Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Navigation
Guide That Contains This Content
[+] Expand All
[-] Collapse All

    Creating a Hub-and-Spoke Layer 3 VPN Service Order

    The Network Activate Service can configure and deploy Layer 3 VPN hub-and-spoke service orders. Creating a service order involves the following tasks:

    1. Selecting the Service Definition
    2. Entering Order Information
    3. Selecting Endpoint PE Devices
    4. Configuring Endpoint Settings
    5. Setting Attributes for UNI Endpoints
    6. Adding, Deleting and Modifying Endpoints
    7. Deploying the New Service

    Selecting the Service Definition

    To select a service definition on which to base the new service order:

    1. Select Service Provisioning > Manage Service Orders > Create L3 VPN Service Order.

      The Select Service Definition page appears and shows a filtered inventory view of only those published service definitions designed to work with Layer 3 VPN hub-and-spoke Ethernet services.

    2. Select the service definition you want to base your service order on, and then click Next.

      You must select only those published service definitions configured to work with Layer 3 VPN hub-and-spoke services. See Selecting a Published L3VPN Service Definition for a Service Order.

      The Enter Order Information screen appears.

    Entering Order Information

    This part of the create a Layer 3 VPN hub-and-spoke service order procedure sets general settings, VPN settings that can be applied to all end points, and routing protocol settings for the PE and CE devices.

    You must enter the service order general settings, VPN settings, and PE-CE settings on the Enter Order Information page. See Entering Layer 3 VPN Order Information.

    Entering General Settings Information

    This part of the create Layer 3 VPN hub-and-spoke Ethernet service order procedure sets general information about the service order in the General Settings box of the Enter Order Information screen.

    Enter the following information:

    1. In the Name field, enter a unique name for the hub-and-spoke service.

      The service order name can consist of only letters, numbers, periods, hyphens, and underscores.

      Note: The name you specify for a Layer 3 VPN service order becomes the routing-instance name in the device configuration when you deploy the service. Consequently, you cannot use any Juniper Networks keywords—for example, “bgp” or “ospf”—as the name of a service order.

    2. In the Customer field, select the customer who is requesting the service.

      If the customer is not in the list, you must add the customer to the database before proceeding. See Adding a New Customer.

    3. In the Comments field, enter a description of the service. This description appears in information screens about the request or service instance created from the request.

      You cannot change the Route Target field. Route targets are always selected automatically.

    Specifying QoS Settings

    If you have selected the Enable QoS check box in the selected service definition, you must configure QoS settings.

    To configure QoS settings:

    1. In the QoS profile field, select a profile from the list.

      The QoS profile list displays the QoS profiles that are currently configured in the QoS Design software.

      A QoS profile classifies traffic into defined service groups to provide special treatment of traffic across the network service.

    2. In the CIR field, select the committed information rate (CIR) from the list.

      The CIR is the guaranteed rate, which specifies the minimum bandwidth available if all sources are active at the same time. Make sure that the CIR value is less than the PIR value.

      Note: For bursty traffic, the CIR represents the average rate of traffic per unit time and the PIR represents the maximum amount of traffic that can be transmitted in a given interval.

    3. In the PIR field, select the peak information rate (PIR) from the list. The PIR is the shaping rate.

      Note: If the QoS profile that you selected in Step 1 is configured with a level-three scheduler and interface oversubscription is enabled, then PIR is not used.

    Entering VPN Settings and PE-CE Settings Information

    This part of the create Layer 3 VPN full mesh Ethernet service order procedure sets VPN attributes that are usually common for all endpoints in the service. The values that you enter will vary, depending on the service definition on which the service order is based.

    If these attributes will not be the same on all endpoints, you can set them to be the same for now and then make changes later, or you can choose to skip this step and apply the attribute values one at a time later.

    To set attributes common to most endpoints on a service:

    1. In the MTU (Bytes) field, specify the maximum transmission unit size for the UNI.

      This field is present in all service orders. However, you can set this field only if the service definition allows you to do so.

    2. Specify the MTU Factor or Burst Period, based on the Calculate Burst Size you have selected in the service definition.

      Note: You cannot edit these fields if you have not selected the Editable in Service Order check box in the service definition.

    3. Select the bandwidth from the Bandwidth list. The Bandwidth Range and Bandwidth fields appear only if you have cleared the Enable QoS check box in the selected service definition:

      Note: You cannot edit these fields if you have not selected the Editable in Service Order check box in the service definition.

    4. Note: The fields specified in the Logical IF Settings box are based on the Ethernet option type. The Logical IF Settings box is not available if you have selected the Ethernet option as Port.

      Specify whether the Autopick UNIT ID can be selected automatically or manually.
      • To assign the UNIT ID automatically, select the Autopick UNIT ID check box.
      • To assign the UNIT ID manually, clear the Autopick UNIT ID check box.

        The window expands to include the UNIT ID field. In the UNIT ID field, type a value.

        Range: 1 through 1073741823

      Note: You can edit this field only if you have selected the Editable in Service Order check box for the VLAN ID selection in the service definition.

    5. Clear the Autopick VLAN ID check box if you want the VLAN ID chosen automatically by the Network Activate software. Select the check box to have the ID assigned manually.

      Note: You cannot edit this field if you have not selected the Editable in Service Order check box in the service definition.

      To manually assign a VLAN ID:

      1. Clear the Autopick VLAN ID check box. The screen expands to include the VLAN ID field.
      2. In the VLAN ID field, enter a value.
    6. Select the Autopick Hub Route Target and Autopick Spoke Route Target check boxes if you want the Route target chosen automatically by the Network Activate software.

      Note: You cannot edit this field if you have not selected the Editable in Service Order check box in the service definition.

      To manually assign a Route target:

      1. Clear the Autopick Hub Route Target and Autopick Spoke Route Target check boxes to activate the Hub Route Target and Spoke Route Target fields respectively.
      2. In the Route Target field, enter a value.

        When you manually enter route target, Junos Space accepts either of the following two formats:

        • <prefix-number>: <assigned-number>

          Where <prefix-number> can be any numeric value from 1 to 65535, inclusive. The <assigned-number> can be any numeric value from 0 to 2,147,483,647, inclusive.

        • <IPV4-address>: <assigned-number>

          Where <IPV4-address> can be any valid IPV4 address (in W.X.Y.Z "dot" notation), and <assigned-number> can be any numeric value from 0 to 65535, inclusive.

    7. Select the Autopick Hub Route Distinguisher and the Autopick Spoke Route Distinguisher check boxes if you want the Route distinguisher chosen automatically by the Network Activate software.

      To manually assign a Route distinguisher:

      1. Clear the Autopick Hub Route Distinguisher and the Autopick Spoke Route Distinguisher check boxes to activate the Hub Route distinguisher and Spoke Route distinguisher fields respectively.
      2. In the Route distinguisher field, enter a value.

        When you manually enter route distinguishers, Junos Space accepts either of the following two formats:

        • <prefix-number>: <assigned-number>

          Where <prefix-number> can be any numeric value from 1 to 65535, inclusive. The <assigned-number> can be any numeric value from 0 to 2,147,483,647, inclusive.

        • <IPV4-address>: <assigned-number>

          Where <IPV4-address> can be any valid IPV4 address (in W.X.Y.Z "dot" notation), and <assigned-number> can be any numeric value from 0 to 65535, inclusive.

    8. To configure a separate label for each VRF to provide double lookup and egress filtering, select the VRF Table label check box

      Note: You cannot edit this field if you have not selected the Editable in Service Order check box in the service definition.

      The Export Direct Routes check box is not editable in service order.

    9. In the PE-CE Settings box, select the Static Route check box if you want to allow a service provisioner to create static routes on the service. Clear the Static Route check box to prevent a service provisioner from creating static routes on the service.
    10. If BGP routing protocol is specified in the service definition, select the AS override check box to allow a service provisioner to override the AS number. Clear the AS override check box to prevent a service provisioner from overriding the AS number.

      If OSPF routing protocol is specified in the service definition, in the OSPF domain ID field, specify any valid IPV4 address in W.X.Y.Z "dot" notation.

    11. Click Next.

      The Select Endpoint PE Devices screen appears.

    Selecting Endpoint PE Devices

    You must select the endpoint PE devices that you want to participate in the service. See Selecting Endpoint PE Devices.

    Configuring Endpoint Settings

    This part of the create multipoint Ethernet service order procedure selects the N-PE devices that will host the service endpoints. The selection is made from the Select Endpoint PE Devices screen.

