Skip to content
Notifications
Clear all

Has anyone tried the SRX as a vSRX in Azure? Performance okay?

1 Posts
1 Users
0 Reactions
0 Views
(@catherine)
Estimable Member
Joined: 1 week ago
Posts: 59
Topic starter   [#6647]

I'm currently evaluating virtual firewall options for a multi-cloud segmentation project, with a significant portion of our workloads residing in Azure. Given our existing on-premise deployment of Juniper SRX380s for branch and perimeter security, the vSRX offering is a logical candidate for maintaining operational consistency and a unified Junos policy framework. However, my experience with virtualized network functions (VNFs) in public clouds has taught me to treat vendor performance claims with a high degree of skepticism until validated with real-world traffic patterns.

My primary concern centers on the performance characteristics of the vSRX (specifically the Next-Generation Firewall license model) in Azure's shared-tenancy hypervisor environment. I am looking for data points beyond the datasheet's "up to" Gbps figures, which are typically derived from ideal, isolated lab conditions.

Key areas where I'd appreciate detailed community feedback or war stories:

* **Measured Throughput vs. Azure Instance Size:** Has anyone conducted iPerf3 or similar throughput tests between Azure VMs across a vSRX, correlating results to instance types (e.g., Dv3-series, Fsv2-series)? I'm particularly interested in scenarios with threat detection (UTM/IDS), AppID, and IPS features enabled, as this is where performance cliffs often appear.
* **Licensing & TCO Nuances:** The consumption-based Next-Generation Firewall licensing (NGPAY) is conceptually aligned with cloud models. In practice, how predictable are the monthly costs under variable traffic loads? Are there any hidden scaling costs related to Azure's own data processing charges that significantly impact the total cost of ownership compared to a native cloud firewall service?
* **Deployment Artifacts & Automation:** The Azure Marketplace offering seems straightforward. However, are there specific ARM template or Terraform configurations you had to modify for production stability? Any issues with bootstrapping via `jsrc`, config persistence, or integration with Azure Monitor/Log Analytics?
* **Comparative Context:** If you also have experience with Palo Alto VM-Series or Fortinet FortiGate-VM in Azure, a comparative analysis of management overhead, feature parity, and performance-per-dollar at specific scale points (e.g., 500 Mbps inspected throughput) would be invaluable.

I will be conducting my own benchmark suite in a sandbox subscription over the next fortnight, focusing on latency introduction and maximum concurrent session capacity under DDoS-like conditions. I am happy to share my methodology and raw results upon completion, provided others are willing to contribute their findings to this thread.


Trust but verify.


   
Quote