Provisioning a Cloud Spoke Site in AWS VPC
Use the following high-level steps to provision a vSRX Virtual Firewall cloud spoke site in Amazon Web Services (AWS) virtual private cloud (VPC).
Before you begin:
Set up your Amazon Web Services (AWS) account.
Identify the virtual private cloud (VPC) in which the AWS spoke site must be provisioned.
Install licenses to use vSRX Virtual Firewall features. Choose any of the following AWS vSRX Virtual Firewall Image Licenses.
Bring Your Own License (BYOL)— If you plan to use a BYOL, then you must install the license on the device before deploying CSO SD-WAN functionality. See https://aws.amazon.com/marketplace/pp/B01LYWCGDX.
License included. See https://aws.amazon.com/marketplace/pp/B01NAUWN0G.
Ensure that you have the supported software version for the AWS spoke.
Reserve two elastic IP (public IP) addresses on AWS.
To set up and monitor your network:
Add a Cloud Spoke Site
To add a cloud spoke site:
Download the Cloud Formation Template
To download the cloud formation template:
Provision the Device on AWS Server
CSO creates cloud formation template with stage-1 configuration bundled in JSON format. You must download this template and then upload to AWS to provision the vSRX Virtual Firewall. The cloud formation template creates the required resources such as subnet, interface, vSRX Virtual Firewall and so on and applies the stage-1 configuration.
To provision the device on AWS server:
Activate the Device
To activate the device: