Juniper SRX210-RMK - Router

SRX210-RMK - Router Juniper - Free user manual and instructions

Find the device manual for free SRX210-RMK Juniper in PDF.

📄 16 pages English EN Download 💬 AI Question 10 questions ⚙️ Specs
Notice Juniper SRX210-RMK - page 1
Pick your language and provide your email: we'll send you a specifically translated version.
Product TypeSecure Router / Services Gateway
ModelSRX210 (Rack Mount Kit: SRX210-RMK)
Dimensions (W x H x D)11.1 x 1.75 x 7.1 in (27.9 x 4.1 x 18.0 cm)
Weight (without interface modules)3.3 lb (1.5 kg) Non-PoE / 4.4 lb (2 kg) PoE
Power Supply100-240 VAC, 60 W (Non-PoE) / 150 W (PoE)
Input Frequency50-60 Hz
Average Power Consumption27 W (Low Memory), 28 W (High Memory), 84 W (PoE)
Fixed Ethernet Ports2 x 10/100/1000BASE-T + 6 x 10/100
Expansion Slots1 Mini-PIM, 1 ExpressCard, 2 USB 2.0
PoE SupportUp to 4 ports 802.3af, max 50 W total
Memory (DRAM / Flash)512 MB default (optional 1 GB) / 1 GB flash
Firewall Performance (Large Packets)750 Mbps
VPN Performance (AES256+SHA-1)75 Mbps
Maximum Concurrent Sessions32,000 (low memory) / 64,000 (high memory)
Maximum Security Policies512
Routing Protocols SupportedOSPF, BGP, RIP, IS-IS, static routes, multicast
High AvailabilityVRRP, JSRP active/active or active/passive
UTM Services (License Required)IPS, antivirus, antispam, web filtering, content filtering
Operating Temperature32°F to 104°F (0°C to 40°C)
Safety CertificationsUL 60950-1, CSA 60950-1, EN 60950-1
EMC CertificationsFCC Class B (Non-PoE) / Class A (PoE)
Cleaning and MaintenanceKeep vents clear; clean exterior with dry cloth; no liquid cleaners
Safety InstructionsUse only supplied power cord; disconnect before servicing; avoid moisture
Spare Parts AvailablePower supplies (60W/150W), rack mount kit (SRX210-RMK), wall mount kit, desk stand
RepairabilityNo user-serviceable parts; contact Juniper support or authorized reseller for repairs
General InformationPart of Juniper SRX Series; runs Junos OS; designed for branch offices

Frequently Asked Questions - SRX210-RMK Juniper

What is the Juniper SRX210-RMK?
The SRX210-RMK is the rack mount kit for the Juniper SRX210 Services Gateway. It allows mounting a single SRX210 unit in a standard 19-inch rack.
What are the main features of the SRX210 services gateway?
The SRX210 combines routing, firewalling, and security in one device. It features 2 Gigabit Ethernet ports, 6 Fast Ethernet ports, a Mini-PIM slot for WAN interfaces, an ExpressCard slot for 3G wireless, PoE support (optional), and runs Junos OS. It supports advanced routing protocols (OSPF, BGP, RIP), VPN (IPsec), and UTM services (IPS, antivirus, etc.) with appropriate licenses.
Does the SRX210 support Power over Ethernet (PoE)?
Yes, the SRX210H-PoE model provides up to 4 PoE ports (802.3af) with a maximum total power budget of 50 W. The non-PoE models do not support PoE.
What are the memory options for the SRX210?
The SRX210 comes with 512 MB DRAM (low memory) or 1 GB DRAM (high memory) as a factory option. Flash memory is 1 GB for all models. High memory is required for UTM features like IPS and antivirus.
Can the SRX210 be used as a router only?
Yes, the SRX210 can function purely as a router. However, its stateful firewall and security policies are always active by default. You can configure routing protocols (e.g., OSPF, BGP) and disable security features as needed.
What VPN protocols does the SRX210 support?
The SRX210 supports IPsec VPN with encryption algorithms DES (56-bit), 3DES (168-bit), and AES (256-bit). It supports manual key, IKE, and PKI (X.509) authentication. Up to 256 concurrent VPN tunnels are supported.
How do I manage the SRX210?
The SRX210 can be managed via the J-Web graphical interface, the Junos CLI (command-line interface), or Juniper Network and Security Manager. It also supports SSH, SNMP, and syslog for monitoring.
What is the maximum throughput of the SRX210?
Firewall throughput with large packets is 750 Mbps and with IMIX traffic is 250 Mbps. IPsec VPN throughput is 75 Mbps (AES256+SHA-1). These values are measured under ideal conditions.
Does the SRX210 support high availability?
Yes, the SRX210 supports VRRP for active/passive failover and JSRP (Junos Services Redundancy Protocol) for active/active clustering. Session synchronization for firewall and VPN is supported in high availability mode.
What spare parts are available for the SRX210?
Spare parts include the SRX210-RMK (rack mount kit), SRX210-DESK-STAND (desk stand), SRX210-WALL-KIT (wall mount kit), and two power supply options: SRX210-PWR-60W (60 W non-PoE) and SRX210-PWR-150W (150 W PoE).

User questions about SRX210-RMK Juniper

0 question about this device. Answer the ones you know or ask your own.

Ask a new question about this device

The email remains private: it is only used to notify you if someone responds to your question.

No questions yet. Be the first to ask one.

Download the instructions for your Router in PDF format for free! Find your manual SRX210-RMK - Juniper and take your electronic device back in hand. On this page are published all the documents necessary for the use of your device. SRX210-RMK by Juniper.

USER MANUAL SRX210-RMK Juniper

natural_image Front view of a network switch device with multiple Ethernet ports and drive bays (no visible text or labels)

SRX SERIES SERVICES GATEWAYS FOR THE BRANCH

SRX100, SRX210, SRX240 AND SRX650

Product Overview

Juniper Networks SRX Series Services Gateways for the branch are secure routers that provide essential capabilities that connect, secure, and manage work force locations sized from handfuls to hundreds of users. By consolidating fast, highly available switching, routing, security, and applications capabilities in a single device, enterprises can economically deliver new services, safe connectivity, and a satisfying end user experience. All SRX Series Services Gateways, including products scaled for the branch, campus and data center applications, are powered by Juniper Networks Junos OS—the proven operating system that provides unmatched consistency, better performance with services, and superior infrastructure protection at a lower total cost of ownership.

Product Description

The Juniper Networks ^ SRX Series Services Gateways for the branch joins Juniper Networks SRX Series for the high end, EX Series Ethernet Switches, M Series Multiservice Edge Routers, MX Series 3D Universal Edges Routers, and T Series Core Routers to provide a single Juniper Networks Junos ^ operating system-based portfolio of unprecedented scale. With Junos OS, enterprises and service providers can lower deployment and operational costs across their entire distributed workforce.

