Juniper SRX Series Firewall Initial Setup

MURALI NIDAMANURI - PeerSpot reviewer
Managing Director at VIPUN COGNITIVE SOLUTIONS PVT LTD.

The initial setup of the Juniper SRX Series Firewall is straightforward. The process takes two hours.

I rate the initial setup of the Juniper SRX Series Firewall a ten out of ten.

View full review »
PJ
Owner at Shree Atharva Sales Corporation

The setup of any firewall is always complex because we have to customize features according to customer requirements.

View full review »
EricLo - PeerSpot reviewer
Assistant IT Manager - Infrastructure & Operation at Hong Kong Aircraft Engineering Co Ltd

The initial setup is pretty straightforward and simple. No matter the brand, the setup, and configuration are very similar. Therefore, if you have some prior experience with firewalls, you should be fine handling the implementation. 

Including the configuration process, the solution only takes an hour or two to deploy.

Normally, we do a POC before deploying the solution fully in order to test everything out. 

We have around four people who can handle deployment and maintenance tasks. 

View full review »
Buyer's Guide
Juniper SRX Series Firewall
March 2024
Learn what your peers think about Juniper SRX Series Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
767,847 professionals have used our research since 2012.
Muhammad_Faisal - PeerSpot reviewer
Manager ITSM at Lucky Cement Limited

The solution is quite easy to install.

View full review »
Mr. Qalat Khan - PeerSpot reviewer
Expert Transport Planning Carrier, Enterprise & IP(Team Lead) at Mobilink GSM

The initial setup of Juniper SRX was simple. It took approximately one to two months to fully deploy.

The first step for the deployment was to share the requirements with the local team. Based on this, they proposed firewalls with sessions, net, and IPsec throughput. After deciding on the firewall, we went through the ordering process, which took longer than usual due to the Covid-19 pandemic. Once the firewall was delivered, it took about a month or two to install it on site, this included doing some joint ventures and having a partner from Juniper come and install the firewall in the rack and power it up. The initial integration took approximately three or four working days. After that, we started the migration process, which took an additional two-plus months.

View full review »
GD
ICT Product Manager at a comms service provider with 1,001-5,000 employees

The installation difficulty depends on the setup. Initially, when we started using the solution, we were using the command line interface and it took us a while to learn the commands, eventually, it becomes straightforward. 

View full review »
Jeff Ehrenberg - PeerSpot reviewer
IT Director at ADS

Coming from other vendors, the initial learning curve was a little steep. However, I would say that the actual setup was not that difficult.

I would rate the initial setup a three out of five.

I would recommend two people with networking knowledge, particularly in Juniper SRX, are enough to have it managed and supported.

One person could do it, but it helps to have a backup.

View full review »
Ihor Shtanko - PeerSpot reviewer
Juniper Engineer at VI-PORT

The initial setup is straightforward. I'd rate the process eight out of ten in terms of ease of implementation.

The deployment time depends on which features we use. Configuring the solution may take two to three hours; however, if more modifications are needed by the client, it may be longer. It depends on the technical requirements of the company.

Firstly, I needed to update the operating system. I checked the recommendations and prepared some configurations. 

View full review »
AT
Project manager at computer care company

The initial setup is not very easy. We had faced problems in the GUI, so we had to switch back to the CLI to get things done. While using the GUI, it was pretty easy and we could accomplish things by just clicking. However, for some reason, there were errors and we had to complete it using the CLI. I have no idea why this was the case, but we finally achieved what we wanted.

View full review »
IhorShtanko - PeerSpot reviewer
Network Engineer at MUK

For me,  the initial setup is straightforward due to my experience. Juniper provides good documentation with example configurations, which should help even beginners.

View full review »
GlennCamilien - PeerSpot reviewer
Senior Cybersecurity Engineer at a financial services firm with 201-500 employees

Setting up Juniper firewalls is straighforward if you have experience. You need some CLI experience. Configuring firewalls with a GUI is much easier than using the Juniper platform.

The deployment time depends on the size of the environment. I worked for a hospital system where we deployed a pair and used them as a firewall. It was relatively easy to deploy once we had a plan to bring the services in one by one as opposed to connecting the host of the hospital to us.

