Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asia Region
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center
image gallery image gallery image gallery image gallery image gallery
SRX Series
SRX100
 
SRX110
 
SRX210
 
SRX220
 
SRX240
 
SRX550
 
SRX650
 
SRX1400
 
SRX3400
 
SRX3600
 
SRX5600
 
SRX5800
 
AppSecure
 
 

Need Help?

  • Learn How to Buy
  • Call Us
  • Email Us
Print
Tweet
  • Specifications
  • Modules
  • Literature
  • Related Information
  • Ordering
Junos Software version tested
Junos 12.1X44
Firewall performance (max)
55 Gbps
IPS performance (NSS 4.2.1)
15 Gbps
AES256+SHA-1 / 3DES+SHA-1 VPN performance
15 Gbps
Maximum concurrent sessions
2.25/ 6 million sessions *
* Additional Extreme License required for 6M sessions
New sessions/second (sustained, TCP, 3-way)
270,000
Maximum security policies
40,000
Maximum users supported
Unrestricted
Maximum available slots for IOCs
6 (front slots)
Fixed I/O ports
8 10/100/1000 + 4 SFP
CX111 3G Bridge support
N/A
Internal 3G Express Card Slot support
N/A
Centralized Management
Junos Space Security Design
LAN interface options
  • 16 x 1 10/100/1000 copper
  • 16 x 1 Gigabit Ethernet small form-factor pluggable transceivers (SFP)
  • 2 x 10 Gigabit Ethernet XFP
High-availability support
  • Active/Passive, Active/Active
  • Low impact chassis cluster
  • Interface aggregation groups across chassis cluster
AppSecure Services
  • Application Identification: yes
  • Application Denial of Service Protection (AppDoS): yes
  • AppTrack: yes
  • AppQoS: yes
  • AAppFW: yes
Dimensions and Power
  • Dimensions (W x H x D): 17.5 x 8.75 x 25.5 in (44.5 x 22.2 x 64.8 cm)
  • Weight: Chassis: 43.6 lb (19.8 kg), Fully Configured: 115.7 lb (52.6 kg)
  • Power supply (AC): 100 to 240 V AC
  • Power supply (DC): -40 to -72 V DC
  • Maximum power draw: 1,750 W (AC power), 1,850 W (DC power)
  • Power supply redundancy: 2 + 1 / 2 + 2
Firewall
  • Network attack detection: Yes
  • DoS and DDoS protection: Yes
  • TCP reassembly for fragmented packet protection: Yes
  • Brute force attack mitigation: Yes
  • SYN cookie protection: Yes
  • Zone-based IP spoofing: Yes
  • Malformed packet protection: Yes
  • GPRS stateful inspection: Yes
Intrusion Prevention System
  • Stateful protocol signatures: Yes
  • Attack detection mechanisms: Stateful signatures, protocol anomaly detection (zero-day coverage), application identification
  • Attack response mechanisms: Drop connection, close connection, session packet log, session summary, email, custom session
  • Attack notification mechanisms: Structured syslog
  • Worm protection: Yes
  • SSL encrypted traffic inspection: Yes
  • Simplified installation through recommended policies: Yes
  • Trojan protection: Yes
  • Spyware/adware/keylogger protection: Yes
  • Other malware protection: Yes
  • Protection against attack proliferation from infected systems: Yes
  • Reconnaissance protection: Yes
  • Request and response side attack protection: Yes
  • Compound attacks — combines stateful signatures and protocol anomalies: Yes
  • Create custom attack signatures: Yes
  • Access contexts for customization: 500+
  • Attack editing (port range, other): Yes
  • Stream signatures: Yes
  • Protocol thresholds: Yes
  • Stateful protocol signatures: Yes
  • Approximate number of attacks covered: 6,000+
  • Detailed threat descriptions and remediation/patch info: Yes
  • Create and enforce appropriate application-usage policies: Yes
  • Attacker and target audit trail and reporting: Yes
  • Deployment modes: Inline or TAP

Switch Fabric and Control Board (SCB)
At the heart of the Dynamic Services Architecture is the switch fabric and control board (SCB). The SCB transforms the chassis from a simple module enclosure into a highly effective mesh network. The purpose of the SCB is to allow all modules in the chassis to send traffic at extremely high bandwidth.

The Route Engine (RE)
The routing engine (RE) is tightly coupled with the functionality of the SCB and can be considered the central nervous system of the architecture. The RE is the control plane of the chassis, and provides overall management and communications to and from system administrators, as well as calculating route tables for routing network traffic.

