SRX产品介绍 Y1003
SRX产品介绍 Y1003
SRX产品介绍 Y1003
—— SRX 产品介绍
学习本教程后,应掌握以下内容:
– SRX 有那些产品?各具有什么特性?
– SRX 与 SSG 、 J 系列有那些主要区别?
– SRX 有那些竞争优势?
120G
SRX5800
60G
SRX5600
30G
SRX3600
20G
SRX3400
7G
NSM
SRX650
Centrally
1.5G
managed
SRX240 by NSM
750M
SRX210
600M
SRX100
分布式企业 数据中心
基于动态服务架构 DSA 加速新服务的应用
Model Description
SRX100B base memory (512MB RAM)
内容安全加速器
4* 端口支持 POE 供电 (802.3af / at)
支持 3G 接入
性能
– 防火墙吞吐率 ( 大包 ) – 750 Mbps
– 并发连接数– 32/ 64K
小型分支用户 (20-200U)
Model Description
SRX210B base memory (512MB RAM)
Features SRX210
Ideal for Small branches On-board Ethernet 2 x GE + 6 x FE
Full UTM features Power over Ethernet (802.3af, 802.3at) 4 ports—50 W total
– IDP, Antivirus, Anti-spam, Web WAN slots 1 x mini PIM
filtering, Content filtering 3G wireless (ExpressCard slot) Yes
– UAC Enforcement USB ports (flash) 2
– UTM requires High Memory model Content Security Accelerator—ExpressAV
Yes
and Intrusion Detection and Prevention
Available Voice version with JUNOS Software version support JUNOS 9.5
mini-PIM options Routing performance 80 Kpps
– Factory-configured voice model Firewall performance (Large Packets) 750 Mbps
内容安全加速器
16* 端口支持 POE 供电 (802.3af / at)
性能
– 防火墙吞吐率 ( 大包 ) – 1.5Gbps
– 并发连接数– 64/128K
中型分支用户 (100-500U)
Model Description
SRX240B base memory (512MB RAM)
Features SRX240
内容安全加速器
性能
– 防火墙吞吐率 ( 大包 ) – 7Gbps
– 并发连接数– 512K
Model Description
大型分支用户 (200-1000U)
with SRE 6, 645W-AC-POE PSU. Includes 2GB
SRX650-BASE-
DRAM, 2GB CF, Fan Tray and Power Cord. Incl 4
SRE6-645AP
onbd 10/100/1000Base-T ports,
Features SRX650
Ideal for regional sites, large branches
On-board Ethernet 4 x GE
Modular- 48 ports GE, 250 or
Power over Ethernet (802.3af, 802.3at)
– LAN switching 500 W
– Services Routing Processors with optional WAN slots 8 x GPIM
redundancy (future) USB ports (flash) 2 per processor
– power supplies with optional redundancy 3G Future
(at FRS)
Content Security Accelerator—ExpressAV
– voice configurations (field upgradable via and Intrusion Detection and Prevention
Yes
PIMs in 2010)
JUNOS Software version support JUNOS 9.5
Full UTM features Routing performance 900 Kpps
– IDP, Antivirus, Anti-spam, Web filtering,
Firewall performance (Large Packets) 7.0 Gbps
Content filtering
– UAC Enforcement Firewall performance (IMIX) 2.5 Gbps
Firewall performance (Large Packets) 600 Mbps 750 Mbps 1.5 Gbps 7.0 Gbps
Firewall performance (IMIX) 175 Mbps 250 Mbps 500 Mbps 2.5 Gbps
Firewall performance (Firewall + Routing PPS
64byte)
65 Kpps 75 Kpps 150 Kpps 900Kpps
SERVICE
PROVIDER
VOIP
SIP Trunking to Failover to PSTN
Corporate to Local PSTN Local PSTN
5
PSTN (typical)
3 SIP
Soft Switch
SIP Trunking
Channelized
CORPORATE OFFICE 4 “VoIP to PSTN” S.P. VoIP
T-1 / E1/ FXO
SIP VoIP
X
INTERNET 4
SRX210 / SRX240
5
handset
SIP Server 4
3 3
2
X
WAN
MPLS
3
2 2
SIP VoIP
1
SIP Trunking handset to
1 digital or
“Toll bypass”, “extension”
analog
PBX, phone
Key System
Analog
FAX Soft Phones SIP VoIP
handset
Digital
Enterprise choice SIP standards Choice of sip phones, SIP Server and SIP
Soft switch
and flexibility call servers and
applications
16 | Copyright © 2009 Juniper Networks, Inc. | www.juniper.net
3G Wireless WAN 2H 2009
Deployments-
Primary connection where
wired broadband is not Datacenter HQ
available
Back up connectivity with
wired primary.
Out of band management, INTERNET
remote deployment.
