Azure Conductor Deployment Guide
This guide walks you through deploying a Juniper Session Smart Conductor on Azure using the Bring Your Own License (BYOL) plan. When you complete this guide, the conductor VM will be running SSR 7.1.4, configured with an authority name, conductor address, and shared services that allow branch routers to onboard and begin forwarding traffic.
Guide Topics
| Step | Topic | Description |
|---|---|---|
| 1 | Create the Azure Conductor VM | Deploy the BYOL Conductor VM from the Azure Marketplace |
| 2 | Initialize and Access the Conductor | Verify the BYOL installation and log in to the Conductor GUI |
| 3 | Configure the Conductor | Set the authority name, conductor address, tenant, and internet service |
| — | Appendix — Conductor Configuration | Complete Azure conductor PCLI configuration reference |
Network Topology
The diagram below shows the logical network this guide builds.
Roles
The role for this deployment is a Conductor on an Azure VM (BYOL) functioning as a standalone SSR Conductor providing centralized management and provisioning for the router deployment of your choice.
Network Design Reference
The following IP addressing and naming scheme is used consistently throughout this guide. Substitute your own values when configuring your network.
| Parameter | Example Value | Description |
|---|---|---|
| Azure Region | eastus | Azure region for all deployed resources |
| Resource Group | SSR-RG | Azure resource group containing all resources |
| VNet Name | SSR-VNet | Virtual network address space 10.0.0.0/16 |
| Conductor Subnet | ssr-conductor-subnet | Conductor management subnet (10.0.0.0/24) |
| Conductor Private IP | 10.0.0.10 | Static private IP assigned within the conductor subnet |
| Conductor Gateway | 10.0.0.1 | Conductor subnet gateway |
| Conductor Public IP | <auto-assigned> | Azure-assigned public IP — used for SSH, GUI, and as the conductor address |
| Authority Name | Authority128 | SSR organizational authority name |
| Conductor Name | Conductor | Conductor system name |
| Conductor Node Name | node0 | Conductor node name |
| Tenant Name | corp | LAN-side user tenant |
| Service Name | Internet-Traffic | Internet breakout service |
| Service Address | 0.0.0.0/0 | All internet-bound traffic |
| Neighborhood | internet | SVR peering neighborhood name |
Prerequisites
Before beginning, ensure the following are available:
- Azure subscription — with permission to create VMs, VNets, network security groups, and managed identities.
- Azure VNet — with at least the following subnets already created:
ssr-conductor-subnet- The Conductor's primary control subnet. Used for communication with the routers as well as SSH and HTTPS administration access.
- Azure Managed Identity — with the minimum read permissions listed in Step 1.
- Juniper software access credentials — Artifactory username and password for SSR software downloads.
- SSH key pair — RSA 2048-bit or stronger; the public key is supplied to the Azure deployment templates.
Software Version Requirements
This guide installs SSR 7.1.4 on the conductor.
The router software version must be lower than or equal to the conductor software version.
BYOL instances require the conductor to run SSR 6.3.0-R1 or newer. SSR 7.1.4 satisfies this requirement.