Try our new research platform with insights from 80,000+ expert users
it_user738864 - PeerSpot reviewer
Senior Network Engineer at a tech services company with 51-200 employees
Real User
Feb 26, 2018
Zones make it easy to logically organize security polices
Pros and Cons
  • "Security policies in combination with zones: It is very easy to organize the security polices in a logical structure."
  • "CLI: Junos CLI is very easy to use, and it is also very easy to find back items in the configuration and to change them."
  • "Commit: You can update the whole configuration without affecting the production. The new configuration will be loaded once the command "Commit" is submitted. You can also do a Commit confirmed to automatically roll back to the previous config after X minutes."
  • "The visibility/reporting could be better. To see something, you have to export the log to a syslog and then process with another product."

How has it helped my organization?

Thanks to the well-structured and organized security policies, we decreased operations time to create/update/delete our security policies.

What is most valuable?

Security policies in combination with zones: It is very easy to organize the security polices in a logical structure.

CLI: Junos CLI is very easy to use, and it is also very easy to find back items in the configuration and to change them.

Commit: You can update the whole configuration without affecting the production. The new configuration will be loaded once the command "Commit" is submitted. You can also do a Commit confirmed to automatically roll back to the previous config after X minutes. 

What needs improvement?

The visibility/reporting could be better. To see something, you have to export the log to a syslog and then process with another product.

For how long have I used the solution?

More than five years.
Buyer's Guide
Juniper SRX Series Firewall
December 2025
Learn what your peers think about Juniper SRX Series Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,425 professionals have used our research since 2012.

What do I think about the stability of the solution?

We have used it for years without any stability issues.

What do I think about the scalability of the solution?

We haven't encountered scalability issues.

How are customer service and support?

Technical support is pretty good. I would rate it eight out of 10.

Which solution did I use previously and why did I switch?

I previously used a Netscreen ISG1000 firewall. I switched because the ISG was end-of-life and Netscreen was bought by Juniper.

How was the initial setup?

Initial setup was complex because Junos is totally different than ScreenOS. But with some introductory courses and some googling it becomes much easier.

What's my experience with pricing, setup cost, and licensing?

I’m just the tech, I didn’t take part in the price negotiation. I would say about $20,000 for a SRX650 with IDP licence.

Which other solutions did I evaluate?

No, we didn't evaluate other options. This was a natural way for us to migrate from ISG to SRX.

What other advice do I have?

Be sure you know what you are looking for. The SRX650 is a perfect product for a small datacenter, not for a branch office where you need lots of visibility.

Implement your structure (zones) first, on paper, before starting to configure it.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Senior Network and Security Consultant, JNCIE-SEC#408 at a financial services firm with 501-1,000 employees
Real User
Jan 25, 2018
Improves our operational performance and stability; there are no outages
Pros and Cons
  • "​It's a reliable firewall and very stable, for both the hardware and applications it is stable."
  • "It'sa very secure device, it has good attack prevention capabilities using UTM."

    How has it helped my organization?

    The greatest improvement we have seen is in operational performance and operational stability. There are no outages.

    What is most valuable?

    • It's a reliable firewall and very stable, for both the hardware and applications it is stable. 
    • It's very powerful. 
    • It's also a very secure device, it has good attack prevention capabilities using UTM.
    • It's user-friendly with a good UI.
    • It has powerful CLI.

    What needs improvement?

    It's not 100%, it's not a perfect product, some points need to be adjusted, need to be enhanced.

    For how long have I used the solution?

    More than five years.

    What do I think about the stability of the solution?

    There have been no issues with this product.

    What do I think about the scalability of the solution?

    It's a very scalable product.

    How are customer service and technical support?

    I think they have professional support. Support is really good, they are professional engineers.

    Customer support is very good.

    Which solution did I use previously and why did I switch?

    I used Cisco, and Palo Alto, and used McAfee. As a consultant, a systems integrator, if customers go to SRX it's because of its features and the stability of the product. It's the most stable product.

    How was the initial setup?

    It was very straightforward, very clear.

    Which other solutions did I evaluate?

    Other than Palo Alto, StrongSoft is very stable. Cisco Firepower is very unstable.

    What other advice do I have?

    I can say for, that for a datacenter, and for price, first I appreciate Palo Alto and then I appreciate Juniper, more than the others.

    Support for Juniper is best, better than Palo Alto, but Palo Alto is more powerful. And there is a big difference in pricing.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Juniper SRX Series Firewall
    December 2025
    Learn what your peers think about Juniper SRX Series Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
    879,425 professionals have used our research since 2012.
    PeerSpot user
    Senior Network Analyst at a energy/utilities company with 10,001+ employees
    Real User
    Jan 25, 2018
    Large total throughput, and we are able to change configurations without downtime
    Pros and Cons
    • "The rollback option and Commit Confirmed are great features. They give us the security to change configurations without downtime."
    • "It would be good if Junos had "unique commands" between all hierarchical levels, discarding the use of the "Run" command."

    How has it helped my organization?

    • Manipulation of rules
    • Flexibility in day-by-day use

    What is most valuable?

    Junos is the best OS for networks. It is very powerful and flexible.

    The rollback option and Commit Confirmed are great features. They give us the security to change configurations without downtime.

    What needs improvement?

    It would be good if Junos had "unique commands" between all hierarchical levels, discarding the use of the "Run" command.

    The robustness of Linux on top of Junos can be more effective after power down.

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    No stability issues.

    What do I think about the scalability of the solution?

    No scalability issues.

    How are customer service and technical support?

    High level of technical support.

    Which solution did I use previously and why did I switch?

    We used Fortinet, and changed to Juniper to use Junos.

    How was the initial setup?

    Easy.

    What's my experience with pricing, setup cost, and licensing?

    Pricing is very good, not expensive.

    What other advice do I have?

    We use the SRX1500 with Junos 15.1X49-D75.5. 

    I rate the product 10 out of 10. It is very strong and Junos is very powerful. The total throughput is very large.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    PeerSpot user
    ICT System Specialist at a comms service provider with 1,001-5,000 employees
    Real User
    Dec 22, 2017
    Provides good routing and high performance of the data center
    Pros and Cons
    • "It provides good routing and high performance of the data center."
    • "The web interface on Juniper SRX is just a short conversion from Junos OS CLI; this is not very suitable for users with little expertise/"

    What is our primary use case?

    One solution is data center Firewall and also we use this solution for protection our service GI + Triple Play

    How has it helped my organization?

    It provides good routing and high performance of the data center. It solves protecting our datacenter, separate networks and protect data center with FW policies + DPI

    What is most valuable?

    The routing feature is most valuable, because SRX is the best enterprise router. SRX has complete MPLS service features with L3VPN, VPLS, EVPN. You can also combine Router and FW in one box, with selective packet filter to bypass flow engine and set traffic to packet mode.

    What needs improvement?

    Web management needs to improve. The web interface on Juniper SRX is just a short conversion from Junos OS CLI; this is not very suitable for users with little expertise.

    But Juniper has complete MGMT for managing SRX devices and other Juniper devices. it' s called Junos Space with APP security director for security devices. It's good, but there is space for improvment.


    What do I think about the stability of the solution?

    There were some stability issues.

    What do I think about the scalability of the solution?

    There are not many scalability issues experienced.

    How are customer service and technical support?

    I would give the technical support an eight out of 10 rating.

    Which solution did I use previously and why did I switch?

    Previously, we were using the old Juniper ScreenOS, we switched due to end-of-support. I have also expertise with Cisco ASA, Cisco Firepower, Checkpoint R80.10, Dell Sonicwall, Fortinet.

    How was the initial setup?

    The setup was very complex, e.g., if you are beginner.

    What about the implementation team?

    We implement is by our self with team in-house.

    What's my experience with pricing, setup cost, and licensing?

    The prices are very good as compared to other vendors.

    Which other solutions did I evaluate?

    We looked at Cisco, FortiGate, Palo Alto

    What other advice do I have?

    It is a very good router with firewall.

    Disclosure: My company has a business relationship with this vendor other than being a customer. We are partners.
    PeerSpot user
    it_user701490 - PeerSpot reviewer
    Network | Firewall Engineer - Cloud Managed Services Delivery at a tech services company with 10,001+ employees
    Consultant
    Jul 15, 2017
    Having this design has greatly simplified the network and improved operational efficiency of support staffs

    What is most valuable?

    Valuable features for us include:

    • Routing: When firewalls can also perform full routing functionality, it helps to save cost on dedicated routing hardware.
    • High Availability (clustering): This is important to ensure service availability in the event of a node failure. These firewalls in HA mode consist of a primary and backup node, and provide redundancy such that if one of the nodes fails, the other node will take over.
    • Deep packet inspection (DPI) capabilities: Juniper SRX firewalls inspect packets as they traverse the firewalls and it goes beyond the traditional five tuples (source IP, destination IP, protocol, source port, and destination port) packet inspection by using the App-ID engine to inspect the protocol to correctly identify applications. It further rate-limits traffic, using the AppQoS features, based on specific types of applications.
    • IPSec VPN: This is crucial because it provides secure site to site connectivity between the DC and remote locations. Traffic traversing the secure link is protected from the prying eyes of unauthorized intruders or the man-in-the-middle.

    These features are valuable because they allow smooth operation of the business from a technology standpoint. Again, this is relative.

    How has it helped my organization?

    There was a business need to provide service high availability and system redundancy in addition to routing and firewalling at the internet edge and the datacenter core.

    Having this design has greatly simplified the network and improved operational efficiency of support staffs.

    What needs improvement?

    The GUI needs improving.

    For how long have I used the solution?

    We have been using the solution for seven years, providing design, implementation, support, and optimization.

    What do I think about the stability of the solution?

    We had a stability issue. Just like any other vendor, there are code stability issues on some of the platforms. However, there is always a recommended code version for each platform.

    What do I think about the scalability of the solution?

    We did not encounter issues with scalability, but this depends on the environment. The DC class firewalls can scale vertically or horizontally.

    How are customer service and technical support?

    They provide an awesome technical support.

    Which solution did I use previously and why did I switch?

    We used Cisco and CheckPoint. Routing functionality and advanced security services were limited.

    How was the initial setup?

    The setup was straightforward and simple once you understand the building blocks of Junos and firewalls.

    What's my experience with pricing, setup cost, and licensing?

    Pricing and licensing are very reasonable.

    Which other solutions did I evaluate?

    We evaluated Palo Alto and Fortinet.

    What other advice do I have?

    This product will offer maximum performance and capacity.

    It is extremely reliable depending on the business need. It supports full routing functionality and advanced security services like Application Security, Unified Threat Management (UTM), IPS, and threat intelligence.

    Advanced security services require a license.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user700152 - PeerSpot reviewer
    NOKIA Lead Engineer at a comms service provider with 10,001+ employees
    Real User
    Jul 13, 2017
    We are satisfied with its stability , but we don’t advise others to implement a cluster design other than Active/Passive.

    What is most valuable?

    Stateful inspection , IPSEC and NAT as per our customers' design. The boxes are used as SecGW, Gi and SGi Firewall, those are the features usually needed in 3G/4G context.

    How has it helped my organization?

    It improved in term of security.

    What needs improvement?

    Clustering fab interface doesn't support bandwidth aggregation. This limitation caused a huge design change in our network.

    For how long have I used the solution?

    I've used the solution for eight years.

    What do I think about the stability of the solution?

    Yes, some bugs in module restart and cluster failover, but without outage.

    What do I think about the scalability of the solution?

    Yes, fab interface doesn't support bandwidth aggregation

    How are customer service and technical support?

    9 out of 10.

    Which solution did I use previously and why did I switch?

    No, we didn't.

    How was the initial setup?

    Not complex.

    What's my experience with pricing, setup cost, and licensing?

    We didn’t use any other solutions so I can’t compare this to others.

    Which other solutions did I evaluate?

    No.

    What other advice do I have?

    We are satisfied with its stability , but we don’t advise others to implement a cluster design other than Active/Passive.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user697011 - PeerSpot reviewer
    Systems Engineer with 1,001-5,000 employees
    Real User
    Jul 5, 2017
    Consolidation combines routing, switching, and firewall services in one device

    What is most valuable?

