Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

Pre-Deployment Tasks for CSO SD-WAN and Next-Generation Firewall

 

Before you deploy SD-WAN or next generation firewall (NGFW) in CSO, pre-deployment tasks must be carried out by the SP Administrator (for CSO on-premises) or the OpCo Administrator (for CSO SaaS):

    • If you are an SP Administrator, go to step 2.

    • If you are an OpCo Administrator, go to step 3.

  1. The following tasks are performed by an SP Administrator (CSO on-premises version) or the Juniper Networks team (CSO SaaS version)
    1. Log in to the CSO Administration Portal. See Log In to CSO Administration Portal.
    2. Configure SMTP settings. See Configure SMTP Settings in CSO.
    3. Download latest signature database. See Download the Signature Database.
    4. (Optional) Customize configuration templates. See Configuration Templates Workflow.
    5. (Optional) Customize device templates. See Device Templates Workflow.
    6. (Optional) Upload the latest software images to CSO. See Device Images Workflow.
    7. If you are deploying SD-WAN, perform the following tasks:
      1. Add one or more points of presence (POPs). See Add a Point of Presence (POP).
      2. Add Operation, Administration, and Maintenance (OAM) provider hub devices. See Add a Provider Hub Device.
      3. (Optional) Add data or data and OAM provider hub devices.
    8. (Optional) Add an OpCo. See Add an Operating Company (OpCo).
    9. Add a tenant with SD-WAN service, NGFW service, or both services. See Add a Tenant.
    10. Add CSO licenses. See Add CSO Licenses.

    After completing these tasks, go to step 5.

  2. If you are an OpCo Administrator:
    1. Log in to the CSO Administration Portal. See Log In to CSO Administration Portal.
    2. (Optional) Configure SMTP settings. See Configure SMTP Settings in CSO.

      This task is optional because the SMTP settings are configured by the service provider (for CSO on-premises) or Juniper Networks (for CSO SaaS).

    3. (Optional) Customize configuration templates. See Configuration Templates Workflow.
    4. (Optional) Customize device templates. See Device Templates Workflow.
    5. (Optional) Upload the latest software images to CSO. See Device Images Workflow.
    6. (Optional) If you are deploying SD-WAN and you want to add provider hubs for tenants, do the following:
      1. Add one or more points of presences (POPs). See Add a Point of Presence (POP).
      2. Add data or data and OAM provider hub devices. See Add a Provider Hub Device.Note

        For CSO SaaS, OpCo Administrators should add only provider hub devices with DATA_ONLY capability because the Juniper Networks adds the OAM-capable hubs.

    7. Add a tenant with SD-WAN service, NGFW service, or both services. See Add a Tenant.
    8. Assign CSO licenses to tenants. See Assign CSO Licenses to Tenants.
  3. To ensure WAN redundancy in CSO, an SP Administrator or an OpCo Administrator can preconfigure aggregated Ethernet links enterprise hub devices for tenants. See WAN Link Redundancy in Enterprise Hubs Using Aggregated Ethernet for more information.
  4. Depending on whether you’re deploying SD-WAN or NGFW, see CSO SD-WAN Deployment Workflow or CSO Next-Generation Firewall (NFGW) Deployment Workflow.