Services Processing Card (SPC)
As the "brains" behind the SRX3000 services gateways, services processing cards (SPCs) are designed to process all available services on the gateway. By eliminating the need for dedicated hardware for specific services or capabilities, no piece of hardware is ever taxed to the limit while other hardware sits idle. All of the processing capabilities of the SPCs are used to support any and all services and capabilities of the gateway. The same SPCs are supported on both the SRX3600 and the SRX3400 services gateways.(Note: A minimum of one NPC and one SPC is required for proper system functionality.)

Network Processing Cards (NPC)
To ensure maximum processing performance and flexibility, the SRX3000 line of services gateways utilize network processing cards (NPCs) to distribute inbound and outbound traffic to the appropriate SPCs and IOCs, apply QoS, and enforce DoS/DDoS protections. The SRX3600 can be configured to support one to three NPCs, while the SRX3400 can be configured to support one or two NPCs. Adding additional NPCs to these gateways allows organizations to tailor the solution to fit their specific performance requirements.(Note: A minimum of one NPC and one SPC is required for proper system functionality.)

Input/Output Cards (IOC)
In addition to supporting an ideal mix of built-in copper, small form-factor pluggable (SFP), and high-availability (HA) ports, the SRX3000 line allows the greatest I/O port density of any comparable offering. Each SRX3000 services gateway can be equipped with one or several input/output cards (IOCs), each supporting either 16 gigabit interfaces (16 x 1 copper or fiber Gigabit Ethernet), or 20 gigabit interfaces (2 x 10 Gigabit XFP Ethernet). With the flexibility to add additional IOCs, the SRX3000 line of services gateways can be equipped to support an ideal balance between interfaces and processing capabilities. (Note: A minimum of one NPC and one SPC is required for proper system functionality.)

SRX Cluster Module
The SRX Cluster Module is a hardware module that can be installed in the SRX3600 gateway to enable dual, or redundant, H/A control links for chassis clustering. When deploying SRX3600's in H/A clusters, the SRX Cluster Module utilizes the redundant architecture design of the SRX3000 line to provide full control link resiliency for mission critical environments.


SRX3K-SPC-1-10-40 SRX 3000 services processing card with 1Ghz processor and 4GB memory
SRX3K-NPC SRX 3000 network processing card
SRX3K-16GE-TX 16x1 10/100/1000 copper CFM I/O card for SRX3000
SRX3K-16GE-SFP 16x1 Gigabit SFP Ethernet I/O card for SRX3000, no transceivers
SRX3K-2XGE-XFP 2x10 Gigabit XFP Ethernet I/O card for SRX3000, no transceivers
SRX3K-RE-12-10 SRX3000 line routing engine with 1200Mhz processor and 1GB memory
SRX3K CRM SRX3000 line cluster module

Select Type

  • Application Notes
  • Brochures
  • Case Studies
  • Datasheets
  • Implementation Guides
  • Mobile Apps
  • Solution Briefs
  • Technical Documentation
  • White Papers
 

SRX Series and J Series Network Address Translation

Download [ PDF Document  635 KB ]

Juniper Networks SRX Series and J Series NAT for ScreenOS Users

Download [ PDF Document  283 KB ]

Security Services Gateways

Download [ PDF Document  751 KB ]

HEAnet provides high speed broadband to over 350,000 pupils in Ireland

Download [ PDF Document  93 KB ]

AppSecure for SRX Series Services Gateways

Download [ PDF Document  464 KB ]

SRX3400 and SRX3600 Services Gateways

Download [ PDF Document  586 KB ]

Securing Flows Within the Cloud-Ready Data Center Implementation Guide

Download [ PDF Document  4.04 MB ]

Application and Identity-Based Security Policies in the Cloud Ready Data Center

Download [ PDF Document  3.86 MB ]

Integrating Firewall Services in Data Center Network Architecture Using SRX Series Services Gateway

Download [ PDF Document  873 KB ]
  • Juniper 1on1 - Apple iPad
  • Juniper 1on1 - Android Tablet

AutoVPN: Easy Cost-Effective Deployment of IPsec VPN Networks on SRX Series Services Gateways

Download [ PDF Document  91 KB ]

Simply Connected: The New Campus and Branch Network

Download [ PDF Document  198 KB ]

Security for the New Mobile Network

Download [ PDF Document  352 KB ]

Unified Threat Management—All-in-One Security for Branch and Small to Medium Offices

Download [ PDF Document  255 KB ]

Simply Connected for Healthcare Network

Download [ PDF Document  383 KB ]

Comprehensive Security for Today’s Data Center

Download [ PDF Document  390 KB ]

