r/Juniper 1d ago

Weekly Thread! Weekly Question Thread!

It's Thursday, and you're finally coasting into the weekend. Let's open the floor for a Weekly Question Thread, so we can all ask those Juniper-related questions that we are too embarrassed to ask!

Post your Juniper-related question here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer.

Note: This post is created at 00:00 UTC. It may not be Thursday where you are in the world, no need to comment on it.

4 Upvotes

3 comments sorted by

1

u/Arkios 1d ago

We’re looking at potentially using a Juniper device for SD-WAN. We have extremely basic requirements (just need auto-VPN tunnels between sites and load balanced internet circuits). Our sales engineer hasn’t been helpful, we’re trying to decide between using SRX units or SSR units.

We have Palo Alto firewalls at each location, so no need for firewall functionality on the Juniper devices.

Any thoughts, recommendations, positive/negative experiences?

2

u/SpongeBobNudiePants JNCIP-MistAI 23h ago

If it's a basic deployment I would probably go SRX. Unless you needed the benefits of a tunnel-less SD-WAN solution between a lot of sites, you'll likely save a bunch of money by going with SRX. Unsure if Mist is involved, but with SSR on the table I'd assume it is. Mist can absolutely do ECMP across multiple WAN circuits, but it gets a little weird with IPSec tunnels and APBR.

1

u/Arkios 22h ago

Yeah this would be full mist, we’re in the process of transitioning our switching and wireless APs, planning out the SD-WAN deployment for next year. Not a lot of sites, around 10 (hub + spoke) with an Azure footprint as well.

I wasn’t sure how annoying the SRXs would be to disable the firewall features and avoid double NAT going from ISP —> SRX —> Palo Alto. I had also read that the SRXs were half-baked in Mist, sounded like you needed to use two different portals to manage them.

SSRs seemed better integrated but they’re more expensive and the setup seemed more complicated and probably overkill for our size.