Positioning Juniper Network Security How to Use this

  • Slides: 72
Download presentation
Positioning Juniper Network Security

Positioning Juniper Network Security

How to Use this Deck This deck is designed to be modular. Although it

How to Use this Deck This deck is designed to be modular. Although it may flow as a presentation on its own, it can also be used in pieces to create your own specific, targeted presentations. • This deck can be used for Campus/Branch, Data Center/Cloud or both • The SDSN section is ONLY a summary. The complete Software Defined Secure Network (SDSN) platform deck is here: https: //juniper. gosavo. com/Document. aspx? id=38131965 • Positioning section is only for sales/partners only (do not use for customers). • Use other slides to build customer facing presentations. • Cheat Sheets can be printed off as quick-reference/reminder material. • Note that some transition and detailed slides are hidden. 2 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Agenda Trends, Drivers, Use Cases and Deployments Juniper Security Services Portfolio Positioning Juniper Security

Agenda Trends, Drivers, Use Cases and Deployments Juniper Security Services Portfolio Positioning Juniper Security Hardware Juniper Security Management Juniper Security platform – Software Defined Secure Networks Selling and Sizing Juniper Security 3 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Industry Trends and Drivers

Industry Trends and Drivers

Threat Climate Continues to Expand 80 OF BLACK-HAT HACKERS ARE AFFILIATED % WITH ORGANIZED

Threat Climate Continues to Expand 80 OF BLACK-HAT HACKERS ARE AFFILIATED % WITH ORGANIZED CRIME CYBERCRIME WILL BECOME A 2. 1 TRILLION BY 2019 MILLION NEW UNIQUE PIECES OF MALWARE IN 2016 1. 1 360 IDENTITIES WERE EXPOSED IN 2017 RANSOMWARE ATTACKS IN 2016 1 IN 131 EMAILS CONTAINED MALWARE, THE HIGHEST RATE IN FIVE YEARS 357 BILLION THOUSAND 2016 Source: Symantec Internet Security Threat Report 2017, Verizon 2016 Data Breach Investigations Report 5 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Cybercrime Happens 60% of initial compromises took 1 minute or less time 43% of

Cybercrime Happens 60% of initial compromises took 1 minute or less time 43% of companies experienced a data breach in the past year $12 M 7 Average cost due to data breach JUNIPER NETWORKS CONFIDENTIAL Results in… Increased cost Lost revenue Reputation damage Performance degradation Heavy fines Career limiting © 2017 Juniper Networks, Inc. All rights reserved.

Security Use Cases

Security Use Cases

Use Cases for Security Enterprise Branch Offices Secure Connected Branch • Fewer local knowledgeable

Use Cases for Security Enterprise Branch Offices Secure Connected Branch • Fewer local knowledgeable resources • Managing local device • Eavesdropping 10 JUNIPER NETWORKS CONFIDENTIAL Enterprise Regional Offices Secure Enterprise Edge • Application visibility/control • User visibility and control • Growing data breaches Data Centers and Cloud DC Edge, DC Core, Private Cloud, Hybrid Cloud • Increased cyber attacks • Unpredictable traffic volumes • Managing © 2017 Juniper Networks, Inc. All rights reserved.

Enterprise Branch Offices Secure Connected Branch Common Targets Used For • • 11 Connectivity

Enterprise Branch Offices Secure Connected Branch Common Targets Used For • • 11 Connectivity Encrypted traffic Prioritizes local applications Protects data in transit JUNIPER NETWORKS CONFIDENTIAL • • Commercial: Distributed retail, state & local gov Strategic: Retail, branch banking Federal: Civilian Financial Services: Branches Selling • • • Head of Networking Head of IT CTO CISO CSO © 2017 Juniper Networks, Inc. All rights reserved.

Enterprise Regional Offices Secure Enterprise Edge Used For • Create, manage and enforce security

Enterprise Regional Offices Secure Enterprise Edge Used For • Create, manage and enforce security policy • NGFW - Application, User, Threat Intelligence • Protection of network assets, users and data 12 JUNIPER NETWORKS CONFIDENTIAL Common Targets • State and Local Government • Education • Headquarters • Accounts with Juniper switching but no security Selling • • • Head of Security Admin CSO CISO CTO © 2017 Juniper Networks, Inc. All rights reserved.

Data Center/ Cloud Data Center Security / Cloud Used For DC Edge - North-South

Data Center/ Cloud Data Center Security / Cloud Used For DC Edge - North-South • Create/Manage/Enforce Policies • Advanced security and visibility DC Core - East-West • Protection via segmentation • Reduce spread of threats Public Cloud • Protection on un-owned assets Common Targets • Every company has data • Accounts with multiple Juniper switches and no Juniper high end security solutions Selling • • • Directly/through partner Head of Security Admin CSO CISO CTO Hybrid Cloud • Secure communication • Cloud to Cloud / Cloud to HQ 13 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Customer Needs Cheatsheet – Branch/Enterprise Secure Connected Branch Secure Enterprise Edge Retail Store, Branch

Customer Needs Cheatsheet – Branch/Enterprise Secure Connected Branch Secure Enterprise Edge Retail Store, Branch Banking, Convenience Store, Restaurant Chains, Fast Food Restaurants Regional Office, College Campus, Headquarters, Finance Regional Office, Insurance Office, Real Estate Office Use cases Secure Router Managed CPE NGFW (fully loaded FW) Attributes • One device for switching, routing, security • Remotely managed by HQ • Lacks local network/ security expertise • One device for switching, routing, security • Remotely managed by SP • Lacks local network/ security expertise • Maximized threat protection • Managed locally or centrally • Dedicated security appliance separate from router • Connectivity • Encrypted traffic • Prioritize local apps • Create, manage and enforce security policy • Application, user and network visibility • Protection from threats • Branch office/remote office • Branch office, regional office, HQ • End customer purchases and manages as branch router • Partner or vendor provides migration, design and installation • SP resells and manages CPE as a service for branch office • SP or vendor provides migration, design and installation • In-line – visibility, blocking, networking • Secure Wire – visibility, blocking, no networking • Out-of-band – visibility, no blocking, no networking • Partner • Direct sales • Service provider mostly • Direct sales • Partners • Data in transit • Outside-in • • Target examples Firewall used for: Deployments Go-to-market Protection focus Network access Users Data Inside-out AND Outside-in

Customer Needs Cheatsheet – Data Center/Cloud Data Center/Private Cloud Public Cloud and Hybrid Cloud

