SRX Juniper PDF
SRX Juniper PDF
SRX Juniper PDF
• SRX Series for the branch are secure routers that bring high performance and proven
deployment capabilities to enterprises that need to build a worldwide network of
thousands of sites. The wide variety of options allow configuration of performance,
functionality, and price scaled to support from a handful to thousands of users.
Ethernet, serial, T1/E1, DS3/E3, xDSL, Wi-Fi, and 3G/4G LTE wireless are all available
options for WAN or Internet connectivity to securely link your sites. Multiple form factors
allow you to make cost-effective choices for mission-critical deployments. Managing
the network is easy using the proven Junos OS command-line interface (CLI), scripting
capabilities, a simple-to-use Web-based GUI, or Juniper Networks Junos® Space
Security Director for centralized management.
1
SRX Series Services Gateways for the Branch Data Sheet
Product Description
SRX100 Services • Eight 10/100 Ethernet LAN ports and 1 USB port (support for 3G USB)
Gateway • Full UTM1; antivirus1, antispam1, enhanced Web filtering1, and content filtering
• Intrusion prevention system1, AppSecure1
• 2 GB DRAM, 2 GB flash default
SRX110 Services • VDSL/ADSL2+ and Ethernet WAN interfaces
Gateway • Eight 10/100 Ethernet LAN ports and two USB port (support for 3G USB)
• Full UTM1; antivirus1, antispam1, enhanced Web filtering1, intrusion prevention system1, AppSecure1
• Unified Access Control (UAC) and content filtering
• 2 GB DRAM, 2 GB CF default
SRX210 Services • Two 10/100/1000 Ethernet and 6 10/100 Ethernet LAN ports, 1 Mini-PIM slot, and 2 USB ports (support for 3G USB)
Gateway • Factory option of 4 dynamic Power over Ethernet (PoE) ports 802.3af
• Support for T1/E1, serial, ADSL/2/2+, VDSL, G.SHDSL, and Ethernet small form-factor pluggable transceiver (SFP)
• Content Security Accelerator hardware for faster performance of IPS and ExpressAV (with high memory version)
• Full UTM1; antivirus1, antispam1, enhanced Web filtering1, and content filtering
• Intrusion prevention system1, User role-based firewall, and AppSecure1
• 2 GB DRAM, 2 GB flash default
SRX220 Services • Eight 10/100/1000 Ethernet LAN ports, 2 Mini-PIM slots
Gateway • Factory option of 8 PoE ports; PoE+ 802.3at, backwards compatible with 802.3af
• Support for T1/E1, serial, ADSL2/2+, VDSL, G.SHDSL, and Ethernet SFP
• Content Security Accelerator hardware for faster performance of IPS and ExpressAV
• Full UTM1; antivirus1, antispam1, enhanced Web filtering1, and content filtering
• Intrusion prevention system1, User role-based firewall and AppSecure1
• 2 GB DRAM, 2 GB CF default
SRX240 Services • 16 10/100/1000 Ethernet LAN ports, 4 Mini-PIM slots
Gateway • Factory option of 16 PoE ports; PoE+ 802.3at, backwards compatible with 802.3af
• Support for T1/E1, serial, ADSL2/2+, VDSL, G.SHDSL, and Ethernet SFP
• Content Security Accelerator hardware for faster performance of IPS and ExpressAV
• Full UTM1; antivirus1, antispam1, enhanced Web filtering1, and content filtering
• Intrusion prevention system1, AppSecure1
SRX550 Services • Ten fixed Ethernet ports (6 10/100/1000 copper, 4 SFP), 2 Mini-PIM slots, 6 GPIM slots or multiple GPIM and XPIM
Gateway combinations
• Support for T1/E1, serial, ADSL2/2+, VDSL, G.SHDSL, DS3/E3, Gigabit Ethernet ports; supports up to 52 Ethernet
ports including SFP; 40 switch ports with optional PoE including 802.3at, PoE+, backwards compatible with 802.3af
(or 50 non-PoE 10/100/1000 copper ports)
• Content Security Accelerator hardware for faster performance of IPS and ExpressAV
• Full UTM1; antivirus1, antispam1, enhanced Web filtering1, and content filtering
• Intrusion prevention system1, User role-based firewall, and AppSecure1
• Threat intelligence for protection from command and control (C&C) botnets, Web application threats, and advanced
malware, and policy enforcement based on GeoIP data
• 2 GB DRAM default, 2 GB compact flash default (SRX550)
• 4 GB DRAM default, 8 GB compact flash default (SRX550 High Memory)
• Optional redundant AC power; standard AC power supply that is PoE-ready; PoE power up to 250 watts single power
supply or 500 watts dual power supply
SRX650 Services • F our fixed ports 10/100/1000 Ethernet LAN ports, 8 GPIM slots or multiple GPIM and XPIM combinations
Gateway • Support for T1, E1, DS3/E3, Ethernet ports; supports up to 52 Ethernet ports including SFP; 48 switch ports with
optional PoE including 802.3at, PoE+, backwards compatible with 802.3af (or 52 non-PoE 10/100/1000 copper ports)
• Content Security Accelerator hardware for faster performance of IPS and ExpressAV
• Full UTM1; antivirus1, antispam1, enhanced Web filtering1, and content filtering
• Intrusion prevention system1, User role-based firewall, and AppSecure1
• Threat intelligence for protection from command and control (C&C) botnets, Web application threats, and advanced
malware, and policy enforcement based on GeoIP data
• Modular Services and Routing Engine; future internal failover and hot-swap
• 2 GB DRAM default, 2 GB compact flash default, external compact flash slot for additional storage
• Optional redundant AC power; standard AC power supply that is PoE-ready; PoE power up to 250 watts single power
supply or 500 watts dual power supply
Network Deployments
The SRX Series Services Gateways for the branch are deployed at remote, branch and Enterprise edge locations in the network to
provide all-in-one secure WAN connectivity, and connection to local PCs and servers via integrated Ethernet switching.
