Technical Documentation

SRX 210 Services Gateway Software Features and Licenses

The SRX 210 services gateway provides the software features listed in Table 1.

Note: You must purchase a separate software license to obtain some software features.

Table 1: SRX 210 Services Gateway Software Features and Licenses

Feature Category

SRX 210 Services Gateway Feature

Routing and Multicast

Open Shortest Path First (OSPF)

Border Gateway Protocol (BGP)

Routing Information Protocol version 1 (RIPv1) and version 2 (RIPv2)

Static routes

Intermediate System-to-Intermediate System (IS-IS)

Connectionless Network Services (CLNS):

Note: CLNS is available only in packet-based mode.

  • End System-to-Intermediate System (ES-IS) protocol
  • IS-IS extensions
  • BGP extensions
  • Static routes

Multiprotocol Label Switching (MPLS):

Note: MPLS is available only in packet-based mode.

  • Layer 2 and Layer 3 virtual private networks (VPNs)
  • VPN routing and forwarding (VRF) table labels
  • Traffic engineering protocols such as Label Distribution Protocol (LDP) and Resource Reservation Protocol (RSVP)

Note: Security features cannot be configured when MPLS/IPv6 is used.


  • Internet Group Management Protocol (IGMP)
  • Protocol Independent Multicast (PIM)
  • Distance Vector Multicast Routing Protocol (DVMRP)
  • Single-source multicast

Internet Protocols


IPv6 routing and forwarding

IP Address Management

Static addresses

Dynamic Host Configuration Protocol (DHCP)



  • Media access control (MAC) encapsulation
  • 802.1p tagging
  • Point-to-Point Protocol over Ethernet (PPPoE)
  • Circuit cross-connect (CCC)
  • Translational cross-connect (TCC)

Synchronous Point-to-Point Protocol (PPP)

Frame Relay

High-level Data Link Control (HDLC)

802.1Q filtering and forwarding

Multilink Frame Relay (MFR)

Multilink PPP


Common Criteria

Network attack detection

Denial-of-service (DoS) and distributed denial-of-service (DDoS) protection

Generic routing encapsulation (GRE), IP-over-IP, and IP Security (IPsec) tunnels

Advanced Encryption Standard (AES) 128-bit, 192-bit, and 256-bit

56-bit Data Encryption Standard (DES) and 168-bit 3DES encryption

MD5 and Secure Hash Algorithm (SHA-1) authentication

Stateful firewall packet filters

Network Address Translation (NAT)

Unified Threat Management (UTM)

Note: Separate license is required for UTM.

Intrusion Detection and Prevention (IDP)

  • Separate license is required for IDP.
  • IDP HA is not supported in this release.

Chassis Clustering

Chassis clustering is supported on the device. Chassis cluster control and chassis cluster data are supported over a single physical interface, thereby minimizing the number of chassis cluster interfaces required on the device. One of the ports on the front panel of the base system is used as the chassis cluster port.


System Management

J-Web browser interface—for services gateway configuration and management

JUNOScript XML application programming interface (API)

JUNOS command-line interface (CLI)—for services gateway configuration and management through the console, Telnet, SSH, or J-Web CLI terminal

Simple Network Management Protocol version 1 (SNMPv1) and SNMPv2

Network and Security Manager (NSM)

Traffic Analysis

J-Flow flow monitoring and accounting

Packet capture (PCAP)

Real-time performance monitoring (RPM)

Activity Logging and Monitoring

System log

J-Web event viewer



  • Access switching provided by onboard Gigabit Ethernet ports
  • VLANs
  • GVRP
  • LACP
  • 802.1x (Port based network authentication)


Supports the following external administrator databases:



Configuration rollback

Button-operated configuration rescue (CONFIG)

Confirmation of configuration changes

Software upgrades

Supports the following features for automating network operations and troubleshooting:

  • Commit scripts
  • Operation scripts
  • Event policies


Updated: 2009-04-27