Example: biology

Data Sheet vSRX VIRTUAL FIREWALL Description

VSRX VIRTUAL FIREWALLDATASHEETP roduct DescriptionData centers increasingly rely on server virtualization to deliver services faster and moreefficiently than ever before. The virtualized data center, however, introduces newchallenges that require additional security considerations beyond those needed to securephysical machines (VM) can be highly dynamic and elastic in a virtualized data center, withfrequent additions, moves, and changes. These frequent changes complicate the ability toattach security policies to a VM instantiation and track security policies with VM movementto ensure continued regulatory compliance. In short, the dynamic and flexible nature ofvirtualization can easily lead to a loss of visibility and and security professionals must perform a delicate balancing act, delivering thebenefits of virtualization and cloud technologies without undermining the organization'ssecurity.

automatically create security intelligence threat feeds based on who and what is currently attacking the network. Table 5. vSRX Services Gateway Key Performance Metrics Performance and Capacity. 1. VMware KVM. vCPUs 2 5 9 17 2 5 9 17 Memory 4 GB 8 GB 16 GB 32/64 GB 4 GB 8 GB 16 GB 32/64 GB Firewall throughput, large packet (1514B)

Tags:

  Attacking

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Data Sheet vSRX VIRTUAL FIREWALL Description

1 VSRX VIRTUAL FIREWALLDATASHEETP roduct DescriptionData centers increasingly rely on server virtualization to deliver services faster and moreefficiently than ever before. The virtualized data center, however, introduces newchallenges that require additional security considerations beyond those needed to securephysical machines (VM) can be highly dynamic and elastic in a virtualized data center, withfrequent additions, moves, and changes. These frequent changes complicate the ability toattach security policies to a VM instantiation and track security policies with VM movementto ensure continued regulatory compliance. In short, the dynamic and flexible nature ofvirtualization can easily lead to a loss of visibility and and security professionals must perform a delicate balancing act, delivering thebenefits of virtualization and cloud technologies without undermining the organization'ssecurity.

2 This challenge can only be met by a security solution that can keep pace withevolving threats while matching the agility and scalability of virtualized and cloudenvironments without sacrificing reliability, visibility, and addresses these challenges head-on by extending the capabilities of the award-winning Juniper Networks SRX Series Firewalls to the VIRTUAL world with the vSRX VirtualFirewall. Juniper makes security easy by securing the cloud at every level: betweenapplications, between instances, and across by Juniper Networks Junos operating system, the vSRX delivers a complete andintegrated VIRTUAL security solution, including L4-L7 advanced security services, robustnetworking, and automated life cycle management capabilities for service providers andenterprises vSRX s automated provisioning capabilities allow network and security administratorsto quickly and efficiently provision and scale FIREWALL protection to meet the dynamic needsof virtualized and cloud environments.

3 By combining the vSRX with the power of JunosSpace Security Director, administrators can significantly improve policy configuration,management, and visibility into both physical and VIRTUAL assets from a standard, service providers and organizations deploying service-oriented applications in software,the vSRX s portfolio of virtualized network and security services supports a variety ofNetwork Functions Virtualization (NFV) use cases. The vSRX also supports JuniperNetworks Contrail, OpenContrail, and other third-party solutions, and can be integratedwith other next-generation cloud orchestration tools such as OpenStack, either directly orthrough rich Sheet 1 Product OverviewThe vSRX VIRTUAL Firewalldelivers a complete virtualfirewall solution, includingadvanced security, robustnetworking, and automatedvirtual machine life cyclemanagement capabilities forservice providers andenterprises.

4 VSRX empowerssecurity professionals to deployand scale FIREWALL protection inhighly dynamic download a trial version ofthe vSRX, including advancedsecurity services such as IPS,AppSecure, and contentsecurity, visit 1. vSRX Content Security Features and BenefitsFeatureFeature DescriptionBenefitsAntivirus Reputation-enhanced, cloud-based antivirus capabilities that detect and blockspyware, adware, viruses, keyloggers, and other malware over POP3, HTTP,SMTP, and FTP protocols Service provided either on-box or in the cloud Sophisticated protection from respected antivirus experts against malware attacksthat can lead to costly data breaches and lost productivityWeb filtering Enhanced Web filtering, including extensive category options (90+ categories)

5 And a real-time scorecard Protection against lost productivity and the impact of malicious URLs, as well ashelping to maintain network bandwidth for essential business trafficContentfiltering Effective inbound and outbound content filtering based on MIME type, fileextension, and protocol commands Protection against inadvertent or malicious file transmitting and malicious contenton the network to minimize the risk of compromise or data leakageAntispam Multilayered spam protection, up-to-date phishing URL detection, standards-basedS/MIME, Open PGP and TLS encryption, MIME type, and extension blockers Protection against advanced persistent threats perpetrated through socialnetworking attacks and the latest phishing scams with sophisticated e-mail filteringand content blockersArchitecture and Key ComponentsAdvanced Security ServicesImplementing nonintegrated, legacy systems built around traditionalfirewalls and individual standalone appliances and software is nolonger adequate to protect against today s sophisticated s advanced security suite enables users to deploy multipletechnologies to meet the unique and evolving needs of modernorganizations and the continually changing threat landscape.

6 Real-time updates ensure that the technologies, policies, and othersecurity measures are always vSRX delivers a versatile and powerful set of advanced securityservices, including content security, intrusion detection andprevention (IDP/IPS), and application control and visibility servicesthrough Juniper Networks SecurityThe vSRX includes comprehensive content security againstmalware, viruses, phishing attacks, intrusions, spam, and otherthreats with best-in-class antivirus, antispam, Web filtering, andcontent filtering features (see Table 1).Intrusion Prevention System (IPS)IPS for vSRX controls access to IT networks to protect systemsfrom attack by inspecting data and taking actions such as blockingattacks as they are developing and before they succeed orcreating a series of rules in the FIREWALL .

7 IPS tightly integratesJuniper s applications security features with the networkinfrastructure to further mitigate threats and protect against a widerange of attacks and vulnerabilities (see Table 2).Table 2. vSRX IPS Features and BenefitsFeatureFeature DescriptionBenefitsStateful signature inspectionSignatures are applied only to relevant portions of the network traffic determinedby the appropriate protocol false positives and offers flexible signature decodesMore than 65 protocol decodes are supported, along with more than 500 contextsto ensure proper protocol signature accuracy through the precise context of are more than 15,000 signatures for identifying anomalies, attacks, spyware,and are accurately identified and attempts to exploit knownvulnerabilities are normalizationReassembly, normalization.

8 And protocol decoding overcomes attempts to bypass other IPS detections by usingobfuscation protectionProtocol anomaly detection and same day coverage for newly found networks against any new policyThe Juniper Security Team identifies attack signatures as critical for the and maintenance are simplified while ensuring the highestnetwork traffic monitoringIPS monitoring includes active/active vSRX chassis included for active/active IPS captureIPS policy supports packet capture logging per can conduct further analysis of surrounding traffic and determineadditional steps to protect the VIRTUAL FIREWALL Datasheet2 Table 3. AppSecure for vSRX Features and BenefitsFeatureDescriptionBenefitAppTrac k Analyzes application data and classifies it based on risk level, zones, source, anddestination application usage to identify high-risk applications and analyze traffic patterns.

9 Improving network management and Creates application control policies to allow or deny traffic based on dynamicapplication or group security policy creation and enforcement based on applications rather thantraditional port and protocol Meters and marks traffic based on the application security policies set by traffic and limits and shapes bandwidth based on application information andcontext to improve overall Visibility and Control with AppSecureAppSecure is a next-generation application security suite for vSRXand SRX Series Firewalls that delivers threat visibility, protection,enforcement, and needing to understand how many users are accessingcloud-based applications like Facebook every day, or needing toknow what applications are using the most bandwidth, AppSecuredelivers powerful visibility and ongoing application tracking.

10 Withopen signatures, unique application sets can be monitored,measured, and controlled to tie closely to the organization sbusiness Advanced Threat PreventionJuniper Advanced Threat Prevention integrates with the vSRX toprovide dynamic, automated protection against known malware andadvanced zero-day threats, resulting in instantaneous responses(see Table 4).Security policies determine if a session can originate in one zoneand be forwarded to another zone. The vSRX receives packets andkeeps track of every session, every application, and every user. As aVM moves within a virtualized or cloud environment, it will stillsend packets to the vSRX for processing, continuouslycommunicating in a secure 1: vSRX session-based forwarding algorithmHigh Availability (HA)The vSRX provides mission-critical reliability, supporting chassisclustering for active/active and active/passive modes.