Setting Up a Distributed Deployment
The following workflow describes the steps required to set up a Hybrid WAN (distributed CPE) deployment.
Before you can start a deployment, complete the following tasks:
Provision your VMs according to the steps discussed in Contrail Service Orchestration Install and Upgrade Guide
Note If you are provisioning your VMs on a KVM-based hypervisor, you must complete the steps in Creating a Data Interface for a Distributed Deployment prior to provisioning. This step creates a required bridge interface for the VMs to communicate with the CPE devices.
Complete the CSO installation as per the CSO Install and Upgrade Guide.
Publish network services with Network Service Designer.
Publishing the VNFs as network services allows them to be seen in the CSO Administration portal under the Allocate Network Services links for installed tenants. See Designing and Publishing Network Services and the Contrail Service Orchestration User Guide for details.
After you have installed Contrail Service Orchestration and published network services with Network Service Designer, you use Administration Portal to set up the distributed deployment. The following workflow describes the process:
Log in to Administration Portal.
Add or import customers (tenants) in Administration Portal.
Tenants in the Cloud CPE solution represent customers who accesses virtualized network functions (VNFs) in a service provider’s cloud through a Layer 3 VPN. Create one tenant for each customer who will use your network services
For distributed CPE deployments, choose Hybrid WAN topology after entering the tenant administrator information in the add tenant pop-up. See The Contrail Service Orchestration User Guide for more information about adding and importing tenants
Allocate networks services to each customer.
All of the published network services are listed in the pop-up window that comes up when you click Allocate Network Services under the Assigned Services column of the tenants list. The number of services assigned to a particular tenant is shown for those tenants which have services assigned. The Allocate Network Services link is only shown if no services have been allocated for that tenant.
Access the tenant view for the first customer by clicking the tenant name link from the list of tenants.
Add an on-premises spoke site for each site in the customer’s network.
Note Alternatively customers can add the spoke sites themselves.
For this deployment guide, we will focus on the spoke sites. Information about Local Service Edge Sites and Regional Service Edge Sites can be found in the Contrail Service Orchestration User Guide.
Repeat Step 3 for each customer in the network.
Access the All Tenants view for the customers.
Add data for the POPs and provider edge (PE) router.
Upload images for devices used in the deployment, such as the vSRX gateway, NFX250 CPE devices or NFX150 CPE devices, to the central activation server.
Configure activation data for CPE devices.
Note You must send an activation code to the customer for each NFX250 or NFX150 device. The customer’s administrative user must provide this code during the NFX installation and configuration process. The Juniper Networks Redirect Service uses this code to authenticate the device.
Upload VNF images.
Upload and install licenses:
- Upload licenses for vSRX and SRX devices and VNFs with the using the
- Upload licenses for other VNFS with Administration Portal.
- Manually install licenses for other VNFs.
Allocate network services to customers.
Activate CPE devices at customer sites.
Note Alternatively customers can activate the devices themselves.
When an administrator installs and configures the NFX devices at a customer site, the device automatically interacts with the Redirect Service. The Redirect Service authenticates the device and sends information about its assigned regional server. The device then obtains a boot image and configuration image from the regional server and uses the images to become operational.
Customers activate SRX Series Services Gateways and vSRX instances acting as CPE devices through Customer Portal.
For detailed information about using Administration Portal, see the Contrail Service Orchestration User Guide.
