You are on page 1of 15

Data Sheet

SRX5400, SRX5600,
and SRX5800
Services Gateways

Product Overview Product Description
SRX Series Services Gateways The Juniper Networks® SRX5400, SRX5600, and SRX5800 Services Gateways are
are next-generation intelligent next-generation intelligent security platforms that deliver outstanding protection,
security platforms based on market-leading performance, six nines reliability and availability, scalability, and services
a revolutionary architecture integration. These devices are ideally suited for service provider, large enterprise, and public
offering outstanding protection,
sector networks, including:
performance, scalability,
availability, and security services • Cloud and hosting provider data centers
integration. Custom designed for • Mobile operator environments
flexible processing scalability, • Managed service providers
I/O scalability, and services
• Core service provider infrastructures
integration, the SRX Series exceed
the security requirements of data • Large enterprise data centers
center consolidation and services Delivering the highest level of protection from Layer 3 to Layer 7, these platforms feature a
aggregation. The award-winning carrier grade next generation firewall with advanced security services such as application
SRX Series is powered by Junos security, Unified Threat Management (UTM), Intrusion Prevention System (IPS), and
OS, the same industry-leading
integrated threat intelligence services.
operating system platform
that keeps the world’s largest For advanced protection, the SRX Series now offers integrated threat intelligence services via
networks available, manageable, Spotlight Secure, Juniper’s open threat intelligence platform in the cloud. Spotlight Secure
and secure for the data center. delivers actionable security intelligence to SRX Series that enables advanced protection
against command and control (C&C) related botnets and web application threats, and in
addition allows policy enforcement based on GeoIP data—all based on Juniper provided
feeds. Customers may also leverage their own custom and third-party feeds for protection
from advanced malware and other threats unique to their business environment. This
advanced, customer relevant and consolidated threat intelligence service is delivered to the
SRX Series on premises from the cloud, and centrally managed by Junos Space/Security
Director for distributed enforcement by the SRX firewalls within seconds.

Based on Juniper’s Dynamic Services Architecture, the SRX5000 line provides unrivaled
scalability and performance. Each services gateway can support near linear scalability, with
the addition of Services Processing Cards (SPCs) and Input/Output Cards (IOCs), enabling
a fully equipped SRX5800 to support up to 2 Tbps firewall throughput with Express Path
enabled—an industry first for firewall performance. The SPCs are designed to support
a wide range of services, enabling future support of new capabilities without the need
for service-specific hardware. Using SPCs on all services ensures that there are no idle
resources based on specific services being used—maximizing hardware utilization.

The scalability and flexibility of the SRX5000 line is supported by equally robust interfaces.
The SRX5000 line employs a modular approach to interfaces, where each platform can be
equipped with a flexible number of IOCs that offer a wide range of connectivity options—
from 1GbE to 100GbE interfaces. With the IOCs sharing the same interface slot as the SPCs,
the gateway can be configured as needed to support the ideal balance of processing and
Your ideas. Connected.™


The SRX5600 is ideally suited for securing IOC2 is supported on all three platforms in the SRX5000 line of enterprise data centers as well as aggregation of various security services gateways. or options including 100GbE. The and 50 Gbps IPS. This level of scalability and footprint ratio make the SRX5400 an optimal solution for edge flexibility enables future expansion and growth of the network or data center services in large enterprise. the SRX and SRX5800 Services Gateways. SPCs are designed equipped with a robust set of services that include stateful to process all available services on the platform. The SRX Series is As the “brains” behind the SRX5000 line. SPCs are quality of service (QoS). SPC on any available slot. delivering all the benefits of the IOC2 cards while enabling the firewalls to deliver higher levels of throughput—up to an industry- leading 2 Tbps on the SRX5800. Hence. With this flexibility. 28 million ports. Network Address there are no instances in which a piece of hardware is taxed Translation (NAT). mobile operator environments. The SRX5000 sessions. Series enjoys the benefit of a single source OS. The capability to support unique security policies per zone and its ability to scale with the growth of the network The third generation of IOCs from Juniper. the SRX5K series offers an ultra-low latency solution. providing unrivaled investment protection. mobile operator environments. each deployment of the SRX Series can be tailored to SRX5400 specific network requirements. and the service density make it ideal for cloud and environments while ensuring investment protection. either for edge to 960 Gbps of data transfer. the fabric enables realization or core security deployments. Juniper offers the IOC2. 220 10GbE ports. 40GbE and high-density 10GbE interfaces. The capability to support unique of maximum processing and I/O capability available in security policies per zone and a compelling price/performance/ any particular configuration. denial of service need for dedicated hardware for specific services or capabilities. supporting the services. Without the firewall. The IOC2 offers the industry’s first 100GbE as well as 40GbE and high-density 10GbE and 1GbE connectivity The SRX5600 Services Gateway uses the same SPCs and options. service provider. delivers the infrastructure makes the SRX5600 an ideal deployment for highest throughput levels yet. a newer SPC with superior performance integrated architecture traditionally available on Juniper’s carrier. Furthermore. intrusion prevention system (IPS). as throughput with Express Path. SRX5600. managed service providers. along with superior connectivity consolidation of services in large enterprise.SRX5400. solutions. service hardware upgrades to ensure that security is always on. SRX5600 and SRX5800. expand performance and capacities with the introduction of Junos OS also delivers carrier-class reliability (with six additional SPCs. service provider core and cloud provider infrastructures. drastically reducing management overhead and nines system availability). (DoS). With the flexibility to install an IOC or an hosted or co-located data centers. and single Juniper offers the SPC2. ideal mix of interfaces. These options reduce the need for link aggregation IOCs as the SRX5800 and can support up to 960 Gbps firewall when connecting high throughput switches to the firewall. In addition to the benefit of individual designed to be pooled together. The To provide the most flexible solution. The SRX5400 is a small The scalability of both SPCs and IOCs in the SRX5000 line is footprint. and flexibility of the to support the perfect blend of interfaces and processing SRX5800 makes it ideal for densely consolidated processing capabilities to meet the needs of the most demanding environments. SRX5600. service provider. The SPC2 also features in-service software and in- class routers and switches. or 440 1GbE ports. The SPC2 is supported on the SRX5400. 2 . SRX5800 is ideally suited for securing large enterprise. the SRX5000 line employs SRX5800 also supports 100 Gbps IPS and 100 million concurrent the same modular architecture for SPCs and IOCs. the SRX5000 line can be equipped The massive performance. Equipped with the full range of advanced security line can be equipped with one or several IOCs. The tight service integration on the SRX Series is enabled by Service Processing Cards (SPC) Juniper Networks Junos® operating system. and SRX5800 Services Gateways Data Sheet I/O. The SRX5800 Services Gateway is the market-leading security solution supporting up to 2 Tbps firewall throughput and latency Input/Output Cards (IOCs) as low as 7 microseconds with the Express Path™ capability. high-performance gateway ideally suited for securing enabled by the custom designed switch fabric. or infrastructure. The IOC3 cards are supported on the SRX5400. 44 40GbE can support up to 480 Gbps firewall with Express Path. Supporting up large enterprise campuses as well as data centers. and scale. and SRX5800 SRX5800 Services Gateways. the SRX5800 The SRX5400 Services Gateway uses the IOC2 and SPC2 and can be configured to support up to 22 100GbE ports. the IOC3. allowing the SRX5000 line to services. a second-generation card with superior SRX5600 connectivity options. application security. scalability. and to the limit while other hardware is sitting idle. unified threat management (UTM). VPN (IPsec). the first in the industry to achieve complexity. The same SPCs are supported on both SRX5600 independent verification by Telcordia. 76 million concurrent sessions well as enabling increased throughput in the firewall itself. concurrent sessions and 22 Gbps IPS. and mobile operator environments. The IOC3 operates with the Express Path optimization capability.

