NFX Series Network Services Platform

Download Datasheet

Product Overview

The NFX Series Network Services Platform delivers a flexible, secure, on-demand network service experience to enterprise organizations. An integral part of Juniper’s fully automated software-defined WAN (SD-WAN), secure router, and next-gen firewall solutions, this high-performance universal CPE platform delivers dynamic SD-WAN functionality with Zero Touch Provisioning (ZTP), next-generation network security, and a portfolio of managed services.

The NFX Series supports multiple Juniper and third-party VNFs on a single device, enabling enterprise customers to accelerate application deployment across geographical locations with a single, automated, highly scalable solution.

Product Description

The Juniper Networks® NFX Series Network Services Platform includes the NFX150, NFX250, and NFX350, offering secure, standards-compliant, redundant customer premises devices that simplify the creation and delivery of network services. This enables service providers to deliver innovative managed services with agility and scale, while allowing enterprises to automate and accelerate branch network connectivity.

More than ever, enterprises rely on the Internet to support their business operations. This increasing dependence on the Internet to access geographically distributed data centers and the multitude of mission-critical cloud-based applications has made branch offices difficult to manage, maintain, and upgrade. Rapid business expansion, both local and international, also creates new challenges for branch office deployment and connectivity. Enterprises require a solution that can create branches on demand, accelerate service deployment, and instantly apply business updates and security policies consistently across a diverse and growing number of business applications and branch locations.

While traditional customer premises equipment (CPE) devices have served the market well for years, many of these devices are closed, Layer 2 purpose-built platforms that do not provide the flexibility, agility, reliability, or scalability required to support a flexible cloud deployment. As a result, these devices often inhibit innovation and complicate or, even worse, restrict the ability to automate configuration and provisioning management.

The NFX Series highly scalable, open, and secure customer premises devices work with Juniper Contrail® Service Orchestration to deliver fully automated SD-WAN, secure router, and Cloud CPE solutions. Whether you are an enterprise business or a service provider, this automated, software-driven solution dynamically provisions new services, enabled by Juniper or third-party virtualized network functions (VNFs), on demand, resulting in near instantaneous service delivery. Its Zero Touch Provisioning (ZTP) capability greatly simplifies branch network connectivity for initial deployment and ongoing management. Subsequent service updates and policy changes are consistently and dynamically inserted into the existing device, resulting in operational efficiency for service providers and enterprise customers alike by limiting or even eliminating service interruptions and business disruptions.

The NFX Series empowers service providers to improve overall operational efficiency and service agility. It delivers a platform to the enterprise that can support multiple managed services, such as SD-WAN, managed security, managed Wi-Fi, and managed WAN acceleration, which can all be delivered and managed from the cloud. Fully integrated with the Juniper Networks SRX Series Services Gateways, which are high-performance next-generation firewalls (NGFWs), the NFX Series devices can be deployed as secure router platforms, ensuring the security of the platform itself and the services it delivers. Built with industry-standard interfaces, the NFX Series can also be used with third-party management and orchestration solutions. Additionally, the NFX Series supports multiple connectivity options such as broadband Internet, 4G/LTE, traditional MPLS, ADSL2/VDSL2, and more.

As service providers look to evolve their service portfolios, the NFX Series can evolve with them, transitioning from a virtual network services platform to an application services platform, supporting the delivery of a wide array of application-based network services, such as market data caching, Internet of Things (IoT) gateway, and edge computing.

The NFX150 Network Services Platform delivers versatility, agility, and scale to enterprise organizations and service providers. Its two form factors, compact (desktop) and rack-mount, integrated SRX Series NGFW, and 4G/LTE interface options, make it a great choice for secure SD-WAN, secure router, and managed security use cases.

The NFX250 Network Services Platform delivers capacity, performance, and scale to larger enterprise organizations and service providers who are looking to run multiple services on one platform. The NFX250 family provides greater VNF capacity and is integrated with Juniper Networks vSRX Virtual Firewall for the secure delivery of SD-WAN, secure router, and a broad portfolio of managed services.

The NFX350 offers up to 7.5Gbps IPsec performance for higher SD-WAN scale and performance, while redundant power supplies provide greater platform resiliency. The NFX350 includes support for high network connectivity and WAN interfaces for LTE, DSL, and SFP, as well as for multiple Juniper and third-party VNFs, enabling customers to accelerate application deployment in an automated and scalable fashion.

Architecture and Key Components

The NFX Series Network Services Platform leverages IP and virtualization technologies as the cornerstones of automated, on-demand branch creation and rapid service delivery solutions. Based on field-proven Juniper technology, including open architectures and the Juniper Networks Junos® operating system, the NFX Series delivers high performance and scalability for routing, switching, and security applications. The NFX Series devices are a key component of the Juniper Contrail SD-WAN solution, which also include the following products and technologies:

  • SD-WAN functionality: The NFX Series efficiently utilizes links across the enterprise WAN, blending traditional MPLS with other connectivity options such as broadband Internet, 4G, LTE, ADSL2/VDSL2, and more. Policy and application-based forwarding capabilities enforce business rules set by the enterprise to steer application traffic towards a preferred path.
  • Secure router (integrated security): The NFX Series provides the same high-performance NGFW capabilities as the Juniper Networks SRX Series Services Gateways, providing next-generation security, IPsec connectivity, application visibility and control to improve the user and application experience. This functionality is a component of the NFX150/250/350 platforms.
  • Contrail Service Orchestration: Juniper Contrail Service Orchestration is a comprehensive management and orchestration solution that delivers VNFs to the NFX Series platforms. It works with the NFX Series to deliver Juniper Contrail SD-WAN, a comprehensive SD-WAN solution for enterprises and service providers. A simple GUI customer portal offers service providers the flexibility to select and build customized services from a catalog, or work with third-party VNF suppliers to build a catalog of their own. Contrail Service Orchestration automates service activation and provisions newly requested services instantaneously under an open NFV environment.
  • Virtualized network functions: The NFX Series is capable of hosting and chaining multiple network functions on a single platform. It supports multiple VNFs, including the vSRX Virtual Firewall, the industry’s most efficient and full-function virtualized security appliance1.
  • Wireless support: NFX150 and NFX350 models support wireless 4G/LTE connectivity, enabling enterprises and service providers to activate the platform in new locations quickly and seamlessly. In new deployments, it can provide network connectivity before other network connection services become available. The wireless network connection can be the primary network connection or one of multiple transport paths.
  • Cloud CPE: The NFX Series platforms are universal CPE platforms, built for the delivery of virtual managed services. When used with the Juniper Cloud CPE solution, service providers can use the graphic service design and management tools to create new services as quickly as business requirements emerge. The NFX Series supports a variety of flexible deployments; a distributed services deployment model ensures high availability, performance, and compliance, while a hybrid model provides versatility and cost efficiency for branch connectivity. These flexible deployment models provide freedom of choice, helping enterprise customers with ever-growing business requirements and branch expansions.
  • Open framework: The NFX Series is based on an open framework providing the same service consistency and operational model found in the telco cloud. The open framework supports industry standards, protocols, and seamless API integration.

