| Deployment and Performance |
| Appliance | SSR120 |
| Suggested Location | Small branch |
| Max Throughput (Unencrypted) | 1.5 Gbps |
| System and network services |
| SNAT/DNAT | Supported |
| destination NAPT | Supported |
| shared NAT pool | Supported |
| IPv4/IPv6 | Supported |
| DHCP client | Supported |
| DHCP relay | Supported |
| DHCP server | Supported |
| DHCP server extensions | Supported |
| DHCPv6 PD | Supported |
| DNS client | Supported |
| PPPoE | Supported |
| Proxy ARP | Supported |
| NAT traversal | Supported |
| BFD | Supported |
| inline flow performance monitoring | Supported |
| extended firewall pinhole | Supported |
| path MTU discovery | Supported |
| MSS auto adjust | Supported |
| DSCP based service identification for IPsec | Supported |
| Advanced services |
| Secure Vector Routing (SVR) | Supported |
| Multipoint SVR | Supported |
| IPv6 SVR | Supported |
| overlapping IP service segmentation | Supported |
| Ethernet over SVR | Supported |
| application identification | Supported |
| Routing |
| Service based routing | Supported |
| static routing | Supported |
| BGPv4 | Supported |
| BGP route reflector | Supported |
| BGP graceful restart | Supported |
| BGP over SVR | Supported |
| BGP route map | Supported |
| BGP prefix list | Supported |
| OSPFv2 | Supported |
| BGP VRF | Supported |
| OSPF VRF | Supported |
| Services and Topology Exchange Protocol (STEP) | Supported |
| Traffic engineering |
| Traffic scheduling and shaping | Supported |
| flow policing and shaping | Supported |
| packet marking (DiffServ) | Supported |
| service rate limiting | Supported |
| Network firewall |
| Distributed stateful firewall | Supported |
| distributed and automated access control | Supported |
| fine-grained segmentation/tenancy | Supported |
| ICSA network firewall certified | Supported |
| ICMP blackhole | Supported |
| IDS/IPS and URL filtering |
| Intrusion Detection System/ Intrusion Prevention System (IDS/IPS) and URL filtering capabilities | Available through the Advanced Security Pack |
| Secure edge connectors |
| Seamless connections to Juniper Secure Edge or third-party SSE | Supported |
| Application identification |
| HTTP/S domain-based identification | Supported |
| O365 identification | Supported |
| DNS based identification | Supported |
| application categorization | Supported |
| Analytics |
| Session metrics | Supported |
| network metrics | Supported |
| LTE metrics | Supported |
| peer path SLA | Supported |
| MOS score | Supported |
| session analytics | Supported |
| SSL/TLS metrics | Supported |
| session IPFIX records | Supported |
| Session encryption |
| Session Payload Encryption (AES-256, AES-128) | Supported |
| session/route authentication (HMAC-SHA1, HMAC-SHA256, HMAC-SHA-256-128) | Supported |
| adaptive encryption | Supported |
| rekeying | Supported |
| FIPS 140-2 validated | Supported |
| enhanced replay attack protection | Supported |
| transport-based encryption | Supported |
| Session management |
| Path selection (SLA, MoS, average latency) | Supported |
| load balancing using proportional and hunt | Supported |
| session migration | Supported |
| session duplication | Supported |
| session duplication for non-SVR | Supported |
| session duplication for inter-node links | Supported |
| MOS for VoIP | Supported |
| Path of last resort | Supported |
| session optimization | Supported |
| session reliability | Supported |
| service health learning | Supported |
| service route redundancy | Supported |
| Monitoring |
| Monitoring agent | Supported |
| SNMPv2 | Supported |
| Syslog | Supported |
| audit logs | Supported |
| Management and remote access |
| GUI | Supported |
| CLI | Supported |
| REST | Supported |
| remote access over SVR (LTE) | Supported |
| upgrade rollback | Supported |
| Zero Touch Provisioning | Supported |
| remote service packet capture | Supported |
| user-defined configuration templates | Supported |
| role-based access control | Supported |
| AAA |
| Local registry | Supported |
| LDAP | Supported |
| Interface options |
| Ethernet | Supported |
| LTE support including Dual LTE and Dual SIM | Supported |
| T1 | Supported |
| Platforms |
| Bare metal x86 server | Supported |
| KVM | Supported |
| VMWare ESXi | Supported |
| OpenStack | Supported |
| AWS | Supported |
| Azure | Supported |
| Google Cloud | Supported |
| Security Architecture |
| Service-centric, tenant-based security architecture | Supported |
| Zero Trust security (deny-by-default) | Supported |
| Integrated next-generation firewall (NGFW) Layer 3/Layer 4 | Supported |
| Integrated security (IDS/IPS, URL filtering, antivirus) | Built-in with Advanced Security Pack for IDS/IPS |
| AI-native management with Marvis AI | Supported via WAN Assurance |
| Advanced Security Pack |
| Integrates IDS/IPS, URL filtering into routing fabric | Available standalone or with SRX Series; supports SASE journey |