Juniper-LOGO

Juniper NCE-511 AI-Driven SD-WAN Reference Architecture

Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -PRODUCT

Specifications

  • Khoom Lub npe: Juniper AI-Driven SD-WAN
  • Kev koom ua ke: Microsoft's SSE Solution
  • Tshaj tawm Hnub tim: 2024-12-16 ib

Cov ntaub ntawv khoom
Juniper AI-Driven SD-WAN koom nrog Microsoft's SSE Solution los muab kev teeb tsa network examples rau deployment scenarios. Cov kev daws teeb meem muab cov txiaj ntsig xws li kev txhim kho network kev ua tau zoo thiab kev npaj ua kom zoo tshaj plaws.

Cov lus qhia siv khoom

Configuration Workflow
Kev teeb tsa example suav nrog kev tsim thiab xa tawm ib ceg qauv qauv rau kev sib txuas ntawm cov cuab yeej. Ua ntej kev teeb tsa, xyuas kom koj muaj cov ntaub ntawv tsim nyog rau txhua qhov chaw, suav nrog WAN qhov chaw nyob txuas, BGP peering chaw nyob, BGP AS tus lej, kev tso cai nkag mus, kev xav tau bandwidth, thiab cov qauv rov ua dua.

Configuration Basics

  1. Tsim ib ceg qauv qauv rau kev sib txuas ntawm cov cuab yeej.
  2. Configure IPsec qhov.
  3. Associate traffic profiles.
  4. View lub network profile.
  5. Tsim cov ntawv thov.
  6. Hloov kho WAN Edge templates.
  7. Tshawb xyuas kev ua haujlwm.

Configuration Options
Ntau qhov kev xaiv configuration muaj nyob nrog ntau ntau redundancy. Nyob ntawm qhov teeb tsa, koj tuaj yeem teeb tsa ib lossis ob qhov txuas WAN nrog Microsoft's SSE Solution. Xyuas kom ua raws li cov lus qhia tshwj xeeb rau WAN Edge thiab Microsoft's SSE Solution configurations.

Juniper AI-Driven SD-WAN thiab Microsoft's SSE Solution Integration-Network Configuration Example (NCE)
Juniper Networks Network Configuration Example (NCE) piav qhia yuav ua li cas teeb tsa thiab xa cov khoom Juniper hauv ib qho xwm txheej siv cov xwm txheej. Hauv NCE no, koj yuav pom cov xwm txheej siv nrog cov topology, cov ntaub ntawv teeb tsa, thiab cov ntaub ntawv pov thawj rau kev teeb tsa. Nyeem ntxiv kom npaj thiab ua kom zoo dua koj lub network xa tawm.

Cov txiaj ntsig daws

  • Qhov no network configuration example (NCE) piav qhia txog kev sib koom ua ke uas koj tuaj yeem ua tiav ntawm Juniper AI-Driven SD-WAN thiab Microsoft's SSE daws. NCE piav qhia txog cov txiaj ntsig ntawm kev sib koom ua ke cov kev daws teeb meem thiab muab ntau yam example configurations nrog rau cov kauj ruam pov thawj.
  • Microsoft's cloud-based Secure Service Edge (SSE) kev daws teeb meem suav nrog Microsoft Entra Internet Access thiab Microsoft Private Access, nyob rau hauv lub ntiaj teb Kev Ruaj Ntseg Access hom. Juniper AI-Driven SD-WAN kev daws teeb meem muab seamless nkag mus rau Microsoft's SSE daws los ntawm ceg thiab chaw ua haujlwm. Qhov kev sib koom ua ke no yog automated siv scalable device templates kom yooj yim lub luag haujlwm ntawm kev xa cov kev pabcuam rau ntau qhov chaw. Phau ntawv qhia no piav qhia txog yuav ua li cas teeb tsa Microsoft lub SSE kev daws teeb meem thiab Juniper Mist WAN Edge template rau kev sib txuas.

