Skip to main content

Azure Conductor Deployment Guide

This guide walks you through deploying a Juniper Session Smart Conductor on Azure using the Bring Your Own License (BYOL) plan. When you complete this guide, the conductor VM will be running SSR 7.1.4, configured with an authority name, conductor address, and shared services that allow branch routers to onboard and begin forwarding traffic.

Guide Topics​

StepTopicDescription
1Create the Azure Conductor VMDeploy the BYOL Conductor VM from the Azure Marketplace
2Initialize and Access the ConductorVerify the BYOL installation and log in to the Conductor GUI
3Configure the ConductorSet the authority name, conductor address, tenant, and internet service
—Appendix — Conductor ConfigurationComplete Azure conductor PCLI configuration reference

Network Topology​

The diagram below shows the logical network this guide builds.

Roles​

The role for this deployment is a Conductor on an Azure VM (BYOL) functioning as a standalone SSR Conductor providing centralized management and provisioning for the router deployment of your choice.

Network Design Reference​

The following IP addressing and naming scheme is used consistently throughout this guide. Substitute your own values when configuring your network.

ParameterExample ValueDescription
Azure RegioneastusAzure region for all deployed resources
Resource GroupSSR-RGAzure resource group containing all resources
VNet NameSSR-VNetVirtual network address space 10.0.0.0/16
Conductor Subnetssr-conductor-subnetConductor management subnet (10.0.0.0/24)
Conductor Private IP10.0.0.10Static private IP assigned within the conductor subnet
Conductor Gateway10.0.0.1Conductor subnet gateway
Conductor Public IP<auto-assigned>Azure-assigned public IP — used for SSH, GUI, and as the conductor address
Authority NameAuthority128SSR organizational authority name
Conductor NameConductorConductor system name
Conductor Node Namenode0Conductor node name
Tenant NamecorpLAN-side user tenant
Service NameInternet-TrafficInternet breakout service
Service Address0.0.0.0/0All internet-bound traffic
NeighborhoodinternetSVR peering neighborhood name

Prerequisites​

Before beginning, ensure the following are available:

  • Azure subscription — with permission to create VMs, VNets, network security groups, and managed identities.
  • Azure VNet — with at least the following subnets already created:
    • ssr-conductor-subnet - The Conductor's primary control subnet. Used for communication with the routers as well as SSH and HTTPS administration access.
  • Azure Managed Identity — with the minimum read permissions listed in Step 1.
  • Juniper software access credentials — Artifactory username and password for SSR software downloads.
  • SSH key pair — RSA 2048-bit or stronger; the public key is supplied to the Azure deployment templates.

Software Version Requirements​

This guide installs SSR 7.1.4 on the conductor.

note

The router software version must be lower than or equal to the conductor software version.

note

BYOL instances require the conductor to run SSR 6.3.0-R1 or newer. SSR 7.1.4 satisfies this requirement.