1
Unified Threat Management—antivirus, antispam, Web filtering, AppSecure, and IPS require a subscription license option to use the feature. UTM is not supported on the low memory version.
Please see the ordering section for options. Content Filtering and UAC are part of the base software with no additional license.
2
SRX Series Services Gateways for the Branch Data Sheet
Figure 1: Firewalls, zones, to protect your environment network edge to fulfill their networking and security needs. For
and policies against threats, manage how many organizations, the SRX Series for the branch can fulfill
your network bandwidth is allocated, and control who has access both roles with one solution. Juniper built best-in-class routing,
to what. switching and firewall capabilities into one product.
3
SRX Series Services Gateways for the Branch Data Sheet
When SRX Series Services Gateways for the branch are the forwarding table along with a pointer to the next-hop route.
configured as an active/active HA pair, traffic and configuration Established sessions have a single table lookup to verify that the
is mirrored automatically to provide active firewall and VPN session has been permitted and to find the next hop. This efficient
session maintenance in case of a failure. The branch SRX Series algorithm improves throughput and lowers latency for session
synchronizes both configuration and runtime information. As a traffic when compared with a classic router that performs multiple
result, during failover, synchronization of the following information table lookups to verify session information and then to find a next-
is shared: connection/session state and flow information, IPSec hop route.
security associations, Network Address Translation (NAT) traffic,
Figure 3 shows the session-based forwarding algorithm. When a
address book information, configuration changes, and more. In
new session is established, the session-based architecture within
contrast to the typical router active/standby resiliency protocols
Junos OS verifies that the session is allowed by the forwarding
such as Virtual Router Redundancy Protocol (VRRP), all dynamic
policies. If the session is allowed, Junos OS will look up the next-
flow and session information is lost and must be reestablished
hop route in the routing table. It then inserts the session and the
in the event of a failover. Some or all network sessions will have
next-hop route into the session and forwarding table and forwards
to restart depending on the convergence time of the links or
the packet. Subsequent packets for the established session
nodes. By maintaining state, not only is the session preserved,
require a single table lookup in the session and forwarding table,
but security is kept intact. In an unstable network, this active/
and are forwarded to the egress interface.
active configuration also mitigates link flapping affecting session
performance.
Session Initial
Security Policy Evaluation
Packet Processing and Next-Hop Lookup
Session-Based Forwarding Without the
Table
Performance Hit Update
Session and
In order to optimize the throughput and latency of the combined Forwarding Table
Ingress Forwarding for Egress
router and firewall, Junos OS implements session-based Interface Permitted Traffic Interface
forwarding, an innovation that combines the session state Disallowed by
Policy: Dropped
information of a traditional firewall and the next-hop forwarding
of a classic router into a single operation. With Junos OS, a Figure 3: Session-based forwarding algorithm
session that is permitted by the forwarding policy is added to
4
SRX Series Services Gateways for the Branch Data Sheet
3G
SRX110 SF.com SIP UC
Connectivity
Internet Facebook
Skype Server Server
Google
App Server
Small Office
Private Data Center
VDSL
Private WAN
SRX650 SRX650
4G LTE
Hosted Web
Large HA Office Server Server T1/E1 VDSL T1/E1
4G LTE
SFP DS3/E3 SRX210
SRX240
CX111
SRX550 SRX550
WLA532
SRX220 SRX240
SRX550 SRX650
5
SRX Series Services Gateways for the Branch Data Sheet
• MPLS (RSVP, LDP, Circuit Cross-connect (CCC), Translational • Screens denial of service (DoS) and provides distributed
Cross-connect (TCC), Layer 2 VPN (VPLS), Layer 3 VPN, denial of service (DDoS) protection (anomaly-based)
VPLS, NGMVPN) • Prevent replay attack; Anti-Replay
• Source NAT with Port Address Translation (PAT) -- Malformed packet protection
• 802.1x, LLDP, 802.1ad (Q-in-Q), IGMP Snooping -- User-based application policy enforcement
1
BGP Route Reflector supported on SRX550 and SRX650. See ordering section for more information.
2
As of Junos 15.1X49-D40, the SRX550 High Memory unit does not support xSTP, LLDP, 802.1x, Q-in-Q, IGMP Snooping and L2 switching with HA
3
Unified Threat Management – antivirus, antispam, Web filtering, AppSecure, and IPS require individual subscription license. UTM is not supported on the low memory version. Please see the
ordering section for options.