  • SRX Series for the branch runs Junos OS, the proven operating system that is used by core Internet routers in all of the top 100 service providers around the world. The rigorously tested carrier class routing features of IPv4/IPv6, OSPF, BGP, and multicast have been proven in over 10 years of worldwide deployments.
  • SRX Series Services Gateways for the branch provide perimeter security, content security, access control, and network-wide threat visibility and control. Best-in-class firewall and VPN technologies secure the perimeter with minimal configuration and consistent performance. By using zones and policies, even new network administrators can configure and deploy an SRX Series for the branch quickly and securely. Policy-based VPNs support more complex security architectures that require dynamic addressing and split tunneling. For content security, SRX Series for the branch offers a complete suite of Unified Threat Management (UTM) services consisting of: intrusion prevention system (IPS), antivirus, antispam, Web filtering and data loss prevention via content filtering to protect your network from the latest content borne threats. Select models feature Content Security Accelerator for high-performance IPS and antivirus performance. The branch SRX Series integrates with other Juniper security products to deliver enterprise-wide unified access control and adaptive threat management. These capabilities give security professionals powerful tools in the fight against cybercrime and data loss.

- SRX Series for the branch are secure routers that bring high-performance and proven deployment capabilities to enterprises that need to build a worldwide network of thousands of sites. The wide variety of options allows configuration of performance, functionality, and price scaled to support from a handful to thousands of users. Ethernet, serial, T1/E1, xDSL, Metro Ethernet, and third generation (3G) cellular wireless are all available options for WAN or Internet connectivity to securely link your sites. Multiple form factors allow you to make cost-effective choices for mission-critical deployments. Managing the network is easy using the proven Junos OS command-line interface (CLI) and scripting capabilities, or a simple to use Web-based GUI.

Architecture and Key Components

Key Hardware Features of the Branch SRX Series Products

PRODUCT DESCRIPTION

SRX100 Services Gateway8 10/100 Ethernet LAN portsFull UTM2; antivirus2, antispam2, Web filtering2, intrusion prevention system2 (with high memory version)Unified Access Control (UAC) and content filtering1 GB DRAM, 1 GB flash default (512 MB DRAM accessible in low memory version)
SRX210 Services Gateway2 10/100/1000 Ethernet and 6 10/100 Ethernet LAN ports, 1 Mini-PIM slot, 1 ExpressCard slot and 2 USB portsFactory option of 4 dynamic Power over Ethernet (PoE) ports 802.3afSupport for TI/E1, serial, ADSL/2/2+, Ethernet small form-factor pluggable transceiver (SFP), and Gigabit Ethernet interfacesContent Security Accelerator hardware for faster performance of IPS and ExpressAVFull UTM2; antivirus2, antispam2, Web filtering2, intrusion prevention system2 (with high memory version)Unified Access Control (UAC) and content filtering512 MB DRAM default, optional factory 1 GB DRAM, 1 GB flash default
SRX240 Services Gateway16 10/1000/1000 Ethernet LAN ports, 4 Mini-PIM slotsFactory option of 16 PoE ports; PoE+ 803.3at, backwards compatible with 802.3afSupport for TI/E1, serial, ADSL2/2+, Ethernet SFP, and Gigabit Ethernet interfacesContent Security Accelerator hardware for faster performance of IPS and ExpressAVFull UTM2; antivirus2, antispam2, Web filtering2, intrusion prevention system2 (with high memory version)Unified Access Control and content filtering512 MB RAM default, optional factory 1 GB DRAM, 1 GB flash default
SRX650 Services Gateway4 fixed ports 10/100/1000 Ethernet LAN ports, 8 GPIM slots or multiple GPIM and XPIM combinationsSupport for TI, EI, Gigabit Ethernet LAN ports; supports up to 48 ports switching with optional PoE including 802.3at, PoE+, backwards compatible with 802.3afContent Security Accelerator hardware for faster performance of IPS and ExpressAVFull UTM2; antivirus2, antispam2, Web filtering2, and intrusion prevention system2Unified Access Control and content filteringModular Services and Routing Engine; future internal failover and hot-swap2 GB DRAM default, 2 GB compact flash default, external compact flash slot for additional storageOptional redundant AC power; standard AC power supply that is PoE-ready; PoE power up to 250 watts redundant, or 500 watts non-redundant

Network Deployments

The SRX Series Services Gateways for the branch are deployed at remote and branch locations in the network to provide all-in-one secure WAN connectivity, IP telephony, and connection to local PCs and servers via integrated Ethernet switching.

Features and Benefits

Secure Routing

Should you use a router and a firewall to secure your network? By building the branch SRX Series with best in class routing and firewall capabilities in one product, enterprises don't have to make that choice. Why forward traffic if it's not legitimate?

SRX Series for the branch checks the traffic to see if it is legitimate, and only forwards it on when it is. This reduces the load on the network, allocates bandwidth for all other mission-critical applications, and secures the network from hacking.

The main purpose of a secure router is to provide firewall protection and apply policies. The firewall (zone) functionality inspects traffic flows and state to ensure that originating and returning information in a session is expected and permitted for a particular zone. The security policy determines if the session can originate in one zone and traverse to another zone. This architectural choice receives packets from a wide variety of clients and servers and keeps track of every session, of every application, and of every user. It allows the enterprise to make sure that only legitimate traffic is on its network and that traffic is flowing in the expected direction.

Juniper SRX210-RMK - Secure Routing - 1

flowchart
graph TD
    A[""Untrust" Zone"] --> B["INTERNET"]
    B --> C[""Trust" Zone"]
    C --> D["Intranet"]
    C --> E[""Guest" Zone"]
    C --> F[""DMZ" Zone"]

Figure 1: Firewalls, zones and policies

Juniper SRX210-RMK - Secure Routing - 2

flowchart
graph TD
    subgraph_High_Availability["High Availability"]
        A1["Active"] --> B1["EX Series EX Series"]
        A1 --> C1["SRX240SRX240 Standby"]
        C1 --> D1["Failure"]
        C1 --> E1["Active"]
    end

    subgraph_High_Availability["High Availability"]
        F1["Active/Standby"] --> G1["Internet"]
        F1 --> H1["Internet"]
        F1 --> I1["Internet"]
        F1 --> J1["Internet"]
        F1 --> K1["Internet"]
        F1 --> L1["Internet"]
        F1 --> M1["Internet"]
    end

    subgraph_High_Availability["High Availability"]
        N1["Active/Active"] --> O1["Internet"]
        N1 --> P1["Active Active"]
        N1 --> Q1["SRX240SRX240 Standby"]
        Q1 --> R1["Failure"]
        Q1 --> S1["Active"]
        Q1 --> T1["Internet"]
        Q1 --> U1["Internet"]
        Q1 --> V1["Internet"]
        Q1 --> W1["Internet"]
    end

    style High_Availability fill:#f9f,stroke:#333
    style High_Availability fill:#ccf,stroke:#333

Figure 2: High availability

To ease the configuration of a firewall, SRX Series for the branch uses two features—"zones" and "policies." While these can be user defined, the default shipping configuration contains, at a minimum, a trust and an untrust zone. The trust zone is used for configuration and attaching the LAN to the branch SRX Series. The untrust zone is used for the WAN or Internet interface. To simplify installation and make configuration easier, a default policy is in place that allows traffic originating from the trust zone to flow to the untrust zone. This policy blocks ALL traffic originating from the untrust zone to the trust zone. A traditional router forwards all traffic without regard to a firewall (session awareness) or policy (origination and destination of a session).

