Juniper SRX to Core Switch – L2 Mode vs Routing Mode

firewalljuniper-junosjuniper-srxswitch

We have to plug two brand new Juniper SRX firewalls to the core switches, and I'm tasked with the research for what's the best mode of operation for the FW, either transparent mode or routing mode.

Core-Distribution-Firewall.where.to

The purpose for the firewalls is to protect and perform the IPS to both inbound and outbound traffic.

Eager to hear your thoughts.
Thanks.

Best Answer

For data center deployments, I like Layer 2 Transparent Mode Chassis Clusters as layer2 adjacency is required for vMotion, for example. You can then do your layer 3 stuff on the ASR's but allow east west (server-to-server) traffic to bypass them all together.

ISSU appears to be supported so you won't bring down the data center when rolling out new software to the SRX's.

Your ASR's can provide VPN and NAT.

Related Topic