Overclock.net › Forums › Software, Programming and Coding › Networking & Security › Alternatives for Juniper SRX240?
New Posts  All Forums:Forum Nav:

Alternatives for Juniper SRX240?

post #1 of 7
Thread Starter 
I need a router/UTM that can deliver around 100k pps and pfSense can't reliably do it on full packet payloads. I'm pretty much set on getting an SRX240. Anyone know the Cisco equivalent or others I can look at before I pull the trigger?
Green Lantern
(18 items)
 
 
The Router 3.0
(14 items)
 
CPUMotherboardGraphicsGraphics
Intel i7 920 3.8GHz 1.25v HT Asus P6T XFX 5870 XFX 5780 
RAMHard DriveHard DriveOptical Drive
Kingston HyperX Intel X25-M 80GB G2 10Tb iSCSI Lite-On 1635S 
CoolingOSMonitorKeyboard
Corsair H50 Windows 7 x64 Ultimate Asus PA246 Logitech G15 v1 
PowerCaseMouseAudio
Corsair 1000HX Lian Li v1000+ Logitech G5 v1 Creative Audigy 2 ZS 
Other
Intel Pro/1000 PT Server Adapter 
CPUCPUMotherboardGraphics
Intel Xeon L5335 Intel Xeon L5335 Intel 5000P ATI ES1000 
RAMHard DriveOSPower
Elpida ECC WD20NPVT SmartOS HP 350W + Hot Spare 
Case
HP Proliant 380 G5 
CPUMotherboardRAMHard Drive
AMD Athlon 64 X2 3800+ nForce 3 250 2 GB 512MB CF To IDE 
OSCaseOtherOther
pfSense 2.0.1 x64 Shuttle XPC Intel PWLA8492MT PRO/1000 MT Dual Port Server A... Verizon FiOS 75/35Mbit 
  hide details  
Reply
Green Lantern
(18 items)
 
 
The Router 3.0
(14 items)
 
CPUMotherboardGraphicsGraphics
Intel i7 920 3.8GHz 1.25v HT Asus P6T XFX 5870 XFX 5780 
RAMHard DriveHard DriveOptical Drive
Kingston HyperX Intel X25-M 80GB G2 10Tb iSCSI Lite-On 1635S 
CoolingOSMonitorKeyboard
Corsair H50 Windows 7 x64 Ultimate Asus PA246 Logitech G15 v1 
PowerCaseMouseAudio
Corsair 1000HX Lian Li v1000+ Logitech G5 v1 Creative Audigy 2 ZS 
Other
Intel Pro/1000 PT Server Adapter 
CPUCPUMotherboardGraphics
Intel Xeon L5335 Intel Xeon L5335 Intel 5000P ATI ES1000 
RAMHard DriveOSPower
Elpida ECC WD20NPVT SmartOS HP 350W + Hot Spare 
Case
HP Proliant 380 G5 
CPUMotherboardRAMHard Drive
AMD Athlon 64 X2 3800+ nForce 3 250 2 GB 512MB CF To IDE 
OSCaseOtherOther
pfSense 2.0.1 x64 Shuttle XPC Intel PWLA8492MT PRO/1000 MT Dual Port Server A... Verizon FiOS 75/35Mbit 
  hide details  
Reply
post #2 of 7
What's your max spend?
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II MSI GTX560 Ti TwinFrozr II 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 OCZ Vertex 3 Western Digital Caviar Black Western Digital Caviar Green 
Hard DriveOptical DriveCoolingOS
Samsung 840 Pro Lite-On 24x DVD-RW CoolerMaster V8 Windows 8.1 Professional 
OSMonitorMonitorMonitor
Debian 7.1 Samsung S22B350H Samsung S22B350H Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II MSI GTX560 Ti TwinFrozr II 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 OCZ Vertex 3 Western Digital Caviar Black Western Digital Caviar Green 
Hard DriveOptical DriveCoolingOS
Samsung 840 Pro Lite-On 24x DVD-RW CoolerMaster V8 Windows 8.1 Professional 
OSMonitorMonitorMonitor
Debian 7.1 Samsung S22B350H Samsung S22B350H Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
post #3 of 7
Thread Starter 
My connection is 85/35Mbit. While any router I have can easily bench the throughput, they all lack in packet per second and new connection per second performance only hardware routers can give.

Do you have a hardware UTM in mind?
Green Lantern
(18 items)
 
 
The Router 3.0
(14 items)
 
CPUMotherboardGraphicsGraphics
Intel i7 920 3.8GHz 1.25v HT Asus P6T XFX 5870 XFX 5780 
RAMHard DriveHard DriveOptical Drive
Kingston HyperX Intel X25-M 80GB G2 10Tb iSCSI Lite-On 1635S 
CoolingOSMonitorKeyboard
Corsair H50 Windows 7 x64 Ultimate Asus PA246 Logitech G15 v1 
PowerCaseMouseAudio
Corsair 1000HX Lian Li v1000+ Logitech G5 v1 Creative Audigy 2 ZS 
Other
Intel Pro/1000 PT Server Adapter 
CPUCPUMotherboardGraphics
Intel Xeon L5335 Intel Xeon L5335 Intel 5000P ATI ES1000 
RAMHard DriveOSPower
Elpida ECC WD20NPVT SmartOS HP 350W + Hot Spare 
Case
HP Proliant 380 G5 
CPUMotherboardRAMHard Drive
AMD Athlon 64 X2 3800+ nForce 3 250 2 GB 512MB CF To IDE 
OSCaseOtherOther
pfSense 2.0.1 x64 Shuttle XPC Intel PWLA8492MT PRO/1000 MT Dual Port Server A... Verizon FiOS 75/35Mbit 
  hide details  
Reply
Green Lantern
(18 items)
 