Available on SRX210 3G Wireless
支持的是 Verizon 的
CDMA/EVDO 3G SRX210
INTERNET
SRX
Originating Zone
External Internal
INTERNET Threats Threats
Core Security
Firewall, VPN, Unified Access Control Firewall, VPN, Unified Access Control
POLICY SERVER
1
IC Series
Identity
Authenticate User, Stores
Profile Endpoint,
Determine Location 1 2 Dynamically
Provision 2
Policy APPLICATIONS
Enforcement
3
IPSec VPN
Switch Voice
Routing 语音
VoIP
交换
VLAN,STP,LAG…
路由
RIP,OSPF,BGP,PBR…
POE STRM
Private WAN
SRX Virtual
EX4200 Chassis Local
Printer
DATA CENTER
Internet
DC SRX
POE
PSTN WX Client
7 x 10/100 /
固定 I/O 8 x FE
5 x 10/100
2 x GE + 6 x FE 2 x GE + 6 x FE 16 x GE 4 x GE 4 x GE
防火墙性能 650 Mbps 160 Mbps 750 Mbps 350 Mbps 1.5 Gbps 450bps 550bps
防火墙 + 路由 PPS 60K PPS 30K PPS 80K PPS 100K PPS 200K PPS 175Kpps 225Kpps
并发会话数 16K / 32K 8K /16K 32K / 64K 48K 64K / 128K 64K 128K
附加插槽 0 0/2 1 4 4 3 5
支持
无线 AP 支持 不支持 不支持 支持 不支持 不支持 不支持
支持 支持
VoIP 支持 不支持 不支持 不支持 不支持 不支持
12,600 65,978
RMB List 15,378/20,878
/16,200
24,178/29,678 48,600/57,600
/81,378
77,000/88,000 110,000
固定 I/O 4 x GE 4 x GE 16 x GE 4 x GE 4 x GE 4 x GE 4 x GE
防火墙性能 450bps 550bps 1.5 Gbps 650bps 1Gbps 7.0 Gbps 2Gbps
防火墙 + 路由 PPS 175Kpps 225Kpps 200K PPS 300Kpps 600Kpps 900K PPS 1.5Mpps
附加插槽 3 5 4 6 6 8 2
RMB List 88,000 110,000 65,978 /81,378 143,000 231,000 352,000 800,000
8 x GE + 4 8 x GE + 4
固定 I/O 4 x GE
xSFP xSFP
0 0 0 0
防火墙性能 4Gbps 10/20Gbps 10/20/30Gbps 10G bps 30G bps 60Gbps 120Gbps
防火墙 + 路由 PPS 3Mpps 3M PPS 6M PPS 6M PPS 18M PPS 7M PPS 15M PPS
附加插槽 4 4 6 2 4 5 11
RMB List
防火墙性能 650 Mbps 150 Mbps 750 Mbps 300 Mbps 1.5 Gbps 450 Mbps
RIP/OSPF/BGP 支持 不支持 BGP 80K PPS 不支持 BGP 200K PPS 不支持 BGP
并发会话数 16K / 32K 25K 32K / 64K 130K 64K / 128K 280K
附加插槽 0 0 1 1 4 1
IPS 性能 60M bps n/a 80M bps 150M bps 250M bps 225M bps
支持
无线 AP 支持 不支持 不支持 支持 不支持 不支持
支持 支持
VoIP 支持 不支持 不支持 不支持 不支持
防火墙性能 650 Mbps 80 Mbps 185 Mbps 750 Mbps 400 Mbps 1.5 Gbps 1Gbps
防火墙 + 路由 PPS 60K PPS n/a n/a 80K PPS n/a 200K PPS n/a
10 / 60M
VPN 性能 65Mbps 30Mbps bps( 软 / 硬 75Mbps 200M bps 250Mbps 600Mbps
件)
并发 IPsec VPN 隧道
256 n/a n/a 256 n/a 1,000 Na
数
附加插槽 0 0 1 1 1 4 1
支持
无线 AP 支持 不支持 不支持 不支持 支持 不支持 不支持
支持 支持
VoIP 支持 不支持 不支持 不支持 不支持 不支持
ASA 5505
ASA 5510 ASA 5520 ASA 5540 N/A N/A
Cisco PIX 501/ ASA 5550
PIX 515 PIX 525 PIX 535
506
60 台 PC 的小型分支机构,通过两条 E1 线路与总部连
接,互为备份。本地有服务器,通过 Web 对总部进行
业务访问
要求:
– 设备之间进行高速通讯
– 要配置一定的安全措施,如防火墙
– 防火墙的吞吐量要求要达到 200Mbps+
预计:
– PC 机的数量在 1-2 年之内增长一倍
– 移动办公需要使用 POE 端口支持 5-6 个 802.11n AP 的接入
– 安全扩展到全面的 UTM 功能
新增 switch 新增 switch
1 x WS-C2960G-48TC-L 2 x EX3200-48T
1 x WS-C3560G-24PS-S 实现 UTM
实现 UTM 功能 1 x SRX240-SMB-CS
1 x ASA5520-CSC10-K9
1 x ASA-CSC10-PLUS
1 x NME-IPS 模块
Note: 未来 EX2200 非 POE 的交换机 +SRX240H-
POE 的解决方案更经济
37 | Copyright © 2009 Juniper Networks, Inc. | www.juniper.net
SRX 高端系列
SRX 3400/3600/5600/5800
Model Description
SRX 3400 Chassis, Midplane, Fan, RE, SFB-12GE,
SRX3400BASE-AC
AC PEM - no power cord - no SPC - no NPC
SRX 3400 Chassis, Midplane, Fan, RE, SFB-12GE,
SRX3400BASE-DC
DC PEM - no SPC - no NPC
* 最少需配 1SPC,1NPC
Model Description
SRX 3600 Chassis, Midplane, Fan, RE, SFB-12GE,
SRX3600BASE-AC
2xAC PEM - no power cords - no SPC - no NPC
SRX 3600 Chassis, Midplane, Fan, RE, SFB-12GE,
