Juniper SRX 3400
Juniper SRX 3400
The SRX3400 Services Gateway supports up to 20 Gbps firewall, 6 Gbps firewall and IPS, or 6 Gbps of IPsec VPN, and up to 175,000 new connections per second. This SRX Services Gateway is ideal for securing and segmenting data center network infrastructures, aggregating a variety of different security solutions, and enforcing unique per-zone security policies in small to midsize server farms and hosting sites.
The SRX3400 Services Gateway uses the same SPCs, IOCs and NPCs as the SRX3600 and can support up to 20 Gbps firewall, 6 Gbps firewall and IPS, or 6 Gbps of IPsec VPN, along with up to 175,000 new connections per second. The SRX3400 is ideally suited for securing and segmenting enterprise data centers/network infrastructure as well as aggregation of various security solutions. The capability to support unique security policies per zones and its ability to scale with the growth of the network makes the SRX3400 an ideal deployment for small to midsized server farms , hosting sites, or mobile operators. The SRX3400 Services Gateway is also managed by Juniper Networks Network and Security Manager.
Juniper Networks SRX3000 line of services gateways is the next-generation solution for securing the ever-increasing network infrastructure and applications requirements for both enterprise and service provider environments. Designed from the ground up to provide flexible processing scalability, I/O scalability, and high integration, the SRX3000 line can meet the network and security requirements of data center hyperconsolidation, rapid managed services deployments, and aggregation of security solutions. Incorporating the routing heritage and service provider reliability of Junos OS with the rich security heritage of ScreenOS, the SRX3000 line offers the high-feature/ service integration necessary to secure modern network infrastructure and applications.
Juniper Networks® SRX3400 Services Gateway and SRX3600 Services Gateway are next-generation security platforms that deliver market-leading performance, scalability and service integration in a mid-sized form factor. These devices are ideally suited for medium to large enterprise, public sector and service provider networks, including:
- Enterprise server farms/data centers
- Securing mobile operator environments
- Aggregation of departmental or segmented security solutions
- Cloud and hosting provider data centers
- Managed services deployments
Based on an innovative mid-plane design and Juniper’s dynamic services architecture, the SRX3000 line resets the bar in price/performance for enterprise and service provider environments. Each services gateway can support near linear scalability with each additional Services Processing Card (SPC), enabling the SRX3600 to support up to 30 Gbps of firewall throughput. The SPCs are designed to support a wide range of services enabling future support of new capabilities without the need for service-specific hardware. Using SPCs on all services ensures that there are no idle resources based on specific services in operation—maximizing hardware utilization.
Market leading flexibility and price/performance of the SRX3000 line comes from the modular architecture. Based on Juniper’s dynamic services architecture, the gateway can be equipped with a flexible number of I/O cards (IOCs), network processing cards (NPCs) and service processing cards (SPCs)—allowing the system to be configured to support the ideal balance of performance and port density enabling each deployment of the Juniper Networks SRX Series Services Gateways to be tailored to specific network requirements. With this flexibility, the SRX3600 can be configured to support more than 100 Gbps interfaces with choices of Gigabit Ethernet or 10-Gigabit Ethernet ports; firewall performance from 10 to 30 Gbps; and services processing to match specific business needs.
The switch fabric employed in the SRX3000 line enables the scalability of SPCs, NPCs and IOCs. Supporting up to 320 Gbps of data transfer, the fabric enables the realization of maximum processing and I/O capability available in any particular configuration. This level of scalability and flexibility facilitates future expansion and growth of the network infrastructure, providing unrivaled investment protection.
The flexibility of the SRX3000 line extends beyond the innovation and proven benefit of the dynamic services architecture. Enabling the installation of SPCs on both the front and the back of the SRX3000 line, the mid-plane design delivers market-leading flexibility and scalability. By doubling the number of SPCs supported in half the rack space needed, the SRX3000 line offers not only underlying architectural innovation but also an innovative physical design.
The tight service integration on SRX Series Services Gateways is enabled by Juniper Networks Junos® operating system. By combining the routing heritage of Junos OS and the security heritage of ScreenOS®, the SRX Series Services Gateways are equipped with a robust list of features that include firewall, intrusion prevention system (IPS), denial of service (DoS), application security, Network Address Translation (NAT), and quality of service (QoS). In addition, incorporating multiple networking and security services under a single OS greatly optimizes the flow of traffic through the platform. With Junos OS, the SRX Series enjoys the benefit of a single source OS, single release train, and one architecture that is also available across Juniper’s carrier-class routers and switches.