Customer Needs Cheatsheet – Data Center/Cloud Data Center/Private Cloud Public Cloud and Hybrid Cloud Target examples Web Retailers, High Tech, Financial Services, Governments, Health Care, Saa. S providers…Pretty much everyone Use case Data Center/Cloud Edge Data Center/Cloud Core • Own their own Equipment • Tend to lean toward physical appliances • High Availability • Need for visibility and control • Compliance • • Perimeter protection – both ways • Advanced Security (e. g. IPS) • Secure communication (IPSec VPN) Attributes Firewall used for: Protect Data and Application in Public Cloud Secure Link between Public and Private Cloud • Subscription service for compute, storage and networking • Maximized threat protection • Continue to leverage existing tools to manage security • Secure data and application • Need for agility • Need for elasticity • Needs consistency of security and audit compliance policies • Secure and Encrypted communication between Private and Public Cloud • E-W protection through segmentation and microsegmentation • Block threats between systems (IPS) • Identify and quarantine threats in real time • • • Secure Communication • Cloud to cloud • Cloud to HQ • Physical Firewall • Physical firewalls • Virtual firewalls in choices of Cloud (AWS, Azure) • At edge of Data Center as physical or virtual firewall • In Public cloud as virtual firewall • Data Protection • Application protection • Isolate network segments and applications • Threat detection/prevention • Mitigation • App visibility • Threat detection • Isolation of threats • Privacy of communication between clouds and HQ Deployments Protection focus Own their own Equipment Need for agility and elasticity Need for automation High availability High performance Compliance/IT governance Need for Visibility of traffic Create, manage and enforce security policy Application visibility Protection from threats Segmentation/isolation

Juniper Security Services Portfolio

Juniper Security Services Portfolio

Juniper Security Services Overview Next Generation Firewall Services Unified Threat Management (Known Threats) Threat

Juniper Security Services Overview Next Generation Firewall Services Unified Threat Management (Known Threats) Threat Intelligence Platform Advanced Threat Prevention Application Control & Visibility Anti-virus Botnets/C&C Sandboxing Intrusion Prevention Anti-spam GEO-IP Evasive Malware User-based Firewall Web Filtering Custom Feeds, APT Rich Reporting & Analytics SRX Foundation Services 37 Firewall NAT VPN Routing Management Reporting Analytics Automation JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved. SIEM

Juniper Security Services Products Overview Next Generation Firewall Services Unified Threat Management (Known Threats)

Juniper Security Services Products Overview Next Generation Firewall Services Unified Threat Management (Known Threats) Threat Intelligence Platform Advanced Threat Prevention Application Control App Secure & Visibility Anti-virus Botnets/C&C Sandboxing Juniper Sky™ Advanced Threat Prevention (ATP) GEO-IP Evasive Malware and Juniper Advanced Threat Prevention (JATP) Appliance IPS UTM Anti-spam User-based Firewall SRX, v. SRX Web Filtering Custom Feeds, APT Rich Reporting & Analytics SRX Foundation Services Firewall NAT VPN Routing Analytics Automation SRX Series Firewalls v. SRX Virtual Firewall Management 38 JUNIPER NETWORKS CONFIDENTIAL Reporting © 2017 Juniper Networks, Inc. All rights reserved. JSA

Application Visibility and Control • Ingress • • 39 Heuristics for evasive and tunneled

Application Visibility and Control • Ingress • • 39 Heuristics for evasive and tunneled apps More application signatures Open signature language JUNIPER NETWORKS CONFIDENTIAL App Tracking • Understanding security risks • Address new user behavior App Firewall • Block access to risky apps • Allow user tailored policies App Qo. S • Prioritize important apps • Rate-limit less important apps App Routing • Define packet forwarding for Apps • Create custom app environment SSL Proxy • SSL packet inspection IPS • Prevent application borne security threats Egress © 2017 Juniper Networks, Inc. All rights reserved.

Intrusion Prevention System Ingress Inspect Content aware Report Detect vulnerabilities Block Among leaders in

Intrusion Prevention System Ingress Inspect Content aware Report Detect vulnerabilities Block Among leaders in detection efficacy Allows time to patch vulnerable systems behind the firewall 40 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved. Egress

User Firewall Controls Finance • P 2 P apps blocked • You. Tube allowed

User Firewall Controls Finance • P 2 P apps blocked • You. Tube allowed • Anti-virus applied Sales • P 2 P, You. Tube blocked • Anti-virus applied CEO • No apps blocked • Anti-virus applied Internet Allows different users to have different application policies based on their role and group 41 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Unified Threat Management Services Anti-Virus • Protection from top-tier AV partner • Reputation-enhanced capabilities

Unified Threat Management Services Anti-Virus • Protection from top-tier AV partner • Reputation-enhanced capabilities Anti-Spam • Multilayered spam protection • Protection against APTs Web Filtering 42 JUNIPER NETWORKS CONFIDENTIAL • Block malicious URLs • Prevent lost productivity © 2017 Juniper Networks, Inc. All rights reserved.

Juniper Sky™ Advanced Threat Prevention Solution Overview Sky™ Advanced Threat Prevention Cloud Sandbox w/Deception

Juniper Sky™ Advanced Threat Prevention Solution Overview Sky™ Advanced Threat Prevention Cloud Sandbox w/Deception ATP Static Analysis Juniper Cloud 2. SRX sends potentially malicious content to Advanced Threat Prevention cloud 3. Advanced Threat Prevention cloud performs static and dynamic analysis 4. Advanced Threat Prevention cloud provides malware results and C&C server data to the SRX Customer 01101010 01110101 01101110 01101001 01110000 Customer SRX SKY ATP Quick Start Service planning, design, and execution service 43 1. SRX extracts potentially malicious objects and files JUNIPER NETWORKS CONFIDENTIAL 5. SRX blocks known malicious file downloads and outbound C&C traffic 6. Services to assure rapid installation and configuration © 2017 Juniper Networks, Inc. All rights reserved.

Juniper Sky™ Advanced Threat Prevention Cloud Machine Learning • Verdicts determined at every level

Juniper Sky™ Advanced Threat Prevention Cloud Machine Learning • Verdicts determined at every level Cache Potentially malicious files Inline Blocking Multiple Anti-Virus Static Analysis Behavioral Analysis Deception Sandbox Cloud Infrastructure 44 JUNIPER NETWORKS CONFIDENTIAL • Additive verdict determination ensures accuracy • Over 50 deception techniques employed to trick malware into exposing itself © 2017 Juniper Networks, Inc. All rights reserved.