SRX5000 Services Gateways can support single. Feature Feature Description Benefits Purpose-built platform Built from the ground up on dedicated hardware Delivers unrivaled performance and flexibility to designed for networking and security services. security devices. enforcement. protect high-speed network environments. traditional port and protocol analysis. Express Path identifies Routing Engine (RE-1800X4) and prioritizes active session flows to receive appropriate security treatment based on the type of traffic and the level of inspection The Routing-Engine RE-1800x4 is the latest in the family of routing required. and virtual Features the capability to tailor unique security and routers that allow administrators to deploy security networking policies for various internal.SRX5400. external. address ranges. signatures control and protection. patterns for improved network management and control. and 100GbE) to meet the port density requirements of demanding network environments. services with appropriate processing. which securely optimizes the SRX5000 line performance to dramatically increasing the amount of secured traffic that can be improve IMIX bandwidth by identifying traffic flows that do not exchanged for express downloads and frequent data transfers. the SRX5000 Services Gateways intra. information and contexts for improved application and overall network performance. Scalable performance Offers scalable processing based on the Dynamic Simple and cost-effective solution to leverage new Services Architecture. SRX5600. deliver low latency and high throughput with six-nines reliability. and policies to isolate subnetworks and use overlapping IP demilitarized zone (DMZ) subgroups. 40. packets and identify high-risk applications and analyze traffic sessions. networks. With Express Path. and SRX5800 Services Gateways Data Sheet Enhanced System Control board (SCBE) and per-policy basis within the same line card. scalability and reduces network latency and improves performance of selected reliability with 16G DRAM and 128G SSD. AppQoS Leverage Juniper’s rich QoS capabilities to prioritize Provides the ability to prioritize traffic as well as applications based on customers’ business and limit and shape bandwidth based on application bandwidth needs. Application signatures Open signature library for identifying applications Applications are accurately identified and the resulting and nested applications with over 3000 application information can be used for visibility. 10. extremely high bandwidth flows of up to 40 Gbps and 100 Gbps. Express Path With Express Path. as well as ensuring the security of routing infrastructure—all via a dedicated management environment. virtual LANs (VLANs). Utilizes a unique architectural design based on multiple processing cores and a separation of the data and control planes. assuring that security is maintained at all times while engines for the SRX5000 line with multi-core processor running performance and latency needs are met. Express Path significantly at 1800Mhz. across the firewall estate. System and network Provides carrier-class hardware design and proven OS. The Enhanced System traffic types. Configurable on a Features and Benefits Networking and Security Juniper Networks SRX5000 line has been designed from the ground up to offer robust networking and security services. Interface flexibility Offers flexible I/O options with modular cards based Offers flexible I/O configuration and independent I/O on the Dynamic Services Architecture. IOC2 and IOC3 cards support the Express Path capability. Threat intelligence Integration with Spotlight Secure for application of Policy enforcement based on optimized and up-to- advanced threat detection technologies and feeds for date threat intelligence is automatically syndicated policy enforcement. AppFirewall Fine grained application control policies to allow or Enhances security policy creation and enforcement deny traffic based on dynamic application name or based on applications and user roles rather than group names. scalability (options include 1. making it ideal for high-speed latency-sensitive Control Board (SCBE) enables 120G per slot throughput with applications. and delivers improved performance. 3 . High availability (HA) Active/passive and active/active HA configurations Achieve availability and resiliency necessary for critical using dedicated high availability interfaces. AppTrack Detailed analysis on application volume/usage Provides the ability to track application usage to help throughout the network based on bytes. Network segmentation Security zones. Robust routing engine Dedicated routing engine that provides physical and Enables deployment of consolidated routing and logical separation to data and control planes. Offers the reliability needed for any critical high-speed resiliency network deployments without service well as inter-chassis high availability and redundancy. require additional inspection or deep processing. enabling higher security effectiveness and operational efficiency. The IOC.

