Juniper Networks Firewall/VPN Solutions
1.1
MB
The Juniper Networks integrated security devices are purpose-built to
perform essential security functions. Optimized for maximum performance,
they are controlled by a security-specific, real-time operating system
called ScreenOS. These integrated devices provide network and
application-level protection, virtual private networking (VPN) capabilities,
and denial of service (DoS) mitigation functions. They are available in a
range of appliances built to meet the throughput requirements of service
providers and enterprises of all sizes.
WAN
Routing Configuration Examples for the Secure Services Gateway Family
1.1
MB
Outlines a series of routing deployment scenarios and configuration examples
(with and without QoS) starting with a basic T1 connection using OSPF and
advancing to more elaborate configurations using MLPPP and MLFR. The
Configuration Commands required to implement the deployment scenarios on any one
of the SSG Family platforms are included in each scenario.
Juniper Networks SSL VPN Appliances
1.7
MB
Juniper Networks SSL VPN appliances lead the market with solutions that meet the
needs of organizations of every size.
Network Based VPN/Firewall Services
2.0
MB
This document outlines a typical solution that Juniper can build to offer
Network-based IPsec VPN and Firewall services.
Perimeter Gateway with Firewall, IDP and NSM
856
KB
This paper addresses the triage (layered) approach to security in the network
perimeter.
Internet Access from Layer 3 VPNs
654
KB
This application note explores key architectures for supporting NAT/VRF
interworking solutions.
Juniper Networks Intrusion Detection and Prevention Solutions
924
KB
Juniper Networks Intrusion Detection and Prevention (IDP) products provide
network visibility and comprehensive inline protection to stop network- and
application-level attacks before they can proliferate. Using industry-recognized
stateful detection and prevention techniques, Juniper Networks IDP provides real
time protection against worms, Trojans, spyware, keyloggers, and other malware.
Buyer's Guide For Integrated Firewall and Virtual Private Network Solutions
259
KB
This guide is designed to help customers evaluate firewall and VPN products. It
provides an executive framework, a list of quick questions that users should ask
all vendors and a complete feature checklist.
Buyer's Guide For Intrusion Prevention Systems (IPS)
261
KB
The IPS Buyer's Guide is designed to help customers evaluate Intrusion
Prevention Systems, providing an overall framework for what to look for in
solutions, quick questions that can help customers understand a vendor's
approach, and a detailed feature by feature list that can be used to compare
NetScreen-IDP to other solutions.
VPN Decision Guide: IPSec or SSL VPN Decision Criteria
145
KB
Together, IPSec and SSL VPNs enable enterprises to provide their offices and
users secure, ubiquitous availability to the corporate network to support the
overall success of the business. This paper looks at how IPSec and SSL VPNs
differ and examines the criteria to be considered in deciding which technology
best fits each business need.
SSL VPN Decision Guide for Small to Medium Sized Enterprises
102
KB
The SME market is growing rapidly around the world, and coincides with the trend
toward remote and mobile employees. This paper discusses why having a
cost-effective, robust remote access solution is a business necessity for the
small to medium sized enterprise.
Datasheets
PIM Datasheets
Mini-PIM Datasheets
Feature Briefs
White Papers
Solution Briefs
Juniper
NetScreen
-
Integrated security solutions designed for medium to
large enterprise networks, offices, e-business sites, data centers, and carrier
infrastructures
-
High-performance platform with excellent
price/performance and superior features
-
Firewall attack protection on every interface, for
secure internal and external networks
Overview:
The Juniper Networks NetScreen-200 series includes
two enterprise network products: the NetScreen-204 appliance with four 10/100
interfaces, and the NetScreen-208 appliance with eight 10/100 interfaces.
Together, they are among the most versatile security appliances available today,
easily integrating into many different environments, including medium to large
enterprise networks, offices, e-business sites, data centers, and carrier
infrastructures. Complete with either four or eight auto-sensing 10/100 Base-T
Ethernet ports, the NetScreen-200 series performs firewall functions at wire
speed (375 Mbps). Even the most computationally intense applications, such as
3DES and AES encryption, are performed at speeds up to 175 Mbps. In addition to
physical interface density, the NetScreen-200 series optionally supports
virtualization, including VLAN support and additional custom security zones and
virtual routers.
Features & Benefits:
Key features and benefits of the NetScreen-204 and
NetScreen-208 appliances include the following:
-
Integrated solution with security-optimized hardware,
operating system, and applications
-
High-performance platform with excellent
price/performance and superior features
-
Comprehensive high-availability solution for
sub-second failover between interfaces or devices
-
Customizable security zones to increase interface
density without additional hardware expenditures
-
Integrated Deep Inspection firewall for
application-level attack protection for Internet-facing protocols, applied on a
per-policy basis
-
Redundant VPN gateways for an additional level of
redundancy in a VPN network, by allowing backup tunnel definitions in the event
of a lost VPN connection
-
Firewall attack protection on every interface, for a
secure internal as well as external network
-
Transparent mode to allow the device to function as a
Layer 2 IP security bridge, but with minimal change to the existing network
-
Management through graphical Web UI, CLI, or the
NetScreen-Security Manager central management system
-
Policy-based management for centralized, end-to-end
life-cycle management
|
NetScreen 204/208 Series: |
NetScreen-204 |
NetScreen-208 |
|
Physical Features |
| Number
of interfaces |
4 x
10/100 Ethernet |
8 x
10/100 Ethernet |
| Maximum
Number of IP Addresses in Trusted Interfaces |
Unrestricted |
Unrestricted |
| Maximum
Throughput |
375 Mbps
Firewall 175 Mbps 3DES VPN |
375 Mbps
Firewall 175 Mbps 3DES VPN |
| Maximum
Number of Sessions |
128,000 |
128,000 |
| Maximum
Number of VPN Tunnels |
1,000 |
1,000 |
| Maximum
Number of Policies |
4,000 |
4,000 |
| Maximum
Number of Virtual LANs |
32
default, up to 96 additional |
32
default, up to 96 additional |
| Maximum
Number of Security Zones |
4
default, up to 10 additional |
8
default, up to 10 additional |
| Maximum
Number of Virtual Routers |
3
default, up to 5 additional |
3
default, up to 5 additional |
| Routing
Protocol Support |
RIPv1/v2,
OSPF, BGP |
RIPv1/v2,
OSPF, BGP |
| High
Availability Modes Supported |
Active/Passive Active/Active |
Active/Passive Active/Active Active/Active Full Mesh |
| Routing
Protocols Supported |
RIPv1/v2,
OSPF, BGP |
RIPv1/v2,
OSPF, BGP |
| IPS
(Deep Insection Firewall) |
Yes |
Yes |
|
Integrated/Redirect Web Filtering |
No/Yes |
No/Yes |
The features and capacities described in the table
above represent the Advanced licensing option for the Netscreen-204 and the
NetScreen-208.
A Baseline software license is also available as an
entry-level solution for customer environments where features such as Deep
Inspection, OSPF and BGP dynamic routing, advanced High Availability, and full
capacity are not critical requirements. The following table shows the Baseline
features and capacities that are different than the Advanced models.
|
NetScreen 204/208 Baseline Series: |
NetScreen-204 Baseline |
NetScreen-208 Baseline |
|
Physical Features |
| Maximum
Number of Sessions |
64,000 |
64,000 |
| Maximum
Number of VPN Tunnels |
500 |
500 |
| Virtual
LANs* |
Not
Available |
Not
Available |
| Routing
Protocol Support |
RIPv1/v2
Only |
RIPv1/v2
Only |
| High
Availability Modes Supported |
Active/Passive |
Active/Passive |
| IPS
(Deep Insection Firewall) |
Not
Available |
Not
Available |
|
Integrated/Redirect Web Filtering |
No/Yes |
No/Yes |
|
NetScreen-Security Manager |
Supported |
Supported |
*NetScreen-204/208 Baseline can be upgraded to
support 96 VLANs, 5 additional virtual routers, and 10 additional security zones
with purchase of a VirtualizationKey.