Juniper Sky™ ATP Licensing Model § 1 YR or 3 YR software subscription SKUs

Juniper Sky™ ATP Licensing Model § 1 YR or 3 YR software subscription SKUs 45 Free Premium • Available on any SRX with valid contract • No license installation required – ‘zero friction’ • Comprehensive analysis and reporting - EXE files only • Infected host quarantine • Inline blocking • Purchase 1/3 YR subscription • ALL “FREE” features PLUS… • Comprehensive analysis and reporting - EXE, PDF, MS Office • Limited analysis for other files (java, audio, video, etc. ) • Full C&C server protection • Juniper Software Advantage support and upgrades JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

JSA (Juniper Secure Analytics) • #1 SIEM according to Gartner MQ • Analyze event

JSA (Juniper Secure Analytics) • #1 SIEM according to Gartner MQ • Analyze event data in real time • Early detection of targeted attacks & data breaches • Collect, store, investigate and report on log data for incident response and regulatory compliance. 46 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Juniper Advanced Threat Prevention (ATP) Appliance 2 Detection • On-premise solution that can detect

Juniper Advanced Threat Prevention (ATP) Appliance 2 Detection • On-premise solution that can detect advanced threats across web, email and lateral traffic Threat Behavior Analytics • Machine learning + behavior analysis + threat feeds Analytics • Improve productivity of SOC and IR teams by automating manual activities Juniper ATP Appliance 1 Advanced Malware Detection 47 JUNIPER NETWORKS CONFIDENTIAL 3 • Timeline view of all security events that have occurred on a host or user One-Touch Mitigation • Leverage existing security infrastructure to mitigate threats • Automatically block malicious IPs, URLs and infected hosts © 2017 Juniper Networks, Inc. All rights reserved.

Juniper ATP Appliance In Action 48 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc.

Juniper ATP Appliance In Action 48 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Positioning Juniper Security Hardware

Positioning Juniper Security Hardware

Previous SRX Product Line Branch 2 T Edge Data Center Up to 2 Tbps

Previous SRX Product Line Branch 2 T Edge Data Center Up to 2 Tbps FW throughput and 100 million concurrent sessions scaling SRX 5800 SRX 5600 1 T SRX 5400 SRX 3600 SRX 3400 100 G v. SRX 1400 (Virtual SRX) 10 G 1 G SRX 650 SRX 550 SRX 100 SRX 110 SRX 220 SRX 240 Integrated Routing, Switching and Security Unprecedented Scale Single Junos 50 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Latest SRX Product Line up Branch 2 T Edge Data Center Up to 2

Latest SRX Product Line up Branch 2 T Edge Data Center Up to 2 Tbps FW throughput and 258 M concurrent sessions scaling SRX 5800 SRX 5600 v. SRX 1 T 100 G SRX 4600 C-SRX * Containerized SRX 40 G 20 G 1 G SRX 5400 (Virtual SRX) SRX 4100 SRX 4200 SRX 1500 SRX 550 SRX 320 SRX 345 SRX 300 Integrated Routing, Switching and Security Unprecedented Scale Single Junos 51 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Positioning the Refreshed Branch & Campus SRX Series Retail Office Up to 50 Users

Positioning the Refreshed Branch & Campus SRX Series Retail Office Up to 50 Users SRX 300 (SRX 100 Refresh) Small Branch Up to 50 Users SRX 320 (SRX 110 / SRX 220 Refresh) Mid Branch Up to 100 Users Mid-Large Branch Up to 200 Users Large Branch Up to 500 Users SRX 340 SRX 345 SRX 550 -M (SRX 240 Refresh) (New Model) (SRX 550 Ro. HS) Campus Up to 1000 Users SRX 1500 Routing 500 Mbps 1 Gbps 1. 7 Gbps 2. 5 Gbps Firewall 500 Mbps 1 Gbps 1. 7 Gbps 2. 5 Gbps IPSec VPN 100 Mbps 200 Mbps 350 Mbps 1 Gbps NGFW* 100 Mbps 200 Mbps 300 Mbps 400 Mbps 1. 5 Gbps *NGFW = Client Side IPS + App. FW + External Logging – ALL numbers are projections Note: User numbers are guidelines and NOT license restrictions 52 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

SRX 300 Ideal for small sites, retail office Up to 50 users Full security

SRX 300 Ideal for small sites, retail office Up to 50 users Full security features Firewall and VPN UTM: IPS, App. Secure, antivirus, webfiltering, and anti-spam Threat Intelligence Routing and switching features Fanless (no noise) Typical use cases Secure Router Managed CPE 53 JUNIPER NETWORKS CONFIDENTIAL Features SRX 300 8 x GE (w/ 2 x. SFP) On-board Ethernet No Power Over Ethernet (802. 3 af, 802. 3 at) None WAN Slots JUNOS Software Version Support JUNOS 15. 1 X 1000 Mbps Firewall Performance (large packets) Firewall Performance (IMIX) 500 Mbps Firewall Performance (Firewall + Routing PPS 64 byte) 200 Kpps VPN Performance – AES 256+SHA-1 3 DES+SHA 1 100 Mbps NGFW Performance (IPS, App. FW, logging) 100 Mbps Connections Per Second (CPS) 5 K CPS Maximum Concurrent Sessions 64 K Spotlight Secure Enforcement Yes A/A, A/P High Availability AES 128 MAC-Sec 2 SFP Ports © 2017 Juniper Networks, Inc. All rights reserved.

SRX 320 Ideal for small sites, retail office Up to 50 users Full security

SRX 320 Ideal for small sites, retail office Up to 50 users Full security features Firewall and VPN UTM: IPS, App. Secure, antivirus, webfiltering, and anti-spam Threat Intelligence Routing and switching features WAN slots Typical use cases Secure Router Managed CPE 54 JUNIPER NETWORKS CONFIDENTIAL Features SRX 320 On-board Ethernet 8 x. GE (w/ 2 x. SPF) Optional Power Over Ethernet (802. 3 af, 802. 3 at) 6 ports GE, 90 W WAN Slots 2 x mini PIM JUNOS Software Version Support JUNOS 1501 X Firewall Performance (large packets) 1000 Mbps Firewall Performance (IMIX) 500 Mbps Firewall Performance (Firewall + Routing PPS 64 byte) 200 Kpps VPN Performance – AES 256+SHA-1 3 DES+SHA-1 100 Mbps NGFW Performance (IPS, App. FW, logging) 100 Mbps Connections Per Second (CPS) 5 K CPS Maximum Concurrent Sessions 94 K Spotlight Secure Enforcement Yes High Availability AES 128 MAC-Sec A/A or A/P 2 SFP Ports © 2017 Juniper Networks, Inc. All rights reserved.

SRX 300 and SRX 320 Compared 55 JUNIPER NETWORKS CONFIDENTIAL Specification SRX 300 SRX

SRX 300 and SRX 320 Compared 55 JUNIPER NETWORKS CONFIDENTIAL Specification SRX 300 SRX 320 RAM / storage 4 GB / 8 GB On-board ports 8 x. GE (w 2 x SFP) MAC-sec ports 2 x SFP Optional Po. E+ ports 0 6 (90 W) WAN slots 0 2 x Mini. PIM Acoustics 0 d. BA 35 d. BA Power Adapter 60 W External 75 W / 280 W Forwarding capacity 200 Kpps Routing / firewall 500 Mbps IPSec VPN 100 Mbps IPS 200 Mbps NGFW 100 Mbps Concurrent session 64, 000 © 2017 Juniper Networks, Inc. All rights reserved.

