Contrail Service Orchestration (CSO) provides the ability to create, modify, and delete firewall policies from the CSO UI. Firewall policies are intent-based and CSO analyzes the intent and then translates it to configuration that devices running Junos OS can understand.
This article explains how to view the configuration that is generated after adding firewall policy intents in the CSO UI.
In this example, we create a simple firewall policy from the CSO UI, select the site to apply the policy, and then add an intent. After the intent is added, we demonstrate how to view the configuration that is generated.
Steps
In this example, we first create a simple firewall policy from the CSO UI.
In the CSO UI, go to the tenant page and navigate to Configuration > Firewall > Firewall Policy.
Create a firewall policy, select the site to apply the policy, and add an intent.
In this example, we add a simple intent to allow the site to access Internet services.
We then deploy the firewall policy.
Now we can check what configuration the above intent has translated to.
Navigate to the Monitor > Jobs page and click the firewall configuration job that was created. A View link will be provided under Configuration, which will show you the configuration that the intent was translated to and which will be added to the site configuration. During firewall policy creation, two jobs are created in CSO: firewall policy job and deploy job.
Navigate to the Monitor > Jobs page and click the firewall configuration job that was created.
A View link will be provided under Configuration, which will show you the configuration that the intent was translated to and which will be added to the site configuration.
During firewall policy creation, two jobs are created in CSO: firewall policy job and deploy job.
.Click the firewall policy job and view its configuration.
The above screenshot shows the configuration that our intent specified in the policy has been translated to.