Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Navigation  Back up to About Overview 
[+] Expand All
[-] Collapse All

New and Changed Features for NFX250 Network Services Platform

This section describes the new features of the NFX250 platform, and enhancements to existing features in Junos OS Release 15.1X53-D47 for NFX250.


  • NFX250-S1E–NFX250-S1E is a new model with 1.9 GHz 6-core Intel CPU, 16 GB of memory, and 200 GB of enterprise grade solid-state drive (SSD) storage. NFX250-S1E can be wall mounted using the separately orderable Juniper Networks wall-mount kit.

Juniper Device Manager

In this release, Juniper Device Manager (JDM) additionally provides support for the following features:

  • The cross-connect feature enables traffic switching between any two OVS interfaces (any VNF interface or physical interface (hsxe0, hsxe1) connected to OVS). Either all traffic (unconditional) or traffic belonging to a particular VLAN can be bidirectionally switched between any two OVS interfaces.
  • Port-mirroring allows you to monitor network traffic. When the feature is enabled on a VNF interface, a copy of all network packets of that VNF interface is sent to the analyzer VNF for analysis. Additionally, you can configure MTU of size 2048 bytes on VNF interfaces.


  • vSRX offers the same capabilities as Juniper Networks SRX Series Services Gateways in a virtual form factor, providing perimeter security, IPsec connectivity, and filtering for malicious traffic without sacrificing reliability, visibility, and policy control. This virtual security and routing appliance ensures reliability for each application. The IPSec implementation for NFX250 platforms has been enhanced to protect the management traffic between JDM, VNFs and the remote SDN controller and other central servers. The IPSec implementation uses AutoKey IKE with preshared keys to authenticate the participants in an IKE session, each side must configure and securely exchange the preshared key in advance. IPSec for NFX250 devices supports only traffic selector based tunnels, multiple IPsec security associations are negotiated based on multiple traffic selectors configured. Configuration of interfaces and static routes is supported.

    Note: By default, vSRX version 15.1X49-D78 is pre-loaded on NFX250 Network Services platform 15.1X53-D47 release. Earlier versions of vSRX is not compatible with the NFX250 15.1X53-D47 release.

Related Documentation

Modified: 2017-09-08