Juniper Networks
 
Country/Region
  • United States
  • ASEAN Region
  • Australia
  • 中国 - China
  • France
  • Deutschland - Germany
  • India
  • Italia - Italy
  • 日本 - Japan
  • 대한민국 - Korea
  • Россия - Russia
  • España - Spain
  • 台灣 - Taiwan
  • United Kingdom
Contact Us
|
Country/Region
United States
Select a country
Solutions
Products & Services
Company
Partners
Support
Education
Community
image gallery image gallery image gallery image gallery image gallery
SRX Series
SRX100
 
SRX210
 
SRX220
 
SRX240
 
SRX650
 
SRX3400
 
SRX3600
 
SRX5600
 
SRX5800
 
 

Need Help?

  • Learn How to Buy
  • Call Us
  • Email Us
Print
  • Specifications
  • Modules
  • Literature
  • Related Information
  • Ordering
Junos Software version tested
Junos 10.2
Firewall performance (max)
30 Gbps
IPS performance (NSS 4.2.1)
10 Gbps
AES256+SHA-1 / 3DES+SHA-1 VPN performance
10 Gbps
Maximum concurrent sessions
2.25 Million
New sessions/second (sustained, TCP, 3-way)
175,000
Maximum security policies
40,000
Maximum users supported
Unrestricted
Maximum available slots for IOCs
6 (front slots)
Fixed I/O ports
8 10/100/1000 + 4 SFP
CX111 3G Bridge support
N/A
Internal 3G Express Card Slot support
N/A
LAN interface options
  • 16 x 1 10/100/1000 copper
  • 16 x 1 Gigabit Ethernet small form-factor pluggable transceivers (SFP)
  • 2 x 10 Gigabit Ethernet XFP
High-availability support
  • Active/Passive, Active/Active
  • Low impact chassis cluster
  • Interface aggregation groups across chassis cluster
AppSecure Services
  • Application Identification: yes
  • Application Denial of Service Protection (AppDoS): yes
  • AppTrack: yes
Firewall
  • Network attack detection: Yes
  • DoS and DDoS protection: Yes
  • TCP reassembly for fragmented packet protection: Yes
  • Brute force attack mitigation: Yes
  • SYN cookie protection: Yes
  • Zone-based IP spoofing: Yes
  • Malformed packet protection: Yes
  • GPRS stateful inspection: Yes
Intrusion Prevention System
  • Stateful protocol signatures: Yes
  • Attack detection mechanisms: Stateful signatures, protocol anomaly detection (zero-day coverage), application identification
  • Attack response mechanisms: Drop connection, close connection, session packet log, session summary, email, custom session
  • Attack notification mechanisms: Structured syslog
  • Worm protection: Yes
  • SSL encrypted traffic inspection: Yes
  • Simplified installation through recommended policies: Yes
  • Trojan protection: Yes
  • Spyware/adware/keylogger protection: Yes
  • Other malware protection: Yes
  • Protection against attack proliferation from infected systems: Yes
  • Reconnaissance protection: Yes
  • Request and response side attack protection: Yes
  • Compound attacks — combines stateful signatures and protocol anomalies: Yes
  • Create custom attack signatures: Yes
  • Access contexts for customization: 500+
  • Attack editing (port range, other): Yes
  • Stream signatures: Yes
  • Protocol thresholds: Yes
  • Stateful protocol signatures: Yes
  • Approximate number of attacks covered: 6,000+
  • Detailed threat descriptions and remediation/patch info: Yes
  • Create and enforce appropriate application-usage policies: Yes
  • Attacker and target audit trail and reporting: Yes
  • Deployment modes: Inline or TAP
Dimensions and Power
  • Dimensions (W x H x D): 17.5 x 8.75 x 25.5 in (44.5 x 22.2 x 64.8 cm)
  • Weight: Chassis: 43.6 lb (19.8 kg), Fully Configured: 115.7 lb (52.6 kg)
  • Power supply (AC): 100 to 240 V AC
  • Power supply (DC): -40 to -72 V DC
  • Maximum power draw: 1,750 W (AC power), 1,850 W (DC power)
  • Power supply redundancy: 2 + 1 / 2 + 2

Switch Fabric and Control Board (SCB)
At the heart of the Dynamic Services Architecture is the switch fabric and control board (SCB). The SCB transforms the chassis from a simple module enclosure into a highly effective mesh network. The purpose of the SCB is to allow all modules in the chassis to send traffic at extremely high bandwidth.

The Route Engine (RE)
The routing engine (RE) is tightly coupled with the functionality of the SCB and can be considered the central nervous system of the architecture. The RE is the control plane of the chassis, and provides overall management and communications to and from system administrators, as well as calculating route tables for routing network traffic.

Services Processing Card (SPC)
As the "brains" behind the SRX3000 services gateways, services processing cards (SPCs) are designed to process all available services on the gateway. By eliminating the need for dedicated hardware for specific services or capabilities, no piece of hardware is ever taxed to the limit while other hardware sits idle. All of the processing capabilities of the SPCs are used to support any and all services and capabilities of the gateway. The same SPCs are supported on both the SRX3600 and the SRX3400 services gateways.(Note: A minimum of one NPC and one SPC is required for proper system functionality.)

