| Specifications |
|
| Software Specifications |
| Routing Protocols |
• IPv4, IPv6, ISO, Connectionless Network Service (CLNS)
• Static routes
• RIP v1/v2
• OSPF/OSPF v3
• BGP with Route Reflector
• IS-IS
• Multicast: IGMP v1/v2, PIM SM/DM/SSM, Session Description Protocol (SDP), DVMRP, MSDP, RPF
• Encapsulation: VLAN, PPP, Frame Relay, HDLC, serial, MLPPP, MLFR, PPPoE
• Virtual routers
• Policy-based routing, source-based routing
• Equal-cost multipath (ECMP)
|
| QoS Features |
• Support for 802.1p, DSCP, EXP
• Classification based on VLAN, DLCI, interface, bundles, or multifield filters
• Marking, policing, and shaping
• Classification and scheduling
• Weighted random early detection (WRED)
• Guaranteed and maximum bandwidth
• Ingress traffic policing
• Virtual channels
• Hierarchical shaping and policing
|
| Switching Features |
• ASIC-based Layer 2 forwarding
• MAC address learning
• VLAN addressing and IRB support
• Link aggregation and LACP
• LLDP and LLDP-MED
• STP, RSTP, MSTP
• MVRP
• 802.1X authentication
|
| Firewall Services |
• Stateful and stateless firewall
• Zone-based firewall
• Screens and DDoS protection
• Protection from protocol and traffic anomaly
• Integration with Pulse Unified Access Control (UAC)
• Integration with Aruba Clear Pass Policy Manager
• User role-based firewall
• SSL Inspection (Forward-proxy)
|
| Network Address Translation (NAT) |
• Source NAT with Port Address Translation (PAT)
• Bidirectional 1:1 static NAT
• Destination NAT with PAT
• Persistent NAT
• IPv6 address translation
|
| VPN Features |
• Tunnels: Site-to-Site, Hub and Spoke, Dynamic Endpoint, AutoVPN, ADVPN, Group VPN (IPv4/IPv6/Dual Stack)
• Juniper Secure Connect: Remote access / SSL VPN
• Configuration payload: Yes
• IKE encryption: Prime, DES-CBC, 3DES-CBC, AES-CBC, AES-GCM, SuiteB
• IKE authentication: MD5, SHA-1, SHA-128, SHA-256, SHA-384
• Authentication: PSK and PKI (X.509)
• IPsec: AH / ESP
• IPsec auth: hmac-md5, hmac-sha-196, hmac-sha-256
• IPsec encryption: Prime, DES-CBC, 3DES-CBC, AES-CBC, AES-GCM, SuiteB
• Perfect forward secrecy, anti-replay
• IKEv1 / IKEv2
• Dead peer detection (DPD), VPN monitoring
• GRE, IP-in-IP, MPLS VPNs
• Application/bandwidth usage reporting, auto installation, debug tools
• Zero-Touch Provisioning with Contrail Service Orchestration
|
| Network Services |
• DHCP client/server/relay
• DNS proxy, DDNS
• Real-time performance monitoring (RPM) and IP monitoring
• J-Flow monitoring
• Bidirectional Forwarding Detection (BFD)
• TWAMP
• IEEE 802.3ah Link Fault Management (LFM)
• IEEE 802.1ag Connectivity Fault Management (CFM)
|
| High Availability Features |
• VRRP
• Stateful high availability
• Dual box clustering
• Active/passive and active/active
• Config and session synchronization
• Device/link detection
• In-Band Cluster Upgrade (ICU)
• Dial on-demand backup interfaces
• IP monitoring with route and interface failover
|
| Management, Automation, Logging, and Reporting |
• SSH, Telnet, SNMP
• Smart image download
• Juniper CLI and Web UI
• Mist AI (Simplified management, WAN Assurance)
• Security Director / Security Director Cloud
• Juniper Secure Edge
• Python
• Junos OS event, commit, and OP script
|
| Advanced Routing Services |
• Packet mode
• MPLS (RSVP, LDP)
• CCC, TCC
• L2/L3 MPLS VPN, pseudowires
• VPLS, NG-MVPN
• MPLS traffic engineering, MPLS fast reroute
|
|
Application Security Services (advanced security services subscription licenses) |
• Application visibility and control
• Application-based advanced policy-based routing (APBR)
• Application-based link monitoring and switchover with AppQoE
|
| Threat Defense and Intelligence Services |
• Intrusion prevention
• Antivirus
• Antispam
• Category/reputation-based URL filtering
• Botnet protection (command and control)
• Adaptive enforcement based on GeoIP
• Juniper Advanced Threat Prevention (zero-day detection/blocking)
• Adaptive Threat Profiling
• Encrypted Traffic Insights
• SecIntel threat intelligence
|
| Hardware Specifications |
| Total onboard ports |
8x 1GbE |
| Onboard RJ-45 ports |
6x 1GbE |
| Onboard SFP ports |
2x 1GbE |
| MACsec-capable ports |
2x 1GbE |
| Console (RJ-45 + miniUSB) |
1 |
| USB 3.0 ports (Type-A) |
1 |
| Memory and Storage |
| System memory (RAM) |
4 GB |
| Storage |
8 GB |
| Dimensions and Power |
| Form factor |
Desktop |
| Size (WxHxD) |
12.63 x 1.37 x 7.52 in (32.08 x 3.47 x 19.10 cm) |
| Weight (device and PSU) |
4.38 lb (1.98 kg) |
| Redundant PSU |
No |
| Power supply |
AC (external) |
| Average power consumption |
24.9 W |
| Average heat dissipation |
85 BTU/h |
| Maximum current consumption |
0.346 A |
| Acoustic noise level |
0 dB (fanless) |
| Airflow/cooling |
Fanless |
| Environmental, Compliance, and Safety |
| Operational temperature |
-20°C to 60°C (-4°F to 140°F) |
| Nonoperational temperature |
-20°C to 70°C (-4°F to 158°F) |
| Operating humidity |
10% to 90% noncondensing |
| Nonoperating humidity |
5% to 95% noncondensing |
| MTBF |
44.5 years |
| FCC classification |
Class A |
| RoHS compliance |
RoHS 2 |
| FIPS 140-2 |
Level 2 (Junos 19.2R1) |
| Common Criteria certification |
NDPP, VPNEP, FWEP, IPSEP (based on Junos 19.2R1) |
| Performance and Scale |
| Routing (packet mode, 1,518B) |
1,500 Mbps |
| Routing (packet mode, IMIX) |
800 Mbps |
| Stateful firewall (IMIX) |
600 Mbps |
| Stateful firewall (1,518B) |
1,900 Mbps |
| IPsec VPN (IMIX) |
116 Mbps |
| IPsec VPN (1,400B) |
336 Mbps |
| Application visibility and control |
500 Mbps |
| Recommended IPS |
200 Mbps |
| Next-generation firewall |
226 Mbps |
| Secure Web Access firewall |
171 Mbps |
| Route table size (RIB/FIB) |
256,000 / 256,000 |
| Maximum concurrent sessions |
64,000 |
| Maximum security policies |
1,000 |
| Connections per second |
5,000 |
| NAT rules |
1,000 |
| MAC table size |
15,000 |
| IPsec VPN tunnels |
256 |
| Remote access/SSL VPN users (concurrent) |
25 |
| GRE tunnels |
256 |
| Maximum security zones |
16 |
| Maximum virtual routers |
32 |
| Maximum VLANs |
1,000 |
| AppID sessions |
16,000 |
| IPS sessions |
16,000 |
| URLF sessions |
16,000 |