SRX 340 Ideal for enterprise medium-sized branch offices Up to 100 users Ideal office-in-a-box

SRX 340 Ideal for enterprise medium-sized branch offices Up to 100 users Ideal office-in-a-box solution for managed services or commercial business Full security features Firewall and VPN UTM: IPS, App. Secure, antivirus, web-filtering, and anti-spam Threat Intelligence Routing and switching features Typical use cases NGFW Managed CPE 56 JUNIPER NETWORKS CONFIDENTIAL Features On-board Ethernet SRX 340 16 x. GE (w/ 8 x. SFP) WAN Slots 4 x mini PIM JUNOS Software Version Support JUNOS 15. 1 X Firewall Performance (large packets) 3 Gbps Firewall Performance (IMIX) 1 Gbps Firewall Performance (Firewall + Routing PPS 64 byte) 350 Kpps VPN Performance – AES 256+SHA-1 3 DES+SHA-1 400 Mbps NGFW Performance (IPS, App. FW, logging) 200 Mbps Connections Per Second (CPS) 10 K CPS Maximum Concurrent Sessions 256 K Spotlight Secure Enforcement Yes High Availability AES 128 MAC-Sec A/A or A/P 16 SFP Ports 1 GE Out-of-Band Management Port 1 Field Upgradable SSD © 2017 Juniper Networks, Inc. All rights reserved.

SRX 345 Ideal for enterprise medium sized branch offices Up to 200 users Ideal

SRX 345 Ideal for enterprise medium sized branch offices Up to 200 users Ideal office-in-a-box solution for managed services or commercial business Full security features Firewall and VPN UTM: IPS, App. Secure, antivirus, web-filtering, and anti-spam Threat Intelligence Routing and switching features Typical Use Cases NGFW Managed CPE 57 JUNIPER NETWORKS CONFIDENTIAL Features On-board Ethernet SRX 345 16 x. GE (w/ 8 x. SFP) WAN Slots 4 x mini PIM JUNOS Software Version Support JUNOS 15. 1 X Firewall Performance (large packets) 5 Gbps Firewall Performance (IMIX) 1. 7 Gbps Firewall Performance (Firewall + Routing PPS 64 byte) 550 Kpps VPN Performance – AES 256+SHA-1 3 DES+SHA-1 300 Mbps NGFW Performance (IPS, App. FW, logging) 300 Mbps Connections Per Second (CPS) 15 K CPS Maximum Concurrent Sessions 375 K Spotlight Secure Enforcement Yes High Availability AES 128 MAC-Sec A/A or A/P 16 SFP Ports 1 GE Out-of-Band Management Port 1 Field upgradable SSD © 2017 Juniper Networks, Inc. All rights reserved.

SRX 340 and SRX 345 Compared 58 JUNIPER NETWORKS CONFIDENTIAL Specification SRX 340 SRX

SRX 340 and SRX 345 Compared 58 JUNIPER NETWORKS CONFIDENTIAL Specification SRX 340 SRX 345 RAM / storage 4 GB / 8 GB On-board ports 16 x. GE (w 8 x SFP) MAC-sec ports 16 x GE OOB management 1 x GE WAN slots 4 x Mini. PIM Acoustics 35 d. BA Power Supply 180 W Internal Forwarding capacity 400 Kpps 550 Kpps Routing / firewall 1 Gbps 1. 7 Gbps IPSec VPN 200 Mbps 300 Mbps IPS 400 Mbps 600 Mbps NGFW 200 Mbps 300 Mbps Concurrent session 256, 000 375, 000 © 2017 Juniper Networks, Inc. All rights reserved.

SRX 550 Ideal for large enterprise branch office Ideal office-in-a-box solution for managed services

SRX 550 Ideal for large enterprise branch office Ideal office-in-a-box solution for managed services or commercial business Up to 500 users SRX 550 offers: Comprehensive routing and security services High density on-board and modular switch ports, copper and SFP Application awareness and control Business continuity and resiliency Typical use cases NGFW Larger secure router CPE 59 JUNIPER NETWORKS CONFIDENTIAL Features On-board Ethernet SRX 550 10 x. GE (6 Copper, 4 x. SFP) Power Over Ethernet (802. 3 af, 802. 3 at) WAN Slots 40 ports GE, 500 W 2 x mini PIM, 6 x GPIM JUNOS Software Version Support JUNOS 15. 1 X Firewall Performance (large packets) 8 Gbps Firewall Performance (IMIX) 2. 5 Gbps Firewall Performance (Firewall + Routing PPS 64 byte) 800 Kpps VPN Performance – AES 256+SHA-1 3 DES+SHA-1 350 Mbps NGFW Performance (IPS, App. FW, logging) 300 Mbps Connections Per Second (CPS) 27 K CPS Maximum Concurrent Sessions 512 K* Spotlight Secure Enforcement High Availability Yes A/A or A/P 1 Field Upgradable SSD © 2017 Juniper Networks, Inc. All rights reserved.

New Mid-Range SRX 1500 for Enterprise Replaces SRX 650, SRX 1400 Modular Interfaces •

New Mid-Range SRX 1500 for Enterprise Replaces SRX 650, SRX 1400 Modular Interfaces • • 12 x 1 GE (Cu) + 4 x 1 GE (SFP) 4 x 10 GE (SFP+) 2 x PIM slots (for future use) Dedicated HA control port (SFP) • Dedicated OOB mgmt (1 x. GE) 60 JUNIPER NETWORKS CONFIDENTIAL Power, Storage & Dimensions • • • 16 G e. SATA + 100 G SSD Dual power supply (AC / DC) Average power: 150 W Size: 1 RU Front to back airflow Firewall Performance • • • Firewall (IMIX): 6. 0 Gbps VPN (IMIX): 1. 0 Gbps App. ID (HTTP): 5. 0 Gbps IPS recommended: 3. 0 Gbps NGFW: 1. 5 Gbps © 2017 Juniper Networks, Inc. All rights reserved.

SRX 1500 Ideal for enterprise campus, regional offices and large branch offices Up to

SRX 1500 Ideal for enterprise campus, regional offices and large branch offices Up to 1000 users Software security services App. Secure and IPS AV and web filtering Threat intelligence Sky Advanced Threat Prevention Typical use cases Large secure router VPN concentrator Small data center NGFW 61 JUNIPER NETWORKS CONFIDENTIAL Features On-board Ethernet SRX 1500 16 x 1 GE (12 Cu +4 SFP) 4 x 10 GE (SFP+) JUNOS Software Version Support JUNOS 15. 1 X Firewall Performance (large packets) 9 Gbps Firewall Performance (IMIX) 5 Gbps Firewall Performance (firewall + routing PPS 64 byte) VPN Performance – AES 256+SHA-1 or 3 DES+SHA 1 NGFW Performance (IPS, App. FW, logging) Intrusion Prevention System 1. 7 Mbps 1 Gbps 1. 5 Gbps 3 Gbps Connections Per Second (CPS) 50 K Maximum Concurrent Sessions 2 M High Availability (dedicated HA control port – SFP) © 2017 Juniper Networks, Inc. All rights reserved. A/A or A/P

