Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation

Scale-Out IPsec Solution for Enterprises — Juniper Validated Design (JVD)

keyboard_arrow_up
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

Solution Benefits

date_range 13-Dec-24
JVD-MSE-SCALEOUT-IPSEC-ENT-01-01

The Juniper Scale-Out Security Services Solution is a scalable IPsec Security Gateway (IPSEC) for use in central offices or for data centres in enterprises or managed security providers. The security complex leverages the scale-out network architecture and automation with a tight integration between routing and security services elements represented by MX universal routers and SRX Series Firewalls. This provides the best routing and security stacks of both worlds for optimal performance and total cost of ownership. The scale-out approach offers advantages over scale-up or integrates security engines directly into routing domain, including:

  • Highly scalable IPsec systems with respect to number of tunnels and IPv4/IPv6 prefixes
  • Pay-as-you-grow approach
  • Flexibility to handle unpredictable traffic growth
  • High availability with sub-second restoration for IPsec Security Associations
  • Optimal operational preferences for a choice of physical or virtual nodes
  • Improved time to market for security services on new platforms
  • Flexible placement for security services in the network
Figure 1: Juniper Scale-Out General Architecture A close-up of a computer screen Description automatically generated

This solution is equally applicable for the green-field deployments or as a nested solution on top of an existing MX Series Routers in the centralized or distributed networks allowing flexibility in placement of the services across enterprises and data centers infrastructure.

The Scale-Out Security Services Solution provides a scale out model for enabling high-capacity IPsec Gateway services combining Juniper MX Series modular and compact routers with Juniper vSRX and SRX4600 security products (Virtual Network Functions or Appliances). Generally, a solution includes three layers: security services layer, forwarding layer, and management and control layer, which enable consistent traffic flows through the service complex in both directions, addresses high availability requirements and simplified operations and management of multiple systems constitute the solution.

This JVD focuses on first two layers only, which include the following functional elements and solution building blocks:

Security Services Layer

  • IPsec security services (terminating IPsec from branch/data centers/MSS/users)
  • Stateful firewall (not focused as such however the SRX Series Firewall handles all traffic in a stateful way, even within IPsec)
  • High availability function (using MNHA aka Multinode High Availability (MNHA))

Forwarding Layer

  • Router forwarding plane with virtual routing instance (“external” and “internal”)
  • Load balancing between multiple nodes of the security service layer
  • High availability function
  • Might include a distribution forwarding layer optionally
footer-navigation