Juniper Networks J2320 Services Router
J Series Appliances

| Juniper Networks Products | ||
|---|---|---|
| J Series Appliances | ||
| Juniper Networks J2320 Services Routers -
Base Memory (512MB DRAM, 512 MB Flash) - JUNOS, 3 PIM Slots, SW Security, AC Power Supply, 19" Rack Mount |
#J2320-JB-SC List Price: $2,500.00 |
|
| Juniper Networks J2320 Services Routers -
Base Memory (512MB DRAM, 512 MB Flash) with TAA - JUNOS, 3 PIM Slots, SW Security, AC Power Supply, TAA 19" Rack Mount |
#J2320-JB-SC-TAA List Price: $4,000.00 |
|
| Juniper Networks J2320 Services Routers -
High Memory (1GB DRAM, 512 MB Flash) - JUNOS, 3 PIM Slots, HW Encryption, AC Power Supply, 19" Rack Mount |
#J2320-JH List Price: $4,000.00 |
|
More pricing below, click here
J2320 Overview:
The Juniper Networks J2320 is a modular router for enterprises running desktops, servers, VoIP, CRM/ERP/SCM applications. It offers three PIM slots for additional LAN/WAN connectivity, Avaya VoIP Gateway, and WAN acceleration.
Key Hardware Features:
- Support for T1, E1, Synchronous Serial, ISDN Basic Rate Interface, ADSL2/ADSL2+, G.SHDSL, and Gigabit Ethernet interfaces
- Support for integrated IP telephony using the Avaya IG550 Integrated Gateway
- Support for application acceleration using the Juniper Networks ISM200 Integrated Services Module
- 4 fixed Gigabit Ethernet LAN ports, and 3 PIM slots
- 512 MB DRAM default, expandable to 1 GB DRAM
- 512 MB compact flash default, upgradeable to 1 GB
- Hardware encryption acceleration (optional)
- Full UTM; antivirus, antispam, Web filtering, intrusion prevention system (with high memory version)
- Unified Access Control (UAC) and content filtering
Juniper Networks J Series Services Routers extend enterprise applications and deliver reliable connectivity to remote offices with a powerful blend of high-performance network protection and advanced services. J Series Services Routers leverage the modular JUNOS Software and Juniper’s rich product and partner portfolio to consolidate market leading security, application optimization, and voice capabilities onto a single, easy to manage platform. Our innovative security approach inseparably integrates routing and firewalls for exceptional performance. Available options, including integrated Juniper Networks WX application acceleration and integrated voice gateway technology from Avaya, make the J Series the ideal choice for closing the distance between central resources and remote locations.
Enterprises are faced with a number of challenges and opportunities by converging voice, video and data to one network. This consolidation of network elements reduces cost by easing deployment of SIP enabled VoIP, real-time high-definition Telepresence and standardizing on a consistent infrastructure network operating system like Juniper Networks® Junos® operating system. These new technologies improve; customer relations, interactions with suppliers, and employee productivity. This mission-critical multi-media network must be always on and always available. To accomplish this, fully integrated stateful security is a key requirement, not merely forwarding packets without regard to the intended application or individual user session. Junos OS provides the high-performance networking infrastructure that helps enterprises implement key initiatives that:
- Integrates routing, firewalling and VPN into one best in class secure router. By
securing an enterprise’s mission critical information and protecting the network from
vulnerabilities and attack, the Juniper Networks J Series Services Router offers a
combination of features that increases productivity and reduces costs. With Junos OS
release 9.6, the J Series enhances these features with Unified Threat Management,
consisting of antivirus, antispam, Web filtering and intrusion prevention system. These
advanced security features can eliminate a standalone appliance and be applied with a
software key.
- Minimizes the cost of installing and operating a network by deploying J Series. With the modular, protected mode design of Junos OS and the rigorous Junos OS development and testing process, there are fewer system process failures. The single code source of Junos OS makes the qualification of new releases across the network much simpler. In addition, superior configuration management reduces human errors that could lead to network downtime.
Whether you have an enterprise network or a service provider looking for customer premise equipment for an MPLS or IP network, the J Series offers a mix of features that excel at both. By leveraging Junos OS, the J Series can be deployed at medium to large sites and the wide range of interfaces scales the bandwidth as necessary for today’s real time communications.

Features & Benefits:
Secure Routing
Should you use a router and a firewall to secure your network? By building the branch J Series Services Routers with best-in-class routing and firewall capabilities in one product, enterprises don’t have to make that choice. Why forward traffic if it’s not legitimate?
J Series for the branch checks the traffic to see if it is legitimate, and only forwards it on when it is. This reduces the load on the network, allocates bandwidth for all other mission-critical applications, and secures the network from hacking.
The main purpose of a secure router is to provide firewall protection and apply policies. The firewall (zone) functionality inspects traffic flows and state to ensure that originating and returning information in a session is expected and permitted for a particular zone. The security policy determines if the session can originate in one zone and traverse to another zone. This architectural choice receives packets from a wide variety of clients and servers and keeps track of every session, of every application, and of every user. It allows the enterprise to make sure that only legitimate traffic is on its network and that traffic is flowing in the expected direction.
To ease the configuration of a firewall, J Series for the branch uses two features—“zones” and “policies.” While these can be user defined, the default shipping configuration contains, at a minimum, a trust and an untrust zone. The trust zone is used for configuration and attaching the LAN to the branch J Series routers. The untrust zone is used for the WAN or Internet interface. To simplify installation and make configuration easier, a default policy is in place that allows traffic originating from the trust zone to flow to the untrust zone. This policy blocks all traffic originating from the untrust zone to the trust zone. A traditional router forwards all traffic without regard to a firewall (session awareness) or policy (origination and destination of a session).