New mid-range SRX 4000 series for Enterprise High Performance, Cost effective, Highly Available, Next

New mid-range SRX 4000 series for Enterprise High Performance, Cost effective, Highly Available, Next Gen FW SRX 4200 SRX 4100 Benefits: Use Cases: Provides outstanding protection with Sky ATP • • Integrates networking & security in a single platform Modular Interfaces • 8 x 10 GE SFP+ • Dedicated OOB mgmt (1 x. GE) plus 2 x USBs Enterprise Campus and Data Center Edge Secure Router and VPN Concentrator Power, Storage & Dimensions • 64 G RAM • 240 G (RAID 1) SSD • Dual PS (AC / DC) • Average power: 200 W • Size: 1 RU Firewall Performance • • Firewall: 40 & 80 Gbps Firewall (IMIX): 20 & 40 Gbps IPS recommended: 10/20 Gbps NGFW: 5 & 10 Gbps • Front to back airflow 64 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

SRX 4100 Ideal for medium to large enterprise campus, regional offices, very large branch

SRX 4100 Ideal for medium to large enterprise campus, regional offices, very large branch offices, smaller Service Provider networks Software security services App. Secure and IPS AV and web filtering Threat intelligence Sky Advanced Threat Prevention Typical use cases Large secure router VPN concentrator Data Center (Hybrid cloud solutions) NGFW 65 JUNIPER NETWORKS CONFIDENTIAL Features On-board Ethernet SRX 4100 8 x 10 GE (SFP+) JUNOS Software Version Support JUNOS 15. 1 X Firewall Performance (large packets) 40 Gbps Firewall Performance (IMIX) 20 Gbps Firewall Performance with Application Security 18 Gbps IPSec VPN Performance 5 Gbps NGFW Performance (IPS, App. FW, logging) 5 Gbps Intrusion Prevention System 10 Gbps Connections Per Second (CPS) 120 K Maximum Concurrent Sessions 5 M High Availability (dedicated HA control port – SFP) © 2017 Juniper Networks, Inc. All rights reserved. A/A or A/P

SRX 4200 Ideal for medium to large enterprise campus, regional offices, very large branch

SRX 4200 Ideal for medium to large enterprise campus, regional offices, very large branch offices, Service Provider networks Software security services App. Secure and IPS AV and web filtering Threat intelligence Sky Advanced Threat Prevention Typical use cases Large secure router VPN concentrator Data Center (Hybrid cloud solutions) NGFW 66 JUNIPER NETWORKS CONFIDENTIAL Features On-board Ethernet SRX 4200 8 x 10 GE (SFP+) JUNOS Software Version Support JUNOS 15. 1 X Firewall Performance (large packets) 80 Gbps Firewall Performance (IMIX) 40 Gbps Firewall Performance with Application Security 35 Gbps IPSec VPN Performance 10 Gbps NGFW Performance (IPS, App. FW, logging) 10 Gbps Intrusion Prevention System 20 Gbps Connections Per Second (CPS) 240 K Maximum Concurrent Sessions 10 M High Availability (dedicated HA control port – SFP) © 2017 Juniper Networks, Inc. All rights reserved. A/A or A/P

SRX 4100 and SRX 4200 Compared 67 JUNIPER NETWORKS CONFIDENTIAL Specification SRX 4100 SRX

SRX 4100 and SRX 4200 Compared 67 JUNIPER NETWORKS CONFIDENTIAL Specification SRX 4100 SRX 4200 RAM / storage 64 GB / 240 GB SSD On-board ports 8 x 10 GE (SFP+) OOB management 1 x 1 Gb. E Acoustics 70 d. BA Power Supply 2 x 650 W redundant AC/DC Firewall Large packet 40 Gbps 80 Gbps Firewall IMIX 20 Gbps 40 Gbps IPSec VPN 5 Gbps 10 Gbps IPS 10 Gbps 20 Gbps NGFW 5 Gbps 10 Gbps Concurrent session 5 M 10 M © 2017 Juniper Networks, Inc. All rights reserved.

SRX 4600 Ideal for large enterprise campus, regional offices, Service Provider networks Software security

SRX 4600 Ideal for large enterprise campus, regional offices, Service Provider networks Software security services App. Secure and IPS AV and web filtering Threat intelligence Sky Advanced Threat Prevention One RU size Great for consolidation Typical use cases Data Center Edge/Core Private/Hybrid Cloud NGFW Service Provider Edge Features SRX 4600 On-board Ethernet 4 x 40 G or 4 x 100 G QSFP 28 Ports 8 x 10 GE (SFP+) JUNOS 15. 1 X JUNOS Software Version Support Firewall Performance (large packets) 100 Gbps Firewall Performance (IMIX) 80 Gbps Firewall Performance with App Security IPSec VPN Performance (large/IMIX) Gbps * 40/20 Gbps* NGFW Performance (IPS, App. FW, logging) Intrusion Prevention System (HTTP/Ent Mix) 25 Gbps* 40/30 Gbps* Connections Per Second (CPS) 400 K* Maximum Concurrent Sessions 60 M High Availability A/A or A/P 4 x 10 G SFP + MAC SEC HA Ports *Target estimate 68 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Scalable Protection for Diverse Environments SRX 4600 Next Generation Firewall High Performance NGFW Throughput

Scalable Protection for Diverse Environments SRX 4600 Next Generation Firewall High Performance NGFW Throughput targets: • Stateful FW • 100 G Large Packet • 80 G IMIX Firewall • 60 M connections, 500 k CPS • 20 G NGFW IMIX Throughput • IPsec VPN throughput: 40 G Large, 20 G IMIX • SSL: 2 G • PST-NAT (Persistent NAT): 2. 5 M • Multiple Services • IPS • Content Security (UTM) • Advanced Threat Prevention Performance 69 Compact form factor • • • 1 RU Form Factor 2 Xeon™ processors x 14 cores 4 x 40 G or 4 x 100 G QSFP 28 ports 8 x 10 G SFP+ ports 4 x 10 G SFP+ MACSEC HA Ports • 256 GB DDR 4 w/ECC (128 G/CPU) • 2 x 1 TB (2 x 960 G formatted) GM. 2 SSD (RAID 1*) • 1+1 Redundant PSU (AC/DC) • Front to Back Airflow • NEBS and TAA Compliant • 650 W typical power consumption OPEX JUNIPER NETWORKS CONFIDENTIAL – NEED TO KNOW * Roadmap Features & Performance subject to change without notice FRS- Feb 28, 2018 Key Differentiators • Competitively Price/Performance for SFW, NGFW and Threat Prevention • Compact form factor – 1 RU • On-board high-speed ports: 1 G/10 G/40 G/100 G • Software Defined Secure Networks • Junos Automation & openframework CAPEX © 2017 Juniper Networks, Inc. All rights reserved.

v. SRX Ideal for cloud implementations Up to ~1000 users per instance Full security

v. SRX Ideal for cloud implementations Up to ~1000 users per instance Full security features Firewall and VPN UTM: IPS, App. Secure, antivirus, web-filtering, and anti-spam Threat Intelligence Routing and switching features • Highest Performance and Lowest TCO • 18 Gbps large packet FW performance and 4 Gbps IMIX with using 2 v. CPUs • 100 Gbps large packet FW and 25 Gbps IMIX with using 17 v. CPUs v. SRX Vmware (Gpbs) v. SRX KVM (Gbps) JUNOS 15. 1 X 49 -D 15 Firewall Performance – multi-v. CPUs Large Packet (2 H 16) 100 na Firewall Performance – multi-v. CPUs IMIX (2 H 16) 20 na Firewall Performance (large packets, 2 v. CPUs 17 13. 5 Firewall Performance (IMIX) 2 v. CPUs 4 3 57 us VPN Performance – AES 256+SHA-1 0. 8 0. 7 App. Secure throughput 4. 5 3. 5 IPS throughput 1. 8 1. 4 NGFW Performance (IPS, App. FW, logging) 0. 1 New Sessions Per Second 54 K 36 K Maximum Concurrent Sessions 520 K Yes A/A or A/P Features JUNOS Software Version Support Latency Spotlight Secure Enforcement High Availability 70 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

v. SRX – Fits into the Virtualization Ecosystem • VMware ESXi 5. x, 6.

v. SRX – Fits into the Virtualization Ecosystem • VMware ESXi 5. x, 6. 0 • KVM - Centos & Ubuntu • Microsoft – Hyper. V Platforms • Amazon AWS • Microsoft Azure • Google Cloud* *Roadmap 73 JUNIPER NETWORKS CONFIDENTIAL Iaa. S Orchestration Policy & SDN • VMware – v. Center • Open Stack – Plugin • Contrail Service Orchestrator (CSO) • Jspace – SD, CLI, JWeb • Net. Conf • Contrail Security* • VMware NSX © 2016 Juniper Networks, Inc. All rights reserved.

100 G v. SRX Value Proposition The industry’s highest performance virtual firewall! Agile v.

100 G v. SRX Value Proposition The industry’s highest performance virtual firewall! Agile v. SRX Virtual Appliance 5 x Increase throughput to the endpoint for mobility and high-bandwidth applications Elastic Multi v. CPU allows SPs to scale up and scale out virtual FW Comprehensive & Consistent Complete firewall feature set for common features across all firewalls and L 4 -L 7 services Junos Rich and Extensible Security Stack Perimeter Security Content Security Application Security Firewall Anti-Virus App. ID VPN IPS App. FW NAT Web Filtering App. Qo. S Routing Anti-Spam App. Track Junos Routing Protocols and SDK Junos Space – Security Director & Network Director, CLI, JWEB, SNMP, HA Targeted for 15. 1 X 49 -D 70 74 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

c. SRX - Security Micro-Services with Containers • • Industry’s FIRST containerized Firewall –

c. SRX - Security Micro-Services with Containers • • Industry’s FIRST containerized Firewall – Docker based Key features – Firewall, IPS, App. Secure, Content Security Elasticity Agility Cost-Savings 75 JUNIPER NETWORKS CONFIDENTIAL With small footprint and no resource reservation requirement, c. SRX can scale massively to keep up with customers’ peak demand With bootup/restart times under 1 second, c. SRX provides greater agility Low footprint enables less compute (servers), customers can choose the features they require (micro-services), at the price point they can afford © 2017 Juniper Networks, Inc. All rights reserved.

c. SRX – SRX in a Containerized Environment The industry’s first firewall purpose built

c. SRX – SRX in a Containerized Environment The industry’s first firewall purpose built for container applications! Container applications are inherently isolated but not secure c. SRX Container Virtual Appliance Agile Purpose built virtual appliance delivering L 2 - L 7 Firewall services for container applications and delivering micro-services Elastic Small memory and compute footprint delivering higher number of instances with sub-second boot-up times Junos Rich and Extensible Security Stack Perimeter Security Content Security Application Security Firewall Anti-Virus* App. ID VPN* IPS App. FW NAT* Web Filtering* App. Qo. S Anti-Spam* App. Track Comprehensive & Consistent Comprehensive security services with the agility required by container environments for distributed applications 76 JUNIPER NETWORKS CONFIDENTIAL Junos Space – Security Director & Network Director, CLI, JWEB, SNMP, HA Targeted for 1 H 2017 release © 2017 Juniper Networks, Inc. All rights reserved. *roadmap items

SRX 5400 Features Ideal for medium to large enterprises and Service Provider networks Software

SRX 5400 Features Ideal for medium to large enterprises and Service Provider networks Software Security Services App. Secure and IPS AV and web filtering Threat intelligence Next-generation, high-performance line cards power supply On-Board Ports 100 GE – CFP/CFP 2 40 GE – QSFPP 10 GE – SFPP/XFP 1 GE - SFP JUNOS Software Version Support JUNOS 15. 1 X 49 -D 30 Firewall Performance (large Packets)* 480 Gbps Firewall Performance (IMIX)* 468 Gbps Firewall Performance (Firewall + Routing PPS 64 byte) /with Express Path 9 Mpps /98 Mpps VPN Performance – AES 256+SHA-1 or 3 DES+SHA 1 35 Gbps App. Secure (NGFW) 42 Gbps Intrusion Prevention System 22 Gbps Connections Per Second (CPS) 420 K Maximum Concurrent Sessions 42 M High Availability IOC 2 card A/A or A/P SPC 2 Card SCB and RE card slot cover 79 *Performance with Express Path enabled; throughput without Express Path: 65 Gbps large packet, 25 Gbps IMIX JUNIPER NETWORKS CONFIDENTIAL SRX 5400 © 2017 Juniper Networks, Inc. All rights reserved.

SRX 5600 Features Ideal for large enterprise, Service Provider, and public sector networks Software

SRX 5600 Features Ideal for large enterprise, Service Provider, and public sector networks Software Security Services App. Secure and IPS AV and web filtering Threat intelligence Next-generation, high-performance line cards SPC 2 Card IOC 2 card SRX 5600 On-board Ethernet 100 GE – CFP/CFP 2 40 GE – QSFPP 10 GE – SFPP, XFP 1 GE - SFP JUNOS Software Version Support JUNOS 15. 1 X 49 -D 30 Firewall Performance (large Packets)* 960 Gbps Firewall Performance (IMIX)* 936 Gbps Firewall Performance (Firewall + Routing PPS 64 byte) /with Express Path 23 Mpps /390 Mpps VPN Performance – AES 256+SHA-1 100 Gbps App. Secure (NGFW) 114 Gbps Intrusion Prevention System 58 Gbps Connections Per Second (CPS) 1 M Maximum Concurrent Sessions 114 M High Availability A/A or A/P SCBE and RE card *Performance with Express Path enabled; throughput without Express Path: 130 Gbps Large Packet, 70 Gbps IMIXNote: IDP Performance is with Recommended policy and using 44 KB HTTP. VPN performance is based on 1420 packet size 80 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

SRX 5800 Features Ideal for large enterprise, Service Provider, and public sector networks Software

SRX 5800 Features Ideal for large enterprise, Service Provider, and public sector networks Software Security Services App. Secure and IPS AV and web filtering Threat intelligence Next-generation, high-performance line cards SPC 2 card IOC 2 Card SRX 5800 On-board Ethernet 100 GE – CFP/CFP 2 40 GE - QSFPP 10 GE – SFPP, XFP 1 GE - SFP JUNOS Software Version Support JUNOS 15. 1 X 49 -D 30 Firewall Performance (Large Packets)* 2 Tbps Firewall Performance (IMIX)* 2 Tbps Firewall Performance (Firewall + Routing PPS 64 byte) /with Express Path 50 Mpps /880 Mpps VPN Performance – AES 256+SHA-1 200 Gbps App. Secure (NGFW) 230 Gbps Intrusion Prevention System 120 Gbps Connections Per Second (CPS) 2 M Maximum Concurrent Sessions 234 M High Availability A/A or A/P SCBE and RE card *Performance with Express Path enabled; throughput without Express Path: 320 Gbps Large Packet, 140 Gbps IMIX Note: IDP Performance is with Recommended policy and using 44 KB HTTP. VPN performance is based on 1420 packet size 81 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Addressing the Pain Points Enterprise Branch Offices • Centralized Management • Combined FW and

Addressing the Pain Points Enterprise Branch Offices • Centralized Management • Combined FW and Router • Secure Communication • Easy deployment • SRX 300 s, SRX 550, v. SRX Enterprise Regional Offices Data Centers and Cloud • Centralized Management • High performance and scale • Application visibility and control • North-South Advanced Threat Prevention • East-West Protection and Isolation • High performance and scale • SRX 1500, 4100, 4200, 4600, 5 xxx, v. SRX • SRX 340, 345, 550, 1500, 4100, 4200, 4600 82 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Manage Your Migration and Upgrade Juniper Professional Services If you customers lack: Resources Domain

Manage Your Migration and Upgrade Juniper Professional Services If you customers lack: Resources Domain expertise Experience deploying NGFW Juniper Professional Services Reduce Risk Reduce Time to implementation 83 Quick. Start Services: • SRX Series Quick. Start Service • Junos Space Security Director Quick. Start Service • JSA Security Analytics Quick. Start Service Firewall Conversion Service © 2016 Juniper Networks, Inc. All rights reserved.

Juniper Enterprise Security Product Cheatsheet Secure Connected Branch Target examples Use cases Typical hardware

Juniper Enterprise Security Product Cheatsheet Secure Connected Branch Target examples Use cases Typical hardware to sell (note sizing is estimated) Typical software to sell (services added will determine size of hardware) Sell to (buyers and influencers) Features they look for 84 Secure Enterprise Edge Retail Store, Branch Banking, Convenience Store, Restaurant Chains, Fast Food Restaurants Regional Office, College Campus, Headquarters, Finance Regional Office, Insurance Office, Real Estate Office Secure Router NGFW (fully loaded FW) Managed CPE • • • SRX 300 SRX 320 SRX 345 SRX 550 v. SRX • • • SRX 340 SRX 345 SRX 550 SRX 1500 SRX 4 xxx • • App Secure (for App QOS) Spotlight Secure VPN Security Director • App Secure (for App QOS) • VPN • Support for the WAN interface • • • App Secure (for App Visibility, App Control and IPS) UTM with AV, Anti-spam, Web filtering Spotlight Secure (Threat Intelligence) Advanced Threat Prevention (Sandboxing) Security Director • • The company directly/through partner Head of Network Head of IT Security Admin CSO CISO CTO • Service Provider • Managed Service Product Manager • • • The company directly/through partner Head of Security Admin CSO CISO CTO • • • Remote management Routing capability VPN Easy provisioning Rate limiting per application • • • Ability to create, manage and enforce security policy Application, User and Network Visibility Various threat prevention alternatives IPS Advanced Threat Protection JUNIPER NETWORKS CONFIDENTIAL SRX 300 SRX 320 SRX 345 SRX 550 v. SRX Remote management Routing capability VPN Easy provisioning Ability to track and manage SLAs Good pricing so they can make margins © 2017 Juniper Networks, Inc. All rights reserved.

Juniper Data Center/Cloud Product Cheatsheet Data Center/Private Cloud Public Cloud and Hybrid Cloud Target

Juniper Data Center/Cloud Product Cheatsheet Data Center/Private Cloud Public Cloud and Hybrid Cloud Target examples Web Retailers, High Tech, Financial Services, Governments, Health Care, Saa. S providers…Pretty much everyone Use case Data Center/Cloud Edge Data Center/Cloud Core • SRX 1500 • SRX 4 xxx • SRX 5 xxx Protect Data and Application in Public Cloud Secure Link between Public and Private Cloud • v. SRX • SRX 1500 • SRX 4 xxx • v. SRX in cloud • Any SRX on the Edge • SRX 1500 • SRX 4 xxx • App Secure (for App Visibility, App Control and IPS) • UTM with AV, Anti-spam, Web filtering • Spotlight Secure • Sky Advanced Threat Prevention • Security Director • App Secure (for App Visibility, App Control and IPS) • Spotlight Secure • Sky Advanced Threat Prevention • Security Director • Create, manage and enforce security policy • Application visibility • Protection from threats • Segmentation/isolation • Secure Communication • Cloud to cloud • Cloud to HQ Sell to (buyers and influencers • The company directly/through partner • Head of Security • Security Admin • CSO • CISO • CTO • • • Features they look for • Ability to create, manage and enforce security policy • Application, User and Network Visibility • Various threat prevention alternatives • IPS • Ability to isolate network segments and applications • Threat detection/prevention • App visibility • Threat detection • Isolation of threats Typical hardware to sell (note sizing is estimated) Typical software to sell (services added will determine size of hardware) 85 JUNIPER NETWORKS CONFIDENTIAL The company directly/through partner Head of Security Admin CSO CISO CTO • Encryption of data between clouds and HQ © 2017 Juniper Networks, Inc. All rights reserved.

How We Compete Enterprise Branch Offices • All-in-one security, routing, switching platforms • Centralized

How We Compete Enterprise Branch Offices • All-in-one security, routing, switching platforms • Centralized Management across product line • Centralized management across product line • Superior Price/Performance and Performance • Better secure communications 86 Enterprise Regional Offices JUNIPER NETWORKS CONFIDENTIAL • SDSN Platform Data Centers and Cloud • World’s fastest firewall • World’s fastest virtual firewall • Better Price/Performance • Better connectivity • SDSN Platform © 2017 Juniper Networks, Inc. All rights reserved.

Juniper Security Management

Juniper Security Management

Enhanced Security Director Dashboard Firewall Policy Threat Map Events and Logs Application Visibility 91

Enhanced Security Director Dashboard Firewall Policy Threat Map Events and Logs Application Visibility 91 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Enhanced Jweb On-Box Security Management Dashboard Firewall Policy User Visibility Events Application Visibility 92

Enhanced Jweb On-Box Security Management Dashboard Firewall Policy User Visibility Events Application Visibility 92 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Software-Defined Secure Networks Juniper’s Innovation in Secure Enterprise Networks

Software-Defined Secure Networks Juniper’s Innovation in Secure Enterprise Networks

A Change in Mindset Stop talking about Network Security. Start talking about Secure Networks.

A Change in Mindset Stop talking about Network Security. Start talking about Secure Networks. Realize threats are everywhere. They are already inside. They walked in your front door Recognize perimeter security isn’t enough Detection and Enforcement should be enabled anywhere Acknowledge security is everyone’s problem – horizontal and vertical 97 Copyright © 2014 Juniper Networks, Inc.

The Software-Defined Secure Network Operate network as single enforcement domain, every element becomes a

The Software-Defined Secure Network Operate network as single enforcement domain, every element becomes a policy enforcement point Policy Create and centrally manage intent based policy directly aligned to business objectives Detection Gather & distribute threat intelligence, from multiple sources – know who the bad guys are faster Leverage cloud economics for real time analysis – find the bad guys faster Enforcement Enforce policy to the threat feed information, real time across the network – adapt the network real-time 98 Copyright © 2016 Juniper Networks, Inc.

Software Defined Secure Networks (SDSN) Unified Security Platform DETECTION Juniper Cloud Sky™ Advanced Threat

Software Defined Secure Networks (SDSN) Unified Security Platform DETECTION Juniper Cloud Sky™ Advanced Threat Prevention (ATP) Spotlight Secure Threat Intelligence POLICY Third Party Threat Intel Juniper Secure Analytics Detection • Fast, effective protection from advanced threats • Integrated threat intelligence Policy • Adaptive enforcement to firewalls, switches and third party devices (routers in the future) • Robust visibility and management Security Director + Policy Enforcer Policy Enforcement, Visibility, Automation Enforcement DETECTION ENFORCEMENT SRX v. SRX Physical Firewall Virtual Firewall EX & QFX Switches MX Third Party Elements • Consistent protection across physical/virtual • Open and programmable environment Routers* *Roadmap, subject to change Network as a single enforcement domain - Every element is a policy enforcement point 99 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

SDSN Portfolio Security Director Policy Enforcer Secure Analytics Sky Advanced Threat Prevention Application Security

SDSN Portfolio Security Director Policy Enforcer Secure Analytics Sky Advanced Threat Prevention Application Security SSL Inspection Intrusion Prevention User Firewall UTM Management, Visibility, Automation SIEM Advanced Malware Prevention Service Next Gen Security Services 4 Gb/s (2 v. CPU) 25 Gb/s (16 v. CPU ) c. SRX* v. SRX 2 RU 5. 5 Gb/s SRX 300 SRX 3 XX SRX 550 Branch 1 RU 5 Gb/s SRX 1500 Campus 16 RU 2 Tb/s 1 RU 20/49 Gb/s SRX 4100 SRX 4200 Data Center 1 RU 80 Gb/s SRX 4600 Cloud 5 RU 480 Gb/s SRX 5400 8 RU 960 Gb/s SRX 5600 SRX 5800 Service Provider Beta* 100 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Policy Enforcer for Threat Remediation Sky ATP detects malware; renders verdict • Enables remediation

Policy Enforcer for Threat Remediation Sky ATP detects malware; renders verdict • Enables remediation via Policy Enforcer workflows in Security Director Threat Intel 2 Sky ATP 3 Threat remediation data v. SRX 4 EX/QFX Switch Cisco Switch Unknown 1 Malware enters 4 Policy Enforcer Security Director Threat remediation automatically deployed 4 • Delivers micro security services to switches such as EX, QFX and Cisco • Updates enforcement criteria automatically with new threat data • Tracks infected host/endpoint movement from site to site via MAC address vs IP address 5 Infected endpoint quarantined via port 104 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

SDSN Security Alliances CASB Access Security Endpoint Security Micro-segmentation Cloud App Security Access Security

SDSN Security Alliances CASB Access Security Endpoint Security Micro-segmentation Cloud App Security Access Security Endpoint Protection SDSN for the SDDC Ready to Deploy Comprehensive Security Solutions 105 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Sizing Juniper Security

Sizing Juniper Security

How to Size an SRX Questions to Ask How fast is your network link?

How to Size an SRX Questions to Ask How fast is your network link? What security services do you want to have running on the appliance? • Check the VPN max speed to ensure it is at or above line speed • Key for Secure Router use case • Check the NGFW max speed to ensure it is at or above line speed • Key for NGFW use case ? What kind of WAN interface do you need? • All branch devices support on-box Ethernet or SFP interfaces as a WAN interfaces • If you need non. Ethernet WAN interfaces such as DSL and T 1, you must choose SRX 300, 345, or 550 Will your branch office be growing in terms of bandwidth needed, people to support or security services needing to be supported? • Based on budget, you may want to increase the size of the firewall for future growth How many Gb. E ports are required? • • SRX 300, 320 = 8 SRX 340, 345 = 16 SRX 550 = 42 SRX 1500 = 16 1 GE, 4 10 GE

Entry Level SRX Sizing Numbers Product Secure Connected Branch - Is this above line

Entry Level SRX Sizing Numbers Product Secure Connected Branch - Is this above line speed? Secure Enterprise Edge Is this above line speed (with services)? SRX 300 SRX 320 SRX 345 SRX 550 SRX 1500 List price $995 $1495 $3, 195 $4, 495 $9, 999 $22, 000 On-board ports 8 x. GE 16 x. GE 10 x. GE 16 x. GE, 4 x 10 GE Firewall (IMIX) 500 Mbps 1 Gbps 2. 5 Gbps AVC (http) 200 Mbps 1 Gbps 2. 0 Gbps VPN (IMIX) 100 Mbps 200 Mbps 350 Mbps IPS (REC) 200 Mbps 400 Mbps 600 Mbps 800 Mbps NGFW* 100 Mbps 200 Mbps 300 Mbps 400 Mbps 5 Gbps 1 Gbps 3 Gbps 1. 5 Gbps *NGFW = Client Side IPS + App. FW + External Logging 108 JUNIPER NETWORKS CONFIDENTIAL © 2017 Juniper Networks, Inc. All rights reserved.

Thank you Thank You

Thank you Thank You