6
SRX Series Services Gateways for the Branch Data Sheet
• Antispyware IPv6
• Anti-adware • OSPFv3
• Antikeylogger • RIPng
-- Cloud-based antivirus • IPv6 Multicast Listener Discovery (MLD)
• Antispam • BGP
• Integrated enhanced Web filtering • ISIS
-- Category granularity (90+ categories) Wireless
-- Real time threat score • CX111 Cellular 3G/4G/LTE Broadband Data Bridge supported
on all branch SRX Series devices
• Redirect Web filtering
• 3G USB modem support for SRX100, SRX110, and SRX210
• Content Security Accelerator in SRX210 high memory,
SRX220, SRX240, SRX550, and SRX6504 SLA, Measurement, and Monitoring
• ExpressAV option in SRX210 high memory, SRX220 high • Real-time performance monitoring (RPM)
memory, SRX240, SRX550, and SRX6504 • Sessions, packets, and bandwidth usage
• Content filtering • Juniper J-Flow monitoring and accounting services
-- Based on MIME type, file extension, and protocol • IP Monitoring
commands
Logging
VPN • Syslog
• Auto VPN (Zero Touch Hub) • Traceroute
• Tunnels (GRE, IP-IP, IPsec) • Extensive control- and data-plane structured and
• IPsec, Data Encryption Standard (DES) (56-bit), triple Data unstructured syslog
Encryption Standard (3DES) (168-bit), Advanced Encryption
Standard (AES) (128-bit+) encryption
Administration
• Juniper Networks Network and Security Manager support
• Message Digest 5 (MD5),SHA-1 , SHA-128, SHA-256
(NSM)
authentication
• Juniper Networks Junos Space Security Director support
• Junos Pulse Dynamic VPN client; browser-based remote
access feature requiring a license • Juniper Networks STRM Series Security Threat Response
• IPv4 and IPv6 VPN Managers support
• Multi-Proxy ID for site-to-site VPN • Juniper Networks Advanced Insight Solutions support
• External administrator database (RADIUS, LDAP, SecureID)
Multimedia Transport
• Auto-configuration
• Compressed Real-Time Transport Protocol (CRTP)
• Configuration rollback
High Availability
• Rescue configuration with button
• VRRP
• Commit confirm for changes
• JSRP
• Auto-record for diagnostics
• Stateful failover and dual box clustering
• Software upgrades (USB upgrade option)
• SRX550/SRX650:
• Juniper Networks J-Web
-- Redundant power (optional)
• Command-line interface
-- GPIM hot swap
• Smart image download
-- Future internal failover and SRE hot swap (OIR) on
SRX650 Certifications
• NEBS Compliance for SRX240, SRX6506
• Backup link via 3G/4G LTE wireless or other WAN
• Department of Defense (DoD) Certification for SRX Series
• Active/active—L3 mode5
Services Gateways, including testing and certification by the
• Active/passive—L3 mode5 Department of Defense Joint Interoperability Test Command
• Configuration synchronization5 (JITC) for interoperability with DoD networks and addition of
• Session synchronization for firewall and VPN5 the SRX Series Services Gateways to the Unified Capabilities
Approved Product List (UC APL)
• Session failover for routing change5
• Device failure detection5
• Link failure detection5
• IP Monitoring with route and interface failover
4
Unified Threat Management – antivirus, antispam, Web filtering, AppSecure and IPS require individual subscription license. UTM is not supported on the low memory version. Please see the
ordering section for options.
5
SRX100B installed with 1 GB DRAM, with 512 MB accessible. Optional upgrade to 1 GB DRAM is available with purchase of memory software license key.
6
Coming soon for SRX110 and SRX550.
