Skip to content
Notifications
Clear all

Anyone using Juniper firewalls in a large enterprise? Real throughput

3 Posts
3 Users
0 Reactions
3 Views
(@jakef9)
Estimable Member
Joined: 1 week ago
Posts: 79
Topic starter   [#11911]

The vendor datasheet says one thing. The sales engineer, after a few beers at the summit, might hint at another. But what actually happens when you deploy a few hundred SRXes, turn on all the required security services, and push real enterprise traffic through them?

I'm specifically looking at the higher-end models (4xx, 5xx series) in an active/active chassis cluster scenario. We all know the throughput numbers assume tiny packets and a best-case, lab-grade scenario with nothing but throughput tests running. That's survivorship bias on a datasheet. Nobody buys a firewall just to route jumbo frames.

What I want to know from teams who have done it:
* What's the realistic, sustainable throughput with UTM, IDP, and AppID all turned on? Is it 40% of the spec? Less?
* How much does performance degrade when you're logging at a detailed level for compliance? We found on another platform that turning on certain log fields halved our session setup rate.
* Does Juniper's licensing for the advanced features follow the usual enterprise sales playbook—cheap year one, then punitive increases at renewal? The SRX itself might be decent, but the cost governance around the subscriptions is where they usually get you.

I'm anticipating a wave of "we love them, they're rock solid" from the true believers. I'm more interested in the teams who migrated *away* from them, or who are planning to, and what the actual breaking points were. Was it raw throughput, or was it the operational overhead, or the classic SaaS sprawl of managing yet another security subscription portal?

—jake


Your mileage will vary


   
Quote
(@integration_ian_2)
Reputable Member
Joined: 2 months ago
Posts: 159
 

Oh man, you're hitting the nail on the head. We rolled out about 150 SRX4100s across our branch offices a few years back. With AppID, IDP, and the full UTM suite active - including SSL decryption for a subset of traffic - we consistently saw about 35-40% of the datasheet's "threat prevention" throughput in steady state. The real killer was session establishment rate under load. When a bunch of users fire up video calls at 9 AM, that's when you feel the gap.

On the licensing front, brace yourself. The first three-year quote was palatable, a real "proof of value" price. The renewal quote came in at nearly double. It took six months of wrangling, threats to do a POC with another vendor, and finally getting a global account exec involved to get it back to a reasonable increase. They absolutely play the "you're now locked into our ecosystem" game. The hardware is solid, but the subscription governance is a full time job.

For logging, we had to be very selective. Turning on extended logging for all IDP events on our main internet-facing SRX5400 clusters did introduce a noticeable lag in application responsiveness. We ended up creating a separate, dedicated log feed for high-value targets only, which kept performance stable.


api first


   
ReplyQuote
(@docker_diver)
Estimable Member
Joined: 1 month ago
Posts: 109
 

That licensing bit is a real concern. I'm not on the networking team but I help deploy our app containers, and I see the budget fights. Is the performance drop consistent, or does it get way worse when you hit certain thresholds? Like, if you're at 35% of spec on a normal day, does a spike just kill it?


Containers are magic, but I want to know how the magic works.


   
ReplyQuote