We just raised a $30M Series A: Read our story
2017-12-18T07:21:00Z

What needs improvement with Juniper SRX?

20

Please share with the community what you think needs improvement with Juniper SRX.

What are its weaknesses? What would you like to see changed in a future version?

ITCS user
Guest
4545 Answers

author avatar
Top 20Real User

We've had some issues with the firmware. The solution is quite advanced. You need a lot of training to use it effectively. When we bought the equipment, and we have more Juniper devices, not just SRX, they started to malfunction. I'm not sure why. All the devices that we bought were from the year 2018. We had the EX4600. Something was not working with this device. It was offline. We bought everything in twos so we could make a high availability with all of them. The current has malfunctioned, and all the warranties have also expired. We are, generally, expecting malfunctioning, maybe in the next few years. I was planning to switch the Juniper equipment with something else to avoid this. It does not have a simple user interface. The warranty offered on the devices isn't long enough. it would be better if you could extend it out to five or eight years. Otherwise, you have to be very careful with the equipment. I'm not sure if Juniper SRX can filter emails or block viruses. I'm not familiar with these aspects as I haven't had that much experience using the SRX inside the UI. However, if they do not, it would be ideal if they did. I'm not sure if it can deflect any kind of DDoS attack. The one particular issue that I've seen on the SRX, is if you have SSH enabled and if there is a large number of SSH connections, when a brute force attack happens, the SRX, in general, tends to become unstable, or it resets by itself. That's one issue that's particularly making me angry, and I had to request the reseller to block the SSH permanently, or just to allow access, so only they can connect.

2021-09-13T15:19:36Z
author avatar
Top 20Reseller

The reporting is lacking. it's an aspect of the solution I would like to see improved upon in the future. The solution isn't as present in the market as Cisco and Fortigate. They need to do a better job of marketing themselves and becoming more visible.

2021-07-29T12:12:27Z
author avatar
Top 5Real User

In the next release, I would like to have a better web interface. It needs to be more user-friendly. Right now, you can only access many features through the console.

2021-06-29T12:43:03Z
author avatar
Top 5Real User

It could be more secure.

2021-06-04T20:27:22Z
author avatar
Top 5Real User

I've noticed that the management interface could use some updates and upgrades. The dashboard can be updated. The reporting could be more robust and in-depth. I've looked into the Check Point firewall a bit and I've found that its anti-spoofing is a good feature. Juniper should consider adding that as a feature. I've only just begun to really use the product. I only have one year of experience so far. It's still new to me. Therefore, it's hard to make any notes on any features or improvements, as I'm still familiarizing myself with everything. I need time to compare it to other firewalls, and I have not gone through the process of doing that just yet. I need more time.

2021-04-06T17:00:54Z
author avatar
Top 5Real User

The interface could be more user-friendly.

2021-03-15T13:52:17Z
author avatar
Top 10Real User

It must be 5G ready. The 5G network is rolling out soon in India, and Juniper must upgrade their firewall slot to the 5G network, or they must manufacture a 5G dongle card for the Juniper firewall. I want Juniper to upgrade their dongle from 4G to 5G. Presently, they have an expansion slot in the SRX 322 series and higher firewalls. In that expansion slot, they can put a 4G mobility SIM card so that whenever our primary link is down, it will automatically connect through this GSM network and form a tunnel.

2021-02-25T17:24:55Z
author avatar
Top 5LeaderboardReal User

They recently improved this solution. Currently, I feel comfortable with Juniper in general.

2021-02-20T07:04:04Z
author avatar
Top 10Real User

Their models for service providers could improve. We are an MSP, we resell services and I think the company could have a better program for service providers because our needs are different from our regular customer that is buying it for. More recently we started using the GUI interface and that looks pretty shameful and needs improvement. Juniper has a different product line that has artificial intelligence capabilities. In the future, we would like to see that extended to the SRX line.