Cov ntaub ntawv no ua rau cov topology qhia hauv daim duab 1 ntawm nplooj ntawv 2. Ib qho IPsec qhov tau teeb tsa ntawm Juniper AI-Driven SD-WAN ntaus ntawv, tseem hu ua Juniper Session Smart Router (SSR), thiab Microsoft's SSE tov siv lub Secure Edge Connector hauv WAN Edge template. Tsis tas li ntawd, BGP dhau IPsec kev sib txuas tau teeb tsa kom muaj kev kawm routing destinations los ntawm Microsoft txoj kev daws teeb meem SSE. Thaum siv rau Microsoft 365 nkag mus, Microsoft's SSE cov chaw nyob tshaj tawm yog siv los txiav txim cov tsheb xa mus rau qhov kev pabcuam es tsis yog WAN Edge-raws li phau ntawv txhais lus thov.

Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (1)

Configuration Workflow
Qhov sib lawv liag ntawm cov dej num hauv no configuration example:

  1. Tsim thiab xa tawm ib ceg qauv qauv rau kev sib txuas ntawm cov cuab yeej. Tsim cov qauv yooj yim yog tawm ntawm qhov kev qhia no, tab sis WAN Edge template tej zaum yuav yog ib leeg los yog SD-WAN nrog kev ruaj ntseg enabled.
  2. Configure ib tug tej thaj chaw deb network nyob rau hauv lub Microsoft Entra portal. Qhov no txhais cov yam ntxwv IPsec qhov thiab txhais cov ntsiab lus kawg rau kev ncav cuag.
  3. Configure ib tug Secure Edge Connector nyob rau hauv lub ntaus ntawv template. Qhov no tsim ib qho kev cai IPsec qhov rau Microsoft's SSE kev daws teeb meem thiab txheeb xyuas qhov tsis muaj encryption.
  4. Configure a BGP peer rau Microsoft's SSE solution service to learn Microsoft 365 destinations dynamically.
  5. Configure ib daim ntawv thov kom tso cai rau kev khiav tsheb mus rau IPsec qhov. Daim ntawv thov no yuav raug siv rau hauv daim ntawv thov txoj cai kom tso cai rau cov neeg siv khoom siv nkag mus rau BGP txoj kev kawm.
  6. Teeb tsa ib daim ntawv thov txoj cai nrog lub network thiab daim ntawv thov, tab sis tsis muaj txoj cai tswj hwm kev khiav tsheb los qhia rau WAN Edge tias lub rooj sib tham yuav tsum tau siv rau qhov chaw kawm.

Configuration Planning
Ua ntej kev teeb tsa, cov ntaub ntawv hauv qab no yuav tsum muaj rau txhua qhov chaw:

  1. Qhov chaw nyob pej xeem ntawm WAN txuas uas siv los mus cuag Microsoft's SSE kev pabcuam daws teeb meem. Lub sijhawm no, tsuas yog qhov chaw nyob zoo li qub WAN yuav raug siv los mus txog qhov kev pabcuam.
  2. Ib lossis ob / 29 qhov chaw nyob uas muaj rau BGP peering ntawm WAN Edge loopback thiab Microsoft's SSE daws. Thaum xav tau ib cheeb tsam redundancy, ob qhov chaw nyob yuav tsum tau.
  3. BGP AS siv los ntawm Microsoft's SSE daws. Qhov no yuav yog nyob rau hauv tus kheej AS ntau yam tsis siv lwm qhov hauv kev lag luam network.
  4. Networks thiab cov neeg siv uas tau tso cai nkag mus rau Microsoft's SSE kev daws teeb meem.
  5. Bandwidth xav tau rau txhua qhov chaw. Qhov no yog siv nyob rau hauv tej thaj chaw deb network configuration nyob rau hauv lub Microsoft Entra portal.
  6. Desired redundancy qauv rau txhua qhov chaw. Cov kev xaiv muaj xws li ib leeg / dual WAN rau WAN Edge thiab ib leeg / dual Zone rau Microsoft's SSE daws. Kev teeb tsa ib leeg / dual WAN tuaj yeem siv nrog ib leeg SSR lossis HA SSR.

Configuration Options thiab Workflows
Muaj ntau qhov kev xaiv configuration muaj nyob nrog ntau theem ntawm redundancy. Rau Juniper SSR WAN Edge, nws tuaj yeem teeb tsa ib qho ntawm ib qho los yog ob qho WAN interfaces txuas nrog Microsoft's SSE daws. Lub dual node HA SSR router yuav tsum tau teeb tsa nrog ob WAN interfaces txuas nrog Microsoft's SSE daws.

