Task Overview
To help organize the guided setup, we break the configuration into six main tasks.
- Create the sites. In this task, we create a site for the hubs and spokes. We also configure site variables for each site, which are used later in the templates for WAN Edge devices and the hub profile.
Set up the networks. In this tasks, we define the subnet and configure the network “users” (these are the source addresses you will use later for the access policies). You’ll also create LAN segments here, and you can set up NAT rules if need be.
Configure the applications. Applications can be selected from a predefined list, selected by category, or defined individually according to IP address or hostname.
Create hub profiles. These contain the overlay and network paths that are used on the overlay.
- If you add or remove a WAN link in the hub profile, it will affect the paths on the overlay.
- The system automatically creates all the necessary AutoVPN tunnels for the hubs and spokes. The Juniper Mist CA will generate and transfer the certificates used for authentication.
- The system automatically creates a failover probe for each WAN link. You can modify these settings using the API.
Create WAN Edge template for the spoke sites. The WAN Edge template is where you define the WAN interfaces, select the overlay path (as configure in the hub profile), and define the LAN networks. You can also set up traffic steering preferences, define user service policies, and set up the default routing policies (static, BGP, or OSPF).
Attach the template to the site to bring the topology together, and then
Push the configuration to the SRX Services Gateways by saving it.