|

|
STRM Series Appliances |
Juniper Networks STRM 5000 Base Hardware Appliance
Note: Requires at least STRM5K-ADD-2500E-100KF for All-in-One Deployment to complete the STRM
5000 Order.
Note: Requires STRM5K-ADD-EP-2500E OR
STRM5K-ADD-FP-100KF License SKU for Distributed
deployment to complete the STRM5000 Order. |
#STRM5000-A-BSE
List Price: $11,000.00 |
|
More pricing below,
click here
STRM5000 Overview:
Juniper Networks STRM5000 Security Threat Response Manager is an enterprise and carrier-class appliance which provides a scalable network security management
solution for medium-sized companies up to large, globally-deployed organizations. STRM5000 is the ideal solution for growing companies that anticipate the need
for additional flow and event monitoring capacity in the future. It is also the base platform for large companies that are geographically dispersed and looking
for a distributed enterprise/carrier-class scalable solution. The STRM5000 utilizes on-board event/flow collection and correlation capabilities, and is expandable
with additional STRM5000 appliances acting as event and flow collectors.
Juniper Networks STRM Series Security Threat Response Managers combine, analyze and manage an incomparable set of surveillance data—network behavior,
security events, vulnerability profiles and threat information—to empower companies to efficiently manage business operations on their networks from a
single console. With pre-installed software, a hardened operating system and a Web-based setup, the STRM Series lets you get your network security up and running
quickly and easily. The bottom line of the STRM Series is simple deployment, fast implementation and improved security, at a low total cost of ownership.

STRM Series dashboard
(Click enlarge)
The integrated approach of the STRM Series used in conjunction with unparalleled data collection, analysis, correlation and auditing capabilities, enables
organizations to quickly and easily implement a corporate-wide security management program that delivers security best practices that include:
Log Management: STRM Series provides scalable log management by enabling distributed log collection across an organization and a centralized view of the information.
Threat Management: STRM Series provides an advanced network security management solution that bridges the gap between network and security operations to deliver real time surveillance
and detect complex IT-based threats.
Compliance Management: STRM Series brings to enterprises, institutions and agencies the accountability, transparency and measurability that are critical factors
to the success of any IT security program required to meet regulatory mandates.