guest. deep inspection. exploit a known vulnerability are detected. Signatures There are more than 8. or two 100GbE interfaces the firewall and enables very high firewall throughput and four 10GbE interfaces. interfaces. capabilities for protecting key GPRS nodes within mobile operator networks. using obfuscation methods. IPS Capabilities Juniper Networks IPS capabilities offer several unique features that assure the highest level of network security. latency- throughput and lowers latency by identifying sensitive networks and applications. User identity-based access Secure access to data center resources via tight Enables agent-based and agentless identity security control enforcement integration of standards-based access control services for enterprise data centers by integrating capabilities of Juniper Networks Junos Pulse Access the SRX5000 line with the standards-based access Control Service and SRX5000 line. firewall. including IPS. high- (UTM) antispam. as well as high- and accelerating traffic flows that do not require performance compute networks. two 40GbE. Protocol decodes Enables most accurate detection and helps reduce Accuracy of signatures are improved through precise false positives. Provides support for single. The card efficiency and record-breaking high throughput I/O includes two board choices: six 40GbE interfaces interfaces. IKE.1x49-D10 or greater.) 4 . contexts of protocols. normalization. Reduces the need for link aggregation 10GbE. twenty 1 GbE. interfaces. and antispam from Sophos. Zero-day protection Protocol anomaly detection and same-day coverage Your network is already protected against any new for newly found vulnerabilities are provided. and instant protection. *Requires Junos 15. easy. The card includes a choice of ten I/O interfaces. context.500 signatures for identifying Attacks are accurately identified and attempts to anomalies. and content filtering. exploits. AutoVPN One time hub configuration for site-to-site VPN for all Enables IT administrative time and cost savings with spokes. enabling detection of vulnerabilities in network traffic and highly granular control over IPS policy enforcement. for specific platform and release compliance. Unified threat management Strong UTM capabilities. backwards Delivers always-on security resiliency to meet your compatibility to SRX5000 chassis and cards. expanding and adaptive capabilities from multiple expert security companies. Traffic normalization Reassembly. and protocol decoding are Overcome attempts to bypass other IPS detections by provided. Services Offload) for the SRX5000 line that improves making it the ideal solution for high-speed. and SRX5800 Services Gateways Data Sheet Feature Feature Description Benefits SSL Proxy (forward and Performs SSL encryption and decryption between the Combined with application identification. current SPCs. Reduces the need for link aggregation to and 24 10GbE interfaces. or one 100GbE I/O to the firewall and enables higher firewall throughput. SRX5600. that are quickly activated for zero-day. Feature Feature Description Benefits Stateful signature inspection Signatures are applied only to relevant portions of the Minimize false positives and offer flexible signature network traffic determined by the appropriate protocol development. include: routing. including corporate. high- bandwidth flows of 40 Gbps and 100 Gbps. IOC2 supports 2 MICs The first firewall I/O card in the industry to offer Increases connectivity efficiency with high throughput 100GbE connectivity. and mobile. and IPsec. Like growing network performance needs. Antivirus options are available from Sophos. provides reverse) client and the server. The IOC3 pairs well with of up to 2 Tbps. Best-in-class UTM protection with strong. Web. and top-of-the-line connectivity of firewall throughput and low latency. SPC2 card Enables performance and scale with full. SPC2 for maximum firewall performance in any of the SRX5000 services gateways. control capabilities of Junos Pulse Access Control Service. Available on-box performance content security leveraging intelligence with preinstalled. Pairs well with SPC2s for maximized firewall performance in any of the SRX5000 line of gateways.SRX5400. IOC3* The third-generation I/O card offers very high levels Vastly superior. attacks. visibility and protection against threats embedded in SSL encrypted traffic. Intrusion Prevention System Detects known and unknown exploits and anomalies Adds critical layer of protection beyond stateful (IPS) in network traffic streams. Can be configured on a per-policy basis. spyware. Web filtering from Websense. these cards support in-service software and in-service hardware upgrades Express Path An optional optimization capability (formerly Securely delivers extremely high levels of throughput. even newly added ones. Stateful GPRS and SCTP Support for GPRS and SCTP firewall in mobile Enables the SRX5000 line to provide stateful firewall inspection operator networks. (See http://pathfinder. Configuration options easy. zero-touch deployment for IPsec VPN networks. This integration enables administrative flexibility to manage a variety of user access.

network-wide management functionality. IPS. a dedicated security company. provider. up-to-date phishing URL Protection against advanced persistent threats detection. Content Security UTM Capabilities The UTM services offered on the SRX5000 line of gateways include industry-leading antivirus. SMTP. file Protection against lost productivity and the impact of extension.SRX5400. and additional content security services. and VPN security management for intuitive and quick policy administration. extraneous or malicious content on the network to help maintain bandwidth for business essential traffic. SRX5600. cloud-based Sophisticated protection from respected antivirus antivirus capabilities that detect and block spyware. including ongoing access to Juniper and third-party Junos Space ecosystem innovations. Packet capture IPS policy supports packet capture logging per rule. and protocol commands. and SRX5800 Services Gateways Data Sheet Feature Feature Description Benefits Recommended policy Group of attack signatures are identified by Juniper Installation and maintenance are simplified while Networks Security Team as critical for the typical ensuring the highest network security. an expert Web security bandwidth for business essential traffic. security company. a dedicated and content blockers. Centralized Management Juniper Networks Junos Space Security Director delivers scalable and responsive security management that improves the reach. accessible via standard browsers. standards-based S/MIME. viruses. It lets administrators manage all phases of the security policy lifecycle through a single Web-based interface. POP3 HTTP. and other malware over breaches and lost productivity. keyloggers. Junos Space Security Director runs on the Junos Space Network Management Platform for highly extensible. Enhanced Web filtering Enhanced Web filtering includes extensive category Protection against lost productivity and the impact of granulation (95+ categories) and a real-time threat malicious URLs as well as helping to maintain network score delivered with Websense. NAT. Antispam Multilayered spam protection. advanced features such as in-service software upgrade. enterprise to protect against. SRX5400 SRX5600 Services Gateway Services Gateway SRX5800 Services Gateway 5 . firewall. Content filtering Effective content filtering based on MIME type. IMAP. and FTP protocols. MIME type and extension blockers are latest phishing scams with sophisticated e-mail filtering provided in cooperation with Sophos Labs. experts against malware attacks that can lead to data adware. ease. and accuracy of security policy administration. Open PGP and perpetrated through social networking attacks and the TLS encryption. Junos Space Security Director centralizes application identification. Feature Feature Description Benefits Antivirus Antivirus includes reputation-enhanced. content filtering. Active/active traffic IPS monitoring on active/active SRX5000 line chassis Support for active/active IPS monitoring including monitoring clusters. Conduct further analysis of surrounding traffic and determine further steps to protect target. antispam. This service is provided in cooperation with Sophos Labs.

SRX5800E.1x49 Junos OS 15. SRX5K-MPC3-40G10G) Supports 2 pluggable MIC modules per card. SRX5K-4XGE-XFP) 4 x 10GbE XFP Supports 2 pluggable IOC modules per card.000 15. and SRX5800E.000 Tunnel interfaces 15. MICs can be mixed from the following models: IOC2 options 20 x 1GbE SFP (SRX5K-MPC) 10 x 10GbE SFP+ 2 x 40GbE QSFP 1 x 100GbE CFP IOC options3 40 x 1GbE SFP or (SRX5K-40GE-SFP.1x49 Junos OS 15. tcp.1X49-D30. capacity and features listed are based on systems running Junos OS 15.000 1 Million 2 Million Maximum user supported Unrestricted Unrestricted Unrestricted Network Connectivity Maximum available slots for IOCs 2 5 11 IOC3 options 2x100GbE CFP2 and 4x10GbE SFP+ or 6x40GbE QSFP+ and 24x10GbE SFP+ (SRX5K-MPC3-100G10G. IMIX (with Express Path) 468 Gbps 936 Gbps 2 Tbps Firewall performance 65 Gbps 130 Gbps 320 Gbps Latency (with Express Path) ~7-11µsec ~7-11µsec ~7-11µsec Maximum AES256+SHA-1 VPN performance 35 Gbps 100 Gbps 200 Gbps Maximum IPS performance 22 Gbps 50 Gbps 100 Gbps Maximum concurrent sessions 2 42 Million 114 Million 230 Million New sessions/second (sustained. SRX5400X. and SRX5800 Services Gateways Data Sheet Specifications SRX5400 SRX5600 SRX5800 Maximum Performance and Capacity 1 Junos OS version tested Junos OS 15.000 DES (56-bit). 2 Maximum concurrent sessions and new sessions/second improvements are a result of Junos 15. Actual results may vary based on Junos OS releases and by deployments. SRX5600E. 3way)2 420.000 15. SRX5600X. 3 IOC and Flex IOC are not compatible with SRX5400E. 3DES (168-bit). SRX5600.SRX5400. IOCs can be mixed from the following models: Flex IOC options3 16 x 1GbE RJ-45 (SRX5K-FPC-IOC) 16 x 1GbE SFP 4 x 10GbE XSP SRX5400 SRX5600 SRX5800 Processing Scalability Maximum available slots for SPCs 2 5 11 SPC: Dual CPU SPC: Dual CPU Services Process Card (SPC) options SPC2: Quad CPU SPC2: Quad CPU SPC2: Quad CPU Firewall Network attack detection Yes Yes Yes DoS and DDoS protection Yes Yes Yes TCP reassembly for fragmented packet protection Yes Yes Yes Brute force attack mitigation Yes Yes Yes SYN cookie protection Yes Yes Yes Zone-based IP spoofing Yes Yes Yes Malformed packet protection Yes Yes Yes IPsec VPN Site-to-site tunnels 15. large packet (with Express Path) 480 Gbps 960 Gbps 2 Tbps Firewall performance.000 15. and AES encryption Yes Yes Yes MD5 and SHA-1 authentication Yes Yes Yes 1 Performance. 6 .1x49 Firewall performance.000 15.1x49 and are measured under ideal testing conditions.