SRX3600BASE-DC
2xDC PEM - no SPC - no NPC
* 最少需配 1SPC,1N
Switch Fabric
Air Board (SFB)
Intake
IOC 16xSFP
IOC 2x10GE
IOC 16xCopper Services Processing
Card (SPC)
Front
Slot guide
Fan tray
door
Services Processing
Cards (SPC)
Network Processing
Cards (NPC)
Routing Engine [ or SPCs ]
(RE) Rear
Slot guide
42 | Copyright © 2009 Juniper Networks, Inc. | www.juniper.net
SRX 3x00 SFB – Switch Fabric Board
Control
Panel Virtual
IOC HA-control
HA-control
Port 1
Port 0
BITS
clock^
SFB status
LED
Aggregated RE0 Master RE^
CFM status LEDs Console AUX/USB
Yellow
Alarm
LED
Red
Alarm
LED
Power
RE1^ RE0 RE1^
HA status Button
Console Ethernet Ethernet
LED
Note: these “built-in” ports will not work unless an NPC and an SPC are installed in the system.
Model Description
SRX5600 chassis, includes RE, SCB, 2 AC power
SRX5600BASE-AC supplies. Country specific power cords purchased
separately, see below.
SRX5600 chassis, includes RE, SCB, 2 DC power
SRX5600BASE-DC
supplies
* 最少需配 1SPC
Model Description
SRX5800 chassis, includes RE, 2xSCB, 3 AC power
SRX5800BASE-AC supplies. Country specific power cords purchased
separately, see below.
SRX5800 chassis, includes RE, 2xSCB, 2 DC power
SRX5800BASE-DC
supplies
* 最少需配 1SPC
Control Panel
Switch Control
IOC 40x1GE Boards (SCB)
IOC 4x10GE
Air
Intake
SRX 5800
– Redundant fabric configuration
3 SCBs in SCB slot 0 (with RE), SCB slot 1 and SCB slot 2
11 IOC/SPC with IOC/SPC slots 0-5 and slots 7-11
– Non redundant fabric configuration
2 SCBs in SCB slot 0 (with RE) and SCB slot 1
12 IOC/SPC with IOC/SPC slots 0-5 and slots 6-11
SRX 5600
– Redundant fabric configuration
2 SCBs in SCB slot 0 (with RE), SCB slot 1
6 IOC/SPC with IOC/SPC slots 0-5
– Non redundant fabric configuration
1 SCB in SCB slot 0 (with RE)
6 IOC/SPC with IOC/SPC slots 0-5
Only single RE currently supported per chassis
SRX5K-RE-13-20
– 1.3 GHz Celeron-M
– 2 GB DDR2-400 SDRAM (2 DIMMs).
– 1GB internal CF
– USB 2.0 flash drive support
– 30GB HD
RE is NOT involved in traffic processing
– Handles all routing
– Handles chassis management
High Throughput
– 20Gbps
2M Sessions
2.2Mpps
100K new sessions / second
Flexible networking and security processing
– Advanced Routing
– Stateful Firewall
– IDP
– NAT
– DoS/DDoS
What is an HD-CPU?
– High Density CPU
– Characterized by:
Multiple core
Multiple thread
– #cores x #threads = #‘virtual CPUs’
High bandwidth interfaces & memory bus
Specialized acceleration (crypto, etc)
Easily programmable
Based on ‘standard’ CPU architectures
•Stateful Firewall
•IPSec VPN processing
•IDP Processing
•NAT, DoS, etc…
SCB
I HD-CPU
SCB
I HD-CPU
SCB
Fabric Service
Interface Processing
•Flow lookup
•Screens
•SPC load balancing
IOC
Ingress IOC
Switch Fabric
I SCB
NP I
NP I
NP I SCB
•Rich QoS
•Queuing
•Shaping
SCB
I ESE
SCB I ESE
I ESE
I NP
SCB
Fabric Shaping
Interface Queuing
Device 1 Device 2
GE
switch
Device wide:
– Independent Control and
Data planes
– Redundant power and fan
I I I I – A/B Control plane I I I I
– A/B Data plane
I I I I I I I I
System wide:
I I I I – Independent and I I I I
redundant Control and
Data plane paths
I I I I I I I I
– A/B control plane
IO IO SP SP – A/B data plane IO IO SP SP
C C C C C C C C