SRX

 View Only
  • 1.  ETSI GS QKD 014 support possibility for SRX 300 series

    Posted 20 days ago

    According to the information below, only the SRX1500 and above support the ETSI GS QKD 014 API.

    Page.221

    Hardware requirements -Juniper Networks® SRX1500 Firewall and higher-numbered device models
    or Juniper Networks® vSRX Virtual Firewall (vSRX3.0)
    https://www.juniper.net/documentation/us/en/software/junos/vpn-ipsec/vpn-ipsec.pdf

    Q1. Is the lack of support for SRX300 series due to hardware limitations or product positioning reasons?

    Q2. Is there a possibility that SRX300 series will support the ETSI GS QKD 014 API in a future version?



    ------------------------------
    Shigeyuki Miyazaki
    ------------------------------


  • 2.  RE: ETSI GS QKD 014 support possibility for SRX 300 series

    Posted 19 days ago

    I've been wondering much the same thing. As far as I know everything post-quantum requires at least SRX1500, not just the key distribution part. The SRX300 series does have a pretty sluggish control plane. Perhaps HPE is holding out for an SRX400 series?



    ------------------------------
    Nikolay Semov
    ------------------------------



  • 3.  RE: ETSI GS QKD 014 support possibility for SRX 300 series

    Posted 16 days ago

    Hi Nikolay

    Thank you for the suggestion about SRX400.
    According to this article, it seems the new generation SRX400 will support PQC.

    HPE introduces sweeping security advancements to secure AI adoption and strengthen enterprise resiliency | HPE

    Then what I want to know is whether existing SRX300 series will need to replace to SRX400 to support PQC,
     or if it can be done with OS upgrade.



    ------------------------------
    Shigeyuki Miyazaki
    ------------------------------



  • 4.  RE: ETSI GS QKD 014 support possibility for SRX 300 series

    Posted 15 days ago
      |   view attached

    I uploaded some info on SRX400. The info should be "public" according to a Juniper SE, but still preliminary. From earlier SRX announcements, performance figures will not decrease but rather the opposite after more testing has been done. First models are scheduled to be released before July this year.

    The SRX400 will not support traditional clustering, only MNHA clustering. MNHA clustering will also finally go from M=dual to M=multi, as in 2-4 clustering (in 25.4 I seem to recall).

    -------------------------------------------

    Attachment(s)

    pptx
    SRX400.pptx   15.13 MB 1 version


  • 5.  RE: ETSI GS QKD 014 support possibility for SRX 300 series

    Posted 15 days ago

    Thank you for that!

    The lack of chassis cluster is a total bummer. It means the SRX400 will not be a straightforward drop-in replacement for the SRX300. Sigh ... I hope it would at least be cheaper.



    ------------------------------
    Nikolay Semov
    ------------------------------



  • 6.  RE: ETSI GS QKD 014 support possibility for SRX 300 series

    Posted 13 days ago

    Thank you for SRX400 slide. It is usefult.

    >Looking further ahead, HPE is also addressing the future of encryption.
    >Post-quantum cryptography (PQC) is being added to Junos OS Evolved, with broader rollout to Junos planned for summer 2026. 
    https://www.hpe.com/us/en/newsroom/press-release/2026/03/hpe-introduces-sweeping-security-advancements-to-secure-ai-adoption-and-strengthen-enterprise-resiliency.html


    It has been announced that PQC will be provided not only for Junos OS Evolved (e.g. SRX 400), but also for Junos.
    Does this mean that the functionality and supported model range of PQC differ from the existing PQC provided for SRX1500 series and above?



    ------------------------------
    Shigeyuki Miyazaki
    ------------------------------



  • 7.  RE: ETSI GS QKD 014 support possibility for SRX 300 series

    Posted 13 days ago

    I have my doubts about that. Shortly after the release of the 400 series, perhaps before the end of this year, we're likely to see an End-of-Life announcement for the 300 series. Maybe they'll release a PQC-capable JunOS for it, maybe they won't.



    ------------------------------
    Nikolay Semov
    ------------------------------



  • 8.  RE: ETSI GS QKD 014 support possibility for SRX 300 series

    Posted 13 days ago

    I talked to one of the Juniper experts in the area in February and she confirmed that the SRX3xx series doesn't have the hardware to support PQC at all. The SRX400 is about to be released, but isn't on the HPE web site yet. It will only have 1 G interfaces, which is weird because it will support >5 Gbps of throughput in an L4 only situation. There will be a base version and a -C version, which in contrast to the EX4100-C doesn't mean "compact" but "cellular", so LTE/4G and NR/SA/5G is built-in.

    -------------------------------------------