Features & Benefits:
| Features |
Features
Description |
Benefits |
|
Embedded QFlow |
Allows users to tap into Layer 7 traffic by using existing ports or extended 4-port module (optional only on the STRM500). |
Provides visibility into the security controls, the business applications, and the assets that are being protected. |
|
Distributed support |
Ability to scale to large distributed deployments from 500 to 10,000+ events from 15 K to 400 K flows per minute. |
Users have the flexibility to scale to large deployments as their business grows. STRM Series can be easily deployed in large distributed environments. |
|
Hardened OS |
Juniper’s security team monitors and maintains the STRM Series that is optimized for performance and security. |
Users don’t need to worry about security vulnerabilities, support or patch management for the OS. |
|
Redundant Arrays of Inexpensive
Disks (RAID) Implementation |
STRM Series utilizes embedded RAID (1-5) implementation. |
RAID implementation provides high availability (HA) and redundancy. |
|
All-in-one appliances |
Event collection, flow collection event processing, flow processing, correlation, analysis and reporting are all embedded within the Juniper Networks
STRM Series Security Threat Response Managers. |
All core functions are available within the system and it is easy for users to deploy and manage in minutes. STRM Series architecture provides a streamlined
solution for secure and efficient log management from a common interface. |
|
Easy and quick install |
Easy out-of-the-box setup wizard. |
Users can install and manage STRM Series appliances in a couple of steps. |
|
Centralized updates |
One place to get all updates. |
Users don’t need to worry about maintaining appliance and OS updates and patches. |
|
One stop support |
Juniper Networks Technical Assistance Center (JTAC) supports all aspects of the STRM Series and multi-vendor support. |
Users don’t need to go to several places to get support even for multi-vendor issues. |
Log Management and Reporting
STRM Series provides a comprehensive log management framework that includes scalable and secure log management capabilities integrated with real time event correlation,
policy monitoring, threat detection and compliance reporting.
| Features |
Features
Description |
Benefits |
|
Comprehensive log management |
Scalable and secure log management with storage capabilities from GB to TB of data storage. |
Provides long term collection, archival, search and reporting of event logs, flow logs and application data that enables logging taxonomy from a centralized view. |
|
Comprehensive reporting |
STRM Series comes with 500+ canned reports. Report Wizard allows users to customize and schedule daily, weekly and monthly reports. These reports could be exported in PDF, HTML, RTF, Word, Excel and XML formats. |
Provides users not only the convenience of canned reports but also the flexibility to create and customize their own reports according to their business needs. |
|
Log management and reporting only
option |
Provides a comprehensive log management and reporting solution for organizations that are looking to implement a distributed log management only solution to collect, archive, customize and analyze network security event logs. |
Allows users to start with log management and reporting only option and then upgrade to full blown STRM Series functionality as their business need grows without upgrading their existing hardware. |
|
Log retention and storage |
STRM Series can easily archive logs and integrate into an existing storage infrastructure for long-term log retention and hands of storage. |
The STRM Series database enables organizations to archive event and flow logs for however long is specified by a specific regulation. |
|
Tamper proof data |
- Event and flow logs are protected by SHA-x (1-256) hashing for tamper proof log archives.
- Support of extensive log file integrity checks including National Institute of Standards and Technology (NIST) log management standards.
|
Provides secure storage based on industry regulations. |
|
Real-time event viewing |
STRM Series allows users to monitor and investigate events in real-time or perform advanced searches. The event viewer indicates what events are being correlated to offenses and which are not. |
- Users have the ability to quickly and effectively view and filter real-time events.
- Provides a flexible query engine that includes advanced aggregating capability and valuable and actionable IT forensics.
|
|
Data warehousing |
Purpose-built data warehouse for high speed insertion and retrieval of data archive of all security logs, event logs and network activity logs (flow logs). |
Full audit of all original events and flow content without modification. |
Threat Management
Juniper Networks STRM Series Security Threat Response Managers’ network security management solution takes an innovative approach to managing computer-based
threats in the enterprise. Recognizing that discrete analysis of security events is not enough to properly detect threats, the STRM Series was developed to provide an
integrated approach to threat management that combines the use of traditionally silo’d information to more effectively detect and manage today’s complex
threats. Specific information that is collected includes:
Network Events:
Events generated from networked resources including switches, routers, servers and desktops.
Security Logs:
Includes log data generated from security devices like firewalls, VPNs, intrusion detection/prevention, antivirus, identity management and vulnerability scanners.
Host and Application Logs:
Includes log data from industry leading host operating systems (Microsoft Windows, UNIX and Linux) and from critical business applications (authentication, database, mail and Web).
Network and Flow Logs:
Includes flow data generated by networking devices from vendors and provides the ability to build a context of network and protocol activity.
User and Asset Identity Information:
Includes information from commonly used directories including active directory and Lightweight Directory Access Protocol (LDAP). By incorporating patent
pending “offense” management technology, this integrated information is normalized and correlated by the STRM Series, resulting in automated intelligence that
quickly detects, notifies and responds to threats missed by other security solutions with isolated visibility.
| Features |
Features
Description |
Benefits |
|
Out-of-the-box correlation rules |
STRM Series correlation rules allow users to detect specific or sequential events or offenses. A rule consists of tests and functions that perform a response when events match. |
Provides hundreds of out-of-the-box correlation rules that provide immediate value. Users can create their own rules by using the STRM Series rule wizard to generate automated
alerts to security response teams and enable real time policy enforcement. |
|
Offense management |
The offense manager allows you to investigate offenses, behaviors, anomalies, targets and attackers on your network. The STRM Series can correlate events and network
activity with targets located across multiple networks in the same offense and ultimately the same network incident. |
This allows users to effectively investigate each offense in their network. Users can navigate the common interface to investigate the event details to determine the
unique events that caused the offense. |
|
QID mappings |
STRM Series associates or maps a normalized or raw event to a high-level and low-level category. |
Allows users to see real-time events mapped to appropriate categories, which allows the STRM Series to map unknown device events to known STRM Series events in order to be categorized and correlated appropriately. |
|
Historical profiling |
Extensive use of historical profiling for improved accuracy of results. STRM Series collects and stores entire event data for later use. |
Allows users to view historical data at any given point as well as views into incident management and the tracking of events. |
|
STRM Series magistrate |
STRM Series magistrate component prioritizes the offenses and assigns a magnitude value based on several factors that include the number of events, severity, relevance and credibility. |
- Allows users to see prioritized security events rather than looking through thousands of log events.
- Allows users to see what events have the most impact on their business and respond quickly to threats.
|
|
Offense Manager API |
STRM Series provides a set of open API’s to modify and configure incident management parameters like “create, close and open” offenses. |
Allows users to integrate third-party customer care applications like Remedy and other ticketing solutions. |
Compliance Management
Organizations of all sizes across almost every
vertical market face a growing set of requirements
from IT security regulatory mandates.

