This article explains the configuration needed via CSO in order for internet connectivity for LAN segments.
The content in this article applies to CSO 5.0.1.
There are two ways to achieve this goal:
Via Local Breakout in spoke
When creating sites, local breakout must be enabled and the WAN links that are used for local breakout traffic on the site that needs to be configured. You also need to specify whether the WAN links are used exclusively for local breakout traffic or for both local breakout and non-Internet traffic. If a specific WAN link is used exclusively for local breakout, then overlay tunnels for that WAN link are not created.
FW policy must be provisioned from the selected Department (which contains LAN segment) to Any, in order to take care of outgoing traffic.
Routing traffic via hub, including NAT config in hub (No Local breakout)
This can be achieved by including NAT config in Stage-2 template of hub.
To add a stage-2 configuration template:
The Device Templates page appears.
Select a device template for which you want to add the stage-2 configuration and select Edit Device Template > Stage-2 Config Templates.
Note: In 5.0.3, Config designer is integrated to admin portal. If you are running 5.0.1/5.0.1, please contact your Juniper Support Representative to create custom stage 2 templates. (Global admin and SP admin has privilege to access designer tool and OpCo/tenant admin is unauthorized.)