By using the Web interface or CLI, enterprises can create a series of security policies that will control the traffic from within and in between zones by defining policies. At the broadest level, all types of traffic can be allowed from any source in security zones to any destination in all other zones without any scheduling restrictions. At the narrowest level, policies can be created that allow only one kind of traffic between a specified host in one zone and another specified host in another zone during a scheduled time period.
High Availability

System redundancy in an active-passive configuration maintains all session information on a standby J Series Services Router in the event of a box failure. Network capacity is always one half of the maximum.

System redundancy in an active-active configuration maintains all session information load balanced across two active J Series Services Routers. Since Network capacity is load balanced, using all availablt
resources when active-active and half the capacity in the event of a failure.
High Availability
Junos OS Services Redundancy Protocol (JSRP) is a core feature of the J Series for the branch. JSRP enables a pair of security systems to be easily integrated into a high availability network architecture, with redundant physical connections between the systems and the adjacent network switches. With link redundancy, Juniper Networks can address many common causes of system failures, such as a physical port going bad or a cable getting disconnected, to ensure that a connection is available, without having to fail over the entire system. This is consistent with a typical active/standby nature of routing resiliency protocols.
When J Series routers for the branch are configured as an active/active pair, traffic and configuration will be mirrored automatically to provide active firewall and VPN session maintenance in case of a failure. The J Series will now synchronize both configuration and runtime information. As a result, during failover, synchronization of the following information is shared: connection/session state and flow information, IPsec security associations, Network Address Translation (NAT) traffic, address book information, configuration changes, and more. In contrast to the typical router active/standby resiliency protocols such as Virtual Router Redundancy Protocol (VRRP), all dynamic flow and session information is lost and must be reestablished in the event of a failover. Some or all applications sessions will have to restart depending on the convergence time of the links or nodes. By maintaining state, not only is the session preserved, but security is intact. In an unstable network, this active/active configuration also mitigates link flapping affecting session performance.
Session-Based Forwarding Without the Performance Hit
In order to optimize the throughput and latency of the combined router and firewall, Junos OS implements session-based forwarding, an innovation that combines the session state information of a traditional firewall and the next-hop forwarding of a classic router into a single operation. With Junos OS, a session that is permitted by the forwarding policy is added to the forwarding table along with a pointer to the next-hop route. Established sessions have a single table lookup to verify that the session has been permitted and to find the next hop. This efficient algorithm improves throughput and lowers latency for session traffic when compared with a classic router that performs multiple table lookups to verify session information and then to find a next-hop route.
Session-based forwarding algorithm shows the session-based forwarding algorithm. When a new session is established, the session-based architecture within Junos OS verifies that the session is allowed by the forwarding policies. If the session is allowed, Junos OS will look up the next-hop route in the routing table. It then inserts the session and the next-hop route into the session and forwarding table and forwards the packet. Subsequent packets for the established session require a single table lookup in the session and forwarding table, and are forwarded to the egress interface.

Session-based forwarding algorithm
Product Options:
Juniper Networks J2320, J2350, J4350, and J6350 Services Routers offer a number of options in terms of LAN and WAN ports, hardware encryption acceleration, power supplies, DRAM, compact flash, and feature licenses.
LAN Ports
All J2320, J2350, J4350, and J6350 Services Routers ship with four fixed 10/100/1000 Ethernet ports. You can add more modular LAN interfaces by ordering the appropriate PIMs, Enhanced PIMs (EPIMs), or Universal PIMs (UPIMs).
WAN Ports
All J2320, J2350, J4350, and J6350 Services Routers ship without fixed WAN ports. The customer can add modular WAN interfaces by ordering the appropriate PIMs.
Hardware Encryption Acceleration
The J2320, J2350, and J4350 are available with optional hardware encryption acceleration. All J6350 models include hardware encryption acceleration by default. If you purchase a J2320, J2350, or J4350 without hardware encryption, you can add it later by ordering the appropriate encryption card.
Power Supply
All J2350, J4350, and J6350 Services Routers ship with either a DC power supply or an AC power supply and include a region-specific power cord. (The J2320 is available with AC power only.) The J6350 supports a second redundant AC or DC power supply, which can be added by ordering SSG-PS-DC or SSG-PS-AC. The region-specific AC power cable for SSG-PS-AC must be ordered separately.
DRAM
The J2320 and J2350 are upgradeable to a maximum of 1 GB DRAM. The J2320 and J2350 models without hardware encryption acceleration (J2320-JB-SC and J2350-JB-SC) come with 512 MB DRAM. All other models come with 1 GB of DRAM.
All J4350 models are upgradeable to a maximum of 2 GB DRAM. The J4350 model that ships without hardware encryption acceleration (J-4350-JB-SC) ships with 512 MB of DRAM. All other J4350 models ship with 1 GB of DRAM.
All J6350 Services Routers ship with 1 GB of DRAM and are upgradeable to 2 GB of DRAM. Order and install two additional JXX50-MEM-512M-S DIMMs.
Note that when upgrading DRAM, DIMMs should always be installed in pairs; for example, to upgrade to 1 GB DRAM, order two JXX50-MEM-512M-S DIMMs. To upgrade to 2 GB DRAM, order four JXX50-MEM-512M-S DIMMs.
