SSR400 Line of Routers Datasheet

Download Datasheet

Product overview

Networks today require powerful, secure, and easily manageable connectivity for distributed branches. The Juniper SSR400 is an AI-native Session Smart Router that consolidates routing, SD-WAN, and next-generation firewall capabilities into a single, compact, fanless device. This all-in-one solution simplifies IT operations, accelerates deployment, and ensures a secure, high-performance experience, all managed via the Mist cloud.

 

Product description

The modern enterprise demands more from its network. It needs powerful, secure, and easily manageable connectivity that can keep pace with the demands of cloud-enabled applications and a distributed workforce. Legacy routers and tunnel-based SD-WAN solutions are no longer up to the task, creating complexity and compromising performance. The Juniper SSR400 challenges this status quo.

Juniper Session Smart Routers provide the foundation for Juniper AI-native SD-WAN. They enable enterprises to build service-centric fabrics that connect users to applications with unparalleled efficiency. When deployed at branch offices the SSR400 Router, provides a service-centric control plane and a service-aware data plane. The router offers robust IP routing, a fully featured policy engine, and proactive analytics. The result is a next-generation SD-WAN solution that lets you fundamentally reimagine branch networking.

Uncompromising security

The SSR400 is built on a Zero Trust SD-WAN architecture. It includes a full-fledged next-generation firewall (NGFW) with deny-by-default access controls and military-grade encryption that protects against threats from the first packet. This unified security fabric goes beyond the limitations of add-on security solutions. It simplifies operations while delivering the protection modern enterprises demand.

 

Revolutionary performance and efficiency

The SSR400 harnesses the power of Session Smart Technology, which eliminates the need for complex, inefficient tunnels. Eliminating the tunnel-based approach lets the router deliver a more efficient service fabric that offers intelligent, sub-second traffic rerouting. This provides superior performance and ensures a quick boot-up time of under two minutes for rapid traffic recovery after an outage.

 

Proactive AI-native operations

The SSR400 is driven by Marvis® AI, transforming network management from reactive to proactive. It leverages AI Forensics to deliver unparalleled visibility into service level experiences (SLEs) and provide automated root cause analysis. The SSR400 can identify over 8,500 applications and ensure each one gets the performance it needs. This intelligent automation dramatically reduces operational overhead and the need for manual troubleshooting.

 

Streamlined simplicity

Designed with the “Branch in a Box” concept in mind, the SSR400 is a compact, fanless device ideal for quiet, small branch and retail locations. Its physical simplicity is matched by its operational elegance. With flexible templates, automated Zero Touch Provisioning (ZTP), and centralized management from the Juniper Mist cloud, it dramatically simplifies deployment and ongoing management.

For features and benefits of Juniper Session Smart Routers, as well as ordering information, see the Session Smart Routing datasheet.

 

Architecture and key components

By combining the AI-native intelligence of Juniper® WAN Assurance with the Session Smart Router, enterprises gain industry-leading automation and insight to ensure the best user, device, and application experiences in their branch and remote locations. The Juniper WAN Assurance cloud service simplifies operations, provides superior visibility into end user experiences, and reduces the mean time to repair for SD-WAN issues.

The Juniper Networks SSR400 line of routers provides the hardware foundation for this service-centric fabric. These appliances feature a service-centric control plane and service-aware data plane that offer robust IP routing, a feature-rich policy management engine, improved visibility, and proactive analytics. This architecture moves beyond the limitations of traditional, tunnel-based solutions by delivering a single, unified platform for powerful and secure connectivity.

SSR400 fixed configuration appliances

The fixed configuration appliances in the SSR400 line are designed for a variety of branch sizes:

  • The SSR400: Ideal for small branches and retail locations
  • The SSR440: Designed to serve the needs of medium-sized branches

These appliances run the FIPS 140-3 Level 2 compliant Session Smart Router software, which provides secure and resilient WAN connectivity as a core component of the Juniper AI-native SD-WAN solution.