5 1. application identification identification identification Drop connection. application coverage).SRX5400.509) Yes Yes Yes Perfect forward secrecy (DH groups) 1. Attack response mechanisms session packet log. email summary. session session packet log. Stateful signatures. 2. Stateful signatures. 5 Prevent replay attack Yes Yes Yes IPv4 and IPv6 Yes Yes Yes Redundant VPN gateways Yes Yes Yes Intrusion Prevention System (IPS)* Signatures based and customizable (via templates) Yes Yes Yes Active/active traffic monitoring Yes Yes Yes Stateful protocol signatures Yes Yes Yes Stateful signatures. 5 1. close connection.000+ 15. 2. connection. email summary. session session packet log. IKE. email Attack notification mechanisms Structured syslog Structured syslog Structured syslog Worm protection Yes Yes Yes Simplified installation through recommended policies Yes Yes Yes Trojan protection Yes Yes Yes Spyware/adware/keylogger protection Yes Yes Yes Advanced malware protection Yes Yes Yes Protection against attack proliferation from infected Yes Yes Yes systems Reconnaissance protection Yes Yes Yes Request and response side attack protection Yes Yes Yes Compound attacks—combines stateful signatures and Yes Yes Yes protocol anomalies Create custom attack signatures Yes Yes Yes Access contexts for customization 600+ 600+ 600+ Attack editing (port range. connection. application coverage).000+ 15. other) Yes Yes Yes Stream signatures Yes Yes Yes Protocol thresholds Yes Yes Yes Stateful protocol signatures Yes Yes Yes Approximate number of attacks covered 15. PKI (X. 7 . and SRX5800 Services Gateways Data Sheet SRX5400 SRX5600 SRX5800 Manual key.000+ Detailed threat descriptions and remediation/patch info Yes Yes Yes Create and enforce appropriate application-usage Yes Yes Yes policies Attacker and target audit trail and reporting Yes Yes Yes Frequency of updates Daily and emergency Daily and emergency Daily and emergency * Session capacity differs based on UTM/AppSecure/IPS features enabled. 2. protocol anomaly protocol anomaly protocol anomaly Attack detection mechanisms detection (zero-day detection (zero-day detection (zero-day coverage). close Drop connection. session summary. SRX5600. close Drop connection.

DIP with loopback Yes Yes Yes grouping User Authentication and Access Control Built-in (internal) database Yes Yes Yes RADIUS accounting Yes Yes Yes Web-based authentication Yes Yes Yes * Session capacity differs based on UTM/AppSecure/IPS features enabled.SRX5400.IP-shifting DIP Yes Yes Yes Source NAT with PAT .fix-port Yes Yes Yes Source NAT . 8 . and SRX5800 Services Gateways Data Sheet SRX5400 SRX5600 SRX5800 UTM * Antivirus Yes Yes Yes Content filtering Yes Yes Yes Enhanced Web filtering Yes Yes Yes Redirect Web filtering Yes Yes Yes Antispam Yes Yes Yes AppSecure* AppTrack (application visibility and tracking) Yes Yes Yes AppFirewall (policy enforcement by application name) Yes Yes Yes AppQoS (network traffic prioritization by application Yes Yes Yes name) User-based application policy enforcement Yes Yes Yes GPRS Security GPRS stateful firewall Yes Yes Yes Destination Network Address Translation Destination NAT with PAT Yes Yes Yes Destination NAT within same subnet as ingress Yes Yes Yes interface IP Destination addresses and port numbers to one single Yes Yes Yes address and a specific port number (M:1P) Destination addresses to one single address (M:1) Yes Yes Yes Destination addresses to another range of addresses Yes Yes Yes (M:M) Source Network Address Translation Static Source NAT .port-translated Yes Yes Yes Source NAT without PAT . SRX5600.IP address persistency Yes Yes Yes Source pool grouping Yes Yes Yes Source pool utilization alarm Yes Yes Yes Source IP outside of the interface subnet Yes Yes Yes Interface source NAT .interface DIP Yes Yes Yes Oversubscribed NAT pool with fallback to PAT when the Yes Yes Yes address pool is exhausted Symmetric NAT Yes Yes Yes Allocate multiple ranges in NAT pool Yes Yes Yes Proxy ARP for physical port Yes Yes Yes Source NAT with loopback grouping .

000 BGP peers 2.000 Dynamic routing Yes Yes Yes Static routes Yes Yes Yes Source-based routing Yes Yes Yes Policy-based routing Yes Yes Yes Equal cost multipath (ECMP) Yes Yes Yes Reverse path forwarding (RPF) Yes Yes Yes Multicast Yes Yes Yes IPv6 Firewall/stateless filters Yes Yes Yes Dual stack IPv4/IPv6 firewall Yes Yes Yes RIPng Yes Yes Yes BFD.000 1. 9 .SRX5400.000 segregation (virtual routers) Maximum security zones 2.000 2. and SRX5800 Services Gateways Data Sheet SRX5400 SRX5600 SRX5800 Public Key Infrastructure (PKI) Support PKI certificate requests (PKCS 7 and PKCS 10) Yes Yes Yes Automated certificate enrollment (SCEP) Yes Yes Yes Certificate authorities supported Yes Yes Yes Self-signed certificates Yes Yes Yes Virtualization Maximum virtual firewalls with data plane traffic 2.000 30.096 4.000 Maximum virtual firewalls with data plane and 32 32 32 administrative separation (logical systems) Additional off-platform virtual firewall option with Firefly Unlimited Unlimited Unlimited (VM based) Maximum number of VLANs 4.000 2.000 30.096 4.000 2.000 2.096 Routing BGP instances 1.000 2. BGP Yes Yes Yes ICMPv6 Yes Yes Yes OSPFv3 Yes Yes Yes Class of service Yes Yes Yes Mode of Operation Layer 2 (transparent) mode Yes Yes Yes Layer 3 (route and/or NAT) mode Yes Yes Yes IP Address Assignment Static Yes Yes Yes Dynamic Host Configuration Protocol (DHCP) Yes Yes Yes Internal DHCP server Yes Yes Yes DHCP relay Yes Yes Yes 4 Maximum number of BGP and OSPF routes recommended is 100. SRX5600.000 1.000 BGP routes 1 Million4 1 Million4 1 Million4 OSPF instances 400 400 400 OSPF routes 1 Million4 1 Million4 1 Million4 RIP v1/v2 instances 50 50 50 RIP v2 table size 30.000.000 2.