1SRX Series next-generation firewall software is fully integrated with the NFX Series product family. The vSRX software runs on the NFX250 platform as a VNF, while the SRX Series software is fully integrated into the NFX150

Features and Benefits

VNF Flexibility

Unlike traditional CPE devices that inhibit agility, the NFX Series is highly scalable, supporting multiple concurrent VNFs on a single device. This substantially reduces upfront CapEx and software costs, establishing a flexible consumption model for on-demand network services from the cloud. The NFX Series features Open vSwitch, an open-source network automation and switching framework that intelligently manages service chaining. Open vSwitch effectively optimizes data traffic flow within the NFX Series platforms, providing consistent VNF service functions and improving performance to minimize service interruptions.

Security and Reliability

The NFX Series offers a complete suite of NGFW, unified threat management (UTM), and threat intelligence services. These consist of intrusion prevention system (IPS), application security (AppSecure), user role-based firewall controls, on-box and cloud-based antivirus and zero-day detection, antispam, and enhanced Web filtering, protecting your network from the latest content-borne threats, exploits, and malware. Security Intelligence (SecIntel) provides threat intelligence and offers adaptive threat protection against command and control (C&C) related botnets and policy enforcement based on GeoIP and attacker fingerprinting technology (the latter providing Web application protection)—all based on Juniper-provided feeds. Customers may also leverage their own custom and third-party feeds to defend against advanced malware and other threats.

Additionally, the NFX Series incorporates many advanced security features. The Secure Boot feature ensures that only an authentic, unmodified Junos OS can launch at boot time, safeguarding system integrity from the factory to the branch site. The embedded Trusted Platform Module (TPM) ensures platform integrity and provides entropy for cryptographic operations. This functionality is a standard component of the NFX150, NFX250, and NFX350 platforms.

High Availability

The NFX Series high availability (HA) redundancy features provide both enterprises and service providers the peace of mind that comes from knowing their networks will scale without affecting performance or reliability. With link redundancy, the NFX Series can address many common causes of system failures, such as a physical port going bad or someone inadvertently disconnecting a cable, to ensure that a connection is available without having to fail over the entire system. When NFX Series platforms are configured in a dual CPE cluster as an active/active high-availability pair, their traffic and configuration information, including routing and FIB tables, are mirrored automatically to provide active firewall and VPN session maintenance in case of a failure. The NFX Series platforms synchronize both configuration and runtime information. As a result, during failover, synchronization of the following information is shared: connection/session state and flow information, IPsec security associations, Network Address Translation (NAT) traffic, address book information, configuration changes, and more. The NFX150 and NFX250 offer high availability on link, CPE, and/or vSRX VNF failovers.

Zero Touch Provisioning

When bringing up a new network device in a remote office or branch, it can be costly to dispatch resources to provision equipment. With Zero Touch Provisioning (ZTP), all new devices connected to the ZTP environment can function without any manual CLI or GUI intervention. The network device simply needs to be connected and turned on. This is useful when technical staff is limited or unavailable at customer premises locations.

The ZTP process is simple. First, the service provider registers the NFX Series platform via the service activation portal, guaranteeing their customer a seamless activation experience. Once the platform is registered, it is ready for customer delivery and self-activation. Upon receiving the device, the customer simply needs to apply power and connect it to the Internet; the NFX Series platform will then securely boot its software, self-upgrade (if necessary), download its customer-specific configuration, and self-provision all services through a secure connection with Contrail Service Orchestration. In a matter of minutes the device is fully activated, services are enabled, and the customer is ready for business.

Cost Efficiencies

The NFX Series improves the overall cost efficiency of the enterprise WAN by supporting SD-WAN and a broad portfolio of managed services as a component of the Juniper Cloud CPE solution. CapEx efficiency is enhanced where a single and scalable NFX Series platform replaces multiple on-premises devices. OpEx efficiency is achieved through automation, which simplifies operations and eliminates the extensive manual processes required by traditional CPE devices. Cost efficiencies help enterprise customers achieve operational agility and boost profitability.

Agility

Enterprise business requirements are always evolving, reflecting constantly changing market dynamics and seasonality. The NFX Series devices let enterprise customers select and automatically implement new services and applications from an extensive service catalog in real time, fostering collaboration across branch sites to improve overall productivity.

Table 1. NFX Series Features and Benefits
Features Benefits
2Available on the NFX250 only
SD-WAN functionality effectively allocates workloads across the enterprise WAN. Efficient utilization of links across the enterprise WAN leverage policy-based routing, blending traditional MPLS with other connectivity options such as broadband Internet, 4G, LTE, ADSL2/VDSL2, and more.
The NFX Series provides the same high-performance NGFW security services found in the physical SRX Series Services Gateways. The SRX Series next-generation firewall software comes fully integrated with the NFX Series platforms. Use the integrated vSRX/SRX Series software to secure the WAN and the LAN, and to deliver-value added managed security services.
Application visibility and control; Advanced Threat Prevention. Detects more than 3500 applications, provides controls, and prioritizes traffic based on application and users. Offers real-time updates to IPS signatures and protects against exploits while offering an open threat intelligence platform that integrates with third-party feeds. Industry-leading antivirus and URL filtering.
Seamless integration with Contrail Service Orchestration ensures automated management and a consistent service life-cycle experience. Service chaining and delivery can be automated on demand, increasing revenue-generating service delivery opportunities.
Network Service Activator enables fast device discovery and provisioning. Automated configuration eliminates complex device setup and delivers a plug-and-play experience.
Wire-speed performance ensures 1GbE and 10GbE rates. High performance simplifies network topologies and operations.
Data Path Development Kit (DPDK) and Single Root I/O Virtualization (SR-IOV) harness high performance from the Intel x86 processor.2 DPDK enables fast packet processing of networking applications by providing a framework for Intel x86 processors. SR-IOV allows VNFs to bypass the hypervisor to directly access resources on the CPU network interface, significantly boosting I/O performance.