With JUNOS Release 9.1 and later, all J Series Services Routers (J2320, J2350, J4350, J6350) must run at least 512 MB of DRAM.
Compact Flash
All J2320, J2350, J4350, and J6350 Services Routers ship with 512 MB of primary compact flash. You can replace that with a larger compact flash by ordering one either JX-CF-512M-S (for 512 MB) or JX-CF-1G-S (for 1 GB).
Network Deployments:
The J Series Services Routers are deployed at branch and remote locations in the network to provide all-in-one secure WAN connectivity, IP telephony, and connection to local PCs and servers via integrated Ethernet switching.
A typical network scenario is depicted for a distributed or branch enterprise. By using IPsec VPNs over the Internet, remote sites, branch offices, small datacenters and the headquarters are all connected as if they were in the same location variety of WAN connections are depicted.
The Distributed Enterprise Deployment

Technical Specifications:

Front View

Rear View
| Model: | J2320 | J2350 | J4350 | J6350 |
|---|---|---|---|---|
| Maximum Performance and Capacity | ||||
| Junos OS version tested | Junos OS 9.6 | Junos OS 9.6 | Junos OS 9.6 | Junos OS 9.6 |
| Firewall performance (Large packets) | 600 Mbps | 750 Mbps | 2 Gbps | 3.5 Gbps |
| Firewall performance (IMIX) | 400 Mbps | 500 Mbps | 600 Mbps | 1 Gbps |
| Firewall + Routing packets per second (64 byte) | 150 Kpps | 175 Kpps | 225 Kpps | 400 Kpps |
| AES256+SHA-1/3DES+SHA-1 VPN performance | 125 Mbps | 150 Mbps | 400 Mbps | 900 Mbps |
| IPsec VPN Tunnels | 512 MB / GB DRAM 256 / 512 |
512 MB / GB DRAM 256 / 512 |
512 MB / GB DRAM 256 / 512 |
1 GB / 2 GB DRAM 512 / 1024 |
| IPS (intrusion prevention system) | 115 Mbps | 130 Mbps | 250 Mbps | 500 Mbps |
| Antivirus | 25 Mbps | 30 Mbps | 65 Mbps | 130 Mbps |
| Connections per second | 5,000 | 5,000 | 10,000 | 20,000 |
| Maximum concurrent sessions DRAM options |
64 K / 128K 512 MB / 1 GB DRAM |
64 K / 128K 512 MB / 1 GB DRAM |
64 K / 128K 512 MB / 1 GB DRAM |
256 K / 256 K 512 MB / 1 GB DRAM |
| Maximum security policies | 2048 (1 GB DRAM) | 2048 (1 GB DRAM) | 5192 (1 GB DRAM) | 10384 (1 GB DRAM) |
| Maximum users supported | Unrestricted | Unrestricted | Unrestricted | Unrestricted |
| Network Connectivity | J2320 | J2350 | J4350 | J6350 |
| Fixed I/O | 4 x 10/100/1000 | 4 x 10/100/1000 | 4 x 10/100/1000 | 4 x 10/100/1000 |
| I/O slots | 3 x PIM | 5 x PIM | 4 x PIM + 2 x EPIM/PIM | 2 x PIM + 4 x EPIM/PIM |
| Services and Routing Engine slots | N/A | N/A | N/A | N/A |
| ExpressCard slot (3G WAN) | N/A | N/A | N/A | N/A |
| Optional maximum number of PoE ports | N/A | N/A | N/A | N/A |
| USB | 2 | 2 | 2 | 2 |
| Flash and Memory | J2320 | J2350 | J4350 | J6350 |
| Memory minimum and maximum (DRAM) | 512 MB, 1GB | 512 MB, 1GB | 512 MB, 1GB | 1GB, 2GB |
| Memory slots | 4 DIMM | 4 DIMM | 4 DIMM | 4 DIMM |
| Standard and Maximum Flash memory | 512 MB, 1 GB | 512 MB, 1 GB | 512 MB, 1 GB | 512 MB, 1 GB |
| USB port for external storage | Yes | Yes | Yes | Yes |
| Dimensions | J2320 | J2350 | J4350 | J6350 |
| Size (W x H x D) | 17.5 x 1.75 x 15.1 in (445 x 44 x 383 mm) | 17.5 x 1.75 x 15.1 in (445 x 44 x 383 mm) | 17.5 x 3.5 x 21.5 in (445 x 89 x 546 mm) | 17.5 x 3.5 x 21.5 in (445 x 89 x 546 mm) |
| Weight | 15 lb (6.8 kg)
No interface modules, 16.6 lb (7.6 kg) 3 interface modules |
16 lb (7.3 kg)
No interface modules, 19 lb (8.6 kg) 5 interface modules |
23 lb (10.4 kg)
No interface modules, 25.3 lb (11.5 kg) 6 interface modules |
25 lb (11.3 kg)
No interface modules, 1 power supply 30.7 lb (13.9 kg) 6 interface modules, 2 power supplies |
| Rack mountable | Yes, 1RU | Yes, 1.5RU | Yes, 2RU | Yes, 2RU |
| Power | J2320 | J2350 | J4350 | J6350 |
| Power supply (AC) | 100 to 240 VAC, 275 watts | 100 to 240 VAC, 300 watts | 100 to 240 VAC, 350 watts | 100 to 240 VAC, 420 watts |
| Average power consumption | 80 W | 80 W | 143 W | 166 W |
