Solution Benefits
This document provides comprehensive guidance on the benefits of implementing a secure data center design by integrating security into a modern three‑stage fabric using EVPN‑VXLAN. For the purposes of this JVDE, the Juniper SRX4600 referenced in this design is a next‑generation firewall platform engineered to deliver high‑performance security within data center and cloud‑enabled environments. The 3-Stage Fabric with security integrated is designed to meet the needs of most of Juniper’s customers. Advanced JVDE testing by Juniper combined with widespread adoption simplifies troubleshooting and shortens the support cycle, leading to a secure and stable data center fabric, reducing operational costs.
The data center connected Security JVD is an extension to 3-Stage Data Center Design with Juniper Apstra (JVD). Like all Juniper data centre JVDs, it is based on best practices as determined by Juniper’s subject matter experts, and Juniper support teams have extensive training and resources necessary to support networks based on JVDs.
Juniper SRX Series Firewall Integration with EVPN VXLAN Fabric
The integration of Ethernet VPN (EVPN) with Virtual Extensible LAN (VXLAN) on Juniper SRX Series Firewall enables secure, scalable multi-tenant data center interconnect (DCI) and segmentation. By combining the flexibility of VXLAN overlays with EVPN’s control plane, organizations can extend Layer 2 and Layer 3 networks across geographically distributed locations while maintaining high levels of visibility and security.
With Juniper SRX Native EVPN VXLAN Type 5 integration, SRX can secure EVPN VXLAN fabrics while significantly reducing operational overhead. SRX can inspect the traffic with advanced security services such as, IDP, App Secure, and Content Security for both North-South and East-West traffic. For high-availability, the SRX4600 device is configured in MNHA cluster. Since SRX decapsulates the VXLAN traffic, all the security features can be applied to the traffic.
- Unified policy
- Application Security:
- Application Identification
- Application Based Routing
- Content Security
- Web Filtering
- Antivirus
- Content Filtering
- Anti-Spam
- IDP
- SSL Inspection
- Advance Threat Prevention
- Security intelligence
- Advance Anti-malware
- Adaptive Threat Profiling
- DNS Security
- Encrypted Traffic Insights
- User/Device Authentication
The SRX4600 can inspect North-South and east-west traffic as described in the Use Case and Reference Architecture.