Saturday, 15 August 2020

Junos Software Versions - Suggested Releases to Consider and Evaluate

Summary:

Juniper provides this document as a means to help customers and Juniper manufacturing select a Junos software version that aligns with their deployment needs. The releases listed below have performed well for the general population, but note that due to the uniqueness of our customer network deployments to include areas such as design, traffic patterns/flows, and specific usage of features and functionality, Juniper recommends that all customers A) read the associated Release Notes to understand how features, functionality, fixes, and any known outstanding issues may apply to your specific network and applications, and B) test and certify the suggested code version(s) to ensure they will perform as expected in your network.
This article applies to the following devices:
  • EX Series
  • M, T, and MX Series
  • ACX Series
  • NFX Series
  • QFX Series
  • SRX Series
For other Junos devices, refer to the Release Notes and the Alerts column on the Download Software pages.
Notes:
  1. The software versions included in this article are selected by utilizing input from Juniper Engineering, customers, and analysis of field usage data.
  2. To be automatically notified of updates to this document, use the Subscribe link. If you do not see the Subscribe link, log in with your user account.
  3. ​Juniper Networks offers optional fee-based services to further aide customers in selecting and testing software releases. If interested in more information, please contact your Juniper Sales Representative to discuss offering details and pricing.

Symptoms:
For use by customers and Juniper manufacturing planning an upgrade or initial installation.
Exceptions for evaluating these suggested software versions include:
  • A Juniper Engineer has recommended that a customer use a specific version of Junos software that is different from what is listed here in this article.
  • You require specific features (Feature Explorer) that are available only in another version of Junos software. In that case, be sure to download the latest maintenance release.
  • Your currently installed version of Junos is meeting your requirements as is.
  • If you use NSM, refer to the NSM & Junos Compatibility Matrix to make sure the suggested Junos software version can be managed by NSM.
To see the list​ of End of Engineering (EOE) and EOS (End of Support) dates for specific Junos versions, please go to the Junos Dates & Milestones page: https://support.juniper.net/support/eol/software/junos/
To see features supported per specific Junos versions, please go the Juniper Pathfinder page and navigate to "Feature Explorer": https://apps.juniper.net/home/

Solution:
To download Junos Software, go to the Software Download site and find your product.
Suggested Junos Software Versions for your consideration and evaluation are listed in the tables below.
NOTE: To locate a Junos release containing an 'S' (i.e. Junos 17.3R3-S3), on the Software Download product page change the OS drop-down from Junos to Junos SR
 
Select to jump to a platform series:
 

EX Series Ethernet Switches

Platform Junos Software by Platform Last
Updated
EX2200 (See Note 3) Junos 12.3R12-S15 9 Mar 2020
EX2200-C ( See Note 3) Junos 12.3R12-S15 9 Mar 2020
EX2300 Junos 18.2R3-S4 11 Jun 2020
EX2300-C Junos 18.2R3-S4 11 Jun 2020
EX3200 Junos 12.3R12-S15 / 14.1X53-D40 9 Mar 2020
EX3300 ( See Note 4) Junos 12.3R12-S15 9 Mar 2020
EX3400 Junos 18.2R3-S4 11 Jun 2020
EX4200  Junos 12.3R12-S15 / 15.1R7-S6 9 Mar 2020
EX4300 Junos 18.1R3-S9/18.4R2-S3 9 Mar 2020
EX4300-MP Junos 18.4R2-S3 9 Mar 2020
EX4500  Junos 12.3R12-S15 / 15.1R7-S6 9 Mar 2020
EX4550  Junos 12.3R12-S15 / 15.1R7-S6 9 Mar 2020
EX4600 Junos 18.1R3-S9/18.4R2-S3 9 Mar 2020
EX4650 Junos 18.4R2-S3 9 Mar 2020
EX6200 Junos 12.3R12-S15 / 15.1R7-S6 9 Mar 2020
EX8200 (See Note 2) Junos 12.3R12-S15 / 15.1R7-S6 9 Mar 2020
EX8200-VC (XRE200) (See Note 2 ) Junos 12.3R12-S15 / 15.1R7-S6 9 Mar 2020
EX9200  Junos 18.4R2-S3 9 Mar 2020
EX9251 Junos 18.4R2-S3 9 Mar 2020
EX9253 Junos 18.4R2-S3 9 Mar 2020
Junos Fusion Enterprise (JFE) Junos 18.4R2-S3 9 Mar 2020
  Notes:
  1. It is highly recommended to refer to the Release Notes, Technical Documentation, and KB articles for any outstanding and resolved issues before making the upgrade decision. Contact JTAC if there are any queries.
  2. Please refer to TSB16758 for minimum software requirements for newer revision EX8200 linecards.
  3. Please refer TSB17138 for more details.
  4. Please refer TSB17329 .
(back to the top)