| Input frequency | 47–63 Hz | 47–63 Hz | 47–63 Hz | 47–63 Hz |
| Maximum current consumption | 3.2 A @ 100 VAC | 3.5 A @ 100 VAC | 5.7 A @ 100 VAC | 5.7 A @ 100 VAC |
| Maximum inrush current | 30 A | 32 A | 32 A | 42 A |
| Average heat dissipation | 273 BTU/hour | 273 BTU/hour | 488 BTU/hour | 566 BTU/hour |
| Maximum heat dissipation | 1091 BTU/hour | 1195 BTU/hour | 1070 BTU/hour | 1145 BTU/hour |
| Power supply (DC) | N/A | -48 to -60 VDC, 300 W | -48 to -60 VDC, 420 W | -48 to -60 VDC, 420 W |
| Redundant power supply (hot swappable) | No | No | No | Yes |
| Noise level | 40.0 dB | 59.2 dB | 59.3 dB | 61.2 dB |
| Environment | J2320 | J2350 | J4350 | J6350 |
| Operating Temperature | 32°–122° F (0°–50° C) |
32°–122° F (0°–50° C) |
32°–122° F (0°–50° C) |
32°–122° F (0°–50° C) |
| Non-Operating Temperature | 4°–158° F (-20°–70° C) |
4°–158° F (-20°–70° C) |
4°–158° F (-20°–70° C) |
4°–158° F (-20°–70° C) |
| Humidity | 10%–90% noncondensing | 10%–90% noncondensing | 10%–90% noncondensing | 10%–90% noncondensing |
| Mean time between failure (Bellcore model) | 7.2 years | 6.8 years | 7.6 years | 12 years with redundant power |
| Other | - | NEBS Level 3 | NEBS Level 3 | NEBS Level 3 |
| Certifications | J2320 | J2350 | J4350 | J6350 |
| Safety Certifications | UL, CUL, CSA, CB | UL, CUL, CSA, CB | UL, CUL, CSA, CB | UL, CUL, CSA, CB |
| Electromagnetic Compatibility (EMC) Certifications | FCC class B, CE class A, C-Tick, VCCI class B | FCC class B, CE class A, C-Tick, VCCI class B | FCC class B, CE class A, C-Tick, VCCI class B | FCC class B, CE class A, C-Tick, VCCI class A |
Additional Specification Features:
Protocols
Routing and Multicast
IP Address Management
Encapsulations
Traffic Management
Security
Voice Transport
|
High Availability
IPv6
SLA and Measurement
Logging and Monitoring
Administration
Operating System All J Series Services Routers ship with the worldwide version of Junos OS, which has standard encryption, as opposed to the US and Canada version, which has strong encryption. You can download the strong encryption version at no charge so long as you can certify eligibility. The download is available from Juniper’s Customer Support Center Web site: www.juniper.net/customers/csc/software/. Feature Licenses Licenses are required for advanced functionality on the J Series Services Routers. To run the Advanced BGP features, order Advanced BGP (JX-BGP-ADV-LTU). Each license is good for one chassis. On the high memory versions of the J Series, you can run Unified Threat Management consisting of antivirus, antispam, Web filtering and IPS. These licenses are good for one chassis and available as single features, bundles, single year and multi year ordering options. |
Additional Features and Comparison:
| Model: | J2320 | J2350 | J4350 | J6350 |
|---|---|---|---|---|
| Firewall | ||||
| Network attack detection | Yes | Yes | Yes | Yes |
| DoS and DDoS protection | Yes | Yes | Yes | Yes |
| TCP reassembly for fragmented packet protection | Yes | Yes | Yes | Yes |
| Brute force attack mitigation | Yes | Yes | Yes | Yes |
| SYN cookie protection | Yes | Yes | Yes | Yes |
| Zone-based IP spoofing | Yes | Yes | Yes | Yes |
| Malformed packet protection | Yes | Yes | Yes | Yes |
| VoIP Security | J2320 | J2350 | J4350 | J6350 |
| H.323. Application-level gateway (ALG) | Yes | Yes | Yes | Yes |
| SIP ALG | Yes | Yes | Yes | Yes |
| MGCP ALG | Yes | Yes | Yes | Yes |
| SCCP ALG | Yes | Yes | Yes | Yes |
| Network Address Translation (NAT) for VoIP protocols | Yes | Yes | Yes | Yes |
| Routing | J2320 | J2350 | J4350 | J6350 |
| BGP instances | 32 | 32 | 32 | 64 |
| BGP peers | 512 MB / 1 GB DRAM 64 / 64 | 512 MB / 1 GB DRAM 64 / 64 | 512 MB / 1 GB DRAM 64 / 64 | 1 GB / 2 GB DRAM 64 / 64 |
| BGP routes | 512 MB / 1 GB DRAM 64 K / 400 K | 512 MB / 1 GB DRAM 64 K / 400 K | 512 MB / 1 GB DRAM 64 K / 400 K | 1 GB / 2 GB DRAM