and SRX5800 Services Gateways Data Sheet SRX5400 SRX5600 SRX5800 Traffic Management Quality of Service (QoS) Maximum bandwidth Yes Yes Yes RFC2474 IP Diffserv in IPv4 Yes Yes Yes Firewall filters for COS Yes Yes Yes Classification Yes Yes Yes Scheduling Yes Yes Yes Shaping Yes Yes Yes Intelligent Drop Mechanisms (WRED) Yes Yes Yes Three level scheduling Yes Yes Yes Weighted round robin for each level of scheduling Yes Yes Yes Priority of routing protocols Yes Yes Yes Traffic management/policing in hardware Yes Yes Yes High Availability (HA) Active/passive. 10 . admin. two SRX5K-RE-13-20 modules must be installed on each cluster member. telnet.SRX5400. SSH) Yes Yes Yes Junos Space Security Director Yes Yes Yes Administration Local administrator database support Yes Yes Yes External administrator database support Yes Yes Yes Restricted administrative networks Yes Yes Yes Root admin. active/active Yes Yes Yes In-Service Software Upgrade (ISSU) 5 Yes Yes Yes Configuration synchronization Yes Yes Yes Session synchronization for firewall and IPsec VPN Yes Yes Yes Session failover for routing change Yes Yes Yes Device failure detection Yes Yes Yes Link and upstream failure detection Yes Yes Yes Dual control links 6 No Yes Yes Interface link aggregation/LACP Yes Yes Yes Redundant fabric links Yes Yes Yes Management WebUI (HTTP and HTTPS) Yes Yes Yes Command line interface (console. 6 To enable dual control links on the SRX5000 line. SRX5600. and read only user levels Yes Yes Yes Software upgrades Yes Yes Yes Configuration rollback Yes Yes Yes Logging/Monitoring Structured syslog Yes Yes Yes SNMP (v2 and v3) Yes Yes Yes Traceroute Yes Yes Yes 5 Please consult the technical publication documents and release notes for a list of compatible ISSU features.

5 in 17. please visit www.026kg water/kg of dry air water/kg of dry air water/kg of dry air 7 SRX5000 line of gateways operating with Junos OS release 10. R7. SRX5600.3. SRX-MIC-10XG-SFPP en/products-services. and SRX5800 Services Gateways Data Sheet SRX5400 SRX5600 SRX5800 3GPP TS 20. network to maintain required levels of performance. † These products require Junos 12.1 kg) (81.0 Yes Yes Yes R8: 3GPP TS 29.8 in 17. SCB.1x46) 12. SRX5K-MPC. For more details. and not greater than 15 days in 1 year Warranty Ordering Information For warranty information. SRX5K-SPC-4-15-320. and R8 releases of 3GPP TS 20. RE. high-performance network.5B Mobile Station (MS) info change messages .1x46) 12.5A Multimedia Broadcast and Multicast Services (MBMS) messages .5 x 14 x 23.Section 7. operational efficiency while reducing costs and minimizing SRX5K-SPC-4-15-320. extend. Juniper Networks Services and Support Routing Engine (RE).1x46) 12.45 x 8.5 x 59. reliability.1x46) Dimensions and Power 17.3. version 7. SRX5K-RE-1800X4. and optimize your SRX5400E-B1-AC† SRX5400 Configuration 1 includes chassis.060 Compliance 7 R6: 3GPP TS 29.21.026kg but not to exceed 0. SRX5K-MPC.5 x 70. 11 . and SRX-MIC-10XG-SFPP that are designed to accelerate.100 watts (AC high 8.7 x 24.060 version 6.Section 7.1X47-D15 or greater.0 Yes Yes Yes R7: 3GPP TS 29.0 Yes Yes Yes Certifications Safety certifications Yes Yes Yes Electromagnetic Compatibility (EMC) certifications Yes Yes Yes RoHS2 Compliant (European Directive 2011/65/EU) Yes Yes Yes Designed for NEBS Level 3 Yes Yes Yes NIST FIPS-140-2 Level 2 In progress Yes (with Junos OS 10. please visit www. SRX5K-SPC-4-15-320.6 x 60.4R4) Yes (with Junos OS 10. achieving a faster time to value for your network.4R4) Yes (with Junos OS Yes (with Junos OS Yes (with Junos OS Common Criteria NDPP+TFFW EP + VPN EP 12.060 with the following exceptions (not supported on the SRX5000 line): . and risk.7 cm) Fully configured 128 lb Fully Configured: 180 lb Fully Configured: 334 lb Weight (58. 2xAC HC PEM.3.060 version 8.026kg but not to exceed 0.2 cm) (44.5 x 27.12 Initiate secondary PDP context from GGSN 8 Short term is not greater than 96 consecutive hours. two DC HC power supplies.3 x 22. Our services allow you to maximize standard midplane. two AC HC Juniper Networks is the leader in performance-enabling services power supplies.5 x 35.0 and later are compliant with the R6.7 kg) (151. and and availability.1 x 62.Section 7.200 watts (AC high Maximum power (AC high capacity) capacity) capacity) Typical Power 1540 watts 2440 watts 5015 watts Environmental Operating temperature – long term 41° to 104° F (5° to 40° C) 41° to 104° F (5° to 40° C) 41° to 104° F (5° to 40° C) Operating temperature – short term 8 23° to 131° F (-5° to 55° C) 23° to 131° F (-5° to 55° C) 23° to 131° F (-5° to 55° C) Humidity – long term 5% to 85% noncondensing 5% to 85% noncondensing 5% to 85% noncondensing 5% to 93% noncondensing 5% to 93% noncondensing 5% to 93% noncondensing Humidity – short term8 but not to exceed 0.100 watts 4.6 kg) Power supply (AC) 100 to 240 VAC 100 to 240 VAC 200 to 240 VAC Power supply (DC) -40 to -60 VDC -40 to -60 VDC -40 to -60 VDC 4. HC fan tray.5 cm) (44. SRX5K-MPC.1x46) 12. Juniper SRX-MIC-10XG-SFPP Networks ensures operational excellence by optimizing the SRX5400BB-DC SRX5400 base bundle includes Chassis.1x46) ICSA Network Firewall Yes Yes Yes ICSA IPsec Yes Yes Yes Yes (with Junos OS Yes (with Junos OS Yes (with Junos OS USGv6 Base/Bundle SRX5400BB-AC SRX5400 base bundle includes Chassis.8 x 23.5 in Dimensions (W x H x D) ( Model Number Description warranty/.

