---
name: vmwaresolutions-juniper_ordering
title: Ordering Juniper vSRX
description: As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
last-updated: 2026-05-26
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/vmwaresolutions?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Ordering Juniper vSRX
{: #juniper-ordering}

As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
{: deprecated}

You can include the Juniper® vSRX service with a new VMware Cloud Foundation for Classic - Automated instance or add the service to your existing instance.

You can install multiple instances of Juniper vSRX on the management cluster. On a single gateway cluster, you can install only one instance of Juniper vSRX.

You can install Juniper vSRX on 25 Gb uplink speed management and gateway clusters on VMware vSphere® 7 with NSX-T. On 25 Gb uplink speed clusters, only the Content Security Bundle license is available.

The license that is used depends on the target cluster you choose.

* For VCF for Classic - Automated instances with vSphere 7 and later, the management and gateway clusters with 25 Gb uplink speed use the 25 Gb uplink speed version of the license selected.
* For Regulated Workloads and Security and Compliance Readiness Bundle instances, the same license selection process occurs for gateway clusters with 25 Gb uplink speeds.

You cannot install Juniper vSRX and FortiGate Virtual Appliance on the same gateway cluster.
{: restriction}

## Ordering Juniper vSRX for a new instance
{: #juniper-ordering-new-instance}

1. When you [order the instance](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-vc_orderinginstance-procedure&format=markdown), scroll down to the **Add-on services** section. Juniper vSRX is in the **Security and compliance** category.
2. Open the category, locate Juniper vSRX, and toggle its switch on.
3. Click **Edit** to review and specify [the configuration information](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-juniper-ordering&format=markdown#juniper-ordering-service-config), then click **Save**.

   The Juniper vSRX service is deployed on the management cluster unless you order a gateway cluster. For Juniper vSRX to function as a gateway for your instance, you must include the gateway cluster in your order.

## Ordering Juniper vSRX for an existing instance
{: #juniper-ordering-exist-instance}

1. On the instance details page, click the **Services** tab.
2. Click **Add** to add the service.
3. On the **Add services** page, locate the **Juniper vSRX** service in the **Security and compliance** section and toggle its switch on.
4. Click **Edit** to review and specify [the configuration information](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-juniper-ordering&format=markdown#juniper-ordering-service-config), then click **Save**.

   When you add Juniper vSRX to an existing VCF for Classic - Automated instance, you can select the cluster on which to install Juniper vSRX, either a management cluster or a gateway cluster. For Juniper vSRX to function as a gateway for your instance, you must deploy the service to a gateway cluster.

## Juniper vSRX service configuration
{: #juniper-ordering-service-config}

When you order the service, provide the following settings:

### Name
{: #juniper-ordering-service-config-name}

Specify the nickname for the installed instance in the **Enter a name for the HA deployment** field. Because multiple copies of Juniper vSRX can be in a single VCF for Classic - Automated instance, this name is used to ensure that the names of all networking components are unique.

### License model
{: #juniper-ordering-service-config-license-model}

Review the features of the two licenses and select either **Standard Edition** or **Content Security Bundle**.

You can't change the license model after service installation. To change the license model, you must delete the existing service and reinstall the service by selecting a different license option.
{: important}

After the service is ordered, the vSRX nodes are automatically ordered with the selected license models.

### Juniper vSRX deployment on a gateway cluster
{: #juniper-ordering-service-config-edge-deployment}

If you deploy Juniper vSRX on a gateway cluster, after deployment, you must configure Juniper vSRX for your environment. Complete the following steps:

1. Configure the redundant Ethernet `reth2` interface with the default gateway IP addresses of each subnet in your private trunk VLAN. The IP addresses are assigned to the logical interface, which is in the format of `reth2.VLANid`.
2. Configure the redundant Ethernet `reth3` interface with the default gateway IP addresses of each subnet in your public trunk VLAN, if you have one. The IP addresses are assigned to the logical interface, which is in the format of `reth3.VLANid`.
3. In the IBM Cloud&reg; infrastructure customer portal, look at the gateway appliance ordered for the gateway cluster. From there, assign the VLANs that you want to the gateway appliance and put them in `route-through` mode.

## Related links
{: #juniper-ordering-related-links}

* [Juniper vSRX overview](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-juniper-overview&format=markdown)
* [Managing Juniper vSRX](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-juniper-managing&format=markdown)
* [Ordering services for VCF for Classic - Automated instances](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-vc_addingservices&format=markdown)
* [FAQ for VCF for Classic](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-faq-vmwaresolutions&format=markdown)
* [Getting help and support](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-trbl_support&format=markdown)
* [Juniper vSRX Virtual Firewall](https://buy.hpe.com/us/en/networking/juniper-solutions/juniper-security-solutions/juniper-vsrx-virtual-firewall/p/1014920022){: external}
* [Juniper vSRX Documentation](https://www.juniper.net/documentation/product/us/en/vsrx/){: external}