Juniper SRX is a firewall offering. It provides a variety of modular features, scaled for enterprise-level use, based on a 3-in-1 OS that enables routing, switching, and security in each product.
N/A
WatchGuard XTM - Discontinued Product
Score 8.0 out of 10
N/A
WatchGuard XTM is a firewall option, from WatchGuard Technologies.
N/A
Pricing
Juniper SRX
WatchGuard XTM - Discontinued Product
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Juniper SRX
WatchGuard XTM - Discontinued Product
Free Trial
No
No
Free/Freemium Version
No
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
—
—
More Pricing Information
Community Pulse
Juniper SRX
WatchGuard XTM - Discontinued Product
Considered Both Products
Juniper SRX
Verified User
Anonymous
Chose Juniper SRX
Juniper SRX stands tall compared to all these products for Large Service Provider Networks, where traffic volume is larger. Also, cost comparison with SRX's few other products can also be another contributing factor while selecting this. As well as Juniper Routers, Switches, …
The comparison between the different firewalls is really down to preference and price at this point. The SRX is a solid device, and we have not seen a hardware failure to date. The Juniper support I have had is stellar and has helped me out with larger more complex scenario …
Equipment prices ran about the same. Performance and management were also more or less equal. The biggest deciding factors for going with Juniper were (1) fewer security incidents related to SRX firewalls and (2) technical support costs were significantly less.
Juniper SRX is significantly better in every category.
Cisco ASA was terrible. The config is unintuitive and not easy to manage. Cisco left the ASA abandoned from any kind of meaningful software updates for around a decade.
I love the Cisco ASA but I've become used to the SRX. I am a CLI kind of guy so the SRX works for me. Others may be more GUI based so the ASA may be more comfortable to you. If that's the case then the ASA's ASDM is a solid platform to manage your FW. Junos hasn't gotten this …
The SRX Stacks up well to the ASA and Sonic wall but I feel the features provided by Fortigate/Palo Alto and Checkpoint far exceed that of the competitors.
I believe this is the firewall series I worked on. The machine is terrible to configure as settings aren't grouped how a normal person would expect. Settings can be poorly labeled, adding more issues/confusion to the issues. I have not had a great experience trying to get …
The price-performance ratio was much better than the other brands. It is easy to use, manage and with a lot of compatibility
It offers the same functionality as other competitive solutions at a more accessible price, additionally its databases such as antivirus, antispam, and …
While these are all great firewalls, the price of the Palo Alto and Cisco boxes were high enough to make them not a viable option. I believe that the WatchGuard is in a leauge of its own in the price point. While there are nicer offerings out there, you will need to have a much …
Again, WatchGuard is priced much lower than other vendors in its space. It may not have some of the bigger features such as Layer 7 awareness. It's more simple to manage and provides IT staff the time to work on other tasks versus time spent to create complex rule sets.
Juniper vSRX is an excellent edge gateway device. The combination of Tunneling protocols supported and the advanced routing & security features makes it perfect for this kind of deployment. It is available in physical, virtual appliances as well as support on multiple clouds so you can have the same box be your edge gateway in multiple environments for consistency.
It can also work as a Internet Gateway, DMZ Firewall/Router and it would function just fine.
While it can also work as a DC firewall (North-South), the poor GUI will make it harder in the day to day administration for the multiple policies in a DC.
The web filter is complicated when you don't have a server to log in users. Companies using static IPs. They have to be clear about the number of users that the company has in order to obtain the correct model since each one has its resources according to the number of users.
They are simple to set up and configure. With just a few months of experience you can easily deploy any series of XTM in mid to small environments in minutes. I can deploy clustered M5600 in an enterprise within 30 minutes straight from the box, that's easy.
They are very reasonably priced and competitive in the market. For small and mid-sized businesses it's hard to beat the bang for the buck.
After setting them up, it's also very easy to fine tune and manage them. The packet monitor is very useful in troubleshooting and I use it to tighten down rule sets.
Dimension is a great packet analyzer and I think they still offer it as a free tool.
This is the one area where I have a beef with Juniper. When I called into Cisco TAC, 90% of the time, the first person I spoke with was able to resolve my issue. With Juniper TAC, 90% of the time, the first person I speak with is not able to resolve my issue, seems to almost be reading from a script, and must escalate my ticket. All of which takes time.
Equipment prices ran about the same. Performance and management were also more or less equal. The biggest deciding factors for going with Juniper were (1) fewer security incidents related to SRX firewalls and (2) technical support costs were significantly less.
It is a workhorse for our field operations. It provides the last touch for an ISP to the customer. The customer has no view of the device, but with the repeatability of the device, they do not need to.
The ability to roll out a dynamic routing protocol attached to a security zone allows elasticity to the environment that supports growth.
VLAN support on the inside interfaces allow this to be the only device in some smaller deployments we install these in.