    • Form factor: It is small, very nimble, and can be deployed in very small environments which do not have wiring closets.
    • Consolidation: It combines routing, switching, and firewall services in one device.
    • Stable OS: There is a one Junos release training for all the Juniper products, thus minimizes the training needed and enhances interoperability.
    • Open standards: The Juniper OS is based on the open standards and making it very interoperable in the mixed vendor environments.
    • Superior performance: This can be achieved by true separation of control and data plane, hence data plane inefficiencies do not affect the control plane and vice versa.
    • Cloud-enabled device: The SRX300 is cloud-ready and can be used to implement SDSN in micro-environments.

    How has it helped my organization?

    It has greatly reduced the network management functions by reducing the number of devices to manage (one vs three), and easy fault management using the new GUI.

    What needs improvement?

    Disaggregation (this is available in the box) should be improved to include software intelligence that is actionable.

    For how long have I used the solution?

    I have used this solution for about four and a half years.

    What do I think about the stability of the solution?

    There were no stability issues. It is a very stable and reliable product. It can run for several years without a single glitch.

    What do I think about the scalability of the solution?

    It is highly scalable for its target market.

    How are customer service and technical support?

    The technical support team is very co-operative and gives quick responses for the logged cases. A hundred percent of the logged cases have been resolved within the SLA period.

    Which solution did I use previously and why did I switch?

    We looked at MikroTik. However, more features such as the performance, scalability, and consolidation were available on the Juniper device.

    How was the initial setup?

    The initial setup was simple and can be done 100% via the GUI.

    What's my experience with pricing, setup cost, and licensing?

    The price per performance value is the best out there in the market. No licensing is needed for all the features apart from the security part, i.e., no licensing for extra services and VPN comes free in the base.

    Which other solutions did I evaluate?

    We evaluated the FortiGate 80 and 60 series and Cisco ASA 5500.

    What other advice do I have?

    The Juniper SRX300 is a stable and very reliable product, packed with a lot of capabilities that are not available in the competing products of the same range. I would highly recommend this product to anyone interested in implementing it.

    This box has it all and is more for the small-scale branch market. Packaged as an all-in-one routing, switching, and security solution, the SRX300 minimizes the need to deploy separate devices to perform these functions by leveraging on its consolidation, all coming with the carrier-grade capabilities.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user453054 - PeerSpot reviewer
    NCP Team Lead Secured Networks at a tech services company with 501-1,000 employees
    Consultant
    Jun 29, 2017
    One valuable feature is the reliability of the Junos OS. There is not a global database of objects.

    What is most valuable?

    One valuable feature is the reliability of the Junos OS. However, we did not make full use of the UTM functionality.

    How has it helped my organization?

    We have experienced more dependability.

    What needs improvement?

    Management: Junos Space Security Director is not great and there is no global database of objects.

    For how long have I used the solution?

    We have been using the product for about six years.

    What do I think about the stability of the solution?

    We did not encounter any issues with stability.

    What do I think about the scalability of the solution?

    The clustering of a maximum of two nodes limited some architectural options.

    How are customer service and technical support?

    Support is what the end customer buys. Unfortunately, it's not always from Juniper.

    Which solution did I use previously and why did I switch?

    We migrated from Juniper Screen OS to Junos. We are leaving Juniper now as their focus on security seems to have dropped.

    How was the initial setup?

    The setup was no more difficult than switching to any other firewall implementation.

    What other advice do I have?

    Be wary of Juniper's stake in the security realm. If they are ramping up again and are again competing with Check Point, Palo Alto, and FortiGate, then they are worthy of consideration. It is also worth your consideration if your network is Juniper based and you have a secondary firewall vendor.

    Disclosure: My company has a business relationship with this vendor other than being a customer. We are a partner.
    PeerSpot user
    Buyer's Guide
    Download our free Juniper SRX Series Firewall Report and get advice and tips from experienced pros sharing their opinions.
    Updated: December 2025
    Buyer's Guide
    Download our free Juniper SRX Series Firewall Report and get advice and tips from experienced pros sharing their opinions.