and integrated routing and bridging (IRB) • Monitoring: Standard-based dead peer detection (DPD)
support support, VPN monitoring
• Link aggregation and LACP • VPNs GRE, IP-in-IP, and MPLS
• LLDP and LLDP-MED
• STP, RSTP, MSTP
• MVRP
• 802.1X authentication
4
SRX300 Line of Services Gateways for the Branch
1
Offered as advanced security services subscription licenses.
5
SRX300 Line of Services Gateways for the Branch
Hardware Specifications
6
SRX300 Line of Services Gateways for the Branch
7
SRX300 Line of Services Gateways for the Branch
Ethernet switching (L2 Forwarding, IRB, LACP etc) Included SRX380-P-SYS- SRX380 Services Gateway includes hardware (16GbE PoE+, 4x10GbE, 4x
JB-AC MPIM slots, 4GB RAM, 100GB SSD, single AC power supply, cable and
L2 Transparent, Secure Wire Included RMK) and Junos Software Base (firewall, NAT, IPSec, routing, MPLS and
Routing (RIP, OSPF, BGP, Virtual router) Included switching)
11
Based on concurrent users; two free licenses included
8
SRX300 Line of Services Gateways for the Branch
9
SRX300 Line of Services Gateways for the Branch
Accessories
Product Description
Number
SRX300-RMK0 SRX300 rack mount kit with adaptor tray
SRX300-RMK1 SRX300 rack mount kit without adaptor tray
SRX300-WALL-KIT0 SRX300 wall mount kit with brackets
SRX320-P-RMK0 SRX320-POE rack mount kit with adaptor tray
SRX320-P-RMK1 SRX300-POE rack mount kit without adaptor tray
SRX320-RMK0 SRX320 rack mount kit with adaptor tray
SRX320-RMK1 SRX320 rack mount kit without adaptor tray
SRX320-WALL-KIT0 SRX320 wall mount kit with brackets
SRX34X-RMK SRX340 and SRX345 rack mount kit
EX-4PST-RMK SRX380 rack mount kit
JSU-SSD-MLC-100 Juniper Storage Unit, SSD, MLC, 100GB
JPSU-600-AC-AFO SRX380 600W AC PSU, front-to-back
or +1.408.745.2000
[Link]
Copyright 2021 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper Networks logo, Juniper, and Junos are registered trademarks of Juniper Networks, Inc. in the United
States and other countries. All other trademarks, service marks, registered marks, or registered service marks are the property of their respective owners. Juniper Networks assumes no
responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice.