Skip to main content
TrustRadius
Juniper SRX

Juniper SRX

Overview

What is Juniper SRX?

Juniper SRX is a firewall offering. It provides a variety of modular features, scaled for enterprise-level use, based on a 3-in-1 OS that enables routing, switching, and security in each product.

Read more
Recent Reviews

TrustRadius Insights

The Juniper SRX is a versatile appliance that satisfies various network needs. Users have found it to be an ideal solution for multiple …
Continue reading

SRX Review

3 out of 10
July 12, 2016
Incentivized
We have multiple clients that are utilizing Juniper SRXs that we administer, some of which are used for specific depts/uses some of which …
Continue reading
Read all reviews

Popular Features

View all 11 features
  • High Availability (5)
    10.0
    100%
  • Reporting and Logging (5)
    8.0
    80%
  • Firewall Management Console (5)
    7.0
    70%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Juniper SRX?

Juniper SRX is a firewall offering. It provides a variety of modular features, scaled for enterprise-level use, based on a 3-in-1 OS that enables routing, switching, and security in each product.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

5 people also want pricing

Alternatives Pricing

What is Perimeter 81?

Perimeter 81 is a Zero Trust Network as a Service from the company of the same name in Tel Aviv, designed to simplify secure network, cloud and application access for the modern and distributed workforce.

N/A
Unavailable
What is Cisco Firepower 9300 Series?

The Cisco Firepower 9300 series is presented by the vendor as a carrier-grade next-generation firewall (NGFW) ideal for data centers and high-performance settings that require low latency and high throughput. With it, the vendor providdes, users can deliver scalable, consistent security to…

Return to navigation

Product Demos

Juniper SRX Chassis Cluster

YouTube

Juniper SRX Firewall Security Policy Rules

YouTube

Juniper SRX Initial Configuration Get Started Video

YouTube
Return to navigation

Features

Firewall

A firewall is a filter that stands between a computer or computer network and the Internet. Each firewall can be programmed to keep specific traffic in or out

8.7
Avg 8.5
Return to navigation

Product Details

What is Juniper SRX?

Juniper SRX is a firewall and web security gateway. It can be deployed on-premises, as well as virtually for smaller use cases, and is optimized for enterprise-level use. Each of the SRX line are based on the Junos OS, which enables three-in-one routing, switching, and security. The features of a given product in the line are purpose-built to the scope of the business needs. These features start with base next-generation firewall (NGFW) and Unified Threat Management (UTM) capabilities. From there, the offerings scale up to include additional scalability and customizability, as well as Advanced Threat Protection and SSL inspection.

Juniper SRX Video

Juniper SRX Series Firewall

Juniper SRX Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

Juniper SRX is a firewall offering. It provides a variety of modular features, scaled for enterprise-level use, based on a 3-in-1 OS that enables routing, switching, and security in each product.

Reviewers rate Policy-based Controls and VPN and High Availability highest, with a score of 10.

The most common users of Juniper SRX are from Enterprises (1,001+ employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(32)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

The Juniper SRX is a versatile appliance that satisfies various network needs. Users have found it to be an ideal solution for multiple use cases, such as site-to-site VPN endpoints, standard firewalls, and all-in-one router/firewall/switching. It seamlessly integrates into different designs, including Internet GW, DC firewall, DMZ Firewall, North-South Firewall & Router, and edge router/firewall setups.

One of the standout features of the Juniper SRX is its ability to handle advanced routing capabilities like VRFs, BGP, and GRE, while also providing robust security functionalities such as IPSEC, IPS, Security, and URL Filtering. This makes it suitable for edge devices in data centers or cloud environments where routing instances, support for multiple tunneling, and advanced BGP features are crucial. Furthermore, the Juniper SRX can be configured as physical or virtual boxes with active/standby configuration for enhanced high availability.

Users have come to rely on the Juniper SRX series firewalls for a range of applications including edge firewalls, core firewalls, and VPN point-to-point peers. Its cost-effective price point compared to other options makes it an attractive choice for businesses seeking required security measures without breaking the bank. The Junos platform's ease of use allows for smooth adjustments and reversions with change validation and automated rollback to mitigate unintended consequences. With a reputation for versatility and reliability in diverse scenarios such as basic edge routers or full stateful firewalls with BGP peering for high availability use cases, Juniper SRX devices consistently deliver top-notch performance. They pass audits without issues after firmware updates and are employed in applications like connecting buildings using metro ethernet for high reliability through link failover and automatic route injection on failover.

Users find that Juniper network equipment offers great value with its reliability and effectiveness compared to other networking equipment companies. When it comes to enterprise security requirements like securing workloads, limiting access to internal networks, and protecting against threats and malicious users, the Juniper SRX serves as a robust network firewall. Moreover, it facilitates traffic routing to the internet through Network Address Translation. Administrators rely on Juniper SRXs to handle perimeter security measures and enable blocking of traffic based on IP and port for multiple clients. Overall, the Juniper SRX provides an array of use cases with its versatile capabilities and cost-effective security features.

Attribute Ratings

Reviews

(1-5 of 5)
Companies can't remove reviews or game the system. Here's why
Score 8 out of 10
Vetted Review
Verified User
Juniper SRX is used as Network Firewall, which is responsible for securing the workload behind it. It addresses Network Security within the organization, limits the access of the organization's internal network, and secures the enterprise network from threats and from malicious users. Juniper SRX also helped send the traffic to the Internet with the help of Network Address Translation.
  • Network Address Translation.
  • Securing the Enterprise Workload.
  • Enterprise VPN Connectivity.
  • Antivirus Features can be more advanced.
  • Antispam Filtering features have room for improvement.
  • Cloud Capabilities.
Juniper SRX is well suited for a Service Provider Environment where a high volume of traffic has to pass through the firewall; SRX handles that really well. SRX Network Address Translation (NAT) capabilities are very seamless. SRX also does pretty well in supporting VPN architecture. SRX is less suitable for a typical enterprise environment where multiple capabilities are needed in a single product.
  • IPSec VPN.
  • Network Address Translation.
  • Security Policies.
Firewall (11)
87.27272727272727%
8.7
Identification Technologies
90%
9.0
Visualization Tools
70%
7.0
Content Inspection
80%
8.0
Policy-based Controls
100%
10.0
Active Directory and LDAP
80%
8.0
Firewall Management Console
70%
7.0
Reporting and Logging
80%
8.0
VPN
100%
10.0
High Availability
100%
10.0
Stateful Inspection
100%
10.0
Proxy Server
90%
9.0
  • It really helped secure a big service provider environment.
  • It handles the traffic pretty well.
  • It helps in the seamless implementation of Firewall policies.
Juniper SRX stands tall compared to all these products for Large Service Provider Networks, where traffic volume is larger. Also, cost comparison with SRX's few other products can also be another contributing factor while selecting this. As well as Juniper Routers, Switches, and multiple products from the same vendor to maintain one single vendor environment. As well as Juniper Support is also really good.
Most of the teams are the application teams, hosting their application environment on prem, and connects via Juniper SRX to external partners or toward the internet. These application team also securing their environment via Juniper SRX firewall.
Networking team is the admin team who manages the firewall.
4
Network Security skills are required for supporting the Juniper SRX. Day to day work is manage the firewall faults, as well as changes in firewall configuration as per the application requirement, such as to allow to deny the traffic.
  • Securing the applications.
  • Establishing the connectivity with partner networks.
  • On Prem to Cloud Connectivity.
  • SRX is being used to handle of lot of NAT connections, instead of using the dedicated NATing devices.
  • SRX is used as external point for any Internet traffic to hit the Internal network.
  • Enabling the features such as making it as the proxy server.
  • Utilizing the Decryption capabilities.
Amr Momtaz | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
The Juniper SRX is a very capable firewall & router. It is a versatile appliance that can fit into many designs, it can be placed as an Internet GW, as a DC firewall, as a DMZ Firewall, as a North-South Firewall & Router, as an edge router/firewall. It mainly addresses the need for a L3 feature rich device (VRFs, BGP, GRE...) as well as security features (Security, IPSEC, IPS, URL Filtering, ...).

The combination of routing instances, support for multiple tunneling (Route Based IPSEC, Policy Based IPSEC, GRE, ...) with the advanced BGP features makes the vSRX perfect for an edge device in your DC or Cloud design.

The boxes can be physical or virtual and support active/standby configuration for high availability config.
  • Edge Device (Tunneling & Routing)
  • Routing Instances
  • Zone Based Firewall
  • L3 Gateway/Vlan termination
  • DHCP Server & DHCP Relay
  • Good support community & Good available documentation
  • Good support by the Vendor
  • The GUI is pretty basic and need some enhancements
Juniper vSRX is an excellent edge gateway device. The combination of Tunneling protocols supported and the advanced routing & security features makes it perfect for this kind of deployment. It is available in physical, virtual appliances as well as support on multiple clouds so you can have the same box be your edge gateway in multiple environments for consistency.

It can also work as a Internet Gateway, DMZ Firewall/Router and it would function just fine.

While it can also work as a DC firewall (North-South), the poor GUI will make it harder in the day to day administration for the multiple policies in a DC.
  • Edge Device/Tunnel Termination
  • Routing (eBGP)
  • Zone Based Firewall
  • L3 Gateway
  • DHCP Server/Relay
Firewall (11)
70.9090909090909%
7.1
Identification Technologies
60%
6.0
Visualization Tools
50%
5.0
Content Inspection
70%
7.0
Policy-based Controls
70%
7.0
Active Directory and LDAP
70%
7.0
Firewall Management Console
50%
5.0
Reporting and Logging
70%
7.0
VPN
90%
9.0
High Availability
90%
9.0
Stateful Inspection
90%
9.0
Proxy Server
70%
7.0
  • Solid Return of investment as an edge gateway appliance
  • Very versatile appliance that supports multiple deployment scenarios and configuration. one ha/pair can serve multiple functions using Routing Instances.
  • Great support by the vendor, community and online resources
  • it is not hard to find people with Juniper experience and there is training courses and resources that can help anyone with networking experience pick it up and be able to administrate and configure the box.
The juniper is very versatile router/firewall box. it is an excellent router/edge device with zone based firewall.

The PaloAlto and the Fortinet have better GUIs and similar firewall featureset but they are not as flexible routers.

The Cisco CSR1kv is the only box that I would rank similar or higher to the Juniper SRX as it is as versatile as a router and supports the same security feature-set as the Juniper but it has better support and Cisco IOS is more widely adopted by the industry.
VMware NSX, IBM Cloud for VMware Solutions, Veeam Backup & Replication, VMware HCX (CloudVelox), Palo Alto Networks Next-Generation Firewalls - PA Series, Cisco Cloud Services Router 1000V Series (CSR 1000V)
Score 10 out of 10
Vetted Review
Verified User
Incentivized
in 2014, our organization did a wholesale forklift of our older network equipment and replaced ALL of it with Juniper gear. We use SRX routers/firewalls/IDP and EX & QFX switches. The smaller SRX-220s are in our 17 branch locations with larger SRX-550s in our 3 data center locations. They are all tied together across a telco's MPLS circuitry and also connected to the Internet to 3rd party partners. Juniper network equipment comprises our entire infrastructure - it has proven to be very reliable and effective, plus has a great ROI, especially when compared to the top networking equipment companies.
  • One JUNOS is the Juniper mantra, including for the SRXs. While not entirely true, it comes close enough that if you learn some SRX configuration tricks, they will likely work across all of your SRXs.
  • Out of the box, with no additional license required, you have a NextGen firewall, by default. You can turn off the firewall and have just a plain ole router.
  • Technical support is often lacking. By that, I mean that Tier 1 support frequently has to escalate to the next group. I find that most of my support calls don't get resolved until I hit about Tier 3. Plus it takes minimum of 3 days with medium priority issues.
  • Automation is very flexible, but because there are so many options, it would great to have a road map to perform the most frequent automation tasks.
SRXs seem to be well suited at the enterprise level for plain routers, firewalls, and IDP/IDS. They work well on MPLS and Ethernet, including Internet. I have 3 SRXs also performing edge duty, with 2 in a high availability (HA) cluster. The Juniper line of SRXs provides a good range of scaling from small business to extremely large enterprise. Wire speed is a common comparison factor and Juniper shines in that area.
Firewall (10)
98%
9.8
Visualization Tools
80%
8.0
Content Inspection
100%
10.0
Policy-based Controls
100%
10.0
Active Directory and LDAP
100%
10.0
Firewall Management Console
100%
10.0
Reporting and Logging
100%
10.0
VPN
100%
10.0
High Availability
100%
10.0
Stateful Inspection
100%
10.0
Proxy Server
100%
10.0
  • Annual capital savings on infrastructure equipment about $500,000.
  • Data Center switches function (and are managed) as a single virtual chassis, reducing maintenance and troubleshooting time.
Equipment prices ran about the same. Performance and management were also more or less equal. The biggest deciding factors for going with Juniper were (1) fewer security incidents related to SRX firewalls and (2) technical support costs were significantly less.
This is the one area where I have a beef with Juniper. When I called into Cisco TAC, 90% of the time, the first person I spoke with was able to resolve my issue. With Juniper TAC, 90% of the time, the first person I speak with is not able to resolve my issue, seems to almost be reading from a script, and must escalate my ticket. All of which takes time.
Bear Golightly | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use the Juniper SRX platform to connect two buildings with metro ethernet between two buildings, including link failover, provide high reliability between sites. Our carriers drop LACP frames and most other layer-2 uplink aggregation protocols, so we used specific features on the Juniper SRX platform to implement connectivity testing on each end, with automatic route injection on failover.
  • The Juniper SRX platform is easy to set up (out of the box).
  • The support team responds to tickets quickly and with good solutions.
  • My only real criticism of the product is that it's hard to figure out how to upgrade the firmware from the CLI via TFTP via the docs, but it works great once you get it sorted.
I don't know much about the rest of the line, but if you require a primary branch-grade router with sub-gig throughput and some enterprisey software features, or you need an actual branch router for an office branch, the Juniper SRX is a solid choice. The out-of-box web GUI setup is pretty easy if you choose to set it up as a "real" router, but you can ignore the GUI entirely and configure layer 2/3 ports all you want with a robust CLI.
Firewall (11)
21.818181818181817%
2.2
Identification Technologies
N/A
N/A
Visualization Tools
N/A
N/A
Content Inspection
N/A
N/A
Policy-based Controls
N/A
N/A
Active Directory and LDAP
N/A
N/A
Firewall Management Console
80%
8.0
Reporting and Logging
80%
8.0
VPN
N/A
N/A
High Availability
80%
8.0
Stateful Inspection
N/A
N/A
Proxy Server
N/A
N/A
  • A loss of a single metro ethernet carrier link between buildings is no longer a problem - a warehouse filled with idle pickers is expensive!
  • Using single-purpose Juniper SRX devices on each end provides reliable connectivity independent of SDWAN or any other integrated devices, which helps avoid annoying finger-pointing
I have contacted support twice, once for licensing and again for help figuring out how to achieve what I want. The licensing issue was solved immediately, and the technician provided links to documentation on the specific feature I needed to implement, and I had it resolved within an hour.
Robert Beck | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use the Juniper SRX series FWs as our edge firewalls, core FWs and VPN P2P peers. We use these in our dept, other dept and divisions make their own decisions on products and vendors to suit their specific needs. The SRX provides us the security we require at a price point much better than other options. Once the learning curve is leveled out, the easy of use for making changes or undoing changes is far greater than other manufactures methods. In a 24/7/365 environment, it's critical that changes be made in a timely manner with minimum errors, Junos provides a great way to validate the change and an automated rollback if any unintended outcomes occur.
  • The Junos OS provides engineers the ability to review past changes and see who made the change which can be a huge advantage when troubleshooting issues that recently manifested themselves in a network. Not all issues pop up right away, so this is a great tool to see how the environment has changed in the recent past.
  • Junos uses a 2 config process to make changes and put into operation, a operational config and a proposed config called a candidate config. This allows engineers making changes to see the entire proposed changes and confirm its accuracy prior to implementing.
  • Configuration changes can be done in several different methods. Once you get comfortable with each, making quick changes can done easily and validated prior to committing to operation.
  • There's not a lot about the SRX that I don't like but if I had to say, I'd say the remote access VPN and associated client app needs improvement and by using a 3rd party as the client app provider this made troubleshooting RA issues much more difficult. For this reason, we do not use the SRX for RA VPNs.
The Juniper SRX is a great product for almost any deployment, the form factor, the price point, the power and ease of use make it an all purpose FW for any situation.
  • Although I'm not a part of the budgeting process, I do know that by using Juniper SRXs, we were able to get the products we needed with much less issues and justifications as other product we've purchased in the past.
I love the Cisco ASA but I've become used to the SRX. I am a CLI kind of guy so the SRX works for me. Others may be more GUI based so the ASA may be more comfortable to you. If that's the case then the ASA's ASDM is a solid platform to manage your FW. Junos hasn't gotten this component working and will admit that, but if you're CLI driven, then the SRX is much easier to use and has a lot better context sensitive help in most situations.
Return to navigation