 

Juniper WAN Assurance

WAN Assurance is a cloud service that brings AI-native automation and service levels to Juniper SSR SD-WAN routers, complementing the Juniper AI-native SD-WAN solution. WAN Assurance transforms IT operations from reactive troubleshooting to proactive remediation, turning insights into actions and delivering operational simplicity with seamless integration into existing deployments.

  • SSR Series SD-WAN routers, deployed as secure SD-WAN edge devices, deliver the rich streaming telemetry that provides the insights needed for WAN health metrics and anomaly detection. This data is leveraged within the Mist cloud and Marvis AI engine, driving simpler operations, reducing mean time to repair (MTTR), and providing greater visibility into end user experiences.
  • Insights derived from SSR Series SD-WAN gateway telemetry data allow WAN Assurance to compute unique “User Minutes” that indicate whether users are having a good experience.
  • Marvis® AI Assistant for WAN allows you to ask direct questions like, “Why is my Zoom call bad?” and provides complete insights, correlation, and actions.
  • Marvis Actions identify and summarize issues such as application latency conditions, congested WAN circuits, or negotiation mismatches.

For detailed features and benefits of Juniper Mist WAN Assurance, see the WAN Assurance datasheet.

 

Simplifying branch deployments (secure connectivity/SD-WAN)

SSR400 Routers deliver fully automated SD-WAN to both enterprises and service providers.

  • Configuration templates and ZTP features simplify branch network connectivity for initial deployment and ongoing management.
  • SSR400 line of SD-WAN routers offer best-in-class secure connectivity.
  • The SSR400 line of SD-WAN routers efficiently utilize multiple links and load balance traffic across the enterprise WAN, blending traditional MPLS with other connectivity options such as broadband internet, leased lines, 5G/LTE, and more. Policy- and application-based forwarding capabilities enforce business rules created by the enterprise to steer application traffic toward a preferred path.

 

Features and benefits

Table 1: Features and benefits
CategoryFeatures
System and network servicesSNAT/DNAT, destination NAPT, shared NAT pool, IPv4/IPv6, DHCP client, DHCP relay, DHCP server, DHCP server extensions, DHCPv6 PD, DNS client, PPPoE, Proxy ARP, NAT traversal, BFD, inline flow performance monitoring, extended firewall pinhole, path MTU discovery, MSS auto adjust, DSCP based service identification for IPsec
Advanced servicesSecure Vector Routing (SVR), Multipoint SVR, IPv6 SVR, overlapping IP service segmentation, Ethernet over SVR, application identification
RoutingService based routing, static routing, BGPv4, BGP route reflector, BGP graceful restart, BGP over SVR, BGP route map, BGP prefix list, OSPFv2, BGP VRF, OSPF VRF
Traffic engineeringTraffic scheduling and shaping, flow policing and shaping, packet marking (DiffServ), service rate limiting
Network firewallDistributed stateful firewall, distributed and automated access control, fine-grained segmentation/tenancy, ICSA network firewall certified, ICMP blackhole
IDS/IPS and URL filteringIntrusion Detection System/ Intrusion Prevention System (IDS/IPS) and URL filtering capabilities are available through the Advanced Security Pack.
Secure edge connectorsSeamless connections to Juniper Secure Edge or third-party SSE.
Application identificationHTTP/S domain-based identification, O365 identification, DNS based identification, application categorization
Session encryptionSession metrics, network metrics, LTE metrics, peer path SLA, MOS score, session analytics, SSL/TLS metrics, session IPFIX records

Session Payload Encryption (AES-256, AES-128), session/route authentication (HMAC-SHA1, HMAC-SHA256, HMAC-SHA-256-128), adaptive encryption, rekeying, FIPS 140-3 validated, enhanced replay attack protection, transport-based encryption

Path selection, (SLA, MoS, average latency), load balancing using proportional and hunt, session migration, session duplication, session duplication for non-SVR, session duplication for inter-node links, MOS for VoIP, Path of last resort, session optimization, session reliability, service health learning, service route redundancy
MonitoringMonitoring agent, SNMPv2, Syslog, audit logs
Management and remote accessGUI, CLI, REST, remote access over SVR (LTE), upgrade rollback, Zero Touch provisioning, remote service packet capture, user-defined configuration templates, role-based access control
AAALocal registry, LDAP