Specification
STT | Model | SRX3400 |
1 | Performance and Scale | |
Routing/firewall (IMIX packet size) Gbps | 10 Gbps | |
Routing/firewall (1,518 B packet size) Gbps | 30 Gbps | |
Antivirus throughput Gbps | 2.5 Gbps | |
IPsec VPN (IMIX packet size) Gbps | 8 Gbps | |
Application visibility and control in Gbps | ||
Recommended IPS in Gbps | 8 Gbps | |
Next-generation firewall in Gbps | ||
Route table size (RIB/FIB) (IPv4) | ||
Maximum concurrent sessions (IPv4 or IPv6) | 2,250,000/3,000,000 | |
Maximum security policies | ||
Connections per second | 150,000 | |
IPsec VPN tunnels | 7,500 | |
2 | Connectivity | |
Total onboard ports | 8 x 10/100/1000 + 4 SFP | |
Onboard RJ-45 ports | 16 x 1 10/100/1000 copper | |
Onboard small form-factor pluggable (SFP) transceiver ports | 6 x 1-Gigabit Ethernet SFP 2 x 10-Gigabit Ethernet XFP | |
Dedicated high availability (HA) ports | ||
Console (RJ-45) | 1 | |
USB Port | 2 | |
3 | Memory and Storage | |
System memory (RAM) | ||
Secondary storage (SSD) | ||
4 | Dimensions and Power | |
Form factor | 3 U | |
Size (WxHxD) | 17.5 x 5.25 x 25.5 in (44.5 x 13.3 x 64.8 cm) | |
Weight (device and PSU) | Chassis: 32.3 lb (14.7 kg) Fully configured: 75 lb (34.1 kg) | |
Redundant PSU | 1+1 | |
Power supply | AC: 100 to 240 VAC DC: -40 to -72 VDC | |
Average power consumption | 1,100 W (AC power) 1,050 W (DC power) | |
Average heat dissipation | ||
Maximum current consumption | ||
Maximum inrush current | ||
Acoustic noise level | ||
Airflow/cooling | ||
Operating temperature | 41° to 104° F (5° to 40° C) | |
Nonoperating temperature | 23° to 131° F (-5° to 55° C) | |
Operating humidity | 5% to 85% noncondensing | |
Meantime between failures (MTBF) | ||
5 | Certification | |
Safety certifications | ||
Electromagnetic compatibility (EMC) certifications |
Subscriptions
Licensed Software Feature |
Supported Devices |
Model Number |
---|---|---|
Application Security, Intrusion Detection and Prevention, Enhanced Web Filtering, Antivirus and Sky Advanced Threat Prevention (1 year and 3 year subscription) |
SRX3400 |
SRX3400-ATP-BUN-1 SRX3400-ATP-BUN-3 SRX3400-ATP-BUN-5 |
Application Security, Intrusion Prevention Signatures, Antivirus, Enhanced Web Filtering (1 year and 3 years subscription) |
SRX3400 |
SRX3400-CS-BUN-1 SRX3400-CS-BUN-3 |
Application Security and Intrusion Prevention Signature (1 year and 3 year subscription) |
SRX3400 |
SRX3400-APPSEC-A-1 SRX3400-APPSEC-A-3 |
Sophos antispam (1 year and 3 year subscription) |
SRX3400 |
SRX3400-S-AS-1 SRX3400-S-AS-3 |
Sophos antivirus (1 year and 3 year subscription) |
SRX3400 |
SRX3400-S-AV-1 SRX3400-S-AV-3 |
Logical System License (1, 5, and 25 Incremental) |
SRX3400 |
SRX-3400-LSYS-1 SRX-3400-LSYS-5 SRX-3400-LSYS-25 |
Enhanced Web Filtering (1 year and 3 years subscription) |
SRX3400 |
SRX3400-W-EWF-1 SRX3400-W-EWF-3 |
Intrusion Detection and Prevention (1 year and 3 years subscription) |
SRX3400 |
SRX3K-IDP SRX3K-IDP-3 |
Specs
System Performance
Firewall throughput | 30 Gbps |
Firewall Latency | 10 us |
Firewall IMIX | 10 Gbps |
Antivirus Throughput | 2.5 Gbps |
Concurrent connections | 2,250,000 |
New connections/sec | 150.000 |
IPS throughput | 8 Gbps |
IPSec VPN throughput | 8 Gbps |
IPSec VPN Tunnels | 7.500 |
Physical interfaces
GE RJ45 Ports | 16 x 1 10/100/1000 copper |
GE SFP Slots | 16 x 1-Gigabit Ethernet SFP + 2 x 10-Gigabit Ethernet XFP |
USB Port | Yes |
Console Port | Yes |
Dimensions & Enviroment
Dimensions Width x Depth x Height (inches) | 17.5 x 5.25 x 25.5 inches |
Dimensions Height x Width x Length (mm) | 44.5 x 13.3 x 64.8 cm |
Weight | 32.3 lbs (14.7 kg) |
Power supply | 100-240 VAC |
Maximum Current | 1100W |
Operating Temperature | 41-104 F |
Storage Temperature | 23-131 F |
Humidity | 5-95% non-condensing |
Certifications | UL 60950-1, FCC Class B, TIA-968, ICES Class B, CS-03, AS/NZS 60950-1, AS/NZS CISPR22 Class B, AS/ACIF S 002, S 016, S 043.1, S 043.2, PTC 217, PTC 273, VCCI Class B, EN 300 386, CTR 12/13, CTR 21 DoC, NIST FIPS-140-2 Level 2, ISO Common Criteria NDFP+TFFW EP, USGv6 |