Network Processing Cards (NPC)
To ensure maximum processing performance and flexibility, the SRX3000 line of services gateways utilize network processing cards (NPCs) to distribute inbound and outbound traffic to the appropriate SPCs and IOCs, apply QoS, and enforce DoS/DDoS protections. The SRX3600 can be configured to support one to three NPCs, while the SRX3400 can be configured to support one or two NPCs. Adding additional NPCs to these gateways allows organizations to tailor the solution to fit their specific performance requirements.(Note: A minimum of one NPC and one SPC is required for proper system functionality.)

Input/Output Cards (IOC)
In addition to supporting an ideal mix of built-in copper, small form-factor pluggable (SFP), and high-availability (HA) ports, the SRX3000 line allows the greatest I/O port density of any comparable offering. Each SRX3000 services gateway can be equipped with one or several input/output cards (IOCs), each supporting either 16 gigabit interfaces (16 x 1 copper or fiber Gigabit Ethernet), or 20 gigabit interfaces (2 x 10 Gigabit XFP Ethernet). With the flexibility to add additional IOCs, the SRX3000 line of services gateways can be equipped to support an ideal balance between interfaces and processing capabilities. (Note: A minimum of one NPC and one SPC is required for proper system functionality.)

SRX Cluster Module
The SRX Cluster Module is a hardware module that can be installed in the SRX3600 gateway to enable dual, or redundant, H/A control links for chassis clustering. When deploying SRX3600's in H/A clusters, the SRX Cluster Module utilizes the redundant architecture design of the SRX3000 line to provide full control link resiliency for mission critical environments.


SRX3K-SPC-1-10-40 SRX 3000 services processing card with 1Ghz processor and 4GB memory
SRX3K-NPC SRX 3000 network processing card
SRX3K-16GE-TX 16x1 10/100/1000 copper CFM I/O card for SRX3000
SRX3K-16GE-SFP 16x1 Gigabit SFP Ethernet I/O card for SRX3000, no transceivers
SRX3K-2XGE-XFP 2x10 Gigabit XFP Ethernet I/O card for SRX3000, no transceivers
SRX3K-RE-12-10 SRX3000 line routing engine with 1200Mhz processor and 1GB memory
SRX3K CRM SRX3000 line cluster module

Select Type

  • Application Notes
  • Brochures
  • Datasheets
  • Implementation Guides
  • Network Diagram
  • Solution Briefs
  • White Papers
 

SRX Series Services Gateways High Availability Using Junos Automation

  Download [ PDF Document  251 KB ]

SRX Series and J Series Network Address Translation

  Download [ PDF Document  635 KB ]

Juniper Networks SRX Series and J Series NAT for ScreenOS Users

  Download [ PDF Document  283 KB ]

Juniper Networks Integrated Firewall/VPN Platforms

  Download [ PDF Document  952 KB ]

AppSecure for SRX Series Services Gateways

  Download [ PDF Document  495 KB ]

SRX3400 and SRX3600 Services Gateways

  Download [ PDF Document  862 KB ]

Securing Flows Within the Cloud-Ready Data Center Implementation Guide

  Download [ PDF Document  4.04 MB ]

Application and Identity-Based Security Policies in the Cloud Ready Data Center

  Download [ PDF Document  3.86 MB ]

Integrating Firewall Services in Data Center Network Architecture Using SRX Series Services Gateway

  Download [ PDF Document  873 KB ]

Enterprise Product Portfolio

  Download [ PDF Document  265 KB ]

Juniper Networks Mobile Security Solution

  Download [ PDF Document  716 KB ]

Securing Virtual Server Environments with Juniper Networks and Altor Networks

  Download [ PDF Document  272 KB ]

SRX Series Services Gateways: Delivering a Scalable, Secure Solution for Network-Based Managed Service Providers

  Download [ PDF Document  180 KB ]

Security Considerations for Cloud-Ready Data Centers

  Download [ PDF Document  557 KB ]

The Next Step in Network Security for Enterprises

  Download [ PDF Document  357 KB ]

WANTED: The Future of Network Security for Service Providers - Now!

  Download [ PDF Document  367 KB ]

Dynamic Services Architecture: A Revolutionary Approach to Integrated Network Security

  Download [ PDF Document  188 KB ]

The Dawn of Network Security Super Gateways (NSSGs)

  Download [ PDF Document  443 KB ]

The Network Security Architecture (NSA) Meets Web 2.0

  Download [ PDF Document  328 KB ]

Techinical Support:

  • SRX3600 Technical Support
  • SRX3600 Technical Documentation

Certification and Training

  • Firewall/VPN Certification Track
  • Intrusion Detection and Prevention (IDP) Certification Track

  Ready to order? Find a Juniper partner.