    Note: The Select Endpoint PE Devices screen shows only assigned NPE devices that have an AS number configured. If you do not see the device you are looking for, use the CLI on the device to check for and assign an AS number.

    N-PE devices that have L2VPN only will not appear.

    To select endpoint N-PE devices: For instructions on working with service templates in service orders, see Creating a Service Order Based on a Service Definition with a Template.

    1. In the Select Endpoint PE devices screen, select the devices that you want to participate in the service. Use the multiple selection feature to select more than one device.
    2. Click Next.

      The Endpoint Settings screen appears.

    Setting Attributes for UNI Endpoints

    If there is a service template attached to the service definition, there is a link to that template at the bottom of the Endpoint Settings section of the screen. For instructions on working with service templates in service orders, see Creating a Service Order Based on a Service Definition with a Template.

    This part of the create Ethernet service order procedure sets the attributes for each endpoint in the service. Selection is made using the Endpoint Settings screen.

    The interface shown in the UNI Interface field is automatically selected by the Network Activate software, which chooses the UNI that has the highest available capacity among interfaces that are in the Up state. To calculate the available capacity of the interface, the system subtracts the bandwidth reserved for each service deployed on that interface from the total capacity of the interface.

    For each endpoint, the Endpoint Settings screen shows the value for each UNI attribute.


    To configure or change the endpoint settings:

    1. To add the loopback interface for a Layer 3 VPN service, select the Set loopback check box.

      Note: If you provision a loopback interface for an L3VPN service, an operator is able to identify a VRF routing instance. Thereafter, an operator can manually ping a remote CE router from a local PE router.

    2. Select a value for Ethernet option.
      • Port
      • Dot1Q

        Specifying the Dot1Q Ethernet option enables you to apply a Unit ID, a single VLAN ID, a VLAN Range, or a VLAN list to the service order.

      • QinQ

        Specifying the QinQ Ethernet option enables you to apply a single VLAN, a VLAN Range, or a VLAN list to the service order. For an L3VPN service deployed on a dual tagged interface, the inner tag determines the VPN routing and forwarding instance(VRF).

      • Flexible UNI

        Specifying the Flexible UNI Ethernet option enables you to apply different values for the Unit ID and vlan-tags.

        Note: Prior to release 13.1P6.1, Network Activate set the unit and vlan-id parameters to the same value.

        To create a service order that specifies the Flexible UNI Ethernet option, you must complete two preliminary tasks. First you must create a service template in which you specify both outer and inner vlan tags. Then you must create a service definition that associates the service template with the service definition.

        See Creating a Service Template

        When you create a service order based on a service definition with which a service template is associated, the Add Endpoints window includes a link labeled Flexible Service Attributes. If you click the link, the you can specify Outer and Inner vlan-tags in the Flexible Service Attributes window.


    3. To select a different UNI on a device, click the UNI interface and choose another interface from the list.
    4. In the UNI Description, you can enter the description for the selected UNI interface. The Description field is displayed in Modify Service Order, View Service Order Details, Modify Service, and View Service windows. You can edit this field while modifying a Layer 3 VPN service order or service.

      Range: 0 through 128 characters

    5. Specifying the Logical IF Settings:

      Note: The fields specified in the Logical IF Settings box are based on the Ethernet option type. The Logical IF Settings box is not available if you have selected the Ethernet option as Port.

      • If you have selected the Ethernet option as Dot1Q, or, QinQ, or Flexible UNI, specify whether the Autopick UNIT ID can be selected automatically or manually.
        • To assign the UNIT ID automatically, select the Autopick UNIT ID check box.
        • To assign the UNIT ID manually, clear the Autopick UNIT ID check box.

          The window expands to include the UNIT ID field. In the UNIT ID field, type a value.

          Range: 1 through 1073741823

          Note: The unit ID value that you have specified in the Enter Order Information page is displayed in the UNIT ID field.

      • If you have selected the Ethernet option as Dot1Q, or, QinQ, or Flexible UNI, specify whether the Autopick VLAN ID can be selected automatically or manually.
        • To assign the VLAN ID automatically, select the Autopick VLAN ID check box.
        • To assign the VLAN ID manually, clear the Autopick VLAN ID check box.

          The window expands to include the VLAN ID field. In the VLAN ID field, type a value.

          Note: The unit ID value that you have specified in the Enter Order Information page is displayed in the UNIT ID field.

      • If you have selected the Ethernet option as QinQ, select the Customer VLAN Type.

        If the Customer VLAN type is Transport all traffic, select the Outer Tag Protocol ID.

        If the Customer VLAN type is Transport single vlan, select the Customer VLAN, Inner Tag Protocol ID, and Outer Tag Protocol ID.

        Note: You can optionally specify Inner Tag Protocol ID and Outer Tag Protocol ID.

    6. Clear the Autopick interface IP check box to specify the Interface IP address.

      Select the Autopick interface IP check box to specify the IP address pool and IP block size.

      Note: You cannot edit the Autopick interface IP check box if you have not selected the Editable in Service Order check box in the service definition.

    7. Select the Routing protocol type.

      If the Routing protocol type is BGP, specify the following information:

      • Neighbor IP address

        Note: You need to clear the Autopick neighbor IP check box to specify the Neighbor IP address.

      • Peer AS

      If the Routing protocol type is OSPF, specify the following information:

      • OSPF area ID-–Specify any valid IPV4 address in W.X.Y.Z "dot" notation.

        Note: The IPv4 address that you use must be valid addresses. Refer to http://www.iana.org/assignments/ipv4-address-space for the list of restricted IPv4 addresses.

      • OSPF version-–Select the OSPF version from the list.
    8. If you have attached a service template in the service definition, the Flexible Service Attributes link appears. Click the link to modify the service template attributes. For more information about configuring the flexible service attributes, see Configuring Flexible Service Attributes to Modify Service Template Attributes.
    9. If you have selected the Enable QoS check box in the service definition, specify the following fields:
      • CIR
      • PIR
      • MTU(Bytes)
      • QoS Profile

      If you have cleared the Enable QoS check box in the service definition, specify the following fields:

      • Bandwidth
      • Default MTU

      For more information about these fields, see Creating a Hub-and-Spoke (One Interface) Layer 3 VPN Service Definition.

    10. When you have finished configuring the endpoint settings, click Create.

      The Deployment Options window appears.

    Adding, Deleting and Modifying Endpoints

    You can add or delete UNI interfaces on the PE devices that participate in a service.

    1. To add a UNI on a selected device, select the Add UNI Interface icon in the Actions column, and then select the interface you want from the UNI interface list.
    2. If the interface you selected in the previous step is already configured (duplicate) you must either enter a different value in the VLAN ID field manually, or check the Autopick VLAN ID field.
    3. To delete a UNI from a device, in the Actions column, click the Delete UNI Interface icon in the Actions column.

      If the deleted UNI is the only UNI selected from the device, then the device is deleted form the service configuration.

    4. To set or modify attributes for a UNI endpoint:

      1. Select the row for the UNI endpoint that you want to modify.

        A UNI Settings dialog box appears on the right side of the screen.

      2. Modify the fields in right pane.
      3. Select Save to apply the attributes to the UNI interface, or select Add More to save your changes and modify attributes for other UNI endpoints on the service.
    5. When you have finished modifying the endpoint settings, click Create.

      The Deployment Options window appears.

      The service order that you have created is graphically represented in the topology. To view the service order that you have created in the topology, select Platform > Network Monitoring > Topology > Service > NA service order name.

      For more information on topology, see Junos Space Network Topology Overview

    Deploying the New Service

    This part of the create multipoint Ethernet service order procedure deploys the service.

    To deploy the service, make selections from the Deployment Options window.

    1. Perform one of these actions:
      • To save the request without deploying the service, select Save only and then click OK.

        See Deploying a Service Order for information about how to deploy a saved service at a later time.

      • To deploy the service immediately, select Deploy now and then click OK.
      • To deploy the service later, select Schedule deployment, select a date and time, and then click OK.

        The time field specifies the time kept by the server, but in the time zone of the client.

      • To validate the service, click Validate.

      The Job ID dialog box appears.

    2. Click the Job ID link to monitor the status of the service deployment.

      The Deployment Service job appears on the Platform > Jobs > Job Management inventory page.

    3. You can also view the Platform > Audit Logs > Audit Log inventory page to view the Deploy Service Order username, user IP address, task, timestamp, description, and job ID.

    The service order is now complete.

    The Manage Service Orders inventory view shows the service order you just added. See Viewing Jobs in the Junos Space Network Application Platform User Guide for details about the Jobs workspace.

    Modified: 2017-02-15