Juniper Networks today announced new products and capabilities to help organizations secure their distributed data center environments -- no, it's not secure access service edge (SASE).

The new Juniper Connected Security Distributed Services Architecture is designed to integrate unified security management with advanced routing and artificial-intelligence-powered threat prevention. This enables organizations to scale security services and zero-trust policies across distributed environments.

The architecture decouples forwarding and security layers, allowing each to scale independently. Organizations can use existing Juniper MX Series routers as an intelligent forwarding plane while adding modular firewall engines as needed. Juniper’s Security Director Cloud provides unified management across the architecture, simplifying operations regardless of the number or type of firewalls deployed.

[caption id="attachment_135247" align="alignnone" width="1180"] The Juniper Connected Security Distributed Services Architecture is designed to integrate unified security management with advanced routing and AI-powered threat prevention. Image courtesy of Juniper Networks.[/caption]

"The new distributed security services architecture relies on Junos [Juniper's network operating system], management simplification and Juniper custom silicon to provide scale and performance," Jeff Aaron, VP enterprise marketing at Juniper, told SDxCentral. " In this sense, the solution provides a very high scale firewall and security services solution that enables pay-as-you-go in growing data center environments."

No it's not SASE, it's data center security

Juniper's new distributed security services architecture should not be confused with SASE services, which serve a different set of needs.

Aaron explained that when it comes to securing a business, there are two parts to security. The first part is that users and devices need to be secure and have the right access, which is where SASE fits in to solve the challenge.

The second part is securing the data center and applications within the data center, which is where the new distributed security services architecture comes into play.

"SASE is about protecting end-device and end-user access to ensure that they have secure access to an application," Aaron said. "This news is about data center firewalls to enable data center security."

What's new in the Juniper Connected Security Distributed Services Architecture

The Juniper Connected Security Distributed Services Architecture isn't a collection of existing hardware and software and putting a new label on it, according to Juniper.

Aaron said that there is new software and updates provided as part of the Junos networking operating system. The Junos updates include the introduction of EVPN-VXLAN enhancements into the Juniper SRX firewall product line that allow the SRX to be part of the data center fabric and provide security.

The new architecture also integrates artificial intelligence (AI) predictive threat prevention that brings in higher performance for threat prevention technologies.

Overall, Aaron noted that new capabilities both in Junos and Juniper's management software help to bring forth the distributed security services architecture. He explained that the distributed security services architecture is a combination of hardware and software that enables customers to start small and grow based on their needs all using discrete fixed form factor firewalls enabling deployment consistency from small deployments to the largest.

New hardware from Juniper boosts security

As part of the announcement, Juniper is also rolling out a series of new firewalls, including the SRX1600, SRX2300, SRX4300 and SRX4700.Aaron said that the new SRX firewalls both add to Juniper's existing portfolio and replace certain product lines long-term. The SRX1600 replaces the current SRX1500 and SRX4300 replaces the current SRX4200. In addition he noted that the new platforms bring in higher performance as well as in-built security for the supply chain. For example, all the new platforms come default with a Trusted Platform Module (TPM) 2.0 module that enables secure zero touch provisioning and protects against supply chain threats. Additionally there is advanced encryption with MACSec built into all platforms by default.