2X HC fan tray SRX5400E-B2-AC† SRX5400 Configuration 2 includes chassis. and Engine. enhanced midplane. SRX5K-RE-13-20 SRX5000 line Routing SRX5400 DC-S (extra redundant DC PEMS). two DC HC power Supplies. standard midplane. RE2. SRX5K- SCBE. 2 IOC 16-port SFP for SRX5k-FPC- DC high capacity power supplies Ethernet module. SRX5K-RE-1800X4. All models SRX5K-SPC-4-15-320. SRX5K-MPC3. SRX5K-RE-1800X4. Xeon. SRX5K-SCB3. SRX5600X-BASE : ‡ SRX5600 Configuration includes chassis. 2xSRX5K- SRX-MIC-10XG-SFPP SCBE.8Ghz quad-core SRX5600E SRX5K-SCB3. SRX5K-SCBE. 1x10GbE MIC. SRX5K. SRX5600. and IOC modules 2xSRX5400-APPSEC-1 (1 year) SRX-IOC-16GE-TX SRX5000 line Flex IOC Flex IOC module SRX5600BASE-HC-AC AC SRX5600 chassis includes RE. 1xSPC2. 1xSPC2. 2xHC PEM. SRX5K-MPC. 2xAC HC PEM. 1xSPC2. and SRX-MIC-10XG-SFPP SRX5800BASE-HC-AC AC SRX5800 chassis. two SRX5800E-BASE-HC. Generation Service 40G10G Processing Card (featuring 20 million SRX5400X-B3‡: SRX5400 Configuration includes chassis. no SRX5400X-B5-DC SRX5400X cluster bundle (promotional transceivers offer) includes 2xSRX5400X-B1 (SCB3. SRX5400E-B2-DC† SRX5400 Configuration 2 includes chassis. SRX5K-MPC. HC fan tray SRX-IOC-16GE-SFP SRX5000 line Flex Flex IOC module SRX5600BASE-HC-DC DC SRX5600 chassis. 2xDC HC PEM. HC fan tray. SCB. 1x10GbE MIC. SRX5K-RE-1800X4. SRX5K-SCBE. SRX-MIC-10XG-SFPP enhanced midplane. 2X HC SCB. 1. SRX5000 Line Components Compatible 2xSRX5K-SPC-4-15-320 .3 GHz. 1x10GbE MIC. RE.1X47-D15 or greater. SRX5800 2xDC PEMs). and AC† midplane. SCBE. 4xSRX5600-PWR-2400. SCB. includes RE. HC fan tray. 12 . Systems and SRX-MIC-10XG-SFPP SRX5K-SCB SCB SRX5000 line SRX5400 SRX5400E-B5-AC SRX5400E cluster bundle (promotional Switch Control Board SRX5600 offer) includes 2xSRX5400E-B1-AC SRX5800 (SCB2. 1xIOC2. SRX5K-40GE-SFP 40x1 Gigabit SFP SRX5600 AC-S (extra redundant AC PEMS). SRX5K-SCBE† SRX5K Enhanced SRX5400E 2xAC PEMs). 2xSRX5K- SRX5400B2-DC SRX5400 bundle 2 includes chassis. transceivers 2xAC PEMs). HC fan tray. and SRX5800 Services Gateways Data Sheet Model Number Description Model Number Description SRX5400E-B1-DC † SRX5400 Configuration 1 includes chassis. the SRX5000 line. HC fan tray. and SRX5800E 2xSRX5400-APPSEC-1 (1 year) SRX5K-SCB3‡ SRX5000 SCB3 SRX5400X SRX5400E-B5-DC SRX5400E cluster bundle (promotional Switch Control Board SRX5600X offer) includes 2xSRX5400E-B1-DC SRX5800X (SCB2. 2x high capacity DC power supplies 2xSRX5K-SPC-4-15-320. SRX5800 SCBE. two fan tray SRX5K-SPC-4-15-320. two AC HC power supplies. 4xSRX5600-PWR-2520. includes RE. SRX. HC fan tray SRX5K-SPC-4-15-320. 2xDC HC PEM. 2xDC HC PEM. 2xHC PEM. SRX5800E-BASE-HC. 1xIOC2. RE. SRX5K-MPC. 1x10GbE MIC. SRX5K-SCB3. 128GB SSD SRX5400X MIC-10XG-SFPP SRX5600X SRX5400X-B2‡: SRX5400 Configuration includes chassis. 2xAC HC PEM. SRX5K-RE-1800X4. SRX5800 chassis includes standard and SRX-MIC-10XG-SFPP DC† midplane. RE2. 2xSCB. SRX5K-RE-1800X4. 2 AC high capacity power supplies SRX5400B2-AC SRX5400 bundle 2 includes Chassis. SRX5K-RE-1800X4. 1xSPC2. 1xIOC2. 2xHC PEM. SRX5K-RE-1800X4. 2 16-port 10/100/1000 for SRX5k-FPC- AC high capacity power supplies Ethernet module IOC SRX5600E-BASE-HC. HC fan tray. no RE2. 2xDC PEMs). SRX5800 chassis includes standard SRX5K-SPC-4-15-320. 4xSRX5600-PWR-2400. 2xAC HC PEM. SRX5600 chassis includes standard SRX5600 AC† midplane. 2xSRX5K-SCB3. 2xDC HC PEM. SRX5600 2xSRX5400-APPSEC-1 (1 year) 2 GB DRAM SRX5800 SRX5400X-B1‡: SRX5400 Configuration includes chassis. SRX5K-MPC. HC fan tray † These products require Junos 12.SRX5400. Supports 2 Flex DC-S (extra redundant DC PEMS). SRX5800X enhanced midplane. SRX5600 chassis includes standard SRX5800 DC† midplane. SRX5K-MPC3. SRX5K-SPC-2-10-40 SRX5000 line Service SRX5600 SRX5K-SPC-4-15-320. 2xHC PEM. no IOC transceivers SRX5600 SRX5600E-BASE-HC. 4xSRX5600-PWR-2520. and Ethernet I/O Card for SRX5800 2xSRX5400-APPSEC-1 (1 year) the SRX5000 line. 1xIOC2. SRX5K-MPC. 2xSCB. Switch Control Board SRX5600E AC-S (extra redundant AC PEMS). SRX5K-SPC-4-15-320 SRX5000 line Next. SRX5K-SCB3. SRX5K-RE-1800X4. SRX5800BASE-HC-DC DC SRX5800 chassis. SCB. SRX5K-RE-1800X4. 1. SRX5K-SCBE. SRX5K-MPC. Processing Card SRX5800 100G10G SRX5K-4XGE-XFP 4x10 Gigabit XFP SRX5600 SRX5400X-B5-AC SRX5400X cluster bundle (promotional Ethernet I/O Card for SRX5800 offer) includes 2xSRX5400X-B1 (SCB3. standard midplane. sessions) enhanced midplane. SRX5K-RE-1800X4† SRX5K Route Engine. 2xHC PEM. 16GB DRAM. 2xHC fan tray standard midplane. includes RE. SRX5K-FPC-IOC SRX5000 line Flex IOC SRX5600 RE2. and SRX5800X-BASE‡: SRX5800 Configuration includes chassis. SRX5K-RE-1800X4. HC fan tray. SRX5800E SRX5K-SPC-4-15-320. SRX5400E enhanced midplane. SRX5K-RE-1800X4. SRX5K-RE-1800X4.