View full review »
RT
Cloud & IT-Infrastructure Engineer at Bahnhof AB (publ)

The solution's initial setup depends on what interface you use. If you use the J-Web, it's quite easy. If you do it by console, it isn't always clear what order you should be doing things on when you apply the settings. When you first come into the console, you might not know they're in the FreeBSD shell but not the Juniper OS.

View full review »
SB
Director & CIO of IT services at Connectivity IT Services Private Limited

I consider the setup for the product to be very easy. A basic technical person can do it. But, a person would need to know the capability of a robust box like SRX to make full use of the capabilities and the right choice of the product.  

You install the box, configure the hostname, a password, and set your IP address. By default, Juniper handles the basic configurations automatically. The control frame architecture is very nice. The whole platform architecture is very good. When you work with that box, you just divide the box into two layers: the top layer and the bottom layer. The top layer is exclusively made for the SRX box. The bottom layer is nothing but throughput where the packets get in and get out. We call it a packet forwarding engine, PFE.  

Initiating the routing packets actually go in the mapping connection between the top and the bottom, which is managed as with Oracle in an internal zone. The box is already secured when an attack happens. Nothing is 100% in the world. So, there is the possibility of an attack but at least the control center protects your network.  

The entire installation is just a couple of hours. It depends on the Oracle sizing. Let's say that you want to work on the agility of SRX, something you really need to understand is where you are deploying this product. It is different if you are comparing an SRX box or the cloud. When you are using an SRX box will it be deployed for a small enterprise, a mid-size enterprise, and a data center. You can have SRX boxes for a large data center. That is a difference in the agility of Juniper SRX compared to Cisco. For example, when I work with the cloud, I have an SRX virtual firewall, which is a high-performance network security in the virtual cloud. It is especially good for rapid deployments. It hardly takes hours to deploy on the cloud.  

When you have a container with a firewall, it is known as cSRX. Which is again, a highly available container firewall. These are used especially for microservices. When you start with a small enterprise you start with either the SRX 300 series or a 500 series, which is a next-generation firewall. It is comparable to the Cisco ASA. Probably the next good product to compare is Check Point. But the SRX product is easier to manage and deploy when compared to Check Point or Cisco.  

For the mid-size enterprise organization, we have the SRX 1400 Series or you can consider the 4000 Series. It is just an appliance. You just plug it in, switch it on, configure the network IP address, and then start configuring the protocols. You enable the licenses there, malware prevention, and all the other features you want by just adding on to the licenses.  

So it is just a matter of choosing the right appliance and from there it is practically plug-and-play. The challenge is not the initial setup and deployment, it is what you make use of.  

View full review »
Lukas Harkabus - PeerSpot reviewer
Security Presales Consultant at Trestech s.r.o.

The initial setup is dependent on how much experience one has with the command line. If one is familiar with the command line, the initial setup is relatively simple. However, if one is used to working in a management setting, the initial setup can be more challenging.

The implementation time depends on the number of clusters required.

The first step of implementation is to unplug and upgrade the devices, followed by configuration before moving into production.

View full review »
DS
Project Manager at MULTILINK COMPUTERS PVT LTD

It's easy to set up. I would rate it 5 out of 5.

It takes a maximum of 30 minutes to deploy everything.

Two engineers are enough for maintenance because it's pretty stable and the hardware quality is very good.

View full review »
AG
Network Engineer & Cyber Security Analyst at a tech services company with 201-500 employees

We did not find the initial setup to be complex. The implementation was straightforward and simple. It didn't really give us any trouble.

View full review »
Barrett Lamothe - PeerSpot reviewer
Sr. Enterprise Hardware Consultant at a tech services company with 51-200 employees

It is easy. It is pretty much plug-and-play. This is why people like Juniper.

View full review »
AM
Assistant Manager at GBPL

The initial setup is easy and the deployment takes one week. I rate the setup a ten out of ten. 

View full review »
VS
Senior Manager at Allsec Technologies Ltd

The installation was not very complex, it was rather easy. It took around one hour to complete the installation.

View full review »
PZ
Chair of Communication and Computer Networks at Poznan University of Technology

The solution is quite simple to set up if you spend a few hours learning the syntax. Based on experience level, it can be implemented in a few hours. 

View full review »
SG
First Assistant Vice President at a financial services firm with 1,001-5,000 employees

The initial setup is easy.

As we have been using this product for quite a long time, we are used to it and our resources have become very skilled with Juniper devices. The deployment does not take very long.