ACX Series Service Routers

Platform Junos Software by Platform Release Type Last
Updated
ACX500 Junos 17.4R2-Sx (where x=latest on download page) Standard 9 April 2019
ACX1000 Junos 17.4R2-Sx (where x=latest on download page) Standard 9 April 2019
ACX1100 Junos 17.4R2-Sx (where x=latest on download page) Standard 9 April 2019
ACX2000 Junos 17.4R2-Sx (where x=latest on download page) Standard 9 April 2019
ACX2100 Junos 17.4R2-Sx (where x=latest on download page) Standard 9 April 2019
ACX2200 Junos 17.4R2-Sx (where x=latest on download page) Standard 9 April 2019
ACX4000 Junos 17.4R2-Sx (where x=latest on download page) Standard 9 April 2019
ACX5448 Junos 19.3R2-S3 Standard 26 June 2020
ACX5048 / ACX5096 Junos 17.4R2-Sx (where x=latest on download page) Standard 9 April 2019

(back to the top)

M, T, PTX, and MX Series Routers

Platform Junos Software by Platform Last
Updated
M Series Junos 15.1R7 29 Jan 2020
T Series (all including TX, TXP, TXP-3D) Junos 15.1R7
Junos 16.1R7
21 Apr 2020
PTX Series
(except PTX10002, PTX10003, PTX10008/16)
Junos 17.3R3-S7
Junos 17.4R2-S10
21 Apr 2020
PTX10002,
PTX10008/16 with JNP10K-RE1, JNP10K-RE1-LT
Junos 18.2R3-S3 21 Apr 2020
PTX10008/16 with JNP10K-RE1-128 Junos 18.3R2-S3 21 Apr 2020
PTX10003 Junos Evolved 19.4R2-S2-EVO 15 Jul 2020
PTX10008/16 with FAN2/AC2/DC2 Components Junos 19.2R1-S4 21 Apr 2020
PTX10008 with PTX10K-LC201-36CD and JNP100008-SF3 Junos Evolved 20.1R1-EVO 21 Apr 2020
PTX10016 Junos 17.4R2-S10
Junos 18.2R3-S3
21 Apr 2020
MX Series Junos 17.3R3-S7 21 Apr 2020
MX Series with MX-SPC3 Junos 19.4R1-S1 21 Apr 2020
MX 2010/2020 with MPC6/7/8/9 Junos 17.3R3-S7 21 Apr 2020
MX240/480/960 with MPC10E Junos 19.3R2-S2 12 May 2020
MX 2010/2020 with MPC11 SFB3(*6) Junos 20.1R1 01 Jun 2020
MX 2008 Series Junos 17.3R3-S7 21 Apr 2020
MX5, MX10, MX40, MX80, MX104 Series Junos 17.3R3-S7 21 Apr 2020
MX150, MX204, MX10003 Series Junos 18.2R3-S3 21 Apr 2020
MX10008 Series Junos 19.2R1-S4
Junos 19.3R2-S2(*5)
21 Apr 2020
MX10016 Series Junos 19.2R1-S4
Junos 19.3R2-S2
21 Apr 2020
MX Subscriber Management(*3) Junos 19.1R3-S1
Junos 19.4R1-S2
30 June 2020
MX Services on MS-DPC Junos 17.3R3-S3 23 July  2019
MX Services on MS-MPC/MIC(*4) Junos 17.3R3-S3 23 July 2019
MX Virtual Chassis Junos 19.3R2-S3 30 June 2020
Virtual Route Reflector Junos 19.3R2-S3 30 June 2020
vMX / vBNG(*2) Junos 19.1R3-S1
Junos 19.4R1-S2
30 June 2020
  Notes:
  1. This includes subscriber management deployments that incorporate services such as CGNAT, etc.
  2. This release is also suggested for deployments that include both MS-MPC/MIC and MS-DPC modules within the same chassis.
  3. See KB33938 for detail information and directly downloadable links to software for M/MX/PTX/T-Series JUNOS Software
  4. Recently released hardware may require a software version newer than listed above. Please use the latest Service Release for the required JUNOS software version
  5. Due to feature parity recommended from Product Line Management
  6. MPC11 is not supported in Junos 19.4
  (back to the top)


NFX Series Network Services Platform

Platform Junos Release Software Architecture Release Type Last
Updated
NFX150 Junos 19.3R2-S2 nfx-3 Service 11 May 2020
NFX250 Junos 18.4R3 nfx-2 Standard 11 May 2020
NFX250-NG Junos 19.4R1 nfx-3 Standard 11 May 2020
NFX350 Junos 19.4R1 nfx-3 Standard 11 May 2020

(back to the top)

