Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


VNFs Supported by the Contrail Service Orchestration Solutions


Contrail Service Orchestration (CSO) supports Juniper Networks and third-party VNFs listed in Table 1.

Table 1: VNFs Supported by Contrail Service Orchestration

VNF Name


Network Functions Supported

Deployment Model Support

Juniper Networks vSRX

vSRX KVM Appliance 15.1X49-D123

  • Network Address Translation (NAT)

  • Demonstration version of Deep Packet Inspection (DPI)

  • Firewall

  • Unified threat management (UTM)

Hybrid WAN and SD-WAN deployments supports NAT, firewall, and UTM.




Hybrid WAN and SD-WAN deployments–NFX250 and NFX150 platforms.

Single-legged Ubuntu



Hybrid WAN and SD-WAN deployments–NFX250 and NFX150 platforms.

An on-premises version of CSO is not shipped with any VNFs. Immediately after installation you have to upload any desired VNFs to the CSO platform using the Administration Portal.

You can use VNFs in service chains and configure some settings for them in Network Service Designer. You can then view those network service configuration settings in the Administration Portal. Customers can also configure some settings for the VNFs in their network services through Customer Portal. VNF configuration settings that customers specify in the Customer Portal override VNF configuration settings specified in Network Service Designer, which is not available in a cloud-hosted CSO deployment.


Currently, SD-WAN deployments support only layer 2 (L2) service chains while Hybrid WAN deployments can support L2 and L3 service chains.

In a cloud-hosted deployment, CSO only contains those VNFs installed by Juniper Networks’ administrators. Requests for additional VNFs must be made through your account manager and Professional Services.