7
SRX Series Services Gateways for the Branch Data Sheet
Product Comparison
SRX100 SRX110 SRX210 SRX220 SRX240 SRX550 SRX650
Firewall performance 700 Mbps 700 Mbps 850 Mbps 950 Mbps 1.8 Gbps 7 Gbps 7 Gbps
(large packets)
Firewall performance (IMIX) 200 Mbps 200 Mbps 250 Mbps 300 Mbps 600 Mbps 2 Gbps 2.5 Gbps
Firewall + routing PPS (64 Byte) 70 Kpps 70 Kpps 95 Kpps 125 Kpps 200 Kpps 700 Kpps 850 Kpps
Firewall performance8 (HTTP) 100 Mbps 100 Mbps 290 Mbps 350 Mbps 830 Mbps 2 Gbps 2 Gbps
IPsec VPN throughput (large 65 Mbps 65 Mbps 85 Mbps 100 Mbps 300 Mbps 1.0 Gbps 1.5 Gbps
packets)
IPsec VPN tunnels 128 128 256 512 1,000 2,000 3,000
AppSecure firewall throughput 8
90 Mbps 90 Mbps 250 Mbps 300 Mbps 750 Mbps 2.0 Gbps 1.9 Gbps
IPS (intrusion prevention system) 75 Mbps9 75 Mbps 65 Mbps 80 Mbps 230 Mbps 800 Mbps 1 Gbps
Antivirus 25 Mbps 25 Mbps 30 Mbps 35 Mbps 85 Mbps 300 Mbps 350 Mbps
(Sophos AV) (Sophos AV) (Sophos AV) (Sophos AV) (Sophos AV) (Sophos AV) (Sophos AV)
Connections per second 1,800 1,800 2,200 2,800 8,500 27,000 35,000
Maximum concurrent sessions 32 K 7
32 K 7
64 K 7
96 K 7
256 K 7
375 K 512 K
DRAM options 2 GB DRAM 2 GB DRAM 2 GB DRAM 2 GB DRAM 2 GB DRAM 2 GB/4 GB7 2 GB DRAM
DRAM
Maximum security policies 384 384 512 2,048 4,096 8,000 8,192
Maximum users supported Unrestricted Unrestricted Unrestricted Unrestricted Unrestricted Unrestricted Unrestricted
Network Connectivity
Fixed I/O 8 x 10/100 8 x 10/100 2x 8x 16 x 6x 4x
VDSL/ 10/100/1000 10/100/1000 10/100/1000 10/100/1000 10/100/1000
ADSL2+ BASE-T + 6 x BASE-T BASE-T BASE-T + 4 BASE-T
WAN (Annex 10/100 SFP
A or B)
I/O slots N/A N/A 1 x SRX Series 2 x SRX 4 x SRX 2 x SRX 8 x GPIM
Mini-PIM Series Series Series or multiple
Mini-PIM Mini-PIM Mini-PIM, GPIM
6 x GPIM and XPIM
or multiple combinations
GPIM
and XPIM
combinations
Services and Routing Engine
No No No No No No 210
slots
See ordering See ordering See ordering See ordering See ordering
WAN/LAN interface options N/A N/A
information information information information information
Maximum number of PoE ports N/A N/A Up to 4 ports Up to 8 ports Up to 16 Up to 40 Up to 48
(PoE optional on some SRX of 802.3af of 802.3af/ ports of ports of ports of
Series models) with at with 802.3af/ 802.3af/ 802.3af/
maximum maximum at with at with at with
50 W 120 W maximum maximum maximum
150 W 247 W 247 W
USB 1 2 2 2 2 2 2 per SRE
7
Based on 2 GbE memory models, which require Junos OS 12.1X44-D15 (exception: Junos OS 11.4r5 for SRX240 only).
8
Throughput numbers based on HTTP traffic with 44 kilobyte transaction size.
9
Use software based IPS engine which has higher performance and less capacity
10
SRX650 supports a single Services and Routing Engine (SRE) as of software release 11.4.
8
SRX Series Services Gateways for the Branch Data Sheet
Routing
Routing (Packet Mode) PPS 100Kpps 100Kpps 150Kpps 200Kpps 300Kpps 1000Kpps 1000Kpps
BGP instances 5 5 10 16 20 56 64
BGP peers 8 8 16 16 32 192 256
BGP routes 8K 8K 16 K 32 K 600 K 712 K 800 K
OSPF instances 4 4 10 16 20 56 64
OSPF routes 8K 8K 16 K 32 K 200 K 200 K 200 K
RIP v1 / v2 instances 4 4 10 16 20 56 64
RIP v2 routes 8K 8K 16 K 32 K 32 K 32 K 32 K
Static routes 8K 8K 16 K 32 K 100 K 100 K 100 K
Source-based routing Yes Yes Yes Yes Yes Yes Yes
Policy-based routing Yes Yes Yes Yes Yes Yes Yes
Equal-cost multipath (ECMP) Yes Yes Yes Yes Yes Yes Yes
Reverse path forwarding (RPF) Yes Yes Yes Yes Yes Yes Yes
IPsec VPN
Concurrent VPN tunnels 128 128 256 512 1,000 2,000 3,000
DES (56-bit), 3DES (168-bit) Yes Yes Yes Yes Yes Yes Yes
and AES (256-bit)
MD-5, SHA-1 and SHA-2 Yes Yes Yes Yes Yes Yes Yes
authentication
Manual key, Internet Key Yes Yes Yes Yes Yes Yes Yes
Exchange (IKE v1+v2), public key
infrastructure (PKI) (X.509)
Perfect forward secrecy (DH 1, 2, 5 1, 2, 5 1, 2, 5 1, 2, 5 1, 2, 5 1, 2, 5 1, 2, 5
Groups)
Prevent replay attack Yes Yes Yes Yes Yes Yes Yes
Dynamic remote access VPN Yes Yes Yes Yes Yes Yes Yes
IPsec NAT traversal Yes Yes Yes Yes Yes Yes Yes
Redundant VPN gateways Yes Yes Yes Yes Yes Yes Yes
Number of remote access users 25 users 25 users 50 users 150 users 250 users 500 users 500 users
XAUTH VPN, Web-based, 802.X Yes Yes Yes Yes Yes Yes Yes
authentication
PKI certificate requests (PKCS 7 Yes Yes Yes Yes Yes Yes Yes
and PKCS 10)
Certificate Authorities supported Yes Yes Yes Yes Yes Yes Yes
Virtualization
Maximum number of security 10 10 12 24 64 96 128
zones
Maximum number of virtual 3 3 10 15 64 128 128
routers
Maximum number of VLANs 16 16 64 128 2,000 3,967 3,967
9
SRX Series Services Gateways for the Branch Data Sheet
Encapsulations
PPP/MLPPP N/A N/A Yes Yes Yes Yes Yes
MLFR (FRF .15, FRF .16) N/A N/A Yes Yes Yes Yes Yes
Wireless
CX111 3G /4G LTE Bridge support Yes Yes Yes Yes Yes Yes Yes
11
7: 4 GB DRAM and 8 GB CF is default on the SRX550 High Memory SKUs
10
SRX Series Services Gateways for the Branch Data Sheet
Environment
Operational temperature 32° to 104° F 32° to 104° F 32° to 104° F 32° to 104° F 32° to 104° F 32° to 104° F 32° to 104° F
(0° to 40° C) (0° to 40° C) (0° to 40° C) (0° to 40° C) (0° to 40° C) (0° to 40°C) (0° to 40°C)
11
SRX Series Services Gateways for the Branch Data Sheet
Canada
Safety certifications CSA 60950-1 CSA 60950-1 CSA 60950-1 CSA 60950-1 CSA 60950-1 CSA 60950-1 CSA 60950-1
EMC certifications ICES class B ICES class B ICES class B 1
ICES Class A ICES class A ICES class A ICES class A
Network homologation CS-03 CS-03 CS-03 CS-03 CS-03 CS-03 CS-03
Australia
Safety certifications AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS
60950-1 60950-1 60950-1 60950-1 60950-1 60950-1 60950-1
EMC certifications AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS
CISPR22 CISPR22 CISPR22 CISPR22 CISPR22 CISPR22 CISPR22
Class B Class B Class B1 Class A Class A Class A Class A
Network homologation AS / ACIF AS / ACIF AS / ACIF AS / ACIF AS / ACIF AS / ACIF S AS / ACIF S
S 002, S S 002, S S 002, S S 002, S S 002, S 016 016
016, S 043.1, 016, S 043.1, 016, S 043.1, 016, S 043.1, 016, S 043.1,
S043.2 S043.2 S043.2 S043.2 S043.2
New Zealand
Safety certifications AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS
60950-1 60950-1 60950-1 60950-1 60950-1 60950-1 60950-1
EMC certifications AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS AS / NZS
CISPR22 CISPR22 CISPR22 CISPR22 CISPR22 CISPR22 CISPR22
Class B Class B Class B1 Class A Class A Class A Class A
Network homologation PTC 217, PTC PTC 217, PTC PTC 217, PTC PTC 217, PTC PTC 217, PTC PTC 217 PTC 217
273 273 273 273 273
Japan
Safety certifications Comply safety certifications (UL/CUL/CSA) by CB Scheme
EMC certifications VCCI Class B VCCI Class B VCCI Class B1 VCCI Class A VCCI Class A VCCI Class A VCCI Class A
European Union
Safety certifications EN 60950-1 EN 60950-1 EN 60950-1 EN 60950-1 EN 60950-1 EN 60950-1 EN 60950-1
EMC certifications EN 55022 EN 55022 EN 55022 EN 55022 EN 55022 EN 55022 EN 55022
Class B, Class B, Class B12, Class A, Class A, Class A, Class A,
EN 300 386 EN 300 386 EN 300 386 EN 300 386 EN 300 386 EN 300 386 EN 300 386
Network homologation CTR 12/13, CTR 12/13, CTR 12/13, CTR 12/13, CTR 12/13, CTR 12/13, CTR 12/13,
CTR 21, DoC CTR 21, DoC CTR 21, DoC CTR 21, DoC CTR 21, DoC DoC DoC
Software Certifications
NIST FIPS-140-2 Level 2 Yes Yes Yes Yes Yes In Progress Yes
ISO Common Criteria Yes Yes Yes Yes Yes Yes Yes
NDPP+TFFW EP
USGv6 Yes Yes Yes Yes Yes Yes Yes
SRX210H-POE is class A.
12
*There are several models available for the SRX210 and SRX240 including the enhanced version. Please contact your Juniper or partner account representative for more information.
