Introduction
Juniper Networks offers Contrail Service Orchestration (CSO) Release 5.1.0 as a cloud-based service that gives enterprises of all sizes access to its simple and intuitive GUI for WAN and LAN use cases. You can also deploy CSO Release 51.0 on-premises for customers that demand full control over their deployments.
CSO Release 5.1.0 supports the following types of accounts:
Service provider accounts—Service provider administrators can add tenants to and enable services such as SD-WAN, LAN, and next-generation firewall for the service provider network. They can also manage profiles and policies for traffic, configure service-level agreement (SLA) policies, breakout policies, and firewall management.
OpCo accounts (for multitenant, managed service providers)—OpCo (operating company) administrators can add tenants to and enable services such as SD-WAN, LAN, and next-generation firewall for the OpCo network. They can also manage profiles and policies for traffic, SLA policies, breakout policies, and firewall management.
Tenant account (for enterprise customers that want to use CSO for managing their sites)—Tenant administrators can add sites to and enable services such as SD-WAN, LAN, and next-generation firewall for their networks. They can also configure SLA policies, firewall policies, and breakout policies, and also apply the policies to the sites.
The following are the highlights of the features available in CSO Release 5.1.0:
SD-WAN features
Support for full mesh on an LTE WAN link
Support for multiple WAN links on the same physical interface
Support for OAM and data capability for OpCo provider hub
Enhancements to cloud breakout settings
Support for pool-based NAT for local breakout
Enhancements to certificate authority (CA) configuration
SD-WAN support for CPE devices behind NAT in full mesh topology
Support for provider-edge resiliency
Support for BGP underlay route advertisements
Support for flexible (mixed) VLAN tagging
Support for class of service at the logical interface level
Edit support for site properties
Edit support for tenant properties
SD-LAN features
Deploying SD-LAN using EX4600 and EX4650 switches
Support for EX Series Virtual Chassis
Image upgrade for Virtual Chassis members
Return Material Authorization (RMA) support for EX Series switches
Configuration and monitoring of the ports of an EX Series switch
Firewall configurations for EX Series switches
Next-generation firewall features
Support for custom application signatures in firewall policies
Support for customized IPS signatures, static groups, and dynamic groups
Support for importing policy configurations
Miscellaneous
Support for configuration templates
Support for predefined stage-2 templates
Support for retrying failed bootstrap jobs
Enhancements to CSO licenses