Recognizing that compliance with a policy or
regulation will evolve over time, many industry
experts recommend a compliance program that can
demonstrate and build upon these key factors:
Accountability: Providing surveillance
that reports on who did what and when.
Transparency: Providing visibility into
the security controls, business applications and
assets that are being protected.
Measurability: Metrics and reporting
around IT risks within a company.
| Features |
Features
Description |
Benefits |
|
Built-in compliance reports |
Out-of-the-box compliance reports are included with the STRM Series. |
Provides 500+ out-of-the-box compliance reports. |
|
Reporting and alerting
capabilities for control framework |
- Control Objectives for Information and related Technology (CobiT)
- International Organization for Standardization (ISO) ISO/IEC 27002 (17799)
- Common Criteria (CC) (ISO/IEC 15408) NIST special publication 800-53 revision 1 and Federal Information Processing
- Standard (FIPS) 200
|
Enables repeatable compliance monitoring, reporting and auditing processes. |
|
Compliance-focused regulation
workflow |
- Payment Card Industry Data Security Standard (PCI DSS)
- Health Insurance Portability and Accountability Act (HIPAA)
- Sarbanes-Oxley Act (SOX)
- Graham-Leach-Bliley Act (GLBA)
- Federal Information Security Management
Act (FISMA)
|
- Supports multiple regulations and security best practices.
- Compliance-driven report templates to meet specific regulatory reporting and auditing requirements.
|
|
Management-level reports on
overall security state |
The STRM Series reports interface allows you to create, distribute and manage reports. These reports can be generated in PDF, HTML, RTF, XML and XLS formats. |
Users can use the report wizard to create executive and operational level reports that combine any network traffic and security event data in a single report. |
Diagram:
Depicts two scenarios with STRM500 and STRM2500 in a typical deployment, and an STRM5000 deployed in a distributed environment with the STRM500 configured as a QFlow Collector

Architecture:

Technical Specifications:


| Model: |
STRM500 |
STRM2500 |
STRM5000 |
 |
 |
 |
|
Dimensions and Power |
|
Size (W x H x D) |
17.72 x 3.5 x 17.26 in
(45 x 8.8 x 43.84 cm) |
23.52 x 3.5 x 17.26 in
(59.75 x 8.8 x 43.84 cm) |
23.52 x 3.5 x 17.26 in
(59.75 x 8.8 x 43.84 cm) |
|
Weight |
26 Ib 2 oz |
39 Ib 5 oz |
43 lb 10 oz |
|
Rack mountable |
2U |
2U |
2U |
|
A/C power supply |
90 V to 264 V hot swap dual redundant
400 watt AC power module |
90 V to 264 V hot swap dual redundant
700 watt AC power module |
90 V to 264 V hot swap dual redundant
700 watt AC power module |
|
D/C power supply |
90 V to 264 V hot swap dual redundant
710 watt DC power module with optional 48 V DC power supply |
90 V to 264 V hot swap dual redundant
710 watt DC power module with optional 48 V DC power supply |
90 V to 264 V hot swap dual redundant 710 watt DC power module with optional 48 V DC power supply |
|
Simultaneous AC and DC modules support |
Yes |
Yes |
Yes |
|
Chassis Material |
18 gauge cold rolled steel |
18 gauge cold rolled steel |
18 gauge cold rolled steel |
|
Fans |
2 x 80 mm hot swap redundant fans (2nd optional) |
2 x 80 mm hot swap redundant fans (2nd optional) |
2 x 80 mm hot swap redundant fans (2nd optional) |
|
Traffic ports |
2x RJ45 10/100/1000 |
2x RJ45 10/100/1000 |
2x RJ45 10/100/1000 |
|
Console port |
1x RJ45 serial console |
1x RJ45 serial console |
1x RJ45 serial console |
|
Environment |
|
Operating Temperature |
41° to 104° F
(5° to 40° C) |
41° to 104° F
(5° to 40° C) |
41° to 104° F
(5° to 40° C) |
|
Storage Temperature |
-40° to 158° F
(-40° to 70° C) |
-40° to 158° F
(-40° to 70° C) |
-40° to 158° F
(-40° to 70° C) |
|
Relative Humidity (Operating) |
8% to 90% noncondensing |
8% to 90% noncondensing |
8% to 90% noncondensing |
|
Relative Humidity (Storage) |
5% to 95% noncondensing |
5% to 95% noncondensing |
5% to 95% noncondensing |
|
Altitude (Operating) |
10,000 ft maximum |
10,000 ft maximum |
10,000 ft maximum |
|
Altitude (Storage) |
40,000 ft maximum |
40,000 ft maximum |
40,000 ft maximum |
|
Compliance and Safety |
|
Safety Certifications |
CAN/CSA-C22.2 No. 60950-1-03
UL60950-1:2003
EN60950-1:2001+A11
IEC 60950-1:2001 |
CAN/CSA-C22.2 No. 60950-1-03
UL60950-1:2003
EN60950-1:2001+A11
IEC 60950-1:2001 |
CAN/CSA-C22.2 No. 60950-1-03
UL60950-1:2003
EN60950-1:2001+A11
IEC 60950-1:2001 |
|
Emissions Certifications |
FCC Class A,
EN 55022 Class A,
EN 55024 Immunity,
EN 61000-3-2,
VCCI Class A |
FCC Class A,
EN 55022 Class A,
EN 55024 Immunity,
EN 61000-3-2,
VCCI Class A |
FCC Class A,
EN 55022 Class A,
EN 55024 Immunity,
EN 61000-3-2,
VCCI Class A |
|
Warranty |
Hardware one year and software
90 days |
Hardware one year and software
90 days |
Hardware one year and software
90 days |
|
Hardware Specifications |
|
HDD |
2 x 500 GB RAID 1 |
6 x 250 GB RAID 5 |
6 x 500 GB RAID 10 |
|
Memory |
8 GB |
8 GB |
8 GB |
|
Events per second |
Up to 500 |
Up to 2500 |
Up to 10,000 |
|
Flows per second |
Max 15 K |
Max 100 K |
Max 400 K |
|
Devices (out of the box) |
250 |
750 |
750 |
Performance-Enabling Services and Support
Juniper Networks is the leader in performance-enabling services and support, which are designed to accelerate, extend, and optimize your
high-performance network. Our services allow you to bring revenue-generating capabilities online faster so you can realize bigger productivity
gains, faster rollouts of new business models and ventures, and greater market reach, while generating higher levels of customer satisfaction.
At the same time, Juniper Networks ensures operational excellence by optimizing your network to maintain required levels of performance,
reliability, and availability.
|
STRM Series Appliances |
Juniper Networks STRM 5000 Base Hardware Appliance
Note: Requires at least STRM5K-ADD-2500E-100KF for All-in-One Deployment to complete the STRM
5000 Order.
Note: Requires STRM5K-ADD-EP-2500E OR
STRM5K-ADD-FP-100KF License SKU for Distributed
deployment to complete the STRM5000 Order. |
#STRM5000-A-BSE
List Price: $11,000.00 |
|
|
STRM Mandatory Licenses |
Threat Management License to Add EPS=2500, Flows=100K Qflows/SFlows (200K J/NetFlows); Devices=750
STRM in a All in One architecture |
#STRM5K-ADD-2500E-100KF
List Price: $96,000.00 |
|
License to configure STRM 5000 as Console for Distributed Architecture
STRM in a Distributed architecture |
#STRM5K-ADD-CON
List Price: $35,000.00 |
|
Threat Management License to Add STRM 5000 as Event Processor up to EPS=2500
STRM in a Distributed architecture |
#STRM5K-ADD-EP-2500E
List Price: $52,000.00 |
|
Threat Management License to Add STRM 5000 as Flow Processor up to Flows=100K Qflows/SFlows (200K J/NetFlows)
STRM in a Distributed architecture |
#STRM5K-ADD-FP-100KF
List Price: $52,000.00 |
|
STRM Log Management Only, License to Add EPS=2500; Devices=750
STRM in a All in One architecture |
#STRM5K-LM-ADD-2500E
List Price: $30,000.00 |
|
STRM Log Management Only, License to Add STRM 5000 Log Management Console for Distributed Architecture
STRM in a Distributed architecture |
#STRM5K-LM-ADD-CON
List Price: $25,000.00 |
|
Log Management Only license to add STRM 5000 as Event processor with EPS=2500
STRM in a Distributed architecture |
#STRM5K-LM-ADD-EP-2500E
List Price: $22,000.00 |
|
|
STRM License To Upgrade |
License to upgrade additional Flows=100K Qflows/SFlows (200K J/NetFlows)
only.
STRM in a All in One architecture
Note: Requires STRM5K-ADD-2500E-100KF |
#STRM5K-ADD-100KF
List Price: $52,000.00 |
|
License to upgrade additional EPS=2500 only.
STRM in a All in One architecture
Note: Requires STRM5K-ADD-2500E-100KF |
#STRM5K-ADD-2500E
List Price: $52,000.00 |
|
License to upgrade STRM Log Management to Full STRM with Threat Management. Upgrade to EPS=2500, Flows=25K
STRM in a All in One architecture |
#STRM5K-LM-2500E-TM
List Price: $66,000.00 |
|
License to Upgrade STRM 5000 Log Management Console to Full STRM 5000 Console with Threat Management
STRM in a Distributed architecture |
#STRM5K-LM-CON-TM
List Price: $15,000.00 |
|
Log Management Only license to add STRM 5000 as Event processor EPS=2500
STRM in a Distributed architecture |
#STRM5K-LM-EP-2500E-TM
List Price: $30,000.00 |
|
| License to add additional device support in either Log Management or Threat Management solution in increments of 50 Devices |
#STRM-ADD-DEV-50
List Price: $7,500.00 |
|
|