By using the Web interface or CLI, enterprises can create a series of security policies that will control the traffic from within and in between zones by defining policies. At the broadest level, all types of traffic can be allowed from any source in security zones to any destination in all other zones without any scheduling restrictions. At the narrowest level, policies can be created that allow only one kind of traffic between a specified host in one zone and another specified host in another zone during a scheduled time period.

High Availability

Junos OS Services Redundancy Protocol (JSRP) is a core feature of the SRX Series for the branch. JSRP enables a pair of security systems to be easily integrated into a high availability network architecture, with redundant physical connections between the systems and the adjacent network switches. With link redundancy, Juniper Networks can address many common causes of system failures, such as a physical port going bad or a cable getting disconnected, to ensure that a connection is available, without having to fail over the entire system. This is consistent with a typical active/standby nature of routing resiliency protocols.

When SRX Series Services Gateways for the branch are configured as an active/active pair, traffic and configuration will be mirrored automatically to provide active firewall and VPN session maintenance in case of a failure. The branch SRX Series will now synchronize both configuration and runtime information. As a result, during failover, synchronization of the following information is shared: connection/session state and flow information, IPsec security associations, Network Address Translation (NAT) traffic, address book information, configuration changes, and more. In

contrast to the typical router active/standby resiliency protocols such as Virtual Router Redundancy Protocol (VRRP), all dynamic flow and session information is lost and must be reestablished in the event of a failover. Some or all applications sessions will have to restart depending on the convergence time of the links or nodes. By maintaining state, not only is the session preserved, but security is intact. In an unstable network, this active/active configuration also mitigates link flapping affecting session performance.

Session-Based Forwarding Without the Performance Hit

In order to optimize the throughput and latency of the combined router and firewall, Junos OS implements session-based forwarding, an innovation that combines the session state information of a traditional firewall and the next-hop forwarding of a classic router into a single operation. With Junos OS, a session that is permitted by the forwarding policy is added to the forwarding table along with a pointer to the next-hop route. Established sessions have a single table lookup to verify that the session has been permitted and to find the next hop. This efficient algorithm improves throughput and lowers latency for session traffic when compared with a classic router that performs multiple table lookups to verify session information and then to find a next-hop route.

Figure 3 shows the session-based forwarding algorithm. When a new session is established, the session-based architecture within Junos OS verifies that the session is allowed by the forwarding policies. If the session is allowed, Junos OS will look up the next-hop route in the routing table. It then inserts the session and the next-hop route into the session and forwarding table and forwards the packet. Subsequent packets for the established session require a single table lookup in the session and forwarding table, and are forwarded to the egress interface.

Juniper SRX210-RMK - High Availability - 1

flowchart
graph TD
    A["Session Initial Packet Processing"] --> B["Security Policy Evaluation and Next-Hop Lookup"]
    B --> C["Table Update"]
    C --> D["Session and Forwarding Table"]
    D --> E["Ingress Interface"]
    D --> F["Forwarding for Permitted Traffic"]
    F --> G["Egress Interface"]
    D -.-> H["Disallowed by Policy: Dropped"]

Figure 3: Session-based forwarding algorithm

Juniper SRX210-RMK - High Availability - 2

flowchart
graph TD
    A["SMALL OFFICE"] -->|DSL| B["Service Provider SIP Softswitch"]
    C["FIXED MOBILE SITE (Mobile - 3G)"] -->|Cellular| B
    D["INTERNET"] --> E["Service Provider SIP Softswitch"]
    B --> F["PSTN"]
    F --> G["Clear channel T-1 Data (B82S)"]
    F --> H["Channelized T-1 Voice (AMI)"]
    F --> I["POPPOPPOP"]
    J["LARGE OFFICE"] --> K["EX4200 EX3200"]
    J --> L["J4350"]
    J --> M["LARGE OFFICE"]
    N["HEAD QUARTERS BRANCH BRANCH"] --> O["EX4200-24T"]
    N --> P["J6350"]
    N --> Q["PBX"]
    R["EX3200-24P"] --> S["J2350"]
    T["SRX210"] --> U["SPR"]
    V["Fax Fax"] --> W["Central Channel"]
    X["Mobile"] --> Y["SRX210"]
    Z["Wireless"] --> AA["SRX210"]

Figure 4: The distributed enterprise

Juniper SRX210-RMK - High Availability - 3
SRX100

Juniper SRX210-RMK - High Availability - 4

natural_image Front view of a network switch device (no visible text or labels)

SRX240

Juniper SRX210-RMK - High Availability - 5
SRX210

Juniper SRX210-RMK - High Availability - 6

natural_image Front view of a network switch device labeled 'Juniper SRX650' (no additional text or symbols visible)

SRX650

Specifications

Protocols

• IPv4, IPv6, ISO Connectionless Network Service (CLNS)

Routing and Multicast

  • Static routes
  • RIPv2
    · OSPF
    · BGP
    • BGP Router Reflector
    • IS-IS
  • Multicast ((Internet Group Management Protocol (IGMPv3), PIM, Session Description Protocol (SDP), Distance Vector Multicast Routing Protocol (DVMRP), source-specific))
  • MPLS ^4

IP Address Management

  • Static
    • Dynamic Host Configuration Protocol (DHCP) (client and server)
  • DHCP relay

Encapsulations

  • Ethernet (MAC and tagged)
  • Point-to-Point Protocol (PPP) (synchronous)
  • Multilink Point-to-Point Protocol (MLPPP)
  • Frame Relay

- Multilink Frame Relay (MLFR) (FRF.15, FRF.16)

• High-Level Data Link Control (HDLC)
- Serial (RS-232, RS-449, X.21, V.35, EIA-530)
- 802.1q VLAN support
- Point-to-Point Protocol over Ethernet (PPPoE)

Traffic Management

• Marking, policing, and shaping
• Class-based queuing with prioritization
• Weighted random early detection (WRED)
- Queuing based on VLAN, data-link connection identifier (DLCI), interface, bundles, or filters

Security

  • Firewall, zones, screens, policies
  • Stateful firewall, ACL filters
  • Denial of service (DoS) and distributed denial of service (DDoS) protection (anomaly-based)
  • Prevent replay attack; Anti-Replay
    • Unified Access Control
  • UTM ^2 (SRX650 and high memory versions of SRX240, SRX210, and SRX100 only)

  • Antivirus ^2 , antispam ^2 , Web filtering ^2 , IPS ^2

  • Content Security Accelerator in SRX210 high memory, SRX240 high memory, and SRX650 ^2
  • ExpressAV option in SRX210 high memory, SRX240 high memory, and SRX650 ^2
  • Content filtering

VPN

  • Tunnels (generic routing encapsulation, IP-in-IP, IPsec)
  • IPsec, Data Encryption Standard (DES) (56-bit), triple Data Encryption Standard (3DES) (168-bit), Advanced Encryption Standard (AES) (256-bit) encryption
  • Message Digest 5 (MD5) and SHA-1 authentication
  • Access Manager: Dynamic VPN Client. Browser based remote access feature requiring a license.