2021-02-18T14:24:25Z
author avatar
Top 10Reseller

I think with this Juniper product, the CPU switch could be improved for a better overall performance of traffic flow. I'd also like to see a threat intelligence feed which would hopefully monitor the network traffic flowing through the SRX to detect malware and other content.

2021-02-15T00:35:50Z
author avatar
MSP

I think it needs some automation. I have to find an API for Python and so on, which is quite different from a typical solution. Sometimes committing configurations takes a lot of time in Juniper because of the connections, and it could be a little bit faster. Their documentation could also be better.

2021-02-12T23:44:09Z
author avatar
Top 20Real User

Juniper SRX's UI is very bad. We have to use CLA all of the time and Sky ATP. If I compare Fortinet with SRX, particularly for filtering websites and email addresses, SRX is very very difficult.

2021-02-10T16:40:00Z
author avatar
Top 10Real User

The training videos that are available need to be improved, and made more educative. This will help users to become more familiar with the product.

2021-02-03T02:37:49Z
author avatar
Top 20Real User

The solution could cost less. It's a bit expensive right now. The solution sometimes takes a long time to deliver the products. We're often waiting for stock. They should just have the product available and ready to go when customers need it.

2021-01-23T09:52:02Z
author avatar
Top 5LeaderboardReal User

We are experiencing some issues with the clustering. It needs to be simplified and more stable. Some of the features included in SRX need improvement. For example, if you want to change your SSH port number, you cannot go into the application layer. You will have to go to the shell command to change the port. This is a problem because when you show the configuration, you cannot see what was put in the shell. It should easier. Also, the user interface is a bit slow. In the future, I would like to see the UI more responsive. The new generation doesn't use SSH anymore. One-click would be better.

2021-01-12T17:13:09Z
author avatar
Top 5LeaderboardReal User

It was very difficult to deal with and required a lot of support, and the UI is very poor. I didn't like this product at all. We faced many issues with the power supply causing many outages with this SRX box. We experienced outage issues when load-balancing between two availability architectures, which had an effect on the availability. Once we started to deal with this solution, it was very difficult to troubleshoot. It was not straightforward at all when comparing to Cisco. We always had support tickets. More than 50 tickets per month exceeded the SLA by more than two weeks. Better support is needed. In the next release, this solution needs to be stable, offer better support, better pricing, and less expensive to migrate.

2020-12-24T00:33:06Z
author avatar
Top 20Real User

The reliability needs to be improved. We purchased three devices and all three have been replaced under RMA. We've had other problems where they have needed to be rebooted. A couple of times I've run into the problems where they have to integrate with other systems. The Juniper support really doesn't have a clue about other systems. They know Juniper and if everything is Juniper then it's great. However, we have Windows RADIUS Servers and I need Juniper-specific settings for them. Unfortunately, they're having a real hard time telling me what those should be, and they keep referring back to it being Microsoft, which they don't support. When they say that I need to speak with Microsoft, I remind them that these are things that are defined in the Juniper configurations that I need to set up. They seem to forget that not everybody is exclusively Juniper.

2020-12-18T03:35:55Z
author avatar
Top 20MSP

While the GUI is pretty good on the Juniper side, there can still be tweaks made to it that will make it even better.

2020-12-15T23:40:42Z
author avatar
Top 5LeaderboardReseller

The setup process should be improved.

2020-12-14T20:26:36Z
author avatar
Top 20Real User

Our operational team handles the solution more than I do. I personally haven't seen any features that are missing per se. The solution isn't very granular or detailed. However, we're just using the basics anyway. The product could have a quicker response when it comes to technical support getting back when we have questions.

2020-12-10T05:09:51Z
author avatar
Top 5Real User

The user interface and the GUI need improvement. In the next release, I would like to see mobile support.

2020-11-22T10:55:00Z
author avatar
Top 5Real User

The configuration is difficult and it should be easier.

2020-10-27T16:36:26Z
author avatar
Top 10Real User

I have not given a lot of thought as to what needs to be improved because so much of technology and capabilities are expanding. Probably Juniper could come up with their own dedicated endpoint security. Today they have an integration with Sophos. If you really look at what SRX has as far as antivirus capability, it is really only the integration with Sophos. Sophos is good, I am not saying Sophos is a bad solution. But Juniper having their own antivirus solution may be a batter idea to make it a stand-alone product. If you look at Check Point. They have a lot of experience in the area of security which is integrated with their product. In comparison, Juniper could start developing its own strong capabilities with antivirus and have its own security which may even surpass relying on Sophos. Sophos could improve more but it is definitely a wonderful architecture.

2020-07-14T08:15:49Z
author avatar
Top 20Reseller

There are a lot of features that customers do not know about and I think that better documentation would help when it comes to learning how to use the product. Technical support could be improved by adding local engineers.

2020-06-16T08:37:23Z
author avatar
Top 20Real User

When we first tested the serial interface on our model, it did not work. It should be easier to escalate support tickets.

2020-05-18T07:50:10Z
author avatar
Real User

The workplace management console needs improvement. It should be a little bit more developed. Also, the interface needs a bit more improvement. If the solution would have an intuitive interface would be much better because the work-based interface is not so perfectly developed and it's not ideal. It's not complete yet, and it makes it difficult for beginners and first-time users of this solution. As it is, for new users, it would make it very difficult for them to deploy this solution. Otherwise, the rest is fine. There's no other problem with it.

2019-07-09T05:26:00Z
author avatar
Reseller

The throughput when using features can be improved. 100-gigabit interfaces should be added into the next release because we'd like to adopt them.

2019-07-04T07:00:00Z
author avatar
Real User

In terms of other features, I'd like to see a web filter, 10 point control, application control and DNA features in the next release.

2019-07-04T07:00:00Z
author avatar
Real User

The solution previously had a Clientless SSL VPN, but it has been removed and I would like access to it again. The GUI needs improvement. I can work fine with the command line (CLI), but new people would like a better user interface. I would like to see an SSH VPN in the next release.

2019-05-16T07:47:00Z
author avatar
Top 5LeaderboardReal User

IPS, or IDS services, need improvement. Their major problem is that you have to integrate it with MSN or web building services, you need to buy support for that and services but you cannot. The best thing that I see was a filtering service with custom categories that I can create. If I buy a license, I can integrate it with a different product, but their own web building services is poor. So they can improve web building services, as well as look for application awareness, and maybe, with IPS, they can have their own built-in services rather than integration with MSN for using IPS. There are three things that can be improved. IPS is one that I would definitely want to be improved. I would also like SSL VPN to be integrated. Other than that, I guess it's doing a firewall, so I would say it's cool. Next in features, I would want that to be included, along with SSL VPN, if possible. Other than that for the product, I don't think there's a need for doing anything with this.

2019-05-15T05:16:00Z
author avatar
Real User

The Juniper product has to improve in terms of innovation. It only has standard reports, such as memory capacity and data traffic. By comparison, the Check Point solution comes with great reports. Check Point tracks the logs, then analyses the logs and can tell you when you are under attack. Then, you can prevent it. With Juniper today, what you have in terms of log analysis is not so good. I think that they have another solution for this, but it is not embedded, and you have to purchase it separately.

2019-05-13T08:56:00Z
author avatar
Real User

In terms of improvement, it could use more on the security side. It's a good stable firewall, but it's nowhere near what it needs to be for a next-generation type firewall. They also need to improve their documentation. With Cisco, you can find lots of examples, but with Juniper, it is not always the case. One area that needs more focus is instruction on how to interoperate with other vendor's products. I would like to see documentation on running IPsec tables between Fortinet and Juniper or Cisco and Juniper because the information is not there. Their technical support also needs improvement, as they are lagging behind Cisco.

2019-05-09T13:12:00Z
author avatar
Real User

Improvements can be made to the GUI. The GUI can be improved by creating policies to handle IPS requirements. The configuration should be a one-step process. This would make it easier to complete the setup to register the time of operation.

2019-04-30T08:57:00Z
author avatar
Real User

The Juniper SRX product needs to improve in terms of innovation. E.g., Checkpoint comes with a monitoring solution embedded in its product, as well as providing good reports. Checkpoint also does analysis by tracking the logs and letting you know when you are under attack. What Juniper has today in comparison is not so good. Juniper only has limited reports, such as memory, capacity, data, and traffic.

2019-04-04T09:10:00Z
author avatar
Top 20Real User

We also use firewalls from FortiGate and Palo Alto and they're built with technology to make them next-generation firewalls. Juniper utilizes a router OS and includes enhancements to make it a firewall. But FortiGate and Palo Alto are full-on firewalls because they are built from scratch with features which are specific to firewalls. Juniper needs to enhance the solution so that it is more powerful. They need to update the administrative tools to create an easier admin experience. An average administrator would find it easier to configure if they could use https rather than the command line interface to do so. In addition, it would be more powerful if Juniper brought out a security product other than firewalls, like anti-spam, endpoint protection, etc. Customers who want to deploy security solutions are not just thinking about firewalls. They're thinking about security across their environment. If Juniper could give me a security solution, beyond the firewall, that integrates with the firewall, that would be helpful. Other products have built a security fabric. So if a customer already uses one of their solutions, like a firewall, they will be thinking about integrating with that vendor's other products. If there is more than just a firewall solution, they will use that same vendor's products throughout the security environment. A security fabric is more powerful than just blocking via network parameters. Juniper should have an end-to-end solution, from the endpoint to the network level. It would provide a more powerful security solution to the customer. Customers are looking for a holistic security solution.

2019-03-06T07:41:00Z
author avatar
Real User

The GUI needs to be easier and more helpful for users who don't have security experience. They need to add WAF management to the tool, as competitors already have it as part of their offerings. This feature is future of protecting enterprise solutions.

2019-02-26T08:25:00Z
author avatar
Real User

The device could be more user-friendly.

2019-02-19T12:29:00Z
author avatar
Real User

We are finding that the UTM features which is required (like an antivirus or URL filtering) are not available. We are now looking for the "Next Generation" of firewall protection. We need to be less vulnerable to attacks. In addition, we would really like to see an automated policy feature added.

2018-11-25T07:59:00Z
author avatar
User

* Correct the bugs in the current version. * Help customers more with its configuration so they can feel safer. We tried configuring the IDS for more than four months, but it did not work properly.

2018-09-20T19:49:00Z
author avatar
Real User

The CLI is verbose. You have to say a lot to do a little. I don't like that part of it. Cisco's command syntax seems to be a good bit more concise. When you're trying to get something done, you don't want to have to type a bunch. I wish there was a quicker way to configure through the CLI. I know all the tricks of hitting spacebar etc. to finish the command, and the context tricks of going further in. But it just reminds me of an older operating system, like VAX/VMS. It's just very verbose. Maybe this is where the Space Security Director product comes in, but we aren't quite using the Security Director in Space to its fullest yet.

2018-08-23T08:15:00Z
author avatar
Real User

I would like to see endpoint control and endpoint testing security. The GUI needs to be easier to handle.

2018-08-06T08:33:00Z
author avatar
Real User

I would like them to add a dashboard because it's difficult to operate. The product only has basic features.

2018-08-01T07:08:00Z
author avatar
Top 5Real User

Third-party support for Juniper is a lot less than Cisco. This is no surprise, but a definite consideration if you are expecting to use a lot of third party support. In my guesstimate, for every 100 Cisco shops, you will find one Juniper shop.

2018-05-15T20:16:00Z
author avatar
User

It could improve areas which need high performance.

2018-05-15T01:29:00Z
author avatar
Real User

It needs better interoperability with Cisco gear.

2017-12-18T07:21:00Z
Learn what your peers think about Juniper SRX. Get advice and tips from experienced pros sharing their opinions. Updated: October 2021.
542,608 professionals have used our research since 2012.