Next-Generation Firewall (NGFW) Model
You can deploy a standalone next-generation firewall (NGFW) device at remote branch spoke sites. NGFW deployment provides remote network security through the use of SRX Series devices as customer-premises equipment (CPE) at a spoke site. This solution offers managed security and LAN visibility to a single location without providing CSO-managed site-to-site connectivity or VNFs, like the Contrail SD-WAN solution provides. Figure 1 shows a simplified NGFW deployment topology.