400 K / 1000 K |
| OSPF instances | 512 MB / 1 GB DRAM 32 / 32 |
512 MB / 1 GB DRAM 32 / 32 |
512 MB / 1 GB DRAM 32 / 32 |
1 GB / 2 GB DRAM 64 / 64 |
| OSPF routes | 512 MB / 1 GB DRAM 5 K / 10 K |
512 MB / 1 GB DRAM 5 K / 10 K |
512 MB / 1 GB DRAM 5 K / 10 K |
1 GB / 2 GB DRAM 10 K / 20 K |
| RIP v1/v2 instances | 512 MB / 1 GB DRAM 32 / 32 |
512 MB / 1 GB DRAM 32 / 32 |
512 MB / 1 GB DRAM 32 / 32 |
1 GB / 2 GB DRAM 64 / 64 |
| RIP v2 routes | 512 MB / 1 GB DRAM 5 K / 10 K |
512 MB / 1 GB DRAM 5 K / 10 K |
512 MB / 1 GB DRAM 5 K / 10 K |
1 GB / 2 GB DRAM 10 K / 20 K |
| Static routes | 512 MB / 1 GB DRAM 5 K / 10 K |
512 MB / 1 GB DRAM 5 K / 10 K |
512 MB / 1 GB DRAM 5 K / 10 K |
1 GB / 2 GB DRAM 10 K / 20 K |
| Source-based routing | Yes | Yes | Yes | Yes |
| Policy-based routing | Yes | Yes | Yes | Yes |
| Equal-cost multipath (ECMP) | Yes | Yes | Yes | Yes |
| Multicast | Yes | Yes | Yes | Yes |
| Reverse Path Forwarding (RPF) | Yes | Yes | Yes | Yes |
| Internet Group Management Protocol (IGMP) (v1,v2, v3) | Yes | Yes | Yes | Yes |
| PIM single mode | Yes | Yes | Yes | Yes |
| PIM source-specific multicast | Yes | Yes | Yes | Yes |
| Multicast inside IPsec tunnel | Yes | Yes | Yes | Yes |
| MPLS | J2320 | J2350 | J4350 | J6350 |
| Layer 2 VPN (VPLS) | Yes | Yes | Yes | Yes |
| Layer 3 VPN | Yes | Yes | Yes | Yes |
| LDP | Yes | Yes | Yes | Yes |
| RSVP | Yes | Yes | Yes | Yes |
| Circuit Cross-connect (CCC) | Yes | Yes | Yes | Yes |
| Translational Cross-connect (TCC) | Yes | Yes | Yes | Yes |
| MPLS | J2320 | J2350 | J4350 | J6350 |
| IGMP (v1, v2, v3) | Yes | Yes | Yes | Yes |
| PIM SM | Yes | Yes | Yes | Yes |
| PIM source-specific multicast (SSM) | Yes | Yes | Yes | Yes |
| Multicast inside IPsec tunnel | Yes | Yes | Yes | Yes |
| IPsec VPN | J2320 | J2350 | J4350 | J6350 |
| Concurrent VPN tunnels | 256 / 512 (512 MB / 1 GB DRAM) |
256 / 512 (512 MB / 1 GB DRAM) |
256 / 512 (512 MB / 1 GB DRAM) |
512 / 1024 (1 GB / 2 GB DRAM) |
| Tunnel interfaces | 256 / 512 (512 MB / 1 GB DRAM) |
256 / 512 (512 MB / 1 GB DRAM) |
256 / 512 (512 MB / 1 GB DRAM) |
512 / 1024 (1 GB / 2 GB DRAM) |
| DES (56-bit), 3DES (168-bit) and AES (256-bit) |
Yes | Yes | Yes | Yes |
| MD-5 and SHA-1 authentication | Yes | Yes | Yes | Yes |
| Manual key, Internet Key Exchange (IKE), public key infrastructure (PKI) (X.509) | Yes | Yes | Yes | Yes |
| Perfect forward secrecy (DH Groups) | 1,2,5 | 1,2,5 | 1,2,5 | 1,2,5 |
| Prevent replay attack | Yes | Yes | Yes | Yes |
| Dynamic remote access VPN | Yes | Yes | Yes | No |
| Layer2 Tunneling Protocol (L2TP) within IPsec | No | No | No | No |
| IPsec (NAT) traversal | Yes | Yes | Yes | Yes |
| Redundant VPN gateways | Yes | Yes | Yes | Yes |
| User Authentication and Access Control | J2320 | J2350 | J4350 | J6350 |
| Third-party user authentication | RADIUS, RSA, SecureID, LDAP | RADIUS, RSA, SecureID, LDAP | RADIUS, RSA, SecureID, LDAP | RADIUS, RSA, SecureID, LDAP |
| RADIUS Accounting | Yes | Yes | Yes | Yes |
| XAUTH VPN, Web-based, 802.X authentication | Yes | Yes | Yes | Yes |
| PKI certificate requests (PKCS 7 and PKCS 10) | Yes | Yes | Yes | Yes |
| Web-based authentication | Yes | Yes | Yes | Yes |
| 802.1X authentication (JUNOS 9.2) | Yes | Yes | Yes | Yes |
| PKI Certificate requests (PKCS 7 and PKCS 10) | Yes | Yes | Yes | Yes |
| Certificate Authorities supproted | VeriSign, Entrust, Microsoft, RSA Keon, iPLanet, (Netscape), Baltimore, DoD PKI | VeriSign, Entrust, Microsoft, RSA Keon, iPLanet, (Netscape), Baltimore, DoD PKI | VeriSign, Entrust, Microsoft, RSA Keon, iPLanet, (Netscape), Baltimore, DoD PKI | VeriSign, Entrust, Microsoft, RSA Keon, iPLanet, (Netscape), Baltimore, DoD PKI |
| Virtualization | J2320 | J2350 | J4350 | J6350 |
| Maximum number of security zones | 40 | 40 | 50 | 60 |
| Maximum number of virtual routers | 25 | 25 | 30 | 60 |
| Maximum number of VLANs | 256 | 256 | 512 | 1024 |
| Encapsulations | J2320 | J2350 | J4350 | J6350 |
| Point-to-Point Protocol (PPP) | Yes | Yes | Yes | Yes |
| Multilink Point-to-Point Protocol (MLPPP) | Yes | Yes | Yes | Yes |
| MLPPP max physical interfaces | 6 | 10 | 12 | 12 |
| Frame Relay | Yes | Yes | Yes | Yes |
| Multilink Frame (MLFR) (FRF 15, FRF 16) | Yes | Yes | Yes | Yes |
| MLFR max physical interfaces | 6 | 10 | 12 | 12 |
| HDLC | Yes | Yes | Yes | Yes |
| Mode of Operation | J2320 | J2350 | J4350 | J6350 |
| Layer 2 (transparent) mode(5) | No | No | No | No |
| Layer 3 (route and/or NAT) mode | Yes | Yes | Yes | Yes |
| Address Translation | J2320 | J2350 | J4350 | J6350 |
| Source NAT with Port Address Translation (PAT) | Yes | Yes | Yes | Yes |
| Static NAT | Yes | Yes | Yes | Yes |
| Destination NAT with PAT | Yes | Yes | Yes | Yes |
| Mapped IP (MIP) | Yes | Yes | Yes | Yes |
| Virtual IP (VIP) | Yes | Yes | Yes | Yes |
| MIP/VIP Grouping | Yes | Yes | Yes | Yes |
| IP Address Assignment | J2320 | J2350 | J4350 | J6350 |
| Static | Yes | Yes | Yes | Yes |
| DHCP, PPPoE client | Yes | Yes | Yes | Yes |
| Internal DHCP server | Yes | Yes | Yes | Yes |
| DHCP relay | Yes | Yes | Yes | Yes |
| L2 Switching | J2320 | J2350 | J4350 | J6350 |
| VLAN 802.1Q | Yes | Yes | Yes | Yes |
| Link Aggregation 802.3ad/LACP | Yes | Yes | Yes | Yes |
| Jumbo Frame (9216 Byte) | Yes | Yes | Yes | Yes |
| Spanning Tree Protocol (STP) 802.1D, RSTP 802.1w, MSTP 802.1s | Yes | Yes | Yes | Yes |
| Authentication 802.1x Port based and multiple supplicant | Yes | Yes | Yes | Yes |
| Traffic Management Quality of Service (QoS) | J2320 | J2350 | J4350 | J6350 |
| Guaranteed bandwidth | Yes | Yes | Yes | Yes |
| Maximum bandwidth | Yes | Yes | Yes | Yes |
| Ingress traffic policing | Yes | Yes | Yes | Yes |
| Priority-bandwidth utilization | Yes | Yes | Yes | Yes |
| Differv marking | Yes | Yes | Yes | Yes |
| High Availability (HA) | J2320 | J2350 | J4350 | J6350 |
| Active/Active - L3 mode | Yes | Yes | Yes | Yes |
| Active/Passive -L3 mode | Yes | Yes | Yes | Yes |
| Configuration synchronization | Yes | Yes | Yes | Yes |
| VRRP | Yes | Yes | Yes | Yes |
| Session synchronization for firewall and VPN | Yes | Yes | Yes | Yes |
| Session failover for routing change | Yes | Yes | Yes | Yes |
| Device failure detection | Yes | Yes | Yes | Yes |
| Link failure detection | Yes | Yes | Yes | Yes |
| Unified Threat Management | J2320 | J2350 | J4350 | J6350 |
| Intrusion Prevention System (IPS) | Yes | Yes | Yes | Yes |
| Protocol anomaly detection | Yes | Yes | Yes | Yes |
| Stateful protocol signatures | Yes | Yes | Yes | Yes |
| Intrusion prevention system (IPS) attack pattern obfuscation | Yes | Yes | Yes | Yes |
| Customer signatures creation | Yes | Yes | Yes | Yes |
| Frequency of updates | Daily and emergency | Daily and emergency | Daily and emergency | Daily and emergency |
| Antivirus | J2320 | J2350 | J4350 | J6350 |
| Express AV (packet-based AV) | No | Yes | Yes | Yes |
| File-based antivirus | Yes | Yes | Yes | Yes |
| Signature database | Yes | Yes | Yes | Yes |
| Protocols scanned | POP3, HTTP, SMTP, IMAP, FTP | POP3, HTTP, SMTP, IMAP, FTP | POP3, HTTP, SMTP, IMAP, FTP | POP3, HTTP, SMTP, IMAP, FTP |
| Antispyware | Yes | Yes | Yes | Yes |
| Antiadware | Yes | Yes | Yes | Yes |
| Antikeylogger | Yes | Yes | Yes | Yes |
| Antispam | Yes | Yes | Yes | Yes |
| Integrated Web filtering | Yes | Yes | Yes | Yes |
| Redirect Web filtering | Yes | Yes | Yes | Yes |
| Content filtering | Yes | Yes | Yes | Yes |
| Based on MIME type, file extension, and protocol commands | Yes | Yes | Yes | Yes |
| System Management | J2320 | J2350 | J4350 | J6350 |
| Web UI | Yes | Yes | Yes | Yes |
| Command-line interface | Yes | Yes | Yes | Yes |
| Network and Security Manager | Yes | Yes | Yes | Yes |
| STRM Series | Yes | Yes | Yes | Yes |