QFX Series

Platform Junos Software by Platform Last
Updated
QFX3500 / QFX3600          Junos 14.1X53-D54 26 May 2020
QFX5100  Junos 18.1R3-S9/18.4R2-S3 9 Mar 2020
QFX5200 Junos 18.1R3-S9/18.4R2-S3 9 Mar 2020
QFX5110 Junos 18.1R3-S9/18.4R2-S3 9 Mar 2020
QFX5120-48Y Junos 18.4R2-S3 9 Mar 2020
QFX5210 Junos 18.1R3-S9/18.4R2-S3 9 Mar 2020
QFX10002 / QFX10008 / QFX10016 Junos 18.4R2-S3 9 Mar 2020
QFX10002-60C Junos 18.1R3-S9/18.4R2-S3 9 Mar 2020
EVPN-VXLAN Fabric CRB (Centrally Routed Bridging) Junos 18.4R2-S3 9 Mar 2020
EVPN-VXLAN Fabric ERB ( Edge Routed Bridging)  Junos 18.1R3-S9/18.4R2-S3 9 Mar 2020
Junos Fusion Datacenter (JFD) - MC-LAG Junos 17.3R3-S3 12 Feb 2019
Junos Fusion Datacenter(JFD) - EVPN Junos 18.1R2-S2 28 Feb 2019
Qfabric (See Note 1) Junos 14.1X53-D130 30 Jul 2019

Note:
  1. Qfabric NSSU upgrade from Junos 12.2X50 to later releases is NOT recommended. Please see TSB16842 for more details.
(back to the top)


SRX Series Services Gateways

Platform Junos Software by Platform Release Type Last
Updated
vSRX Junos 18.4R3-S4 Service 16 Jul 2020
vSRX 3.0 Junos 18.4R3-S4 Service 16 Jul 2020
SRX100H2 / SRX110H2 / SRX210HE2 / SRX220H2 / SRX240H2 Junos 12.3X48-D101(*3) Service 24 Apr 2020
SRX300 / SRX320 / SRX340 / SRX345 Junos 18.4R3-S4 Service 16 Jul 2020
SRX380 Junos 20.1R1-S2 Service 16 Jul 2020
SRX550 Junos 12.3X48-D101(*3) Service 24 Apr 2020
SRX550HM Junos 18.4R3-S4 Service 16 Jul 2020
SRX650 Junos 12.3X48-D101(*3) Service 24 Apr 2020
SRX1400 Junos 12.3X48-D101(*3) Service 24 Apr 2020
SRX1500 Junos 18.4R3-S4 Service 16 Jul 2020
SRX3400 / SRX3600 Junos 12.3X48-D101(*3) Service 24 Apr 2020
SRX4100 / SRX4200 Junos 18.4R3-S4 Service 16 Jul 2020
SRX4600 Junos 18.4R3-S3 Service 29 Jul 2020
SRX5400 / SRX5600 / SRX5800
with SRX5K-RE3-128G, SRX5K-SCB4, SRX5K-IOC4-10G or SRX5K-IOC4-MRAT (*1)
Junos 19.4R2 Standard 05 Jun 2020
SRX5400 / SRX5600 / SRX5800
with RE-1800X4 and SRX5K-SPC3 (*1)
Junos 18.4R3-S4 Service 16 Jul 2020
SRX5400 / SRX5600 / SRX5800
with RE-1800X4 (*1)
Junos 18.4R3-S4 Service 16 Jul 2020
SRX5400 / SRX5600 / SRX5800
with SRX5K-RE-13-20 (*1)
Junos 12.3X48-D101(*2)(*3) Service 24 Apr 2020
  Notes:
  1. KB30446 - SRX Junos SRX5K Hardware / Software compatibility matrix.
  2. TSB17655 - On SRX5000 series with SRX5k RE-13-20 a software upgrade to Junos release 12.3X48-D80, D85 or D90 may fail the pre-check due to insufficient space available on the compact flash.
  3. The Junos Service Release 12.3X48-D101 is the same as the Maintenance Release 12.3X48-D100 with the addition of the fix for JSA11021.
  4. Notes for upgrading from Junos 15.1X49 releases to 18.4R3 or 18.4R3 based Service Releases:
    • Junos OS upgrade from 15.1X49 directly to 18.4R3 or 18.4R3 based Service Releases is supported for all SRX platforms. Exception: SRX5k is unable to upgrade directly from Junos 15.1X49 releases to 18.4R3-S2 or 18.4R3-S3 (PR1505864). This issue is resolved in 18.4R3-S4.
    • For vSRX the following limitations apply when upgrading from 15.1X49 directly to 18.4R3 or 18.4R3 based Service Releases:
      • The file system mounted on /var usage must be below 14% of capacity.
        Check this with
        root@vsrx> show system storage | match " /var$"
        /dev/vtbd1s1f 2.7G 82M 2.4G 3% /var

        Note: The CLI command ‘request system storage cleanup’ may help reach that percentage if needed
      • The Junos upgrade image must be placed in the directory /var/host-mnt/var/tmp/
        request system software add /var/host-mnt/var/tmp/
      • It is recommended to deploy a new vSRX VM instead of performing a Junos upgrade. That also gives the option to move from vSRX to the newer and more recommended vSRX 3.0.