Specifications

NFX150

Specification NFX150-C-S1 NFX150-C-S1-AE/AA NFX150-C-S1E-AE/AA NFX150-S1 NFX150-S1E
* Raw capacity; actual capacity will be lower due to overprovisioning.
**The NFX150-S1 and NFX150-S1E platforms provide an expansion slot for additional interface flexibility. The optional Network Interface Module provides additional 100/1000 Mbps Ethernet interfaces, while the LTE Module provides a 4G/LTE interface. The MC7430 wireless modem supports LTE bands for Asia Pacific, Australia, and New Zealand. The MC7455 wireless modem supports LTE bands for North America and Europe.
***ADSL2/VDSL2 interfaces are provided by a small form-factor pluggable transceiver which can be used in any SFP port on the NFX150.
Dimensions (H x W x D) 1.72 x 10.63 x 10.43 in
(4.37 x 27.0 x 26.5 cm)
1.72 x 10.63 x 10.43 in
(4.37 x 27.0 x 26.5 cm)
1.72 x 10.63 x 10.43 in
(4.37 x 27.0 x 26.5 cm)
1.72 x 17.36 x 12 in
(4.37 x 44.094x 30.48 cm)
1.72 x 17.36 x 12 in
(4.37 x 44.094x 30.48 cm)
Rack units (U) 1 U 1 U 1 U 1 U 1 U
Footprint Desktop Desktop Desktop Rack mount Rack mount
Weight  8.81 lb (4.0 kg) 8.81 lb (4.0 kg) 8.81 lb (4.0 kg) 12.99 lb (5.9 kg) 12.99 lb (5.9 kg)
Airflow Front-to-back (AFO)
forced cooling
Front-to-back (AFO)
forced cooling
Front-to-back (AFO)
forced cooling
Front-to-back (AFO)
forced cooling
Front-to-back (AFO)
forced cooling
Acoustics 35 dBA 35 dBA 35 dBA 40 dBA 40 dBA
Power 75 W AC-DC Power Adapter 75 W AC-DC Power Adapter 75 W AC-DC Power Adapter 150W AC-DC open frame power 150W AC-DC open frame power
CPU Intel 4 Core ATOM Intel 4 Core ATOM Intel 4 Core ATOM Intel 8 Core ATOM Intel 8 Core ATOM
Memory 8 GB DDR4 8 GB DDR4 16 GB DDR4 16 GB DDR4 32 GB DDR4
Storage 100 GB* SSD 100 GB* SSD 100 GB* SSD 200 GB* SSD 200 GB* SSD
Software Wind River Linux 8 Wind River Linux 8 Wind River Linux 8 Wind River Linux 8 Wind River Linux 8
Integrated network interfaces
  • 4 x 10/100/
    1000BASE-T RJ-45 LAN ports
  • 2 x 1GbE/10GbE
    SFP+ WAN ports
  • 1 x 10/100/
    1000BASE-T RJ-45 management port
  • 4 x 10/100/
    1000BASE-T RJ-45 LAN ports
  • 2 x 1GbE/10GbE
    SFP+ WAN ports
  • 1 x 10/100/
    1000BASE-T RJ-45 management
  • 4 x 10/100/
    1000BASE-T RJ-45 LAN ports
  • 2 x 1GbE/10GbE
    SFP+ WAN ports
  • 1 x 10/100/
    1000BASE-T RJ-45 management port
  • 4 x 10/100/
    1000BASE-T RJ-45 LAN ports
  • 2 x 1GbE/10GbE
    SFP+ WAN ports
  • 1 x 10/100/
    1000BASE-T RJ-45 management port
  • 4 x 10/100/
    1000BASE-T RJ-45 LAN ports
  • 2 x 1GbE/10GbE
    SFP+ WAN ports
  • 1 x 10/100/
    1000BASE-T RJ-45 management port
Network interface module** Not Available Not Available Not Available
  • 6 x 100BASE-T/ 1000BASE-T
  • 2 x 1000BASE-X SFP module
  • 6 x 100BASE-T/ 1000BASE-T
  • 2 x 1000BASE-X SFP module
Managed Secure Router 200 Mbps 400 Mbps 500 Mbps 500 Mbps 800 Mbps
Managed Security 200 Mbps 400 Mbps 500 Mbps 500 Mbps 800 Mbps
IPsec 80 Mbps 100 Mbps 150 Mbps 150 Mbps 300 Mbps
ADSL2/VDSL2 Interface*** ADSL2/ADSL2+/VDSL SFP ADSL2/ADSL2+/VDSL SFP ADSL2/ADSL2+/VDSL SFP ADSL2/ADSL2+/VDSL SFP ADSL2/ADSL2+/VDSL SFP
Out-of-band interfaces
  • RJ-45 console port
  • Mini USB console port
  • USB 3.0 port
  • RJ-45 console port
  • Mini USB console port
  • USB 3.0 port
  • RJ-45 console port
  • Mini USB console port
  • USB 3.0 port
  • RJ-45 console port
  • Mini USB console port
  • USB 3.0 port
  • RJ-45 console port
  • Mini USB console port
  • USB 3.0 port
Maximum number of VNFs 1-2 1-2 1-2 2-3 2-3
Wireless/LTE Module option No Integrated Integrated LTE Module** LTE Module**
LTE antenna support No Integrated Integrated LTE Module** LTE Module**
LTE chipset Not available

Sierra Wireless Modem**

MC7430

MC7455

Sierra Wireless Modem**

MC7430

MC7455
LTE Module** LTE Module**
LTE bands/regions supported Not available

LTE modem with support for 1-5, 7-8, 12-13, 30, 25-26, 29-30, 41 LTE bands (for North America and Europe)

LTE modem with support for 1, 3, 5, 7-8, 18-19, 21, 28, 38-41 LTE bands (for Asia Pacific, Australia, and New Zealand)

LTE modem with support for 1-5, 7-8, 12-13, 30, 25-26, 29-30, 41 LTE bands (for North America and Europe)

LTE modem with support for 1, 3, 5, 7-8, 18-19, 21, 28, 38-41 LTE bands (for Asia Pacific, Australia, and New Zealand)

LTE modem with support for 1-5, 7-8, 12-13, 30, 25-26, 29-30, 41 LTE bands (for North America and Europe)

LTE modem with support for 1, 3, 5, 7-8, 18-19, 21, 28, 38-41 LTE bands (for Asia Pacific, Australia, and New Zealand)

LTE modem with support for 1-5, 7-8, 12-13, 30, 25-26, 29-30, 41 LTE bands (for North America and Europe)

LTE modem with support for 1, 3, 5, 7-8, 18-19, 21, 28, 38-41 LTE bands (for Asia Pacific, Australia, and New Zealand)

NFX250

Specification NFX250-S1 NFX250-S1E NFX250-S2
* Raw capacity; actual capacity will be lower due to overprovisioning.
** ADSL2/VDSL2 interfaces are provided by a small form-factor pluggable transceiver which can be used in any SFP port on the NFX250.
*** Maximum throughput mode

Dimensions

(H x W x D)

1.72 x 17.36 x 12 in.

