0% found this document useful (0 votes)
94 views4 pages

Juniper SRX vs. Palo Alto NGFWs Analysis

Juniper vS palo alto

Uploaded by

Adli Hakim
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
94 views4 pages

Juniper SRX vs. Palo Alto NGFWs Analysis

Juniper vS palo alto

Uploaded by

Adli Hakim
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Juniper SRX vs.

Palo Alto Networks Next-Generation Firewalls

Founded in 1996 as an ISP router manufacturer, Juniper entered Juniper’s Strengths


the security market in 2004 with the acquisition of NetScreen.* • Strongest routing features: routing, switching, MPLS, and EVPN. As secure router, it beats
ABOUT JUNIPER NETWORKS

Juniper’s SRX firewalls, available as branch, enterprise, or service everything in the industry.
provider (SP) appliances, run on Junos OS, like the company’s MX
• Service module for Juniper MX routing platform running NGFW code. Very attractive for SP
Series routers.
customers looking for specific mission: CGNAT and IPSec VPN.
SPs remain Juniper’s primary focus, with most products built for
• Strong brand recognition among network teams. Can be very strong in SP/DC projects.
large-scale deployments and little attention paid to enterprise
requirements. Even though Juniper continues to struggle in secu- • SRX shares network features with MX Series routers and EX series switches. All run on
rity, with revenue in this area declining year over year, it remains a Junos, meaning they can push “Single OS” story.
strong incumbent that can tug security into larger network deals, • Junos is perceived as mature and stable. Data and control plane are separate.
similar to Cisco.
• Customers like the powerful CLI and API functions (OpenConfig and more).
In 2015, Juniper sold its Pulse VPN technology to a private equity
• Great automation capabilities (Python on box), but manual stitching is required.

STRENGTHS AND WEAKNESSES


firm. It exists today as Pulse Secure without any relationship to
Juniper. In 2019 Juniper acquired WLAN vendor Mist and saw major • Very high L4 throughput/scale without advanced security features, including “Express-
success in enterprise. In 2020 Juniper acquired SD-WAN startup 128 Path” for accelerating established connections.
Technology that competes with their NGFW based SD-WAN. • Mist AI (Jarvis) integration for branch models.
• Branch models with high port density (up to 16x1GE + 4x10GE) and modularity.
*NetScreen to SRX migration was a giant mess.
• (LTE, xDSL, 802.11ac Wave 2 Wi-Fi).
Juniper’s Weaknesses
• Security is not their game. There is no vision or thought leadership for public cloud/SaaS
or endpoint security. Level of funding: “afterthought.” Lack of feature depth: mostly “Us-
Too” approach.
• Classic Serial Architecture: Performance is affected by number of services used and each
service configuration. Accumulated performance drop is massive (~50% or more).
• Security features via OEM: AV (Sophos and Avira; although there’s a native option in latest
releases), URLF (Websense), and App-ID (vendor unknown). None share findings with
Juniper’s threat intelligence platform.
• Central management is a two-piece solution: Junos Space and Security Director (an app
running on top of Junos Space). There are still functional differences between on-board
(J-Web) and central administration via Security Director. Multiple UIs create administra-
tive overhead and opportunities for misconfiguration.
• Space offers limited local log storage and reporting capabilities (no SLR/BPA) and no visi-
bility into threat intelligence (i.e., no AutoFocus equivalent). Security Director Insights VM
required as log server to scale.
• Somewhat convoluted licensing: Depends on model. Remote VPN license is per user.
• 3 VPN client option with no feature parity: 1 OEM, 1 third party, and one native.
• Only one branch model with redundant power supply.
Figure 1: SRX architecture serial packet flow

© 2023 Palo Alto Networks, Inc. | Juniper SRX vs. Palo Alto Networks NGFWs | Confidential and Proprietary Information: For internal use and authorized partners under NDA with Palo Alto Networks only. 1
Juniper SRX vs. Palo Alto Networks Next-Generation Firewalls

Power of the Portfolio


The Palo Alto Networks portfolio of products offers simple yet robust security capabilities in a single plat-
form that Juniper, in many cases, has no answer for. The gaps in Juniper’s security offering are staggering.
Additionally, our ability to enable subscriptions from any of our deployment methods and manage in a uni-
fied policy, all on a single firewall, is unmatched. Juniper has some features in Security Director and others
in Contrail or Junos Space.

