Ready. Set. Let’s go!
Use the following high-level steps to set up your sites and manage policies with Customer Portal. Click the Online Help (?) links for additional information, or refer to the Customer Portal Help Center.
Note: A user can have one or more roles and each role can have one or more access privileges. A role is a function assigned to a user that defines the tasks that the user can perform within CSO.
This task describes how to add an on-premise site. You can add two types of on-premise sites—on-premise spoke and on-premise hub.
To add an on-premise site:
The Sites page appears.
The Add Site for Tenant-Name page appears.
The status of the add operation is displayed.
This task describes how to add a cloud spoke site.
To add a cloud spoke site:
Note:
Only Hub-Spoke topology is supported for AWS cloud spoke site.
Only Internet link is supported for WAN underlay connections.
The WAN traffic page appears, displaying a set of values for the WAN link configuration.
The new cloud spoke site that you created appears in the Sites page.
Power on the new CPE device and then enter the activation code. You can enter the activation code either from the Customer Portal or on the device.
To activate the device:
The Activate Device page appears.
The template file is download to your system. The cloud formation template contains the stage-1 configuration. Upload the cloud formation template to AWS server to provision vSRX. The cloud formation template will create the required resources such as subnet, interface, vSRX and so on and apply the stage-1 configuration.
If you have already logged in to your AWS account, the Create Stack page appears.
If you are not logged into your AWS account, a new web page opens in your browser, displaying the AWS login information. Login to your AWS account.
Note: If you do not see the Create Stack page when you login or access your AWS account, then search for CloudFormation service.
The Create Stack page appears.
The Create Stack pages displays a list of existing stacks and indicates that it is creating the stack that you requested. The create stack process takes up to 30 minutes. If the process does not complete in 30 minutes, a timeout occurs and you must retry the process.
The Activate Device page is visible and you see that CSO is detecting the provisioning agent. This process takes up to 30 minutes. If the process does not complete in 30 minutes, a timeout occurs and you need to retry the process.
Note: You need not download the cloud formation template again. You can log in to the Customer Portal, access the Activate Device page, enter the activation code and click Next. After the CREATE_COMPLETE message is displayed on the AWS server, click Next on the Activate Device page to proceed with device activation.
If the spoke on AWS has been spawned successfully, it will contact CSO through outbound SSH connection. The device is detected and normal ZTP process is triggered. The rest of the workflow is consistent with the normal on-premise workflow.
The Sites page appears. To see the device activation status, hover over the device icon on the Sites page.
To deploy network services:
The Sites page appears.
The Site-Name page appears.
The Deploy Network Services pane appears on the right side of the page.
The Deploy Network Service: Site-Name page appears.
The status of the deploy operation is displayed.
The status of the service is displayed.
The following tasks describe how to view and manage policies.
To view and manage a firewall policy:
Source endpoints can be IP addresses, IP address groups, sites, site groups, or departments
Destination endpoints can be IP addresses, IP address groups, sites, site groups, departments, Layer 7 (L7) applications, or services.
The Firewall Policy page is displayed.
The status of the save operation is displayed.
The Firewall Policy page is displayed.
The Deploy page is displayed.
The status of the deployment operation is displayed.
The Deployments page (Configuration > Deployments) displays the information about all deployments.
To view and manage an SD-WAN policy:
Source endpoints can be sites, site groups, or departments
Destination endpoints can be applications or application groups
Note: You can also use predefined traffic type profiles.
The Application Traffic Type Profiles page appears.
The Create Traffic Type Profile page appears.
The status of the create operation is displayed.
The Application SLA Profiles page appears.
The Create SLA Profile page appears.
The status of the create operation is displayed.
The SD-WAN Policy page appears.
The status of the save operation is displayed.
The SD-WAN Policy page appears.
The Deploy page is displayed.
The status of the deployment operation is displayed.
The Deployments page (Configuration > Deployments) displays the information about all deployments.
To view and manage a NAT policy:
Source endpoints can be IPv4/IPv6 addresses, or port numbers
Destination endpoints can be IPv4/IPv6 addresses, or port numbers
The NAT Policies page appears, displaying the existing NAT policies.
The Single NAT Policy page appears.
The status of the create operation is displayed.
The NAT Pools page appears.
The Create NAT Pool page displays fields required for creating and configuring a NAT pool.
The status of the create operation is displayed.
The NAT Policies page appears.
The NAT policy rules page appears.
Note: Even though you select one or more NAT policy rules, when you click Deploy, all NAT policy rules that are associated with the NAT policy are deployed.
The status of the deployment operation is displayed.
Creating On-Premise Spoke Sites for SD-WAN Deployment
Creating On-Premise Hub Sites for SD-WAN Deployment
Activating a CPE Device
Creating Cloud Spoke Sites for SD-WAN Deployment
Provisioning a Cloud Spoke Site in AWS VPC
Managing a Single Site
About the SD-WAN Policy Page
About the Firewall Policy Page
About the NAT Policies Page
Creating On-Premise Spoke Sites for SD-WAN Deployment
Creating On-Premise Hub Sites for SD-WAN Deployment
Activating a CPE Device
Creating Cloud Spoke Sites for SD-WAN Deployment
Provisioning a Cloud Spoke Site in AWS VPC
Managing a Single Site
About the SD-WAN Policy Page
About the Firewall Policy Page
About the NAT Policies Page