secure-sd-wan
secure-sd-wan
SECURE SD-WAN
Juniper’s Approach to Secure SD-WAN Architecture
EXECUTIVE SUMMARY
Organizations need help understanding the paths available when considering the software-
defined wide area networking (SD-WAN) options available to them. Over many years, Juniper
Networks has pioneered and supported secure SD-WAN for organizations around the world.
As cloud adoption and connectivity requirements have increased, businesses have more
choices for connecting their branch and distribution locations, Juniper’s innovations have
kept pace, delivering capabilities that address these options at every step. With the Juniper
Connected Security strategy, customers are assured a “no compromise” security posture with
the flexibility and operational ease of addressing diverse application requirements regardless of
their WAN connectivity or routing needs. Organizations worldwide, in every vertical, depend
on Juniper to support their critical customer and employee needs from branch to cloud.
Introduction
Traditional branch offices are no longer able to provide the security and access flexibility enterprises need to deliver
the quality of experience demanded by the business. Organizations require additional capacity and improved
application awareness to ensure their users have access from anywhere.
The Challenge
The cloud has transformed how we consume applications and data. In many cases, this has taken the form of Software
as a Service (SaaS), further impacting traffic flow and increasing transfers directly from users to the cloud and back.
Cloud and SaaS consumption have radically changed how security and network teams secure and improve the quality
of user experience across their organizations. For businesses with more than a handful of locations, this has historically
been a challenging, operationally burdensome task. Basic SD-WAN only addresses a portion of these challenges,
leaving enterprises to solve security separately—a daunting task, given the rapid advances in threat actor efficacy.
The Solution
Juniper developed its Secure SD-WAN branch architecture on top of its award-winning Juniper Networks® SRX
Series Services Gateways, adhering to principles in our Connected Security strategy. Under this approach, security
and network convergence offers enterprises a new approach that improves efficacy and the ability to see, automate,
and protect users and data at every point of connection.
Through a cloud-native management interface, enterprises can employ zero-touch provisioning (ZTP) to
automatically configure both security and networking policies, regardless of the branch’s physical location. The
SRX Series firewalls provide several models to choose from and can accommodate any size branch or performance
requirements an organization might have. Using an SRX Series firewall, customers can take advantage of advanced
threat prevention, network intrusion prevention system (IPS), and secure Web gateway functions such as URL
filtering, antivirus, and data loss prevention (DLP) to provide a holistic offering that includes many other cloud-
enabled security capabilities while supporting branch offload or direct-to-SaaS performance.
Benefits
Juniper’s uncompromising approach to network security innovations, which provides customers with a best-in-
class, automated deployment of SD-WAN and SD-branch with ZTP, ensures ease of deployment and centralized
orchestration. Software-defined and AI-driven control of LAN, Wi-Fi, and security provides consistent access to and
management control over all sites, including campus, branch, work-from-home, and temporary locations, supported
by both secure SD-WAN policy and analytics.
Additionally, Juniper’s existing branch SRX Series customers can easily enroll their existing SRX Series firewalls
in a secure SD-WAN, avoiding the need to replace their appliances to enjoy the benefits of the technology. Few
customer environments are alike. While less flexible competitive solutions require you to purchase additional
equipment and lock you in, Juniper’s approach maximizes the value of its solutions over their lifetime.
The shift to cloud and the migration to SaaS applications allowed SD-WAN to shine, highlighting its ability to enable
and accelerate cloud adoption. Although SD-WAN fully supports traditional hub-and-spoke architectures, it enables
alternative topologies that better reflect cloud traffic flows. Traditional WAN topologies routed all branch traffic
back to a corporate headquarters (see Figure 1).
Headquarters
This made sense at the time, since legacy applications resided in the corporate home data center. Even legacy
communication traffic like voice and e-mail was backhauled to headquarters, where it was centrally scrubbed
through the corporate perimeter firewall. Conversely, with cloud, more than 90% of traffic is Internet bound. Do any
of the following applications sound familiar?
This list doesn’t even include other popular, more prevalent apps and technologies like YouTube, blogs, social, research,
and so on. How about general Internet search, or traffic generated by guest Wi-Fi? It’s all bound for the Internet.
• It imposes a 400% bandwidth “tax” by unnecessarily keeping traffic “on the intranet” longer
• It adds 2x round-trip time (RTT) latency, causing poor application experience
As a result, it becomes too costly to duplicate the “HQ stack.” SD-WAN, on the other hand, allows local breakout of
cloud-bound traffic at the branch (see Figure 2).
Headquarters
Figure 2: Breakout at the branch
While internal applications hosted in a private data center still exist, they consume a smaller percentage of the
bandwidth required for all traffic destined for the WAN link from the branch. These applications, such as point of
sale (POS)/inventory systems, healthcare data, and financial software, may be dependent on specific industries.
In discussions with customers around the globe, the opportunity to rethink branch connectivity strategies is not
limited to WAN connection methods; it also includes other aspects of branch management. Large enterprises will
continue to leverage MPLS/VPN and integrate SD-WAN to improve business outcomes, while small to medium-
sized businesses may choose that approach or employ a complete SD-WAN overlay.
At the same time, the need to scale both secure work-from-home and temporary site initiatives drives a requirement
for scale and flexibility that is redefining connectivity for everyone. Gartner introduced a new term in 2019, Secure
Access Service Edge (SASE), which represents enterprise needs that began to emerge over the last couple of years.
While enterprise decisions will be driven by requirements and currently available technologies, SASE will certainly
be top of mind for most SD-WAN considerations moving forward. Leveraging a cloud breakout with cloud security
combines the best security and application experiences to accommodate branch-to-cloud needs in the most
compelling and effective way.
Unfortunately, not all solutions are equally capable. While they all provide some level of connectivity between sites,
offerings differ in their ability to provide stability, security, and operational ease. Few offer flexible architectures that
integrate security, provide multiple WAN connectivity options, and deliver the ability to manage holistically non-
WAN connectivity.
Juniper Secure SD-WAN supports any WAN network architecture and underlay transport. At spoke sites, Juniper
Networks NFX Series Network Services Platform (purpose-built network function virtualization [NFV] appliances),
SRX Series firewalls, or the Juniper Networks vSRX Virtual Firewall can all be used to unite the enterprise securely.
In the cloud or on top of virtualization platforms, connectivity is provided by vSRX virtual firewalls. At the same time,
large-scale WAN topology architectures can use the physical SRX Series firewalls, with vSRX virtual firewalls acting as
routing hubs at major sites. This deployment freedom gives enterprises the ability to meet their secure branch needs,
regardless of location, technology, or business requirements, which is the essence of enabling a threat-aware network.
Internet
Intranet Intranet
MPLS/Private Circuit IPsec VPN
Ubiquitous Security
As SD-WAN traffic shifts inexorably towards direct Internet links, having a security plan for your deployment is
critical. The Juniper Secure SD-WAN solution leverages SRX Series high-performance next-generation firewall
(NGFW) software and the vSRX Virtual Firewall to deliver a consistent level of secure SD-WAN in both physical
and virtual form factors. The vSRX is also included on the universal CPE (uCPE) NFX Series platforms, delivering
the consistency that enterprises require for their diverse vendor and distributed environments—one of the primary
challenges Juniper sought to address with Connected Security.
Juniper’s Secure SD-WAN uses deep packet inspection (DPI) to identify data, determine the optimal route
for enterprise applications, and apply unified security policies to both inbound and outbound traffic—all while
application-based firewall rules offer baseline protection. Additional security layers with advanced security services,
intrusion detection service (IDS), IPS, and antivirus provide consistent managed security policies. Juniper Advanced
Threat Prevention uses real-time information from the cloud to provide anti-malware protection and defend against
sophisticated cybercrimes.
• A unified approach to creating SD-WAN and security policies with workflow management in a single UI that
guides and automates common workflows to support greater control and policy granularity
• ZTP of WAN and LAN devices and cloud-based endpoints
• User- and application-based policies offering 5000 predefined applications
• A full suite of cloud-delivered advanced security services like advanced threat prevention and URL filtering anti-
malware with industry-leading IPS verified by NSS Labs 2019 DCSG Test Report
• Service assurance capabilities, ensuring quality user experience by identifying flows or links that are impacting
locations and applications
• A broad range of connectivity options, including broadband Internet, MPLS, VPNs, 4G/LTE, and a wide array of
legacy WAN interfaces
• Service design and operation tools, including APIs that simplify third-party component and system integration
• Lower TCO and simplified procurement with Juniper WAN edge devices that combine security and SD-WAN
Upon delivery of enterprise network devices, operators benefit from the ZTP capabilities of SD-WAN, security, and
SD-LAN network functions. Adding, modifying, or deleting a service like a LAN segment is managed for the entire site
as a single entity rather than configuring individual boxes. Security is automatically applied and consistently enforced
across all WAN edges and LAN ports, ensuring that sites are safe. In addition, IPsec encryption is applied to all paths
traversing the Internet; however, Juniper Secure SD-WAN’s simplification of connectivity doesn’t end there.
For cloud endpoints on AWS specifically, Juniper’s management automates the endpoint life cycle of the vSRX
Virtual Firewall with the help of generated AWS CloudFormation templates, making it possible to run the vSRX as
an SD-WAN hub and NGFW.
standard open protocols, which is not always the case with offerings from vendors new to networking. All Juniper
Secure SD-WAN’s API-driven components are open and can be extended via automation or integration to other
orchestration systems already in use.
Contrail® Service Orchestration platform also administers services through a unified approach. Its self-service portal
provides access to composed higher level security and network services, while its administrative portal manages the
SD-WAN life-cycle and catalogs contributing network functions. Third-party virtualized network functions (VNFs)
may be included, with components such as WAN optimization. With Juniper Secure SD-WAN, VNFs are delivered
on the uCPE NFX Series platforms.
Juniper’s solution provides for high availability of the SDN control and management plane as well as the
interconnection of the WAN topology of multilinked hub-and-spoke sites or a mesh of WAN edge infrastructure.
Application traffic quality is monitored using Application Quality of Experience (AppQoE) technology; metrics are
collected and analyzed by Contrail Service Orchestration, ensuring that desired reliability levels are met, further
optimizing the user experience.
Connectivity and reliability can both be enhanced with industry-first support for active/active clustering of both
SRX Series firewalls and NFX Series uCPE devices. Contrail’s foundational microservices architecture ensures cloud-
grade reliability and scalability to enable multitenancy and ensure both high availability and high performance.
Cloud-Managed or On-Premises
Juniper SD-WAN
EX Series
Ethernet Switches SRX Series Services Broadband MX Series/SRX Series WAN Hubs for Large Topologies
Gateway Secure CPEs Internet
Secure SD-LAN and SD-WAN Enterprise or Service Provider Hub Gateways
Legacy and
xDSL
Use Cases
The demand for SD-WAN, SD-LAN, and SD-Branch stems from varying use cases that are driving the need for agile,
on-demand services with improved cost profiles. The benefits from these common scenarios are consistent, but the
drivers and situations vary, and ultimately every scenario requires uncompromising security.
Distributed Enterprise
Large enterprises with hundreds or thousands of sites across the world need a central orchestration system that
manages remote and branch offices without requiring onsite technical expertise. Juniper Secure SD-WAN provides
abstracted control and automated workflows, enabling the entire distributed branch infrastructure to be managed
in a unified way. Juniper Networks’ history of operating at service provider scale ensures that enterprises, who
increasingly function as service providers themselves, are supported by Juniper’s ability to scale to meet any need,
simply and reliably.
Professional Services
Juniper offers advisory, implementation, and testing services that help customers and partners evaluate
technologies and integrate them into existing network infrastructures. Schedule a consultation with Juniper
Professional Services to build a strategic plan and tailor a solution for your business. Leveraging the deep experience
of Juniper’s industry-leading service and support experts will minimize risk, speed time to deployment, and deliver
the desired business outcome.
Summary
Juniper Secure SD-WAN creates an evolvable architecture that simplifies and secures SD-WAN while offering the
ability to handle any amount of growth. It offers seamless management for virtual network services such as cloud
endpoints and on-premises uCPE platforms, and it manages and enforces multiple levels of security policy across all
points of presence for any organization. Juniper Secure SD-WAN provides IT teams with the tools needed to collect
and analyze data for situational awareness, efficiency, and management, enabling them to deliver a flexible and
multifaceted solution.
Juniper Secure SD-WAN uniquely enables organizations to manage and secure all of their connectivity needs,
seamlessly integrating full-stack security, monitoring, and third-party network services.
To learn more about how Juniper Secure SD-WAN and branch solutions can help your company gain a competitive
edge, contact your Juniper sales representative or visit http://juniper.net/sd-wan.
Copyright 2020 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper Networks logo, Juniper, and Junos are registered trademarks of Juniper Networks, Inc. in the United
States and other countries. All other trademarks, service marks, registered marks, or registered service marks are the property of their respective owners. Juniper Networks assumes no
responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice.