CSO Next-Generation Firewall (NFGW) Deployment Workflow
The Contrail Service Orchestration (CSO) next generation firewall (NGFW) deployment focuses on providing remote network security through the use of SRX Series NGFW devices as the customer premises equipment (CPE) at the branch site. In CSO, you can add two types of NGFW devices:
Greenfield—Greenfield devices are generally devices on which you’ve not deployed any configuration. When you add a greenfield NGFW site, CSO provisions the device by using Zero Touch Provisioning (ZTP). You can then configure and use the NGFW as needed.
Brownfield—Brownfield devices are generally devices that are already configured and operational. When you add a brownfield NGFW site, CSO does not provision the device by using ZTP. This allows you to import existing policies on the device into CSO and deploy the policies. You can then manage the NGFW by using CSO.
Ensure that the pre-deployment tasks related to NGFW are carried out before you follow the procedure outlined in this topic. See Pre-Deployment Tasks for CSO SD-WAN and Next-Generation Firewall.
The following tasks must be performed in the tenant scope in Customer Portal: