Datasheet
5
Customers can rapidly deploy integrated or external Web filtering using default
configurations based on the Websense database. Web filtering profiles can be customized
by using black lists or white lists, plus a number of predefined and user-defined categories.
Blocking Inbound Spam and Phishing Attacks
Juniper Networks has teamed up with Sophos to leverage their market-leading antispam
solution and reputation service for Juniper’s small-to-medium office platforms to help
limit unwanted emails and the potential attacks they carry. Installed on the Juniper
Networks firewall/VPN gateway, the antispam engine filters incoming email from known
spam and phishing users, acting as a first line of defense. When a known malicious email
arrives, it is blocked and/or flagged so that the email server can take appropriate action.
Integrated antispam is available on the entire SRX Series for the branch.
Boosting Security by Dividing the Network into Multiple
Network Segments
Technologies in the Juniper Networks integrated firewall/VPN, and secure router security
solutions enable users to segment their network into many separate compartments, all
controlled through a single appliance. Administrators can simply segment traffic bound
for different destinations, or they can further divide the network into distinct, secure
segments with their own firewalls and separate security policies.
The firewall/VPN devices support the following virtualization technologies:
• Security Zones: Supported on every product, security zones represent virtual sections of
the network, segmented into logical areas. Security zones can be assigned to a physical
interface or, on the larger devices, to a virtual system. When assigned to a virtual
system, multiple zones can share a single physical interface which lowers ownership
costs by effectively increasing interface densities. Zone policy visibility and integration
with vGW Virtual Gateways.
• Logical Systems (LSYS): Available on the Juniper Networks integrated security
services gateways, logical systems are an additional level of partitioning that creates
multiple independent virtual environments, each with its own set of users, firewalls,
VPNs, security policies, and management interfaces. By providing administrators with
the ability to quickly segment networks into multiple secure environments managed
through a single device, LSYS enables network operators to build multi-customer
solutions with fewer physical firewalls and reduced administrative attention. This
reduces both capital and operational expenses.
Domain 1
Zone A Zone N
VLAN 1 VLAN 1VLAN N VLAN 1 VLAN N
Domain N
Firewall/VPN
Zone A Zone N
VLAN N VLAN 1 VLAN N
INTERNET
Networks are segmented into hierarchies of secure compartments using virtual technology.