    • ISSU is not supported when upgrading from Junos 15.1X49 to higher versions.
    • KB34945 - When Junos Space Security Director is used for managing the SRX configuration and the AppFW, IDP or UTM features are used, then when upgrading to Junos 18.2R1 or higher, the SRX configuration needs to be migrated to the new Unified Policies style and Security Director version 19.3 or higher is required.
    • When upgrading from Junos 15.1X49-D170 to Junos 18.4 releases, the following features are unavailable in 18.4 Junos code version:
      • The following CSO / SD-WAN related features:
        • Application quality of experience (AppQoE) application-based multipath support (SRX Series and vSRX)
          • This feature is available as of  15.1X49-D160 code line and 19.2R1 and higher releases
        • Application quality of experience (AppQoE) increased scaling support (SRX4100, SRX4200)
          • This feature is available as of  15.1X49-D160 code line and 19.1R1 and higher releases
        • Application quality of experience (AppQoE) support in high availability mode (SRX4100, SRX4200)
          • This feature is available as of  15.1X49-D160 code line and 19.1R1 and higher releases
        • MPLS based traffic flow security processing via virtual routing and forwarding (VRF) instances (SRX300, SRX320, SRX340, SRX345, SRX550M, SRX1500, SRX4100, SRX4200, and vSRX)
          • This feature is available as of  15.1X49-D160 / 15.1X49-D170 code line and 19.3R1 and higher releases
        • MPLS based traffic flow security processing linking of multiple VRFs to a vrf-group (SRX Series and vSRX)
          • This feature is available as of  15.1X49-D170 code line and 19.3R1 and higher releases

Wednesday, 1 July 2020

What is artificial intelligence for networking?

What is artificial intelligence for networking?
The purest definition of artificial intelligence (AI) is software that performs a task on par with a human expert. AI plays an increasingly critical role in taming complexity for growing IT networks.
The proliferation of devices, data, and people has made IT infrastructures more complex than ever to manage. Given that most IT budgets are flat or shrinking, businesses need a way to manage this complexity, and many are now looking to artificial intelligence for help.

Key AI Technologies
For AI to be successful, it requires machine learning (ML), which is the use of algorithms to parse data, learn from it, and make a determination or prediction without requiring explicit instructions. Thanks to advances in computation and storage capabilities, ML has recently evolved into more complex structured models, like deep learning (DL), which uses neural networks for even greater insight and automation. Natural language processing (NLP) is another trend that’s driven recent AI advancement, particularly in the area of the virtual home and IT assistants. NLP uses vocal and word-based recognition to make interfacing with machines easier via natural language cues and queries.



What is segment routing?
The role of AI in network environments.
Building an AI System
Without the right AI strategy, IT simply can’t keep up with today’s stringent network requirements. Here are several technology elements that an AI strategy should include.
  • Data: Any meaningful AI solution begins with massive amounts of quality data. AI continually builds its intelligence over time through data collection and analyses. The more diverse the data collected, the smarter the AI solution becomes. In the case of real-time applications involving highly distributed “edge” devices, such as IoT and mobile devices, for example, it’s crucial to collect data from every edge device in real time, then quickly process it locally or very nearby in an edge computer or the cloud using AI algorithms.
  • Domain-specific expertise: Whether helping a doctor diagnose cancer or enabling an IT administrator to diagnose wireless problems, AI solutions need labeled data based on domain-specific knowledge. These metadata chunks help the AI break the problem down into small segments that can be used to train the AI models. This task can be achieved using design intent metrics, which are structured data categories for classifying and monitoring the wireless user experience.
  • Data science toolbox: Once the problem has been divided into domain-specific chunks of metadata, this metadata is ready to be fed into the powerful world of ML and big data. Various techniques, such as supervised or unsupervised ML and neural networks, should be employed to analyze data and provide actionable insight.
  • Virtual network assistant. Collaborative filtering is an ML technique that many people experience when they select a movie on Netflix or buy something from Amazon and receive recommendations for similar movies or items. Beyond recommendations, collaborative filtering can be applied to sort through large data sets and identify and correlate those that form an AI solution to a particular problem.
In AI for networking, the virtual network assistant might function in a wireless environment as a virtual wireless expert that helps solve complex problems. Imagine a virtual network assistant that combines quality data, domain expertise, and syntax (metrics, classifiers, root causes, correlations, and ranking) to provide predictive recommendations on how to avoid problems and to offer actionable insights on how to remediate existing issues. It can learn wireless network nuances and respond to questions such as, “What went wrong?” and “Why did that happen?” These are the types of automated advances that AI is enabling.
Real-World Benefits
With AI comes a lot of hype, and that can be confusing and create false expectations. But AI for networking is very real and is already providing substantive value to companies in almost every industry. There are many examples of how AI-driven networks can help your environment.
  • Detecting time series anomalies. Many devices running on today’s networks were invented 20 years ago, and they don’t support current management messages. AI can detect time series anomalies with a correlation that allows network engineers to quickly find relationships between events that would not be obvious to even a seasoned network specialist.
  • Event correlation and root cause analysis. AI can use various data-mining techniques to explore terabytes of data in a matter of minutes. This ability lets IT departments quickly identify what network feature (for instance, OS, device type, access point, or switch) is most related to a network problem, accelerating problem resolution.
  • Predicting user experiences. Today, application bandwidth apportionment happens largely through capacity planning and manual adjustments. Soon, though, AI will be able to predict a user’s Internet performance, thus allowing a system to dynamically adjust bandwidth capacity based on which applications are in use at specific times. Manual planning will give way to predictive analysis that’s informed by historical trends and current calendar information.
  • Self-driving. AI enables IT systems to self-correct for maximum uptime and provide prescriptive actions as to how to fix problems that occur. In addition, AI-driven networks can capture and save data prior to a network event or outage, helping to speed troubleshooting.
Today, the convergence of several different technologies is enabling AI to completely disrupt the networking industry with new levels of insight and automation. AI helps lower IT costs and it assists businesses in achieving their goal of delivering the best possible IT and user experiences.

