Tool Kit Extends Router Security

Tool Kit Extends Router Security

Written By
Dennis Fisher
Dennis Fisher
Jun 2, 2003
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Looking to add more versatility and flexibility to its line of core routers, Juniper Networks Inc. is rolling out a security tool kit that includes a variety of protection capabilities.

The enhanced functionality is delivered via Junipers PICs (Physical Interface Cards), an architecture that enables customers to select the features they want.

Prominent among the capabilities in J-Protect Toolkit are a stateful inspection firewall and flow monitoring.

So, for example, a service provider can choose to install one PIC with both firewall and network address translation. This configuration would enable the provider to deliver Internet and virtual private network connectivity to its customers on the same circuit.

What makes this kind of configuration possible is the nature of Junipers architecture in all its routers.

The company decided early on to separate the control plane and the forwarding plane in its routers as a way to get the scale that large service providers demanded. But the company quickly discovered that the design opened up other possibilities as well.

“It was a performance issue, but it has a lot of extensibility, too,” said Todd Shimizu, security solutions manager at Juniper, based in Sunnyvale, Calif. “The software modules gave us performance and security and scalability. The extra headroom we had in the ASICs [application-specific integrated circuits] gives us the ability to do packet inspection and rate limiting.”

New Growth

Features of Junipers J-Protect Toolkit

  • Stateful firewall packet inspection
  • Flow monitoring
  • Inline or offline deployment
  • Full traffic sampling

New Growth

Features of Junipers J-Protect Toolkit

  • Stateful firewall packet inspection
  • Flow monitoring
  • Inline or offline deployment
  • Full traffic sampling

New Growth

Features of Junipers J-Protect Toolkit

  • Stateful firewall packet inspection
  • Flow monitoring
  • Inline or offline deployment
  • Full traffic sampling

The flow monitoring capability is designed to allow for full traffic sampling and analysis anywhere on the network.

Each PIC can handle up to 1 million flows, and the ASIC can be used to break out individual flows and send them to another box for deeper inspection.

Designed for high-speed networks, the PICs can each monitor one full OC-48 network.

“The integration is the key advantage for us, as is the scalability aspect,” Shimizu said. “The architecture delivers the advantage. We think you should dictate the security policy; the equipment shouldnt.”

In addition, the J-Protect solution includes a new set of professional services in support of the technology. The services include vulnerability analysis, security architecture, implementation planning, testing and validation, and deployment.

The new capabilities will be available in August on all Junipers routers.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.