Voice Transport

· FRF.12
- Link fragmentation and interleaving (LFI)
• Compressed Real-Time Transport Protocol (CRTP)

High Availability

• VRRP
- Stateful failover and dual box clustering via JSRP3
· SRX650:

- Redundant power (optional)

– Future GPIM hot swap (online insertion and removal, OIR)
– Future internal failover and SRE hot swap (OIR)

- Backup link via 3G wireless or other WAN

Specifications (continued)

IPv6 ^4

  • OSPFv3
    • IPv6 Multicast Listener Discovery (MLD)
    · BGP
    • Quality of service (QoS)

Wireless

  • CX111 Cellular Broadband Data Bridge supported on all branch SRX Series devices
  • 3G ExpressCards supported on SRX210 with built-in ExpressCard slot
  • AX411 Wireless LAN (WLAN) Access Point supported on all branch SRX Series devices

SLA and Measurement

• Real-time performance monitoring (RPM)
- Top talkers (sessions, packets, bandwidth usage)
• J-Flow flow monitoring and accounting services

Logging and Monitoring

  • Syslog
  • Traceroute

Administration

• Juniper Networks Network and Security Manager support
• Juniper Networks STRM Series Security Threat Response Managers support
• Juniper Networks Advanced Insight Solutions support
- External administrator database (RADIUS, LDAP, SecureID)
- Auto configuration
- Configuration rollback
- Rescue configuration with button
- Commit confirm for changes
• Auto record for diagnostics
- Software upgrades
· J-Web

Product Comparison

SRX100 SRX210 SRX240 SRX650
Maximum Performance and Capacity
Junos OS version tested Junos OS 10.0 Junos OS 10.0 Junos OS 10.0 Junos OS 10.0
Firewall performance (large packets) 650 Mbps 750 Mbps 1.5 Gbps 7 Gbps
Firewall performance (IMIX) 200 Mbps 250 Mbps500 Mbps2.5 Gbps
Firewall + routing PPS (64 Byte)75 Kpps80 Kpps200 Kpps900 Kpps
AES256+SHA-1/3DES+SHA-1 VPN performance65 Mbps75 Mbps250 Mbps1.5 Gbps
IPsec VPN Tunnels1282561,0003,000
IPS (intrusion prevention system)60 Mbps80 Mbps250 Mbps900 Mbps
Antivirus25 Mbps30 Mbps85 Mbps350 Mbps
Connections per second2,0002,0009,00030,000
Maximum concurrent sessions16 K / 32 K^3 32 K / 64 K^3 64 K / 128 K^3 512 K^6
DRAM options512 MB / 1 GB DRAM512 MB / 1 GB DRAM512 MB / 1 GB DRAM2 GB DRAM
Maximum security policies38451240968192
Maximum users supportedUnrestrictedUnrestrictedUnrestrictedUnrestricted
Network Connectivity
Fixed I/O8 x 10/1002 x 10/100/1000BASE-T + 6 x 10/10016 x 10/100/1000BASE-T4 x 10/100/1000BASE-T
I/O slotsN/A1 x SRX Mini-PIM4 x SRX Mini-PIM8 x GPIM or multiple GPIM and XPIM combinations
Services and Routing Engine slotsN/AN/AN/A 2^3
ExpressCard slot (3G WAN)NoYesNoNo
WAN/LAN Interface optionsN/ASee ordering InformationSee ordering InformationSee ordering Information
Optional maximum number of PoE portsN/AUp to 4 ports of 802.3af with maximum 50 WUp to 16 ports of 802.3af/at with maximum 150 WUp to 48 ports of 802.3af/at with maximum 247 W
USB1222 per SRE
Routing
BGP instances5102064
BGP peers81632 256
BGP routes4 K / 8 K^6 8 K / 16 K^6 32 K / 64 K^6 1 M^6
OSPF instances4102064
OSPF routes4 K / 8 K^6 8 K / 16 K^6 32 K / 64 K^6 1 M^6
RIP v1 / v2 instances4102064
RIP v2 routes4 K / 8 K^6 8 K / 16 K^6 32 K / 64 K^6 1 M^6
Static routes4 K / 8 K^6 8 K / 16 K^6 32 K / 64 K^6 1 M^6

SRX100 SRX210 SRX240 SRX650

Routing (continued)
Source-based routing Yes Yes Yes Yes
Policy-based routing Yes Yes Yes Yes
Equal-cost multipath (ECMP) Yes Yes Yes Yes
Reverse path forwarding (RPF) Yes Yes Yes Yes
MPLS^4
Layer 2 VPN (VPLS) Yes Yes Yes Yes
Layer 3 VPN Yes Yes Yes Yes
LDP Yes Yes Yes Yes
RSVP Yes Yes Yes Yes
Circuit Cross-connect (CCC) Yes Yes Yes Yes
Translational Cross-connect (TCC)Yes Yes Yes Yes
Multicast^7
IGMP (v1, v2, v3)Yes Yes Yes Yes
Protocol independent multicast (PIM) sparse mode (SM)Yes Yes Yes Yes
PIM dense mode (DM)Yes Yes Yes Yes
PIM source-specific multicast (SSM)Yes Yes Yes Yes
Multicast inside IPsec tunnelYes Yes Yes Yes
IPsec VPN
Concurrent VPN tunnels1282561,0003,000
Tunnel interfaces1064128 512
DES (56-bit), 3DES (168-bit) and AES (256-bit)Yes Yes Yes Yes
MD-5 and SHA-1 authenticationYes Yes Yes Yes
Manual key, Internet Key Exchange (IKE), public key infrastructure (PKI) (X.509)Yes Yes Yes Yes
Perfect forward secrecy (DH Groups)1,2,5 1,2,5 1,2,5 1,2,5
Prevent replay attackYes Yes Yes Yes
Dynamic remote access VPNYes Yes Yes No
IPsec NAT traversalYes Yes Yes Yes
Redundant VPN gatewaysYes Yes Yes Yes
User Authentication and Access Control
Third-party user authenticationRADIUS, RSA SecureID, LDAPRADIUS, RSA SecureID, LDAPRADIUS, RSA SecureID, LDAPRADIUS, RSA SecureID, LDAP
RADIUS accountingYes Yes Yes Yes
XAUTH VPN, Web-based, 802.X authenticationYes Yes Yes Yes
PKI certificate requests (PKCS 7 and PKCS 10)Yes Yes Yes Yes
Certificate Authorities supported VeriSign, Entrust,Microsoft, RSA Keon, IPLanet, (Netscape), Baltimore, DoD PKIVeriSign, Entrust, Microsoft, RSA Keon, IPLanet, (Netscape), Baltimore, DoD PKIVeriSign, Entrust, Microsoft, RSA Keon, IPLanet, (Netscape), Baltimore, DoD PKIVeriSign, Entrust, Microsoft, RSA Keon, IPLanet, (Netscape), Baltimore, DoD PKI
Virtualization
Maximum number of security zones101232126
Maximum number of virtual routers3102060
Maximum number of VLANs16645124096
Encapsulations
PPP/MLPPPN/AYes Yes Yes
MLPPP maximum physical interfacesN/A1412
Frame RelayN/AYesYesYes
MLFR (FRF .15, FRF .16)N/AYes Yes Yes
MLFR maximum physical interfacesN/A1412
HDLC N/A Yes Yes Yes
Address Translation
Source NAT with Port Address Translation (PAT)Yes Yes Yes Yes
Static NATYes Yes Yes Yes
Destination NAT with PATYes Yes Yes Yes
SRX100 SRX210 SRX240 SRX650
IP Address Assignment
Static Yes Yes Yes Yes
DHCP, PPPoE client Yes Yes Yes Yes
Internal DHCP server Yes Yes Yes Yes
DHCP relay Yes Yes Yes Yes
L2 Switching
VLAN 802.1Q Yes Yes Yes Yes
Link Aggregation 802.3ad/LACP Yes Yes Yes Yes
Jumbo Frame (9216 Byte) No Yes Yes Yes
Spanning Tree Protocol (STP) 802.1D, RSTP 802.1w, MSTP 802.1sYes Yes Yes Yes
Authentication 802.1x Port based and multiple supplicantYes Yes Yes Yes
Traffic Management Quality of Service (QoS)
Guaranteed bandwidth Yes Yes Yes Yes
Maximum bandwidthYes Yes Yes Yes
Ingress traffic policingYes Yes Yes Yes
Priority-bandwidth utilizationYes Yes Yes Yes
DiffServ markingYes Yes Yes Yes
High Availability
Active/active-L3 modeYes Yes Yes3Yes ^3
Active/passive-L3 modeYes Yes Yes3Yes ^3
Configuration synchronizationYes Yes Yes3Yes ^4
VRRPYes Yes Yes Yes
Session synchronization for firewall and VPNYes Yes Yes3Yes ^3
Session failover for routing changeYes Yes Yes3Yes ^3
Device failure detection Yes Yes Yes3Yes ^3
Link failure detectionYes Yes Yes3Yes ^3
Firewall
Network attack detectionYes Yes Yes Yes
DoS and DDos protectionYes Yes Yes Yes
TCP reassembly for fragmented packet protectionYes Yes Yes Yes
Brute force attack mitigation Yes Yes Yes Yes
SYN cookie protectionYes Yes Yes Yes
Zone-based IP spoofingYes Yes Yes Yes
Malformed packet protectionYes Yes Yes Yes
Unified Threat Management ^2
Intrusion Prevention System (IPS)Yes ^5 Yes Yes Yes
Protocol anomaly detectionYes ^5 Yes Yes Yes
Stateful protocol signaturesYes ^5 Yes Yes Yes
Intrusion prevention system (IPS) attack pattern obfuscationYes ^5 Yes Yes Yes
Customer signatures creationYes ^5 Yes Yes Yes
Frequency of updatesDaily and emergency ^6 Daily and emergencyDaily and emergencyDaily and emergency
Antivirus
Express AV (packet-based AV)No Yes Yes Yes
File-based antivirusYes Yes Yes Yes
Signature databaseYes Yes Yes Yes
Protocols scannedPOP3, HTTP, SMTP, IMAP, FTPPOP3, HTTP, SMTP, IMAP, FTPPOP3, HTTP, SMTP, IMAP, FTPPOP3, HTTP, SMTP, IMAP, FTP
AntispywareYes Yes Yes Yes
AntiadwareYes Yes Yes Yes
AntikeyloggerYes Yes Yes Yes
AntispamYes Yes Yes Yes
Unified Threat Management ^2 (continued)
Integrated Web filtering Yes Yes Yes Yes
Redirect Web filtering Yes Yes Yes Yes
Content filtering Yes Yes Yes Yes
Based on MIME type, file extension, and protocol commandsYes Yes Yes Yes
System Management
Web UI Yes Yes Yes Yes
Command-line Interface Yes Yes Yes Yes
Network and Security Manager Yes Yes Yes Yes
STRM Series Yes Yes Yes Yes
Wireless
CXIII 3G Bridge support Yes Yes Yes Yes
Internal 3G ExpressCard slot supportNoYesNoNo
Max WLAN access point supported 2^n 4816
Flash and Memory
Memory minimum and maximum (DRAM)512 MB (Accessible), 1GB^a 512 MB, 1 GB512 MB, 1 GB2 GB
Memory slotsFixed memoryFixed memoryFixed memory4 DIMM
Flash memory1 GB1 GB1 GB2 GB CF internal on SRE, External slot empty, up to 2 GB CF supported
USB port for external storage Yes Yes Yes Yes
Dimensions and Power
Dimensions (W x H x D) 8.5 x 1.4 x 5.8 in(21.6 x 3.6 x 14.7 cm)11.1 x 1.75 x 7.1 in(27.9 x 4.1 x 18.0 cm)17.5 x 1.75 x 15.1 in(44.4 x 4.4 x 38.5 cm)17.5 x 3.5 x 18.2 in(44.4 x 8.8 x 46.2 cm)
Weight (Device and Power supply)2.5 lb (1.1 kg)3.3 lb (1.5 kg) Non-POE /4.4 lb (2 kg) POENo interface modules11.2 lb (5.1 kg) Non-POE /12.3 lb (5.6 kg) POENo interface modules24.9 lb (11.3 kg)No interface modules1 power supply
Rack mountableYes, 1 RUYes, 1 RUYes, 1 RUYes, 2 RU
Power supply (AC)100-240 VAC, 30 W100-240 VAC, 60 W(Non-PoE) / 150 W PoE100-240 VAC, 150 W NonPoE / 350 W PoE100-240 VAC, Single645 W or Dual 645 W
Maximum PoE powerN/A50 W150 W247 W redundant, or494 W non-redundant
Average power consumption10 W27 W Low Memory (LM),28 W High Memory (HM),84 W (PoE)61 W (LM),65 W (HM),179 W (PoE)122 W
Input frequency50-60 Hz50-60 Hz50-60 Hz50-60 Hz
Maximum current consumption0.25 A @ 100 VAC0.41 A @ 100 VAC (LM),0.44 A @ 100 VAC (HM),1.13 A @ 100 VAC (PoE)1.0 A @ 100 VAC for LM1.1 A @ 100 VAC for HM3.0 A @ 100 VAC for PoE5.3 A at 100 VAC withsingle PSU with PoE8.3 A at 100 VAC withdual PSU with PoE
Maximum Inrush current60 A80 A for LM/HM,60 A for PoE40 A for LM/HM,45 A for PoE45 A for 1⁄2 cycle
Average heat dissipation 35 BTU/hr92 BTU/hr (SRX210B)95 BTU/hr (SRX210H),116 BTU/hr (SRX210H-PoE)208 BTU/Hr (SRX240B)222 BTU/Hr (SRX240H)249 BTU/Hr (SRX240H-PoE)319 BTU/Hr
Maximum heat dissipation80 BTU/hr120 BTU/hr (SRX210B),126 BTU/hr (SRX210H),157 BTU/hr (SRX210H-PoE)344 BTU/Hr (SRX210B)369 BTU/Hr (SRX210H)413 BTU/Hr (SRX210H-PoE)699 BTU/Hr
Redundant power supply (hot swappable)NoNoNoYes (up to maximumcapacity of single PSU)
Acoustic noise level(Per ISO 7779 Standard)0 dB (fanless)29.1 dB 54.1 dB 60.9 dB
Environment
Operational temperature 32° to 104°F, (0° to 40°C)32° to 104°F, (0° to 40°C)32° to 104°F, (0° to 40°C)32° to 104°F, (0° to 40°C)
Nonoperational temperature 4° to 158°F, (-20° to 70°C)4° to 158°F, (-20° to 70°C)4° to 158°F, (-20° to 70°C)4° to 158°F, (-20° to 70°C)
Humidity 10–90% noncondensing 10–90% noncondensing 10–90% noncondensing
Mean time between failures (Telcordia model) 24.8 years [SRX100B] 24.8 years [SRX100H]15.2 years (SRX210B) 14.3 years (SRX210H) 10.4 years (SRX210H-PoE)15.2 years (SRX240B) 14.3 years (SRX240H) 10.4 years (SRX240H-PoE)9.6 years with redundant power
Certifications and Network Homologation
USA
Safety certifications UL 60950-1 UL 60950-1 UL 60950-1 UL 60950-1
EMC certifications FCC Class B FCC Class B9FCC Class A FCC Class A
Network homologationTIA-968TIA-968TIA-968TIA-966
Canada
Safety certificationsCSA 60950-1CSA 60950-1CSA 60950-1CSA 60950-1
EMC certifications ICES class BICES class B9ICES class AICES class A
Network homologation CS-03 CS-03 CS-03 CS-03
Australia
Safety certificationsAS / NZS 60950-1AS / NZS 60950-1AS / NZS 60950-1AS / NZS 60950-1
EMC certifications AS / NZS CISPR22Class BAS / NZS CISPR22 Class B9AS / NZS CISPR22 Class AAS / NZS CISPR22 Class A
Network homologation AS / ACIF S 002, S 016, S 043.1, S043.2AS / ACIF S 002, S 016, S 043.1, S043.2AS / ACIF S 002, S 016, S 043.1, S043.2AS / ACIF S 016
New Zealand
Safety certificationsAS / NZS 60950-1AS / NZS 60950-1AS / NZS 60950-1AS / NZS 60950-1
EMC certifications AS / NZS CISPR22Class BAS / NZS CISPR22 Class B9AS / NZS CISPR22Class AAS / NZS CISPR22Class A
Network homologationPTC 217, PTC 273PTC 217, PTC 273PTC 217, PTC 273PTC 217
Japan
Safety certificationsCB SchemeCB SchemeCB SchemeCB Scheme
EMC certifications VCCI Class BVCCI Class B9VCCI Class AVCCI Class A
Network homologation Certificate for Technical ConditionsCertificate for Technical ConditionsCertificate for Technical ConditionsCertificate for Technical Conditions
European Union
Safety certificationsEN 60950-1EN 60950-1EN 60950-1EN 60950-1
EMC certifications EN 55022 Class B, EN 300386EN 55022 Class B9, EN 300386EN 55022 Class A, EN 300386EN 55022 Class A, EN 300386
Network homologation CTR 12 / 13, CTR 21, DoCCTR 12 / 13, CTR 21, DoCCTR 12 / 13, CTR 21, DoCCTR 12 / 13, DoC
  1. BGP Route Reflector supported on SRX650. See ordering section for more information.
  2. Unified Threat Management- antivirus, antispam, Web filtering and IPS require a subscription license and the high memory system option to use the feature. UTM is not supported on the low memory version. Please see the ordering section for options. Content Filtering and UAC are part of the base software with no additional license.
  3. High availability. VRRP supported on all SRX Series products. SRX240 and SRX650 will support high availability features in Junos 9.6.
  4. Supported in 9.5 In packet mode without services.
  5. When UTM is enabled capacities supported are low memory specifications, on high memory system options.
  6. When UTM is enabled concurrent sessions supported is 50% Of value shown.
  7. Multicast features in SRX240 and SRX650 are supported as of the 9.6 release.
  8. SRX100B Installed with 1 GB DRAM, with 512 MB accessible. Optional upgrade to 1 GB DRAM is available with purchase of memory software license key.
  9. SRX210H-POE is Class A.
  10. Available Q1 2010