Monday, 1 June 2020

What is Juniper SDN?

Diagram: What is SDN? 


Software-defined networking (SDN) is an approach to network virtualization that seeks to optimize network resources and quickly adapt networks to changing business needs, applications, and traffic. It works by separating the network's control plane and the data plane, creating software-programmable infrastructure that is distinct from physical devices.


With SDN, the functions of network orchestration, management, analytics, and automation become the job of SDN controllers. Because these controllers are not networking devices, they can take advantage of the scale, performance, and availability of modern cloud computing and storage resources. Increasingly, SDN controllers are built on open platforms, using open standards and open APIs, enabling them to orchestrate, manage, and control network equipment from different vendors.
SDN delivers a wide array of business benefits.


Separation of the control and transport layers increases flexibility and accelerates time-to-market for new applications. The ability to respond more swiftly to issues and outages improves network availability. And programmability makes it easier for IT organizations to automate network functions, reducing operating costs.


SDN dovetails with another technology, Network Functions Virtualization (NFV). NFV offers the ability to virtualize appliance-based network functions such as firewalls, load balancers, and WAN accelerators. The centralized control that SDN provides can efficiently manage and orchestrate virtual network functions that are enabled by NFV.

Friday, 1 May 2020

The Power of a Threat-Aware Network

Juniper Connected Security is more than just a marketing catchphrase or a nice metaphorical basket where all of Juniper Networks’ information security products can be placed. It is an information security strategy, one focused on the importance of deep network visibility, multiple points of enforcement throughout the network and interconnectivity between both networking and information security products. The expansion of SecIntel throughout Juniper’s portfolio is a real-world example of this strategy in action. Bringing threat intelligence to network infrastructure with SecIntel provides customers with a threat-aware network, enabling their network infrastructure to act against attacks and help safeguard users and applications.

SecIntel for a Threat-Aware Infrastructure

SecIntel provides carefully curated, verified threat intelligence from Juniper Networks’ Advanced Threat Prevention (ATP) Cloud, Juniper Threat Labs and industry-leading threat feeds to our MX Series routing platforms, SRX Series Services Gateways and NFX Series Network Services Platform to block command-and-control communications at line rate.
Earlier this year, CRN designated Juniper’s SecIntel as one of the “12 Cool New Threat Detection and Response Products Unveiled at Black Hat 2019.” SecIntel integration has now been extended to EX Series and QFX Series switches, enabling them to subscribe to SecIntel’s infected host feed and allowing customers to block compromised hosts at the switch port, simply and easily. Customers can now extend SecIntel throughout their entire network, increasing the number of security enforcement points.

If the expansion of SecIntel capabilities is a technological demonstration of what Juniper Connected Security aims to achieve, 2019 has been a year which reinforced that the Juniper Connected Security approach is working for customers. This year, Juniper Networks was named a Champion in the Infotech SIEM Customer Experience report. In this report , Juniper Secure Analytics ranked first in a number of categories, including service experience and product impact.

Juniper Receives “Recommended” rating from NSS Labs for Juniper’s Data Center Security Gateway

This week, Juniper Networks also achieved a “Recommended” rating from NSS Labsfor our ability to secure the data center in their 2019 Data Center Security Gateway (DCSG) report. NSS Labs tested the Juniper SRX5400 firewall with one SPC3 service card, running AppSec and IDP licenses. NSS Labs’ independent testing focused on security effectiveness, performance, stability and reliability, and TCO.

“Juniper is back,” is the first bullet point listed by NSS Labs under “Key Takeaways” within the DCSG Security Value Map™ Comparative Report. The NSS Labs Data Center Security Gateway tests have traditionally only included server-side evasions, but this year, NSS also included client-side evasions. Juniper scored well, achieving the following results:
  • 100% resistance to evasions
  • 99.62% exploit block rate
  • 13.962 Gbps average secured throughput
Juniper Connected Security represents some of the most effective information security products available on the market today. Making these capabilities available throughout the network increases security for all workloads, no matter where those workloads happen to operate.
NSS Recommended
Partner Alliances

Juniper Connected Security encompasses more than just Juniper’s own products. By connecting our technologies with those of alliance partners, Juniper Connected Security offers organizations the ability to secure their networks from the endpoint to the edge, and every cloud in between.

For example, organizations can use Juniper Connected Security in partnership with Corero to stay ahead of DDoS attacks using the same security tools that identify and classify the risks of compromised endpoints. These are also the same products used to analyze telemetry from – and enforce policy on – firewalls, switches and routers throughout a customer’s network. Juniper Connected Security offers organizations a common toolkit for information security, regardless of a network’s scale; one that works with Juniper’s own products, those of our ecosystem partners and even those of our competitors.

Security at All Points of Connection
Networking and security are inextricably intertwined. It is when vendors (and customers) attempt to architect their networks using only point solutions that they open themselves up for risk. Effective network security starts with designing the network for both connectivity and multiple layers of security and is achieved by deploying multiple technologies, from multiple vendors, creating a whole that is more capable than the sum of its parts.

“Juniper is back.”
– NSS Labs 2019 Data Center Security Gateway Security Value Map Comparative Report, Key Takeaways
Juniper Networks offers organizations the networking and security capabilities they need to not only meet today’s challenges, but tomorrow’s as well. Our network and security portfolio offer industry-leading performance along with the ability to scale. This is reflected in the 22% year-over-year growth of our security portfolio.

Trust is the real IT security challenge of the next decade. Vendors need to build it. Customers need to be judicious about it. Whom will you trust with the future of your business? Which vendor(s) are you certain will be there a decade from now? Who will provide you cross-vendor integration support today, tomorrow and in the future?

At Juniper, we’ve refocused our strategic direction of solving our customers’ challenges to safeguard users, applications and infrastructure by extending security to all points of connection on the network, creating a network that is threat aware and better able to deliver the reliable connectivity we’re known for and a more effective way to secure those connections and the data that traverses them. And we’re actively executing on that strategy. Extending SecIntel first to the firewall, then the router, and now the switch allows the threat-aware network we’ve been talking about to become a reality for our customers.

Wednesday, 1 April 2020

Cloud Networking Transformation Ahead


Networking is undergoing a metamorphosis. Today’s operations are challenged to cope with the DevOps, NetOps, SecOps and CloudOps models that need consistent operations control. Why should enterprises care? How do you cope with decades of legacy and is change possible? Arista believes that the networking world is at the cusp of a transformation, significantly facilitated by the agile, dynamic and economic network models of the public cloud providers. They have proven the elegance of simple yet scalable designs that transform siloed networks for the data center, core, campus or branch PINs (Places in the Network) into east west PICs(Places in the Cloud). This new paradigm is a far cry from the traditional siloed network architectures that required applications to be assigned to specific servers or storage, causing fixed-function rigidity. Agility and high availability are pivotal foundations to building the new PICs.

As large data sets explode, the use of artificial intelligence applications, video and workflow traffic intermingled with breakthroughs in the mobile Internet from 5G to 400Gbps speeds, creates greater pressures on network portability. This has driven Arista to build a highly programmable state-driven software stack –Arista EOS® (Extensible Operating System) and network wide CloudVision®.

Campus is a Natural Extension
As data centers extend to the campus and branch, converting siloed PINs to PICs, applications require increased agility and elasticity, blending cloud native applications and enterprise networks via containers and APIs. The shift to IoT and microservices, be it physical, virtual or container-based with Arista CloudEOS and intelligent wired-WiFi edge connects a common spine with common protocols. This Universal Spine is enabled through CloudVision topology and inference management.

Changing Operation Models
Modern development tools today are closer to distributed systems architectures than before and need to understand failure patterns, network partitions/requirements and how their applications deploy and perform in far more dynamic environments. Traditional CLI based Network ops is lagging behind by decades and the model will only scale if declarative practices are adopted to augment mature DevOps. Ops teams are emerging ‘bottom-up’ as NetOps from IT infrastructure balance out this dynamic. The “operator” functions are rapidly becoming understood and accepted as critical roles within enterprise. CloudVision brings that network wide turnkey control.

Network wide Analytics
Migrating from old school appliances to next generation architectures requires network wide analytics. With switch-based DANZ (Data ANalyZer) and our recent acquisition of Big Switch DANZ Monitoring Fabric, (DMF) we can create overlays to CloudVision for network wide change control, automation and analytics. This is a primary driver of cost and efficiency on Day 2.

Arista Ahead
Until now the intersection of human, users, devices, machines and networking was somewhat loosely- coupled. Now one or many applications or scans can consume gigabytes of data, ingested from IoT devices such as video, storage, and real-time analytics with indexing and queuing views. Arista’s cognitive approach to high availability networking, built on cloud principles of availability, agility, and analytics, brings the combination of inference and real-time action. Troubleshooting shouldn’t be a finger pointing exercise, and live patching should be the norm instead of unplanned outages. The healthy flow of information to critical decision makers demands a cognitive network. Welcome to the new world of software defined cloud networking!

Sunday, 1 March 2020

How machine learning and automation can modernize the network edge

If you want to know the future of networking, follow the money — right to the edge.
Applications are expected to move from data centers to edge facilities in record numbers, opening up a huge new market opportunity. The edge computing market is expected to grow at a compound annual growth rate of 36.3 percent between now and 2022, fueled by rapid adoption of the “internet of things,” autonomous vehicles, high-speed trading, content streaming and multiplayer games.
What these applications have in common is a need for near zero-latency data transfer, usually defined as less than five milliseconds, although even that figure is far too high for many emerging technologies.  
The specific factors driving the need for low latency vary. In IoT applications, sensors and other devices capture enormous quantities of data, the value of which degrades by the millisecond. Autonomous vehicles require information in real-time to navigate effectively and avoid collisions. The best way to support such latency-sensitive applications is to move applications and data as close as possible to the data ingestion point, therefore reducing the overall round-trip time. Financial transactions now occur at sub-millisecond cycle times, leading one brokerage firm to invest more than $100 million to overhaul its stock trading platform in a quest for faster and faster trades.

Operational challenges

As edge computing grows, so do the operational challenges for telecommunications service provider such as Verizon Communications Inc., AT&T Corp. and T-Mobile USA Inc. For one thing, moving to the edge essentially disaggregates the traditional data center. Instead of massive numbers of servers located in a few centralized data centers, the provider edge infrastructure consists of thousands of small sites, most with just a handful of servers. All of those sites require support to ensure peak performance, which strains the resources of the typical information technology group to the breaking point — and sometimes beyond. 
Another complicating factor is network functions moving toward cloud-native applications deployed on virtualized, shared and elastic infrastructure, a trend that has been accelerating in recent years. In a virtualized environment, each physical server hosts dozens of virtual machines and/or containers that are constantly being created and destroyed at rates far faster than humans can effectively manage. Orchestration tools automatically manage the dynamic virtual environment in normal operation, but when it comes to troubleshooting, humans are still in the driver’s seat. 
And it’s a hot seat to be in. Poor performance and service disruptions hurt the service provider’s business, so the organization puts enormous pressure on the IT staff to resolve problems quickly and effectively. The information needed to identify root causes is usually there. In fact, navigating the sheer volume of telemetry data from hardware and software components is one of the challenges facing network operators today. 

Machine learning and automation 

A data-rich, highly dynamic, dispersed infrastructure is the perfect environment for artificial intelligence, specifically machine learning. The great strength of machine learning is the ability to find meaningful patterns in massive amounts of data that far outstrip the capabilities of network operators. Machine learning-based tools can self-learn from experience, adapt to new information and perform humanlike analyses with superhuman speed and accuracy.  
To realize the full power of machine learning, insights must be translated into action — a significant challenge in the dynamic, disaggregated world of edge computing. That’s where automation comes in.
Using the information gained by machine learning and real-time monitoring, automated tools can provision, instantiate and configure physical and virtual network functions far faster and more accurately than a human operator. The combination of machine learning and automation saves considerable staff time, which can be redirected to more strategic initiatives that create additional operational efficiencies and speed release cycles, ultimately driving additional revenue. 

Scaling cloud-native applications

Until recently, the software development process for a typical telco consisted of a lengthy sequence of discrete stages that moved from department to department and took months or even years to complete. Cloud-native development has largely made obsolete this so-called “waterfall” methodology in favor of a high-velocity, integrated approach based on leading-edge technologies such as microservices, containers, agile development, continuous integration/continuous deployment and DevOps. As a result, telecom providers roll out services at unheard-of velocities, often multiple releases per week. 
The move to the edge poses challenges for scaling cloud-native applications. When the environment consists of a few centralized data centers, human operators can manually determine the optimum configuration needed to ensure the proper performance for the virtual network functions or VNFs that make up the application.
However, as the environment disaggregates into thousands of small sites, each with slightly different operational characteristics, machine learning is required. Unsupervised learning algorithms can run all the individual components through a pre-production cycle to evaluate how they will behave in a production site. Operations staff can use this approach to develop a high level of confidence that the VNF being tested is going to come up in the desired operational state at the edge. 