(4.37 x 44.09 x 30.48 cm)

1.72 x 17.36 x 12 in.

(4.37 x 44.09 x 30.48 cm)

1.72 x 17.36 x 12 in.

(4.37 x 44.09 x 30.48 cm)
Rack units (U) 1 U 1 U 1 U
Weight 9.48 lb (4.3 kg) 9.48 lb (4.3 kg) 9.48 lb (4.3 kg)
Airflow Front-to-back (AFO) forced cooling Front-to-back (AFO) forced cooling Front-to-back (AFO) forced cooling
Acoustics 50 dBA 50 dBA 50 dBA
Power Fixed PSU 100-240 VAC Fixed PSU 100-240 VAC Fixed PSU 100-240 VAC
CPU Intel 6 Core Xeon Intel 6 Core Xeon D Intel 6 Core Xeon D
Memory 16 GB DDR4 16 GB DDR4 32 GB DDR4
Storage 100 GB* SSD 200 GB* SSD 400 GB* SSD
Software Wind River Linux 7 Wind River Linux 7 Wind River Linux 7
Network interfaces
  • 8 x 10/100/1000BASE-T RJ-45 LAN ports
  • 2 x 10/100/1000BASE-T RJ-45 LAN/WAN ports
  • 2 x 100/1000BASE-X small form-factor pluggable transceiver (SFP) WAN ports
  • 2 x 1GbE/10GbE SFP+ WAN ports
  • 1 x 10/100/1000BASE-T RJ-45 management port
  • ADSL2/VDSL2 SFP**
  • 8 x 10/100/1000BASE-T RJ-45 LAN ports
  • 2 x 10/100/1000BASE-T RJ-45 LAN/WAN ports
  • 2 x 100/1000BASE-X small form-factor pluggable transceiver (SFP) WAN ports
  • 2 x 1GbE/10GbE SFP+ WAN ports
  • 1 x 10/100/1000BASE-T RJ-45 management port
  • ADSL2/VDSL2 SFP**
  • 8 x 10/100/1000BASE-T RJ-45 LAN ports
  • 2 x 10/100/1000BASE-T RJ-45 LAN/WAN ports
  • 2 x 100/1000BASE-X SFP WAN ports
  • 2 x 1GbE/10GbE SFP+ WAN ports
  • 1 x 10/100/1000BASE-T RJ-45 management port
  • ADSL2/VDSL2 SFP**
Managed Secure Router*** 2 Gbps 3 Gbps 4 Gbps
Managed Security*** 2 Gbps 3 Gbps 4 Gbps
IPsec*** 500 Mbps 750 Mbps 1.2 Gbps
Out-of-band interfaces
  • RJ-45 console port
  • Mini USB console port
  • USB 2.0 port
  • RJ-45 console port
  • Mini USB console port
  • USB 2.0 port
  • RJ-45 console port
  • Mini USB console port
  • USB 2.0 port
Maximum number of VNFs 6 6 8

NFX350

Specification NFX350-S1 NFX350-S2 NFX350-S3
* Raw capacity; actual capacity will be lower due to overprovisioning.
** The NFX150-S1 and NFX150-S1E platforms provide an expansion slot for additional interface flexibility. The optional Network Interface Module provides additional 100/1000 Mbps Ethernet interfaces, while the LTE Module provides a 4G/LTE interface. The MC7430 wireless modem supports LTE bands for Asia Pacific, Australia, and New Zealand. The MC7455 wireless modem supports LTE bands for North America and Europe.
*** ADSL2/VDSL2 interfaces are provided by a small form-factor pluggable transceiver which can be used in any SFP port on the NFX150.
Dimensions (H x W x D) 1.72 x 17.32 x 20.86 in (4.37 x 44.0 x 53.0 cm) 1.72 x 17.32 x 20.86 in (4.37 x 44.0 x 53.0 cm) 1.72 x 17.32 x 20.86 in (4.37 x 44.0 x 53.0 cm))
Rack units (U) 1 U 1 U 1 U
Footprint Rack mount Rack mount Rack mount
Weight 18.5 lb (8.4 kg) 18.6 lb (8.45 kg) 18.6 lb (8.45 kg)
Airflow Front-to-back (AFO) forced cooling Front-to-back (AFO) forced cooling Front-to-back (AFO) forced cooling
Acoustics  61 dBA 61 dBA  61 dBA
Power

650W hot-swappable AC-DC/DC-DC

650W hot-swappable AC-DC/DC-DC

650W hot-swappable AC-DC/DC-DC

CPU Intel 8 Core SKYLAKE Intel 12 Core SKYLAKE Intel 16 Core SKYLAKE
Memory 32 GB DDR4 64 GB DDR4 128 GB DDR4
Storage 100 GB* SSD 100 GB* SSD 100 GB* SSD

Software

Wind River Linux 8 Wind River Linux 8 Wind River Linux 8
Integrated network interfaces
  • 8 x 10/100/
    1000BASE-T RJ-45 LAN or WAN ports
  • 8 x 1GbE/10GbE
    SFP+ LAN or WAN ports
  • 1 x 10/100/
    1000BASE-T RJ-45 management port
  • 8 x 10/100/
    1000BASE-T RJ-45 LAN or WAN ports
  • 8 x 1GbE/10GbE
    SFP+ LAN or WAN ports
  • 1 x 10/100/
    1000BASE-T RJ-45 management port
  • 8 x 10/100/
    1000BASE-T RJ-45 LAN or WAN ports
  • 8 x 1GbE/10GbE
    SFP+ LAN or WAN ports
  • 1 x 10/100/
    1000BASE-T RJ-45 management port
Network interface module** Not Available Not Available Not Available
Managed Secure Router 12 Gbps 20 Gbps 30 Gbps
Managed Security 12 Gbps 20 Gbps 30 Gbps
IPsec 2.5 Gbps 5 Gbps 7.5 Gbps
ADSL2/VDSL2 Interface*** ADSL2/ADSL2+/VDSL SFP ADSL2/ADSL2+/VDSL SFP ADSL2/ADSL2+/VDSL SFP
Out-of-band interfaces
  • RJ-45 console port
  • Mini USB console port
  • 2 x USB 3.0 port
  • RJ-45 console port
  • Mini USB console port
  • 2 x USB 3.0 port
  • RJ-45 console port
  • Mini USB console port
  • 2 x USB 3.0 port
Maximum number of VNFs 8 10 12
Wireless/LTE Module option LTE Module LTE Module LTE Module
LTE antenna support LTE Module LTE Module LTE Module
LTE chipset