 

Specifications

Hardware specifications

SpecificationSSR400SSR400-CSSR400-W-USSSR400-CW-USSSR400-W-WW
Connectivity
Total onboard ports10x1GbE10x1GbE10x1GbE10x1GbE10x1GbE
Onboard RJ-45 ports8x1GbE8x1GbE8x1GbE8x1GbE8x1GbE
Onboard small form-factor pluggable (SFP) transceiver ports2x1GbE2x1GbE2x1GbE2x1GbE2x1GbE
MACsec capable ports10x1GbE10x1GbE10x1GbE10x1GbE10x1GbE
Console (USB-C)11111
USB ports (type C)11111
PoE+ ports22222
Wi-Fi / CellularN/A5G/LTE802.11ax – U.S. only5G/LTE and 802.11ax – U.S. only802.11ax – Worldwide (outside U.S.)
Dimensions and power
Form factorDesktopDesktopDesktopDesktopDesktop
Size (WxHxD)11.81 x 1.3 x 7.52 in.
(30.00 x 3.30 x 19.10 cm)
11.81 x 1.3 x 7.52 in.
(30.00 x 3.30 x 19.10 cm)
11.81 x 1.3 x 7.52 in.
(30.00 x 3.30 x 19.10 cm)
11.81 x 1.3 x 7.52 in.
(30.00 x 3.30 x 19.10 cm)
11.81 x 1.3 x 7.52 in.
(30.00 x 3.30 x 19.10 cm)
Redundant PSUNoNoNoNoNo
Power supplyAC (external)AC (external)AC (external)AC (external)AC (external)
Maximum PoE power60 W60 W60 W60 W60 W
Airflow/coolingFanlessFanlessFanlessFanlessFanless

 

SpecificationSSR400-CW-WWSSR440SSR440-2ACSSR440-CSSR440-C-2AC
Connectivity
Total onboard ports10x1GbE10x1GbE10x1GbE10x1GbE10x1GbE
Onboard RJ-45 ports8x1GbE8x1GbE8x1GbE8x1GbE8x1GbE
Onboard small form-factor pluggable (SFP) transceiver ports2x1GbE2x1GbE2x1GbE2x1GbE2x1GbE
MACsec capable ports10x1GbE10x1GbE10x1GbE10x1GbE10x1GbE
Console (USB-C)11111
USB ports (type C)11111
PoE+ ports22222
Wi-Fi / Cellular5G/LTE and 802.11ax – Worldwide (outside US)N/AN/A5G/LTE5G/LTE
Dimensions and power
Form factorDesktopDesktopDesktopDesktopDesktop
Size (WxHxD)11.81 x 1.3 x 7.52 in.
(30.00 x 3.30 x 19.10 cm)
11.81 x 1.3 x 7.52 in.
(30.00 x 3.30 x 19.10 cm)
11.81 x 1.3 x 7.52 in.
(30.00 x 3.30 x 19.10 cm)
11.81 x 1.3 x 7.52 in.
(30.00 x 3.30 x 19.10 cm)
11.81 x 1.3 x 7.52 in.
(30.00 x 3.30 x 19.10 cm)
Redundant PSUNoNoNoNoNo
Power supplyAC (external)AC (external)2 x redundant AC (external)AC (external)2 x redundant AC (external)
Maximum PoE power60 W60 W60 W60 W60 W
Airflow/coolingFanlessFanlessFanlessFanlessFanless

 

About Juniper Networks

Juniper Networks is leading the convergence of AI and networking. Mist, Juniper’s AI-native networking platform, is purpose-built to run AI workloads and simplify IT operations, assuring exceptional and secure user and application experiences—from the edge to the data center to the cloud. Additional information can be found at www.juniper.net, X, LinkedIn, and Facebook.

 

1000811 - 001 - EN SEPTEMBER 2025