Capability Examples Palo Alto Networks Juniper

CN- PA- VM-


Firewall Series Series Series SRX, vSRX, cSRX

Intrusion Detection and AV TP IDP and UTM

URL Filtering UF Websense

Sandbox Detection WF Sky ATP

DNS Security DNS Only DGA/DNS tunnel detection (via SKY ATP)

IoT
Only device discovery and manual
IoT Security policy enforcement (via SKY ATP)

Data Loss Prevention (DLP) DLP Only as part of SASE

Juniper Secure Connect/NCP Remote Access/


Remote Access for Users GP
Pulse VPN Client (all have different features)

Security as a Service (SaaS) Juniper Secure Edge

SaaS Security Only as part of SASE

Classic VPN fabric SD-WAN


SD-WAN
SD-

(similar to PAN-OS SD-WAN)


WAN

White-labeled, third-party service No solution; requires a third party to cover

© 2023 Palo Alto Networks, Inc. | Juniper SRX vs. Palo Alto Networks NGFWs | Confidential and Proprietary Information: For internal use and authorized partners under NDA with Palo Alto Networks only. 2
Juniper SRX vs. Palo Alto Networks Next-Generation Firewalls

Table 1: Feature Comparison Matrix


1. Position Juniper SRX as a “Secure Router”
Juniper will try to avoid deep security discussions, instead highlighting Feature PAN-OS 11 Junos 22.4
the advanced network features of Junos (e.g., BGP/OSPF/IS-IS, QoS,
switching). SEs will downplay the areas where SRX lacks and steer the Unknown Threat Yes; ML Inline, Very limited Encrypted
conversation toward Juniper’s strong suits or shape around “we sup- Prevention ATP, Adv URLF Traffic Insights
port every checkbox of NGFW” conversation.
Single-Pass Architecture
Counter by emphasizing the importance of application-level visibility No (Each feature degrades
for Predictable Yes
and unknown threat prevention. Demonstrate actual security misses performance)
Performance
with an SLR. How many advanced network features and what CPS does
an enterprise customer really need? No (Router OS with bolt-
Point out that security functions on SRX are managed by a different Natively Engineered on security capabilities;
Yes
UI (Security Director on top of Junos Space). It is not as simple as an NGFW AppControl, URLF,
MX router. AntiSpam are third party)
JUNIPER SALES PLAYS

2. Avoid a Proof of Concept ESXi, NSX, Hyper-V, KVM, ESXi, NSX, KVM,
Virtual NGFW Deployment
Juniper will try to avoid a PoC, but if forced into one, will likely demon- ACI, GCP, AWS, Azure, Hyper-V, AWS, Azure,
Options
strate Space/Security Director and tell a story about automation using AliCloud, Oracle, vCloud Nutanix, CGP
APIs and CLI.
Ask the customer if Juniper showed demos or a live deployment. Push Consistent Management Yes (On-board UI and No (J-Web and Security
for an on-site PoC, and demonstrate the consistency and simplicity of UI Across FW Product Line Panorama) Director)
PAN-OS and Panorama.
Juniper gives customers a lot of automation opportunities but little DNS Security Full support Only DGA and DNS tunneling
guidance on implementation. Do a live demo of our automation capa-
bilities. Don’t let Juniper cherry-pick network-centric use cases. Insist Cloud-based hash lookup
on enabling all security features. Natively Integrated AV On-board engine with local cash (Hash size
depends on model)
3. Sell on Datasheet Numbers
Juniper will try to sell customers on their IMIX L4 firewall performance Natively Integrated URL
Yes No (Forcepoint/Websense)
numbers. “Turn everything on” is a Juniper SE’s nightmare. Filtering
Point out the total lack of security features in this mode (“SRX delivers
AD, LDAP, XML API, syslog,
malware really fast.”). Remind customers that Juniper’s ExpressPath Limited to LDAP/RADIUS/
User Identification port mapping, XFF headers,
will route packets with no inspection after initial session setup. TACACS+
client probing
Utilize third-party results like the [Link] Enterprise Firewall
test that shows Juniper’s SRX 4600 obtaining an average of 7 Gb on a Only with SASE; not
FW that is supposedly rated for 60 Gb. Inline SaaS/DLP Yes available on standalone
NGFW

Credential Theft
Yes No
Prevention

© 2023 Palo Alto Networks, Inc. | Juniper SRX vs. Palo Alto Networks NGFWs | Confidential and Proprietary Information: For internal use and authorized partners under NDA with Palo Alto Networks only. 3
Juniper SRX vs. Palo Alto Networks Next-Generation Firewalls

Educate the Customer on the Importance of Security “You don’t need advanced security features.
Stress the importance of advanced security features like App-ID, Why pay a premium?”
Threat Prevention, DNS Security, and WildFire. Get the customer Juniper claims most of our customers do not use advanced security fea-
to create an SLR and SaaS report. Juniper cannot match this level of tures, such as App-ID, Threat Prevention, and WildFire. In fact, App-ID is
visibility, and it will open your prospect’s eyes to see what is really enabled by default and the attach rate of Threat Prevention is above 80%.
happening in their network. Companies need a Zero Trust strategy to prevent successful cyberattacks
Demonstrate Our ML-Powered Next-Generation Fire- and cannot afford blind spots in their networks.
wall. How Will You Prevent Unknown Threats? “We don’t trust other security vendors to build great net-
Point out that almost all of Juniper’s security technology comes from work stacks. We run the internet.”
other vendors. How long does it take to get a URL recategorized when Juniper wants to use its strong brand in routing/switching to sell security.
Juniper needs to contact Websense? What happens if Juniper switches In reality, it is more difficult to get security right than to get networking
vendors? Automation can’t turn unknown malware into prevention with right. Networks rely on established standards and protocols while cyber-
that many disjointed third parties. Show how our ML-powered security security requires a lot of R&D and specialized knowledge to successfully

OBJECTION HANDLING
on TP, URLF, and now DNS Security are all natively integrated into all fight unknown threats.
our products and how prevention is automated with real-time updates.
“Junos OS is carrier-grade and powers the internet.”
HOW TO COMPETE

Leverage Our Strong Cloud Focus Juniper will say SRX offers the same quality/stability as MX Series routers
Juniper does not have an answer for the customer’s journey to the cloud. because it’s running the same Junos train. That’s not exactly true. There’s
vSRX is only supported on AWS and Azure. Juniper has no CWPP or CSPM a core functionality overlap but security-specific features are plat-
offering. Position inline SaaS, Cortex, and Prisma Cloud. form-specific. There are cases when there’s a feature gap even within the
Push for a Proof of Concept SRX product line.
Set the table for the PoC and put a focus on security features. All features, Junos Space requires a separate application, Security Director, to be
including logging, need to be enabled. Show the feature parity between able to manage SRX firewalls. SRX devices operating as routers are not
PAN-OS, Panorama, and the command line. Make sure Juniper demon- manageable under Junos Space. Sky ATP (a cloud sandbox) and JATP (an
strates the SRX GUI as well. on-premises sandbox) have completely separate UIs.
Make sure every feature on the box is enabled. “Junos OS had an API before it had a CLI.”
Show the Ease of Use of PAN-OS and Panorama Juniper claims to offer the best automation capabilities, but it is mostly
DIY and not ready for enterprise use. There are no templates or docu-
Space and Security Director have functional limitations and poor visibili-
mented best practices. We have automation either built in (e.g., WildFire)
ty. Our user experience is consistent across local and central manage-
or in the form of APIs, DAG/EDLs, HTTP Log Forwarding, auto-tagging,
ment. Show the ACC and reporting capabilities. Demonstrate the power
or via libraries (pan-python, pandevice). With 10.1, we also take away a
or Policy Optimizer. Long-term Juniper customers tend to use the CLI
major lockout Juniper tried to plant with our support of OpenConfig and
and API for managing firewalls. Show that we have the same capabilities.
scheduled policy pushes.

© 2023 Palo Alto Networks, Inc. | Juniper SRX vs. Palo Alto Networks NGFWs | Confidential and Proprietary Information: For internal use and authorized partners under NDA with Palo Alto Networks only. 4

You might also like