Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

Introduction

 

Juniper Networks offers Contrail Service Orchestration (CSO) Release 5.1.0 as a cloud-based service that gives enterprises of all sizes access to its simple and intuitive GUI for WAN and LAN use cases. You can also deploy CSO Release 51.0 on-premises for customers that demand full control over their deployments.

CSO Release 5.1.0 supports the following types of accounts:

  • Service provider accounts—Service provider administrators can add tenants to and enable services such as SD-WAN, LAN, and next-generation firewall for the service provider network. They can also manage profiles and policies for traffic, configure service-level agreement (SLA) policies, breakout policies, and firewall management.

  • OpCo accounts (for multitenant, managed service providers)—OpCo (operating company) administrators can add tenants to and enable services such as SD-WAN, LAN, and next-generation firewall for the OpCo network. They can also manage profiles and policies for traffic, SLA policies, breakout policies, and firewall management.

  • Tenant account (for enterprise customers that want to use CSO for managing their sites)—Tenant administrators can add sites to and enable services such as SD-WAN, LAN, and next-generation firewall for their networks. They can also configure SLA policies, firewall policies, and breakout policies, and also apply the policies to the sites.

The following are the highlights of the features available in CSO Release 5.1.0:

  • SD-WAN features

    • Support for full mesh on an LTE WAN link

    • Support for multiple WAN links on the same physical interface

    • Support for OAM and data capability for OpCo provider hub

    • Enhancements to cloud breakout settings

    • Support for pool-based NAT for local breakout

    • Enhancements to certificate authority (CA) configuration

    • SD-WAN support for CPE devices behind NAT in full mesh topology

    • Support for provider-edge resiliency

    • Support for BGP underlay route advertisements

    • Support for flexible (mixed) VLAN tagging

    • Support for class of service at the logical interface level

    • Edit support for site properties

    • Edit support for tenant properties

  • SD-LAN features

    • Deploying SD-LAN using EX4600 and EX4650 switches

    • Support for EX Series Virtual Chassis

    • Image upgrade for Virtual Chassis members

    • Return Material Authorization (RMA) support for EX Series switches

    • Configuration and monitoring of the ports of an EX Series switch

    • Firewall configurations for EX Series switches

  • Next-generation firewall features

    • Support for custom application signatures in firewall policies

    • Support for customized IPS signatures, static groups, and dynamic groups

    • Support for importing policy configurations

  • Miscellaneous

    • Support for configuration templates

    • Support for predefined stage-2 templates

    • Support for retrying failed bootstrap jobs

    • Enhancements to CSO licenses