| Certifications | J2320 | J2350 | J4350 | J6350 |
| USA | ||||
| Safety certifications | UL 60950-1 | UL 60950-1 | UL 60950-1 | UL 60950-1 |
| EMC certifications | FCC Class B | FCC Class B | FCC Class A | FCC Class A |
| Network homologation | TIA-968 | TIA-968 | TIA-968 | TIA-966 |
| Canada | ||||
| Safety certifications | UL 60950-1 | UL 60950-1 | UL 60950-1 | UL 60950-1 |
| EMC certifications | ICES class B | ICES class B | ICES class A | ICES class A |
| Network homologation | CS-03 | CS-03 | CS-03 | CS-03 |
| European Union | ||||
| Safety certifications | EN 60950-1 | EN 60950-1 | EN 60950-1 | EN 60950-1 |
| EMC certifications | EN 55022 Class B, EN 300386 | EN 55022 Class B, EN 300386 | EN 55022 Class A, EN 300386 | EN 55022 Class A, EN 300386 |
| Network homologation | CTR 12 / 13, CTR 21, DoC | CTR 12 / 13, CTR 21, DoC | CTR 12 / 13, CTR 21, DoC | CTR 12 / 13, CTR 21, DoC |
| Japan | ||||
| Safety certifications | CB Scheme | CB Scheme | CB Scheme | CB Scheme |
| EMC certifications | VCCI Class B | VCCI Class B | VCCI Class A | VCCI Class A |
| Network homologation | Certificate for Technical Conditions | Certificate for Technical Conditions | Certificate for Technical Conditions | Certificate for Technical Conditions |
| Australia | ||||
| Safety certifications | AS / NZS 60950-1 | AS / NZS 60950-1 | AS / NZS 60950-1 | AS / NZS 60950-1 |
| EMC certifications | AS / NZS CISPR22 Class B | AS / NZS CISPR22 Class B | AS / NZS CISPR22 Class A | AS / NZS CISPR22 Class A |
| Network homologation | AS / ACIF S 002, S 016, S 043.1, S043.2 | AS / ACIF S 002, S 016, S 043.1, S043.2 | AS / ACIF S 002, S 016, S 043.1, S043.2 | AS / ACIF S 002, S 016, S 043.1, S043.2 |
| New Zealand | ||||
| Safety certifications | AS / NZS 60950-1 | AS / NZS 60950-1 | AS / NZS 60950-1 | AS / NZS 60950-1 |
| EMC certifications | AS / NZS CISPR22 Class B | AS / NZS CISPR22 Class B | AS / NZS CISPR22 Class A | AS / NZS CISPR22 Class A |
| Network homologation | PTC 217, PTC 273 | PTC 217, PTC 273 | PTC 217, PTC 273 | PTC 217, PTC 273 |
Documentation:
![]()
Download the Juniper Networks J Series Services Routers Datasheet (PDF).
| Juniper Networks Products | ||
|---|---|---|
| J Series Appliances | ||
| Juniper Networks J2320 Services Routers -
Base Memory (512MB DRAM, 512 MB Flash) - JUNOS, 3 PIM Slots, SW Security, AC Power Supply, 19" Rack Mount |
#J2320-JB-SC List Price: $2,500.00 |
|
| Juniper Networks J2320 Services Routers -
Base Memory (512MB DRAM, 512 MB Flash) with TAA - JUNOS, 3 PIM Slots, SW Security, AC Power Supply, TAA 19" Rack Mount |
#J2320-JB-SC-TAA List Price: $4,000.00 |
|
| Juniper Networks J2320 Services Routers -
High Memory (1GB DRAM, 512 MB Flash) - JUNOS, 3 PIM Slots, HW Encryption, AC Power Supply, 19" Rack Mount |
#J2320-JH List Price: $4,000.00 |
|
| Juniper Networks Content Subscriptions | ||
| First Year Subscriptions Main Office Content Security | ||
| One Year Security Subscription for Enterprise
on J2320 - Includes Antivirus, Web Filtering, Antispam and IDP |
#J2320-SMB-CS List Price: $3,300.00 |
|
| Three Year Security Subscription for Enterprise
on J2320 - Includes Antivirus, Web Filtering, Antispam and IDP |
#J2320-SMB-CS-3 List Price: $7,590.00 |
|
| Renewal Subscriptions Main Office Content Security | ||
| One Year Renewal Security Subscription for Enterprise
on J2320 - Includes Antivirus, Web Filtering, Antispam and IDP |
#J2320-SMB-CS-R List Price: $3,300.00 |
|
| Three Year Renewal Security Subscription for Enterprise
on J2320 - Includes Antivirus, Web Filtering, Antispam and IDP |
#J2320-SMB-CS-3-R List Price: $7,590.00 |
|
Use our Quote Form to request additional subscription pricing |
||
| Juniper Networks Accessories | ||
| Interface Modules | ||
| 1-Port ADSL2+ Annex A PIM, Supporting ADSL/ADSL2/ADSL2+ Annex A | #JX-1ADSL-A-S List Price: $750.00 |
|
| 1-Port ADSL2+ Annex B PIM, Supporting ADSL/ADSL2/ADSL2+ Annex B | #JX-1ADSL-B-S List Price: $750.00 |
|
| 2 Port Channelized T1/E1 PIM | #JX-2CT1E1-RJ45-S List Price: $1,300.00 |
|
| 2 Port E1 PIM with integrated CSU/DSU | #JX-2E1-RJ48-S List Price: $1,000.00 |
|
| 2 Port Serial PIM | #JX-2Serial-S List Price: $700.00 |
|
| 2 Port 2-wire or 1 Port 4-wire G.SDHSL PIM | #JX-2SHDSL-S List Price: $950.00 |
|
| 2 Port T1 PIM with integrated CSU/DSU | #JX-2T1-RJ48-S List Price: $1,000.00 |
|
| 4xISDN BRI - S Interface | #JX-4BRI-S-S List Price: $1,100.00 |
|
| 4xISDN BRI - U Interface | #JX-4BRI-U-S List Price: $1,500.00 |
|
| SFP 100BASE-FX Optical Transceiver, LC connector | #JX-SFP-1FE-FX List Price: $250.00 |
|
| SFP 1000Base-LH Gigabit Optical Tranceiver SFP Module | #JX-SFP-1GE-LH List Price: $6,000.00 |
|
| SFP 1000Base-LX Gigabit Optical Tranceiver SFP Module | #JX-SFP-1GE-LX List Price: $995.00 |
|
| SFP 1000Base-SX Gigabit Optical Tranceiver Module | #JX-SFP-1GE-SX List Price: $500.00 |
|
| SFP 1000BASE-T Gigabit Copper Transceiver SFP Module | #JX-SFP-1GE-T List Price: $400.00 |
|
| 16 Port Gigabit Ethernet 10/100/1000 Copper Double-height Universal PIM | #JXU-16GE-TX-S List Price: $3,000.00 |
|
| 1 port Small Form-Factor pluggable (SFP) Universal Physical Interface Module. (SFP Tranceiver purchased separately) 100M and 1000M SFP speeds supported. |
#JXU-1SFP-S List Price: $1,500.00 |
|
| 6 Port SFP Gigabit Ethernet Universal PIM Note SFPs sold separately. Supports 1000M SFPs only |
#JXU-6GE-SFP-S List Price: $3,000.00 |
|
| 8 Port Gigabit Ethernet 10/100/1000 Copper Universal PIM | #JXU-8GE-TX-S List Price: $1,800.00 |
|
| Power Cables | ||
| Power Cable - Spare - Type B, NEMA 5-15 (North American 15A/125V grounded) | #CBL-JX-PWR-US List Price: $50.00 |
|
| WAN Optimization Services Module and License Upgrades | ||
| Upgrade ISM200-WXC, Enable Encryption Services License (SSL) | #ENC-ISM200-WXC List Price: $795.00 |
|
| Upgrade a JX-ISM-200-WXC from 2Mbps to 10Mbps | #WXOS-ISM200-2-10 List Price: $6,500.00 |
|
| Upgrade a JX-ISM-200-WXC from 2Mbps to 4Mbps | #WXOS-ISM200-2-4 List Price: $2,500.00 |
|
| Upgrade a JX-ISM-200-WXC from 4Mbps to 10Mbps | #WXOS-ISM200-4-10 List Price: $4,500.00 |
|
| Upgrade a JX-ISM-200-WXC from 512Kbps to 10Mbps | #WXOS-ISM200-512K-10 List Price: $6,000.00 |
|
| Upgrade a JX-ISM-200-WXC from 512Kbps to 2Mbps | #WXOS-ISM200-512K-2 List Price: $2,000.00 |
|
| Upgrade a JX-ISM-200-WXC from 512Kbps to 4Mbps | #WXOS-ISM200-512K-4 List Price: $3,000.00 |
|
| Memory | ||
| 256MB Memory Module | #J-MEM-256M-S List Price: $600.00 |
|
| 512MB Memory Module | #J-MEM-512M-S List Price: $1,000.00 |
|
| Compact Flash | ||
| 128M Compact Flash for J-Series | #JX-CF-128M-S List Price: $300.00 |
|
| 256M Compact Flash for J-Series | #JX-CF-256M-S List Price: $400.00 |
|
| 512M Compact Flash for J-Series | #JX-CF-512M-S List Price: $800.00 |
|
| 1G Compact Flash for J-Series | #JX-CF-1G-S List Price: $1,600.00 |
|
| Licenses | ||
| DLSw Licenses have been discontinued and is now
included in the base system. License no longer
required. For DC-Power-Supply or NEBS-Compliant systems please refer to the TAA section. |
||
| Advanced BGP License for J-Series | #JX-BGP-ADV-LTU List Price: $2,000.00 |
|
| Accessories | ||
| J2320 to SSG 320M Conversion Kit | #J2320-SSG-CONV-S List Price: $1,000.00 |
|
| EIA530 cable (DTE) | #JX-CBL-EIA530-DTE List Price: $100.00 |
|
| RS232 cable (DTE) | #JX-CBL-RS232-DTE List Price: $100.00 |
|
| RS449 cable (DTE) | #JX-CBL-RS449-DTE List Price: $100.00 |
|
| V.35 cable (DTE) | #JX-CBL-V35-DTE List Price: $100.00 |
|
| X.21 cable (DTE) | #JX-CBL-X21-DTE List Price: $100.00 |
|
| J2320, J2350 Hardware Crytographic Acceleration Module | #JXH-HC2-S List Price: $1,000.00 |
|
| 1 Gigabyte RAM Memory Upgrade for the SSG 500 series, SSG 300 series, J2320, J2350, J4350, J6350 | #SSG-500-MEM-1GB List Price: $2,000.00 |
|