 

Model Number Description
Base System
SRX3600BASE-AC

SRX3600 chassis, midplane, fan, RE, SFB-12GE, 2xAC PEM4 - no power cords - no SPC - no NPC

SRX3600BASE-DC

SRX3600 chassis, midplane, fan, RE, SFB-12GE, 2xDC PEM - no SPC - no NPC

SRX 3000 Line Components
SRX3K-SPC-1-10-40

SRX3000 services processing card with 1Ghz processor and 4GB memory

SRX3K-NPC

SRX3000 network processing card

SRX3K-16GE-TX

16x1 10/100/1000 copper CFM I/O card for SRX3000

SRX3K-16GE-SFP

16x1 Gigabit SFP Ethernet I/O card for SRX3000, no transceivers

SRX3K-2XGE-XFP

2x10 Gigabit XFP Ethernet I/O card for SRX3000, no transceivers

Transceivers
SRX-SFP-1GE-LH

Small form factor pluggable 1000BASE-LH Gigabit Ethernet optic module

SRX-SFP-1GE-LX

Small form-factor pluggable 1000BASE-LX Gigabit Ethernet optic module

SRX-SFP-1GE-SX

Small form-factor pluggable 1000BASE-SX Gigabit Ethernet optic module

SRX-SFP-1GE-T

Small form-factor pluggable 1000BASE-T Gigabit Ethernet module

SRX-XFP-10GE-SR

10 Gigabit Ethernet pluggable transceiver, short reach multimode

SRX-XFP-10GE-LR

10 Gigabit Ethernet pluggable transceiver, 10 Km, single mode

SRX-XFP-10GE-ER

10 Gigabit Ethernet pluggable transceiver, 40 Km, single mode


SRX3600 System Configuration Guidelines
  • 12 slots for common form-factor modules (CFMs):
    • 6 in the front for IOCs and SPCs
    • 6 in the rear for NPCs and SPCs
  • 7 SPCs max (1 min)
  • 3 NPCs max (1 min)
  • 6 IOCs max

SRX3600 base-system configuration: SRX3600 base(AC or DC), one SPC, one NPC, and two power cords.

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy & Policy
Legal Notices
Copyright© 1999-2010 Juniper Networks, Inc. All rights reserved.
Close

Enterprise

Business Needs 

  • Application Infrastructure
  • Business Continuity
  • Distributed Enterprise
  • Security and Compliance

Locations / Architectures 

  • Branch Office
  • Campus
  • Cloud-Ready Data Center
  • Remote Users
  • VPNs and WAN

Industries 

  • Healthcare
  • Financial Services
  • Research and Education

Powered by Junos 

  • Customer Stories
 

Service Provider

Business Needs 

  • Managed Service Provider
  • Network Infrastructure
  • Network Security
  • Network and Service Management
  • Residential
  • Telepresence

Locations / Architectures 

  • Core
  • Cloud Data Center Network
  • Universal Edge

Segments 

  • Cable Operator
  • Wireline Carrier
  • Content Service Provider
  • Wireless Carrier
 

Public Sector

Business Needs 

  • Application Infrastructure
  • Disaster Recovery / Business Continuity
  • Network Infrastructure
  • Security and Compliance

Locations / Architectures 

  • Branch Office
  • Campus
  • Cloud-Ready Data Center
  • Remote Users
  • VPNs and WAN

Verticals 

  • Central Governments
  • Federal Government
  • Energy and Utilities
  • Healthcare
  • Research and Education
  • State and Local Governments
Close

Products by Category

Application Acceleration
Identity and Policy Control
Network Management
Network Operating System
Routing
Security
Software
Switching
Wireless
End-of-Sale Products

Products By Family

AX Series
BX Series
C Series
CTP Series
CX Series
E Series
EX Series
IDP Series
ISG Series
J Series
JCS1200
Junos OS
Junos Pulse
Junos Space
LN Series
M Series
Media Flow Solution
MX Series
NetScreen Series
NSM Central Manager
NSMXpress
Odyssey Access Client
SA Series
SBR Series - Software
SDX300
SRC Series
SRX Series
SSG Series
STRM Series
T Series
Unified Access Control
WXC Series

Products By Name

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z  
 

Services

Consulting Services

  • Assessment and Analysis
  • Design and Planning
  • Project Implementation

Installation and Configuration Services

  • Configuration Services
  • Conversion Services
  • Quick Start Services
  • Startup Services

Technical Services

  • J-Care Technical Services
  • Resident Engineer
Close

See What We’re All About

Analyst Relations
Awards
Careers
Company Profile
Contact Us
Corporate Responsibility
Events
Case Studies and Customer Quotes
Innovation
Investor Relations
Key Business Partners
Leadership
Press Center
Recognition
Subscriptions
 

Executive Blog

The Network Ahead

Juniper executives share their viewpoints on industry topics ranging from cloud computing to economics and green IT.

Read the Network Ahead

Juniper-IBM Alliance

Juniper and IBM have teamed up to deliver technology solutions, standards development, network management, and managed security services.

Learn more
 

Learn how to be green

See how the communications industry is helping address climate change issue.

Watch now

Junos Software

Juniper's single operating system delivering the power of one. Learn how Junos Software reduces complexity and drives operational excellence, lowering the cost of innovation.

Learn more
Help
|
My Account
|
Log Out