 
The Router 3.0
(14 items)
 
CPUMotherboardGraphicsGraphics
Intel i7 920 3.8GHz 1.25v HT Asus P6T XFX 5870 XFX 5780 
RAMHard DriveHard DriveOptical Drive
Kingston HyperX Intel X25-M 80GB G2 10Tb iSCSI Lite-On 1635S 
CoolingOSMonitorKeyboard
Corsair H50 Windows 7 x64 Ultimate Asus PA246 Logitech G15 v1 
PowerCaseMouseAudio
Corsair 1000HX Lian Li v1000+ Logitech G5 v1 Creative Audigy 2 ZS 
Other
Intel Pro/1000 PT Server Adapter 
CPUCPUMotherboardGraphics
Intel Xeon L5335 Intel Xeon L5335 Intel 5000P ATI ES1000 
RAMHard DriveOSPower
Elpida ECC WD20NPVT SmartOS HP 350W + Hot Spare 
Case
HP Proliant 380 G5 
CPUMotherboardRAMHard Drive
AMD Athlon 64 X2 3800+ nForce 3 250 2 GB 512MB CF To IDE 
OSCaseOtherOther
pfSense 2.0.1 x64 Shuttle XPC Intel PWLA8492MT PRO/1000 MT Dual Port Server A... Verizon FiOS 75/35Mbit 
  hide details  
Reply
post #4 of 7
Cisco ASA 5520 is the equivalent to the Juniper SRX240.

There are some other questions you should be asking yourself first before jumping into the SRX. Do you need SSL VPN's? If so do not get the SRX. I moved my SRX's to my internal firewalls and relocated the ASA's to the perimeter. If you are really needing the SRX for Anti-Spam, Mail filtering and Web content...(per my Juniper Rep) you should jump up to the SRX550. If you are limited to the 240 due to cost, make sure you get the SRX240H...the SRX240B does not support Content Filtering, Anti-spam nor Anti virus... It will support IPS if I rem right when they sent me the wrong one by accident. Also note that the SRX does not run Screen OS, it runs Junos latest release that I know of is 11.4R4.4

If you are planning on running redundancy, both Cisco and Juniper has their advantages and disadvantages. The SRX was a complete PITA, literally had to have Juniper set it up as you have to delete all the interfaces and then join the 2 nodes together then re-add the interfaces back in.
The ASA if you are going to run Active/Standby is pretty much straight forward, however if you plan on running Active/Active you will have to run in Multi-context mode which disables the ability for all VPN traffic.

I have also heard decent things about Palo Alto, maybe the PA-5020 but not that familiar with them at all.
The Raven
(16 items)
 
  
CPUMotherboardGraphicsGraphics
i7-2600K Gigabyte GA-P67A-UD5-B3 EVGA GTX 570 SC EVGA GTX 570 SC 
RAMHard DriveOptical DriveCooling
16GB G.SKILL Ripjaws X 1866 Samsung 840 Pro  iHAS324 - Lite-On DVD-RW Noctua NH-D14 
OSMonitorMonitorKeyboard
Windows 10 ASUS VN248 ASUS VN248 Logitech G510 
PowerCaseMouse
XFX 850W BE SILVERSTONE RV02B-EW Logitech MX518 
  hide details  
Reply
The Raven
(16 items)
 
  
CPUMotherboardGraphicsGraphics
i7-2600K Gigabyte GA-P67A-UD5-B3 EVGA GTX 570 SC EVGA GTX 570 SC 
RAMHard DriveOptical DriveCooling
16GB G.SKILL Ripjaws X 1866 Samsung 840 Pro  iHAS324 - Lite-On DVD-RW Noctua NH-D14 
OSMonitorMonitorKeyboard
Windows 10 ASUS VN248 ASUS VN248 Logitech G510 
PowerCaseMouse
XFX 850W BE SILVERSTONE RV02B-EW Logitech MX518 
  hide details  
Reply
post #5 of 7
Thread Starter 
I don't need the SSL VPNs so the 240 is just about right. I also know about the different versions of the 240 so I do mean the H version. I don't have plans to run redundancy right now but I am re-doing my network in anticipation for an active/active setup so I don't have to move much around if I go down that road.

I'm more confident with JunOS than IOS and that was the reason why I looked at the Junipers but I'll definately thourougly research the Cisco 5520. I'll take the PA-5020 into consideration, but I have not heard much about Palo Alto.

