Add an SD-WAN On-Premise Spoke Site
The following illustration shows a simple SD-WAN topology.
Before you add an on-premise spoke site:
Add an enterprise hub site.
Connect cables to the device according to your network design and power on the device.
This task assumes that the device will get DHCP IP address and will have Internet connectivity along with DNS resolution when connected according to the network design.
For more information about connecting the cables and connecting the device to a console, see the documentation for the CPE device as listed in Table 1. .
Ensure that ESP protocol traffic is allowed on the network.
Ensure that the ports listed in Table 1 are open on the network.
Ensure that the devices are running the recommended version of Junos OS. For information about the supported Junos OS versions, see the Release Notes for that release.
CPE WAN Link Ports
SRX3xx devices, SRX550M, and vSRX devices
If you are using a GRE-only overlay between an SRX CPE and a hub device, ensure that GRE Traffic is enabled between CPE and the hub device.
To add an on-premise spoke site for SD-WAN:
- From the Sites page (Resources > Site
Management) of the CSO portal, click Add and select On-Premise Spoke Site.
The Add Site wizard appears.
- Complete the settings as explained in Table 2.
- Click OK to add the site.
When the site is successfully created, the Site Status in the Sites page changes to Provisioned.
Table 2: SD-WAN On-Premise Spoke Site Settings
Enter a unique name for the site. You can use alphanumeric characters and hyphen (-); the maximum length is 10 characters.
Select an enterprise hub site as the primary hub from the list of available hub sites. If there is only one hub site available, that one is selected by default.
Select the CPE device.
Select a device template for the CPE device.
Enter the serial number of the CPE device.
If the selected device template supports ZTP, Auto Activate is enabled. When Auto Activate is enabled, zero-touch provisioning of the device is automatically triggered when the site is added.
The Activation Code field appears if the selected device template does not support ZTP or if you disable the Auto Activate option.
In such cases, specify the activation code of the device to manually activate a device. For information about manually activating a device, see Activate a Device.
Specify whether the link is an Internet link or an MPLS link.
If you select Internet as the Link Type, select the Access Type. The access type options available for Internet link are: Ethernet, LTE, ADSL, and VDSL.
Specify the maximum bandwidth allocated for the WAN link.
Specify whether to use DHCP or Static addresses.
If you select Static, specify a Static IP Prefix and Gateway IP Prefix.
Enter the name of the service provider.
Cost per month
Enter the per month cost of the link. This information is used to identify the least expensive link when link switch occurs.
Add LAN Segment
Click to add a LAN segment.
Enter a unique name for the LAN segment.
Enter a valid gateway IP address andmask for the LAN segment; for example, 192.0.2.8/24.
Select a department from the list; if no department is available, click Create Department and add one.
A department is a grouping of LAN segments within a site. You use departments to apply specific policies to LAN segments that are members of a department.
Select at least one CPE port.
After the site is provisioned, you can complete the following tasks as required:
Upload and install licenses. For example, Administration > Licenses.
Install signatures. For example, Administration > Signature Database.
Add, edit, and deploy an SD-WAN policy. For example, Configuration > SD-WAN Policy .
Create and generate reports. For example, Reports > Report Definitions > SD-WAN.
Monitor alerts and alarms, SLA performance of tenants, and jobs. For example, Monitor > Jobs.
For more information about these tasks, see the Contrail Service Orchestration user guide at https://www.juniper.net/ documentation/product/en_US/contrail-service-orchestration.