Sophos Live Protection Anti-Malware Solution for SRX Series

Download [ PDF Document  268 KB ]

Flatten Your Data Center Architecture

Download [ PDF Document  253 KB ]

SRX Series Services Gateways: Delivering a Scalable, Secure Solution for Network-Based Managed Services Providers

Download [ PDF Document  228 KB ]
  • Release Information
  • Design
  • Configure
  • Install, Upgrade, and Deploy
  • Maintain, Manage, and Operate
  • Monitor and Troubleshoot
  • Downloadable PDFs
  • Documentation Home

SRX Series as Gi/SGi Firewall for Mobile Network Infrastructure Protection

Download [ PDF Document  595 KB ]

Juniper Networks Cloud Security

Download [ PDF Document  535 KB ]

An Integrated Security Solution for the Virtual Data Center and Cloud

Download [ PDF Document  1.12 MB ]

Building a Universal Enterprise WAN

Download [ PDF Document  1.77 MB ]

Security in the Next-Generation Data Center

Download [ PDF Document  199 KB ]

The Evolving Threat Landscape

Download [ PDF Document  220 KB ]

Powering Unified Communications with Branch SRX Series Services Gateways

Download [ PDF Document  640 KB ]

Security Considerations for Cloud-Ready Data Centers

Download [ PDF Document  557 KB ]

WANTED: The Future of Network Security for Service Providers - Now!

Download [ PDF Document  367 KB ]

Dynamic Services Architecture: A Revolutionary Approach to Integrated Network Security

Download [ PDF Document  188 KB ]

Technical Support:

  • SRX3600 Technical Support
  • SRX3600 Technical Documentation

Certification and Training

  • Junos Security Certification Track

  Ready to order? Find a Juniper partner.

 

Model Number Description
Base System
SRX3600BASE-AC

SRX3600 chassis, midplane, fan, RE, SFB-12GE, 2xAC PEM4 - no power cords - no SPC - no NPC

SRX3600BASE-DC

SRX3600 chassis, midplane, fan, RE, SFB-12GE, 2xDC PEM - no SPC - no NPC

SRX3600BASE-DC2

SRX3600 chassis, midplane, fan, routing engine, SFB-12 Gigabit Ethernet, 2xDC PEM - no SPC - no NPC

SRX3K-PWR-DC2

Enhanced DC power entry module for SRX3000 line

SRX 3000 Line Components
SRX3K-SPC-1-10-40

SRX3000 services processing card with 1Ghz processor and 4GB memory

SRX1K3K-NP-2XGE-SFPP

SRX3000 line Network Processing and I/O Card

SRX3K-NPC

SRX3000 network processing card

SRX3K-16GE-TX

16x1 10/100/1000 copper CFM I/O card for SRX3000

SRX3K-16GE-SFP

16x1 Gigabit SFP Ethernet I/O card for SRX3000, no transceivers

SRX3K-2XGE-XFP

2x10 Gigabit XFP Ethernet I/O card for SRX3000, no transceivers

SRX3K-CRM

Clustering module for the SRX3000 line to enable redundant control links in highavailability clusters

Transceivers
SRX-SFP-1GE-LH

Small form factor pluggable 1000BASE-LH Gigabit Ethernet optic module

SRX-SFP-1GE-LX

Small form-factor pluggable 1000BASE-LX Gigabit Ethernet optic module

SRX-SFP-1GE-SX

Small form-factor pluggable 1000BASE-SX Gigabit Ethernet optic module

SRX-SFP-1GE-T

Small form-factor pluggable 1000BASE-T Gigabit Ethernet module

SRX-XFP-10GE-SR

10 Gigabit Ethernet pluggable transceiver, short reach multimode

SRX-XFP-10GE-LR

10 Gigabit Ethernet pluggable transceiver, 10 Km, single mode

SRX-XFP-10GE-ER

10 Gigabit Ethernet pluggable transceiver, 40 Km, single mode

Logical System License
SRX-3600-LSYS-1

1 incremental Logical Systems License for SRX3600

SRX-3600-LSYS-5

5 incremental Logical Systems License for SRX3600

SRX-3600-LSYS-25

25 incremental Logical Systems License for SRX3600

AppSecure Subscription
SRX3600-APPSEC-A-1

One year subscription for Application Security and IPS updates for SRX3600

SRX3600-APPSEC-A-3

Three year subscription for Application Security and IPS updates for SRX3600

Services Offload License
SRX3K-SVCS-OFFLOADRTU

Services offload license for SRX3000 line; this is not an annual subscription license