Juniper Networks Services and Support

Juniper Networks is the leader in performance-enabling services and support, which are designed to accelerate, extend, and optimize your high-performance network. Our services allow you to bring revenue-generating capabilities online faster so you can realize bigger productivity gains and faster rollouts of new business models and ventures. At the same time, Juniper Networks ensures operational excellence by optimizing your network to maintain required levels of performance, reliability, and availability. For more details, please visit www.juniper.net/us/en/products-services/.

Ordering Information

MODEL NUMBER DESCRIPTION
SRX650 Base System
SRX650-BASE-SRE6-645APSRX650 Services Gateway with 1 ServicesRouting Engine (SRE), 4 x 10/100/1000BASE-Tports, 2 GB DRAM, 2 GB CF, fan tray, 645 W ACPoE power supply unit for SRX650. Provides 397W system power @ 12 V and 247 W POE power @50 VDC. Works with 90-250 VAC input. Includespower cord and rack mount kit.
SRX650 Options
Interface Modules
SRX-GP-16GE 16-port 10/100/1000BASE-T XPIM
SRX-GP-16GE-POE 16-port 10/100/1000BASE-T PoE XPIM
SRX-GP-24GE 24-port 10/100/1000BASE-T XPIM, includes4 SFP slots
SRX-GP-24GE-POE24-port 10/100/1000BASE-T PoE XPIM, includes4 SFP slots
SRX-GP-DUAL-TI-E1Dual TI/E1 GPIM
SRX-GP-QUAD-TI-E1QUAD TI/E1 GPIM
Power Supplies and Accessories
SRX600-PWR-645AC-POESpare 645 W AC PoE power supply unit forSRX650 systems. One is included in SRX650Base System (SRX650-BASE-SRE6-645AP).
SRX600-SRE6HSPARESpare SRE6-H for SRX650. One is included inSRX650 Base System (SRX650-BASE-SRE6-645AP).
SRX650-CHAS SRX650 chassis including fan tray. No systemprocessor (SRE) and no power supply unit.
SRX650-FAN-01 Spare SRX650 fan tray. One is included inSRX650 Chassis Spare (SRX650-CHAS), andincluded in SRX650 Base System (SRX650-BASE-SRE6-645AP)
SRX650-FILT-01OPTIONALNot included in SRX650 Chassis Spare (SRX650-CHAS), and not included in SRX650 Base System(SRX650-BASE-SRE6-645AP). Optional, asthis is not required for normal operations, butrecommended for dusty environments.
Additional Software Feature Licenses
SRX650-K-AV One year subscription for Juniper-Kasperskyantivirus updates on SRX650
SRX650-IDP One year subscription for IDP updates onSRX650
SRX650-S2-AS One year subscription for Juniper-Sophosantispam updates on SRX650
SRX650-W-WF One year subscription for Juniper-Websense Webfiltering updates on SRX650
SRX650-SMB2-CS One year security subscription for enterprise-includes Kaspersky antivirus, Web filtering,Sophos antispam, and IDP on SRX650
SRX650-K-AV-3 Three year subscription for Juniper-Kasperskyantivirus updates on SRX650
SRX650-IDP-3 Three year subscription for IDP updates onSRX650
SRX650-S2-AS-3 Three year subscription for Juniper-Sophosantispam updates on SRX650
SRX650-W-WF-3 Three year subscription for Juniper-WebsenseWeb filtering updates on SRX650
MODEL NUMBER DESCRIPTION
Additional Software Feature Licenses (continued)
SRX650-SMB2-CS-3Three year security subscription for enterprise - includes Kaspersky antivirus, Web filtering, Sophos antispam, and IDP on SRX650
SRX-BGP-ADV-LTUAdvanced BGP on SRX650 (Route Reflector)
SRX650-K-AV-5Five year subscription for Juniper-Kaspersky antivirus updates on SRX650
SRX650-IDP-5Five year subscription for IDP updates on SRX650
SRX650-S2-AS-5Five year subscription for Juniper-Sophos antispam updates on SRX650
SRX650-W-WF-5Five year subscription for Juniper-Websense Web filtering updates on SRX650
SRX650-SMB2-CS-5Five year security subscription for enterprise - includes Kaspersky antivirus, Web Filtering, Sophos antispam, and IDP on SRX650
SRX240 Base System
SRX240BSRX240 Services Gateway with 16 Gigabit Ethernet ports, 4 Mini-PIM slots, and base memory (512 MB RAM, 1 GB Flash)
SRX240HSRX240 Services Gateway with 16 Gigabit Ethernet ports, 4 Mini-PIM slots, and high memory (1 GB RAM, 1 GB Flash)
SRX240H-POESRX240 Services Gateway with 16 Gigabit Ethernet ports, 4 Mini-PIM slots, and high memory (1 GB RAM, 1 GB Flash), with 16 ports PoE (150 W)
SRX240-RMK SRX240 Rack mount kit for 19 in rack.Holds one unit.
Interface Modules
SRX-MP-1SERIAL1-port Sync Serial Mini Physical Interface Module (Mini-PIM) for branch SRX Series
SRX-MP-1ADSL2-A1-port ADSL2+ Mini-PIM supporting ADSL/ADSL2/ADSL2+ Annex A
SRX-MP-1ADSL2-B1-port ADSL2+ Mini-PIM supporting ADSL/ADSL2/ADSL2+ Annex B
SRX-MP-1SFP1-port SFP Mini-PIM for branch SRX Series
SRX-MP-1TIE11-port T1 or E1 Mini-PIM for branch SRX Series
Additional Software Feature Licenses
SRX240-K-AVOne year subscription for Juniper-Kaspersky antivirus updates on SRX240
SRX240-IDPOne year subscription for IDP updates on SRX240
SRX240-S2-ASOne year subscription for Juniper-Sophos antispam updates on SRX240
SRX240-W-WF One year subscription for Juniper-Websense Web filtering updates on SRX240
SRX240-SMB2-CSOne year security subscription for enterprise - includes Kaspersky antivirus, Web filtering, Sophos antispam, and IDP on SRX240
SRX240-K-AV-3 Three year subscription for Juniper-Kaspersky antivirus updates on SRX240
SRX240-IDP-3Three year subscription for IDP updates on SRX240
SRX240-S2-AS-3Three year subscription for Juniper-Sophos antispam updates on SRX240
SRX240-W-WF-3Three year subscription for Juniper-Websense Web filtering updates on SRX240

Ordering Information (continued)

MODEL NUMBER DESCRIPTION
Additional Software Feature Licenses (continued)

SRX240-SMB2-CS-3Three year security subscription for enterprise - includes Kaspersky antivirus, Web filtering, Sophos antispam, and IDP on SRX240
SRX240-K-AV-5Five year subscription for Juniper-Kaspersky antivirus updates on SRX240
SRX240-IDP-5Five year subscription for IDP updates on SRX240
SRX240-S2-AS-5Five year subscription for Juniper-Sophos antispam updates on SRX240
SRX240-W-WF-5Five year subscription for Juniper-Websense Web filtering updates on SRX240
SRX240-SMB2-CS-5Five year security subscription for enterprise - includes Kaspersky antivirus, Web filtering, Sophos antispam, and IDP on SRX240
SRX-RAC-5-LTUDynamic VPN Client: 5 simultaneous users for SRX100, SRX210 and SRX240 only
SRX-RAC-10-LTUDynamic VPN Client: 10 simultaneous users for SRX100, SRX210 and SRX240 only
SRX-RAC-25-LTUDynamic VPN Client: 25 simultaneous users for SRX100, SRX210 and SRX240 only
SRX-RAC-50-LTUDynamic VPN Client: 50 simultaneous users for SRX240 only

SRX210 Base System

SRX210B SRX210 Services Gateway with 2 GbE + 6 FastEthernet ports, 1 Mini-PIM slot, 1 ExpressCard slot and base memory (512 MB RAM, 1 GB Flash)
SRX210H SRX210 Services Gateway with 2 GbE+ 6 FastEthernet ports, 1 Mini-PIM slot, 1 ExpressCard slot and high memory (1 GB RAM, 1 GB Flash)
SRX210H-POE SRX210 Services Gateway with 2 GbE + 6 FastEthernet ports, 1 Mini-PIM slot, 1 ExpressCard slot and high memory (1 GB RAM, 1 GB Flash), with 4 ports PoE (50 W)

Interface Modules

SRX-MP-1SERIAL 1-port Sync Serial Mini Physical Interface Module(Mini-PIM) for branch SRX Series
SRX-MP-1ADSL2-A 1-port ADSL2+ Mini-PIM supporting ADSL/ADSL2/ADSL2+ Annex A
SRX-MP-1ADSL2-B 1-port ADSL2+ Mini-PIM supporting ADSL/ADSL2/ADSL2+ Annex B
SRX-MP-1SFP1-port SFP Mini Physical Interface Module(Mini-PIM) for branch SRX Series
SRX-MP-1T1E11-port T1 or E1 Mini Physical Interface Module(Mini-PIM) for branch SRX Series

Additional Hardware

SRX210-DESK-STANDSRX210 desk top stand. Holds one unit.
SRX210-RMK SRX210 Rack mount kit for 19 in rack. Holds one unit.
SRX210-WALL-KITSRX210 Wall mount kit. Holds one unit.
SRX210-PWR-60W-*Spare SRX210 switching power supply, 60 W (non-PoE)
SRX210-PWR-150W-*Spare SRX210 switching power supply, 150 W (PoE)

*See price list for country-specific power cord model numbers.

MODEL NUMBER DESCRIPTION
Additional Software Feature Licenses

SRX210-K-AVOne year subscription for Juniper-Kaspersky antivirus updates on SRX210
SRX210-IDPOne year subscription for IDP updates on SRX210
SRX210-S2-ASOne year subscription for Juniper-Sophos antispam updates on SRX210
SRX210-W-WFOne year subscription for Juniper-Websense Web filtering updates on SRX210
SRX210-SMB2-CSOne year security subscription for enterprise - includes Kaspersky antivirus, Web filtering, Sophos antispam, and IDP on SRX210
SRX210-K-AV-3Three year subscription for Juniper-Kaspersky antivirus updates on SRX210
SRX210-IDP-3Three year subscription for IDP updates on SRX210
SRX210-S2-AS-3Three year subscription for Juniper-Sophos antispam updates on SRX210
SRX210-W-WF-3Three year subscription for Juniper-Websense Web filtering updates on SRX210
SRX210-SMB2-CS-3Three year security subscription for enterprise - includes Kaspersky antivirus, Web filtering, Sophos antispam, and IDP on SRX210
SRX210-K-AV-5Five year subscription for Juniper-Kaspersky antivirus updates on SRX210
SRX210-IDP-5Five year subscription for IDP updates on SRX210
SRX210-S2-AS-5Five year subscription for Juniper-Sophos antispam updates on SRX210
SRX210-W-WF-5Five year subscription for Juniper-Websense Web filtering updates on SRX210
SRX210-SMB2-CS-5Five year security subscription for enterprise - includes Kaspersky antivirus, Web Filtering, Sophos antispam, and IDP on SRX210
SRX-RAC-5-LTUDynamic VPN Client: 5 simultaneous users for SRX100, SRX210 and SRX240 only
SRX-RAC-10-LTUDynamic VPN Client: 10 simultaneous users for SRX100, SRX210 and SRX240 only
SRX-RAC-25-LTUDynamic VPN Client: 25 simultaneous users for SRX100, SRX210 and SRX240 only
SRX-RAC-50-LTUDynamic VPN Client: 50 simultaneous users for SRX240 only

Small Form Factor Pluggable (SFP) Transceivers

SRX-SFP-1GE-LH SFP 1000BASE-LH Optical Transceiver
SRX-SFP-1GE-LXSFP 1000BASE-LX Optical Transceiver
SRX-SFP-1GE-SX SFP 1000BASE-SX Optical Transceiver
SRX-SFP-1GE-TSFP 1000BASE-T Copper Transceiver
SRX-SFP-FE-FXSFP 100BASE-FX Optical Transceiver
SRX100 Base System
SRX100BSRX100 Services Gateway with 8xFE ports and base memory (On-board 1 GB RAM w/ 512 MB accessible, 1 GB flash)
SRX100H SRX100 Services Gateway with 8xFE ports and high memory (1 GB RAM, 1 GB flash)

Additional Hardware

SRX100-PWR-30W-*Spare SRX100 switching power supply, 30 W (non-POE)
SRX-100-RMKSRX100 19" rack mount kit - holds two units
SRX100-WALL-KITSRX100 wall mount kit - holds one unit
SRX100-DESK-STANDSRX100 desk stand - holds one unit

*See price list for country-specific power cord model numbers.

Ordering Information (continued)

MODEL NUMBER DESCRIPTION
Additional Software Feature Licenses

SRX100-MEM-LIC-UPGSRX100 memory software license - upgradesSRX100B model from 512 MB RAM to 1 GB RAM
SRX100-K-AV One year subscription for Juniper-Kaspersky antivirus updates on SRX100
SRX100-W-WF One year subscription for Juniper-Websense Web filtering updates on SRX100
SRX100-IDP One year subscription for IDP updates on SRX100
SRX100-K-AV-3 Three year subscription for Juniper-Kaspersky antivirus updates on SRX100
SRX100-SMB2-CS One year security subscription for enterprise - includes Kaspersky antivirus, Web filtering, Sophos antispam, and IDP on SRX100
SRX100-W-WF-3 Three year subscription for Juniper-Websense Web filtering updates on SRX100
SRX100-IDP-3 Three year subscription for IDP updates on SRX100
SRX100-S2-AS One year subscription for Juniper-Sophos antispam updates on SRX100
SRX100-S2-AS-3 Three year subscription for Juniper-Sophos antispam updates on SRX100
SRX100-SMB2-CS-3Three year security subscription for enterprise - includes Kaspersky antivirus, Web filtering, Sophos antispam, and IDP on SRX100
SRX100-K-AV-5 Five year subscription for Juniper-Kaspersky antivirus updates on SRX100
SRX100-IDP-5 Five year subscription for IDP updates on SRX100
SRX100-S2-AS-5 Five year subscription for Juniper-Sophos antispam updates on SRX100
SRX100-W-WF-5 Five year subscription for Juniper-Websense Web filtering updates on SRX100
SRX100-SMB2-CS-5Five year security subscription for enterprise - includes Kaspersky antivirus, Web Filtering, Sophos antispam, and IDP on SRX100
Dynamic VPN Client
SRX-RAC-5-LTU5 simultaneous users for SRX100, SRX210 and SRX240 only
SRX-RAC-10-LTU 10 simultaneous users for SRX100, SRX210 and SRX240 only
SRX-RAC-25-LTU 25 simultaneous users for SRX100, SRX210 and SRX240 only

Notes

Notes

About Juniper Networks

Juniper Networks, Inc. is the leader in high-performance networking. Juniper offers a high-performance network infrastructure that creates a responsive and trusted environment for accelerating the deployment of services and applications over a single network. This fuels high-performance businesses. Additional information can be found at www.juniper.net.

Corporate and Sales Headquarters

Juniper Networks, Inc.

1194 North Mathilda Avenue

Sunnyvale, CA 94089 USA

Phone: 888.JUNIPER (888.586.4737)

or 408.745.2000

Fax: 408.745.2100

www.juniper.net

APAC Headquarters

Juniper Networks (Hong Kong)

26/F, Cityplaza One

1111 King's Road

Taikoo Shing, Hong Kong

Phone: 852.2332.3636

Fax: 852.2574.7803

EMEA Headquarters

Juniper Networks Ireland

Airside Business Park

Swords, County Dublin, Ireland

Phone: 35.31.8903.600

EMEA Sales: 00800.4586.4737

Fax: 35.31.8903.601

To purchase Juniper Networks solutions, please contact your Juniper Networks representative at 1-866-298-6428 or authorized reseller.

Copyright 2009 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper Networks logo, Junos, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc. in the United States and other countries. All other trademarks, service marks, registered marks, or registered service marks are the property of their respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice.

1000281-005-EN Nov 2009

Juniper SRX210-RMK - About Juniper Networks - 1

Printed on recycled paper

Manual assistant
Powered by Anthropic
Waiting for your message
Product information

Brand : Juniper

Model : SRX210-RMK

Category : Router