Sierra Wireless Modem**

MC7430

MC7455

Sierra Wireless Modem**

MC7430

MC7455

Sierra Wireless Modem**

MC7430

MC7455
LTE bands/regions supported

LTE modem with support for 1-5, 7-8, 12-13, 30, 25-26, 29-30, 41 LTE bands (for North America and Europe)

LTE modem with support for 1, 3, 5, 7-8, 18-19, 21, 28, 38-41 LTE bands (for Asia Pacific, Australia, and New Zealand)

LTE modem with support for 1-5, 7-8, 12-13, 30, 25-26, 29-30, 41 LTE bands (for North America and Europe)

LTE modem with support for 1, 3, 5, 7-8, 18-19, 21, 28, 38-41 LTE bands (for Asia Pacific, Australia, and New Zealand)

LTE modem with support for 1-5, 7-8, 12-13, 30, 25-26, 29-30, 41 LTE bands (for North America and Europe)

LTE modem with support for 1, 3, 5, 7-8, 18-19, 21, 28, 38-41 LTE bands (for Asia Pacific, Australia, and New Zealand)

Packet Switching Capacities

  • Packet Forwarding Engine (PFE) capacity: 64 Gbps
  • VNF capacity: 20 Gbps full-duplex path to CPU for VNF traffic
  • Throughput via VNFs will vary depending on network function and acceleration technologies supported

Layer 2 Switching

  • Maximum media access control (MAC) addresses in hardware: up to 16,000
  • Jumbo frames: 9216 bytes
  • Number of VLANs: up to 1024 (VLAN IDs: 4096)
  • Port-based VLAN
  • MAC-based VLAN
  • Voice VLAN
  • Private VLAN (PVLAN)
  • Number of MST instances supported: 64
  • Compatible with Per-VLAN Spanning Tree Plus (PVST+)
  • Routed VLAN interface (RVI)
  • Link Layer Discovery Protocol–Media Endpoint Discovery (LLDP-MED) with VoIP integration

Routing Protocols

  • IPv4, IPv6, ISO, Connectionless Network Service (CLNS)
  • Static routes
  • RIP v1/v2
  • OSPF/OSPF v3
  • BGP with Route Reflector
  • Multicast: Internet Group Management Protocol (IGMP) v1/v2, Protocol Independent Multicast (PIM) sparse mode (SM)/dense mode (DM)/source-specific multicast (SSM), Session Description Protocol (SDP), Distance Vector Multicast Routing Protocol (DVMRP), Multicast Source Discovery Protocol (MSDP), Reverse Path Forwarding (RPF)
  • Encapsulation: VLAN, Point-to-Point Protocol (PPP), Frame Relay, High-Level Data Link Control (HDLC), serial, Multilink Point-to-Point Protocol (MLPPP), Multilink Frame Relay (MLFR), and Point-to-Point Protocol over Ethernet (PPPoE)
  • Virtual routers
  • Policy-based routing, source-based routing
  • Equal-Cost Multipath (ECMP)

VPN Features

  • Tunnels: Generic routing encapsulation (GRE)3, IP-IP3, IPsec
  • Site-site IPsec VPN
  • IPsec crypto algorithms: Data Encryption Standard (DES), triple DES (3DES), Advanced Encryption Standard (AES-256), AES-GCM
  • IPsec authentication algorithms: MD5, SHA-1, SHA-128, SHA-256
  • Perfect forward secrecy, anti-reply
  • IPv4 and IPv6 IPsec VPN
  • Multiproxy ID for site-site VPN
  • Internet Key Exchange (IKEv1, IKEv2), NAT-T
  • Virtual router and quality-of-service (QoS) aware
  • Standard-based dead peer detection (DPD) support
  • VPN monitoring

Advanced Routing Services

  • MPLS (RSVP, LDP)
  • Circuit cross-connect (CCC), translational cross-connect (TCC)
  • L2/L3 MPLS VPN
  • Virtual private LAN service (VPLS), next-generation multicast VPN (NG-MVPN)
  • MPLS traffic engineering and MPLS fast reroute

Access Control Lists (Junos OS Firewall Filters)

  • Port-based ACL (PACL)—ingress
  • VLAN-based ACL (VACL)—ingress and egress
  • Router-based ACL (RACL)—ingress and egress
  • ACL entries (ACE) in hardware per system: 1500
  • ACL counter for denied packets
  • ACL counter for permitted packets
  • Ability to add/remove/change ACL entries in middle of list (ACL editing)
  • L2-L4 ACL

Security

  • MAC limiting
  • Allowed MAC addresses—configurable per port
  • Sticky MAC (persistent MAC address learning)
  • Dynamic ARP inspection (DAI)
  • Proxy ARP
  • Static ARP support
  • Dynamic Host Configuration Protocol (DHCP) snooping

Application Security Services3

  • Application visibility and control
  • Application-based firewall
  • Application QoS
  • Application-based advanced policy-based routing
  • Application quality of experience (AppQoE)

This data is for NFX250 only
3 Available as part of Junos Software Enhanced (JSE) software package or advanced security subscription licenses.