12
SRX Series Services Gateways for the Branch Data Sheet
13
SRX Series Services Gateways for the Branch Data Sheet
Ordering Information
Model Number Description Model Number Description
SRX650 Power Supplies and Accessories SRX-BGP-ADV-LTU Advanced BGP License for SRX650 only
SRX600-PWR- Spare 645 W AC PoE power supply unit for SRX650-K-AV-5 Five year subscription for Juniper-Kaspersky
645AC-POE SRX650, SRX550 systems—one is included AV updates on SRX650
in SRX650, SRX550 base system (SRX650-
SRX650-S-AV-5 Five year subscription for Juniper-Sophos AV
BASE-SRE6-645AP, SRX550-645AP)
updates on SRX650
SRX600-PWR- 645 W DC source power supply for SRX550
645DC-POE and SRX650; provides 397 W system power SRX650-IDP-5 Five year license for IDP updates for SRX650
@ 12 V and 248 W PoE power @ 50 VDC; SRX650-W-WF-5 Five year subscription for Juniper-Websense
works with 43-56 VDC input—no power cord Web filtering updates on SRX650
SRX600-SRE6H Spare SRE6-H for SRX650—one is included in
SRX650-SMB4-CS-5 Five year security subscription for enterprise—
SRX650 base system (SRX650-BASE-SRE6-
includes Kaspersky AV, enhanced WF, Sophos
645AP)
AS, AppSecure and IDP on SRX650
SRX650-CHAS SRX650 chassis including fan tray—no system
processor (SRE) and no power supply unit SRX650-S-SMB4- Five year security subscription for enterprise—
CS-5 includes Sophos AV, enhanced WF, Sophos
SRX650-FAN-01 Spare SRX650 fan tray, one is included in AS, AppSecure and IDP on SRX650
SRX650 chassis spare (SRX650-CHAS), and
included in SRX650 base system (SRX650- SRX-RAC-5-LTU Dynamic VPN Client: 5 simultaneous users for
BASE-SRE6-645AP) SRX100, SRX110, SRX210, SRX220, SRX240,
SRX550, and SRX650
SRX650-FILT-01 Not included in SRX650 chassis spare
(SRX650-CHAS), and not included in SRX-RAC-10-LTU Dynamic VPN Client: 10 simultaneous users
SRX650 base system (SRX650-BASE-SRE6- for SRX100, SRX110, SRX210, SRX220,
645AP)—optional, as this is not required for SRX240, SRX550, and SRX650
normal operations, but recommended for SRX-RAC-25-LTU Dynamic VPN Client: 25 simultaneous
dusty environments users for SRX100, SRX110, SRX210, SRX220,
SRX650 Additional Software Feature Licenses SRX240, SRX550, and SRX650
SRX650-K-AV One year subscription for Juniper-Kaspersky SRX-RAC-50-LTU Dynamic VPN Client: 50 simultaneous users
antivirus updates on SRX650 for SRX210, SRX220, SRX240, SRX550, and
SRX650 only
SRX650-S-AV One year subscription for Juniper-Sophos
antivirus updates on SRX650 SRX-RAC-100-LTU Dynamic VPN Client: 100 simultaneous users
for SRX220, SRX240, SRX550, and SRX650
SRX650-IDP One year subscription for IDP updates on only
SRX650
SRX-RAC-150-LTU Dynamic VPN Client: 150 simultaneous users
SRX650-S2-AS One year subscription for Juniper-Sophos for SRX220, SRX240, SRX550, and SRX650
antispam updates on SRX650 only
SRX650-W-WF One year subscription for Juniper-Websense SRX-RAC-250-LTU Dynamic VPN Client: 250 simultaneous users
Web filtering updates on SRX650 for SRX240, SRX550, and SRX650 only
SRX650-SMB4-CS One year security subscription for enterprise— SRX-RAC-500-LTU Dynamic VPN Client: 500 simultaneous users
includes Kaspersky AV, enhanced WF, Sophos for SRX550 and SRX650 only
AS, AppSecure and IDP on SRX650
SRX650-APPSEC-A-1 One year subscription for Application Security
SRX650-S-SMB4-CS One year security subscription for enterprise— and IPS updates for SRX650
includes Sophos AV, enhanced WF, Sophos
AS, AppSecure and IDP on SRX650 SRX650- Three year subscription for Application
APPSEC-A-3 Security and IPS updates for SRX650
SRX650-K-AV-3 Three year subscription for Juniper-Kaspersky
AV updates on SRX650 SRX650- Five year subscription for Application Security
APPSEC-A-5 and IPS updates for SRX650
14
SRX Series Services Gateways for the Branch Data Sheet
SRX550-K-AV One year subscription for Juniper-Kaspersky SRX-RAC-250-LTU Dynamic VPN Client: 250 simultaneous users
antivirus updates on SRX550 for SRX240, SRX550, and SRX650 only
SRX550-S-AV One year subscription for Juniper-Sophos SRX-RAC-500-LTU Dynamic VPN Client: 500 simultaneous users
antivirus updates on SRX550 for SRX550 and SRX650 only
SRX550-IDP One year subscription for IDP updates on SRX550-APPSEC-A-1 One year subscription for Application Security
SRX550 and IPS updates for SRX550
SRX550-S2-AS One year subscription for Juniper-Sophos SRX550- Three year subscription for Application
antispam updates on SRX550 APPSEC-A-3 Security and IPS updates for SRX550