Thanks.
Green Lantern
(18 items)
 
 
The Router 3.0
(14 items)
 
CPUMotherboardGraphicsGraphics
Intel i7 920 3.8GHz 1.25v HT Asus P6T XFX 5870 XFX 5780 
RAMHard DriveHard DriveOptical Drive
Kingston HyperX Intel X25-M 80GB G2 10Tb iSCSI Lite-On 1635S 
CoolingOSMonitorKeyboard
Corsair H50 Windows 7 x64 Ultimate Asus PA246 Logitech G15 v1 
PowerCaseMouseAudio
Corsair 1000HX Lian Li v1000+ Logitech G5 v1 Creative Audigy 2 ZS 
Other
Intel Pro/1000 PT Server Adapter 
CPUCPUMotherboardGraphics
Intel Xeon L5335 Intel Xeon L5335 Intel 5000P ATI ES1000 
RAMHard DriveOSPower
Elpida ECC WD20NPVT SmartOS HP 350W + Hot Spare 
Case
HP Proliant 380 G5 
CPUMotherboardRAMHard Drive
AMD Athlon 64 X2 3800+ nForce 3 250 2 GB 512MB CF To IDE 
OSCaseOtherOther
pfSense 2.0.1 x64 Shuttle XPC Intel PWLA8492MT PRO/1000 MT Dual Port Server A... Verizon FiOS 75/35Mbit 
  hide details  
Reply
Green Lantern
(18 items)
 
 
The Router 3.0
(14 items)
 
CPUMotherboardGraphicsGraphics
Intel i7 920 3.8GHz 1.25v HT Asus P6T XFX 5870 XFX 5780 
RAMHard DriveHard DriveOptical Drive
Kingston HyperX Intel X25-M 80GB G2 10Tb iSCSI Lite-On 1635S 
CoolingOSMonitorKeyboard
Corsair H50 Windows 7 x64 Ultimate Asus PA246 Logitech G15 v1 
PowerCaseMouseAudio
Corsair 1000HX Lian Li v1000+ Logitech G5 v1 Creative Audigy 2 ZS 
Other
Intel Pro/1000 PT Server Adapter 
CPUCPUMotherboardGraphics
Intel Xeon L5335 Intel Xeon L5335 Intel 5000P ATI ES1000 
RAMHard DriveOSPower
Elpida ECC WD20NPVT SmartOS HP 350W + Hot Spare 
Case
HP Proliant 380 G5 
CPUMotherboardRAMHard Drive
AMD Athlon 64 X2 3800+ nForce 3 250 2 GB 512MB CF To IDE 
OSCaseOtherOther
pfSense 2.0.1 x64 Shuttle XPC Intel PWLA8492MT PRO/1000 MT Dual Port Server A... Verizon FiOS 75/35Mbit 
  hide details  
Reply
post #6 of 7
Don't discount WatchGuard either, they have a few offerings comparable to your choices.
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II MSI GTX560 Ti TwinFrozr II 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 OCZ Vertex 3 Western Digital Caviar Black Western Digital Caviar Green 
Hard DriveOptical DriveCoolingOS
Samsung 840 Pro Lite-On 24x DVD-RW CoolerMaster V8 Windows 8.1 Professional 
OSMonitorMonitorMonitor
Debian 7.1 Samsung S22B350H Samsung S22B350H Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II MSI GTX560 Ti TwinFrozr II 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 OCZ Vertex 3 Western Digital Caviar Black Western Digital Caviar Green 
Hard DriveOptical DriveCoolingOS
Samsung 840 Pro Lite-On 24x DVD-RW CoolerMaster V8 Windows 8.1 Professional 
OSMonitorMonitorMonitor
Debian 7.1 Samsung S22B350H Samsung S22B350H Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
post #7 of 7
What about RouterOS and Ubiquiti ? I would prefer SRX240 to ASA5520.
    
CPUMotherboardGraphicsRAM
AMD Phenom II X2 550 BE ASUS M4A79XTD EVO ASUS EAH4670/DI/512MD3 G.SKILL Ripjaws Series 4GB (2 x 2GB) 240-Pin DDR3 
Hard DriveOptical DriveOSMonitor
HITACHI Deskstar HD31000 IDK/7K (0S00163) 1TB LG HL Windows 7 x64 Samsung T220HD 
KeyboardPowerCaseMouse
Logitech Access COOLER MASTER eXtreme Power Plus RS-500-PCAR-A3 Antec Three Hundred Razer Krait 
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
AMD Phenom II X2 550 BE ASUS M4A79XTD EVO ASUS EAH4670/DI/512MD3 G.SKILL Ripjaws Series 4GB (2 x 2GB) 240-Pin DDR3 
Hard DriveOptical DriveOSMonitor
HITACHI Deskstar HD31000 IDK/7K (0S00163) 1TB LG HL Windows 7 x64 Samsung T220HD 
KeyboardPowerCaseMouse
Logitech Access COOLER MASTER eXtreme Power Plus RS-500-PCAR-A3 Antec Three Hundred Razer Krait 
  hide details  
Reply
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Networking & Security
Overclock.net › Forums › Software, Programming and Coding › Networking & Security › Alternatives for Juniper SRX240?