Threat Defense and Intelligence Services4

  • Intrusion prevention
  • Antivirus
  • Antispam
  • Category/reputation-based URL filtering
  • SecIntel to provide threat intelligence
  • Protection from botnets (command and control)
  • Adaptive enforcement based on GeoIP
  • Juniper Cloud Advanced Threat Prevention to detect and block zeroday malware attacks5

4 Offered as advanced security services subscription licenses.
5 Juniper Cloud ATP is supported on the NFX150 platform.

High Availability

  • VRRP
  • Backup link via 3G/4G LTE wireless or other WAN (NFX150)
  • Stateful failover and dual CPE clustering
  • Active/active—L3 mode
  • Active/passive—L3 mode
  • Configuration synchronization
  • Session synchronization firewall and VPN
  • Session failover for routing change
  • Device failure detection, link failure detection
  • IP monitoring with route and interface failover

This data is for NFX250 only

Quality of Service (QoS)

  • Layer 2 QoS
  • Layer 3 QoS
  • Ingress policing: 1 rate 2 color
  • Hardware queues per port: 8
  • Scheduling methods (egress): Strict priority (SP), shaped-deficit weighted round-robin (SDWRR)
  • 802.1p: DiffServ code point (DSCP)/IP precedence trust and marking
  • L2-L4 classification criteria: Interface, MAC address, Ethertype, 802.1p, VLAN, IP address, DSCP/IP precedence
  • TCP/UDP port numbers
  • Congestion avoidance capabilities: Tail drop

Multicast

  • Internet Group Management Protocol (IGMP) snooping entries: 1000
  • IGMP: v1, v2, v3
  • IGMP snooping
  • PIM-SM

Services and Manageability

  • Junos OS CLI
  • Web interface (J-Web)
  • Out-of-band management: Serial, 10/100BASE-T Ethernet
  • ASCII configuration
  • Rescue configuration
  • Configuration rollback
  • Simple Network Management Protocol (SNMP): v1, v2c, v3
  • Remote monitoring (RMON) (RFC 2819) Groups 1, 2, 3, 9
  • Network Time Protocol (NTP)
  • DHCP server
  • DHCP client and DHCP proxy
  • DHCP relay and helper
  • RADIUS authentication
  • TACACS+ authentication
  • SSHv2
  • Secure copy
  • HTTP/HTTPs
  • Domain Name System (DNS) resolver
  • System logging
  • Temperature sensor
  • Configuration backup via FTP/secure copy
  • Interface range

Troubleshooting

  • Debugging: CLI via console, telnet, or SSH
  • Diagnostics: Show and debug command statistics
  • Traffic mirroring (port)
  • Traffic mirroring (VLAN)
  • ACL-based mirroring
  • Mirroring destination ports per system: 1
  • LAG port monitoring
  • Multiple destination ports monitored to 1 mirror (N:1)
  • Maximum number of mirroring sessions: 1
  • Mirroring to remote destination (over L2): 1 destination
  • VLAN
  • IP tools: Extended ping and trace
  • Juniper Networks commit and rollback

Optics6

  • EX-SFP-10GE-USR
  • EX-SFP-10GE-DAC-1M
  • EX-SFP-1GE-SX
  • EX-SFP-1GE-SX-ET
  • EX-SFP-1GE-LX
  • EX-SFP-10GE-SR
  • EX-SFP-10GE-LR
  • EX-SFP-10GE-DAC-3M
  • EX-SFP-10GE-DAC-5M
  • EX-SFP-10GE-ER
  • EX-SFP-10GE-ZR
  • EX-SFP-1GE-LH
  • EX-SFP-1GE-LX40K
  • EX-SFP-GE10KT13R14
  • EX-SFP-GE10KT14R13
  • EX-SFP-GE10KT13R15
  • EX-SFP-GE10KT15R13
  • EX-SFP-GE40KT13R15
  • EX-SFP-GE40KT15R13
  • EX-SFP-GE80KCW1470
  • EX-SFP-GE80KCW1490
  • EX-SFP-GE80KCW1510
  • EX-SFP-GE80KCW1530
  • EX-SFP-GE80KCW1550
  • EX-SFP-GE80KCW1570
  • EX-SFP-GE80KCW1590
  • EX-SFP-GE80KCW1610

6 Copper Ethernet SFP modules are not supported on the NFX150 platforms at this time.

Environmental Ranges NFX150

  • Operating temperature: 32° to 104° F (0° to 40° C)
  • Storage temperature: -40° to 158° F (-40° to 70° C)
  • Operating altitude: Up to 6500 ft. (2000 m)
  • Relative humidity operating: 5 to 90% (noncondensing)
  • Relative humidity nonoperating: 5 to 90% (noncondensing)
  • Seismic: Designed to meet Zone 4 earthquake requirements

Environmental Ranges NFX250

  • Operating temperature: 32° to 122° F (0° to 50° C)
  • Storage temperature: -40° to 158° F (-40° to 70° C)
  • Operating altitude: Up to 10,000 ft. (3048 m)
  • Relative humidity operating: 5 to 90% (noncondensing)
  • Relative humidity nonoperating: 5 to 90% (noncondensing)
  • Seismic: Designed to meet GR-63, Zone 4 earthquake requirements

Safety and Compliance

Safety

  • cNRTL-UL60950-1 (Second Edition)
  • C-UL to CAN/CSA 22.2 No.60950-1 (Second Edition)
  • TUV/GS to EN 60950-1 (Second Edition)
  • CB-IEC60950-1 (Second Edition with all country deviations)
  • EN 60825-1 (Second Edition)

Electromagnetic Compatibility

  • FCC 47CFR Part 15 Class A
  • EN 55022 Class A
  • ICES-003 Class A
  • VCCI Class A
  • AS/NZS CISPR 32 Class A
  • CISPR 22 Class A, CISPR 32 Class A
  • EN 55024
  • EN 300386
  • CE

Environmental Compliance

  • Restriction of Hazardous Substances (ROHS) 6/6
  • ROHS 7a exemption for power supply components acceptable
  • Registration, Evaluation, Authorisation and Restriction of Chemicals (REACH)
  • Waste Electronics and Electrical Equipment (WEEE)

Telco

  • Common Language Equipment Identifier (CLEI) code

Standards Compliance

IEEE Standards

  • IEEE 802.1AB: Link Layer Discovery Protocol (LLDP)
  • IEEE 802.1ag: Connectivity Fault Management (CFM)
  • IEEE 802.1ak: Multiple VLAN Registration Protocol (MVRP)
  • IEEE 802.1D: Spanning Tree Protocol
  • IEEE 802.1p: CoS prioritization
  • IEEE 802.1Q: VLAN tagging
  • IEEE 802.1Q-in-Q: VLAN Stacking
  • IEEE 802.1w: Rapid Spanning Tree Protocol (RSTP)
  • IEEE 802.1s: Multiple Spanning Tree Protocol (MSTP)
  • IEEE 802.1X: Port Access Control
  • IEEE 802.3: 10BASE-T
  • IEEE 802.3u: 100BASE-T
  • IEEE 802.3ab: 1000BASE-T
  • IEEE 802.3z: 1000BASE-X
  • IEEE 802.3x: Pause Frames/Flow Control
  • IEEE 802.3ad: Link Aggregation Control Protocol (LACP)
  • IEEE 802.3ah: Ethernet in the First Mile

Supported RFCs

  • RFC 768 UDP
  • RFC 783 Trivial File Transfer Protocol (TFTP)
  • RFC 791 IP
  • RFC 792 ICMP
  • RFC 793 TCP
  • RFC 826 ARP
  • RFC 894 IP over Ethernet
  • RFC 903 Reverse ARP (RARP)
  • RFC 906 TFTP Bootstrap
  • RFC 951, 1542 BootP
  • RFC 1058 Routing Information Protocol
  • RFC 1112 IGMP v1
  • RFC 1122 Host requirements
  • RFC 1256 IPv4 ICMP Router Discovery (IRDP)
  • RFC 1492 TACACS+
  • RFC 1519 Classless Interdomain Routing (CIDR)
  • RFC 1587 OSPF not-so-stubby area (NSSA) Option
  • RFC 1591 Domain Name System (DNS)
  • RFC 1812 Requirements for IP Version 4 routers
  • RFC 2030 SNTP, Simple Network Time Protocol
  • RFC 2068 HTTP server
  • RFC 2131 BOOTP/DHCP relay agent and dynamic host
  • RFC 2138 RADIUS authentication
  • RFC 2139 RADIUS accounting
  • RFC 2267 Network ingress filtering
  • RFC 2338 Virtual Router Redundancy Protocol (VRRP)
  • RFC 2362 PIM-SM (edge mode)
  • RFC 2453 RIP v2
  • RFC 2474 Definition of the Differentiated Services Field in the IPv4 and IPv6 Headers
  • RFC 2597 Assured Forwarding PHB (per-hop behavior) Group
  • RFC 2598 An Expedited Forwarding PHB
  • RFC 2925 MIB for remote ping, trace
  • RFC 3176 sFlow
  • RFC 3569 SSM
  • RFC 5176 Dynamic Authorization Extensions to RADIUS
  • RFC 5880 Bidirectional Forwarding Detection (BFD)

Supported MIBs

  • RFC 1155 SMI
  • RFC 1157 SNMPv1
  • RFC 1212, RFC 1213, RFC 1215 MIB-II, Ethernet-Like MIB and TRAPs
  • RFC 1901 Introduction to Community-based SNMPv2
  • RFC 2011 SNMPv2 for Internet protocol using SMIv2
  • RFC 2012 SNMPv2 for transmission control protocol using SMIv2
  • RFC 2013 SNMPv2 for user datagram protocol using SMIv2
  • RFC 2233 The Interfaces Group MIB using SMIv2
  • RFC 2287 System Application Packages MIB
  • RFC 2570 Introduction to Version 3 of the Internet-standard Network Management Framework
  • RFC 2571 An Architecture for describing SNMP Management Frameworks (read-only access)
  • RFC 2572 Message Processing and Dispatching for the SNMP (read-only access)
  • RFC 2576 Coexistence between SNMP Version 1, Version 2, and Version 3
  • RFC 2578 SNMP Structure of Management Information MIB
  • RFC 2579 SNMP Textual Conventions for SMIv2
  • RFC 2580 Conformance Statements for SMIv2
  • RFC 2665 Ethernet-like interface MIB
  • RFC 2787 VRRP MIB
  • RFC 2790 Host Resources MIB
  • RFC 2819 RMON MIB
  • RFC 2863 Interface Group MIB
  • RFC 3410 Introduction and Applicability Statements for Internet Standard Management Framework
  • RFC 3411 An architecture for describing SNMP Management Frameworks
  • RFC 3412 Message Processing and Dispatching for the SNMP
  • RFC 3413 Simple Network Management Protocol (SNMP)—(all MIBs supported except the Proxy MIB)
  • RFC 3414 User-based Security Model (USM) for version 3 of SNMPv3
  • RFC 3415 View-based Access Control Model (VACM) for the SNMP
  • RFC 3416 Version 2 of the Protocol Operations for the SNMP
  • RFC 3417 Transport Mappings for the SNMP
  • RFC 3418 Management Information Base (MIB) for the SNMP
  • RFC 4188 Definitions of Managed Objects for Bridges
  • RFC 4318 Definitions of Managed Objects for Bridges with Rapid Spanning Tree Protocol
  • RFC 4363b Q-Bridge VLAN MIB

Juniper Networks Services and Support

Juniper Networks is the leader in performance-enabling services that are designed to accelerate, extend, and optimize your high-performance network. Our services allow you to maximize operational efficiency while reducing costs and minimizing risk, achieving a faster time to value for your network. Juniper Networks ensures operational excellence by optimizing the network to maintain required levels of performance, reliability, and availability. For more details, please visit www.juniper.net/us/en/products-services.

Ordering Information

Product
Number
Description
Note 7: Unlimited bandwidth (BW), perpetual license
NFX150
NFX150-C-S1 NFX150 Desktop with no LTE, 4 10/100/1000BASE-T, 2 1GbE/10GbE SFP+ WAN ports, Intel 4 Core ATOM, 100 GB SSD, 8 GB memory (optics sold separately)
NFX150-C-S1-AE NFX150 Desktop with integrated LTE for North America and Europe, 4 10/100/1000BASE-T ports, 2 1GbE/10GbE SFP+ WAN ports, Intel 4 Core ATOM processor, 100 GB SSD, 8 GB memory (optics sold separately)
NFX150-C-S1-AA NFX150 Desktop with integrated LTE for Asia, Australia, New Zealand, 4 10/100/1000BASE-T ports, 2 1GbE/10GbE SFP+ WAN ports, Intel 4 Core ATOM processor, 100 GB SSD, 8 GB memory (optics sold separately)
NFX150-C-S1E-AE NFX150 Desktop with integrated LTE for North America and Europe, 4 10/100/1000BASE-T ports, 2 1GbE/10GbE SFP+ WAN ports, Intel 4 Core ATOM processor, 100 GB SSD, 16 GB memory (optics sold separately)
NFX150-C-S1E-AA NFX150 Desktop with integrated LTE for Asia, Australia, New Zealand, 4 10/100/1000BASE-T ports, 2 1GbE/10GbE SFP+ WAN ports, Intel 4 Core ATOM processor, 100 GB SSD, 16 GB memory (optics sold separately)
NFX150-S1 NFX150 rack-mount with expansion slot, 4 10/100/1000BASE-T, 2 1GbE/10GbE SFP+ WAN ports, Intel 8 Core ATOM, 200 GB SSD, 16 GB memory (optics sold separately)
NFX150-S1E NFX150 rack-mount with expansion slot, 4 10/100/1000BASE-T, 2 1GbE/10GbE SFP+ WAN ports, Intel 8 Core ATOM, 200 GB SSD, 32 GB memory (optics sold separately)
NFX150-C-STD NFX150-C-S1/S1E Junos security software license for Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), and stateful firewall
NFX150-C-ADV NFX150-C-S1/S1E Junos security software license for Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), stateful firewall, AppFW, AppID, AppTrack, AppRoute, and AppQoE
NFX150-S-STD NFX150-S1/S1E Junos security software license for Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), and stateful firewall
NFX150-S-ADV NFX150-S1/S1E Junos security software license for Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), stateful firewall, AppFW, AppID, AppTrack, AppRoute, and AppQoE
NFX250
NFX250-S1 NFX250, 10 10/100/1000BASE-T ports, 2 100/1000BASE-X SFP ports, 2 10GBASE-X SFP+ ports, 6 core x86 processors, 100 GB SSD, 16 GB memory, Junos Device Manager (Linux container for virtual machine [VM] life cycle management and service activation), Junos Control Plane (VM to handle switching), vSRX NGFW with 60 day trial license (optics sold separately)
NFX250-S1E NFX250, 10 10/100/1000BASE-T ports, 2 100/1000BASE-X SFP ports, 2 10GBASE-X SFP+ ports, 6 core x86 processors, 200 GB SSD, 16 GB memory, Junos Device Manager (Linux container for virtual machine [VM] life cycle management and service activation), Junos Control Plane (VM to handle switching), vSRX NGFW with 60 day trial license (optics sold separately)
NFX250-S2 NFX250, 10 10/100/1000BASE-T ports, 2 100/1000BASE-X SFP ports, 2 10GBASE-X SFP+ ports, 6 core x86 processors, 400 GB SSD, 32 GB memory, Junos Device Manager (Linux container for virtual machine [VM] life cycle management and service activation), Junos Control Plane (VM to handle switching), vSRX NGFW with 60 day trial license (optics sold separately)
NFX250-S-STD7 NFX250 Junos, security software license, Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), stateful firewall
NFX250-S-ADV7 NFX250 Junos, security software license, Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), stateful firewall, AppFW, AppID, AppTrack, AppRoute, and AppQoE
Product
Number
Description
Note 8:  Optional modules are applicable to NFX150-S1 and NFX150-S1E products only. The NFX-LTE-AE and NFX-LTE- AA occupy two expansion slots. The NFX-EM-6T2SFP occupies one expansion slot and cannot be combined with the LTE Modules.
Note 9:  Optional modules are applicable to NFX350-S1, NFX350-S2, NFX350-S3 products only. The NFX-LTE-AE and NFX-LTE-AA occupy two expansion slots and are supported on NFX350.
NFX350
NFX350-S1-AC NFX350-S1, 8-core Skylake Xeon-D, QAT, 32GB RAM, 50GB SSD, 2xM2 slots, Dual AC PS capable, single 450W AC PSU, LTE module (2nd PS and LTE module are optional accessories). Includes Junos standard security software license for Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), and stateful firewall
NFX350-S1-DC NFX350-S1, 8-core Skylake Xeon-D, QAT, 32GB RAM, 50GB SSD, 2xM2 slots, Dual DC PS capable, single 450W DC PSU, LTE module (2nd PS and LTE module are optional accessories). Includes Junos standard security software license for Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), and stateful firewall
NFX350-S2-AC NFX350-S2, 12-core Skylake Xeon-D, QAT, 64GB RAM, 50GB SSD, 2xM2 slots, Dual AC PS capable, single 450W AC PSU, LTE module (2nd PS and LTE module are optional accessories). Includes Junos standard security software license for Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), and stateful firewall
NFX350-S2-DC NFX350-S2, 12-core Skylake Xeon-D, QAT, 64GB RAM, 50GB SSD, 2xM2 slots, Dual DC PS capable, single 450W DC PSU, LTE module (2nd PS and LTE module are optional accessories). Includes Junos standard security software license for Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), and stateful firewall
NFX350-S3-AC NFX350-S3, 16-core Skylake Xeon-D, QAT, 128GB RAM, 50GB SSD, 2xM2 slots, Dual AC PS capable, single 450W AC PSU, LTE module (2nd PS and LTE module are optional accessories). Includes Junos standard security software license for Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), and stateful firewall
NFX350-S3-DC NFX350-S3, 16-core Skylake Xeon-D, QAT, 128GB RAM, 50GB SSD, 2xM2 slots, Dual DC PS capable, single 450W DC PSU, LTE module (2nd PS and LTE module are optional accessories). Includes Junos standard security software license for Layer 2 and Layer 3 services, Network Address Translation (NAT), IP Security (IPsec), and stateful firewall
Optional Modules
NFX-EM-6T2SFP8 6-port 100BASE-T/1000BASE-T + 2-port 1000BASE-X SFP module
NFX-LTE-AE8 LTE modem support for 1-5, 7-8, 12-13, 30, 25-26, 29-30, 41 bands (NA and EU)
NFX-LTE-AA8 LTE modem support for 1, 3, 5, 7-8, 18-19, 21, 28, 38-41 bands (APAC, AU, and NZ)
JNP-SFP-VDSL2 ADS2/VDSL2 Smart WAN SFP module for NFX150 and NFX250
JPSU-650W-AC-AO9 Single 650W AC PSU
JPSU-650W-DC-AFO9 Single 650W DC PSU
JNP-SSD-M2-800GB9 JNP-SSD-M2-800GB

For information on how to buy, please visit www.juniper.net/us/en/how-to-buy.

About Juniper Networks

Juniper Networks brings simplicity to networking with products, solutions and services that connect the world. Through engineering innovation, we remove the constraints and complexities of networking in the cloud era to solve the toughest challenges our customers and partners face daily. At Juniper Networks, we believe that the network is a resource for sharing knowledge and human advancement that changes the world. We are committed to imagining groundbreaking ways to deliver automated, scalable and secure networks to move at the speed of business.