SRX550-W-WF One year subscription for Juniper-Websense SRX550- Five year subscription for Application Security
Web filtering updates on SRX550 APPSEC-A-5 and IPS updates for SRX550
SRX550-SMB4-CS One year security subscription for enterprise— SRX240 Base System
includes Kaspersky AV, enhanced WF, Sophos
AS, AppSecure and IDP on SRX550 SRX240H2 SRX240 Services Gateway with 16 x GbE
ports, 4x mini-PIM slots, and high memory
SRX550-S-SMB4-CS One year security subscription for enterprise— (2 GB DRAM, 2 GB Flash); integrated power
includes Sophos AV, enhanced WF, Sophos supply with power cord, and 19” rack mount
AS, AppSecure and IDP on SRX550
kit included
SRX550-K-AV-3 Three year subscription for Juniper-Kaspersky
SRX240H2-POE SRX240 Services Gateway with 16 x GbE
AV updates on SRX550
ports, 4x mini-PIM slots, and high memory
SRX550-S-AV-3 Three year subscription for Juniper-Sophos AV (2 GB RAM, 2 GB Flash), with 16 ports PoE
updates on SRX550 (150 W); integrated power supply with
SRX550-IDP-3 Three year subscription for IDP updates on power cord, and 19” rack mount kit included
SRX550
15
SRX Series Services Gateways for the Branch Data Sheet
SRX240-K-AV-3 Three year subscription for Juniper-Kaspersky SRX-RAC-100-LTU Dynamic VPN Client: 100 simultaneous
antivirus updates on SRX240 users for SRX220, SRX240, SRX550, and
SRX650 only
SRX240-S-AV-3 Three year subscription for Juniper-Sophos
antivirus updates on SRX240 SRX-RAC-150-LTU Dynamic VPN Client: 150 simultaneous
users for SRX220, SRX240, SRX550, and
SRX240-IDP-3 Three year subscription for IDP updates on
SRX650 only
SRX240
SRX-RAC-250-LTU Dynamic VPN Client: 250 simultaneous
SRX240-S2-AS-3 Three year subscription for Juniper-Sophos
antispam updates on SRX240 users for SRX240, SRX550, and SRX650
only
SRX240-W-WF-3 Three year subscription for Juniper-
Websense Web filtering updates on SRX240 SRX240- One year subscription for Application
APPSEC-A-1 Security and IPS updates for SRX240
SRX240-SMB4- Three year security subscription for
CS-3 enterprise—includes Kaspersky AV, SRX240- Three year subscription for Application
enhanced WF, Sophos AS, AppSecure and APPSEC-A-3 Security and IPS updates for SRX240
IDP on SRX240 SRX240- Five year subscription for Application
SRX240-S-SMB4- Three year security subscription for APPSEC-A-5 Security and IPS updates for SRX240
CS-3 enterprise—includes Sophos AV, enhanced SRX220 Base System
WF, Sophos AS, AppSecure and IDP on
SRX240 SRX220H2 SRX220 Services Gateway with 8 GbE ports,
2 Mini-PIM slots, and high memory (2 GB
SRX240-K-AV-5 Five year subscription for Juniper-Kaspersky RAM, 2 GB Flash)—external power supply
antivirus updates on SRX240 and cord included
SRX240-S-AV-5 Five year subscription for Juniper-Sophos SRX220H2-POE SRX220 Services Gateway with 8 GbE ports,
antivirus updates on SRX240 2 Mini-PIM slots, and high memory (2 GB
SRX240-IDP-5 Five year subscription for IDP updates on RAM, 2 GB Flash), with 8 ports PoE (120 W)*
SRX240 SRX220-RMK SRX220 rack-mount kit for 19 in rack (holds
SRX240-S2-AS-5 Five year subscription for Juniper-Sophos one unit)
antispam updates on SRX240 SRX220-WALL-KIT SRX220 wall mount kit (holds one unit)
SRX240-W-WF-5 Five year subscription for Juniper-Websense
SRX220-PWR- Spare SRX220 switching power supply,
Web filtering updates on SRX240
60W* 60 W (non-POE)
16
SRX Series Services Gateways for the Branch Data Sheet
17
SRX Series Services Gateways for the Branch Data Sheet
SRX-RAC-5-LTU Dynamic VPN Client: 5 simultaneous users SRX100/SRX110 Dynamic VPN Client
for SRX100, SRX110, SRX210, SRX220,
SRX-RAC-5-LTU 5 simultaneous users for SRX100, SRX110,
SRX240, SRX550, and SRX650
SRX210, SRX220, SRX240, SRX550, and
SRX-RAC-10-LTU Dynamic VPN Client: 10 simultaneous users SRX650
for SRX100, SRX110, SRX210, SRX220,
SRX-RAC-10-LTU 10 simultaneous users for SRX100, SRX110,
SRX240, SRX550, and SRX650
SRX210, SRX220, SRX240, SRX550, and
SRX-RAC-25-LTU Dynamic VPN Client: 25 simultaneous SRX650
users for SRX100, SRX110, SRX210, SRX220,
SRX-RAC-25-LTU 25 simultaneous users for SRX100, SRX110,
SRX240, SRX550, and SRX650
SRX210, SRX220, SRX240, SRX550, and
SRX-RAC-50-LTU Dynamic VPN Client: 50 simultaneous users SRX650
for SRX210, SRX220, SRX240, SRX550, and
SRX650 only SRX100/SRX110 Additional Software Feature
Licenses **
SRX210-APPSEC-A-1 One year subscription for Application
Security and IPS updates for SRX210 SRX1XX-K-AV One year subscription for Juniper-Kaspersky
AV updates
SRX210- Three year subscription for Application