View full review »
LF
Security Governance at a comms service provider with 1,001-5,000 employees

The initial setup is straightforward. We had the help of the local provider. So, it was very straightforward. 

Even now, when I compare the initial setup to Cisco, the implementation of Juniper SRX is very simple.

View full review »
VK
Key Account Manager at a consultancy with 51-200 employees

The initial setup is straightforward. It's very easy.

The time it takes to deploy is determined by the one you choose. It can take a week or less.

I wouldn't be able to tell the amount of staff that is required to update the solution because I am not involved in the process myself.

View full review »
YS
IP Solution Architect /Deputy Manager at HFCL Limited

The initial setup is complex. It takes one week's time for deployment because we are also integrated with Active Directory and Radius Contactless.

View full review »
VS
Senior Manager at Allsec Technologies Ltd

The initial setup is straightforward.

View full review »
AT
CEO, Member of the Board at beh

The initial setup was difficult the first time. It was a little bit complicated, but after it was done, we've been using it just fine and there's no problem with the use. It was the first time we were using a firewall, the initial setup procedure took about one month to define all the zones. 

View full review »
DN
Security Analyst at a computer software company with 10,001+ employees

Setting up Juniper SRX is a little difficult. 

View full review »
SS
Consultant at a financial services firm with 5,001-10,000 employees

I did not handle the initial implementation. That was handled by someone else. Therefore, I can't really share any insights on the process. I do not know if it was easy or difficult, or how long it really took to deploy.

View full review »
DH
Network Architect - Contractor at TEML

Transitioning from the Cisco ASA that we had running took about two hours of planning and another two hours of execution time.

In terms of the maintenance, myself and one other person take care of everything. We take on small contracts all over the place.

View full review »
AK
Senior Manager (Engineering Department) at a comms service provider with 10,001+ employees

The installation is straightforward.

The time of the deployment depends on the complexity of the environment. If the customer requires HA deployment and the configuration could take longer time. On average, for a small-scale branch office, it can be completed within one day, which includes testing. If the customer does not have any special preference on the policy and they do not have any IP tunnels then it could be completed within half a day.

View full review »
FG
Senior Network Analyst with 1,001-5,000 employees

I migrated it from an ASA to the Juniper. It was a fairly straightforward process. There are things that are required on the Juniper that weren't required on the Cisco, like the global address book. Things have to be on there before you can do a lot of net and the like.

View full review »
it_user701490 - PeerSpot reviewer
Network | Firewall Engineer - Cloud Managed Services Delivery at a tech services company with 10,001+ employees

The setup was straightforward and simple once you understand the building blocks of Junos and firewalls.

View full review »
HP
Network Security Engineer at a tech services company with 1-10 employees

The solution's initial setup process was lengthy as I was new to Juniper. I had to explore and learn the steps to implement the solution. Even after that, there was no guarantee that it would work fine. So that wasn't very easy.

I suggest adding more articles or blogs regarding the deployment and configuration part.

View full review »
KC
Information Security Manager at a recruiting/HR firm with 201-500 employees

The first configuration with my network experts took a little bit of time to work through the differences between their knowledge of the Huawei networking and the Juniper set-up and the change from all the Huawei to the Juniper and Sophos access points. The first install took a couple of weeks to configure the actual hardware, and then on site, what we expected to take half a day in the first instance probably took a week, but once we did one, we've been ok rolling out the next ones after that.

In terms of the initial setup being straightforward, that depends on your knowledge of the product. Juniper has been fairly responsive when my team has asked them questions. So it has taken us longer to install than I would've hoped, but that's one of those things when you change your products.

View full review »
LK
Risk Management and Security Governance at a comms service provider with 501-1,000 employees

The initial setup was straightforward, especially compared to that of Cisco. It was very simple with the help of our local provider.

From the design phase up to the implementation stage took approximately one month per site. This included the time to validate the design documents and then validate and approve the changes. We needed to slot a window of time for the change, consider whether there is any impact on the customer, and then monitor what happens during the change. For both of our sites, it took approximately three months.

For the design and clarification, we had one person for four nodes. In terms of operations, we have two engineers.

View full review »
SO
Sr. Programmer at a tech vendor with 51-200 employees

The initial setup is mostly straightforward. We are converting one of our site-to-site VPNs with another company where we have overlapping subnets. This took some doing because the Cisco ASA allowed us to do policy-based NAT and could NAT the same IP subnet two different ways depending on the destination address. We needed to exclude 10 IP addresses out of a 24 subnet from the static NAT rule which was needed to deal with the overlapping subnets and ended up having to do more than 240 individual 32 NAT rules on the Juniper SRX240H2.

View full review »
it_user738864 - PeerSpot reviewer
Senior Network Engineer at a tech services company with 51-200 employees

Initial setup was complex because Junos is totally different than ScreenOS. But with some introductory courses and some googling it becomes much easier.

View full review »
AP
System Administrator at a leisure / travel company with 51-200 employees

The initial setup was generally handled by the reseller and they did the setup as described on the schematic and regarding core network configuration, high availability, security, firewalls, et cetera. It was, generally, out of the box when it was configured and set up from the ground up.

While the setup was planned in 2017, it was up and running in 2018. It took about six months or so.

We switched office buildings, the main office. The new office was built with this solution. Everything was migrated, including all the network devices, all the servers, all the ISP, internet connections, and so on. Everything was, generally, carefully planned when it was deployed.

Our reseller also handles the maintenance. Generally, that takes one or two people.

View full review »
ANanonymous - PeerSpot reviewer
Consumer Engineer at a comms service provider with 1,001-5,000 employees

The initial setup was straightforward, but has since become straightforward with experience.

For example, with MX (not SRX), it needs to be specific when you export or import the subnetting or addresses that you want to block or filter out of your networks. This is why it is a complex process the first time and becomes subsequently easier

View full review »
TM
Senior Network and Security Consultant, JNCIE-SEC#408 at a financial services firm with 501-1,000 employees

It was very straightforward, very clear.

View full review »
JG
IToV Implementation Engineer at a renewables & environment company with 5,001-10,000 employees

I have not been involved in the installation of this device.

View full review »
EC
Pre-sales manager at RETO Industrial S.A. de. C.V.

The initial setup was very simple.

View full review »
SM
Solutions Architect at a tech services company with 11-50 employees

We were not so much involved in the setup because we had a security company to do that for us. It took us about two months.

View full review »
AV
Senior Consultant with 51-200 employees

It is not at all complex. It's easy. 

The initial setup is straightforward.

The maintenance requirements are based on the customer's agreement and whether it is to manage the firewall and maintain it.

View full review »
FK
Head Of Network & Technical Support at a financial services firm with 501-1,000 employees

This product is easy to install but difficult to configure. It takes perhaps three hours to deploy.

View full review »
GV
Architect - Cloud Serviced at a comms service provider with 10,001+ employees

The initial setup was very simple. I would say it was the simplest one to date.

View full review »
US
Freelancer at a non-tech company with self employed

Because I have been using Juniper for five years, for me the setup is not hard. But compared to FortiGate it is much more difficult for new users.

View full review »
Pawel Jenner - PeerSpot reviewer
DevOps and System Engineer at Netyard

The initial setup is easy for me because I have some papers with notes that help me.

View full review »
PD
Pre-Sales Analyst at a tech services company with 201-500 employees

The initial setup wasn't too complex. It was pretty straightforward. We didn't really face any problems during implementation.

The deployment takes about 20 minutes. This without the client tests and just the configuration and no validation. Everything that was necessary was applied, however, not with the tests as it took too much of the client's time, and would have took much longer.

View full review »
NM
Technology Services Director at a computer software company with 11-50 employees

The initial setup was complex because we have a complex network.

View full review »
MA
Data Department Manager at BTC Networks

For me, the installation and setup is simple. I work hard to do the simulation for the customer, and discuss all the requirements before implementation with the client.

View full review »
AB
IT System Engineer at a computer software company with 201-500 employees

The initial setup was straightforward. The time it takes to implement this solution depends on the complexity of the configuration.

View full review »
it_user897687 - PeerSpot reviewer
Senior Network Security Engineer at Aplikas

The initial setup was complex. It took a group of five, engineers and architects, to get it up and running within 24-hours. And it takes a group of five, engineers and IT experts, to operate and maintain

View full review »
JA
Senior Network Analyst at a energy/utilities company with 10,001+ employees
it_user707172 - PeerSpot reviewer
ICT System Specialist at a comms service provider with 1,001-5,000 employees

The setup was very complex, e.g., if you are beginner.

View full review »
DS
Chief Information Officer at a tech vendor with 51-200 employees

Deploying SRX was straightforward because our environment was ready for it. We used our own IT team and deployment took about two weeks. It was a normal step-by-step process. As for maintenance, SRX usually requires software updates and nothing more. We've installed it in a suitable environment in the server room, so it doesn't require a lot of additional maintenance.

View full review »
SS
Senior Manager - Unified Communications, Smart Infrastructure and Service Provider Solutions at a tech services company with 51-200 employees

The initial setup was straightforward. This is due to the fact that we have a decent Juniper-certified team.

View full review »
TM
Sr. Engineer at a comms service provider with 51-200 employees

The setup depends on the deployment, on what we have to configure. But from one firewall to another firewall, it's about the same. They're not really complex. We have experience using the command line and the user interface. If you ask me which one is easier to configure, I will answer that configuring through the user interface is easier.

The amount of time the deployment takes depends on the complexity of the solution. If the firewall is used as an L3 firewall or L4 firewall, for blocking by IP address and, it's going to be faster to deploy than deploying the firewall using Unified Threat Management. In that case, we need to carefully tune the VPN configuration.

View full review »
TA
Network Manager with 1-10 employees

The initial setup was complex.

View full review »
it_user697011 - PeerSpot reviewer
Systems Engineer with 1,001-5,000 employees

The initial setup was simple and can be done 100% via the GUI.

View full review »
ME
Technical Lead at a tech services company with 10,001+ employees

The installation was not straightforward.

It took more than one month to set it up.

View full review »
CM
Network Engineer

The initial setup was very straightforward. It's an easy process and not very difficult or complex. 

View full review »
SV
Integrator at a tech services company with 11-50 employees

Its initial setup is straightforward. If you are a network engineer with some experience, you will be able to configure it easily. I have configured many Juniper firewalls, and it was really easy. Configuring the device isn't a problem. The main problem is preparing the environment and the infrastructure for your device.

It took more than one year to use this solution in production because I used a lot of features in my demo infrastructure, such as VSRX, to demonstrate this solution to potential and existing customers.

View full review »
PZ
Solutions Architect at a tech services company with 201-500 employees

I don't deal with implementation but in a typical project we have sale, pre-sales and deployment engineers. If the project is really big, we also use project managers. There would be four people involved in a typical project. If the product requires integration of different technologies like web application firewalls, we bring in more engineers specialized in different type of technologies to integrate them together. 

View full review »
SK
Owner & CEO at a comms service provider with 1-10 employees

The initial setup is straightforward and it took three hours to deploy.

Juniper SRX does not require a lot of maintenance.

View full review »
AF
Senior Product Manager at a tech services company with 51-200 employees

The initial setup is straightforward and very easy. The length of time for deployment depends on the size of the solution.

View full review »
MJ
Professional Services (Security) at Business Management Company

I find the setup simple, given that I have been using it for ten years. The deployment is quite easy and fast.

View full review »
it_user222999 - PeerSpot reviewer
Network Security Engineer at a tech services company with 51-200 employees

It's a straightforward setup for us as we have a configuration template.

View full review »
MR
Network Security Engineer at a tech services company with 201-500 employees

It's not too complicated. It's plug and play.

The most challenging is when you upload the ISO. Deployment is less than one hour.

The installation is completed in-house.

We are not a large company, we have a team of less than five for deployment and maintenance.

View full review »
ME
Technical Support Engineer at a tech services company with 51-200 employees

It is more complex than other vendors, but we have gotten used to it. So, we find it easy to implement and deploy.

View full review »
it_user453054 - PeerSpot reviewer
NCP Team Lead Secured Networks at a tech services company with 501-1,000 employees

The setup was no more difficult than switching to any other firewall implementation.

View full review »
it_user700152 - PeerSpot reviewer
NOKIA Lead Engineer at a comms service provider with 10,001+ employees
SS
C.T.O at Sastra Network Solution Inc. Pvt. Ltd.

Initially, it doesn't take too much of your time to deploy.  However, by the time it is fully configured, it is time-consuming.

View full review »
Buyer's Guide
Juniper SRX Series Firewall
March 2024
Learn what your peers think about Juniper SRX Series Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
767,847 professionals have used our research since 2012.