IPS Subscription
SRX3K-IDP

One year IPS signature subscription for SRX3000 line

SRX3K-IDP-3

Three year IPS signature subscription for SRX3000 line

Extreme LTU
SRX3K-EXTREME-LTU

Expanded performance and capacity Extreme License for SRX3000 line

C19 Straight Power Cables
CBL-PWR-C19S-132-UK

Power cord, AC, Great Britain & Ireland, C19 at 70-80 mm, 13 A/250 V, 2.5 mm, straight

CBL-PWR-C19S-151-US15

Power cord, AC, Japan/US, NEMA 5-15 to C19 at 70-80 mm, 15 A/125 V, 2.5 m, straight

CBL-PWR-C19S-152-AU

Power cord, AC, Australia/New Zealand, C19 at 70-80 mm, 15 A/250 V, 2.5 m, straight

CBL-PWR-C19S-162-CH

Power cord, AC, China, C19, 16 A/250 V, 2.5 m, straight

CBL-PWR-C19S-162-EU

Power cord, AC, Continental Europe, C19, 16 A/250 V, 2.5 m, RA

CBL-PWR-C19S-162-IT

Power cord, AC, Italy, C19 at 70-80 mm, 16 A/250 V, 2.5 m, straight

CBL-PWR-C19S-162-JP

Power cord, AC, Japan, NEMA 6-20 to C19, 16 A/250 V, 2.5 m, straight

CBL-PWR-C19S-162-JPL

Power cord, AC, Japan/US, C19 at 70-80 mm, 16 A/250 V, 2.5 m, straight, locking plug

CBL-PWR-C19S-162-US

Power cord, AC, Japan/US, NEMA 6-20 to C19 at 70-80 mm, 16 A/250 V, 2.5 m, straight

CBL-PWR-C19S-162-USL

Power cord, AC, US, NEMA L6-20 to C19, 16 A/250 V, 2.5 m, straight, locking plug


SRX3600 System Configuration Guidelines
  • 12 slots for common form-factor modules (CFMs):
    • 6 in the front for IOCs and SPCs
    • 6 in the rear for NPCs and SPCs
  • 7 SPCs max (1 min)
  • 3 NPCs max (1 min)
  • 6 IOCs max

SRX3600 base-system configuration: SRX3600 base(AC or DC), one SPC, one NPC, and two power cords.

 

Related Products

Centralized Management

  • Junos Space Security Design
 

Network Security

  • Security Intelligence Center
 
 
  • About Juniper
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Green Networking
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Developers
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
  • Follow Us
  • j-net
  • YouTube
  • Twitter
  • Facebook
  • RSS
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.

Enterprise

Service Provider

Public Sector

Business Needs 

  • Application Infrastructure
  • Business Continuity
  • Mobility
  • Network Infrastructure
  • Security

Locations / Architectures 

  • Campus & Branch
  • Cloud-Ready Data Center
  • Remote & Mobile Users

Industries 

  • Energy and Utilities
  • Financial Services
  • Government
  • Healthcare
  • Education

The Innovators 

  • Customer Stories

Juniper Insights 

  • Net Matters

Business Needs 

  • Managed Service Provider
  • Network Infrastructure
  • Network Security
  • Network and Service Management
  • Residential
  • Telepresence

Locations / Architectures 

  • Core
  • Cloud-Ready Data Center
  • Universal Access
  • Universal Edge

Segments 

  • Cable Operator
  • Wireline Carrier
  • Content Service Provider
  • Wireless Carrier

Business Needs 

  • Application Infrastructure
  • Disaster Recovery / Business Continuity
  • Security
  • Certifications

Locations / Architectures 

  • Branch Office
  • Campus
  • Cloud-Ready Data Center
  • Remote Users
  • VPNs and WAN

Products by Category

  • Application Acceleration
  • Content and Media Delivery
  • Data Center Fabric
  • Identity and Policy Control
  • Juniper Developer Network
  • Mobile Infrastructure
  • Network Management
  • Network Operating System
  • Routers
  • Security
  • Software
  • Switches
  • Time Synchronization
  • Wireless
  • End-of-Sale Products

Services

  • Consulting Services
  • Installation and Configuration Services
  • Technical Services

All Products & Services

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

About Juniper

News and Information

The Juniper Difference

  • Company Profile
  • Leadership
  • Business Partners
  • Careers
  • Contact Us
  • Analyst Relations
  • Press Center
  • Events
  • Subscriptions
  • Innovations
  • Awards
  • Recognition
  • Customer Stories
  • Corporate Responsibility
  • Ventures
Help
|
My Account
|
Log Out