Nco tseg: Thaum cheeb tsam redundancy tau teeb tsa ntawm Microsoft's SSE daws, ces ob BGP cov phooj ywg raug teeb tsa raws li cov neeg nyob sib ze hla ib lub qhov.

Peb qhov kev xaiv configuration muaj nyob rau hauv phau ntawv qhia no:

  1. Ib qho WAN txuas thiab cov phooj ywg ntawm Microsoft's SSE daws. Qhov kev teeb tsa no yuav raug siv rau kev xa tawm me me thiab kev sim thaum tsis tas yuav tsum tau rov ua dua.
  2. Ib qho WAN txuas nrog thaj tsam redundancy ntawm Microsoft's SSE daws. Qhov kev teeb tsa no tsis muab kev rov ua dua ntawm SSR WAN Edge tab sis npog tsis ua haujlwm ntawm thaj chaw muaj nyob ntawm Microsoft's SSE daws. Qhov kev xaiv no suav nrog los piav qhia txog yuav ua li cas ob BGP cov phooj ywg yuav raug teeb tsa hla tib IPsec qhov.
  3. Dual WAN txuas siv HA SSR nrog thaj tsam redundancy ib qhov ntawm Microsoft's SSE daws. Qhov no muab qhov siab tshaj plaws ntawm redundancy rau ob qho tib si WAN Edge thiab Microsoft txoj kev daws teeb meem SSE. Kev ua tsis tiav ntawm SSR node, WAN txuas lossis Microsoft muaj nyob hauv cheeb tsam tsis cuam tshuam rau kev khiav tsheb hauv qhov kev teeb tsa no.

Kev rov ua dua ntxiv thiab WAN txuas qhov hloov pauv yuav raug teeb tsa siv cov kev teeb tsa yooj yim hauv tsev tau piav qhia rau txhua qhov kev hloov pauv no.

Ib leeg WAN Txuas thiab Peer ntawm Microsoft's SSE Solution
Qhov kev xaiv configuration no tau piav qhia hauv daim duab hauv qab no.

Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (2)

Configuration Basics

Nkag mus rau Microsoft Entra portal nrog qhov no URL, https://entra.microsoft.com, siv cov ntawv pov thawj nrog kev tso cai tswj hwm los teeb tsa Microsoft's SSE kev daws teeb meem.

  1. Ntawm Microsoft Entra Portal, mus rau Ntiaj Teb Kev Ruaj Ntseg> Cov Khoom Siv> Chaw Taws Teeb.
  2. Xaiv Tsim tej thaj chaw deb network thiab muab lub npe thiab cheeb tsam cov ntsiab lus. Thaj chaw qhia txog thaj av Azure qhov twg qhov kawg ntawm koj lub qhov yuav yog (ib kawg yog WAN Edge SSR router ntawm ceg).
  3. Nyem Next.

Tsim ib lub NETWORK

Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (3)

Configure IPsec Qhov

  1. Xaiv lub + Ntxiv khawm txuas.
  2. Sau cov ntsiab lus hauv qab no:
    1. Lub npe txuas: Lub npe ntawm koj lub cuab yeej WAN Edge.
    2. Ntaus hom: Xaiv ib qho ntawm cov kev xaiv los ntawm daim ntawv teev npe (Lwm yam lossis Juniper).
    3. Ntaus IP chaw nyob: Pej xeem IP chaw nyob ntawm WAN txuas siv los txuas rau Microsoft.
    4. Ntaus BGP chaw nyob: Tus ciam teb rooj vag raws tu qauv chaw nyob ntawm WAN Ntug. Qhov no yuav yog Local BGP chaw nyob ntawm WAN Edge thiab yuav nyob rau hauv /29 ntau yam xaiv rau kev sib txuas. Qhov kev rov qab sib koom ua ke yuav ua tiav hauv Entra portal.
    5. Ntaus ASN: Muab tus lej tswj hwm tus kheej ntawm WAN Edge network. Los ntawm lub neej ntawd, tus nqi no yog 65000 tab sis tuaj yeem hloov kho siv Mist APIs.
    6. Redundancy: Xaiv qhov Tsis muaj redundancy lossis Zone redundancy rau koj IPsec qhov. Yog tias koj xaiv Zone redundancy, ces lwm qhov tshwj xeeb cheeb tsam redundant hauv zos BGP chaw nyob yog teeb tsa.
      CEEB TOOM: Microsoft txwv kev teeb tsa rau cov npe ntawm ASNs siv tau.
    7. Bandwidth peev xwm (Mbps): Xaiv qhov bandwidth rau koj IPsec qhov.
    8. Qhov chaw nyob BGP hauv zos: Qhov no yog qhov chaw nyob IP ntiag tug sab nraud ntawm qhov chaw nyob hauv lub network hauv /29 ntau yam xaiv rau kev sib txuas. Rau example, yog tias lub cuab yeej BGP chaw nyob xaiv rau WAN Edge cov phooj ywg saum toj no yog 10.99.99.1, ces siv 10.99.99.2.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (4)
  3. Nyem Next.
  4. Txoj cai IPsec/IKE tau teem rau Default tab sis hloov nws mus rau Kev Cai.
  5. Tom qab xaiv Custom, xaiv ib qho kev sib txuas ntawm cov chaw uas phim WAN Edge. Hauv no example, xaiv qhov chaw hauv qab no:
    • Encryption
    • IKEv2 kev ncaj ncees
    • DH Group
    • IPSec encryption
    • IPSec kev ncaj ncees
    • PFS Group
    • SA lub neej
      Nco tseg: Txoj cai IPsec/IKE tau teev tseg yuav tsum phim txoj cai ntawm WAN Edge.
  6. Review tej thaj chaw deb network siv tau configurations.
  7. Nyem Next.
  8. Nkag mus rau tus yuam sij pre-shared (PSK). Tib tus yuam sij zais cia yuav tsum siv rau ntawm koj CPE.
  9. Xaiv Ntxiv qhov txuas.

Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (5)

Associate Traffic Profile

  1. Los yog nyem Next lossis xaiv Traffic profiles tab.
  2. Xaiv Microsoft 365 tsheb khiav profile. Qhov no ua kom ntseeg tau tias tsuas yog Microsoft 365 tsheb thauj mus los tau xa mus rau Microsoft txoj kev daws teeb meem SSE. Tus so ntawm lub tsheb yuav ua raws li Txoj Cai Thov Kev Pabcuam.
  3. Xaiv Review + Tsim.

Nco tseg: Xaiv Tsim tej thaj chaw deb network kom ua tiav cov chaw taws teeb network configuration.

Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (6)

View Network Profile
Thaum cov chaw taws teeb network tsim, mus rau cov npe ntawm cov chaw taws teeb network thiab xaiv View kev teeb tsa. Qhov no qhia txog kev ua haujlwm pane nrog cov ntsiab lus txuas rau Microsoft lub rooj vag. Cov ntsiab lus suav nrog pej xeem cov ntsiab lus kawg ntawm Microsoft lub qhov rooj SSE uas tau ntxiv rau WAN, nrog rau BGP thiab ASN qhov tseem ceeb.

Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (7)