APPSEC-A-3 Security and IPS updates for SRX210 SRX1XX-K-AV-3 Three year subscription for Juniper-
Kaspersky AV updates
SRX210- Five year subscription for Application
APPSEC-A-5 Security and IPS updates for SRX210 SRX1XX-K-AV-5 Five year subscription for Juniper-Kaspersky
AV updates
Small Form Factor Pluggable (SFP) Transceivers
SRX1XX-S-AV One year subscription for Juniper-Sophos
SRX-SFP-1GE-LH SFP 1000BASE-LH Optical Transceiver AV updates
SRX-SFP-1GE-LX SFP 1000BASE-LX Optical Transceiver SRX1XX-S-AV-3 Three year subscription for Juniper-Sophos
AV updates
SRX-SFP-1GE-SX SFP 1000BASE-SX Optical Transceiver
SRX1XX-S-AV-5 Five year subscription for Juniper-Sophos AV
SRX-SFP-1GE-T SFP 1000BASE-T Copper Transceiver
updates
SRX-SFP-FE-FX SFP 100BASE-FX Optical Transceiver SRX1XX-S2-AS One year subscription for Juniper-Sophos
SRX-MP-1SFP-GE Single-port SFP Mini-PIM antispam updates
SRX1XX-S2-AS-3 Three year subscription for Juniper-Sophos
SRX-GP-8SFP 8-port GbE copper, fiber SFP XPIM
antispam updates
SRX110 Base System SRX1XX-S2-AS-5 Five year subscription for Juniper-Sophos
SRX110H2-VA SRX110 Services Gateway with 8xFE ports, antispam updates
2 GB RAM and Flash, 1-port VDSL2/ADSL2+ SRX1XX-W-EWF One year subscription for Juniper-Websense
over POTS, USB port for cellular modem enhanced Web filtering updates
connectivity, and external PS and cord
included SRX1XX-W-EWF-3 Three year subscription for Juniper-
Websense enhanced Web filtering updates
SRX110H2-VB SRX110 Services Gateway with 8xFE ports,
2 GB RAM and Flash, 1-port VDSL2/ADSL2+ SRX1XX-W-EWF-5 Five year subscription for Juniper-Websense
over ISDN BRI, USB port for cellular modem enhanced Web filtering updates
connectivity, and external PS and cord SRX1XX-SMB4-CS One year security subscription for enterprise—
included includes Kaspersky AV, enhanced WF, Sophos
AS, AppSecure and IDP
SRX1XX-SMB4-CS-3 Three year security subscription for
Kaspersky AV, enhanced WF, Sophos AS,
AppSecure and IDP
*See price list for country-specific power cord model numbers. **The additional software feature licenses apply to both the SRX100 and the SRX110.
18
SRX Series Services Gateways for the Branch Data Sheet
SRX1XX-K-AV-5-R Five year renewal subscription for Juniper- SRX1XX-IDP-R One year renewal subscription for IDP
Kaspersky AV updates Signature service
SRX1XX-K-AV-R One year renewal subscription for Juniper- SRX1XX-IDP-3-R Three year renewal subscription for IDP
Kaspersky AV updates Signature service
SRX1XX-S-AV-3-R Three year renewal subscription for Juniper- SRX1XX-IDP-5-R Five year renewal subscription for IDP
Sophos AV updates Signature service
SRX1XX-S-AV-5-R Five year renewal subscription for Juniper- SRX100- One year subscription for Application
Sophos AV updates APPSEC-A-1 Security and IPS updates for SRX100
SRX1XX-S-AV-R One year renewal subscription for Juniper- SRX100- Three year subscription for Application
Sophos AV updates APPSEC-A-3 Security and IPS updates for SRX100
SRX1XX-S2-AS-3-R Three year renewal subscription for Juniper- SRX100- Five year subscription for Application
Sophos antispam updates APPSEC-A-5 Security and IPS updates for SRX100
** The additional software feature licenses apply to both the SRX100 and the SRX110.
SRX1XX-S2-AS-5-R Five year renewal subscription for Juniper-
Sophos antispam updates
SRX1XX-S2-AS-R One year renewal subscription for Juniper-
Sophos antispam updates About Juniper Networks
SRX1XX-W-EWF-3-R Three year renewal subscription for Juniper- Juniper Networks challenges the status quo with products,
enhanced Websense enhanced Web
solutions and services that transform the economics of
filtering updates
networking. Our team co-innovates with customers and partners
SRX1XX-W-EWF- Five year renewal subscription for Juniper-
5-R enhanced Websense enhanced Web to deliver automated, scalable and secure networks with agility,
filtering updates performance and value. Additional information can be found at
SRX1XX-W-EWF-R One year renewal subscription for Juniper- Juniper Networks or connect with Juniper on Twitter and Facebook.
enhanced Websense enhanced Web
filtering updates
Copyright 2017 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper Networks logo, Juniper,
and Junos are registered trademarks of Juniper Networks, Inc. in the United States and other countries. All
other trademarks, service marks, registered marks, or registered service marks are the property of their
respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper
Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice.