Juniper Networks pushed security down to its MX routers and updated its containerized firewall as part of its Connected Security strategy.

The vendor first started talking about Connected Security earlier this year at the annual RSA Conference. It involves a layered approach to security where threat detection and policy enforcement is built into each layer. And it uses automation to scale and simplify these things, and also to make the individual security products work together in a more connected way.

“The complexity of security profession has grown,” said Oliver Schuermann, senior director of enterprise product marketing at Juniper. “We’re at an inflection point where we have a lot of different things we have to manage and understand” including not only security products but also threat vectors and potential methods of attack.

Juniper has an advantage here because of its visibility into and multiple points of enforcement throughout the infrastructure, Schuermann said.

To this end, the company incorporated security intelligence (SecIntl) into its MX Series routers. This allows customers to block malicious traffic — like command and control botnet servers — at the hardware level using threat feeds such as Juniper Sky ATP, Juniper Threat Labs, or even custom blacklists for discovery.

Security at the hardware level means customers don't have to use as many compute resources as they would for a deeper packet inspection, Schuermann said. “If I know all this traffic is command and control [traffic] from a country I don’t do business with, that should not be in my network, why not stop it at the edge? Why do a deep-level inspection?”

On top of that, customers can layer the distributed denial of service (DDoS) prevention tool that Juniper offers in partnership with Corero, “which provides an addition layer of defense in depth on your high-performance routers,” Schuermann said.

Juniper also updated its cSRX containerized firewall so that it can integrated with traditional network security management and SDN controllers, such as or Juniper’s Contrail platform or the open source version Tungsten Fabric.

In addition to providing layer 4 through layer 7 protection, the smaller container footprint means it can boot up in seconds, as opposed to minutes, and allows for a more efficient traffic flow, Schuermann said. Additionally, it means that security teams can keep consistent firewall policies across physical, virtual, and containerized workloads.