Tsim Daim Ntawv Thov

  • Ib qho txiaj ntsig ntawm Microsoft's SSE kev daws teeb meem yog tias Microsoft 365 daim ntawv thov raug tshaj tawm dynamically rau WAN Edge. Qhov no txhais tau hais tias, raws li cov chaw tiv thaiv tau hloov kho tshiab thiab cov chaw pabcuam tau hloov kho raws sijhawm, Microsoft's SSE cov kev daws teeb meem tuaj yeem tshaj tawm cov kev pabcuam no mus rau WAN Edge rau kev thauj mus los rau kev pabcuam.
  • Ib qho txiaj ntsig ntawm Juniper's AI-Driven SD-WAN yog txoj cai routing yog "Zero Trust." Qhov no txhais tau hais tias tsuas yog vim txoj kev tau kawm, nws tsis tau txhais hais tias lub network tuaj yeem nkag mus rau qhov chaw mus txog ntawm txoj kev tshaj tawm. Txoj cai thov yuav tsum tso cai rau Network kom nkag mus rau daim ntawv thov.
  • Ib tus yam ntxwv tshwj xeeb ntawm Session Smart Router (SSR) yog tias nws yuav raug teeb tsa rau txoj hauv kev tsis muaj xwm txheej mus rau qhov chaw uas siv Txoj Cai Tswjfwm Ntiag Tug, lossis ua raws li cov kev kawm hauv RIB (cov ntaub ntawv qhia txog lub hauv paus lossis kab lus). Thaum txoj cai tswjfwm tau txhais rau cov tsheb thauj mus los hauv zos mus rau WAN lossis LAN txuas (rau example, DIA), txoj cai no overrides tej kev kawm. Yog li ntawd, ib qho kev pabcuam hauv Is Taws Nem tau coj mus rau qhov chaw sib cuam tshuam hauv zos (tsis yog cov kev kawm dynamically los ntawm kev sib tshooj), ua ntej ntawm cov kev kawm yog tias tau teeb tsa hauv WAN Edge template.
  • Thaum Microsoft's SSE kev daws teeb meem yog siv rau txhua qhov kev khiav tsheb hauv Is Taws Nem, tom qab ntawd ib daim ntawv thov Internet yooj yim nrog lub npe ua ntej 0.0.0.0/0 yuav raug siv, thiab tus neeg siv tau txais kev tso cai yam tsis muaj txoj cai tswj xyuas raws li qhia hauv qab no:Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (8)
  • Qhov no yuav qhia rau WAN ntug kom tso cai rau Network "Lab" siv ib qho ntawm txoj kev kawm los ntawm kev sib tshooj lossis los ntawm IPsec rau Microsoft's SSE daws.
  • Txawm li cas los xij, yog tias qhov kev pabcuam hauv Is Taws Nem twb tau tsim thiab siv DIA cov cai raws li qhia hauv example hauv qab no, tom qab ntawv yuav tsum tau tsim ib daim ntawv thov cais kom tso cai rau cov kev kawm tau siv ua ntej.
  • Txoj hauv kev ua qhov no yog txhais ib daim ntawv thov "IPSec" tshwj xeeb tshaj li 0.0.0.0/0 daim ntawv thov Internet. Thaum cov ntawv sau ua ntej yuav tsum tau kawm tsis paub (tsis tuaj yeem teeb tsa), tom qab ntawd tsim daim ntawv thov IPsec nrog cov lus qhia tshwj xeeb ntxiv kom ntseeg tau tias cov lus qhia tau raug xa los ntawm IPsec BGP cov phooj ywg thiab siv rau kev tso cai network.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (9)
  1. Hauv Mist portal, mus rau Lub Koom Haum> WAN> Daim Ntawv Thov.
  2. Nyem Ntxiv Daim Ntawv Thov.
  3. Txhais lub npe ntawm daim ntawv thov (example, IPSec). Saib daim duab hauv qab no.
  4. Xaiv Custom Apps.
  5. Nkag mus rau cov npe ua ntej 128.0.0.0/1 thiab 0.0.0.0/1 rau IP Chaw Nyob. Cov prefixes no tshwj xeeb tshaj qhov 0.0.0.0/0.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (10)
  6. Nyem Txuag thiab mus rau Lub Koom Haum> WAN> WAN Ntug Templates.

Hloov tshiab WAN Ntug Template

Hauv Mist portal, mus rau WAN Edge Template rau Session Smart Router WAN Edge ntaus ntawv.