SR 100G10G module for SRX5K- MPC CFP2-100GBASE-LR4 CFP2 100G optical SRX5K-MPC3- transceiver. pluggable transceiver. single mode SRX-IOC-4XGE- XFP ‡ Requires Junos 15. SFP LH Gigabit Ethernet SRX5K-40GE. MIC JNP-QSFP-40G-LX4 QSFP+ 40GBASE-LX4 SRX5K-MPC. SRX-SFP-1GE-T Small form. and SRX5800 Services Gateways Data Sheet Model Number Description Model Number Description SRX-IOC-4XGE-XFP SRX5000 line Flex Flex IOC module SRX-XFP-10GE-ER 10-Gigabit Ethernet SRX5K-4XGE- IOC 4x10 Gigabit XFP for SRX5k-FPC. SRX5600E pluggable 1000BASE. SR SRX5K-MPC3 SRX5K-MPC3. no IOC 40 Km. 10GbE and supports 2 MIC transceiver. SFP SRX5400-APPSEC-5 Five year subscription for Application LX Gigabit Ethernet SRX-IOC-16GE. SRX5600.1X49-D10 or greater 13 . LR SRX5K-MPC3 SRX5K-FPC-IOC SRX5800 SRX-SFP-10GE-SR 10GbE SFP+ optical SRX5K-MPC SRX-5K-BLANK Blank Panel for SRX5K All models transceiver. SRX5400-APPSEC-3 Three year subscription for Application optic module SFP Security and IPS updates for SRX5400. MIC module for SRX5K-MPC AppSecure Subscription Transceivers SRX5400-APPSEC-1 One year subscription for Application Security and IPS updates for SRX5400. SRX5600E factor pluggable SFP 1000BASE-T Gigabit SRX-IOC-16GE. XFP SRX5800-APPSEC-A-5 Five year Subscription for Application short reach multimode SRX-IOC-4XGE. SRX-SFP-1GE-SX Small form-factor SRX-MIC-20GE. Optic Module SFP SRX5400E SRX5K-40GE- SFP SRX5600-APPSEC-A-1 One year subscription for Application Security and IPS updates for SRX5600.3ba) for SRX-MIC- SRX5400X 1X100G-CFP SRX5600X SRX5800X SRX-CFP-100G-SR10 100GbE SR10 CFP SRX5K-MPC transceiver. SRX5400E SRX-CFP-100G-LR4 100GbE LR4 CFP SRX5K-MPC 100G10G‡ 2x100GbE and SRX5600E transceiver (IEEE 4x10GbE port SRX5800E 802. SFP SRX5600E SRX5K-40GE- SFP SRX5600-APPSEC-A-5 Give year Subscription for Application Security and IPS updates for SRX5600. XFP SRX5800E SRX-XFP-10GE-LR 10-Gigabit Ethernet SRX5K-4XGE- pluggable transceiver.SRX5400. SRX-SFP-1GE-LH Small form factor SRX-IOC-16GE- SRX5400E pluggable 1000BASE. OM3 for SRX- and 24x10GbE ports SRX5600E MIC-1X100G-CFP SRX5800E SRX5400X SRX-QSFP-40G-SR4 40GbE SR4 QSFP+ SRX5400 SRX5600X transceiver for SRX. 200M ET SRX5K-MPC3 1GbE MIC Interfaces modules 0-85 SRX-MIC-1X100G-CFP MIC with 1x100GbE All models SRX-SFPP-10G-LR 10GE SFP+ optical SRX5K-MPC CFP Interface MIC transceiver. SRX5800E SFP SRX5800-APPSEC-A-3 Three year subscription for Application SRX-XFP-10GE-SR 10-Gigabit Ethernet SRX5K-4XGE. SRX5400E SRX-SFP-1GE-LX Small form-factor SRX-MIC-20GE- pluggable 1000BASE. 40G transceiver. LR SRX5K-MPC3 module for SRX5K- SRX-QSFP-40G-LR4 40GE QSFP+ optical SRX5K-MPC MPC transceiver. SRX-SFPP-10G-SR-ET 10GbE SR SFP+ SRX5K-MPC 40GbE. XFP Ethernet module. 6x40GbE SRX5400E 100M. SRX5800-APPSEC-A-1 One year subscription for Application Ethernet Module (uses SFP Security and IPS updates for SRX5800. SRX-MIC-20GE. LR SRX5K-MPC3 SRX-MIC-2X40G-QSFP MIC with 2x40GbE All models CFP2-100GBASE-SR10 CFP2 100G optical SRX5K-MPC3- QSFP+ Interfaces MIC transceiver. SRX5K-MPC SRX5800X MIC-2X40G-QSFP SRX5K-MPC3 SRX5K-MPC MPC for 100GbE. Security and IPS updates for SRX5800 pluggable transceiver. XFP 10 Km. SRX5K IOC3. module for SRX5K. LR 100G10G SRX-MIC-10XG-SFPP MIC with 10x10GbE All models SFP+ Interfaces. single mode SRX-IOC-4XGE- transceivers SRX5600 XFP SRX5800 SRX-SFP-10GE-LR 10GbE SFP+ optical SRX5K-MPC SRX5K-IOC-BLANK Blank Panel for SRX5600 transceiver. Security and IPS updates for SRX5800. All models. SRX5K-MPC3-40G10G ‡ SRX5K IOC3. Security and IPS updates for SRX5400. MMF. 100m SRX5K-MPC3- MPC (150m) with OM3 40G10G (OM4) duplex MMF SRX-MIC-20GE-SFP MIC with 20x1GbE SFP All models fiber Interfaces. SFP SX Gigabit Ethernet SRX5600-APPSEC-A-3 Three year subscription for Application SRX-IOC-16GE- Optic Module Security and IPS updates for SRX5600 . Cat 5 cable) SRX5K-40GE.

C19.5 m. CBL-M-PWR-RA-EU AC power cord. Canada. SRX5800E Angle SRX5800-W-EWF-1 One year subscription for Juniper- Websense Enhanced Web Filtering service on SRX5800. SRX5400. Right Angle SRX5400-W-EWF-1 One year subscription for Juniper- Websense Enhanced Web Filtering service CBL-M-PWR-RA-CH AC power cord. CBL-PWR-RA-TWLK. AV and Anti-spam service on CBL-M-PWR-RA. Websense Enhanced Web Filtering service 16 A/250 V. Right Angle SRX5600-W-EWF-1 One year subscription for Juniper- CBL-PWR-RA-JP15 AC power cable. Japan (NEMA LOCKING). Sophos Anti-spam service on SRX5800.. and SRX5800 Services Gateways Data Sheet Model Number Description Model Number Description IPS Subscription Services Offload License* Compatible SRX5K-IDP One year IPS signature subscription for Systems** SRX 5000 line SRX5K-SVCS. parts of Central America. SRX5800E * In 12. C19. C19. Cont. AC power cord. Australia (SAA/3/15). US (NEMA LOCKING). SRX5600E 13 A/250 V. JIS 8303 15 A/125 V Websense Enhanced Web Filtering service on SRX5600. C19. EWF. SRX5400E SRX5600 SRX5400-S-AS-1 One year subscription for Juniper. SRX5800. Right Angle SRX5600-S-AV-1 One year subscription for Juniper-Sophos CBL-M-PWR-RA-US AC power cord. C19. SRX5400E SRX-5800-LSYS-25 25 incremental Logical Systems License for SRX5800. SRX5400E IDP. on SRX5400.5 m. Right Angle SRX5400-W-EWF-3 Three year subscription for Juniper. SRX5400E 15 A/250 V. SRX5400E SRX-5800-LSYS-1 1 incremental Logical Systems License for SRX5400-S-AS-5 Five year subscription for Juniper. SRX5800E Sophos Anti-spam service on SRX5400. SRX5400E Power Cords SRX5400-S-AV-5 Five year subscription for Juniper-Sophos CBL-M-PWR-RA-AU AC power cord. SRX5800E SRX5400-S-AV-3 Three year subscription for Juniper-Sophos AV service on SRX5400. the Express Path feature is supported on all SRX5000 Services Gateways including the SRX5400. SRX5400E SRX5400. SRX5800. Services offload SRX5400 SRX5K-IDP-3 Three year IPS signature subscription for OFFLOAD-RTU license for SRX5600 SRX 5000 line SRX5000 line. AV and Anti-spam service on SRX-5600-LSYS-1 1 incremental Logical Systems License for SRX5400. Right Angle on SRX5400.5 m. 2. parts of SRX5800E South America. 2. 2. For versions prior to the X48 release. SRX5400E SRX-5400-LSYS-5 5 incremental Logical Systems License for SRX5400-CS-BUN-3 Three year subscription for AppSecure.S.5 m.SRX5400. UK (BS89/13). USA/Canada (N6/20). 2. SRX5800E and Mexico. 2. this SRX5800 is not an annual SRX5K-IDP-5 Five year IPS signature subscription for SRX license subscription 5000 line UTM Subscription Logical Systems License SRX5400-CS-BUN-1 One year subscription for AppSecure.5 m. SRX5800E SRX5400-S-AV-1 One year subscription for Juniper-Sophos AV service on SRX5400. and parts of Asia. AV and Anti-spam service on US15 15 A/125 V 2. SRX5400E CBL-M-PWR-RA-IT AC power cord. NEMA L5-15P (twist lock) IDP. SRX5400E Angle). 2. SRX-5400-LSYS-1 1 incremental Logical Systems License for IDP. No separate license is required. AC power cable. Right Angle Websense Enhanced Web Filtering service on SRX5400. the Services Offload feature was renamed Express Path and is included without requiring a license for Junos X48 releases and beyond. EWF. 16 A/250 V. Right Angle SRX5800-S-AS-1 One year subscription for Juniper.5 m. C19. 14 . SRX5600E SRX5400E SRX-5600-LSYS-25 25 incremental Logical Systems License SRX5400-S-AS-3 Three year subscription for Juniper- for SRX5600 Sophos Anti-spam service on SRX5400. AV and Anti-spam service on SRX5400. China (GB 2099. SRX5800-S-AV-1 One year subscription for Juniper-Sophos parts of Africa. SRX5600 and SRX5800 Services Gateways.5 m. EWF. AV service on SRX5400. CBL-PWR-RA-US15 AC power cable. SRX5400E SRX-5800-LSYS-5 5 incremental Logical Systems License for SRX5800. 20 A/250 V. With the X48 release.5 m length for U. EWF. SRX5600. Right Angle SRX5600-S-AS-1 One year subscription for Juniper- Sophos Anti-spam service on SRX5600. 2. Right AV service on SRX5800. IDP. SRX5600E 20 A/250 V. SRX5600. 2. Right Angle IDP. SRX5600E 2. C19. AV service on SRX5600. Europe (VII).3X48-D10. Italy (I/3/16). AV and Anti-spam service on SRX5400. required and supports only SRX5600 and SRX5800 products. CBL-M-PWR-RA-UK AC power cord. NEMA 5-15 15 A/125 V.5 m length for Japan.5 m length for North America. 2. SRX5600. C19.1-1996. SRX5400E SRX5400-CS-BUN-5 Five year subscription for AppSecure. SRX-5600-LSYS-5 5 incremental Logical Systems License for Sophos Anti-spam service on SRX5400. the Services Offload license is still ** Express Path is available on the SRX5400.5 m. SRX5400E SRX-5400-LSYS-25 25 incremental Logical Systems License for SRX5400. SRX5600E TWLK-US 20 A/250 V. Right Angle SRX5800-CS-BUN-1 One year subscription for AppSecure. SRX5600-CS-BUN-1 One year subscription for AppSecure. EWF. SRX5400-W-EWF-5 Five year subscription for Juniper- 16 A/250 V. SRX5400E CBL-M-PWR-RA-JP AC power cord.

All rights reserved. Junos and QFabric are registered trademarks of Juniper Networks. or registered service marks are the property of their respective owners.JUNIPER (888.586. All other trademarks.745. 1000254-029-EN Feb 2016 . registered marks. The Netherlands or +1.SRX5400.701 www. Juniper Networks International Inc.2000 Phone: Amsterdam. in the United States and other countries. Corporate and Sales Headquarters APAC and EMEA Headquarters Juniper Networks. Juniper Networks delivers the software. Juniper Networks assumes no responsibility for any inaccuracies in this document. from consumers to cloud providers.2100 Fax: +31. SRX5600. transfer.207. Inc. 1133 Innovation Way Boeing Avenue 240 Sunnyvale. service marks. or otherwise revise this publication without notice. modify. Additional information can be found at www. the Juniper Networks logo. Inc.125. and SRX5800 Services Gateways Data Sheet About Juniper Networks Juniper Networks is in the business of network innovation.700 Fax: +1. CA 94089 USA 1119 PZ Schiphol-Rijk Phone: Copyright 2016 Juniper Networks. The company serves customers and partners worldwide. silicon and systems that transform the experience and economics of networking. Juniper Networks. Juniper Networks reserves the right to From devices to data centers.