Troubleshooting at the speed of AI 

AI and automation can also add significant value in troubleshooting within cloud-native environments. Take the case of a service provider running 10 instances of a voice call processing application as a cloud-native application at an edge location. A remote operator notices that one VNF is performing significantly below the other nine.  
The first question is, “Do we really have a problem?” Some variation in performance between application instances is not unusual, so answering the question requires a determination of the normal range of VNF performance values in actual operation. A human operator could take readings of a large number of instances of the VNF over a specified time period and then calculate the acceptable key performance indicator values — a time-consuming and error-prone process that must repeated frequently to account for software upgrades, component replacements, traffic pattern variations and other parameters that affect performance.
In contrast, AI can determine KPIs in a fraction of the time and adjust the KPI values as needed when parameters change, all with no outside intervention. Once AI determines the KPI values, automation takes over. An automated tool can continuously monitor performance, compare the actual value to the AI-determined KPI and identify underperforming VNFs.
That information can then be forwarded to the orchestrator for remedial action such as spinning up a new VNF or moving the VNF to a new physical server. The combination of AI and automation helps ensure compliance with service-level agreements and removes the need for human intervention — a welcome change for operators weary of late-night troubleshooting sessions. 

Harnessing the competitive edge

As service providers accelerate their adoption of edge-oriented architectures, IT groups must find new ways to optimize network operations, troubleshoot underperforming VNFs and ensure SLA compliance at scale. Artificial intelligence technologies such as machine learning, combined with automation, can help them do that.
In particular, there have been a number of advancements over the last few years to enable this AI-driven future. They include systems and devices to provide high-fidelity, high-frequency telemetry that can be analyzed, highly scalable message buses such as Kafka and Redis that can capture and process that telemetry, and compute capacity and AI frameworks such as TensorFlow and PyTorch to create models from the raw telemetry streams. Taken together, they can determine in real time if operations of production systems are in conformance with standards and find problems when there are disruptions in operations.
All that has the potential to streamline operations and give service providers a competitive edge — at the edge.

Saturday, 1 February 2020

Secure SD-WAN - Branch Platforms

The announcement of Juniper's newest hardware additions for the AI-driven enterprise makes our portfolio of CPE the most extensive for secure SD-WAN across all sizes of branch and campuses. There’s no denying the growing importance of SD-WAN for providing secure and efficient connectivity of remote sites to the cloud. Even more important is enterprises’ need to drive operational simplicity and uniformity across the branch and campus in today’s multicloud environment. For SD-WAN to be successful, the key is to satisfy the needs of today while preparing for the ones of tomorrow and beyond.

One of the core needs of increasing importance for SD-WAN is security. Traditional security solutions don’t cut in when it comes to performance, interconnectivity and flexibility, meanwhile, SD-WAN-centric solutions may offer elementary security features that will ultimately put the business at risk. The industry is at an intersection where SD-WAN features and advanced threat protection need to be designed hand-in-hand to safeguard users, applications and infrastructure. This has been our exact focus for our SD-WAN solution and, to that end, we’ve now expanded our range of CPE hardware in the WAN edge portfolio to include:

Wi-Fi Mini Physical Interface Module (mPIM): An enterprise-grade Wi-Fi card for compact locations with our SRX Series Services Gateways. It provides dual radio support of 2.4 and 5Ghz frequencies along with 802.11ac Wave 2 and 802.11ac with backward compatibility of 802.11n standards. The module is suited for remote offices, guest Wi-Fi, small office, IoT connectivity or kiosks. It is an ideal branch-in-a-box solution where one access point is sufficient.

This mPIM is manageable by CLI, JWeb or Juniper Sky Enterprise. It also offers ZTP and management via the Contrail Service Orchestration interface, as part of Juniper’s cloud-managed or on-premises Contrail SD-WAN solution.

Branch Platforms Image 1.png

SRX380: For larger branches, the SRX380 is the fastest performing CPE platform of the branch SRX300 product line. Leading features include high port density with 10G options for high on-board connectivity, increased POE+ port density for IoT devices, AE256 MACsec encryption, dual power supplies and up to four MPIM card slots for wired or wireless connectivity.

The SRX380 can be adapted to be a secure SD-WAN and next-gen firewall device. Users can add advanced threat prevention services to expand on the native next-generation firewall and UTM capabilities, IPS and AppSecure application visibility and policies.
Branch Platforms Image 2.png

NFX350: The NFX350 is a high-end universal CPE platform in the NFX Series for large branch site deployments. Built on the next generation of Intel processors, Skylake, it offers up to 7.5 Gbps IPsec performance for higher SD-WAN scale and performance, while redundant power supplies provide greater platform resiliency. It includes 8x1Gbps and 8xSFP/SFP+ ports with AES256 MACsec support for high network connectivity and WAN interfaces for LTE, DSL and SFP. Support for multiple Juniper and third-party VNFs enables customers to accelerate application deployment in an automated and scalable fashion.

The NFX350 universal CPE platform fits the bill as a secure router, SD-WAN device or next-generation firewall. Consistent with the NFX Series, users reap the many benefits of SD-WAN, but most importantly, the simplicity of automation and consolidation with the reliability of smarter security and SDN.

Branch Platforms Image 3.png

These new products meet the needs of both the top and bottom ends of all branch and campus sizes – the SRX Wi-Fi mini card for compact spaces and the SRX380 and NFX350 as top line branch CPEs. Be sure to tune in or test drive Contrail SD-WAN for free.
loading...