  1. Xaiv Ntxiv Cov Chaw Pabcuam hauv Secure Edge Connectors kom qhib lub vaj huam sib luag teeb tsa.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (11)
  2. Nkag mus rau cov npe hauv qab no kom phim Microsoft's SSE daws:
    • Lub npe: (example, MicrosoftSSE)
    • Tus neeg zov me nyuam: Kev cai
    • raws tu qauv: IPSec
    • LocalID:
    • Pre-shared Key:
    • IP los yog Hostname:
    • Qhov chaw IP:
    • Chaw taws teeb ID:
    • WAN interface:
    • IPSec Proposals:
      • Encryption: aes256
      • Authentication Algorithm: sha2
      • DH Group: 14
    • IPSec Proposals:
      • Encryption Algorithm: aes_gcm256
      • DH Group: 14
      • SA Lub neej: 1800 vib nas thisJuniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (12)Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (13)
  3. Nyem Txuag rau hauv qab ntawm lub qhov rais.
  4. Tsim ib pab pawg BGP tshiab siv BGP dialog.
    Siv cov txiaj ntsig tau xaiv yav dhau los:
    • Lub npe:
    • Hom: Sab nraud
    • Hauv zos AS: <65000 lossis tsis yog AS rau WAN Ntug>Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (14)
  5. Xaiv Ntxiv Neighbor hauv BGP dialog box.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (15)
  6. 6. Sau cov txiaj ntsig hauv qab no rau BGP cov phooj ywg:
    • IP Chaw Nyob: BGP tus phooj ywg chaw nyob ntawm Microsoft txoj kev daws teeb meem SSE
    • Yeem: Ntxiv BGP txoj cai rau ntshuam/export ntawm txoj kevJuniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (16)
  7. Nkag mus rau Daim Ntawv Thov Txoj Cai thiab nyem Ntxiv Daim Ntawv Thov Txoj Cai.
    • Ntshuam Daim Ntawv Thov Txoj Cai
    • Ntxiv Txoj Cai Thov
    • Kho cov ntawv thov
  8. Siv daim ntawv thov npe tsim nyob rau hauv cov kauj ruam saum toj no, ntxiv ib txoj cai tso cai rau cov kev sib txuas uas xav tau kom ncav cuag qhov tshwj xeeb "IPSec" daim ntawv thov siv cov lus qhia. Tawm ntawm Txoj Cai Tswjfwm Ntiag Tug qhia rau SSR kom siv lub rooj sib tham rau cov lus hais ua ntej nyob rau hauv daim ntawv thov ntau yam.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (17)
  9. Nkag mus rau sab saum toj ntawm Template thiab nyem Txuag.
    Soj Ntsuam Xyuas Haujlwm
    • Thaum tus qauv hloov kho, IPsec teeb tsa yuav raug thawb mus rau WAN Edge ntaus ntawv. Yog tias qhov no yog thawj zaug IPsec xa tawm, qhov no yuav siv sijhawm qee lub sijhawm los rub tawm cov software / teeb tsa.
    • Thaum lub IPsec configuration yog deployed, koj ua tau view IPsec xwm txheej nyob rau hauv WAN Ntug> > Ruaj ntseg Edge Connector Paub meej.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (18)
    • BGP cov neeg nyob ze cov xwm txheej tuaj yeem pom nyob rau hauv Saib> Kev Pom Zoo> WAN Ntug.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (19)
    • Tej zaum nws yuav muaj txiaj ntsig zoo rau kev mus rau Kev Ntsuas cov cuab yeej los soj ntsuam cov kev kawm hauv qab WAN Edge > Utilities > Testing Tools > Routes > Qhia Routes. Hauv cov duab hauv qab no, cov kev kawm tau los ntawm IPsec yuav tshwm sim nrog Microsoft's SSE daws BGP cov phooj ywg raws li kev vam tom ntej.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (20)

Ib qho WAN Txuas nrog Zone Redundancy ntawm Microsoft SSE Solution

Qhov kev xaiv configuration no tau piav qhia hauv daim duab hauv qab no.

Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (21)

Hauv qhov kev teeb tsa no, tus neeg sib tw BGP thib ob yog tsim siv thaj tsam redundancy hauv Microsoft SSE daws. Ua raws li cov kauj ruam tau piav qhia saum toj no nrog cov hauv qab no ntxiv:

  1. Nco ntsoov xaiv Zone redundancy thaum tsim qhov txuas mus rau cov chaw taws teeb network hauv Microsoft SSE daws raws li qhia hauv qab no. Qhov no tsim ib tug thib ob BGP cov phooj ywg uas yuav mus txog los ntawm tib lub chaw taws teeb network txuas thiab IPsec qhov los ntawm SSR.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (22)
  2. Tsim ib tug thib ob BGP cov phooj ywg siv tib pab pawg BGP nyob rau hauv lub ntaus ntawv template nyob rau hauv Mist. Qhov chaw nyob ua phooj ywg tuaj yeem pom nyob rau hauv SSE teeb tsa raws li qhia.Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (23)

Dual WAN Txuas Siv HA SSR nrog Zone Redundancy Ib Qhov ntawm Microsoft SSE Solution
Qhov kev xaiv configuration no tau piav qhia hauv daim duab hauv qab no.

Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (24)

Hauv qhov kev teeb tsa no, ob qhov txuas thib ob thiab thib ob BGP cov phooj ywg ib qhov txuas tau tsim siv thaj tsam redundancy hauv Microsoft SSE daws. Ua raws li cov kauj ruam tau piav qhia saum toj no nrog cov hauv qab no ntxiv:

  1. Xyuas kom xaiv Zone redundancy thaum tsim cov txuas raws li tau piav qhia saum toj no.
  2. Tsim tus thib ob BGP cov phooj ywg nyob rau hauv tib lub BGP pawg teeb tsa uas yog taw tes rau SEC Qhov av raws li kev sib raug zoo network.
  3. Tsim ib qhov txuas thib ob hauv Microsoft SSE kev daws teeb meem rau tib lub chaw taws teeb chaw taws teeb. Qhov txuas no tuaj yeem raug ntxiv thaum lub sij hawm pib lub network teeb tsa lossis ntxiv siv qhov chaw taws teeb network dialog box qhia hauv qab no. Xaiv cov chaw taws teeb network> Chaw Taws Teeb Lub Npe> Txuas> Ntxiv qhov txuas.
  4. Rov ua cov kauj ruam saum toj no ntxiv rau lwm qhov Secure Edge Connector nyob rau hauv tus qauv ntaus ntawv hauv Mist. Qhov no muab lub sijhawm los tswj lub qhov av tawm ntawm qhov chaw nruab nrab hauv qhov kev teeb tsa siab.
  5. Tsim ib pab pawg BGP thib ob uas raug xa mus rau qhov thib ob Secure Edge Connector. Cov pab pawg no raug xa mus rau qhov txuas thib ob (SEC qhov) ua qhov sib txuas sab nraud.
  6. Tsim ib khub thib ob ntawm BGP cov phooj ywg hauv BGP Pawg siv qhov txuas ntxiv thiab BGP peering teeb tsa hauv Microsoft SSR daws.

Juniper-NCE-511-AI-Driven-SD-WAN-Reference-Architecture -FIG- (25)

Juniper Networks, Juniper Networks logo, Juniper, thiab Junos yog cov npe lag luam ntawm Juniper Networks, Inc. hauv Tebchaws Meskas thiab lwm lub tebchaws. Tag nrho lwm cov cim kev lag luam, cov cim kev pabcuam, cov cim sau npe, lossis cov cim npe kev pabcuam yog cov cuab yeej ntawm lawv cov tswv. Juniper Networks xav tias tsis muaj lub luag haujlwm rau qhov tsis raug hauv daim ntawv no. Juniper Networks muaj cai hloov pauv, hloov kho, hloov pauv, lossis hloov kho cov ntawv tshaj tawm no yam tsis muaj ntawv ceeb toom. Copyright © 2024 Juniper Networks, Inc. All rights reserved.

FAQ

Q: Cov ntaub ntawv dab tsi yuav tsum tau ua ua ntej teeb tsa lub network?
A: Ua ntej kev teeb tsa, koj yuav tsum muaj cov chaw nyob pej xeem ntawm WAN txuas, BGP peering chaw nyob ranges, BGP AS tus lej, kev tso cai nkag, bandwidth yuav tsum, thiab cov qauv rov ua dua tshiab rau txhua qhov chaw.

Q: Muaj pes tsawg txoj kev xaiv muaj nyob rau hauv phau ntawv qhia? 
A: Cov lus qhia npog peb txoj kev teeb tsa: Ib qho WAN txuas thiab cov phooj ywg ntawm Microsoft's SSE Solution, Ib qho WAN txuas nrog thaj tsam redundancy ntawm Microsoft's SSE Solution, thiab Dual WAN txuas siv HA SSR nrog thaj tsam redundancy ib qhov ntawm Microsoft's SSE Solution.

Cov ntaub ntawv / Cov ntaub ntawv

Juniper NCE-511 AI-Driven SD-WAN Reference Architecture [ua pdf] Cov neeg siv phau ntawv qhia
NCE-511 AI-Driven SD-WAN Reference Architecture, NCE-511, AI-Driven SD-WAN Reference Architecture, Siv Architecture, Architecture

Cov ntaub ntawv

Cia ib saib

Koj email chaw nyob yuav tsis raug luam tawm. Cov teb uas yuav tsum tau muaj yog cim *